exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 1636 discussion

Actual exam question from Isaca's CRISC
Question #: 1636
Topic #: 1
[All CRISC Questions]

A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization's data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?

  • A. Request a policy exception from senior management.
  • B. Request an exception from the local regulatory agency.
  • C. Comply with the organizational policy.
  • D. Report the noncompliance to the local regulatory agency.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
King24
3 months, 2 weeks ago
Selected Answer: A
Requesting a policy exception from senior management is the best approach because it allows the organization to address the specific conflict between its data-handling policy and local privacy regulations while ensuring that senior leadership is aware of and approves the deviation from standard policies. This approach allows the organization to maintain compliance with local regulations without undermining its internal policies.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago