nerdexam
CompTIA

SY0-701 · Question #504

Which of the following should an internal auditor check for first when conducting an audit of the organization's risk management program?

The correct answer is A. Policies and procedures. When conducting an audit of an organization's risk management program, the internal auditor should first review the policies and procedures. These documents form the foundation of the risk management program by outlining the organization’s approach, goals, roles…

Submitted by satoshi_tk· Mar 6, 2026Security program management and oversight

Question

Which of the following should an internal auditor check for first when conducting an audit of the organization's risk management program?

Options

  • APolicies and procedures
  • BAsset management
  • CVulnerability assessment
  • DBusiness impact analysis

How the community answered

(24 responses)
  • A
    92% (22)
  • B
    4% (1)
  • C
    4% (1)

Explanation

When conducting an audit of an organization's risk management program, the internal auditor should first review the policies and procedures. These documents form the foundation of the risk management program by outlining the organization’s approach, goals, roles, responsibilities, and processes for managing risks.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice