exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 1058 discussion

Actual exam question from Isaca's CRISC
Question #: 1058
Topic #: 1
[All CRISC Questions]

Which of the following is a risk practitioner's BEST recommendation to address an organization's need to secure multiple systems with limited IT resources?

  • A. Perform a vulnerability analysis.
  • B. Schedule a penetration test.
  • C. Apply available security patches.
  • D. Conduct a business impact analysis (BIA).
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
trev0r
1 week, 2 days ago
Selected Answer: D
D - allow the organization to identify its most critical assets and then apply its limited resources effectively
upvoted 1 times
...
abhincarnation
11 months ago
Selected Answer: C
Applying available security patches is a crucial step in securing systems. It's a relatively straightforward action that can significantly enhance system security by addressing known vulnerabilities. This action doesn't require extensive resources and can be done in a targeted manner. While conducting a business impact analysis (BIA) is important for understanding the potential impact of security incidents, it might not directly address the need to secure systems with limited resources. A BIA focuses on understanding the potential consequences of various incidents rather than the immediate actions needed to secure systems.
upvoted 1 times
...
krishccie
11 months, 4 weeks ago
Selected Answer: D
BIA to prioritize and highlight loss to senior management and have them accept the risk of no resources
upvoted 1 times
...
CbtL
1 year, 2 months ago
Selected Answer: D
Going with D. In the BIA section of the 7th edition review manual it discusses that BIA lets you prioritize risk as a risk practitioner. Limited resources are applied to systems in order of criticality.
upvoted 2 times
...
Koulyo
1 year, 3 months ago
A. Perform a vulnerability analysis is a risk practitioner's BEST recommendation to address an organization's need to secure multiple systems with limited IT resources. A vulnerability analysis is an assessment of potential vulnerabilities within an organization's systems, and can help identify areas that require immediate attention. By performing a vulnerability analysis, an organization can prioritize its security efforts and focus on the most critical vulnerabilities first. This can help maximize the effectiveness of limited IT resources.
upvoted 1 times
...
Broesweelies
1 year, 3 months ago
Selected Answer: C
limited resources? Just install patches
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...