Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISA Exam - Topic 9 Question 18 Discussion

Which of the following is necessary for effective risk management in IT governance?
B) Risk evaluation is embedded in management processes.
A) Risk management strategy is approved by the audit committee
C) Local managers are solely responsible for risk evaluation
D) IT risk management is separate from corporate risk management

Isaca CISA Exam - Topic 9 Question 18 Discussion

Actual exam question for Isaca's CISA exam
Question #: 18
Topic #: 9
[All CISA Questions]

Which of the following is necessary for effective risk management in IT governance?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Paris
8 months ago
I’m not convinced that embedding risk evaluation is enough.
upvoted 0 times
...
Trina
9 months ago
D is a bad idea, IT risks should be part of the bigger picture.
upvoted 0 times
...
Fatima
9 months ago
Wait, are local managers really supposed to handle all the risk evaluation? Seems risky!
upvoted 0 times
...
Ciara
9 months ago
Totally agree, B is essential too!
upvoted 0 times
...
Odette
9 months ago
A solid risk management strategy needs approval from the audit committee.
upvoted 0 times
...
Oneida
9 months ago
I practiced a question similar to this, and I think integrating IT risk with corporate risk is crucial, so D seems wrong.
upvoted 0 times
...
Jesusa
9 months ago
I feel like local managers being solely responsible for risk evaluation, like in option C, isn't a good idea. It seems too risky to me.
upvoted 0 times
...
Berry
9 months ago
I'm not entirely sure, but I remember something about the audit committee needing to approve strategies. Could that be option A?
upvoted 0 times
...
Suzi
9 months ago
I think option B makes the most sense since risk evaluation should be part of the overall management processes, right?
upvoted 0 times
...
Eleonora
9 months ago
I'm a bit confused by this question. I know replication is important, but I'm not sure which user is specifically enabled for it. I'll have to make an educated guess on this one.
upvoted 0 times
...
Kenneth
9 months ago
Hmm, this looks like a tricky one. We need something that feels like a desktop app but also loads fast and is SEO-friendly.
upvoted 0 times
...
Jennifer
9 months ago
Hmm, I'm a bit unsure here. The question mentions both employee eligibility and specific purchased products, so I'm not sure if Accounts and Service Contracts fully cover both requirements.
upvoted 0 times
...
Kayleigh
10 months ago
Wait, I'm confused. Aren't battery and assault the same thing? How are they different in the context of security work? I better re-read the question carefully.
upvoted 0 times
...

Save Cancel