exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 659 discussion

Actual exam question from Isaca's CRISC
Question #: 659
Topic #: 1
[All CRISC Questions]

Which of the following should be the PRIMARY input when designing IT controls?

  • A. Internal and external risk reports
  • B. Outcome of control self-assessments
  • C. Benchmark of industry standards
  • D. Recommendations from IT risk experts
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CbtL
9 months, 2 weeks ago
Selected Answer: A
Believe it is A.
upvoted 1 times
...
john_boogieman
11 months ago
Selected Answer: A
Review and correct, reason: Internal and external risk reports should be the primary input when designing IT controls. These reports help identify the potential risks that may affect the organization's IT environment and provide insight into the types of controls that can be implemented to mitigate those risks. Control self-assessments can also provide valuable information, but they are typically more focused on evaluating the effectiveness of existing controls rather than designing new controls.
upvoted 2 times
...
john_boogieman
11 months, 4 weeks ago
Selected Answer: B
When designing controls, the first step is to understand the current control environment, through mechanisms such as control self-testing.
upvoted 2 times
...
SkipC
1 year, 1 month ago
I think this should be D.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...