🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control148 / 150
Question 148 of 150
During a risk assessment, a CRISC practitioner identifies that a legacy financial application cannot support multifactor authentication due to technical constraints. The vendor has confirmed no patch or upgrade is available for at least 18 months. Management refuses to decommission the system because it supports a critical revenue process. What should the practitioner recommend FIRST to address the identified control deficiency?
Reviewed for accuracy · Report an issueNext question