exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 1200 discussion

Actual exam question from Isaca's CRISC
Question #: 1200
Topic #: 1
[All CRISC Questions]

Which of the following is MOST important for an IT risk practitioner to update once risk mitigation action plans have been verified as completed?

  • A. Risk rating
  • B. Control inventory
  • C. Risk impact
  • D. Control ownership
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
trev0r
2 days, 18 hours ago
Selected Answer: A
A - The primary purpose of completing risk mitigation action plans is to reduce the level of risk to the organization
upvoted 1 times
...
CbtL
8 months, 1 week ago
Selected Answer: A
This is covered in the 7th edition of the review manual, pg 161 3.8.3 and pg 165 3.9.2. Pg 161 talks only about updating documentation related to the control. Pg 165 talks about after the control is deemed effective, update the risk register. If you think the question is making a point of omitting that the control has been evaluated as effective, then "control inventory" is the best answer. If you think it is about remembering to update the risk register then A seems the better answer. Horrible question :)
upvoted 3 times
...
Koulyo
9 months, 1 week ago
the successful implementation of the control will lower the risk rating. so its A IMO.
upvoted 1 times
...
john_boogieman
10 months, 2 weeks ago
Selected Answer: A
Correction, reason: The risk rating is a measure of the likelihood and impact of a risk occurring, and it takes into account both the probability and impact of the risk event. If the risk mitigation plan has successfully reduced either the probability, impact, or both, then updating the risk rating will capture the net effect of the mitigation plan.
upvoted 1 times
john_boogieman
10 months, 2 weeks ago
In the question it is not known what has reduced the mitigation and therefore the change in answer.
upvoted 1 times
...
...
john_boogieman
11 months, 1 week ago
Selected Answer: C
If the risks have been mitigated, "the most important" of the options presented is to update the impact, which will modify the rating.
upvoted 2 times
...
GRamos
1 year ago
control inventory should be updated once risk mitigation action plans have been verified as completed. A control inventory is a list of all the controls that an organization has in place to manage risk. It is important for the IT risk practitioner to update the control inventory once risk mitigation action plans have been verified as completed, as this helps to ensure that the inventory is accurate and up-to-date.
upvoted 1 times
...
GRamos
1 year ago
control inventory.
upvoted 1 times
...
skhalid
1 year, 1 month ago
changing the impact will change the rating automatically...
upvoted 1 times
...
blokey
1 year, 1 month ago
should be A
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...