🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control105 / 150
Question 105 of 150
A risk practitioner is reviewing the enterprise risk register during a quarterly cycle. Threat intelligence feeds indicate a sharp rise in a new ransomware variant that specifically targets the organization's unpatched VPN concentrators. The register already contains an entry for 'ransomware infection,' but its likelihood rating was set two years ago and has not been revisited. What should the practitioner do FIRST?
Reviewed for accuracy · Report an issueNext question