Best Input for a Business Case Addressing System Vulnerabilities?

Answer Correct answer: C — Leverage a comprehensive risk assessment to quantify vulnerability exposure and align technical remediation with organizational priorities for executive approval.

Which of the following would provide the BEST input to a business case for a technical solution to address potential system vulnerabilities?

  1. Business impact analysis (BIA)
  2. Vulnerability scan results
  3. Risk assessment Correct Answer
  4. Penetration test results

Community Votes

C
58%
B
25%
A
17%

58% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your ability to bridge technical vulnerability data with executive decision-making, where the trap is choosing granular technical reports over holistic risk evaluation.

Building a security business case requires translating technical findings into business-aligned risk metrics. The CISM community consensus confirms that a comprehensive risk assessment provides the best input by quantifying threats, impacts, and priorities for decision-makers.

Many candidates select vulnerability scan results or penetration test results because they focus on technical details rather than recognizing that executives approve funding based on aggregated business risk exposure.

Community Discussion (5 comments)

koala_lay 👍 3 Selected: C
A risk assessment provides a comprehensive view of potential threats, vulnerabilities, and the associated impacts on the business. It helps prioritize risks and justifies the need for a technical solution by outlining the potential consequences of inaction. While the other options (BIA, vulnerability scan results, and penetration test results) provide valuable information, they are more focused on specific aspects rather than the overall risk profile, which is crucial for a business case.
oluchecpoint 👍 4 Selected: C
Risk assessment output
shootnot 👍 2
C- Business case is prepared by ISM and Risk Assessment is ISM's best approach, therefore, C.
yottabyte 👍 2 Selected: A
I would go with A here. The senior management would not require to see the vulnerability results, they would be more interested in how the business might get impacted if the vulnerabilities are exploited and what is the loss going to be. Vulnerability scan report on a business case is going to play light, however if we can show them how these vulnerabilities may affect the business, that will be playing hard.
3czz 👍 3 Selected: B
Vulnerability scan results

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A risk assessment synthesizes threat intelligence, vulnerability data, and business impact to calculate overall risk levels. This holistic view directly answers executive questions about cost-benefit trade-offs and strategic alignment, making it the ideal foundation for a business case. As noted in comment [1], it justifies the technical solution by outlining potential consequences of inaction.

Why the Other Options Are Wrong

A business impact analysis (Option A) identifies critical processes and recovery time objectives but does not evaluate vulnerability likelihood or threat landscapes. Vulnerability scans (Option B) and penetration tests (Option D) deliver raw technical metrics that lack business context and financial justification, which are mandatory for securing budget approval.

Community Comment Notes

Several users initially leaned toward Option A or B, arguing that leadership cares more about operational loss or technical proof. However, experienced candidates emphasize that risk assessments already incorporate impact data while adding likelihood and treatment options, bridging the gap between IT findings and board-level approvals (comments [1], [2], [4]).

Official Reference

Exam Strategy

Always filter CISM questions through an executive lens; funding requests must justify ROI, compliance, and risk reduction, not just technical fixes. When asked for business case inputs, prioritize documents that translate IT data into organizational impact and strategic alignment.

Frequently Asked Questions

Why isn't a BIA better for a security business case?

A BIA focuses on process criticality and recovery targets, not threat likelihood or vulnerability scoring. Risk assessments combine impact data with risk treatment options to justify funding.

Can penetration test results replace a risk assessment?

No. Pen tests provide technical exploit validation but lack business context, financial impact, and prioritization frameworks required for executive buy-in.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide