🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control129 / 150
Question 129 of 150

A financial services firm purchases a cyber-insurance policy to address the risk of a data breach affecting customer records. During a review, the risk practitioner notes that the policy covers direct financial losses but excludes regulatory fines, reputational damage, and the cost of mandatory customer notification. Which conclusion should the risk practitioner communicate to management about this risk response?

Reviewed for accuracy · Report an issueNext question