Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Isaca Certified in Risk and Information Systems Control CRISC Question # 374 Topic 38 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 374 Topic 38 Discussion

CRISC Exam Topic 38 Question 374 Discussion:
Question #: 374
Topic #: 38

An organization discovers significant vulnerabilities in a recently purchased commercial off-the-shelf software product which will not be corrected until the next release. Which of the following is the risk manager ' s BEST course of action?


A.

Review the risk of implementing versus postponing with stakeholders.


B.

Run vulnerability testing tools to independently verify the vulnerabilities.


C.

Review software license to determine the vendor ' s responsibility regarding vulnerabilities.


D.

Require the vendor to correct significant vulnerabilities prior to installation.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.