List of questions
Related questions
Question 518 - CRISC discussion
An organization's risk practitioner learns a new third-party system on the corporate network has introduced vulnerabilities that could compromise corporate IT systems. What should the risk practitioner do
FIRST?
A.
Confirm the vulnerabilities with the third party
B.
Identify procedures to mitigate the vulnerabilities.
C.
Notify information security management.
D.
Request IT to remove the system from the network.
Your answer:
0 comments
Sorted by
Leave a comment first