CRISC · Question #48
Which of the following management action will MOST likely change the likelihood rating of a risk scenario related to remote network access?
The correct answer is A. Updating the organizational policy for remote access. Updating the organizational policy for remote access is the management action most likely to change the likelihood rating of a related risk scenario.
Question
Which of the following management action will MOST likely change the likelihood rating of a risk scenario related to remote network access?
Options
- AUpdating the organizational policy for remote access
- BCreating metrics to track remote connections
- CImplementing multi-factor authentication
- DUpdating remote desktop software
How the community answered
(27 responses)- A70% (19)
- B7% (2)
- C19% (5)
- D4% (1)
Why each option
Updating the organizational policy for remote access is the management action most likely to change the likelihood rating of a related risk scenario.
Updating the organizational policy for remote access directly influences the rules, procedures, and conditions under which remote access is granted and used, thereby changing user behavior and system configuration. This policy change can introduce stricter requirements, new access conditions, or a broader scope of allowable activities, directly impacting the probability (likelihood) of a risk event related to remote access occurring.
Creating metrics to track remote connections monitors activity but does not inherently change the probability of a risk event occurring.
Implementing multi-factor authentication is a technical control that primarily reduces the *impact* of unauthorized access (by making it harder to gain access), rather than broadly changing the fundamental *likelihood* of an attempt or exposure at a policy level.
Updating remote desktop software addresses specific technical vulnerabilities but does not broadly impact the overall likelihood rating as much as a comprehensive policy change governing access.
Concept tested: Risk likelihood factors via policy change
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.