Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 2 out of 12 pages
Viewing questions 51-100 out of questions
Questions # 51:

An organization is implementing internet of Things (loT) technology to control temperature and lighting in its headquarters. Which of the following should be of GREATEST concern?

Options:

A.

Insufficient network isolation


B.

impact on network performance


C.

insecure data transmission protocols


D.

Lack of interoperability between sensors


Expert Solution
Questions # 52:

A root because analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators Who should be accountable for resolving the situation?

Options:

A.

HR training director


B.

Business process owner


C.

HR recruitment manager


D.

Chief information officer (CIO)


Expert Solution
Questions # 53:

Which of the following is MOST important to consider when selecting risk indicators (KRIs)? The ability to:

Options:

A.

Monitor the performance of a process


B.

Assess the risk associated with risk scenarios


C.

Measure changes in the threat landscape


D.

Refine the organization’s risk appetite


Expert Solution
Questions # 54:

Which of the following is MOST important when identifying an organization ' s risk exposure associated with Internet of Things (loT) devices?

Options:

A.

Defined remediation plans


B.

Management sign-off on the scope


C.

Manual testing of device vulnerabilities


D.

Visibility into all networked devices


Expert Solution
Questions # 55:

An organization has outsourced its ERP application to an external SaaS provider. Which of the following provides the MOST useful information to identify risk scenarios involving data loss?

Options:

A.

Data classification schemes


B.

Industry data breach reports


C.

Data storage locations


D.

Data flow documentation


Expert Solution
Questions # 56:

When an organization ' s business continuity plan (BCP) states that it cannot afford to lose more than three hours of a critical application ' s data, the three hours is considered the application’s:

Options:

A.

Maximum tolerable outage (MTO).


B.

Recovery point objective (RPO).


C.

Mean time to restore (MTTR).


D.

Recovery time objective (RTO).


Expert Solution
Questions # 57:

An organization mandates the escalation of a service ticket when a key application is offline for 5 minutes or more due to potential risk exposure. The risk practitioner has been asked by management to prepare a report of application offline times using both 3- and 5-minute thresholds. What does the 3-minute threshold represent?

Options:

A.

Recovery Time Objective (RTO)


B.

Key Risk Indicator (KRI)


C.

Recovery Point Objective (RPO)


D.

Key Performance Indicator (KPI)


Expert Solution
Questions # 58:

A business unit is unable to fully implement the security policy on a critical business application. Which type of process should be in place to BEST manage the related risk?

Options:

A.

Change management


B.

Exception management


C.

Configuration management


D.

Incident management


Expert Solution
Questions # 59:

Which of the following is the PRIMARY benefit when senior management periodically reviews and updates risk appetite and tolerance levels?

Options:

A.

It ensures compliance with the risk management framework.


B.

It ensures an effective risk aggregation process.


C.

It ensures decisions are risk-informed.


D.

It ensures a consistent approach for risk assessments.


Expert Solution
Questions # 60:

An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization ' s risk appetite and tolerance, which of the following is the risk practitioner ' s BEST recommendation?

Options:

A.

Obtain adequate cybersecurity insurance coverage.


B.

Ensure business continuity assessments are up to date.


C.

Adjust the organization ' s risk appetite and tolerance.


D.

Obtain certification to a global information security standard.


Expert Solution
Questions # 61:

A legacy application used for a critical business function relies on software that has reached the end of extended support Which of the following is the MOST effective control to manage this application?

Options:

A.

Subscribe to threat intelligence to monitor external attacks.


B.

Apply patches for a newer version of the application.


C.

Segment the application within the existing network.


D.

Increase the frequency of regular system and data backups.


Expert Solution
Questions # 62:

Which of the following BEST facilitates the process of documenting risk tolerance?

Options:

A.

Creating a risk register


B.

Interviewing management


C.

Conducting a risk assessment


D.

Researching industry standards


Expert Solution
Questions # 63:

An organization has just started accepting credit card payments from customers via the corporate website. Which of the following is MOST likely to increase as a result of this new initiative?

Options:

A.

Risk tolerance


B.

Risk appetite


C.

Inherent risk


D.

Residual risk


Expert Solution
Questions # 64:

Which of the following is MOST important for an organization to have in place when developing a risk management framework?

Options:

A.

A strategic approach to risk including an established risk appetite


B.

A risk-based internal audit plan for the organization


C.

A control function within the risk management team


D.

An organization-wide risk awareness training program


Expert Solution
Questions # 65:

Which of the following BEST helps to mitigate risk associated with users inputting incorrect data into a system?

Options:

A.

Sequence check


B.

Tool tips


C.

User training


D.

Allowed values


Expert Solution
Questions # 66:

Which of the following presents the GREATEST challenge for an IT risk practitioner who wants to report on trends in historical IT risk levels?

Options:

A.

Qualitative measures for potential loss events


B.

Changes in owners for identified IT risk scenarios


C.

Changes in methods used to calculate probability


D.

Frequent use of risk acceptance as a treatment option


Expert Solution
Questions # 67:

Which of the following would provide the MOST useful information for communicating an organization’s risk level to senior management?

Options:

A.

A list of organizational threats


B.

A high-level risk map


C.

Specialized risk publications


D.

A list of organizational vulnerabilities


Expert Solution
Questions # 68:

Which of the following would MOST effectively reduce risk associated with an increase of online transactions on a retailer website?

Options:

A.

Scalable infrastructure


B.

A hot backup site


C.

Transaction limits


D.

Website activity monitoring


Expert Solution
Questions # 69:

Which of the following BEST enables the integration of IT risk management across an organization?

Options:

A.

Enterprise risk management (ERM) framework


B.

Enterprise-wide risk awareness training


C.

Robust risk reporting practices


D.

Risk management policies


Expert Solution
Questions # 70:

Which of the following provides the MOST important information to facilitate a risk response decision?

Options:

A.

Audit findings


B.

Risk appetite


C.

Key risk indicators


D.

Industry best practices


Expert Solution
Questions # 71:

What would be a risk practitioner ' s BEST recommendation when several key performance indicators (KPIs) for a control process fail to meet service level agreements (SLAs)?

Options:

A.

Adjust the process KPI threshold.


B.

Develop an IT risk response plan.


C.

Review the organization ' s IT risk profile.


D.

Review process efficiency.


Expert Solution
Questions # 72:

An organization has provided legal text explaining the rights and expected behavior of users accessing a system from geographic locations that have strong privacy regulations. Which of the following control types has been applied?

Options:

A.

Detective


B.

Directive


C.

Preventive


D.

Compensating


Expert Solution
Questions # 73:

Which of the following provides the MOST useful information for developing key risk indicators (KRIs)?

Options:

A.

Business impact analysis (BIA) results


B.

Risk scenario ownership


C.

Risk thresholds


D.

Possible causes of materialized risk


Expert Solution
Questions # 74:

Which of the following provides the BEST indication that existing controls are effective?

Options:

A.

Control testing


B.

Control logging


C.

Control documentation


D.

Control design


Expert Solution
Questions # 75:

An organization ' s stakeholders are unable to agree on appropriate risk responses. Which of the following would be the BEST course of action?

Options:

A.

Escalate to senior management.


B.

Identify a risk transfer option.


C.

Reassess risk scenarios.


D.

Benchmark with similar industries.


Expert Solution
Questions # 76:

An organization has completed a risk assessment of one of its service providers. Who should be accountable for ensuring that risk responses are implemented?

Options:

A.

IT risk practitioner


B.

Third -partf3ecurity team


C.

The relationship owner


D.

Legal representation of the business


Expert Solution
Questions # 77:

An organization has restructured its business processes, and the business continuity plan (BCP) needs to be revised accordingly. Which of the following should be identified FIRST?

Options:

A.

Variances in recovery times


B.

Ownership assignment for controls


C.

New potentially disruptive scenarios


D.

Contractual changes with customers


Expert Solution
Questions # 78:

In a public company, which group is PRIMARILY accountable for ensuring sufficient attention and resources are applied to the risk management process?

Options:

A.

Board of directors


B.

Risk officers


C.

Line management


D.

Senior management


Expert Solution
Questions # 79:

Which of the following s MOST likely to deter an employee from engaging in inappropriate use of company owned IT systems?

Options:

A.

A centralized computer security response team


B.

Regular performance reviews and management check-ins


C.

Code of ethics training for all employees


D.

Communication of employee activity monitoring


Expert Solution
Questions # 80:

Which of the following is the PRIMARY benefit of using a risk profile?

Options:

A.

It promotes a security-aware culture.


B.

It enables vulnerability analysis.


C.

It enhances internal risk reporting.


D.

It provides risk information to auditors.


Expert Solution
Questions # 81:

Which of the following is the GREATEST concern associated with business end users developing their own applications on end user spreadsheets and database programs?

Options:

A.

An IT project manager is not assigned to oversee development.


B.

Controls are not applied to the applications.


C.

There is a lack of technology recovery options.


D.

The applications are not captured in the risk profile.


Expert Solution
Questions # 82:

A control for mitigating risk in a key business area cannot be implemented immediately. Which of the following is the risk practitioner ' s BEST course of action when a compensating control needs to be applied?

Options:

A.

Obtain the risk owner ' s approval.


B.

Record the risk as accepted in the risk register.


C.

Inform senior management.


D.

update the risk response plan.


Expert Solution
Questions # 83:

Which of the following introduces the GREATEST amount of risk during the software development life cycle (SDLC)?

Options:

A.

Use of debugging tools


B.

Incorrect firewall configuration


C.

Inability to pass user acceptance tests (UATs)


D.

Untested changes to production


Expert Solution
Questions # 84:

The percentage of unpatched systems is a:

Options:

A.

threat vector.


B.

critical success factor (CSF).


C.

key performance indicator (KPI).


D.

key risk indicator (KRI).


Expert Solution
Questions # 85:

During the internal review of an accounts payable process, a risk practitioner determines that the transaction approval limits configured in the system are not being enforced. Which of the following should be done NEXT?

Options:

A.

Identify the extent of the approval limit violations.


B.

Notify senior management of the system deficiency.


C.

Update the risk register with higher risk likelihood of violation.


D.

Remind users of the importance of adhering to approval limits.


Expert Solution
Questions # 86:

Which of the following would be the BEST senior management action to influence a strong risk-aware culture within an organization?

Options:

A.

Initiating disciplinary actions against individuals causing incidents


B.

Identifying the root cause of incidents


C.

Sponsoring changes to prevent recurrence of incidents


D.

Reviewing the risk register and preparing incident reports


Expert Solution
Questions # 87:

A rule-based data loss prevention {DLP) tool has recently been implemented to reduce the risk of sensitive data leakage. Which of the following is MOST likely to change as a result of this implementation?

Options:

A.

Risk likelihood


B.

Risk velocity


C.

Risk appetite


D.

Risk impact


Expert Solution
Questions # 88:

Which of the following should be the PRIMARY input when designing IT controls?

Options:

A.

Benchmark of industry standards


B.

Internal and external risk reports


C.

Recommendations from IT risk experts


D.

Outcome of control self-assessments


Expert Solution
Questions # 89:

The results of a risk assessment reveal risk scenarios with high impact and low likelihood of occurrence. Which of the following would be the BEST action to address these scenarios?

Options:

A.

Assemble an incident response team.


B.

Create a disaster recovery plan (DRP).


C.

Develop a risk response plan.


D.

Initiate a business impact analysis (BIA).


Expert Solution
Questions # 90:

A risk practitioner is evaluating policies defined by an organization as part of its IT security framework. Which of the following would be of GREATEST concern?

Options:

A.

Lack of alignment with global security standards


B.

Inadequate policy enforcement


C.

Lack of a single repository for security procedures


D.

Increased cost for policy adoption


Expert Solution
Questions # 91:

During a risk assessment, the risk practitioner finds a new risk scenario without controls has been entered into the risk register. Which of the following is the MOST appropriate action?

Options:

A.

Include the new risk scenario in the current risk assessment.


B.

Postpone the risk assessment until controls are identified.


C.

Request the risk scenario be removed from the register.


D.

Exclude the new risk scenario from the current risk assessment


Expert Solution
Questions # 92:

An organization has used generic risk scenarios to populate its risk register. Which of the following presents the GREATEST challenge to assigning of the associated risk entries?

Options:

A.

The volume of risk scenarios is too large


B.

Risk aggregation has not been completed


C.

Risk scenarios are not applicable


D.

The risk analysts for each scenario is incomplete


Expert Solution
Questions # 93:

Which of the following is MOST important when developing key performance indicators (KPIs)?

Options:

A.

Alignment to risk responses


B.

Alignment to management reports


C.

Alerts when risk thresholds are reached


D.

Identification of trends


Expert Solution
Questions # 94:

Which of the following is MOST likely to increase the likelihood or impact of an identified risk scenario?

Options:

A.

Addition of an emerging technology into an existing process.


B.

Change from a quantitative to a qualitative risk analysis methodology.


C.

Introduction of controls based on recent audit findings.


D.

Increased use of risk acceptance by senior management.


Expert Solution
Questions # 95:

Which of the following should be done FIRST when developing an initial set of risk scenarios for an organization?

Options:

A.

Refer to industry standard scenarios.


B.

Use a top-down approach.


C.

Consider relevant business activities.


D.

Use a bottom-up approach.


Expert Solution
Questions # 96:

It is MOST important that security controls for a new system be documented in:

Options:

A.

testing requirements


B.

the implementation plan.


C.

System requirements


D.

The security policy


Expert Solution
Questions # 97:

Which of the following is MOST important to ensure risk management practices are effective at all levels within the organization?

Options:

A.

Communicating risk awareness materials regularly


B.

Establishing key risk indicators (KRIs) to monitor risk management processes


C.

Ensuring that business activities minimize inherent risk


D.

Embedding risk management in business activities


Expert Solution
Questions # 98:

Which of the following statements in an organization ' s current risk profile report is cause for further action by senior management?

Options:

A.

Key performance indicator (KPI) trend data is incomplete.


B.

New key risk indicators (KRIs) have been established.


C.

Key performance indicators (KPIs) are outside of targets.


D.

Key risk indicators (KRIs) are lagging.


Expert Solution
Questions # 99:

Which of the following is the GREATEST concern when using artificial intelligence (AI) language models?

Options:

A.

The model could be hacked or exploited.


B.

The model could be used to generate inaccurate content.


C.

Staff could become overly reliant on the model.


D.

It could lead to biased recommendations.


Expert Solution
Questions # 100:

The head of a business operations department asks to review the entire IT risk register. Which of the following would be the risk manager s BEST approach to this request before sharing the register?

Options:

A.

Escalate to senior management


B.

Require a nondisclosure agreement.


C.

Sanitize portions of the register


D.

Determine the purpose of the request


Expert Solution
Viewing page 2 out of 12 pages
Viewing questions 51-100 out of questions