exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 244 discussion

Actual exam question from Isaca's CCAK
Question #: 244
Topic #: 1
[All CCAK Questions]

While using Software as a Service (SaaS) to store secret customer information, an organization identifies a risk of disclosure to unauthorized parties. Although the SaaS service continues to be used, secret customer data is not processed. Which of the following risk treatment methods is being practiced?

  • A. Risk acceptance
  • B. Risk transfer
  • C. Risk mitigation
  • D. Risk reduction
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Auditor2020
5 days, 21 hours ago
Selected Answer: C
C. Risk mitigation The scenario describes a situation where the organization continues to use the SaaS service but avoids processing secret customer data to prevent disclosure to unauthorized parties. By not processing the sensitive data, the organization is reducing the potential impact of the risk. This approach aligns with risk mitigation, which involves taking steps to reduce either the likelihood or the impact of a risk to an acceptable level. In this case, the organization is mitigating the risk by altering its operations to avoid exposing sensitive data while still using the SaaS service for other purposes.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago