Best Input for a Business Case Addressing System Vulnerabilities?
Which of the following would provide the BEST input to a business case for a technical solution to address potential system vulnerabilities?
Community Votes
58% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your ability to bridge technical vulnerability data with executive decision-making, where the trap is choosing granular technical reports over holistic risk evaluation.
Building a security business case requires translating technical findings into business-aligned risk metrics. The CISM community consensus confirms that a comprehensive risk assessment provides the best input by quantifying threats, impacts, and priorities for decision-makers.
Many candidates select vulnerability scan results or penetration test results because they focus on technical details rather than recognizing that executives approve funding based on aggregated business risk exposure.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A risk assessment synthesizes threat intelligence, vulnerability data, and business impact to calculate overall risk levels. This holistic view directly answers executive questions about cost-benefit trade-offs and strategic alignment, making it the ideal foundation for a business case. As noted in comment [1], it justifies the technical solution by outlining potential consequences of inaction.Why the Other Options Are Wrong
A business impact analysis (Option A) identifies critical processes and recovery time objectives but does not evaluate vulnerability likelihood or threat landscapes. Vulnerability scans (Option B) and penetration tests (Option D) deliver raw technical metrics that lack business context and financial justification, which are mandatory for securing budget approval.Community Comment Notes
Several users initially leaned toward Option A or B, arguing that leadership cares more about operational loss or technical proof. However, experienced candidates emphasize that risk assessments already incorporate impact data while adding likelihood and treatment options, bridging the gap between IT findings and board-level approvals (comments [1], [2], [4]).Official Reference
Exam Strategy
Always filter CISM questions through an executive lens; funding requests must justify ROI, compliance, and risk reduction, not just technical fixes. When asked for business case inputs, prioritize documents that translate IT data into organizational impact and strategic alignment.
Frequently Asked Questions
Why isn't a BIA better for a security business case?
A BIA focuses on process criticality and recovery targets, not threat likelihood or vulnerability scoring. Risk assessments combine impact data with risk treatment options to justify funding.
Can penetration test results replace a risk assessment?
No. Pen tests provide technical exploit validation but lack business context, financial impact, and prioritization frameworks required for executive buy-in.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →