exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 639 discussion

Actual exam question from Isaca's CRISC
Question #: 639
Topic #: 1
[All CRISC Questions]

An organization is planning to engage a cloud-based service provider for some of its data-intensive business processes. Which of the following is MOST important to help define the IT risk associated with this outsourcing activity?

  • A. Service level agreement
  • B. Right to audit the provider
  • C. Customer service reviews
  • D. Scope of services provided
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
eblue
10 months, 3 weeks ago
Selected Answer: B
the most important factor to consider when defining the IT risk associated with outsourcing data-intensive business processes to a cloud-based service provider is the right to audit the provider 1. This right allows the organization to assess the provider’s security controls and ensure that they meet the organization’s requirements. It also helps to ensure that the provider is complying with any relevant regulations and standards.
upvoted 1 times
...
Staanlee
11 months ago
Selected Answer: B
B. Right to audit the provider. When an organization plans to engage a cloud-based service provider for data-intensive business processes, having the right to audit the provider is crucial. This right allows the organization to assess the security and compliance measures of the provider, ensuring that they meet the organization's standards and regulatory requirements. It provides transparency into the provider's operations, data handling practices, and security controls. While other factors such as service level agreements (SLAs), customer service reviews, and the scope of services provided are important considerations, the right to audit is particularly critical for assessing and managing IT risks associated with outsourcing, especially when sensitive or critical data is involved. It helps the organization maintain control over its data and verify that the service provider is meeting its obligations.
upvoted 1 times
...
CbtL
1 year, 4 months ago
Selected Answer: D
It is D. The risk a third party represents to a company is predicated on the services the third party is providing. Right to audit allows you to identify how the third party is handling the risks they present to your organization.
upvoted 1 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: D
the scope of services provided would be more important to help define IT risk, as it outlines the specific responsibilities of the cloud-based service provider and the organization, including the types of data being processed and the methods for processing and protecting that data. Understanding the scope of services provided can help identify potential areas of risk and develop appropriate risk mitigation strategies.
upvoted 1 times
...
sleekygurl
1 year, 7 months ago
Option A is correct as SLA contains the scope of services between both parties and include other clauses such as right to audit, Information security clauses, performace metrics and service review.
upvoted 4 times
...
tsangckl
2 years, 4 months ago
remember in the contract. scope is define what the vendor do. SLA is define the performance agreed in both parties. let say, scope, vendor response the server preferences, SLA is server availability is 99.95%. to define risk, you will look into scope or SLA? for me SLA. given answer is correct.
upvoted 1 times
...
aselunar
3 years, 2 months ago
Also see R1-100.
upvoted 1 times
...
aselunar
3 years, 2 months ago
I agree with D. See R1-82. Not the same answer, but similar.
upvoted 4 times
...
Rooks
3 years, 11 months ago
The Answer could be D too as SLA would be defined based on scope of service.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...