Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 7 out of 12 pages
Viewing questions 301-350 out of questions
Questions # 301:

Which of the following provides the MOST useful information to trace the impact of aggregated risk across an organization ' s technical environment?

Options:

A.

Business case documentation


B.

Organizational risk appetite statement


C.

Enterprise architecture (EA) documentation


D.

Organizational hierarchy


Expert Solution
Questions # 302:

Which of the following emerging technologies is frequently used for botnet distributed denial of service (DDoS) attacks?

Options:

A.

Internet of Things (IoT)


B.

Quantum computing


C.

Virtual reality (VR)


D.

Machine learning


Expert Solution
Questions # 303:

An organization wants to launch a campaign to advertise a new product Using data analytics, the campaign can be targeted to reach potential customers. Which of the following should be of GREATEST concern to the risk practitioner?

Options:

A.

Data minimization


B.

Accountability


C.

Accuracy


D.

Purpose limitation


Expert Solution
Questions # 304:

Which of the following is the PRIMARY consideration when determining the impact to an organization after the discovery of malware on an endpoint device?

Options:

A.

Asset criticality and sensitivity


B.

Currency of anti-malware signatures


C.

Availability of patches and security updates


D.

Currency of the incident response plan


Expert Solution
Questions # 305:

When reporting on the performance of an organization ' s control environment including which of the following would BEST inform stakeholders risk decision-making?

Options:

A.

The audit plan for the upcoming period


B.

Spend to date on mitigating control implementation


C.

A report of deficiencies noted during controls testing


D.

A status report of control deployment


Expert Solution
Questions # 306:

An organization has implemented a policy requiring staff members to take a minimum of five consecutive days ' leave per year to mitigate the risk of malicious insider activities. Which of the following is the BEST key performance indicator (KPI) of the effectiveness of this policy?

Options:

A.

Percentage of staff turnover following five consecutive days of leave


B.

Average number of consecutive days of leave per staff member


C.

Number of suspected malicious activities reported since policy implementation


D.

Financial loss incurred due to malicious activities since policy implementation


Expert Solution
Questions # 307:

Which of the following is the BEST control to detect an advanced persistent threat (APT)?

Options:

A.

Utilizing antivirus systems and firewalls


B.

Conducting regular penetration tests


C.

Monitoring social media activities


D.

Implementing automated log monitoring


Expert Solution
Questions # 308:

Who should be accountable for monitoring the control environment to ensure controls are effective?

Options:

A.

Risk owner


B.

Security monitoring operations


C.

Impacted data owner


D.

System owner


Expert Solution
Questions # 309:

Which of the following would BEST help identify the owner for each risk scenario in a risk register?

Options:

A.

Determining which departments contribute most to risk


B.

Allocating responsibility for risk factors equally to asset owners


C.

Mapping identified risk factors to specific business processes


D.

Determining resource dependency of assets


Expert Solution
Questions # 310:

Which of the following provides the MOST insight regarding an organization ' s risk culture?

Options:

A.

Awareness training participation rate


B.

Risk assessment results


C.

Senior management interviews


D.

Risk management framework


Expert Solution
Questions # 311:

Which of the following is MOST likely to be impacted when a global organization is required by law to implement a new data protection regulation across its operations?

Options:

A.

Risk ownership assignments


B.

Threat profile


C.

Vulnerability assessment results


D.

Risk profile


Expert Solution
Questions # 312:

An information system for a key business operation is being moved from an in-house application to a Software as a Service (SaaS) vendor. Which of the following will have the GREATEST impact on the ability to monitor risk?

Options:

A.

Reduced ability to evaluate key risk indicators (KRIs)


B.

Reduced access to internal audit reports


C.

Dependency on the vendor ' s key performance indicators (KPIs)


D.

Dependency on service level agreements (SLAs)


Expert Solution
Questions # 313:

During testing, a risk practitioner finds the IT department ' s recovery time objective (RTO) for a key system does not align with the enterprise ' s business continuity plan (BCP). Which of the following should be done NEXT?

Options:

A.

Report the gap to senior management


B.

Consult with the IT department to update the RTO


C.

Complete a risk exception form.


D.

Consult with the business owner to update the BCP


Expert Solution
Questions # 314:

Which of the following is the BEST metric to demonstrate the effectiveness of an organization’s software testing program?

Options:

A.

Average time to complete software test cases


B.

Percentage of applications with defined business cases


C.

Number of incidents resulting from software changes


D.

Percentage of staff completing software development training


Expert Solution
Questions # 315:

Which of the following management action will MOST likely change the likelihood rating of a risk scenario related to remote network access?

Options:

A.

Updating the organizational policy for remote access


B.

Creating metrics to track remote connections


C.

Implementing multi-factor authentication


D.

Updating remote desktop software


Expert Solution
Questions # 316:

A global organization has implemented an application that does not address all privacy requirements across multiple jurisdictions. Which of the following risk responses has the organization adopted with regard to privacy requirements?

Options:

A.

Risk avoidance


B.

Risk transfer


C.

Risk mitigation


D.

Risk acceptance


Expert Solution
Questions # 317:

Which of the following should be the PRIMARY goal of developing information security metrics?

Options:

A.

Raising security awareness


B.

Enabling continuous improvement


C.

Identifying security threats


D.

Ensuring regulatory compliance


Expert Solution
Questions # 318:

Which of the following is the MAIN benefit of involving stakeholders in the selection of key risk indicators (KRIs)?

Options:

A.

Improving risk awareness


B.

Obtaining buy-in from risk owners


C.

Leveraging existing metrics


D.

Optimizing risk treatment decisions


Expert Solution
Questions # 319:

The following is the snapshot of a recently approved IT risk register maintained by an organization ' s information security department.

Question # 319

After implementing countermeasures listed in ‘’Risk Response Descriptions’’ for each of the Risk IDs, which of the following component of the register MUST change?

Options:

A.

Risk Impact Rating


B.

Risk Owner


C.

Risk Likelihood Rating


D.

Risk Exposure


Expert Solution
Questions # 320:

A monthly payment report is generated from the enterprise resource planning (ERP) software to validate data against the old and new payroll systems. What is the BEST way to mitigate the risk associated with data integrity loss in the new payroll system after data migration?

Options:

A.

Compare new system reports with functional requirements.


B.

Compare encrypted data with checksums.


C.

Compare results of user acceptance testing (UAT) with the testing criteria.


D.

Compare processing output from both systems using the previous month ' s data.


Expert Solution
Questions # 321:

When developing a business continuity plan (BCP), it is MOST important to:

Options:

A.

identify an alternative location to host operations.


B.

identify a geographically dispersed disaster recovery site.


C.

prioritize critical services to be restored.


D.

develop a multi-channel communication plan.


Expert Solution
Questions # 322:

Which of the following provides the MOST up-to-date information about the effectiveness of an organization ' s overall IT control environment?

Options:

A.

Key performance indicators (KPIs)


B.

Risk heat maps


C.

Internal audit findings


D.

Periodic penetration testing


Expert Solution
Questions # 323:

What is the PRIMARY reason an organization should include background checks on roles with elevated access to production as part of its hiring process?

Options:

A.

Reduce internal threats


B.

Reduce exposure to vulnerabilities


C.

Eliminate risk associated with personnel


D.

Ensure new hires have the required skills


Expert Solution
Questions # 324:

Which of the following is the MOST appropriate risk owner for a payroll application that has recently been outsourced to a cloud software provider?

Options:

A.

IT executive.


B.

HR executive.


C.

Vendor management executive.


D.

Cloud service provider’s information security executive.


Expert Solution
Questions # 325:

Which of the following is the BEST way to quantify the likelihood of risk materialization?

Options:

A.

Balanced scorecard


B.

Threat and vulnerability assessment


C.

Compliance assessments


D.

Business impact analysis (BIA)


Expert Solution
Questions # 326:

Which of the following BEST enables effective risk reporting to the board of directors?

Options:

A.

Presenting case studies of breaches from other similar organizations


B.

Mapping risk scenarios to findings identified by internal audit


C.

Communicating in terms that correlate to corporate objectives and business value


D.

Reporting key metrics that indicate the efficiency and effectiveness of risk governance


Expert Solution
Questions # 327:

During an acquisition, which of the following would provide the MOST useful input to the parent company ' s risk practitioner when developing risk scenarios for the post-acquisition phase?

Options:

A.

Risk management framework adopted by each company


B.

Risk registers of both companies


C.

IT balanced scorecard of each company


D.

Most recent internal audit findings from both companies


Expert Solution
Questions # 328:

Which of the following is the BEST recommendation when a key risk indicator (KRI) is generating an excessive volume of events?

Options:

A.

Reevaluate the design of the KRIs.


B.

Develop a corresponding key performance indicator (KPI).


C.

Monitor KRIs within a specific timeframe.


D.

Activate the incident response plan.


Expert Solution
Questions # 329:
Options:

A.

Conduct frequent internal audits of IT systems.


B.

Review information from threat intelligence sources.


C.

Define a comprehensive set of key risk indicators (KRIs).


D.

Document thorough IT risk scenarios in the risk register.


Expert Solution
Questions # 330:

An application development team has a backlog of user requirements for a new system that will process insurance claim payments for customers. Which of the following should be the MOST important consideration for a risk-based review of the user requirements?

Options:

A.

Number of claims affected by the user requirements


B.

Number of customers impacted


C.

Impact to the accuracy of claim calculation


D.

Level of resources required to implement the user requirements


Expert Solution
Questions # 331:

Which of the following should be of GREATEST concern when reviewing the results of an independent control assessment to determine the effectiveness of a vendor ' s control environment?

Options:

A.

The report was provided directly from the vendor.


B.

The risk associated with multiple control gaps was accepted.


C.

The control owners disagreed with the auditor ' s recommendations.


D.

The controls had recurring noncompliance.


Expert Solution
Questions # 332:

Which of the following is the PRIMARY goal of enterprise architecture (EA)?

Options:

A.

To document all implemented systems reflecting the architectural views relevant to the IT team


B.

To provide a vision of the future state and generate strategy to move from current to future state


C.

To implement a governance framework that aligns with the desired organizational structure


D.

To develop and design a technology framework to be used by all IT staff within the organization


Expert Solution
Questions # 333:

Which of the following is the MOST useful information for a risk practitioner when planning response activities after risk identification?

Options:

A.

Risk register


B.

Risk appetite


C.

Risk priorities


D.

Risk heat maps


Expert Solution
Questions # 334:

A risk practitioner has been notified that an employee sent an email in error containing customers ' personally identifiable information (Pll). Which of the following is the risk practitioner ' s BEST course of action?

Options:

A.

Report it to the chief risk officer.


B.

Advise the employee to forward the email to the phishing team.


C.

follow incident reporting procedures.


D.

Advise the employee to permanently delete the email.


Expert Solution
Questions # 335:

Which of the following is the BEST method to identify unnecessary controls?

Options:

A.

Evaluating the impact of removing existing controls


B.

Evaluating existing controls against audit requirements


C.

Reviewing system functionalities associated with business processes


D.

Monitoring existing key risk indicators (KRIs)


Expert Solution
Questions # 336:

Which of the following is the GREATEST concern associated with redundant data in an organization ' s inventory system?

Options:

A.

Poor access control


B.

Unnecessary data storage usage


C.

Data inconsistency


D.

Unnecessary costs of program changes


Expert Solution
Questions # 337:

Which of the following is the BEST indication of an improved risk-aware culture following the implementation of a security awareness training program for all employees?

Options:

A.

A reduction in the number of help desk calls


B.

An increase in the number of identified system flaws


C.

A reduction in the number of user access resets


D.

An increase in the number of incidents reported


Expert Solution
Questions # 338:

An organization with a large number of applications wants to establish a security risk assessment program. Which of the following would provide the MOST useful information when determining the frequency of risk assessments?

Options:

A.

Feedback from end users


B.

Results of a benchmark analysis


C.

