IIA-CIA-Part1 Exam QuestionsBrowse all questions from this exam

IIA-CIA-Part1 Exam - Question 66


Which is the least effective form of risk management?

Show Answer
Correct Answer: BD

People-based preventive control is considered the least effective form of risk management because it relies heavily on human intervention and behavior, which are prone to error and inconsistency. Systems-based controls, both preventive and detective, are more effective because they are automated and less susceptible to human error. Even people-based detective controls, while also dependent on humans, are effective for identifying issues after they occur, unlike preventive methods.

Discussion

1 comment
Sign in to comment
Elvoo
Mar 8, 2024

Why D?