CRISC · Question #632
Upon learning that the number of failed backup attempts continually exceeds the current risk threshold, the risk practitioner should:
The correct answer is A. initiate corrective action to address the known deficiency.. When the number of failed backup attempts consistently exceeds the established risk threshold, the risk practitioner must take immediate action to address this identified deficiency.
Question
Upon learning that the number of failed backup attempts continually exceeds the current risk threshold, the risk practitioner should:
Options
- Ainitiate corrective action to address the known deficiency.
- Badjust the risk threshold to better reflect actual performance.
- Cinquire about the status of any planned corrective actions.
- Dkeep monitoring the situation as there is evidence that this is normal.
How the community answered
(39 responses)- A79% (31)
- B8% (3)
- C10% (4)
- D3% (1)
Why each option
When the number of failed backup attempts consistently exceeds the established risk threshold, the risk practitioner must take immediate action to address this identified deficiency.
Exceeding a risk threshold signifies that an unacceptable level of risk has been realized or is imminent, indicating a known deficiency in controls or processes. The appropriate response is to initiate corrective action to bring the risk back within the acceptable threshold and prevent potential data loss or operational disruption due to backup failures.
Adjusting the risk threshold to match poor performance is a form of risk acceptance without remediation and undermines the purpose of risk management, rather than addressing the underlying issue.
Inquiring about planned corrective actions is insufficient; the situation requires active initiation of new or accelerated existing corrective actions due to the continuous threshold breach.
Monitoring the situation further is inappropriate when the risk threshold is continually exceeded, as it implies a critical control deficiency that requires immediate attention, not passive observation.
Concept tested: Risk response to threshold breaches
Topics
Community Discussion
No community discussion yet for this question.