🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control18 / 150
Question 18 of 150
During a risk assessment of a payment processing application, a CRISC practitioner discovers that a mandated data encryption control is configured but has been failing silently for three months due to an expired certificate. Management asks how this finding should be reflected in the risk analysis. What is the MOST accurate way to characterize this situation?
Reviewed for accuracy · Report an issueNext question