exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 732 discussion

Actual exam question from Isaca's CRISC
Question #: 732
Topic #: 1
[All CRISC Questions]

Which of the following will BEST quantify the risk associated with malicious users in an organization?

  • A. Business impact analysis
  • B. Threat risk assessment
  • C. Vulnerability assessment
  • D. Risk analysis
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
01010100
9 months, 2 weeks ago
Selected Answer: D
D. Risk analysis Risk analysis encompasses the process of identifying, evaluating, and quantifying risk. In the context of the question, risk analysis would consider both the likelihood of malicious users exploiting vulnerabilities and the impact on the organization if such an event occurred. This comprehensive approach helps in quantifying the risk associated with malicious users. Here's a brief overview of the other options: A. Business impact analysis (BIA) focuses on the potential consequences of an event that disrupts a business function. It's more about understanding the effect of disruptions, not specifically about malicious users. B. Threat risk assessment focuses on identifying and assessing threats (like malicious users) but might not fully quantify the risk since it doesn't always include vulnerability assessment or the potential business impact. C. Vulnerability assessment focuses on identifying, quantifying, and prioritizing vulnerabilities in a system. While it can identify weaknesses that malicious users might exploit, by itself, it doesn't quantify the risk related to malicious users.
upvoted 2 times
...
Staanlee
10 months, 2 weeks ago
Selected Answer: B
B. Threat risk assessment A threat risk assessment is the most appropriate method for quantifying the risk associated with malicious users in an organization. Threat risk assessments focus on evaluating the likelihood and potential impact of specific threats or threat actors, such as malicious users, on an organization's assets and operations.
upvoted 1 times
...
Koulyo
1 year, 3 months ago
isn't Risk analysis about prop times magnitude?
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: B
Malicious users are threat actors, so threat assessment to understand that threat.
upvoted 2 times
...
john_boogieman
1 year, 4 months ago
Selected Answer: B
Agree.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...