New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISA Exam - Topic 9 Question 18 Discussion

Actual exam question for Isaca's CISA exam
Question #: 18
Topic #: 9
[All CISA Questions]

Which of the following is necessary for effective risk management in IT governance?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Paris
4 months ago
I’m not convinced that embedding risk evaluation is enough.
upvoted 0 times
...
Trina
4 months ago
D is a bad idea, IT risks should be part of the bigger picture.
upvoted 0 times
...
Fatima
4 months ago
Wait, are local managers really supposed to handle all the risk evaluation? Seems risky!
upvoted 0 times
...
Ciara
4 months ago
Totally agree, B is essential too!
upvoted 0 times
...
Odette
5 months ago
A solid risk management strategy needs approval from the audit committee.
upvoted 0 times
...
Oneida
5 months ago
I practiced a question similar to this, and I think integrating IT risk with corporate risk is crucial, so D seems wrong.
upvoted 0 times
...
Jesusa
5 months ago
I feel like local managers being solely responsible for risk evaluation, like in option C, isn't a good idea. It seems too risky to me.
upvoted 0 times
...
Berry
5 months ago
I'm not entirely sure, but I remember something about the audit committee needing to approve strategies. Could that be option A?
upvoted 0 times
...
Suzi
5 months ago
I think option B makes the most sense since risk evaluation should be part of the overall management processes, right?
upvoted 0 times
...
Eleonora
5 months ago
I'm a bit confused by this question. I know replication is important, but I'm not sure which user is specifically enabled for it. I'll have to make an educated guess on this one.
upvoted 0 times
...
Kenneth
5 months ago
Hmm, this looks like a tricky one. We need something that feels like a desktop app but also loads fast and is SEO-friendly.
upvoted 0 times
...
Jennifer
5 months ago
Hmm, I'm a bit unsure here. The question mentions both employee eligibility and specific purchased products, so I'm not sure if Accounts and Service Contracts fully cover both requirements.
upvoted 0 times
...
Kayleigh
5 months ago
Wait, I'm confused. Aren't battery and assault the same thing? How are they different in the context of security work? I better re-read the question carefully.
upvoted 0 times
...

Save Cancel