exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 876 discussion

Actual exam question from Isaca's CRISC
Question #: 876
Topic #: 1
[All CRISC Questions]

Which of the following should be implemented to BEST mitigate the risk associated with infrastructure updates?

  • A. Change management audit
  • B. Change control process
  • C. Role-specific technical training
  • D. Risk assessment
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ramye
Highly Voted 2 years, 9 months ago
Answer should be B. Change control process Every chance/update including infrastructure update should / must follow the established change management process.
upvoted 6 times
Josh93
2 years, 8 months ago
I agree.
upvoted 3 times
...
...
Stefan07
Highly Voted 2 years, 8 months ago
agreed the answer is B - the best control is Preventive, audit is a detective control, hence B is a better option
upvoted 5 times
...
CbtL
Most Recent 8 months, 4 weeks ago
Selected Answer: B
It is B.
upvoted 1 times
...
Koulyo
9 months, 1 week ago
i like D but its B. a significant update in Infra Stru. warrants a risk assessment as the risk profile might change, irrespective of existence of a Change Control Process
upvoted 1 times
...
john_boogieman
10 months, 4 weeks ago
Selected Answer: B
Agree 'B'.
upvoted 2 times
...
Ceecil1959
1 year, 9 months ago
A change management audit is an independent appraisal that provides feedback to management regarding the design and operational effectiveness of the change management controls in place and helps to identify if any control design or operational weaknesses exist. Change Control is the process that management uses to identify, document, and authorize changes to an IT environment. It minimizes the likelihood of disruptions, unauthorized alterations and errors. The change control procedures should be designed with the size and complexity of the environment in mind.
upvoted 1 times
...
Ceecil1959
1 year, 9 months ago
The answer is total garbage. I mean, most of the answers given have no justification. How can an audit mitigate any risk associated with infrastructure update?. In order to do any update or change, a Change Control process is put in place, and approval has to be made.
upvoted 1 times
...
boyladdudeman
1 year, 10 months ago
B: Change control process
upvoted 2 times
...
Raj1510
1 year, 11 months ago
agree with B
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...