exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 724 discussion

Actual exam question from Isaca's CRISC
Question #: 724
Topic #: 1
[All CRISC Questions]

An organization has completed a project to implement encryption on all databases that host customer data. Which of the following elements of the risk register should be updated to reflect this change?

  • A. Risk tolerance
  • B. Inherent risk
  • C. Risk appetite
  • D. Risk likelihood
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fora
Highly Voted 2 years, 2 months ago
Selected Answer: D
B is wrong - Inherent is the initial risk, it doesnt change after implementing controls. Residual does - but there is no such choice. In this case D would be the best one - as encryption reduces the probability of risk materialization...
upvoted 6 times
...
eblue
Most Recent 10 months, 3 weeks ago
Selected Answer: B
In this scenario, an organization has completed a project to implement encryption on all databases that host customer data. To reflect this change, the inherent risk element of the risk register should be updated
upvoted 1 times
...
Staanlee
11 months ago
Selected Answer: B
B. Inherent risk When an organization completes a project to implement encryption on all databases hosting customer data, it is effectively reducing the inherent risk associated with the exposure of customer data. Inherent risk refers to the level of risk that exists before any controls or mitigation measures are applied. By implementing encryption, the organization is reducing the inherent risk of unauthorized access or data breaches.
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: D
It is D. You only change inherent risk when you add or change activities / processes. And I am still stuck on the 723 before this one where the chart on pg 152 of the 7th review manual indicates that preventive controls reduce impact. Still picking D, and should probably change my answer on 723.
upvoted 2 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: B
Question with a little trick. A preventive control (such as encryption) reduces the impact, not the probability. I would choose the inherent risk, even knowing that this is not the best option (it exists regardless of the application of controls).
upvoted 1 times
...
Log4J
2 years, 4 months ago
Answer B appears best. Encryption project is completed so subsequent analysis should consider encryption as an existing control when assessing inherent risk. Furthermore, encryption is a preventive control and does not reduce the likelihood, hence D is not an option.
upvoted 2 times
...
tsangckl
2 years, 4 months ago
I pick D. Inherent risk is the total risk without any control. encryption is lower the risk of data explore to public. So it is risk likelihood.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...