正解:D
The main goal of a cybersecurity risk assessment is to gain visibility into the organization's current security posture, identify vulnerabilities, evaluate threats, and understand the potential impact of various risks.
"Risk assessments provide an understanding of the organization's threat landscape, asset vulnerabilities, and residual risk exposure."
- CISM Review Manual 15th Edition, Chapter 2: Risk Assessment and Risk Identification* While assessments support reporting and compliance, their primary role is situational awareness.