Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CRISC Questions and answers with CertsForce

Viewing page 9 out of 12 pages
Viewing questions 401-450 out of questions
Questions # 401:

It is MOST important to the effectiveness of an IT risk management function that the associated processes are:

Options:

A.

aligned to an industry-accepted framework.


B.

reviewed and approved by senior management.


C.

periodically assessed against regulatory requirements.


D.

updated and monitored on a continuous basis.


Expert Solution
Questions # 402:

Which of the following should a risk practitioner recommend FIRST when an increasing trend of risk events and subsequent losses has been identified?

Options:

A.

Conduct root cause analyses for risk events.


B.

Educate personnel on risk mitigation strategies.


C.

Integrate the risk event and incident management processes.


D.

Implement controls to prevent future risk events.


Expert Solution
Questions # 403:

Which of the following is the BEST evidence that a user account has been properly authorized?

Options:

A.

An email from the user accepting the account


B.

Notification from human resources that the account is active


C.

User privileges matching the request form


D.

Formal approval of the account by the user ' s manager


Expert Solution
Questions # 404:

Which of the following is the PRIMARY benefit of implementing key control indicators (KCIs)?

Options:

A.

Confirming the adequacy of recovery plans.


B.

Improving compliance with control standards.


C.

Providing early detection of control degradation.


D.

Reducing the number of incidents.


Expert Solution
Questions # 405:

Which of the following is the BEST way to ensure data is properly sanitized while in cloud storage?

Options:

A.

Deleting the data from the file system


B.

Cryptographically scrambling the data


C.

Formatting the cloud storage at the block level


D.

Degaussing the cloud storage media


Expert Solution
Questions # 406:

Which of the following BEST indicates that an organization ' s risk management processes are mature?

Options:

A.

Risk policy is approved and communicated by the risk manager


B.

Annual risk awareness training is conducted by risk owners


C.

Risk principles are embedded within business operations and decisions


D.

The board regularly follows up on risk status and action plans


Expert Solution
Questions # 407:

Which of the following is the FIRST step in managing the risk associated with the leakage of confidential data?

Options:

A.

Maintain and review the classified data inventor.


B.

Implement mandatory encryption on data


C.

Conduct an awareness program for data owners and users.


D.

Define and implement a data classification policy


Expert Solution
Questions # 408:

A financial institution has identified high risk of fraud in several business applications. Which of the following controls will BEST help reduce the risk of fraudulent internal transactions?

Options:

A.

Periodic user privileges review


B.

Log monitoring


C.

Periodic internal audits


D.

Segregation of duties


Expert Solution
Questions # 409:

Which of the following is the BEST approach for selecting controls to minimize risk?

Options:

A.

Industry best practice review


B.

Risk assessment


C.

Cost-benefit analysis


D.

Control-effectiveness evaluation


Expert Solution
Questions # 410:

Which of the following risk activities is BEST facilitated by enterprise architecture (EA)?

Options:

A.

Aligning business unit risk responses to organizational priorities


B.

Determining attack likelihood per business unit


C.

Adjusting business unit risk tolerances


D.

Customizing incident response plans for each business unit


Expert Solution
Questions # 411:

The PRIMARY advantage of implementing an IT risk management framework is the:

Options:

A.

establishment of a reliable basis for risk-aware decision making.


B.

compliance with relevant legal and regulatory requirements.


C.

improvement of controls within the organization and minimized losses.


D.

alignment of business goals with IT objectives.


Expert Solution
Questions # 412:

The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:

Options:

A.

obtain the support of executive management.


B.

map the business processes to supporting IT and other corporate resources.


C.

identify critical business processes and the degree of reliance on support services.


D.

document the disaster recovery process.


Expert Solution
Questions # 413:

A new regulator/ requirement imposes severe fines for data leakage involving customers ' personally identifiable information (Pll). The risk practitioner has recommended avoiding the risk. Which of the following actions would BEST align with this recommendation?

Options:

A.

Reduce retention periods for Pll data.


B.

Move Pll to a highly-secured outsourced site.


C.

Modify business processes to stop collecting Pll.


D.

Implement strong encryption for Pll.


Expert Solution
Questions # 414:

Which of the following would be MOST helpful when estimating the likelihood of negative events?

Options:

A.

Business impact analysis


B.

Threat analysis


C.

Risk response analysis


D.

Cost-benefit analysis


Expert Solution
Questions # 415:

Which of the following is MOST important to the effectiveness of a senior oversight committee for risk monitoring?

Options:

A.

Key risk indicators (KRIs)


B.

Risk governance charter


C.

Organizational risk appetite


D.

Cross-business representation


Expert Solution
Questions # 416:

The PRIMARY advantage of involving end users in continuity planning is that they:

Options:

A.

have a better understanding of specific business needs


B.

can balance the overall technical and business concerns


C.

can see the overall impact to the business


D.

are more objective than information security management.


Expert Solution
Questions # 417:

Which of the following is MOST important for managing ethical risk?

Options:

A.

Involving senior management in resolving ethical disputes


B.

Developing metrics to trend reported ethics violations


C.

Identifying the ethical concerns of each stakeholder


D.

Establishing a code of conduct for employee behavior


Expert Solution
Questions # 418:

Which of the following is the MOST important reason to communicate control effectiveness to senior management?

Options:

A.

To demonstrate alignment with industry best practices


B.

To assure management that control ownership is assigned


C.

To ensure management understands the current risk status


D.

To align risk management with strategic objectives


Expert Solution
Questions # 419:

Which of the following should a risk practitioner recommend FIRST when a risk assessment identifies the exposure of a significant number of personal customer records in a database?

Options:

A.

Revise the information security policy.


B.

Invoke the incident response plan (IRP).


C.

Update the risk register.


D.

Escalate the issue to senior management.


Expert Solution
Questions # 420:

An organization has established a contract with a vendor that includes penalties for loss of availability. Which risk treatment has been adopted by the organization?

Options:

A.

Acceptance


B.

Avoidance


C.

Transfer


D.

Reduction


Expert Solution
Questions # 421:

Which of the following key risk indicators (KRIs) provides the BEST insight into the risk associated with IT systems being unable to meet the required availability service level in the future?

Options:

A.

Percentage of IT systems having defined incident management service levels


B.

Percentage of IT systems having met the availability service level


C.

Percentage of IT outsourced systems having met the availability service level


D.

Percentage of IT systems routinely running at peak utilization


Expert Solution
Questions # 422:

Establishing and organizational code of conduct is an example of which type of control?

Options:

A.

Preventive


B.

Directive


C.

Detective


D.

Compensating


Expert Solution
Questions # 423:

During which phase of the system development life cycle (SDLC) should information security requirements for the implementation of a new IT system be defined?

Options:

A.

Monitoring


B.

Development


C.

Implementation


D.

Initiation


Expert Solution
Questions # 424:

Vulnerabilities have been detected on an organization ' s systems. Applications installed on these systems will not operate if the underlying servers are updated. Which of the following is the risk practitioner ' s BEST course of action?

Options:

A.

Recommend the business change the application.


B.

Recommend a risk treatment plan.


C.

Include the risk in the next quarterly update to management.


D.

Implement compensating controls.


Expert Solution
Questions # 425:

An organization is implementing data warehousing infrastructure. Senior management is concerned about safeguarding client data security in this new environment. Which of the following should the risk practitioner recommend be done NEXT?

Options:

A.

Ensure a role-based access control (RBAC) model is implemented.


B.

Perform a gap analysis regarding the organization ' s client data access model.


C.

Ensure an attribute-based access control model is implemented.


D.

Establish new controls addressing a consistently applied data access model.


Expert Solution
Questions # 426:

Which of the following practices BEST mitigates risk related to enterprise-wide ethical decision making in a multi-national organization?

Options:

A.

Customized regional training on local laws and regulations


B.

Policies requiring central reporting of potential procedure exceptions


C.

Ongoing awareness training to support a common risk culture


D.

Zero-tolerance policies for risk taking by middle-level managers


Expert Solution
Questions # 427:

Which of the following is the MOST effective control to maintain the integrity of system configuration files?

Options:

A.

Recording changes to configuration files


B.

Implementing automated vulnerability scanning


C.

Restricting access to configuration documentation


D.

Monitoring against the configuration standard


Expert Solution
Questions # 428:

An organization operates in an environment where reduced time-to-market for new software products is a top business priority. Which of the following should be the risk practitioner ' s GREATEST concern?

Options:

A.

Sufficient resources are not assigned to IT development projects.


B.

Customer support help desk staff does not have adequate training.


C.

Email infrastructure does not have proper rollback plans.


D.

The corporate email system does not identify and store phishing emails.


Expert Solution
Questions # 429:

Which of the following is the PRIMARY reason to compare the business impact analysis (BIA) against the organization ' s business continuity plan (BCP)?

Options:

A.

The results of the BIA quantify the BCP objectives and supporting technology for each operational area.


B.

The BCP provides detailed information on alternative facilities to use in case of business interruptions.


C.

The results of the BIA quantify the cost of the technology environment needed to restart each operational area.


D.

The BCP provides the backup and restoration procedures to follow in case of business interruptions.


Expert Solution
Questions # 430:

Which of the following is MOST important for mitigating ethical risk when establishing accountability for control ownership?

Options:

A.

Ensuring processes are documented to enable effective control execution


B.

Ensuring regular risk messaging is Included in business communications from leadership


C.

Ensuring schedules and deadlines for control-related deliverables are strictly monitored


D.

Ensuring performance metrics balance business goals with risk appetite


Expert Solution
Questions # 431:

Which of the following should be done FIRST upon learning that the organization will be affected by a new regulation in its industry?

