nerdexam
Isaca

CRISC · Question #535

An organization's board of directors is concerned about recent data breaches in the news and wants to assess its exposure to similar scenarios. Which of the following is the BEST course of action?

The correct answer is A. Evaluate the organization's existing data protection controls.. To address board concerns about data breach exposure, the most effective first step is to evaluate the existing data protection controls to determine their effectiveness against potential threats.

Submitted by daniela_cl· Apr 18, 2026IT Risk Assessment

Question

An organization's board of directors is concerned about recent data breaches in the news and wants to assess its exposure to similar scenarios. Which of the following is the BEST course of action?

Options

  • AEvaluate the organization's existing data protection controls.
  • BReassess the risk appetite and tolerance levels of the business.
  • CEvaluate the sensitivity of data that the business needs to handle.
  • DReview the organization's data retention policy and regulatory requirements.

How the community answered

(43 responses)
  • A
    77% (33)
  • B
    2% (1)
  • C
    9% (4)
  • D
    12% (5)

Why each option

To address board concerns about data breach exposure, the most effective first step is to evaluate the existing data protection controls to determine their effectiveness against potential threats.

AEvaluate the organization's existing data protection controls.Correct

The board's concern stems from external data breaches, implying a need to understand the organization's own resilience. Evaluating existing data protection controls directly assesses how well the organization is currently protected against such breaches by reviewing the design and operational effectiveness of its security measures. This will provide a direct answer to their concern about exposure.

BReassess the risk appetite and tolerance levels of the business.

While risk appetite and tolerance are important for setting overall risk strategy, reassessing them doesn't directly evaluate the current effectiveness of defenses against data breaches.

CEvaluate the sensitivity of data that the business needs to handle.

Evaluating data sensitivity is a critical component of data classification and risk assessment, but it doesn't directly assess the effectiveness of controls against breaches, which is the immediate concern triggered by external events.

DReview the organization's data retention policy and regulatory requirements.

Reviewing data retention policies and regulatory requirements is important for compliance, but it focuses on data lifecycle and legal obligations rather than the immediate effectiveness of technical and administrative controls to prevent a breach.

Concept tested: Data breach exposure assessment

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/data-protection-overview

Topics

#Security Controls Evaluation#Data Breach Risk#Risk Exposure#IT Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CRISC Practice