exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 918 discussion

Actual exam question from Isaca's CRISC
Question #: 918
Topic #: 1
[All CRISC Questions]

Which of the following is MOST important to the successful development of IT risk scenarios?

  • A. Control effectiveness assessment
  • B. Threat and vulnerability analysis
  • C. Internal and external audit reports
  • D. Cost-benefit analysis
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aselunar
Highly Voted 3 years, 1 month ago
R2-78 B is correct.
upvoted 5 times
...
Raj1510
Highly Voted 2 years, 6 months ago
Agree with B
upvoted 5 times
...
Staanlee
Most Recent 10 months, 2 weeks ago
Selected Answer: B
B. Threat and vulnerability analysis. Threat and vulnerability analysis is essential in understanding the potential risks that IT systems and assets face. By identifying and assessing threats (potential sources of harm) and vulnerabilities (weaknesses in the system that can be exploited), organizations can create realistic and relevant IT risk scenarios. These scenarios form the basis for risk assessments and help organizations prioritize their risk mitigation efforts effectively.
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: B
It is B, agreed. It is a shame the company does not go back and update answers once the entire community votes against them for years.
upvoted 1 times
...
Koulyo
1 year, 3 months ago
I agree with B and with the point made by Ceecil1959 and this is why i have no respect for ISACA
upvoted 1 times
CbtL
1 year, 3 months ago
Remember they are only pulling the questions, not the "correct" answers when they create these lists for us. The answers are guessed at in the same manner as someone taking the exam.
upvoted 1 times
...
...
john_boogieman
1 year, 5 months ago
Selected Answer: B
Agree.
upvoted 3 times
...
Suchib
1 year, 7 months ago
Its B. Threat and Vulnerability is part of risk scenario.
upvoted 2 times
...
BituBaba
1 year, 9 months ago
CBA is for Risk Response Selection , Correct answer should be B
upvoted 3 times
...
Ceecil1959
2 years, 4 months ago
B is correct: Who selects these answers for people to fail the exam?. The risk scenario should be based on an identified risk. A risk scenario is developed on the basis of potential threats to the business assets. A risk practitioner can identify potential threats from the risk register.
upvoted 4 times
...
Stefan07
3 years, 2 months ago
yes agreed B. CBA is good for risk response/treatment
upvoted 4 times
...
oguz_1523
3 years, 2 months ago
Should be B.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...