nerdexam
Isaca

CRISC · Question #369

A risk practitioner discovers that an IT operations team manager bypassed web filtering controls by using a mobile device, in violation of the network security policy. Which of the following should…

The correct answer is A. Report the incident. Upon discovering that an IT operations team manager bypassed web filtering controls, violating network security policy, the risk practitioner's first action should be to report the incident.

Submitted by tarun92· Apr 18, 2026Risk Response and Reporting

Question

A risk practitioner discovers that an IT operations team manager bypassed web filtering controls by using a mobile device, in violation of the network security policy. Which of the following should the risk practitioner do FIRST?

Options

  • AReport the incident.
  • BPlan a security awareness session.
  • CAssess the new risk.
  • DUpdate the risk register.

How the community answered

(41 responses)
  • A
    78% (32)
  • B
    2% (1)
  • C
    12% (5)
  • D
    7% (3)

Why each option

Upon discovering that an IT operations team manager bypassed web filtering controls, violating network security policy, the risk practitioner's first action should be to report the incident.

AReport the incident.Correct

Bypassing web filtering controls in violation of policy constitutes a security incident, as it could expose the organization to threats and indicates a breakdown in control enforcement. The risk practitioner's first responsibility is to report this incident through the established incident management process to ensure it is properly investigated and handled.

BPlan a security awareness session.

Planning a security awareness session is a proactive measure for future prevention but does not address the immediate policy violation and potential security breach.

CAssess the new risk.

While assessing the potential new risk is important, it occurs after the incident has been reported and an initial investigation has identified the scope and nature of the bypass.

DUpdate the risk register.

Updating the risk register is a later step, possibly reflecting the control failure or new risk, but the immediate priority is to address the active policy violation as an incident.

Concept tested: Incident identification and reporting

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Management#Policy Violation#Risk Practitioner Responsibilities#Security Incident Reporting

Community Discussion

No community discussion yet for this question.

Full CRISC Practice