Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 3 out of 12 pages
Viewing questions 101-150 out of questions
Questions # 101:

Who should be accountable for ensuring effective cybersecurity controls are established?

Options:

A.

Risk owner


B.

Security management function


C.

IT management


D.

Enterprise risk function


Expert Solution
Questions # 102:

Which of the following is MOST important to determine when assessing the potential risk exposure of a loss event involving personal data?

Options:

A.

The cost associated with incident response activitiesThe composition and number of records in the information asset


B.

The maximum levels of applicable regulatory fines


C.

The length of time between identification and containment of the incident


Expert Solution
Questions # 103:

A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner s NEXT step? r

Options:

A.

Prepare a business case for the response options.


B.

Identify resources for implementing responses.


C.

Develop a mechanism for monitoring residual risk.


D.

Update the risk register with the results.


Expert Solution
Questions # 104:

Which of the following is the BEST way to mitigate the risk to IT infrastructure availability?

Options:

A.

Establishing a disaster recovery plan (DRP)


B.

Establishing recovery time objectives (RTOs)


C.

Maintaining a current list of staff contact delays


D.

Maintaining a risk register


Expert Solution
Questions # 105:

Which of the following is MOST helpful to ensure effective security controls for a cloud service provider?

Options:

A.

A control self-assessment


B.

A third-party security assessment report


C.

Internal audit reports from the vendor


D.

Service level agreement monitoring


Expert Solution
Questions # 106:

Which of the following is performed after a risk assessment is completed?

Options:

A.

Defining risk taxonomy


B.

Identifying vulnerabilities


C.

Conducting an impact analysis


D.

Defining risk response options


Expert Solution
Questions # 107:

Which of the following is the GREATEST benefit of having a mature enterprise architecture (EA) in place?

Options:

A.

Standards-based policies


B.

Audit readiness


C.

Efficient operations


D.

Regulatory compliance


Expert Solution
Questions # 108:

Which of the following will be MOST effective to mitigate the risk associated with the loss of company data stored on personal devices?

Options:

A.

An acceptable use policy for personal devices


B.

Required user log-on before synchronizing data


C.

Enforced authentication and data encryption


D.

Security awareness training and testing


Expert Solution
Questions # 109:

Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?

Options:

A.

Apply data classification policy


B.

Utilize encryption with logical access controls


C.

Require logical separation of company data


D.

Obtain the right to audit


Expert Solution
Questions # 110:

Which of the following BEST enables a risk practitioner to understand management ' s approach to organizational risk?

Options:

A.

Organizational structure and job descriptions


B.

Risk appetite and risk tolerance


C.

Industry best practices for risk management


D.

Prior year ' s risk assessment results


Expert Solution
Questions # 111:

After a risk has been identified, who is in the BEST position to select the appropriate risk treatment option?

Options:

A.

The risk practitioner


B.

The business process owner


C.

The risk owner


D.

The control owner


Expert Solution
Questions # 112:

Which of the following groups represents the first line of defense?

Options:

A.

Internal audit


B.

Compliance committee


C.

External audit


D.

Operational managers


Expert Solution
Questions # 113:

What is the MOST effective approach to promote ethical decision-making in a global organization?

Options:

A.

Embed risk averse culture within the organization.


B.

Ensure ethics considerations are made in the hiring process.


C.

Ensure code of conduct is incorporated into organization-wide awareness training


D.

Require annual metrics related to ethics be reported.


Expert Solution
Questions # 114:

Which of the following is the BEST time for an enterprise project management team to use risk analysis?

Options:

A.

When the final testing phase begins


B.

During the project initiation phase


C.

At the end of the project


D.

During business impact analysis (BIA)


Expert Solution
Questions # 115:

Which of the following BEST helps to ensure disaster recovery staff members

are able to complete their assigned tasks effectively during a disaster?

Options:

A.

Performing parallel disaster recovery testing


B.

Documenting the order of system and application restoration


C.

Involving disaster recovery staff members in risk assessments


D.

Conducting regular tabletop exercises and scenario analysis


Expert Solution
Questions # 116:

After identifying new risk events during a project, the project manager s NEXT step should be to:

Options:

A.

determine if the scenarios need 10 be accepted or responded to.


B.

record the scenarios into the risk register.


C.

continue with a qualitative risk analysis.


D.

continue with a quantitative risk analysis.


Expert Solution
Questions # 117:

An organization ' s IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?

Options:

A.

Due diligence for the recommended cloud vendor has not been performed.


B.

The business can introduce new Software as a Service (SaaS) solutions without IT approval.


C.

The maintenance of IT infrastructure has been outsourced to an Infrastructure as a Service (laaS) provider.


D.

Architecture responsibilities may not be clearly defined.


Expert Solution
Questions # 118:

A recent regulatory requirement has the potential to affect an organization’s use of a third party to supply outsourced business services. Which of the following is the BEST course of action?

Options:

A.

Conduct a gap analysis


B.

Transfer risk to the third party


C.

Terminate the outsourcing agreement


D.

Identify compensating controls


Expert Solution
Questions # 119:

A risk assessment indicates the residual risk associated with a new bring your own device (BYOD) program is within organizational risk tolerance. Which of the following should the risk practitioner

recommend be done NEXT?

Options:

A.

Implement targeted awareness training for new BYOD users.


B.

Implement monitoring to detect control deterioration.


C.

Identify log sources to monitor BYOD usage and risk impact.


D.

Reduce the risk tolerance level.


Expert Solution
Questions # 120:

Which of the following is the BEST approach when a risk practitioner has been asked by a business unit manager to exclude an in-scope system from a risk assessment?

Options:

A.

Postpone the risk assessment.


B.

Facilitate the exception process.


C.

Accept the manager ' s request.


D.

Reject the manager ' s request.


Expert Solution
Questions # 121:

Which of the following will be MOST effective in helping to ensure control failures are appropriately managed?

Options:

A.

Control procedures


B.

Peer review


C.

Compensating controls


D.

Control ownership


Expert Solution
Questions # 122:

Which of the following is the GREATEST benefit of centralizing IT systems?

Options:

A.

Risk reporting


B.

Risk classification


C.

Risk monitoring


D.

Risk identification


Expert Solution
Questions # 123:

Which of the following is MOST important to ensure when reviewing an organization ' s risk register?

Options:

A.

Risk ownership is recorded.


B.

Vulnerabilities have separate entries.


C.

Control ownership is recorded.


D.

Residual risk is less than inherent risk.


Expert Solution
Questions # 124:

During a routine check, a system administrator identifies unusual activity indicating an intruder within a firewall. Which of the following controls has MOST likely been compromised?

Options:

A.

Data validation


B.

Identification


C.

Authentication


D.

Data integrity


Expert Solution
Questions # 125:

When of the following is the BEST key control indicator (KCI) to determine the effectiveness of en intrusion prevention system (IPS)?

Options:

A.

Percentage of system uptime


B.

Percentage of relevant threats mitigated


C.

Total number of threats identified


D.

Reaction time of the system to threats


Expert Solution
Questions # 126:

Which of the following BEST reduces the likelihood of employees unintentionally disclosing sensitive information to outside parties?

Options:

A.

Regular employee security awareness training


B.

Sensitive information classification and handling policies


C.

Anti-malware controls on endpoint devices


D.

An egress intrusion detection system (IDS)


Expert Solution
Questions # 127:

An organization has decided to implement a new Internet of Things (loT) solution. Which of the following should be done FIRST when addressing security concerns associated with this new technology?

Options:

A.

Develop new loT risk scenarios.


B.

Implement loT device monitoring software.


C.

Introduce controls to the new threat environment.


D.

Engage external security reviews.


Expert Solution
Questions # 128:

Which of the following BEST protects organizational data within a production cloud environment?

Options:

A.

Data encryption


B.

Continuous log monitoring


C.

Right to audit


D.

Data obfuscation


Expert Solution
Questions # 129:

Which of the following is the BEST indicator of the effectiveness of a control monitoring program?

Options:

A.

Time between control failure and failure detection


B.

Number of key controls as a percentage of total control count


C.

Time spent on internal control assessment reviews


D.

Number of internal control failures within the measurement period


Expert Solution
Questions # 130:

Which of the following poses the GREATEST risk to an organization ' s operations during a major it transformation?

Options:

A.

Lack of robust awareness programs


B.

infrequent risk assessments of key controls


C.

Rapid changes in IT procedures


D.

Unavailability of critical IT systems


Expert Solution
Questions # 131:

Which of the following is the MOST important for an organization to have in place to ensure IT asset protection?

Options:

A.

Procedures for risk assessments on IT assets


B.

An IT asset management checklist


C.

An IT asset inventory populated by an automated scanning tool


D.

A plan that includes processes for the recovery of IT assets


Expert Solution
Questions # 132:

A business delegates its application data management to the internal IT team. Which of the following is the role of the internal IT team in this situation?

Options:

A.

Data controllers


B.

Data custodians


C.

Data analysts


D.

Data owners


Expert Solution
Questions # 133:
Options:

A.

Develop policies with less restrictive requirements to ensure consistency across the organization.


B.

Develop a global policy to be applied uniformly by each country.


C.

Develop country-specific policies to address local regulations.


D.

Develop a global policy that accommodates country-specific requirements.


Expert Solution
Questions # 134:

An organization ' s risk tolerance should be defined and approved by which of the following?

Options:

A.

The chief risk officer (CRO)


B.

The board of directors


C.

The chief executive officer (CEO)


D.

The chief information officer (CIO)


Expert Solution
Questions # 135:

An organization uses one centralized single sign-on (SSO) control to cover many applications. Which of the following is the BEST course of action when a new application is added to the environment after testing of the SSO control has been completed?

Options:

A.

Initiate a retest of the full control


B.

Retest the control using the new application as the only sample.


C.

Review the corresponding change control documentation


D.

Re-evaluate the control during (he next assessment


Expert Solution
Questions # 136:

The MOST important objective of information security controls is to:

Options:

A.

Identify threats and vulnerability


B.

Ensure alignment with industry standards


C.

Provide measurable risk reduction


D.

Enforce strong security solutions


Expert Solution
Questions # 137:

Which of the following should be done FIRST when developing a data protection management plan?

Options:

A.

Perform a cost-benefit analysis.


B.

Identify critical data.


C.

Establish a data inventory.


D.

Conduct a risk analysis.


Expert Solution
Questions # 138:

Which type of cloud computing deployment provides the consumer the GREATEST degree of control over the environment?

Options:

A.

Community cloud


B.

Private cloud


C.

Hybrid cloud


D.

Public cloud


Expert Solution
Questions # 139:

The software version of an enterprise ' s critical business application has reached end-of-life and is no longer supported by the vendor. IT has decided to develop an in-house replacement application. Which of the following should be the PRIMARY concern?

Options:

A.

The system documentation is not available.


B.

Enterprise risk management (ERM) has not approved the decision.


C.

The board of directors has not approved the decision.


D.

The business process owner is not an active participant.


Expert Solution
Questions # 140:

Which of the following would BEST facilitate the implementation of data classification requirements?

Options:

A.

Implementing a data toss prevention (DLP) solution


B.

Assigning a data owner


C.

Scheduling periodic audits


D.

Implementing technical controls over the assets


Expert Solution
Questions # 141:

The MOST essential content to include in an IT risk awareness program is how to:

Options:

A.

define the IT risk framework for the organization


B.

populate risk register entries and build a risk profile for management reporting


C.

comply with the organization ' s IT risk and information security policies


D.

prioritize IT-related actions by considering risk appetite and risk tolerance


Expert Solution
Questions # 142:

While reviewing the risk register, a risk practitioner notices that different business units have significant variances in inherent risk for the same risk scenario. Which of the following is the BEST course of action?

Options:

A.

Update the risk register with the average of residual risk for both business units.


B.

Review the assumptions of both risk scenarios to determine whether the variance is reasonable.


C.

Update the risk register to ensure both risk scenarios have the highest residual risk.


D.

Request that both business units conduct another review of the risk.


Expert Solution
Questions # 143:

Which of the following would MOST likely drive the need to review and update key performance indicators (KPIs) for critical IT assets?

Options:

A.

The outsourcing of related IT processes


B.

Outcomes of periodic risk assessments


C.

Changes in service level objectives


D.

Findings from continuous monitoring


Expert Solution
Questions # 144:

The BEST key performance indicator (KPI) to measure the effectiveness of a vulnerability remediation program is the number of:

Options:

A.

vulnerability scans.


B.

recurring vulnerabilities.


C.

vulnerabilities remediated,


D.

new vulnerabilities identified.


Expert Solution
Questions # 145:

A global company s business continuity plan (BCP) requires the transfer of its customer information….

event of a disaster. Which of the following should be the MOST important risk consideration?

Options:

A.

The difference In the management practices between each company


B.

The cloud computing environment is shared with another company


C.

The lack of a service level agreement (SLA) in the vendor contract


D.

The organizational culture differences between each country


Expert Solution
Questions # 146:

Which of the following is the BEST key control indicator (KCI) for risk related to IT infrastructure failure?

Options:

A.

Number of times the recovery plan is reviewed


B.

Number of successful recovery plan tests


C.

Percentage of systems with outdated virus protection


D.

Percentage of employees who can work remotely


Expert Solution
Questions # 147:

Which of the following would be a weakness in procedures for controlling the migration of changes to production libraries?

Options:

A.

The programming project leader solely reviews test results before approving the transfer to production.


B.

Test and production programs are in distinct libraries.


C.

Only operations personnel are authorized to access production libraries.


D.

A synchronized migration of executable and source code from the test environment to the production environment is allowed.


Expert Solution
Questions # 148:

When developing a risk awareness training program, which of the following is the BEST way to promote a risk-aware culture?

Options:

A.

Emphasize individual responsibility for managing risk.


B.

Communicate incident escalation procedures.


C.

Illustrate methods to identify threats and vulnerabilities.


D.

Challenge the effectiveness of business processes.


Expert Solution
Questions # 149:

Which of the following issues should be of GREATEST concern when evaluating existing controls during a risk assessment?

Options:

A.

A high number of approved exceptions exist with compensating controls.


B.

Successive assessments have the same recurring vulnerabilities.


C.

Redundant compensating controls are in place.


D.

Asset custodians are responsible for defining controls instead of asset owners.


Expert Solution
Questions # 150:

A robotic process automation (RPA) project has implemented new robots to enhance the efficiency of a sales business process. Which of the following provides the BEST evidence that the new controls have been implemented successfully?

Options:

A.

A post-implementation review has been conducted by key personnel.


B.

A qualified independent party assessed the new controls as effective.


C.

Senior management has signed off on the design of the controls.


D.

Robots have operated without human interference on a daily basis.


Expert Solution
Viewing page 3 out of 12 pages
Viewing questions 101-150 out of questions