Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 1 out of 12 pages
Viewing questions 1-50 out of questions
Questions # 1:

Which of the following is the MOST important reason to integrate IT risk management practices into the enterprise-wide operational risk management framework?

Options:

A.

To reduce conflicts of interest between IT and non-IT business units


B.

To align the operational risk management framework with regulatory requirements


C.

To optimize the efficiency of enterprise-wide risk management resources


D.

To ensure IT risk scenarios are reflected in the corporate risk profile


Expert Solution
Questions # 2:

Which of the following should a risk practitioner recommend be done prior to disposal of server hardware containing confidential data?

Options:

A.

Destroy the hard drives.


B.

Encrypt the backup.


C.

Update the asset inventory.


D.

Remove all user access.


Expert Solution
Questions # 3:

The PRIMARY objective of the board of directors periodically reviewing the risk profile is to help ensure:

Options:

A.

the risk strategy is appropriate


B.

KRIs and KPIs are aligned


C.

performance of controls is adequate


D.

the risk monitoring process has been established


Expert Solution
Questions # 4:

A risk practitioner is collaborating with key stakeholders to prioritize a large number of IT risk scenarios. Which scenarios should receive the PRIMARY focus?

Options:

A.

Scenarios with the highest number of open audit issues


B.

Scenarios with the highest frequency of incidents


C.

Scenarios with the largest budget allocation for risk mitigation


D.

Scenarios with the highest risk impact to the business


Expert Solution
Questions # 5:

Which of the following controls would BEST reduce the likelihood of a successful network attack through social engineering?

Options:

A.

Automated controls


B.

Security awareness training


C.

Multifactor authentication


D.

Employee sanctions


Expert Solution
Questions # 6:

Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?

Options:

A.

Segregation of duties


B.

Monetary approval limits


C.

Clear roles and responsibilities


D.

Password policies


Expert Solution
Questions # 7:

A vendor’s planned maintenance schedule will cause a critical application to temporarily lose failover capabilities. Of the following, who should approve this proposed schedule?

Options:

A.

Business application owner


B.

Business continuity manager


C.

Chief risk officer (CRO)


D.

IT infrastructure manager


Expert Solution
Questions # 8:

Which of the following is the MOST important enabler of effective risk management?

Options:

A.

User awareness of policies and procedures


B.

Implementation of proper controls


C.

Senior management support


D.

Continuous monitoring of threats and vulnerabilities


Expert Solution
Questions # 9:

Which of the following is MOST important for maintaining the effectiveness of an IT risk register?

Options:

A.

Removing entries from the register after the risk has been treated


B.

Recording and tracking the status of risk response plans within the register


C.

Communicating the register to key stakeholders


D.

Performing regular reviews and updates to the register


Expert Solution
Questions # 10:

Which of the following is of GREATEST concern when uncontrolled changes are made to the control environment?

Options:

A.

A decrease in control layering effectiveness


B.

An increase in inherent risk


C.

An increase in control vulnerabilities


D.

An increase in the level of residual risk


Expert Solution
Questions # 11:

Days before the realization of an acquisition, a data breach is discovered at the company to be acquired. For the accruing organization, this situation represents which of the following?

Options:

A.

Threat event


B.

Inherent risk


C.

Risk event


D.

Security incident


Expert Solution
Questions # 12:

The analysis of which of the following will BEST help validate whether suspicious network activity is malicious?

Options:

A.

Logs and system events


B.

Intrusion detection system (IDS) rules


C.

Vulnerability assessment reports


D.

Penetration test reports


Expert Solution
Questions # 13:

Which of the following has the GREATEST impact on ensuring the alignment of the risk profile with business objectives?

Options:

A.

An effective enterprise-wide risk awareness program


B.

Senior management approval of risk appetite and tolerance


C.

Stage gate reviews throughout the risk management process


D.

Incorporation of industry best practice benchmarks and standards


Expert Solution
Questions # 14:

From a risk management perspective, which of the following is the PRIMARY benefit of using automated system configuration validation tools?

Options:

A.

Residual risk is reduced.


B.

Staff costs are reduced.


C.

Operational costs are reduced.


D.

Inherent risk is reduced.


Expert Solution
Questions # 15:

Which of the following is a risk practitioner ' s BEST course of action when a control is not meeting agreed-upon performance criteria?

Options:

A.

Implement additional controls to further mitigate risk


B.

Review performance results with the control owner


C.

Redefine performance criteria based on control monitoring results


D.

Recommend a tool to meet the performance requirements


Expert Solution
Questions # 16:

From a data protection and regulatory compliance perspective, which of the following is the MOST important reason for a global organization to use immutable backups?

Options:

A.

Immutable backups can be used for data recovery testing.


B.

Data contains time stamps that indicate when it was backed up.


C.

Immutable backups enable effective disaster recovery response.


D.

Data cannot be tampered with through the use of encryption capabilities


Expert Solution
Questions # 17:

Risk mitigation procedures should include:

Options:

A.

buying an insurance policy.


B.

acceptance of exposures


C.

deployment of counter measures.


D.

enterprise architecture implementation.


Expert Solution
Questions # 18:

Which of the following techniques is MOST helpful when quantifying the potential loss impact of cyber risk?

Options:

A.

Cost-benefit analysis


B.

Penetration testing


C.

Business impact analysis (BIA)


D.

Security assessment


Expert Solution
Questions # 19:

Which element of an organization ' s risk register is MOST important to update following the commissioning of a new financial reporting system?

Options:

A.

Key risk indicators (KRIs)


B.

The owner of the financial reporting process


C.

The risk rating of affected financial processes


D.

The list of relevant financial controls


Expert Solution
Questions # 20:

Which of the following should be management ' s PRIMARY focus when key risk indicators (KRIs) begin to rapidly approach defined thresholds?

Options:

A.

Designing compensating controls


B.

Determining if KRIs have been updated recently


C.

Assessing the effectiveness of the incident response plan


D.

Determining what has changed in the environment


Expert Solution
Questions # 21:

Which of the following is the MOST critical consideration when awarding a project to a third-party service provider whose servers are located offshore?

Options:

A.

Difficulty of monitoring compliance due to geographical distance


B.

Cost implications due to installation of network intrusion detection systems (IDSs)


C.

Delays in incident communication


D.

Potential impact on data governance


Expert Solution
Questions # 22:

Which of the following activities BEST facilitates effective risk management throughout the organization?

Options:

A.

Reviewing risk-related process documentation


B.

Conducting periodic risk assessments


C.

Performing a business impact analysis (BIA)


D.

Performing frequent audits


Expert Solution
Questions # 23:

When evaluating a number of potential controls for treating risk, it is MOST important to consider:

Options:

A.

risk appetite and control efficiency.


B.

inherent risk and control effectiveness.


C.

residual risk and cost of control.


D.

risk tolerance and control complexity.


Expert Solution
Questions # 24:

Which of the following is the BEST key control indicator (KCI) for measuring the security of a blockchain network?

Options:

A.

Number of active nodes


B.

Blockchain size in gigabytes


C.

Average transaction speed


D.

Number of validated transactions


Expert Solution
Questions # 25:

When a high number of approved exceptions are observed during a review of a control procedure, an organization should FIRST initiate a review of the:

Options:

A.

Relevant policies.


B.

Threat landscape.


C.

Awareness program.


D.

Risk heat map.


Expert Solution
Questions # 26:

Which of the following is the MOST important reason for a risk practitioner to identify stakeholders for each IT risk scenario?

Options:

A.

To ensure enterprise-wide risk management


B.

To establish control ownership


C.

To enable a comprehensive view of risk


D.

To identify key risk indicators (KRIs)


Expert Solution
Questions # 27:

Which of the following stakeholders define risk tolerance for an enterprise?

Options:

A.

IT compliance and IT audit


B.

Regulators and shareholders


C.

The board and executive management


D.

Enterprise risk management (ERM)


Expert Solution
Questions # 28:

Which of the following provides the BEST assurance of…..

Options:

A.

Penetration testing


B.

Service-level monitoring


C.

Service provider ' s control self-assessment (CSA)


D.

Independent assessment report


Expert Solution
Questions # 29:

The BEST way to improve a risk register is to ensure the register:

Options:

A.

is updated based upon significant events.


B.

documents possible countermeasures.


C.

contains the risk assessment completion date.


D.

is regularly audited.


Expert Solution
Questions # 30:

If preventive controls cannot be Implemented due to technology limitations, which of the following should be done FIRST to reduce risk7

Options:

A.

Evaluate alternative controls.


B.

Redefine the business process to reduce the risk.


C.

Develop a plan to upgrade technology.


D.

Define a process for monitoring risk.


Expert Solution
Questions # 31:

The MOST important characteristic of an organization s policies is to reflect the organization ' s:

Options:

A.

risk assessment methodology.


B.

risk appetite.


C.

capabilities


D.

asset value.


Expert Solution
Questions # 32:

The PRIMARY objective of collecting information and reviewing documentation when performing periodic risk analysis should be to:

Options:

A.

Identify new or emerging risk issues.


B.

Satisfy audit requirements.


C.

Survey and analyze historical risk data.


D.

Understand internal and external threat agents.


Expert Solution
Questions # 33:

The MAIN purpose of a risk register is to:

Options:

A.

document the risk universe of the organization.


B.

promote an understanding of risk across the organization.


C.

enable well-informed risk management decisions.


D.

identify stakeholders associated with risk scenarios.


Expert Solution
Questions # 34:

A newly enacted information privacy law significantly increases financial penalties for breaches of personally identifiable information (Pll). Which of the following will MOST likely outcome for an organization affected by the new law?

Options:

A.

Increase in compliance breaches


B.

Increase in loss event impact


C.

Increase in residual risk


D.

Increase in customer complaints


Expert Solution
Questions # 35:

Which of the following is the MOST important course of action to foster an ethical, risk-aware culture?

Options:

A.

