Certified Information Systems Auditor CISA · Free Practice Question Medium

Question 34

A risk analysis that is carried out by an auditor is distinct and separate from the risk analysis that is performed as part of the IS risk management program in all of the following ways EXCEPT:
  • A It has a unique perspective.
  • B It identifies a high risk in an existing control.
  • C It identifies a low risk in an existing control.
  • D It is the focus of risk assessment.
Reveal correct answer

Correct answer: C

Explanation

Correct Answer:

It identifies a low risk in an existing control, is correct. A low risk with an existing control applied is likely to be treated similarly in either case.

Incorrect Answers:

All other answers are incorrect. These are ways that the risk analysis performed by an auditor is different from one performed by the IS risk management function.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need