ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While drafting the annual security assessment plan, you review the last two audit reports for a cloud-hosted ERP system and note that both cited unresolved weaknesses in database backup encryption. How should this recurring finding influence the scope and resourcing of the upcoming assessment?
Record the issue as an accepted residual risk and focus assessment resources on new control areas instead.
Defer testing of backup encryption until the next audit cycle to give system owners more remediation time.
Plan a dedicated follow-up test with additional sampling and interviews to verify that backup encryption controls are now properly implemented.
Exclude backup encryption from the assessment scope because it was already documented in prior audits.
Because the weakness has appeared in multiple past reports without being fully remediated, the assessor should expand the upcoming assessment's focus on that control. This means allocating extra time and resources-such as larger sample sizes, deeper technical testing, and targeted interviews-to verify that encryption of backups is finally implemented and operating effectively. Simply dropping the item from scope, delaying its review, or recording an acceptance without re-testing would contradict good audit practice and the requirement to confirm whether corrective actions have closed previously identified gaps.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is it important to allocate additional resources to unresolved findings in an assessment?
Open an interactive chat with Bash
What is the role of follow-up assessments in addressing unresolved audit findings?
Open an interactive chat with Bash
Why is dropping unresolved issues from scope or deferring testing considered bad audit practice?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .