Certified in Risk and Information Systems Control (CRISC) — Question 347
Which of the following controls BEST enables an organization to ensure a complete and accurate IT asset inventory?
Answer options
- A. Requesting an asset list from business owners
- B. Prohibiting the use of personal devices for business
- C. Performing network scanning for unknown devices
- D. Documenting asset configuration baselines
Correct answer: C
Explanation
The correct answer, C, is effective because network scanning can identify devices that are connected to the network, ensuring that all assets are accounted for. Options A and D may not capture all assets if not all owners or configurations are documented, while B restricts personal device use but does not directly contribute to asset inventory completeness.