ExamQuestions.com

Register
Login
Certified Information Security Manager Exam Questions

Isaca

Certified Information Security Manager

265 / 500

Question 265:

Which of the following techniques MOST clearly indicates whether specific risk-reduction controls should be implemented? 

Answer options:

A. Countermeasure cost-benefit analysis
B. Penetration testing
C. Frequent risk assessment programs
D. Annual loss expectancy (ALE) calculation