Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca AAIR Exam - Topic 1 Question 5 Discussion

Which risk treatment is MOST appropriate when an organization's AI system presents residual risk within tolerance and impacts non-critical functions?
A) Document a formal risk acceptance.
B) Recommend increasing the tolerance threshold.
C) Enhance monitoring to detect deviations
D) Implement periodic vulnerability scans.

Isaca AAIR Exam - Topic 1 Question 5 Discussion

Actual exam question for Isaca's AAIR exam
Question #: 5
Topic #: 1
[All AAIR Questions]

Which risk treatment is MOST appropriate when an organization's AI system presents residual risk within tolerance and impacts non-critical functions?

Show Suggested Answer Hide Answer
Suggested Answer: A

Risk treatment decisions are driven by two factors: whether the residual risk falls within or outside tolerance, and the criticality of the affected function. When both conditions---risk within tolerance AND non-critical function impact---are met, formal risk acceptance is the appropriate and proportionate treatment.

Why A is Correct: According to ISACA AAIR risk treatment guidance, documented formal risk acceptance is the appropriate response when residual risk is within defined tolerance for non-critical functions. Risk acceptance acknowledges the identified exposure, documents the organization's conscious decision to accept it, and establishes accountability for that decision. This proportionate response avoids over-investing in controls for risk that the organization has determined is acceptable.

Why B is Wrong: Recommending increases to tolerance thresholds is a governance manipulation rather than a risk treatment. Adjusting thresholds upward to accommodate risk does not address the risk; it merely reclassifies it as acceptable. This approach undermines risk governance integrity.

Why C is Wrong: Enhancing monitoring to detect deviations represents additional control investment that may be disproportionate for risk that is already within tolerance affecting non-critical functions. Enhanced monitoring is more appropriate when risk is near the tolerance boundary or when trends indicate potential future breach.

Why D is Wrong: Periodic vulnerability scanning is a security assurance activity that identifies technical weaknesses. It represents an ongoing control measure rather than the appropriate risk treatment decision for a residual risk that is already within tolerance.


Contribute your Thoughts:

0/2000 characters
Janet
1 day ago
Totally agree with A), it's a solid approach!
upvoted 0 times
...
Stephaine
6 days ago
D) Implement periodic vulnerability scans could be overkill here.
upvoted 0 times
...
Annmarie
11 days ago
Surprised that B) is even an option, why increase risk?
upvoted 0 times
...
Jose
17 days ago
I disagree, C) Enhance monitoring is better for non-critical functions.
upvoted 0 times
...
Bernardine
22 days ago
A) Document a formal risk acceptance seems logical.
upvoted 0 times
...
Delisa
27 days ago
I’m not confident about B; increasing the tolerance threshold seems risky. I feel like we should stick to what we know is manageable.
upvoted 0 times
...
Rebeca
1 month ago
I'm leaning towards option C, but what if the deviations are minor? Would that still justify enhancing monitoring?
upvoted 0 times
...
Bette
1 month ago
I remember a practice question where we had to choose between monitoring and vulnerability scans. I feel like enhancing monitoring could be more effective here.
upvoted 0 times
...
Fernanda
1 month ago
I think option A makes sense since the risk is within tolerance, but I'm not entirely sure if formal documentation is always necessary.
upvoted 0 times
...

Save Cancel