🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control17 / 150
Question 17 of 150

During a risk assessment, an analyst discovers that a critical database server was compromised despite having patch management, access controls, and network segmentation in place. Investigation reveals that the patch management tool had not successfully applied updates for six months because a service account had expired, and no one monitored the tool's job completion status. What should the analyst identify as the most significant control deficiency to document in the risk register?

Reviewed for accuracy · Report an issueNext question