Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 6 out of 12 pages
Viewing questions 251-300 out of questions
Questions # 251:

Optimized risk management is achieved when risk is reduced:

Options:

A.

with strategic initiatives.


B.

to meet risk appetite.


C.

within resource availability.


D.

below risk appetite.


Expert Solution
Questions # 252:

Which of the following is the BEST key control indicator (KCI) for a vulnerability management program?

Options:

A.

Percentage of high-risk vulnerabilities missed


B.

Number of high-risk vulnerabilities outstanding


C.

Defined thresholds for high-risk vulnerabilities


D.

Percentage of high-risk vulnerabilities addressed


Expert Solution
Questions # 253:

Which of the following is the MOST important information to cover in a business continuity awareness training program for all employees of the organization?

Options:

A.

Recovery time objectives (RTOs)


B.

Communication plan


C.

Critical asset inventory


D.

Separation of duties


Expert Solution
Questions # 254:

A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner ' s NEXT step?

Options:

A.

Develop a mechanism for monitoring residual risk.


B.

Update the risk register with the results.


C.

Prepare a business case for the response options.


D.

Identify resources for implementing responses.


Expert Solution
Questions # 255:

Print jobs containing confidential information are sent to a shared network printer located in a secure room. Which of the following is the BEST control to prevent the inappropriate disclosure of confidential information?

Options:

A.

Requiring a printer access code for each user


B.

Using physical controls to access the printer room


C.

Using video surveillance in the printer room


D.

Ensuring printer parameters are properly configured


Expert Solution
Questions # 256:

A Software as a Service (SaaS) company wants to use aggregated data from its clients to improve its services via a machine learning (ML) model. However, its contracts do not clearly allow this use of aggregated data. What should the organization do NEXT?

Options:

A.

Request formal consent from clients to use their data.


B.

Update the organization ' s privacy policy to reflect the use of aggregated data


C.

Request internal risk acceptance from senior management.


D.

Update the organization ' s data processing agreement template.


Expert Solution
Questions # 257:

Which of the following is the GREATEST risk associated with the use of data analytics?

Options:

A.

Distributed data sources


B.

Manual data extraction


C.

Incorrect data selection


D.

Excessive data volume


Expert Solution
Questions # 258:

Which of the following BEST indicates that an organizations risk management program is effective?

Options:

A.

Fewer security incidents have been reported.


B.

The number of audit findings has decreased.


C.

Residual risk is reduced.


D.

inherent risk Is unchanged.


Expert Solution
Questions # 259:

Which of the following is the PRIMARY purpose of analyzing control effectiveness during risk analysis?

Options:

A.

To enable a control cost-benefit analysis


B.

To evaluate the risk impact


C.

To determine the likelihood of occurrence


D.

To determine the current risk level


Expert Solution
Questions # 260:

A risk practitioner implemented a process to notify management of emergency changes that may not be approved. Which of the following is the BEST way to provide this information to management?

Options:

A.

Change logs


B.

Change management meeting minutes


C.

Key control indicators (KCIs)


D.

Key risk indicators (KRIs)


Expert Solution
Questions # 261:

Which of the following is MOST helpful when determining whether a system security control is effective?

Options:

A.

Control standard operating procedures


B.

Latest security assessment


C.

Current security threat report


D.

Updated risk register


Expert Solution
Questions # 262:

Which of the following is the GREATEST risk associated with the misclassification of data?

Options:

A.

inadequate resource allocation


B.

Data disruption


C.

Unauthorized access


D.

Inadequate retention schedules


Expert Solution
Questions # 263:

A recent regulatory requirement has the potential to affect an organization ' s use of a third party to supply outsourced business services. Which of the following is the BEST course of action?

Options:

A.

Conduct a gap analysis.


B.

Terminate the outsourcing agreement.


C.

Identify compensating controls.


D.

Transfer risk to the third party.


Expert Solution
Questions # 264:

Which of the following BEST represents a critical threshold value for a key control indicator (KCI)?

Options:

A.

The value at which control effectiveness would fail


B.

Thresholds benchmarked to peer organizations


C.

A typical operational value


D.

A value that represents the intended control state


Expert Solution
Questions # 265:

A key performance indicator (KPI) has been established to monitor the number of software changes that fail and must be re-implemented. An increase in the KPI indicates an ineffective:

Options:

A.

Preventive control


B.

Administrative control


C.

Corrective control


D.

Deterrent control


Expert Solution
Questions # 266:

Which of the following is the PRIMARY role of a data custodian in the risk management process?

Options:

A.

Performing periodic data reviews according to policy


B.

Reporting and escalating data breaches to senior management


C.

Being accountable for control design


D.

Ensuring data is protected according to the classification


Expert Solution
Questions # 267:

Which of the following approaches will BEST help to ensure the effectiveness of risk awareness training?

Options:

A.

Piloting courses with focus groups


B.

Using reputable third-party training programs


C.

Reviewing content with senior management


D.

Creating modules for targeted audiences


Expert Solution
Questions # 268:

Which of the following is MOST likely to result in a major change to the overall risk profile of the organization?

Options:

A.

Changes in internal and external risk factors


B.

Changes in internal and external auditors


C.

Changes in risk appetite and risk tolerance


D.

Changes in vulnerability assessment and penetration testing


Expert Solution
Questions # 269:

Which of the following BEST prevents control gaps in the Zero Trust model when implementing in the environment?

Options:

A.

Relying on multiple solutions for Zero Trust


B.

Utilizing rapid development during implementation


C.

Establishing a robust technical architecture


D.

Starting with a large initial scope


Expert Solution
Questions # 270:

Which of the following will be MOST effective in uniquely identifying the originator of electronic transactions?

Options:

A.

Digital signature


B.

Edit checks


C.

Encryption


D.

Multifactor authentication


Expert Solution
Questions # 271:

A small organization finds it difficult to implement separation of duties necessary to mitigate the likelihood of system misuse. Which of the following would be the BEST compensating control?

Options:

A.

Undertake control self-assessments (CSAs)


B.

Require reports from staff with multiple duties


C.

Obtain independent analysis of transaction logs


D.

Assign activities to fewer employees


Expert Solution
Questions # 272:

An IT department originally planned to outsource the hosting of its data center at an overseas location to reduce operational expenses. After a risk assessment, the department has decided to keep the data center in-house. How should the risk treatment response be reflected in the risk register?

Options:

A.

Risk mitigation


B.

Risk avoidance


C.

Risk acceptance


D.

Risk transfer


Expert Solution
Questions # 273:

Which of the following should be the PRIMARY consideration for a startup organization that has decided to adopt externally-sourced security policies?

Options:

A.

Availability of policy updates and support


B.

Stakeholder buy-in of policies


C.

Applicability to business operations


D.

Compliance with local regulations


Expert Solution
Questions # 274:

When prioritizing risk response, management should FIRST:

Options:

A.

evaluate the organization s ability and expertise to implement the solution.


B.

evaluate the risk response of similar organizations.


C.

address high risk factors that have efficient and effective solutions.


D.

determine which risk factors have high remediation costs


Expert Solution
Questions # 275:

Whether the results of risk analyses should be presented in quantitative or qualitative terms should be based PRIMARILY on the:

Options:

A.

requirements of management.


B.

specific risk analysis framework being used.


C.

organizational risk tolerance


D.

results of the risk assessment.


Expert Solution
Questions # 276:

Which of the following resources is MOST helpful when creating a manageable set of IT risk scenarios?

Options:

A.

Results of current and past risk assessments


B.

Organizational strategy and objectives


C.

Lessons learned from materialized risk scenarios


D.

Internal and external audit findings


Expert Solution
Questions # 277:

Which of the following is MOST commonly compared against the risk appetite?

Options:

A.

IT risk


B.

Inherent risk


C.

Financial risk


D.

Residual risk


Expert Solution
Questions # 278:

Which of the following BEST contributes to the implementation of an effective risk response action plan?

Options:

A.

An IT tactical plan


B.

Disaster recovery and continuity testing


C.

Assigned roles and responsibilities


D.

A business impact analysis


Expert Solution
Questions # 279:

Which of the following would BEST facilitate the implementation of data classification requirements?

Options:

A.

Assigning a data owner


B.

Implementing technical control over the assets


C.

Implementing a data loss prevention (DLP) solution


D.

Scheduling periodic audits


Expert Solution
Questions # 280:

Which of the following is MOST important to consider when assessing the likelihood that a recently discovered software vulnerability will be exploited?

Options:

A.

The skill level required of a threat actor


B.

The amount of personally identifiable information (PH) disclosed


C.

The ability to detect and trace the threat action


D.

The amount of data that might be exposed by a threat action


Expert Solution
Questions # 281:

An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner ' s FIRST course of action?

Options:

A.

Determine whether the impact is outside the risk appetite.


B.

Request a formal acceptance of risk from senior management.


C.

Report the ineffective control for inclusion in the next audit report.


D.

Deploy a compensating control to address the identified deficiencies.


Expert Solution
Questions # 282:

The BEST indication that risk management is effective is when risk has been reduced to meet:

Options:

A.

risk levels.


B.

risk budgets.


C.

risk appetite.


D.

risk capacity.


Expert Solution
Questions # 283:

An organization has engaged a third party to provide an Internet gateway encryption service that protects sensitive data uploaded to a cloud service. This is an example of risk:

Options:

A.

mitigation.


B.

avoidance.


C.

transfer.


D.

acceptance.


Expert Solution
Questions # 284:

A recent vulnerability assessment of a web-facing application revealed several weaknesses. Which of the following should be done NEXT to determine the risk exposure?

Options:

A.

Code review


B.

Penetration test


C.

Gap assessment


D.

Business impact analysis (BIA)


Expert Solution
Questions # 285:

Of the following, who is accountable for ensuing the effectiveness of a control to mitigate risk?

Options:

A.

Control owner


B.

Risk manager


C.

Control operator


D.

Risk treatment owner


Expert Solution
Questions # 286:

Malware has recently affected an organization. The MOST effective way to resolve this situation and define a comprehensive risk treatment plan would be to perform:

Options:

A.

a gap analysis


B.

a root cause analysis.


C.

an impact assessment.


D.

a vulnerability assessment.


Expert Solution
Questions # 287:
Options:

A.

Conduct targeted risk assessments.


B.

Recommend management accept the low risk scenarios.


C.

Assess management ' s risk tolerance.


D.

Propose mitigating controls.


Expert Solution
Questions # 288:

The BEST way to demonstrate alignment of the risk profile with business objectives is through:

Options:

A.

risk scenarios.


B.

risk tolerance.


C.

risk policy.


D.

risk appetite.


Expert Solution
Questions # 289:

A multinational organization is considering implementing standard background checks to ' all new employees A KEY concern regarding this approach

Options:

A.

fail to identity all relevant issues.


B.

be too costly


C.

violate laws in other countries


D.

be too line consuming


Expert Solution
Questions # 290:

Which of the following controls will BEST detect unauthorized modification of data by a database administrator?

Options:

A.

Reviewing database access rights


B.

Reviewing database activity logs


C.

Comparing data to input records


D.

Reviewing changes to edit checks


Expert Solution
Questions # 291:

A business is conducting a proof of concept on a vendor ' s Al technology. Which of the following is the MOST important consideration for managing risk?

Options:

A.

Use of a non-production environment


B.

Adequate vendor support


C.

Third-party management plan


D.

Regular security updates


Expert Solution
Questions # 292:

Which stakeholders are PRIMARILY responsible for determining enterprise IT risk appetite?

Options:

A.

Audit and compliance management


B.

The chief information officer (CIO) and the chief financial officer (CFO)


C.

Enterprise risk management and business process owners


D.

Executive management and the board of directors


Expert Solution
Questions # 293:

Which of the following BEST supports the integration of IT risk management into an organization ' s strategic planning?

Options:

A.

Clearly defined organizational goals and objectives


B.

Incentive plans that reward employees based on IT risk metrics


C.

Regular organization-wide risk awareness training


D.

A comprehensive and documented IT risk management plan


Expert Solution
Questions # 294:

An organization is adopting block chain for a new financial system. Which of the following should be the GREATEST concern for a risk practitioner evaluating the system ' s production readiness?

Options:

A.

Limited organizational knowledge of the underlying technology


B.

Lack of commercial software support


C.

Varying costs related to implementation and maintenance


D.

Slow adoption of the technology across the financial industry


Expert Solution
Questions # 295:

Which organizational role should be accountable for ensuring information assets are appropriately classified?

Options:

A.

Data protection officer


B.

Chief information officer (CIO)


C.

Information asset custodian


D.

Information asset owner


Expert Solution
Questions # 296:

Which of the following is the MOST important objective of regularly presenting the project risk register to the project steering committee?

Options:

A.

To allocate budget for resolution of risk issues


B.

To determine if new risk scenarios have been identified


C.

To ensure the project timeline is on target


D.

To track the status of risk mitigation actions


Expert Solution
Questions # 297:

When implementing an IT risk management program, which of the following is the BEST time to evaluate current control effectiveness?

Options:

A.

Before defining a framework


B.

During the risk assessment


C.

When evaluating risk response


D.

When updating the risk register


Expert Solution
Questions # 298:

During a data loss incident, which role in the RACI chart would be aligned to the risk practitioner?

Options:

A.

Responsible


B.

Accountable


C.

Informed


D.

Consulted


Expert Solution
Questions # 299:

A risk practitioner is performing a risk assessment of recent external advancements in quantum computing. Which of the following would pose the GREATEST concern for the risk practitioner?

Options:

A.

The organization has not adopted Infrastructure as a Service (IaaS) for its operations


B.

The organization has incorporated blockchain technology in its operations


C.

The organization has implemented heuristics on its network firewall


D.

The organization has not reviewed its encryption standards


Expert Solution
Questions # 300:

Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of an antivirus program?

Options:

A.

Percentage of IT assets with current malware definitions


B.

Number of false positives defected over a period of time


C.

Number of alerts generated by the anti-virus software


D.

Frequency of anti-vinjs software updates


Expert Solution
Viewing page 6 out of 12 pages
Viewing questions 251-300 out of questions