Which of the following would be the BEST way for a risk practitioner to validate the effectiveness of a patching program? A. Conduct vulnerability scans. B. Review change control board documentation. C. Interview IT operations personnel. D. Conduct penetration testing. Suggested Answer: A This question is in CRISC exam For getting Risk and Information Systems Control Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by ISACA. The website does not contain actual questions and answers from ISACA's Certification Exams. Trademarks, certification & product names are used for reference only and belong to ISACA.
Please login or Register to submit your answer