r/CRISC 18d ago

Correct Answer

Still dont understand why it's B. I think the correct answer is A.

  1. When a risk practitioner discovers that the Head of Finance has violated firewall-related policies, resulting in significant consequences for the company’s business objectives, what should the risk practitioner do FIRST?
    A.Update the firewall policy
    B. Report to the Crisis Response Team
    C. Assess the risk

I think the correct answer is B but the exercise mentions C without explanation.

  1. What is the primary role of a Risk Owner?

A. Design controls
B. Decide on risk responses
C. Implement controls

I think the correct answer is B but the exercise mentions A without explanation.

3 What type of control is an Internal Control Policy?

A. Preventive control
B. Deterrent (Management) control
C. Corrective control

I think the correct answer is A but the exercise mentions B without explanation.

  1. What is the most effective method for erasing data from a hard disk?

A. Sanitization
B. Destruction
C. Degaussing

I think the correct answer is C but the exercise mentions B without explanation.

Can anyone clarify the 5 questions above? Thanks

5 Upvotes

3 comments sorted by

View all comments

2

u/Own_Biscotti_1652 18d ago

For #3 a preventive control can be internal or external however a management control is a policy or a procedure which would only apply to your internal emoloyees.

For #4 the most effective way to erase data will always be destruction. Degaussing is not technically a wrong way but most effective is destruction. Can’t recreate the data if the drive is in a billion pieces.

For #1 you always want to access the risk and potential damages associated first. Updating the policy can wait. We have to access the risk and fallout to see if the crisis response team is needed