正解:B
Performing a risk assessment gives a holistic and objective understanding of the threats, vulnerabilities, and controls across the organization. It reveals actual risk exposures and the effectiveness of current controls, which directly reflect the organization's security posture.
"Risk assessments identify and evaluate risk and provide the basis for determining how those risks should be managed and mitigated."
- CISM Review Manual 15th Edition, Chapter 2: Risk Management, Section: Risk Assessment According to ISACA's CISM Practice Question Database, performing a risk assessment is prioritized over reviewing documents or conducting interviews because it offers direct insight into current exposures and control effectiveness.