🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control79 / 150
Question 79 of 150

After implementing a new data loss prevention (DLP) solution, a risk analyst reassesses a data exfiltration scenario. The inherent risk was rated High. Following control implementation, the residual risk is rated Medium, but the organization's documented risk appetite for data exfiltration is Low. What should the risk analyst recommend as the MOST appropriate next step?

Reviewed for accuracy · Report an issueNext question