Big Cyber Monday Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Isaca Certified in Risk and Information Systems Control CRISC Question # 365 Topic 37 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 365 Topic 37 Discussion

CRISC Exam Topic 37 Question 365 Discussion:
Question #: 365
Topic #: 37

An organization's risk practitioner learns a new third-party system on the corporate network has introduced vulnerabilities that could compromise corporate IT systems. What should the risk practitioner do

FIRST?


A.

Confirm the vulnerabilities with the third party


B.

Identify procedures to mitigate the vulnerabilities.


C.

Notify information security management.


D.

Request IT to remove the system from the network.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.