Recommendations from internal audit


D.

Prioritization from business owners


Expert Solution
Questions # 339:

Mapping open risk issues to an enterprise risk heat map BEST facilitates:

Options:

A.

risk response.


B.

control monitoring.


C.

risk identification.


D.

risk ownership.


Expert Solution
Questions # 340:

Which of the following is the MOST important characteristic of a key risk indicator (KRI) to enable decision-making?

Options:

A.

Monitoring the risk until the exposure is reduced


B.

Setting minimum sample sizes to ensure accuracy


C.

Listing alternative causes for risk events


D.

Illustrating changes in risk trends


Expert Solution
Questions # 341:

Which of the following is the MOST effective way to integrate business risk management with IT operations?

Options:

A.

Perform periodic IT control self-assessments.


B.

Require a risk assessment with change requests.


C.

Provide security awareness training.


D.

Perform periodic risk assessments.


Expert Solution
Questions # 342:

Which of the following is the GREATEST benefit of identifying appropriate risk owners?

Options:

A.

Accountability is established for risk treatment decisions


B.

Stakeholders are consulted about risk treatment options


C.

Risk owners are informed of risk treatment options


D.

Responsibility is established for risk treatment decisions.


Expert Solution
Questions # 343:

A data processing center operates in a jurisdiction where new regulations have significantly increased penalties for data breaches. Which of the following elements of the risk register is MOST important to update to reflect this change?

Options:

A.

Risk impact


B.

Risk trend


C.

Risk appetite


D.

Risk likelihood


Expert Solution
Questions # 344:

Management has required information security awareness training to reduce the risk associated with credential compromise. What is the BEST way to assess the effectiveness of the training?

Options:

A.

Conduct social engineering testing.


B.

Audit security awareness training materials.


C.

Administer an end-of-training quiz.


D.

Perform a vulnerability assessment.


Expert Solution
Questions # 345:

A risk practitioner is summarizing the results of a high-profile risk assessment sponsored by senior management. The BEST way to support risk-based decisions by senior management would be to:

Options:

A.

map findings to objectives.


B.

provide quantified detailed analysis


C.

recommend risk tolerance thresholds.


D.

quantify key risk indicators (KRls).


Expert Solution
Questions # 346:

Which of the following events is MOST likely to trigger the need to conduct a risk assessment?

Options:

A.

An incident resulting in data loss


B.

Changes in executive management


C.

Updates to the information security policy


D.

Introduction of a new product line


Expert Solution
Questions # 347:

An application runs a scheduled job that compiles financial data from multiple business systems and updates the financial reporting system. If this job runs too long, it can delay financial reporting. Which of the following is the risk practitioner ' s BEST recommendation?

Options:

A.

Implement database activity and capacity monitoring.


B.

Ensure the business is aware of the risk.


C.

Ensure the enterprise has a process to detect such situations.


D.

Consider providing additional system resources to this job.


Expert Solution
Questions # 348:

A maturity model will BEST indicate:

Options:

A.

confidentiality and integrity.


B.

effectiveness and efficiency.


C.

availability and reliability.


D.

certification and accreditation.


Expert Solution
Questions # 349:

Which of the following should be the MOST important consideration when performing a vendor risk assessment?

Options:

A.

Results of the last risk assessment of the vendor


B.

Inherent risk of the business process supported by the vendor


C.

Risk tolerance of the vendor


D.

Length of time since the last risk assessment of the vendor


Expert Solution
Questions # 350:

An organization is planning to move its application infrastructure from on-premises to the cloud. Which of the following is the BEST course of the actin to address the risk associated with data transfer if the relationship is terminated with the vendor?

Options:

A.

Meet with the business leaders to ensure the classification of their transferred data is in place


B.

Ensure the language in the contract explicitly states who is accountable for each step of the data transfer process


C.

Collect requirements for the environment to ensure the infrastructure as a service (IaaS) is configured appropriately.


D.

Work closely with the information security officer to ensure the company has the proper security controls in place.


Expert Solution
Viewing page 7 out of 12 pages
Viewing questions 301-350 out of questions