exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 408 discussion

Actual exam question from Isaca's CRISC
Question #: 408
Topic #: 1
[All CRISC Questions]

When reviewing management's IT control self-assessments, a risk practitioner noted an ineffective control that links to several low residual risk scenarios. What should be the NEXT course of action?

  • A. Propose mitigating controls
  • B. Assess management's risk tolerance
  • C. Recommend management accept the low risk scenarios
  • D. Re-evaluate the risk scenarios associated with the control
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
khushiag
Highly Voted 2 years, 10 months ago
Answer should be D. The control is ineffective and linked to multiple low risks so there is potential of ineffective control to increase the risk when aggregated. So reevaluation of risk seems like a best fit here.
upvoted 15 times
...
mraiyan
Most Recent 1 month, 1 week ago
Selected Answer: D
The question does not emphasize if the level of residual risk (even it is a low residual risk) is acceptable for the organization or not. If it is unacceptable, we would go with option "A". However, to know if the mentioned risks are acceptable or not (in order to take the decision); you have to reassess. Most times, in such questions, you have to evaluate then decide.
upvoted 1 times
...
pastor1
1 month, 1 week ago
Selected Answer: D
When a risk practitioner identifies an ineffective control that is linked to several low residual risk scenarios, it is important to re-evaluate the risk scenarios to ensure their accuracy and validity.
upvoted 1 times
...
CbtL
2 months, 1 week ago
Selected Answer: D
Agree with D.
upvoted 1 times
...
john_boogieman
4 months, 3 weeks ago
Selected Answer: D
Of course.
upvoted 2 times
...
Suchib
6 months, 2 weeks ago
Selected Answer: D
For low risk mitigation is not best option. Will go with D
upvoted 2 times
...
johnwalters
9 months, 4 weeks ago
D sounds best since the residual risk needs to be re-evaluated
upvoted 3 times
...
Odenkyem
2 years, 2 months ago
The emphasis is on "ineffective control that links to several low residual risk scenarios." Meaning the controls may not be providing the true picture of the risks, being false positive. I will go for "D"
upvoted 3 times
...
Rooks
2 years, 10 months ago
Why this answer is A where the risks are low? If the risks are low under the acceptable level then management just need to accept this risk or they might need to re-evaluate the scenarios so the answer would be either C of D. Thoughts???
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago