Isaca Certified in Risk and Information Systems Control CRISC Question # 190 Topic 20 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 190 Topic 20 Discussion

CRISC Exam Topic 20 Question 190 Discussion:
Question #: 190
Topic #: 20

An internal audit report reveals that not all IT application databases have encryption in place. Which of the following information would be MOST important for assessing the risk impact?


A.

The number of users who can access sensitive data


B.

A list of unencrypted databases which contain sensitive data


C.

The reason some databases have not been encrypted


D.

The cost required to enforce encryption


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.