nerdexam
Isaca

CRISC · Question #48

Which of the following management action will MOST likely change the likelihood rating of a risk scenario related to remote network access?

The correct answer is A. Updating the organizational policy for remote access. Updating the organizational policy for remote access is the management action most likely to change the likelihood rating of a related risk scenario.

Submitted by rania.sa· Apr 18, 2026Governance

Question

Which of the following management action will MOST likely change the likelihood rating of a risk scenario related to remote network access?

Options

  • AUpdating the organizational policy for remote access
  • BCreating metrics to track remote connections
  • CImplementing multi-factor authentication
  • DUpdating remote desktop software

How the community answered

(27 responses)
  • A
    70% (19)
  • B
    7% (2)
  • C
    19% (5)
  • D
    4% (1)

Why each option

Updating the organizational policy for remote access is the management action most likely to change the likelihood rating of a related risk scenario.

AUpdating the organizational policy for remote accessCorrect

Updating the organizational policy for remote access directly influences the rules, procedures, and conditions under which remote access is granted and used, thereby changing user behavior and system configuration. This policy change can introduce stricter requirements, new access conditions, or a broader scope of allowable activities, directly impacting the probability (likelihood) of a risk event related to remote access occurring.

BCreating metrics to track remote connections

Creating metrics to track remote connections monitors activity but does not inherently change the probability of a risk event occurring.

CImplementing multi-factor authentication

Implementing multi-factor authentication is a technical control that primarily reduces the *impact* of unauthorized access (by making it harder to gain access), rather than broadly changing the fundamental *likelihood* of an attempt or exposure at a policy level.

DUpdating remote desktop software

Updating remote desktop software addresses specific technical vulnerabilities but does not broadly impact the overall likelihood rating as much as a comprehensive policy change governing access.

Concept tested: Risk likelihood factors via policy change

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#Risk Likelihood#Management Actions#Organizational Policy#Risk Governance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice