Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 5 out of 12 pages
Viewing questions 201-250 out of questions
Questions # 201:

When establishing an enterprise IT risk management program, it is MOST important to:

Options:

A.

review alignment with the organizations strategy.


B.

understand the organization ' s information security policy.


C.

validate the organization ' s data classification scheme.


D.

report identified IT risk scenarios to senior management.


Expert Solution
Questions # 202:

Which of the following should management consider when selecting a risk mitigation option?

Options:

A.

Maturity of the enterprise architecture


B.

Cost of control implementation


C.

Reliability of key performance indicators (KPIs)


D.

Reliability of key risk indicators (KPIs)


Expert Solution
Questions # 203:

Which of the following is the PRIMARY concern for a risk practitioner regarding an organization ' s adoption of innovative big data analytics capabilities?

Options:

A.

It may be expensive to maintain a data lake.


B.

It may be difficult to find experts who can develop analytical queries.


C.

There may be a lack of documented processes for big data analysis.


D.

Analytics methods may identify someone who was previously de-identified.


Expert Solution
Questions # 204:

When developing risk scenario using a list of generic scenarios based on industry best practices, it is MOST imported to:

Options:

A.

Assess generic risk scenarios with business users.


B.

Validate the generic risk scenarios for relevance.


C.

Select the maximum possible risk scenarios from the list.


D.

Identify common threats causing generic risk scenarios


Expert Solution
Questions # 205:

When evaluating enterprise IT risk management it is MOST important to:

Options:

A.

create new control processes to reduce identified IT risk scenarios


B.

confirm the organization’s risk appetite and tolerance


C.

report identified IT risk scenarios to senior management


D.

review alignment with the organization ' s investment plan


Expert Solution
Questions # 206:

Which of the following is the MOST effective control to ensure user access is maintained on a least-privilege basis?

Options:

A.

User authorization


B.

User recertification


C.

Change log review


D.

Access log monitoring


Expert Solution
Questions # 207:

Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?

Options:

A.

Accountability may not be clearly defined.


B.

Risk ratings may be inconsistently applied.


C.

Different risk taxonomies may be used.


D.

Mitigation efforts may be duplicated.


Expert Solution
Questions # 208:

Which of the following BEST facilitates the identification of appropriate key performance indicators (KPIs) for a risk management program?

Options:

A.

Reviewing control objectives


B.

Aligning with industry best practices


C.

Consulting risk owners


D.

Evaluating KPIs in accordance with risk appetite


Expert Solution
Questions # 209:

It is MOST important that entries in an organization’s risk register be updated:

Options:

A.

when the key risk indicator (KRI) threshold has been reached.


B.

when required by internal audit.


C.

prior to a risk review.


D.

when aspects of the risk scenario change.


Expert Solution
Questions # 210:

An organization uses a vendor to destroy hard drives. Which of the following would BEST reduce the risk of data leakage?

Options:

A.

Require the vendor to degauss the hard drives


B.

Implement an encryption policy for the hard drives.


C.

Require confirmation of destruction from the IT manager.


D.

Use an accredited vendor to dispose of the hard drives.


Expert Solution
Questions # 211:

The MAIN reason a risk practitioner should review control assessment reports is to:

Options:

A.

Provide assurance on effective compliance.


B.

Determine exceptions for management acceptance.


C.

Determine overall efficiency of the control environment.


D.

Determine if controls effectively lower risk exposure.


Expert Solution
Questions # 212:

Which of the following controls would BEST reduce the risk of account compromise?

Options:

A.

Enforce password changes.


B.

Enforce multi-factor authentication (MFA).


C.

Enforce role-based authentication.


D.

Enforce password encryption.


Expert Solution
Questions # 213:

A highly regulated enterprise is developing a new risk management plan to specifically address legal and regulatory risk scenarios What should be done FIRST by IT governance to support this effort?

Options:

A.

Request a regulatory risk reporting methodology


B.

Require critical success factors (CSFs) for IT risks.


C.

Establish IT-specific compliance objectives


D.

Communicate IT key risk indicators (KRIs) and triggers


Expert Solution
Questions # 214:

What would be the MAIN concern associated with a decentralized IT function maintaining multiple risk registers?

Options:

A.

Risk treatment efforts within the IT function may overlap one another.


B.

Duplicate IT risk scenarios may be documented across the organization.


C.

Aggregate risk within the IT function may exceed the organization ' s appetite.


D.

Related IT risk scenarios in the IT function may be updated at different times.


Expert Solution
Questions # 215:

In an organization where each division manages risk independently, which of the following would BEST enable management of risk at the enterprise level?

Options:

A.

A standardized risk taxonomy


B.

A list of control deficiencies


C.

An enterprise risk ownership policy


D.

An updated risk tolerance metric


Expert Solution
Questions # 216:

Which of the following has the MOST validity for conducting risk assessments?

Options:

A.

Internal control effectiveness measured through inference from external assessment


B.

Control effectiveness determined through subject matter expertise estimation


C.