Implement a fraud detection and prevention framework.


B.

Ensure the alignment of the organization ' s policies and standards to the defined risk appetite.


C.

Establish an enterprise-wide ethics training and awareness program.


D.

Perform a comprehensive review of all applicable legislative frameworks and requirements.


Expert Solution
Questions # 36:

A risk practitioner has been asked to assess the risk associated with a new critical application used by a financial process team that the risk practitioner was a member of two years ago. Which of the following is the GREATEST concern with this request?

Options:

A.

The risk assessment team may be overly confident of its ability to identify issues.


B.

The risk practitioner may be unfamiliar with recent application and process changes.


C.

The risk practitioner may still have access rights to the financial system.


D.

Participation in the risk assessment may constitute a conflict of interest.


Expert Solution
Questions # 37:

A bank has outsourced its statement printing function to an external service provider. Which of the following is the MOST critical requirement to include in the contract?

Options:

A.

Monitoring of service costs


B.

Provision of internal audit reports


C.

Notification of sub-contracting arrangements


D.

Confidentiality of customer data


Expert Solution
Questions # 38:

Which of the following practices MOST effectively safeguards the processing of personal data?

Options:

A.

Personal data attributed to a specific data subject is tokenized.


B.

Data protection impact assessments are performed on a regular basis.


C.

Personal data certifications are performed to prevent excessive data collection.


D.

Data retention guidelines are documented, established, and enforced.


Expert Solution
Questions # 39:

An organization automatically approves exceptions to security policies on a recurring basis. This practice is MOST likely the result of:

Options:

A.

a lack of mitigating actions for identified risk


B.

decreased threat levels


C.

ineffective service delivery


D.

ineffective IT governance


Expert Solution
Questions # 40:

Which of the following is MOST essential for an effective change control environment?

Options:

A.

Business management approval of change requests


B.

Separation of development and production environments


C.

Requirement of an implementation rollback plan


D.

IT management review of implemented changes


Expert Solution
Questions # 41:

From a governance perspective, which of the following is MOST important to ensure when risk management policies are being updated to facilitate the pursuit of new opportunities?

Options:

A.

Updates align with strategic business objectives.


B.

Updates will be approved by the risk owners.


C.

Updates align with industry standards and benchmarks.


D.

Updates will be reviewed periodically to ensure compliance.


Expert Solution
Questions # 42:

An organization requires data owners to perform a quarterly review of all privileged users on key financial systems. What type of control does this represent?

Options:

A.

Preventive.


B.

Directive.


C.

Corrective.


D.

Detective.


Expert Solution
Questions # 43:

What should a risk practitioner do FIRST when an assessment reveals a control is not operating as intended?

Options:

A.

Recommend updates to the control procedures


B.

Determine the root cause of the control issue.


C.

Discuss the status with the control owner.


D.

Recommend compensating controls.


Expert Solution
Questions # 44:

Which of the following is MOST important requirement to include in a Software as a Service (SaaS) vendor contract to ensure data is protected?

Options:

A.

The vendor must provide periodic independent assurance reports.


B.

The vendor must host data in a specific geographic location.


C.

The vendor must be held liable for regulatory fines for failure to protect data.


D.

The vendor must participate in an annual vendor performance review.


Expert Solution
Questions # 45:

Which of the following BEST measures the efficiency of an incident response process?

Options:

A.

Number of incidents escalated to management


B.

Average time between changes and updating of escalation matrix


C.

Average gap between actual and agreed response times


D.

Number of incidents lacking responses


Expert Solution
Questions # 46:

Which of the following would BEST help minimize the risk associated with social engineering threats?

Options:

A.

Enforcing employees’ sanctions


B.

Conducting phishing exercises


C.

Enforcing segregation of dunes


D.

Reviewing the organization ' s risk appetite


Expert Solution
Questions # 47:

The acceptance of control costs that exceed risk exposure is MOST likely an example of:

Options:

A.

low risk tolerance.


B.

corporate culture misalignment.


C.

corporate culture alignment.


D.

high risk tolerance


Expert Solution
Questions # 48:

Reviewing which of the following provides the BEST indication of an organizations risk tolerance?

Options:

A.

Risk sharing strategy


B.

Risk transfer agreements


C.

Risk policies


D.

Risk assessments


Expert Solution
Questions # 49:

A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management the risk practitioner should explain:

Options:

A.

mitigation plans for threat events should be prepared in the current planning period.


B.

this risk scenario is equivalent to more frequent but lower impact risk scenarios.


C.

the current level of risk is within tolerance.


D.

an increase in threat events could cause a loss sooner than anticipated.


Expert Solution
Questions # 50:

Which of the following is MOST important to consider when selecting and designing key control indicators (KCIs)?

Options:

A.

The KCI can establish a formal correlation with relevant KRIs


B.

The KCI can demonstrate whether the control objective has been met


C.

The KCI can be implemented within the allocated budget


D.

The KCI can be measured using quantitative methods


Expert Solution
Viewing page 1 out of 12 pages
Viewing questions 1-50 out of questions