CISM Certified Information Security Manager – Question0300

When performing a qualitative risk analysis, which of the following will BEST produce reliable results?

A.
Estimated productivity losses
B. Possible scenarios with threats and impacts
C. Value of information assets
D. Vulnerability assessment

Correct Answer: B

Explanation:

Explanation:
Listing all possible scenarios that could occur, along with threats and impacts, will better frame the range of risks and facilitate a more informed discussion and decision. Estimated productivity losses, value of information assets and vulnerability assessments would not be sufficient on their own.