exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 717 discussion

Actual exam question from Isaca's CISA
Question #: 717
Topic #: 1
[All CISA Questions]

During an audit of an organization's risk management practices, an IS auditor finds several documented IT risk acceptances have not been renewed in a timely manner after the assigned expiration date. When assessing the severity of this finding, which mitigating factor would MOST significantly minimize the associated impact?

  • A. There are documented compensating controls over the business processes.
  • B. The risk acceptances with issues reflect a small percentage of the total population.
  • C. The business environment has not significantly changed since the risk acceptances were approved.
  • D. The risk acceptances were previously reviewed and approved by appropriate senior management.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pLulu
3 months, 3 weeks ago
C. If the business environment remains largely unchanged, the risks identified and accepted previously are likely still relevant and the controls in place may still be effective. This stability reduces the urgency and potential impact of not renewing the risk acceptances on time.
upvoted 1 times
...
RS66
8 months ago
C. The business environment has not significantly changed since the risk acceptances were approved.
upvoted 2 times
...
a84n
10 months, 2 weeks ago
Selected Answer: D
Answer D Option D emphasizes that the risk acceptances were previously reviewed and approved by appropriate senior management. This suggests that the risks were assessed and accepted at a higher level of authority, providing a level of assurance that the risks were understood and acknowledged by the organization's leadership. Therefore, in this context, Option D represents a more significant mitigating factor.
upvoted 1 times
...
Jag127
2 years, 1 month ago
Selected Answer: C
You should check whether there are changes to the business environment then check whether the compensating controls are still effective.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago