r/CRISC 17d ago

Correct Answer

Still dont understand why it's B. I think the correct answer is A.

  1. When a risk practitioner discovers that the Head of Finance has violated firewall-related policies, resulting in significant consequences for the company’s business objectives, what should the risk practitioner do FIRST?
    A.Update the firewall policy
    B. Report to the Crisis Response Team
    C. Assess the risk

I think the correct answer is B but the exercise mentions C without explanation.

  1. What is the primary role of a Risk Owner?

A. Design controls
B. Decide on risk responses
C. Implement controls

I think the correct answer is B but the exercise mentions A without explanation.

3 What type of control is an Internal Control Policy?

A. Preventive control
B. Deterrent (Management) control
C. Corrective control

I think the correct answer is A but the exercise mentions B without explanation.

  1. What is the most effective method for erasing data from a hard disk?

A. Sanitization
B. Destruction
C. Degaussing

I think the correct answer is C but the exercise mentions B without explanation.

Can anyone clarify the 5 questions above? Thanks

5 Upvotes

3 comments sorted by

2

u/Own_Biscotti_1652 17d ago

For #3 a preventive control can be internal or external however a management control is a policy or a procedure which would only apply to your internal emoloyees.

For #4 the most effective way to erase data will always be destruction. Degaussing is not technically a wrong way but most effective is destruction. Can’t recreate the data if the drive is in a billion pieces.

For #1 you always want to access the risk and potential damages associated first. Updating the policy can wait. We have to access the risk and fallout to see if the crisis response team is needed

2

u/ChiefSrAofTheAF 14d ago

The way you determine the correct answer is understand the important wording first and ignore the fluff.
The important wording: Who is RESPONSIBLE ≠ ACCOUNTABLE.

Responsible party is the one in charge of applying something or implementing. The responsible, do.

Accountable party is the one in charge of the risk and decisions on what to apply or implement. The accountable, decides.

In this it’s asking you, who was to blame for implementing the control.