nerdexam
Isaca

CRISC · Question #502

Which of the following BEST enables an organization to address risk associated with technical complexity?

The correct answer is C. Aligning with a security architecture. Aligning with a security architecture provides a structured framework to manage and reduce risks arising from technical complexity. It ensures that security is designed into systems from the ground up, simplifying complex environments.

Submitted by fatema_kw· Apr 18, 2026Risk Response and Reporting

Question

Which of the following BEST enables an organization to address risk associated with technical complexity?

Options

  • ADocumenting system hardening requirements
  • BMinimizing dependency on technology
  • CAligning with a security architecture
  • DEstablishing configuration guidelines

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    13% (4)
  • C
    55% (17)
  • D
    26% (8)

Why each option

Aligning with a security architecture provides a structured framework to manage and reduce risks arising from technical complexity. It ensures that security is designed into systems from the ground up, simplifying complex environments.

ADocumenting system hardening requirements

Documenting system hardening requirements is a specific control activity but doesn't address the overall complexity of the technical landscape itself; it's a component of a broader security strategy.

BMinimizing dependency on technology

Minimizing dependency on technology is often impractical in modern organizations and is not a direct method for *addressing* risk associated with *existing* technical complexity.

CAligning with a security architectureCorrect

Aligning with a security architecture provides a standardized, holistic blueprint for designing and implementing secure systems across an organization. This structured approach helps reduce technical complexity by enforcing consistent security controls, design patterns, and principles, making systems more manageable, understandable, and less prone to vulnerabilities introduced by ad-hoc implementations.

DEstablishing configuration guidelines

Establishing configuration guidelines helps standardize settings for individual systems but does not inherently simplify or manage the *interconnections and overall architecture* that contribute to technical complexity.

Concept tested: Managing risk through security architecture

Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/overview

Topics

#Risk management#Technical complexity#Security architecture#Risk mitigation

Community Discussion

No community discussion yet for this question.

Full CRISC Practice