Certified Information Security Manager CISM · Free Practice Question Easy

Question 100

Risk Appetite is best described as:
  • A A) The acceptable variations in achieving the organization's objectives.
  • B B) The maximum level of risk an organization can handle.
  • C C) The amount of risk an organization is willing to accept to achieve its objectives.
  • D D) The process of identifying and assessing risks.
Reveal correct answer

Correct answer: C

Explanation

Explanation: A) Incorrect because this is more aligned with the concept of risk tolerance, which involves acceptable deviations from the risk appetite. B) Incorrect as this defines risk capacity, not risk appetite. C) Correct because risk appetite is the total exposure an organization is willing to accept to reach its goals, reflecting its willingness to take on risk. D) Incorrect because this is a description of risk assessment, a component of risk management, not a definition of risk appetite.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need