C. Expected frequency and potential impact.
An IT risk register is a dynamic tool used to document, assess, and manage IT-related risks. To keep it effective, you need to regularly update the information it contains. This includes reviewing and revising the expected frequency (likelihood) and potential impact (severity) of identified risks as new information becomes available or as the business environment changes.
I am guessing that D. Enterprise-wide IT risk assessment is not the correct answer because it's too specific. You don't need to do an enterprise-wide assessment to up date the risk registry. In addition, a risk registry can contain other things than "IT." That is why C is the better answer. (Note: I initially picked D as well.)
The answer could be D. Enterprise-wide IT risk assessment.
No sure the why C is the answer provided.
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.CRISC Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Staanlee
10 months, 2 weeks agoCbtL
1 year, 3 months agoCbtL
1 year, 3 months agoKoulyo
1 year, 3 months agojohn_boogieman
1 year, 5 months agoRaj1510
2 years, 6 months agoAnon530
3 years, 3 months agoRamye
3 years, 3 months ago