🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control5 / 150
Question 5 of 150

A risk practitioner is conducting a risk assessment for a customer-facing e-commerce platform. During the initial data-gathering phase, the practitioner discovers that the asset inventory used to scope the assessment only lists production servers and databases, but omits the CI/CD pipeline, cloud storage buckets holding customer data, and third-party payment integration components. What is the GREATEST concern this poses to the validity of the risk assessment?

Reviewed for accuracy · Report an issueNext question