Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 4 out of 12 pages
Viewing questions 151-200 out of questions
Questions # 151:

An IT risk practitioner is evaluating an organization ' s change management controls over the last six months. The GREATEST concern would be an increase in:

Options:

A.

rolled back changes below management ' s thresholds.


B.

change-related exceptions per month.


C.

the average implementation time for changes.


D.

number of user stories approved for implementation.


Expert Solution
Questions # 152:

An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:

Options:

A.

a recognized industry control framework


B.

guidance provided by the external auditor


C.

the service provider ' s existing controls


D.

The organization ' s specific control requirements


Expert Solution
Questions # 153:

A management team is on an aggressive mission to launch a new product to penetrate new markets and overlooks IT risk factors, threats, and vulnerabilities. This scenario BEST demonstrates an organization ' s risk:

Options:

A.

management.


B.

tolerance.


C.

culture.


D.

analysis.


Expert Solution
Questions # 154:

A service provider is managing a client’s servers. During an audit of the service, a noncompliant control is discovered that will not be resolved before the next audit because the client cannot afford the downtime required to correct the issue. The service provider’s MOST appropriate action would be to:

Options:

A.

develop a risk remediation plan overriding the client ' s decision


B.

make a note for this item in the next audit explaining the situation


C.

insist that the remediation occur for the benefit of other customers


D.

ask the client to document the formal risk acceptance for the provider


Expert Solution
Questions # 155:

Which of the following is the MOST important consideration when establishing a recovery point objective (RPO)?

Options:

A.

Latency of the alternate site


B.

Amount of acceptable data loss


C.

Time and resources for offsite backups


D.

Cost of testing the business continuity plan (BCP)


Expert Solution
Questions # 156:

Which of the following BEST provides an early warning that network access of terminated employees is not being revoked in accordance with the service level agreement (SLA)?

Options:

A.

Updating multi-factor authentication


B.

Monitoring key access control performance indicators


C.

Analyzing access control logs for suspicious activity


D.

Revising the service level agreement (SLA)


Expert Solution
Questions # 157:

A peer review of a risk assessment finds that a relevant threat community was not included. Mitigation of the risk will require substantial changes to a software application. Which of the following is the BEST course of action?

Options:

A.

Ask the business to make a budget request to remediate the problem.


B.

Build a business case to remediate the fix.


C.

Research the types of attacks the threat can present.


D.

Determine the impact of the missing threat.


Expert Solution
Questions # 158:

A bank wants to send a critical payment order via email to one of its offshore branches. Which of the following is the BEST way to ensure the message reaches the intended recipient without alteration?

Options:

A.

Add a digital certificate


B.

Apply multi-factor authentication


C.

Add a hash to the message


D.

Add a secret key


Expert Solution
Questions # 159:

When developing risk treatment alternatives for a Business case, it is MOST helpful to show risk reduction based on:

Options:

A.

cost-benefit analysis.


B.

risk appetite.


C.

regulatory guidelines


D.

control efficiency


Expert Solution
Questions # 160:

Which of the following will BEST help to ensure implementation of corrective action plans?

Options:

A.

Contracting to third parties


B.

Establishing employee awareness training


C.

Setting target dates to complete actions


D.

Assigning accountability to risk owners


Expert Solution
Questions # 161:

IT stakeholders have asked a risk practitioner for IT risk profile reports associated with specific departments to allocate resources for risk mitigation. The BEST way to address this request would be to use:

Options:

A.

the cost associated with each control.


B.

historical risk assessments.


C.

key risk indicators (KRls).


D.

information from the risk register.


Expert Solution
Questions # 162:

The risk associated with an asset before controls are applied can be expressed as:

Options:

A.

a function of the likelihood and impact


B.

the magnitude of an impact


C.

a function of the cost and effectiveness of control.


D.

the likelihood of a given threat


Expert Solution
Questions # 163:

Which of the following is MOST important to include in a risk assessment of an emerging technology?

Options:

A.

Risk response plans


B.

Risk and control ownership


C.

Key controls


D.

Impact and likelihood ratings


Expert Solution
Questions # 164:

A key risk indicator (KRI) for technology operations has been above risk thresholds for the last three reporting periods. What is the BEST way for a risk practitioner to address this concern?

Options:

A.

Adjust the original thresholds for the KRI for future reporting periods


B.

Initiate corrective actions with the accountable risk owner


C.

Implement forward-looking risk metrics to compare results


D.

Continue monitoring the KRI for changes in subsequent reporting periods


Expert Solution
Questions # 165:

Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?

Options:

A.

Conducting security awareness training


B.

Updating the information security policy


C.

Implementing mock phishing exercises


D.

Requiring two-factor authentication


Expert Solution
Questions # 166:

An organization wants to develop a strategy to mitigate the risk associated with unethical actions by stakeholders. Which of the following should be done FIRST?

Options:

A.

Provide incentives for whistleblowers to report unethical actions.


B.

Create a policy regarding ethical behavior.


C.

Communicate sanctions and penalties for unethical actions.


D.

Develop company-wide training on business ethics.


Expert Solution
Questions # 167:

A risk practitioner ' s BEST guidance to help an organization develop relevant risk scenarios is to ensure the scenarios are:

Options:

A.

Aligned with risk management capabilities.


B.

Based on industry trends.


C.

Related to probable events.


D.

Mapped to incident response plans.


Expert Solution
Questions # 168:

Which of the following would be MOST helpful when selecting appropriate protection for data?

Options:

A.

Business objectives


B.

Risk tolerance level


C.

Data access requirements


D.

Data classification


Expert Solution
Questions # 169:

Which of the following is the BEST approach for an organization in a heavily regulated industry to comprehensively test application functionality?

Options:

A.

Use production data in a non-production environment


B.

Use masked data in a non-production environment


C.

Use test data in a production environment


D.

Use anonymized data in a non-production environment


Expert Solution
Questions # 170:

Changes in which of the following would MOST likely cause a risk practitioner to adjust the risk impact rating in the risk register?

Options:

A.

Control effectiveness


B.

Risk appetite


C.

Control costs


D.

Risk tolerance


Expert Solution
Questions # 171:

Which of the following would be the GREATEST challenge when implementing a corporate risk framework for a global organization?

Options:

A.

Privacy risk controls


B.

Business continuity


C.

Risk taxonomy


D.

Management support


Expert Solution
Questions # 172:

Which of the following would be the GREATEST concern related to data privacy when implementing an Internet of Things (loT) solution that collects personally identifiable information (Pll)?

Options:

A.

A privacy impact assessment has not been completed.


B.

Data encryption methods apply to a subset of Pll obtained.


C.

The data privacy officer was not consulted.


D.

Insufficient access controls are used on the loT devices.


Expert Solution
Questions # 173:

Which of the following is the MOST important key performance indicator (KPI) for monitoring the user access management process?

Options:

A.

Proportion of end users having more than one account


B.

Percentage of accounts disabled within the service level agreement (SLA)


C.

Proportion of privileged to non-privileged accounts


D.

Percentage of accounts that have not been activated


Expert Solution
Questions # 174:

Who is the BEST person to the employee personal data?

Options:

A.

Human resources (HR) manager


B.

System administrator


C.

Data privacy manager


D.

Compliance manager


Expert Solution
Questions # 175:

A risk practitioner is reporting on an increasing trend of ransomware attacks in the industry. Which of the following information is MOST important to include to enable an informed response decision by key stakeholders?

Options:

A.

Methods of attack progression


B.

Losses incurred by industry peers


C.

Most recent antivirus scan reports


D.

Potential impact of events


Expert Solution
Questions # 176:

To minimize the risk of a potential acquisition being exposed externally, an organization has selected a few key employees to be engaged in the due diligence process. A member of the due diligence team realizes a close acquaintance is a high-ranking IT professional at a subsidiary of the company about to be acquired. What is the BEST course of action for this team member?

Options:

A.

Enforce segregation of duties.


B.

Disclose potential conflicts of interest.


C.

Delegate responsibilities involving the acquaintance.


D.

Notify the subsidiary ' s legal team.


Expert Solution
Questions # 177:

Which of the following is MOST critical when designing controls?

Options:

A.

Involvement of internal audit


B.

Involvement of process owner


C.

Quantitative impact of the risk


D.

Identification of key risk indicators


Expert Solution
Questions # 178:

The BEST way to obtain senior management support for investment in a control implementation would be to articulate the reduction in:

Options:

A.

detected incidents.


B.

residual risk.


C.

vulnerabilities.


D.

inherent risk.


Expert Solution
Questions # 179:

Which of the following criteria associated with key risk indicators (KRIs) BEST enables effective risk monitoring?

Options:

A.

Approval by senior management


B.

Low cost of development and maintenance


C.

Sensitivity to changes in risk levels


D.

Use of industry risk data sources


Expert Solution
Questions # 180:

Which of the following is the PRIMARY purpose of a risk register?

Options:

A.

To assign control ownership of risk


B.

To provide a centralized view of risk


C.

To identify opportunities to transfer risk


D.

To mitigate organizational risk


Expert Solution
Questions # 181:

Which of the following is the PRIMARY objective of providing an aggregated view of IT risk to business management?

Options:

A.

To enable consistent data on risk to be obtained


B.

To allow for proper review of risk tolerance


C.

To identify dependencies for reporting risk


D.

To provide consistent and clear terminology


Expert Solution
Questions # 182:

A risk owner has accepted a high-impact risk because the control was adversely affecting process efficiency. Before updating the risk register, it is MOST important for the risk practitioner to:

Options:

A.

ensure suitable insurance coverage is purchased.


B.

negotiate with the risk owner on control efficiency.


C.

reassess the risk to confirm the impact.


D.

obtain approval from senior management.


Expert Solution
Questions # 183:

Which of the following is the BEST success criterion for control implementation?

Options:

A.

Adequate resources are allocated to perform the control.


B.

Responsibilities for control execution are properly defined.


C.

Risk is at an acceptable level after the control is in place.


D.

Key risk indicators (KRIs) for the control are properly defined.


Expert Solution
Questions # 184:

Following the implementation of an Internet of Things (loT) solution, a risk practitioner identifies new risk factors with impact to existing controls. Which of the following is MOST important to include in a report to stakeholders?

Options:

A.

Identified vulnerabilities


B.

Business managers ' concerns


C.

Changes to residual risk


D.

Risk strategies of peer organizations


Expert Solution
Questions # 185:

Which of the following BEST supports ethical IT risk management practices?

Options:

A.

Robust organizational communication channels


B.

Mapping of key risk indicators (KRIs) to corporate strategy


C.

Capability maturity models integrated with risk management frameworks


D.

Rigorously enforced operational service level agreements (SLAs)


Expert Solution
Questions # 186:

Which of the following would be a risk practitioner ' $ BEST recommendation to help ensure cyber risk is assessed and reflected in the enterprise-level risk profile?

Options:

A.

Manage cyber risk according to the organization ' s risk management framework.


B.

Define cyber roles and responsibilities across the organization


C.

Conduct cyber risk awareness training tailored specifically for senior management


D.

Implement a cyber risk program based on industry best practices


Expert Solution
Questions # 187:

Which of the following is a risk practitioner ' s MOST important course of action when the level of risk has exceeded risk tolerance?

Options:

A.

Facilitate a review of risk tolerance levels


B.

Adjust the risk impact and likelihood scale


C.

Revise key risk indicator (KRI) thresholds


D.

Introduce the risk treatment process


Expert Solution
Questions # 188:

Which of the following would BEST provide early warning of a high-risk condition?

Options:

A.

Risk register


B.

Risk assessment


C.

Key risk indicator (KRI)


D.

Key performance indicator (KPI)


Expert Solution
Questions # 189:

A failed IT system upgrade project has resulted in the corruption of an organization ' s asset inventory database. Which of the following controls BEST mitigates the impact of this incident?

Options:

A.

Encryption


B.

Authentication


C.

Configuration


D.

Backups


Expert Solution
Questions # 190:

Which of the following is the MOST important reason to revisit a previously accepted risk?

Options:

A.

To update risk ownership


B.

To review the risk acceptance with new stakeholders


C.

To ensure risk levels have not changed


D.

To ensure controls are still operating effectively


Expert Solution
Questions # 191:

The BEST key performance indicator (KPI) for monitoring adherence to an organization ' s user accounts provisioning practices is the percentage of:

Options:

A.

accounts without documented approval


B.

user accounts with default passwords


C.

active accounts belonging to former personnel


D.

accounts with dormant activity.


Expert Solution
Questions # 192:

Where should a risk practitioner document the current state and desired future state of organizational risk?

Options:

A.

Risk register


B.

Risk action plan


C.

Risk management strategy


D.

Business continuity plan (BCP)


Expert Solution
Questions # 193:

Which of the following is the BEST way to reduce the likelihood of an individual performing a potentially harmful action as the result of unnecessary entitlement?

Options:

A.

Application monitoring


B.

Separation of duty


C.

Least privilege


D.

Nonrepudiation


Expert Solution
Questions # 194:

Which of the following is a specific concern related to machine learning algorithms?

Options:

A.

Low software quality


B.

Lack of access controls


C.

Data breaches


D.

Data bias


Expert Solution
Questions # 195:

Which of the following is the PRIMARY role of the first line within the three lines model?

Options:

A.

Maintaining effective internal controls


B.

Providing oversight and governance


C.

Conducting independent audits


D.

Establishing the organization’s risk appetite


Expert Solution
Questions # 196:

Which of the following should be accountable for ensuring that media containing financial information are adequately destroyed per an organization ' s data disposal policy?

Options:

A.

Compliance manager


B.

Data architect


C.

Data owner


D.

Chief information officer (CIO)


Expert Solution
Questions # 197:

The cost of maintaining a control has grown to exceed the potential loss. Which of the following BEST describes this situation?

Options:

A.

Insufficient risk tolerance


B.

Optimized control management


C.

Effective risk management


D.

Over-controlled environment


Expert Solution
Questions # 198:

A risk practitioner discovers several key documents detailing the design of a product currently in development have been posted on the Internet. What should be the risk practitioner ' s FIRST course of action?

Options:

A.

invoke the established incident response plan.


B.

Inform internal audit.


C.

Perform a root cause analysis


D.

Conduct an immediate risk assessment


Expert Solution
Questions # 199:

Which of the following BEST enables an organization to determine whether risk management is aligned with its goals and objectives?

Options:

A.

The organization has approved policies that provide operational boundaries.


B.

Organizational controls are in place to effectively manage risk appetite.


C.

Environmental changes that impact risk are continually evaluated.


D.

The organization has an approved enterprise architecture (EA) program.


Expert Solution
Questions # 200:

Which of the following is the BEST way to validate whether controls to reduce user device vulnerabilities have been implemented according to management ' s action plan?

Options:

A.

Survey device owners.


B.

Rescan the user environment.


C.

Require annual end user policy acceptance.


D.

Review awareness training assessment results


Expert Solution
Viewing page 4 out of 12 pages
Viewing questions 151-200 out of questions