Isaca Certified in Risk and Information Systems Control CRISC Question # 116 Topic 12 Discussion
CRISC Exam Topic 12 Question 116 Discussion:
Question #: 116
Topic #: 12
A risk practitioner learns of an urgent threat intelligence alert to patch a critical vulnerability identified in the organization ' s operating system. Which of the following should the risk practitioner do FIRST?
A.
Patch the operating system immediately
B.
Determine whether any active attacks are exploiting the vulnerability
C.
Invoke the organization ' s incident response plan
D.
Evaluate the threat in the context of the organization ' s IT environment
Before acting, the risk practitioner mustevaluate the threat in the organizational context. This includes checking system exposure, current mitigations, and potential business impact. Only then can an informed decision (such as patching or mitigation) be made.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit