正解:A
In the Three Lines Model, the first line (operational management) owns and manages risk through daily operations.
Per ISACA:
"Operational management, as the first line of defense, is responsible for maintaining effective internal controls and executing risk management processes." Oversight is the second line's role; audits belong to the third line.
Hence, A is correct.
CRISC Reference: Domain 1 - IT Risk Governance, Topic: Three Lines of Defense Model.