Inferences of internal control effectiveness from peer reports


D.

Internal control effectiveness measured through direct testing


Expert Solution
Questions # 217:

Which of the following offers the SIMPLEST overview of changes in an organization ' s risk profile?

Options:

A.

A risk roadmap


B.

A balanced scorecard


C.

A heat map


D.

The risk register


Expert Solution
Questions # 218:

Which of the following is MOST likely to introduce risk for financial institutions that use blockchain?

Options:

A.

Cost of implementation


B.

Implementation of unproven applications


C.

Disruption to business processes


D.

Increase in attack surface area


Expert Solution
Questions # 219:

Which of the following is the MOST important consideration when determining the appropriate data retention period throughout the data management life cycle?

Options:

A.

Data storage and collection methods


B.

Data owner preferences


C.

Legal and regulatory requirements


D.

Choice of encryption algorithms


Expert Solution
Questions # 220:

Which of the following provides the MOST helpful information in identifying risk in an organization?

Options:

A.

Risk registers


B.

Risk analysis


C.

Risk scenarios


D.

Risk responses


Expert Solution
Questions # 221:

A key risk indicator (KRI) indicates a reduction in the percentage of appropriately patched servers. Which of the following is the risk practitioner ' s BEST course of action?

Options:

A.

Determine changes in the risk level.


B.

Outsource the vulnerability management process.


C.

Review the patch management process.


D.

Add agenda item to the next risk committee meeting.


Expert Solution
Questions # 222:

Which of the following would BEST ensure that identified risk scenarios are addressed?

Options:

A.

Reviewing the implementation of the risk response


B.

Creating a separate risk register for key business units


C.

Performing real-time monitoring of threats


D.

Performing regular risk control self-assessments


Expert Solution
Questions # 223:

Which of the following is the MAIN purpose of monitoring risk?

Options:

A.

Communication


B.

Risk analysis


C.

Decision support


D.

Benchmarking


Expert Solution
Questions # 224:

The BEST way to mitigate the high cost of retrieving electronic evidence associated with potential litigation is to implement policies and procedures for:

Options:

A.

data classification and labeling.


B.

data logging and monitoring.


C.

data retention and destruction.


D.

data mining and analytics.


Expert Solution
Questions # 225:

What should be the PRIMARY driver for periodically reviewing and adjusting key risk indicators (KRIs)?

Options:

A.

Risk impact


B.

Risk likelihood


C.

Risk appropriate


D.

Control self-assessments (CSAs)


Expert Solution
Questions # 226:

Which of the following BEST indicates the effectiveness of anti-malware software?

Options:

A.

Number of staff hours lost due to malware attacks


B.

Number of downtime hours in business critical servers


C.

Number of patches made to anti-malware software


D.

Number of successful attacks by malicious software


Expert Solution
Questions # 227:

An organization has agreed to a 99% availability for its online services and will not accept availability that falls below 98.5%. This is an example of:

Options:

A.

risk mitigation.


B.

risk evaluation.


C.

risk appetite.


D.

risk tolerance.


Expert Solution
Questions # 228:

Which risk analysis methodology uses diagrams to analyze causes and consequences of particular risk events?

Options:

A.

Failure mode and effects analysis


B.

Process and control mapping


C.

Monte Carlo simulation


D.

Fault tree analysis


Expert Solution
Questions # 229:

An organization ' s Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in the risk register and accepted. Who should be accountable for any related losses to the organization?

Options:

A.

Risk owner


B.

IT risk manager


C.

Server administrator


D.

Risk practitioner


Expert Solution
Questions # 230:

Which of the following provides the MOST insight into an organization ' s IT threat exposure?

Options:

A.

Industry benchmarks


B.

Risk assessment reports


C.

External audit results


D.

Tabletop exercises


Expert Solution
Questions # 231:

When creating a program to manage data privacy risk, which of the following is MOST important to ensure that the program is successful?

Options:

A.

Compliance with industry frameworks


B.

Alignment with applicable legal and regulatory requirements


C.

Approval of mitigating and compensating controls


D.

Adoption of mission and vision statements


Expert Solution
Questions # 232:

Which of the following is the GREATEST risk associated with an environment that lacks documentation of the architecture?

Options:

A.

Legacy technology systems.


B.

Inability to scale.


C.

Inadequate network isolation.


D.

Unknown vulnerabilities.


Expert Solution
Questions # 233:

Who should be responsible for strategic decisions on risk management?

Options:

A.

Chief information officer (CIO)


B.

Executive management team


C.

Audit committee


D.

Business process owner


Expert Solution
Questions # 234:

Which of the following is the MOST useful information for prioritizing risk mitigation?

Options:

A.

Cost of risk mitigation


B.

Asset criticality


C.

Acceptable risk level


D.

Business impact assessment


Expert Solution
Questions # 235:

An organization is participating in an industry benchmarking study that involves providing customer transaction records for analysis Which of the following is the MOST important control to ensure the privacy of customer information?

Options:

A.

Nondisclosure agreements (NDAs)


B.

Data anonymization


C.

Data cleansing


D.

Data encryption


Expert Solution
Questions # 236:

An organization has asked an IT risk practitioner to conduct an operational risk assessment on an initiative to outsource the organization ' s customer service operations overseas. Which of the following would MOST significantly impact management ' s decision?

Options:

A.

Time zone difference of the outsourcing location


B.

Ongoing financial viability of the outsourcing company


C.

Cross-border information transfer restrictions in the outsourcing country


D.

Historical network latency between the organization and outsourcing location


Expert Solution
Questions # 237:

Which of these documents is MOST important to request from a cloud service

provider during a vendor risk assessment?

Options:

A.

Nondisclosure agreement (NDA)


B.

Independent audit report


C.

Business impact analysis (BIA)


D.

Service level agreement (SLA)


Expert Solution
Questions # 238:

During an organization ' s simulated phishing email campaign, which of the following is the BEST indicator of a mature security awareness program?

Options:

A.

A high number of participants reporting the email


B.

A high number of participants deleting the email


C.

A low number of participants with questions for the help desk


D.

A low number of participants opening the email


Expert Solution
Questions # 239:

Which of the following is the FIRST step in risk assessment?

Options:

A.

Review risk governance


B.

Asset identification


C.

Identify risk factors


D.

Inherent risk identification


Expert Solution
Questions # 240:

Which of the following would BEST help to determine the inherent risk associated with a cloud service provider?

Options:

A.

Cloud access security broker (CASB).


B.

Cloud service configuration.


C.

Cloud service attestation.


D.

Cloud service level agreement (SLA).


Expert Solution
Questions # 241:

Which of the following BEST indicates that an organization has implemented IT performance requirements?

Options:

A.

Service level agreements(SLA)


B.

Vendor references


C.

Benchmarking data


D.

Accountability matrix


Expert Solution
Questions # 242:

Which of the following is a risk practitioner ' s MOST important action to reduce the likelihood of internal fraud?

Options:

A.

Recommend fraud awareness training for staff


B.

Communicate legal consequences for internal fraud.


C.

Update the internal fraud risk likelihood in the risk register.


D.

Verify the effectiveness of separation of duties.


Expert Solution
Questions # 243:

The BEST metric to demonstrate that servers are configured securely is the total number of servers:

Options:

A.

exceeding availability thresholds


B.

experiencing hardware failures


C.

exceeding current patching standards.


D.

meeting the baseline for hardening.


Expert Solution
Questions # 244:

Business management is seeking assurance from the CIO that IT has a plan in place for early identification of potential issues that could impact the delivery of a new application Which of the following is the BEST way to increase the chances of a successful delivery ' ?

Options:

A.

Implement a release and deployment plan


B.

Conduct comprehensive regression testing.


C.

Develop enterprise-wide key risk indicators (KRls)


D.

Include business management on a weekly risk and issues report


Expert Solution
Questions # 245:

Which of the following would be MOST helpful in assessing the risk associated with data loss due to human vulnerabilities?

Options:

A.

Reviewing password change history


B.

Performing periodic access recertification


C.

Conducting social engineering exercises


D.

Reviewing the results of security awareness surveys


Expert Solution
Questions # 246:

Which of the following is the BEST way to incorporate continuous monitoring in IT risk policies?

Options:

A.

Standardize IT risk mitigation for better monitoring of IT risk.


B.

Define how risk thresholds are aligned with organizational objectives.


C.

Establish a cross-functional risk steering committee to oversee risk initiatives.


D.

Implement a governance, risk, and compliance (GRC) tool.


Expert Solution
Questions # 247:

In response to the threat of ransomware, an organization has implemented cybersecurity awareness activities. The risk practitioner ' s BEST recommendation to further reduce the impact of ransomware attacks would be to implement:

Options:

A.

two-factor authentication.


B.

continuous data backup controls.


C.

encryption for data at rest.


D.

encryption for data in motion.


Expert Solution
Questions # 248:

Which of the following is the PRIMARY role of the first line of defense with respect to information security policies?

Options:

A.

Draft the information security policy.


B.

Approve the information security policy.


C.

Audit the implementation of the information security policy.


D.

Implement controls in response to the policy requirements.


Expert Solution
Questions # 249:

Which of the following is the MOST effective way for a large and diversified organization to minimize risk associated with unauthorized software on company devices?

Options:

A.

Scan end points for applications not included in the asset inventory.


B.

Prohibit the use of cloud-based virtual desktop software.


C.

Conduct frequent reviews of software licenses.


D.

Perform frequent internal audits of enterprise IT infrastructure.


Expert Solution
Questions # 250:

An organization has implemented a system capable of comprehensive employee monitoring. Which of the following should direct how the system is used?

Options:

A.

Organizational strategy


B.

Employee code of conduct


C.

Industry best practices


D.

Organizational policy


Expert Solution
Viewing page 5 out of 12 pages
Viewing questions 201-250 out of questions