exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 819 discussion

Actual exam question from Isaca's CRISC
Question #: 819
Topic #: 1
[All CRISC Questions]

An internal audit report reveals that not all IT application databases have encryption in place. Which of the following information would be MOST important for assessing the risk impact?

  • A. The reason some databases have not been encrypted.
  • B. A list of unencrypted databases which contain sensitive data.
  • C. The cost required to enforce encryption.
  • D. The number of users who can access sensitive data.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hussmohsin
Highly Voted 3 years, 5 months ago
So if you ask IT why is the database is not encrypted and they say because we don't have enough license for the encryption software .. how can you determine the impact using this piece of information? To assess the impact you should know the sensitive data that is not encrypted, so the answer is B
upvoted 6 times
...
Staanlee
Most Recent 10 months, 2 weeks ago
Selected Answer: B
B. A list of unencrypted databases which contain sensitive data. When assessing the risk impact of not having encryption in place for IT application databases, the most important information would be to identify which databases contain sensitive data and are currently unencrypted. This information helps in understanding the scope and magnitude of the risk. Knowing which specific databases are affected allows for a more targeted risk assessment and risk management efforts. It's crucial to focus on databases that store sensitive information as they pose a higher risk if not properly protected.
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: B
B it is.
upvoted 1 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: B
When assessing the risk impact of the lack of encryption in IT application databases, the most important information to consider would be the sensitivity and confidentiality of the data stored in those databases.
upvoted 2 times
...
Suchib
1 year, 6 months ago
Its B, the root cause has no relation with impact. For any incident the impact to be derived first.Rootcause is required to identify the resolution or risk treatment.
upvoted 2 times
...
Ceecil1959
2 years, 4 months ago
Not all databases have encryption. And that may also mean that not all those DB's have sensitive data for them to be encrypted. Most important for assessing the impact is knowing the reason why all were not encrypted.
upvoted 1 times
john_boogieman
1 year, 5 months ago
The context of the questions and the answers offered seem to be directed to the importance of knowing the sensitivity of the data preferably.
upvoted 1 times
...
...
Raj1510
2 years, 6 months ago
agree with B
upvoted 3 times
...
Josh93
3 years, 3 months ago
Answer is B
upvoted 3 times
...
Abhaythemagician
3 years, 4 months ago
So you are saying that if an application database has non sensitive data or public data, then it should be encrypted ? So understanding why it is not encrypted makes sense. The keyword is " most". Remember it's isaca's way of thinking not yours.
upvoted 1 times
...
Tsuresh
3 years, 5 months ago
The answer should be B.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...