ExamQuestions.com

Register
Login
Certified in Risk and Information Systems Control Exam Questions

Isaca

Certified in Risk and Information Systems Control

254 / 500

Question 254:

You are the Risk Official in Bluewell Inc. You have detected much vulnerability during risk assessment process. What you should do next? 

Answer options:

A. Prioritize vulnerabilities for remediation solely based on impact.
B. Handle vulnerabilities as a risk, even though there is no threat.
C. Analyze the effectiveness of control on the vulnerabilities` basis.
D. Evaluate vulnerabilities for threat, impact, and cost of mitigation.