Exam CRISC Topic 2 Question 1136 Discussion
Actual exam question for ISACA's CRISC exam
Question #: 1136
Topic #: 2
Question #: 1136
Topic #: 2
An organization that has been the subject of multiple social engineering attacks is developing a risk awareness
program. The PRIMARY goal of this program should be to:
program. The PRIMARY goal of this program should be to:
Suggested Answer: A Vote an answer
According to the CRISC Review Manual (Digital Version), the primary goal of a risk awareness program is to
reduce the risk to an acceptable level by increasing the knowledge and understanding of the risk among the
stakeholders. A risk awareness program should:
Educate the stakeholders about the sources, types and impacts of IT-related risks
Explain the roles and responsibilities of the stakeholders in the risk management process
Promote a risk-aware culture that supports the risk appetite and risk tolerance of the organization
Provide guidance and tools for identifying, assessing, responding and monitoring IT-related risks
Encourage the reporting and escalation of risk issues and incidents
Reinforce the benefits and value of effective risk management
References = CRISC Review Manual (Digital Version), Chapter 4: IT Risk Monitoring and Reporting,
Section 4.2: IT Risk Reporting, pp. 224-2251
reduce the risk to an acceptable level by increasing the knowledge and understanding of the risk among the
stakeholders. A risk awareness program should:
Educate the stakeholders about the sources, types and impacts of IT-related risks
Explain the roles and responsibilities of the stakeholders in the risk management process
Promote a risk-aware culture that supports the risk appetite and risk tolerance of the organization
Provide guidance and tools for identifying, assessing, responding and monitoring IT-related risks
Encourage the reporting and escalation of risk issues and incidents
Reinforce the benefits and value of effective risk management
References = CRISC Review Manual (Digital Version), Chapter 4: IT Risk Monitoring and Reporting,
Section 4.2: IT Risk Reporting, pp. 224-2251
by Moore at Sep 19, 2026, 04:16 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).