Certified in Risk and Information Systems Control (CRISC) — Question 810
An organization's business process requires the verbal verification of personal information in an environment where other customers may overhear this information. Which of the following is the MOST significant risk?
Answer options
- A. The customer may view the process negatively.
- B. The information could be used for identity theft.
- C. The process could result in intellectual property theft.
- D. The process could result in compliance violations.
Correct answer: B
Explanation
The correct answer is B because overheard personal information can be exploited for identity theft, which poses a serious risk. The other options, while potential issues, do not directly relate to the immediate threat of personal information being misused by unauthorized individuals.