Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Isaca Certified in Risk and Information Systems Control CRISC Question # 386 Topic 39 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 386 Topic 39 Discussion

CRISC Exam Topic 39 Question 386 Discussion:
Question #: 386
Topic #: 39

An organization discovers significant vulnerabilities in a recently purchased commercial off-the-shelf software product which will not be corrected until the next release. Which of the following is the risk manager ' s BEST course of action?


A.

Review the risk of implementing versus postponing with stakeholders.


B.

Run vulnerability testing tools to independently verify the vulnerabilities.


C.

Review software license to determine the vendor ' s responsibility regarding vulnerabilities.


D.

Require the vendor to correct significant vulnerabilities prior to installation.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.