exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 728 discussion

Actual exam question from Isaca's CRISC
Question #: 728
Topic #: 1
[All CRISC Questions]

Which of the following is the MAIN reason for documenting the performance of controls?

  • A. Justifying return on investment
  • B. Demonstrating effective risk mitigation
  • C. Providing accurate risk reporting
  • D. Obtaining management sign-off
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Staanlee
10 months ago
Selected Answer: B
B. Demonstrating effective risk mitigation The main reason for documenting the performance of controls is to demonstrate their effectiveness in mitigating risks. By documenting control performance, an organization can provide evidence that it is taking proactive steps to manage and reduce risks effectively. This documentation is crucial for compliance, audit purposes, and ensuring that the controls are achieving their intended objectives. While justifying return on investment, providing accurate risk reporting, and obtaining management sign-off are all important aspects of risk management, they are secondary to the primary goal of demonstrating control effectiveness in mitigating risks.
upvoted 1 times
...
Koulyo
1 year, 2 months ago
so if the controls are not performing well, we don't document the results? I opt for A.
upvoted 1 times
...
CbtL
1 year, 2 months ago
Selected Answer: B
Agree with B. Showing the controls are effective.
upvoted 1 times
...
john_boogieman
1 year, 4 months ago
Selected Answer: B
But... The main reason for documenting the performance of controls is to demonstrate effective risk mitigation. By documenting the performance of controls, an organization can provide evidence that the controls have been implemented and are operating effectively. This evidence can be used to demonstrate to stakeholders, such as regulators and auditors, that the organization is effectively mitigating the risks that it faces.
upvoted 2 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: C
Used to report compliance to management, effective mitigation is demonstrated with key controls.
upvoted 1 times
...
SkipC
1 year, 7 months ago
I think C is the best answer.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...