exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 1007 discussion

Actual exam question from Isaca's CRISC
Question #: 1007
Topic #: 1
[All CRISC Questions]

Which of the following provides the MOST reliable information to ensure a newly acquired company has appropriate IT controls in place?

  • A. Vulnerability assessment
  • B. Information system audit
  • C. Penetration testing
  • D. IT risk assessment
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jennarink13
1 month ago
I think C. There's a question in the QAE similar to this. I forgot what specific number. But the explanation says that penetration test reflects real-life attack that's why it's a better test to determine whether controls in place are effective.
upvoted 1 times
...
CbtL
2 months, 2 weeks ago
Selected Answer: D
It is either B or D. The problem word is "appropriate". Audit says they have controls according to the audit criteria. Risk assessment says the following situations need to be addressed and includes evaluating the existing controls.
upvoted 1 times
...
Koulyo
3 months, 1 week ago
Telling you its B
upvoted 2 times
...
john_boogieman
4 months, 2 weeks ago
Selected Answer: B
Correction, reason: During an information system audit, auditors review and test the effectiveness of IT controls to ensure they are operating as intended and that they are adequate to manage the risks faced by the organization. This enables auditors to identify weaknesses in IT controls and provide recommendations to address any deficiencies. In contrast, an IT risk assessment may not provide the same level of detail or depth as an information system audit. IT risk assessments may only focus on high-level risks and may not provide a comprehensive assessment of an organization's IT controls.
upvoted 2 times
...
john_boogieman
4 months, 3 weeks ago
Selected Answer: D
To ensure a newly acquired company has appropriate IT controls in place, the MOST reliable information would be obtained through a comprehensive IT security assessment or audit.
upvoted 1 times
...
Suchib
6 months, 2 weeks ago
Thats right, but at a particular point of time through PT it can be better and quickly understod how prepared is the entity for an attack.
upvoted 1 times
...
johnwalters
9 months ago
Selected Answer: D
Risk assessment will cover more than pen test
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago