Certified in Risk and Information Systems Control (CRISC) — Question 270
When determining which control deficiencies are most significant, which of the following would provide the MOST useful information?
Answer options
- A. Exception handling policy
- B. Benchmarking assessments
- C. Vulnerability assessment results
- D. Risk analysis results
Correct answer: D
Explanation
Risk analysis results are crucial because they provide insights into potential impacts and likelihood of risks associated with control deficiencies. While vulnerability assessments and benchmarking can offer valuable data, they do not prioritize the significance of deficiencies as effectively as a comprehensive risk analysis does.