exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 307 discussion

Actual exam question from Isaca's CRISC
Question #: 307
Topic #: 1
[All CRISC Questions]

What is the FIRST phase of IS monitoring and maintenance process?

  • A. Report result
  • B. Prioritizing risks
  • C. Implement monitoring
  • D. Identifying controls
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Following are the phases that are involved in Information system monitoring and maintenance:
✑ Prioritize risk: The first phase involves the prioritization of risk which in turn involves following task:
- Analyze and prioritize risks to organizational objectives.
- Identify the necessary application components and flow of information through the system.
- Examine and understand the functionality of the application by reviewing the application system documentation and interviewing appropriate personnel.
✑ Identify controls: After prioritizing risk now the controls are identified, and this involves following tasks:
- Key controls are identified across the internal control system that addresses the prioritized risk.
- Applications control strength is identified.
- Impact of the control weaknesses is being evaluated.
- Testing strategy is developed by analyzing the accumulated information.
✑ Identify information: Now the IS control information should be identified:
- Identify information that will persuasively indicate the operating effectiveness of the internal control system.
- Observe and test user performing procedures.
✑ Implement monitoring: Develop and implement cost-effective procedures to evaluate the persuasive information.
✑ Report results: After implementing monitoring process the results are being reported to relevant stakeholders.
Incorrect Answers:
A, C, D: These all phases occur in IS monitoring and maintenance process after prioritizing risks.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Joloms
1 month, 1 week ago
The correct answer is: D. Identifying controls Identifying controls is the initial phase in the Information Systems (IS) monitoring and maintenance process. This phase involves determining which controls need to be in place to protect information systems and ensure their integrity, confidentiality, and availability. Once controls are identified, they can be monitored and maintained effectively.
upvoted 1 times
...
Abbey2
6 months, 1 week ago
Selected Answer: D
The first phase of Information Security (IS) monitoring and maintenance process is: D. Identifying controls.
upvoted 1 times
...
Kennethlim79
7 months, 2 weeks ago
The correct answer is D. Identifying controls. IS monitoring and maintenance is an ongoing process that involves identifying, assessing, and mitigating risks to the organization's information systems. The first step in this process is to identify the controls that are currently in place to protect the organization's information systems. This includes identifying both technical and organizational controls. Once the current controls have been identified, they need to be assessed to determine their effectiveness in mitigating risks. This will involve evaluating the likelihood and impact of potential threats and vulnerabilities, as well as the effectiveness of the controls in preventing or detecting these threats and vulnerabilities. The results of the risk assessment will be used to prioritize risks and to identify the controls that need to be strengthened or implemented. The organization will then implement the necessary controls to mitigate the risks to an acceptable level.
upvoted 1 times
...
FZ88
2 years, 5 months ago
Selected Answer: C
Shouldbe C?
upvoted 2 times
...
kingsmann
3 years, 3 months ago
Prioritizing risks should be part of the risk assessment process, not in the monitoring process.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago