Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CRISC topic 1 question 876 discussion

Actual exam question from Isaca's CRISC
Question #: 876
Topic #: 1
[All CRISC Questions]

Which of the following should be implemented to BEST mitigate the risk associated with infrastructure updates?

  • A. Change management audit
  • B. Change control process
  • C. Role-specific technical training
  • D. Risk assessment
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Ramye
Highly Voted 3 years ago
Answer should be B. Change control process Every chance/update including infrastructure update should / must follow the established change management process.
upvoted 6 times
Josh93
3 years ago
I agree.
upvoted 3 times
...
...
Stefan07
Highly Voted 2 years, 11 months ago
agreed the answer is B - the best control is Preventive, audit is a detective control, hence B is a better option
upvoted 5 times
...
CbtL
Most Recent 1 year ago
Selected Answer: B
It is B.
upvoted 1 times
...
Koulyo
1 year ago
i like D but its B. a significant update in Infra Stru. warrants a risk assessment as the risk profile might change, irrespective of existence of a Change Control Process
upvoted 1 times
...
john_boogieman
1 year, 2 months ago
Selected Answer: B
Agree 'B'.
upvoted 2 times
...
Ceecil1959
2 years ago
A change management audit is an independent appraisal that provides feedback to management regarding the design and operational effectiveness of the change management controls in place and helps to identify if any control design or operational weaknesses exist. Change Control is the process that management uses to identify, document, and authorize changes to an IT environment. It minimizes the likelihood of disruptions, unauthorized alterations and errors. The change control procedures should be designed with the size and complexity of the environment in mind.
upvoted 1 times
...
Ceecil1959
2 years, 1 month ago
The answer is total garbage. I mean, most of the answers given have no justification. How can an audit mitigate any risk associated with infrastructure update?. In order to do any update or change, a Change Control process is put in place, and approval has to be made.
upvoted 1 times
...
boyladdudeman
2 years, 1 month ago
B: Change control process
upvoted 2 times
...
Raj1510
2 years, 3 months ago
agree with B
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...