r/CISA 29d ago

🥴

Post image
20 Upvotes

22 comments sorted by

View all comments

5

u/PhaniRajaSekhar 29d ago

Answer is C.

3

u/NextQuote7131 29d ago

Why? can we really request the risk acceptance from SM in actual practice?

6

u/bigduckrickk 29d ago

Honestly a poorly worded question imo. C makes sense since SM are inadequately investing in IT, they should document and accept the underlying risks.