exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 723 discussion

Actual exam question from Isaca's CRISC
Question #: 723
Topic #: 1
[All CRISC Questions]

A rule-based data loss prevention (DLP) tool has recently been implemented to reduce the risk of sensitive data leakage. Which of the following is MOST likely to change as a result of this implementation?

  • A. Risk velocity
  • B. Risk impact
  • C. Risk likelihood
  • D. Risk appetite
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hussmohsin
Highly Voted 2 years, 11 months ago
Risk impact when sensitive data is leaked will remain the same. The DLP will reduce the risk likelihood (Answer C). Any type of data that has a rule in the DLP will be protected.
upvoted 12 times
Ramye
2 years, 5 months ago
Not quite understand how the risk impact is same if the sensitive data is leaked. There could be huge impact if the sensitive data is leaked, say your company’s secret formula or your customers’ personal data.
upvoted 1 times
MusMus
2 years ago
because the impact if the sensitive data is leaked is the same, regardless of the reason (control bypass, control failure, ...). what the DLP is doing is just help prevent the leakage (probability/likelihood), but in the case the document gets leaked then, the impact is the same. unlike for example redacting a sensitive document. this control will reduce its sensitivity, and thus it's impact if it ever gets released.
upvoted 2 times
...
...
...
travdaman
Highly Voted 2 years, 11 months ago
Reducing risk impact is for corrective controls, ie- backup. DLP is considered as preventive control, and preventive controls reduces probability. Anyhow, I'm open for discussions.
upvoted 5 times
...
CbtL
Most Recent 9 months, 1 week ago
Selected Answer: B
I agree it is C from using logic, but from the diagram in the ISACA review manual 7th edition on page 152 it is clear that preventive reduces impact, deterrent reduces likelihood.
upvoted 1 times
CbtL
9 months, 1 week ago
The next question, 724, raises the same dilemma. Really seems like C is the answer, both from common sense / real world interactions AND Google searches that include both impact and likelihood reduction for preventive controls. Bless ISACA...
upvoted 1 times
...
...
john_boogieman
10 months, 4 weeks ago
Selected Answer: C
Well, correction, reason: The implementation of a rule-based data loss prevention (DLP) tool is likely to reduce the risk likelihood of sensitive data leakage. The purpose of the DLP tool is to prevent the unauthorized transmission of sensitive data outside the organization's network by applying rules to identify and block sensitive data from leaving the network. By preventing the unauthorized transmission of sensitive data, the tool can significantly reduce the likelihood of data leakage incidents occurring.
upvoted 1 times
...
john_boogieman
11 months, 1 week ago
Selected Answer: B
Curious answers. A DLP (Data loss 'prevention') system is a 'preventive' control (7th CRISC manual 'control types, standards and frameworks' section), and these types of controls by their nature reduce impact, not probability. For more information, controls capable of reducing probability are 'deterrents' or 'compensatory'.
upvoted 1 times
...
BituBaba
1 year, 3 months ago
Preventative Controls first reduce the likelihood , then impact.
upvoted 2 times
...
fora
1 year, 8 months ago
Selected Answer: C
Should be C
upvoted 1 times
...
Log4J
1 year, 9 months ago
CRISC Manual (7nth) p.152. Preventive controls reduces the impact. Agree with B.
upvoted 2 times
...
Raj1510
1 year, 12 months ago
Agree with C
upvoted 2 times
...
FZ88
2 years ago
Selected Answer: C
Should C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...