CRISC · Question #175
Which of the following is the PRIMARY reason for a risk practitioner to review an organization's IT asset inventory?
The correct answer is C. To understand vulnerabilities associated with the use of the assets. The primary reason for a risk practitioner to review an IT asset inventory is to understand the vulnerabilities associated with those assets.
Question
Which of the following is the PRIMARY reason for a risk practitioner to review an organization's IT asset inventory?
Options
- ATo plan for the replacement of assets at the end of their life cycles
- BTo assess requirements for reducing duplicate assets
- CTo understand vulnerabilities associated with the use of the assets
- DTo calculate mean time between failures (MTBF) for the assets
How the community answered
(27 responses)- B4% (1)
- C93% (25)
- D4% (1)
Why each option
The primary reason for a risk practitioner to review an IT asset inventory is to understand the vulnerabilities associated with those assets.
Planning for asset replacement is an IT operations function, not a primary risk management activity.
Reducing duplicate assets is an efficiency and cost-saving measure, not the primary focus of risk assessment.
An IT asset inventory provides a comprehensive list of all IT assets, allowing a risk practitioner to identify what needs protection, what specific vulnerabilities (e.g., outdated software, missing patches) might exist for each asset, and how these vulnerabilities could be exploited. This is fundamental for risk assessment and mitigation planning.
Calculating MTBF is for reliability engineering and capacity planning, not the core function of a risk practitioner reviewing inventory.
Concept tested: Asset inventory in risk management
Source: https://learn.microsoft.com/en-us/compliance/assurance/shared-responsibility-for-cloud-security#asset-management
Topics
Community Discussion
No community discussion yet for this question.