exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 925 discussion

Actual exam question from Isaca's CRISC
Question #: 925
Topic #: 1
[All CRISC Questions]

Which of the following BEST protects an organization against breaches when using a software as a service (SaaS) application?

  • A. Security information and event management (SIEM) solutions
  • B. Control self-assessment (CSA)
  • C. Data privacy impact assessment (DPIA)
  • D. Data loss prevention (DLP) tools
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
c445ac5
2 months, 4 weeks ago
Selected Answer: A
Should be SIEM - D is incorrect
upvoted 1 times
...
Staanlee
7 months, 4 weeks ago
Selected Answer: D
D. Data loss prevention (DLP) tools. Data loss prevention tools are designed to monitor, detect, and prevent the unauthorized transfer or exposure of sensitive data. When using a SaaS application, sensitive organizational data is often stored and processed in the cloud, and DLP tools can help ensure that this data remains secure. These tools can identify and block attempts to share sensitive information outside of the organization or take other actions to protect against data breaches.
upvoted 1 times
...
CbtL
1 year ago
Selected Answer: D
Horrible question. Just horrible. I would have to go with the logic that DLP is protecting. You aren't going to be collecting a lot of logs from a SaaS solution. The other two assessments might help you understand the situation with the SaaS provider better, but are not protecting you.
upvoted 2 times
faed87a
1 month, 3 weeks ago
While collecting logs directly from a SaaS solution may not be feasible, it is also not an effective approach. Typically, SaaS providers do not grant access to their internal logs for independent analysis. Therefore, the key action is to ensure that the SaaS provider is utilizing a Security Information and Event Management (SIEM) solution and properly maintaining logs on their side. From your end, this ensures that log data is managed effectively without direct access to the SaaS provider's logs. Thus, the most appropriate answer in this case is DLP
upvoted 1 times
...
...
Koulyo
1 year, 1 month ago
D is best option in my opinion: D. Data loss prevention (DLP) tools are the best option for protecting an organization against breaches when using a software as a service (SaaS) application. DLP tools are designed to prevent sensitive data from leaving the organization's network, which can help prevent data breaches that could occur as a result of using a SaaS application. SIEM solutions, CSA, and DPIA are all useful tools in their own right, but they are not specifically designed to protect against SaaS-related breaches.
upvoted 2 times
...
Jco
1 year, 5 months ago
Answer is D: DLP. DLP can be implemented by the SaaS provider if required.
upvoted 2 times
...
Ceecil1959
2 years, 2 months ago
D is incorrect as SIEM protects or features threat detection. SIEM is the correct answer. A is right.
upvoted 1 times
Ceecil1959
2 years, 1 month ago
SIEM software collects and aggregates log and event data to help identify and track breaches. It is a powerful tool for security insights.
upvoted 2 times
...
...
Raj1510
2 years, 3 months ago
Agree with D
upvoted 2 times
...
aselunar
2 years, 11 months ago
Looks like D is correct
upvoted 2 times
...
aselunar
2 years, 11 months ago
SIEM is for aggregation. See R4-56.
upvoted 2 times
...
Stefan07
3 years ago
A is a better answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago