Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 3 out of 12 pages
Viewing questions 101-150 out of questions
Questions # 101:

The BEST metric to demonstrate that servers are configured securely is the total number of servers:

Options:

A.

exceeding availability thresholds


B.

experiencing hardware failures


C.

exceeding current patching standards.


D.

meeting the baseline for hardening.


Expert Solution
Questions # 102:

Which of the following is the FIRST step in managing the risk associated with the leakage of confidential data?

Options:

A.

Maintain and review the classified data inventor.


B.

Implement mandatory encryption on data


C.

Conduct an awareness program for data owners and users.


D.

Define and implement a data classification policy


Expert Solution
Questions # 103:

The PRIMARY benefit of maintaining an up-to-date risk register is that it helps to:

Options:

A.

implement uniform controls for common risk scenarios.


B.

ensure business unit risk is uniformly distributed.


C.

build a risk profile for management review.


D.

quantify the organization ' s risk appetite.


Expert Solution
Questions # 104:

An organization ' s risk management team wants to develop IT risk scenarios to show the impact of collecting and storing credit card information. Which of the following is the MOST comprehensive approach to capture this scenario?

Options:

A.

Top-down analysis


B.

Event tree analysis


C.

Control gap analysis


D.

Bottom-up analysis


Expert Solution
Questions # 105:

Which of the following is the MOST important key performance indicator (KPI) for monitoring the user access management process?

Options:

A.

Proportion of end users having more than one account


B.

Percentage of accounts disabled within the service level agreement (SLA)


C.

Proportion of privileged to non-privileged accounts


D.

Percentage of accounts that have not been activated


Expert Solution
Questions # 106:

A new software package that could help mitigate risk in an organization has become available. Which of the following is the risk practitioner ' s BEST course of action?

Options:

A.

Perform a business impact analysis (BIA).


B.

Perform a cost-benefit analysis.


C.

Review industry best practice.


D.

Review risk governance policies.


Expert Solution
Questions # 107:

A risk practitioner has established that a particular control is working as desired, but the annual cost of maintenance has increased and now exceeds the expected annual loss exposure. The result is that the control is:

Options:

A.

mature


B.

ineffective.


C.

optimized.


D.

inefficient.


Expert Solution
Questions # 108:

A key risk indicator (KRI) is reported to senior management on a periodic basis as exceeding thresholds, but each time senior management has decided to take no action to reduce the risk. Which of the following is the MOST likely reason for senior management ' s response?

Options:

A.

The underlying data source for the KRI is using inaccurate data and needs to be corrected.


B.

The KRI is not providing useful information and should be removed from the KRI inventory.


C.

The KRI threshold needs to be revised to better align with the organization s risk appetite


D.

Senior management does not understand the KRI and should undergo risk training.


Expert Solution
Questions # 109:

Management has required information security awareness training to reduce the risk associated with credential compromise. What is the BEST way to assess the effectiveness of the training?

Options:

A.

Conduct social engineering testing.


B.

Audit security awareness training materials.


C.

Administer an end-of-training quiz.


D.

Perform a vulnerability assessment.


Expert Solution
Questions # 110:

Which of the following BEST facilitates the mitigation of identified gaps between current and desired risk environment states?

Options:

A.

Develop a risk treatment plan.


B.

Validate organizational risk appetite.


C.

Review results of prior risk assessments.


D.

Include the current and desired states in the risk register.


Expert Solution
Questions # 111:

Which of the following is the MOST important course of action to foster an ethical, risk-aware culture?

Options:

A.

Implement a fraud detection and prevention framework.


B.

Ensure the alignment of the organization ' s policies and standards to the defined risk appetite.


C.

Establish an enterprise-wide ethics training and awareness program.


D.

Perform a comprehensive review of all applicable legislative frameworks and requirements.


Expert Solution
Questions # 112:

Which of the following will BEST help to ensure the continued effectiveness of the IT risk management function within an organization experiencing high employee turnover?

Options:

A.

Well documented policies and procedures


B.

Risk and issue tracking


C.

An IT strategy committee


D.

Change and release management


Expert Solution
Questions # 113:

Which of the following is the BEST way to help ensure risk will be managed properly after a business process has been re-engineered?

Options:

A.

Reassessing control effectiveness of the process


B.

Conducting a post-implementation review to determine lessons learned


C.

Reporting key performance indicators (KPIs) for core processes


D.

Establishing escalation procedures for anomaly events


Expert Solution
Questions # 114:

A cote data center went offline abruptly for several hours affecting many transactions across multiple locations. Which of the to " owing would provide the MOST useful information to determine mitigating controls?

Options:

A.

Forensic analysis


B.

Risk assessment


C.

Root cause analysis


D.

Business impact analysis (BlA)


Expert Solution
Questions # 115:

Which of the following should be the GREATEST concern for an organization that uses open source software applications?

Options:

A.

Lack of organizational policy regarding open source software


B.

Lack of reliability associated with the use of open source software


C.

Lack of monitoring over installation of open source software in the organization


D.

Lack of professional support for open source software


Expert Solution
Questions # 116:

Which of the following is MOST important information to review when developing plans for using emerging technologies?

Options:

A.

Existing IT environment


B.

IT strategic plan


C.

Risk register


D.

Organizational strategic plan


Expert Solution
Questions # 117:

Which of the following BEST indicates the efficiency of a process for granting access privileges?

Options:

A.

Average time to grant access privileges


B.

Number of changes in access granted to users


C.

Average number of access privilege exceptions


D.

Number and type of locked obsolete accounts


Expert Solution
Questions # 118:

An organization ' s capability to implement a risk management framework is PRIMARILY influenced by the:

Options:

A.

guidance of the risk practitioner.


B.

competence of the staff involved.


C.

approval of senior management.


D.

maturity of its risk culture.


Expert Solution
Questions # 119:

A control owner has completed a year-long project To strengthen existing controls. It is MOST important for the risk practitioner to:

Options:

A.

update the risk register to reflect the correct level of residual risk.


B.

ensure risk monitoring for the project is initiated.


C.

conduct and document a business impact analysis (BIA).


D.

verify cost-benefit of the new controls being implemented.


Expert Solution
Questions # 120:

To enable effective integration of IT risk scenarios and enterprise risk management (ERM), it is MOST important to have a consistent approach to reporting:

Options:

A.

Key risk indicators (KRIs).


B.

Risk velocity.


C.

Risk response plans and owners.


D.

Risk impact and likelihood.


Expert Solution
Questions # 121:

An IT risk practitioner ' s report includes a treatment plan and projected risk ratings if recommendations are implemented. Once corrective actions are taken by the system owner, which of the following types of risk will the projected risk become?

Options:

A.

Control


B.

Inherent


C.

Residual


D.

Compliance


Expert Solution
Questions # 122:

Which of the following key risk indicators (KRIs) is MOST effective for monitoring risk related to a bring your own device (BYOD) program?

Options:

A.

Number of users who have signed a BYOD acceptable use policy


B.

Number of incidents originating from BYOD devices


C.

Budget allocated to the BYOD program security controls


D.

Number of devices enrolled in the BYOD program


Expert Solution
Questions # 123:

The acceptance of control costs that exceed risk exposure is MOST likely an example of:

Options:

A.

low risk tolerance.


B.

corporate culture misalignment.


C.

corporate culture alignment.


D.

high risk tolerance


Expert Solution
Questions # 124:

Which of the following is the MOST important benefit of implementing a data classification program?

Options:

A.

Reduction in data complexity


B.

Reduction in processing times


C.

Identification of appropriate ownership


D.

Identification of appropriate controls


Expert Solution
Questions # 125:

Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?

Options:

A.

Implement segregation of duties.


B.

Enforce an internal data access policy.


C.

Enforce the use of digital signatures.


D.

Apply single sign-on for access control.


Expert Solution
Questions # 126:

An organization is considering the adoption of an aggressive business strategy to achieve desired growth From a risk management perspective what should the risk practitioner do NEXT?

Options:

A.

Identify new threats resorting from the new business strategy


B.

Update risk awareness training to reflect current levels of risk appetite and tolerance


C.

Inform the board of potential risk scenarios associated with aggressive business strategies


D.

Increase the scale for measuring impact due to threat materialization


Expert Solution
Questions # 127:

A control for mitigating risk in a key business area cannot be implemented immediately. Which of the following is the risk practitioner ' s BEST course of action when a compensating control needs to be applied?

Options:

A.

Obtain the risk owner ' s approval.


B.

Record the risk as accepted in the risk register.


C.

Inform senior management.


D.

update the risk response plan.


Expert Solution
Questions # 128:

Which of the following provides the MOST useful information when determining if a specific control should be implemented?

Options:

A.

Business impact analysis (BIA)


B.

Cost-benefit analysis


C.

Attribute analysis


D.

Root cause analysis


Expert Solution
Questions # 129:

Continuous monitoring of key risk indicators (KRIs) will:

Options:

A.

ensure that risk will not exceed the defined risk appetite of the organization.


B.

provide an early warning so that proactive action can be taken.


C.

provide a snapshot of the risk profile.


D.

ensure that risk tolerance and risk appetite are aligned.


Expert Solution
Questions # 130:

Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?

Options:

A.

Apply data classification policy


B.

Utilize encryption with logical access controls


C.

Require logical separation of company data


D.

Obtain the right to audit


Expert Solution
Questions # 131:

A business unit is updating a risk register with assessment results for a key project. Which of the following is MOST important to capture in the register?

Options:

A.

The team that performed the risk assessment


B.

An assigned risk manager to provide oversight


C.

Action plans to address risk scenarios requiring treatment


D.

The methodology used to perform the risk assessment


Expert Solution
Questions # 132:

A company has located its computer center on a moderate earthquake fault. Which of the following is the MOST important consideration when establishing a contingency plan and an alternate processing site?

Options:

A.

The contingency plan provides for backup media to be taken to the alternative site.


B.

The contingency plan for high priority applications does not involve a shared cold site.


C.

The alternative site is a hot site with equipment ready to resume processing immediately.


D.

The alternative site does not reside on the same fault no matter how far the distance apart.


Expert Solution
Questions # 133:

Which of the following would offer the MOST insight with regard to an organization ' s risk culture?

Options:

A.

Risk management procedures


B.

Senior management interviews


C.

Benchmark analyses


D.

Risk management framework


Expert Solution
Questions # 134:

Which of the following is the MOST important consideration for prioritizing risk treatment plans when faced with budget limitations?

Options:

A.

Inherent risk and likelihood


B.

Management action plans associated with audit findings


C.

Residual risk relative to appetite and tolerance


D.

Key risk indicator (KRI) trends


Expert Solution
Questions # 135:

Which of the following is the GREATEST risk associated with the use of data analytics?

Options:

A.

Distributed data sources


B.

Manual data extraction


C.

Incorrect data selection


D.

Excessive data volume


Expert Solution
Questions # 136:

A risk practitioner is preparing a report to communicate changes in the risk and control environment. The BEST way to engage stakeholder attention is to:

Options:

A.

include detailed deviations from industry benchmarks,


B.

include a summary linking information to stakeholder needs,


C.

include a roadmap to achieve operational excellence,


D.

publish the report on-demand for stakeholders.


Expert Solution
Questions # 137:

A key risk indicator (KRI) threshold has reached the alert level, indicating data leakage incidents are highly probable. What should be the risk practitioner ' s FIRST course of action?

Options:

A.

Update the KRI threshold.


B.

Recommend additional controls.


C.

Review incident handling procedures.


D.

Perform a root cause analysis.


Expert Solution
Questions # 138:

Which of the following is the BEST metric to measure the effectiveness of an organization ' s disaster recovery program?

Options:

A.

Percentage of applications subject to disaster recovery tests


B.

Number of personnel dedicated to the disaster recovery program


C.

Number of disaster recovery tests performed per year


D.

Percentage of systems meeting defined recovery objectives


Expert Solution
Questions # 139:

Which of the following is MOST useful when communicating risk to management?

Options:

A.

Risk policy


B.

Audit report


C.

Risk map


D.

Maturity model


Expert Solution
Questions # 140:

Which of the following is the MOST important consideration when selecting either a qualitative or quantitative risk analysis?

Options:

A.

Expertise in both methodologies


B.

Maturity of the risk management program


C.

Time available for risk analysis


D.

Resources available for data analysis


Expert Solution
Questions # 141:

The BEST reason to classify IT assets during a risk assessment is to determine the:

Options:

A.

priority in the risk register.


B.

business process owner.


C.

enterprise risk profile.


D.

appropriate level of protection.


Expert Solution
Questions # 142:

A risk practitioner recently discovered that sensitive data from the production environment is required for testing purposes in non-production environments. Which of the following i the BEST recommendation to address this situation?

Options:

A.

Enable data encryption in the test environment


B.

Implement equivalent security in the test environment.


C.

Prevent the use of production data for test purposes


D.

Mask data before being transferred to the test environment.


Expert Solution
Questions # 143:

It is MOST important for a risk practitioner to have an awareness of an organization s processes in order to:

Options:

A.

perform a business impact analysis.


B.

identify potential sources of risk.


C.

establish risk guidelines.


D.

understand control design.


Expert Solution
Questions # 144:

Which of the following is the MOST important driver of an effective enterprise risk management (ERM) program?

Options:

A.

Risk policy


B.

Risk committee


C.

Risk culture


D.

Risk management plan


Expert Solution
Questions # 145:

A global company s business continuity plan (BCP) requires the transfer of its customer information….

event of a disaster. Which of the following should be the MOST important risk consideration?

Options:

A.

The difference In the management practices between each company


B.

The cloud computing environment is shared with another company


C.

The lack of a service level agreement (SLA) in the vendor contract


D.

The organizational culture differences between each country


Expert Solution
Questions # 146:

Which of the following is MOST helpful to review when assessing the risk exposure associated with ransomware?

Options:

A.

Potentially impacted business processes


B.

Recent changes in the environment


C.

Key performance indicators (KPIs)


D.

Suspected phishing events


Expert Solution
Questions # 147:

An organization is concerned that its employees may be unintentionally disclosing data through the use of social media sites. Which of the following will MOST effectively mitigate tins risk?

Options:

A.

Requiring the use of virtual private networks (VPNs)


B.

Establishing a data classification policy


C.

Conducting user awareness training


D.

Requiring employee agreement of the acceptable use policy


Expert Solution
Questions # 148:

Which of the following will BEST ensure that information security risk factors are mitigated when developing in-house applications?

Options:

A.

Identify information security controls in the requirements analysis


B.

Identify key risk indicators (KRIs) as process output.


C.

Design key performance indicators (KPIs) for security in system specifications.


D.

Include information security control specifications in business cases.


Expert Solution
Questions # 149:

Which of the following, who should be PRIMARILY responsible for performing user entitlement reviews?

Options:

A.

IT security manager


B.

IT personnel


C.

Data custodian


D.

Data owner


Expert Solution
Questions # 150:

In response to the threat of ransomware, an organization has implemented cybersecurity awareness activities. The risk practitioner ' s BEST recommendation to further reduce the impact of ransomware attacks would be to implement:

Options:

A.

two-factor authentication.


B.

continuous data backup controls.


C.

encryption for data at rest.


D.

encryption for data in motion.


Expert Solution
Viewing page 3 out of 12 pages
Viewing questions 101-150 out of questions