Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 1 out of 12 pages
Viewing questions 1-50 out of questions
Questions # 1:

Which of the following risk impacts should be the PRIMARY consideration for determining recovery priorities in a disaster recovery situation?

Options:

A.

Data security


B.

Recovery costs


C.

Business disruption


D.

Recovery resource availability


Expert Solution
Questions # 2:

Which of the following is MOST likely to be impacted as a result of a new policy which allows staff members to remotely connect to the organization ' s IT systems via personal or public computers?

Options:

A.

Risk appetite


B.

Inherent risk


C.

Key risk indicator (KRI)


D.

Risk tolerance


Expert Solution
Questions # 3:

The PRIMARY benefit of classifying information assets is that it helps to:

Options:

A.

communicate risk to senior management


B.

assign risk ownership


C.

facilitate internal audit


D.

determine the appropriate level of control


Expert Solution
Questions # 4:

Which of the following is the MOST important outcome of a business impact analysis (BIA)?

Options:

A.

Understanding and prioritization of critical processes


B.

Completion of the business continuity plan (BCP)


C.

Identification of regulatory consequences


D.

Reduction of security and business continuity threats


Expert Solution
Questions # 5:

Which of the following is MOST important for a multinational organization to consider when developing its security policies and standards?

Options:

A.

Regional competitors ' policies and standards


B.

Ability to monitor and enforce compliance


C.

Industry-standard templates


D.

Differences in regulatory requirements


Expert Solution
Questions # 6:

During a risk assessment, the risk practitioner finds a new risk scenario without controls has been entered into the risk register. Which of the following is the MOST appropriate action?

Options:

A.

Include the new risk scenario in the current risk assessment.


B.

Postpone the risk assessment until controls are identified.


C.

Request the risk scenario be removed from the register.


D.

Exclude the new risk scenario from the current risk assessment


Expert Solution
Questions # 7:

An organization is participating in an industry benchmarking study that involves providing customer transaction records for analysis Which of the following is the MOST important control to ensure the privacy of customer information?

Options:

A.

Nondisclosure agreements (NDAs)


B.

Data anonymization


C.

Data cleansing


D.

Data encryption


Expert Solution
Questions # 8:

Which of the following is MOST important for a risk practitioner to update when a software upgrade renders an existing key control ineffective?

Options:

A.

Audit engagement letter


B.

Risk profile


C.

IT risk register


D.

Change control documentation


Expert Solution
Questions # 9:

Which of the following tools is MOST effective in identifying trends in the IT risk profile?

Options:

A.

Risk self-assessment


B.

Risk register


C.

Risk dashboard


D.

Risk map


Expert Solution
Questions # 10:

Which of the following is the BEST way to estimate the impact of an inherent risk over the next year?

Options:

A.

Obtain input from organizational risk stakeholders.


B.

Leverage industry threat intelligence reports.


C.

Model and simulate historical impact.


D.

Review industry and emerging risk trends.


Expert Solution
Questions # 11:

Which of the following is MOST helpful in reducing the likelihood of inaccurate risk assessment results?

Options:

A.

Involving relevant stakeholders in the risk assessment process


B.

Updating organizational risk tolerance levels


C.

Reviewing the applicable risk assessment methodologies


D.

Having internal audit validate control effectiveness


Expert Solution
Questions # 12:

Which of the following is the MAIN benefit to an organization using key risk indicators (KRIs)?

Options:

A.

KRIs assist in the preparation of the organization ' s risk profile.


B.

KRIs signal that a change in the control environment has occurred.


C.

KRIs provide a basis to set the risk appetite for an organization


D.

KRIs provide an early warning that a risk threshold is about to be reached.


Expert Solution
Questions # 13:

Which of the following controls are BEST strengthened by a clear organizational code of ethics?

Options:

A.

Detective controls


B.

Administrative controls


C.

Technical controls


D.

Preventive controls


Expert Solution
Questions # 14:

A financial institution has identified high risk of fraud in several business applications. Which of the following controls will BEST help reduce the risk of fraudulent internal transactions?

Options:

A.

Periodic user privileges review


B.

Log monitoring


C.

Periodic internal audits


D.

Segregation of duties


Expert Solution
Questions # 15:

Which of the following is the MOST important topic to cover in a risk awareness training program for all staff?

Options:

A.

Internal and external information security incidents


B.

The risk department ' s roles and responsibilities


C.

Policy compliance requirements and exceptions process


D.

The organization ' s information security risk profile


Expert Solution
Questions # 16:

Which of the following facilitates a completely independent review of test results for evaluating control effectiveness?

Options:

A.

Segregation of duties


B.

Three lines of defense


C.

Compliance review


D.

Quality assurance review


Expert Solution
Questions # 17:

After mapping generic risk scenarios to organizational security policies, the NEXT course of action should be to:

Options:

A.

record risk scenarios in the risk register for analysis.


B.

validate the risk scenarios for business applicability.


C.

reduce the number of risk scenarios to a manageable set.


D.

perform a risk analysis on the risk scenarios.


Expert Solution
Questions # 18:

What can be determined from the risk scenario chart?

Question # 18

Options:

A.

Relative positions on the risk map


B.

Risk treatment options


C.

Capability of enterprise to implement


D.

The multiple risk factors addressed by a chosen response


Expert Solution
Questions # 19:

The BEST key performance indicator (KPI) to measure the effectiveness of a vendor risk management program is the percentage of:

Options:

A.

vendors providing risk assessments on time.


B.

vendor contracts reviewed in the past year.


C.

vendor risk mitigation action items completed on time.


D.

vendors that have reported control-related incidents.


Expert Solution
Questions # 20:

Which of the following occurs during the implementation phase of the system development life cycle (SDLC)?

Options:

A.

Evaluation of updated coding into production


B.

Collaboration with stakeholders to gather system requirements


C.

Development of architectural designs based on system requirements


D.

Formal authorization for deploying the system into production


Expert Solution
Questions # 21:

Winch of the following can be concluded by analyzing the latest vulnerability report for the it infrastructure?

Options:

A.

Likelihood of a threat


B.

Impact of technology risk


C.

Impact of operational risk


D.

Control weakness


Expert Solution
Questions # 22:

When developing a business continuity plan (BCP), it is MOST important to:

Options:

A.

identify an alternative location to host operations.


B.

identify a geographically dispersed disaster recovery site.


C.

prioritize critical services to be restored.


D.

develop a multi-channel communication plan.


Expert Solution
Questions # 23:

An organization has introduced risk ownership to establish clear accountability for each process. To ensure effective risk ownership, it is MOST important that:

Options:

A.

senior management has oversight of the process.


B.

process ownership aligns with IT system ownership.


C.

segregation of duties exists between risk and process owners.


D.

risk owners have decision-making authority.


Expert Solution
Questions # 24:

Which of the following is the BEST indication of an enhanced risk-aware culture?

Options:

A.

Users have read and agreed to comply with security policies.


B.

Risk issues are openly discussed within the organization.


C.

Scores have improved on risk awareness quizzes.


D.

There is a decrease in the number of reported incidents.


Expert Solution
Questions # 25:

During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?

Options:

A.

Escalate the non-cooperation to management


B.

Exclude applicable controls from the assessment.


C.

Review the supplier ' s contractual obligations.


D.

Request risk acceptance from the business process owner.


Expert Solution
Questions # 26:

For no apparent reason, the time required to complete daily processing for a legacy application is approaching a risk threshold. Which of the following activities should be performed FIRST?

Options:

A.

Temporarily increase the risk threshold.


B.

Suspend processing to investigate the problem.


C.

Initiate a feasibility study for a new application.


D.

Conduct a root-cause analysis.


Expert Solution
Questions # 27:

Which of the following is the GREATEST concern related to the monitoring of key risk indicators (KRIs)?

Options:

A.

Logs are retained for longer than required.


B.

Logs are reviewed annually.


C.

Logs are stored in a multi-tenant cloud environment.


D.

Logs are modified before analysis is conducted.


Expert Solution
Questions # 28:

Which of the following groups represents the first line of defense?

Options:

A.

Internal audit


B.

Compliance committee


C.

External audit


D.

Operational managers


Expert Solution
Questions # 29:

Which of the following would BEST support the integrity of online financial transactions?

Options:

A.

Developing an integrated audit facility


B.

Implementing audit trail logs


C.

Deploying multi-factor authentication (MFA)


D.

Implementing blockchain technology


Expert Solution
Questions # 30:

Which of the following presents the GREATEST risk to change control in business application development over the complete life cycle?

Options:

A.

Emphasis on multiple application testing cycles


B.

Lack of an integrated development environment (IDE) tool


C.

Introduction of requirements that have not been approved


D.

Bypassing quality requirements before go-live


Expert Solution
Questions # 31:

Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?

Options:

A.

Accountability may not be clearly defined.


B.

Risk ratings may be inconsistently applied.


C.

Different risk taxonomies may be used.


D.

Mitigation efforts may be duplicated.


Expert Solution
Questions # 32:

A highly regulated enterprise is developing a new risk management plan to specifically address legal and regulatory risk scenarios What should be done FIRST by IT governance to support this effort?

Options:

A.

Request a regulatory risk reporting methodology


B.

Require critical success factors (CSFs) for IT risks.


C.

Establish IT-specific compliance objectives


D.

Communicate IT key risk indicators (KRIs) and triggers


Expert Solution
Questions # 33:

When assessing the maturity level of an organization ' s risk management framework, which of the following deficiencies should be of GREATEST concern to a risk practitioner?

Options:

A.

Unclear organizational risk appetite


B.

Lack of senior management participation


C.

Use of highly customized control frameworks


D.

Reliance on qualitative analysis methods


Expert Solution
Questions # 34:

A company has located its computer center on a moderate earthquake fault. Which of the following is the MOST important consideration when establishing a contingency plan and an alternate processing site?

Options:

A.

The alternative site is a hot site with equipment ready to resume processing immediately.


B.

The contingency plan provides for backup media to be taken to the alternative site.


C.

The contingency plan for high priority applications does not involve a shared cold site.


D.

The alternative site does not reside on the same fault to matter how the distance apart.


Expert Solution
Questions # 35:

Which of the following is the MOST important consideration when determining the appropriate data retention period throughout the data management life cycle?

Options:

A.

Data storage and collection methods


B.

Data owner preferences


C.

Legal and regulatory requirements


D.

Choice of encryption algorithms


Expert Solution
Questions # 36:

Which of the following represents a vulnerability?

Options:

A.

An identity thief seeking to acquire personal financial data from an organization


B.

Media recognition of an organization ' s market leadership in its industry


C.

A standard procedure for applying software patches two weeks after release


D.

An employee recently fired for insubordination


Expert Solution
Questions # 37:

Which of the following is the PRIMARY responsibility of the first line of defense related to computer-enabled fraud?

Options:

A.

Providing oversight of risk management processes


B.

Implementing processes to detect and deter fraud


C.

Ensuring that risk and control assessments consider fraud


D.

Monitoring the results of actions taken to mitigate fraud


Expert Solution
Questions # 38:

Winch of the following key control indicators (KCIs) BEST indicates whether security requirements are identified and managed throughout a project He cycle?

Options:

A.

Number of projects going live without a security review


B.

Number of employees completing project-specific security training


C.

Number of security projects started in core departments


D.

Number of security-related status reports submitted by project managers


Expert Solution
Questions # 39:

A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner ' s NEXT step?

Options:

A.

Develop a mechanism for monitoring residual risk.


B.

Update the risk register with the results.


C.

Prepare a business case for the response options.


D.

Identify resources for implementing responses.


Expert Solution
Questions # 40:

To reduce costs, an organization is combining the second and third tines of defense in a new department that reports to a recently appointed C-level executive. Which of the following is the GREATEST concern with this situation?

Options:

A.

The risk governance approach of the second and third lines of defense may differ.


B.

The independence of the internal third line of defense may be compromised.


C.

Cost reductions may negatively impact the productivity of other departments.


D.

The new structure is not aligned to the organization ' s internal control framework.


Expert Solution
Questions # 41:

Which of the following BEST balances the costs and benefits of managing IT risk*?

Options:

A.

Prioritizing and addressing risk in line with risk appetite. Eliminating risk through preventive and detective controls


B.

Considering risk that can be shared with a third party


C.

Evaluating the probability and impact of risk scenarios


Expert Solution
Questions # 42:
Options:

A.

Implement a new risk assessment process.


B.

Revalidate the corporate risk appetite.


C.

Review and adjust key risk indicators (KRIs).


D.

Communicate the new risk profile.


Expert Solution
Questions # 43:

Which of the following is the MOST reliable validation of a new control?

Options:

A.

Approval of the control by senior management


B.

Complete and accurate documentation of control objectives


C.

Control owner attestation of control effectiveness


D.

Internal audit review of control design


Expert Solution
Questions # 44:

Which of the following is MOST important for maintaining the effectiveness of an IT risk register?

Options:

A.

Removing entries from the register after the risk has been treated


B.

Recording and tracking the status of risk response plans within the register


C.

Communicating the register to key stakeholders


D.

Performing regular reviews and updates to the register


Expert Solution
Questions # 45:

Which of the following practices MOST effectively safeguards the processing of personal data?

Options:

A.

Personal data attributed to a specific data subject is tokenized.


B.

Data protection impact assessments are performed on a regular basis.


C.

Personal data certifications are performed to prevent excessive data collection.


D.

Data retention guidelines are documented, established, and enforced.


Expert Solution
Questions # 46:

Which of the following BEST mitigates reputational risk associated with disinformation campaigns against an organization?

Options:

A.

Monitoring digital platforms that disseminate inaccurate or misleading news stories


B.

Engaging public relations personnel to debunk false stories and publications


C.

Restricting the use of social media on corporate networks during specific hours


D.

Providing awareness training to understand and manage these types of attacks


Expert Solution
Questions # 47:

Which of the following BEST indicates that additional or improved controls ate needed m the environment?

Options:

A.

Management, has decreased organisational risk appetite


B.

The risk register and portfolio do not include all risk scenarios


C.

merging risk scenarios have been identified


D.

Risk events and losses exceed risk tolerance


Expert Solution
Questions # 48:

Which of the following provides the BEST evidence of the effectiveness of an organization ' s account provisioning process?

Options:

A.

User provisioning


B.

Role-based access controls


C.

Security log monitoring


D.

Entitlement reviews


Expert Solution
Questions # 49:

Which key performance indicator (KPI) BEST measures the effectiveness of an organization ' s disaster recovery program?

Options:

A.

Number of disaster recovery scenarios identified


B.

Percentage of employees involved in the disaster recovery exercise


C.

Number of total systems recovered within the recovery point objective (RPO)


D.

Percentage of critical systems recovered within the recovery time objective (RTO)


Expert Solution
Questions # 50:

Which of the following is the MOST effective way to incorporate stakeholder concerns when developing risk scenarios?

Options:

A.

Evaluating risk impact


B.

Establishing key performance indicators (KPIs)


C.

Conducting internal audits


D.

Creating quarterly risk reports


Expert Solution
Viewing page 1 out of 12 pages
Viewing questions 1-50 out of questions