🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control108 / 150
Question 108 of 150

A risk analyst is populating a qualitative risk register for a new customer-facing web application. For an entry describing 'exploitation of an unpatched authentication vulnerability,' the analyst must assign a likelihood rating and an impact rating. Which combination of factors should the analyst use as the primary basis for these two ratings, respectively?

Reviewed for accuracy · Report an issueNext question