Certified Information Systems Auditor CISA · Free Practice Question Medium
Question 34
A risk analysis that is carried out by an auditor is distinct and separate from the risk analysis that is performed as part of the IS risk management program in all of the following ways EXCEPT:
- A It has a unique perspective.
- B It identifies a high risk in an existing control.
- C It identifies a low risk in an existing control.
- D It is the focus of risk assessment.
Reveal correct answer
Correct answer: C
Explanation
Correct Answer:
It identifies a low risk in an existing control, is correct. A low risk with an existing control applied is likely to be treated similarly in either case.
Incorrect Answers:
All other answers are incorrect. These are ways that the risk analysis performed by an auditor is different from one performed by the IS risk management function.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
