Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca IT Risk Fundamentals Exam - Topic 4 Question 33 Discussion

Which of the following is the MOST likely reason that a list of control deficiencies identified in a recent security assessment would be excluded from an IT risk register?
C) The deficiencies have already been resolved.
A) The deficiencies have no business relevance.
B) The deficiencies are actual misconfigurations.

Isaca IT Risk Fundamentals Exam - Topic 4 Question 33 Discussion

Actual exam question for Isaca's IT Risk Fundamentals exam
Question #: 33
Topic #: 4
[All IT Risk Fundamentals Questions]

Which of the following is the MOST likely reason that a list of control deficiencies identified in a recent security assessment would be excluded from an IT risk register?

Show Suggested Answer Hide Answer
Suggested Answer: C

The most likely reason to exclude control deficiencies from an IT risk register is that they have already been resolved. The risk register should focus on current risks that require attention or action.

While deficiencies with no business relevance (A) might be lower priority, they could still be relevant to the risk register. Actual misconfigurations (B) are definitely relevant and should be included.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel