Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 515 discussion

Actual exam question from Isaca's CRISC
Question #: 515
Topic #: 1
[All CRISC Questions]

An organization's internal auditors have identified a new IT control deficiency in the organization's identity and access management (IAM) system. It is most important for the risk practitioner to:

  • A. perform a follow-up risk assessment to quantify the risk impact
  • B. verify that applicable risk owners understand the risk
  • C. implement compensating controls to address the deficiency
  • D. recommend replacement of the deficient system
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Dopy
1 month, 4 weeks ago
Selected Answer: A
there is a need to prove the findings
upvoted 1 times
...
01010100
1 year, 2 months ago
Selected Answer: B
B. verify that applicable risk owners understand the risk When a control deficiency is identified, the primary responsibility of the risk practitioner is to ensure that the relevant risk owners are aware of and understand the implications of the deficiency. Only with this understanding can the risk owners make informed decisions about whether to address the risk and how to do so. Once the risk is understood, other actions such as performing follow-up assessments, implementing compensating controls, or recommending system changes can be considered.
upvoted 1 times
...
mraiyan
1 year, 5 months ago
Selected Answer: C
Going with "C". Guys, we are focusing on the role of risk practitioner in Risk Management rather than How should the risk be mitigated. in similar questions here in ExamTopics, when a control is ineffective, we should look for alternative controls. If it is about the role of risk practitioner (that he/she does not implement controls) then "A" or "B". However, the word "quantify" in "A" is misleading.
upvoted 1 times
...
[Removed]
1 year, 6 months ago
Selected Answer: A
A, understand the impact
upvoted 1 times
...
Buzzkill_555
1 year, 6 months ago
Selected Answer: A
Would assume internal audit notified risk owner, so going with A
upvoted 1 times
King21
11 months, 1 week ago
That's why it says verify they understand the risk and its implications
upvoted 1 times
...
...
Koulyo
1 year, 7 months ago
Selected Answer: A
voting for A
upvoted 1 times
...
CbtL
1 year, 7 months ago
Selected Answer: B
I am caught between A and B. The question asks what is most important, and communicating the risk to the risk owners seems the most important. The risk assessment would come first, but does that make it most important?
upvoted 1 times
Koulyo
1 year, 7 months ago
R owners are already informed. B says understand.
upvoted 1 times
...
...
john_boogieman
1 year, 9 months ago
Selected Answer: U
Agree 'A'.
upvoted 1 times
...
cybervds
1 year, 10 months ago
Selected Answer: C
An organization's internal auditors have identified a new IT control deficiency in the organization's identity and access management (IAM) system. It is most important for the risk practitioner to: A. perform a follow-up risk assessment to quantify the risk impact -> this is the most important step because it underpins any action that will follow. B. verify that applicable risk owners understand the risk -> this is important but is an intermediary step between analyzing/understanding the risk and taking corrective action C. implement compensating controls to address the deficiency -> the risk practitioner does not implement controls D. recommend replacement of the deficient system -> we dont know at this time that replacing the deficient system is an appropriate response
upvoted 1 times
cybervds
1 year, 10 months ago
RIP me - I should have voted A
upvoted 1 times
...
...
Suchib
1 year, 11 months ago
Risk manager never implement control, need to do the risk assessment to identify the impact.
upvoted 1 times
...
Raj1510
2 years, 10 months ago
echo A
upvoted 3 times
...
aselunar
3 years, 5 months ago
Risk assessment needs to come before compensating controls are implemented. A is correct.
upvoted 1 times
ARAMiS
3 years, 5 months ago
Most important.. not what to do FIRST Answer is correct
upvoted 2 times
tsangckl
2 years, 7 months ago
is risk manger to implement the control? i dont think so. its not C
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...