exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 849 discussion

Actual exam question from Isaca's CRISC
Question #: 849
Topic #: 1
[All CRISC Questions]

An organization has identified that terminated employee accounts are not disabled or deleted within the time required by corporate policy. Unsure of the reason, the organization has decided to monitor the situation for three months to obtain more information. As a result of this decision, the risk has been:

  • A. accepted.
  • B. transferred.
  • C. avoided.
  • D. mitigated.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CbtL
9 months ago
Selected Answer: A
They are putting up with it for a few months, that is risk acceptance for the interim. Selecting A.
upvoted 1 times
...
john_boogieman
11 months ago
Selected Answer: A
The risk has not been fully addressed by the organization's decision to monitor the situation for three months. While monitoring can provide valuable information about the issue, it does not by itself reduce or mitigate the risk of terminated employee accounts not being disabled or deleted in a timely manner. By not taking immediate action to address the risk, the organization continues to expose itself to the potential consequences of unsecured terminated employee accounts, such as unauthorized access to sensitive data, loss of intellectual property, or reputation damage.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...