New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CGEIT Exam - Topic 8 Question 61 Discussion

Actual exam question for Isaca's CGEIT exam
Question #: 61
Topic #: 8
[All CGEIT Questions]

A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Desirae
3 months ago
Defining a risk mitigation strategy is key here. Let's not jump to conclusions!
upvoted 0 times
...
Margurite
3 months ago
Researching competitors seems pointless. We need to focus on our own security.
upvoted 0 times
...
Beatriz
4 months ago
Wait, are these headsets really that advanced? I had no idea!
upvoted 0 times
...
Ming
4 months ago
I think updating the policy is a must. Can't have random devices in the data center.
upvoted 0 times
...
Eleonore
4 months ago
Sounds like a security nightmare! Better assess the risks first.
upvoted 0 times
...
Lonny
4 months ago
Competitor usage might not be the best focus right now. We should really prioritize understanding the specific risks of this device first, right?
upvoted 0 times
...
Chanel
4 months ago
This reminds me of a practice question we did on risk management. I think defining a risk mitigation strategy could come after assessing the risks.
upvoted 0 times
...
Novella
5 months ago
I'm not entirely sure, but I think updating the acceptable use policy could be important too. It might help clarify what devices are allowed.
upvoted 0 times
...
Kristel
5 months ago
I remember discussing the importance of assessing risks before making any decisions about new technology. Option D seems like the right step to take first.
upvoted 0 times
...
Theodora
5 months ago
I'm a little confused by this question. I'm not sure if administrators can add things like reports or policies to organizational groups. I'll have to review my notes on administrative capabilities to answer this one confidently.
upvoted 0 times
...
Malcom
5 months ago
Designing a new system sounds great, but we need to understand the actual issues before jumping to solutions, right? I guess brainstorming is the way to go.
upvoted 0 times
...
Leonora
5 months ago
This looks like a straightforward SQL question. I'm pretty confident I can handle this - the key is to carefully read through the options and select the three that are true.
upvoted 0 times
...
Devorah
9 months ago
I bet the CIO is just jealous they didn't get the cool new hands-free device first. Maybe we should all petition for one!
upvoted 0 times
...
Jestine
9 months ago
Hmm, I wonder if the employee was just trying to play Candy Crush hands-free. Maybe we should buy them a stand for their phone instead of banning the device.
upvoted 0 times
Sherron
8 months ago
D) Assess the risk associated with the device.
upvoted 0 times
...
Raymon
8 months ago
Hmm, that could be a good compromise.
upvoted 0 times
...
Catarina
9 months ago
B) Update the acceptable use policy.
upvoted 0 times
...
Gerardo
9 months ago
A) Define a risk mitigation strategy.
upvoted 0 times
...
...
Donte
9 months ago
Research competitor usage? Really? I'd much rather focus on our own security than worry about what others are doing. Let's just handle our own house first.
upvoted 0 times
...
Pearline
10 months ago
I'd go with updating the acceptable use policy. It's the most proactive approach to address this new technology before it becomes a bigger issue.
upvoted 0 times
Valene
8 months ago
C) Research competitor usage of similar devices.
upvoted 0 times
...
Virgina
8 months ago
B) Update the acceptable use policy.
upvoted 0 times
...
Fairy
8 months ago
A) Define a risk mitigation strategy.
upvoted 0 times
...
...
Dierdre
10 months ago
Definitely need to assess the risk first before deciding on any action. Can't just jump to banning the device without understanding the potential vulnerabilities.
upvoted 0 times
Miesha
8 months ago
D) Assess the risk associated with the device.
upvoted 0 times
...
Janella
8 months ago
Definitely need to assess the risk first before deciding on any action. Can't just jump to banning the device without understanding the potential vulnerabilities.
upvoted 0 times
...
Muriel
8 months ago
B) Update the acceptable use policy.
upvoted 0 times
...
Dwight
8 months ago
A) Define a risk mitigation strategy.
upvoted 0 times
...
Paris
9 months ago
D) Assess the risk associated with the device.
upvoted 0 times
...
Dominga
9 months ago
Definitely need to assess the risk first before deciding on any action. Can't just jump to banning the device without understanding the potential vulnerabilities.
upvoted 0 times
...
Pilar
9 months ago
B) Update the acceptable use policy.
upvoted 0 times
...
Robt
9 months ago
D) Assess the risk associated with the device.
upvoted 0 times
...
Elza
9 months ago
Definitely, it's important to assess the risk before making any decisions.
upvoted 0 times
...
Pearline
10 months ago
A) Define a risk mitigation strategy.
upvoted 0 times
...
Giuseppe
10 months ago
A) Define a risk mitigation strategy.
upvoted 0 times
...
...
Vallie
10 months ago
Updating the acceptable use policy could also help address the CIO's concerns.
upvoted 0 times
...
Demetra
11 months ago
I agree with Dorthy. Assessing the risk associated with the device is crucial.
upvoted 0 times
...
Dorthy
11 months ago
I think we should define a risk mitigation strategy.
upvoted 0 times
...

Save Cancel