exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 695 discussion

Actual exam question from Isaca's CRISC
Question #: 695
Topic #: 1
[All CRISC Questions]

Malware has recently affected an organization. The MOST effective way to resolve this situation and define a comprehensive risk treatment plan would be to perform:

  • A. a vulnerability assessment.
  • B. a root cause analysis.
  • C. an impact assessment.
  • D. a gap analysis.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aselunar
Highly Voted 2 years, 10 months ago
I think B is correct. See R2-106. Impact analysis will not directly help with mitigation for a specific security incident.
upvoted 5 times
...
SuperMax
Most Recent 5 months, 1 week ago
Selected Answer: B
B. a root cause analysis. When an organization is affected by malware, the most effective way to resolve the situation and define a comprehensive risk treatment plan is to perform a root cause analysis. This analysis aims to identify the underlying reasons or root causes that allowed the malware to infect the organization's systems in the first place. By understanding the root causes, the organization can take targeted actions to remediate the issues and prevent future malware infections. A root cause analysis may include identifying vulnerabilities, weaknesses in security controls, human errors, or other factors that contributed to the malware incident. Once these root causes are identified, appropriate measures can be taken to address them, such as patching vulnerabilities, improving security policies and procedures, enhancing employee training, and implementing technical controls.
upvoted 1 times
...
CbtL
1 year ago
Selected Answer: B
Agree it is B.
upvoted 1 times
...
john_boogieman
1 year, 2 months ago
Selected Answer: B
Agree.
upvoted 3 times
...
Hashi1_snr
1 year, 5 months ago
The given answer is correct. For comprehensive treatment plan to be developed you need to know the root cause of the problem so that you start the correction there. Knowing the impact without knowing the cause has potential for recurrence
upvoted 3 times
...
fora
1 year, 12 months ago
Selected Answer: B
B is a "model answer"
upvoted 3 times
...
tsangckl
2 years ago
impact assessment is to find out the impact and do in risk analysis. When the malware is already making effect. which means you are already know the impact. (You are under impact already). What you should do is, find out the root cause and resolve the problem. So B is correct.
upvoted 3 times
...
Raj1510
2 years, 2 months ago
I will go with B , Risk impact assessment require to be done but after risk analysis in this case RCA .
upvoted 4 times
...
MusMus
2 years, 3 months ago
Selected Answer: C
C makes more sense
upvoted 2 times
...
Josh93
3 years ago
Deff C
upvoted 2 times
...
Khy
3 years ago
should be C?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago