正解:D
Explanation
The most important outcome of effective risk treatment is the implementation of corrective actions that address the root causes of the risk and reduce its likelihood and/or impact to an acceptable level. Effective risk treatment does not necessarily eliminate the risk, but rather brings it within the organization's risk appetite and tolerance. Timely reporting of incidents and reduced cost of acquiring controls are desirable benefits of effective risk treatment, but they are not the primary outcome.
References: The CISM Review Manual 2023 defines risk treatment as "the process of selecting and implementing measures to modify risk" and states that "the objective of risk treatment is to implement corrective actions that will reduce the risk to a level that is acceptable to the enterprise" (p. 92). The CISM Review Questions, Answers & Explanations Manual 2023 also provides the following rationale for this answer: "Implementation of corrective actions is the correct answer because it is the most important outcome of effective risk treatment, as it ensures that the risk is managed in accordance with the organization's risk appetite and tolerance" (p. 28). Additionally, the Not All Risk Treatment Options Are the Same article from the ISACA Journal 2021 states that "risk treatment is the process of implementing corrective actions to address the root causes of the risk and to reduce the likelihood and/or impact of the risk" (p. 1)1.