🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control130 / 150
Question 130 of 150

A risk analyst is building risk scenarios for a new cloud-based payroll platform. The analyst has drafted a scenario describing a threat actor exploiting a misconfigured storage bucket to exfiltrate employee salary data. Before adding this scenario to the risk register for analysis, what is the MOST important step the analyst should take?

Reviewed for accuracy · Report an issueNext question