Options:

A.

Transfer the risk.


B.

Perform a gap analysis.


C.

Determine risk appetite for the new regulation.


D.

Implement specific monitoring controls.


Expert Solution
Questions # 432:

In the three lines of defense model, a PRIMARY objective of the second line is to:

Options:

A.

Review and evaluate the risk management program.


B.

Ensure risk and controls are effectively managed.


C.

Implement risk management policies regarding roles and responsibilities.


D.

Act as the owner for any operational risk identified as part of the risk program.


Expert Solution
Questions # 433:

Which of the following is the MOST essential characteristic of a good IT risk scenario?

Options:

A.

The scenario is aligned to business control processes.


B.

The scenario is aligned to the organization’s risk appetite and tolerance.


C.

The scenario is aligned to a business objective.


D.

The scenario is aligned to known vulnerabilities in information technology.


Expert Solution
Questions # 434:

Which of the following metrics is BEST used to communicate to senior management that the control environment manages risk within appetite and tolerance?

Options:

A.

Number of security incidents


B.

Reduction in control expenditures


C.

Number of risk responses executed


D.

Reduction in residual risk


Expert Solution
Questions # 435:

Which of the following is the BEST way to address IT regulatory compliance risk?

Options:

A.

Assign highest priority to remediation of related risk scenarios.


B.

Prevent acceptance of related risk scenarios.


C.

Conduct specialized business impact analyses (BIAs).


D.

Manage risk like other types of operational risk.


Expert Solution
Questions # 436:

An organization is subject to a new regulation that requires nearly real-time recovery of its services following a disruption. Which of the following is the BEST way to manage the risk in this situation?

Options:

A.

Move redundant IT infrastructure to a closer location.


B.

Obtain insurance and ensure sufficient funds are available for disaster recovery.


C.

Review the business continuity plan (BCP) and align it with the new business needs.


D.

Outsource disaster recovery services to a third-party IT service provider.


Expert Solution
Questions # 437:

Which of the following is the BEST approach for a risk practitioner to use for identifying the level of technical debt in an organization?

Options:

A.

Review business cases for large organizational projects.


B.

Measure the alignment of technical standards with information security policies.


C.

Analyze trends in technology investments over time.


D.

Compare the current state to the target enterprise architecture (EA).


Expert Solution
Questions # 438:

After conducting a risk assessment for regulatory compliance, an organization has identified only one possible mitigating control. The cost of the control has been determined to be higher than the penalty of noncompliance. Which of the following would be the risk practitioner ' s BEST recommendation?

Options:

A.

Accept the risk with management sign-off.


B.

Ignore the risk until the regulatory body conducts a compliance check.


C.

Mitigate the risk with the identified control.


D.

Transfer the risk by buying insurance.


Expert Solution
Questions # 439:

Owners of technical controls should be PRIMARILY accountable for ensuring the controls are:

Options:

A.

Mapped to the corresponding business areas.


B.

Aligned with corporate security policies.


C.

Effectively implemented and maintained.


D.

Designed based on standards and frameworks.


Expert Solution
Questions # 440:

An updated report from a trusted research organization shows that attacks have increased in the organization ' s industry segment. What should be done FIRST to integrate this data into risk assessments?

Options:

A.

Average the ransomware attack frequencies together


B.

Revise the threat frequency for ransomware attack types


C.

Adjust impact amounts based on the average ransom


D.

Use the new frequency as the maximum value in a Monte Carlo simulation


Expert Solution
Questions # 441:

An organization is reviewing a contract for a Software as a Service (SaaS) sales application with a 99.9% uptime service level agreement (SLA). Which of the following BEST describes ownership of availability risk?

Options:

A.

The risk is shared by both organizations.


B.

The liability for the risk is owned by the cloud provider.


C.

The risk is transferred to the cloud provider.


D.

The liability for the risk is owned by the sales department.


Expert Solution
Questions # 442:

Which of the following should be the PRIMARY basis for prioritizing risk responses?

Options:

A.

The impact of the risk


B.

The replacement cost of the business asset


C.

The cost of risk mitigation controls


D.

The classification of the business asset


Expert Solution
Questions # 443:

The PRIMARY purpose of vulnerability assessments is to:

Options:

A.

provide clear evidence that the system is sufficiently secure.


B.

determine the impact of potential threats.


C.

test intrusion detection systems (IDS) and response procedures.


D.

detect weaknesses that could lead to system compromise.


Expert Solution
Questions # 444:

An organization has recently been experiencing frequent data corruption incidents. Implementing a file corruption detection tool as a risk response strategy will help to:

Options:

A.

reduce the likelihood of future events


B.

restore availability


C.

reduce the impact of future events


D.

address the root cause


Expert Solution
Questions # 445:

The PRIMARY objective of a risk identification process is to:

Options:

A.

evaluate how risk conditions are managed.


B.

determine threats and vulnerabilities.


C.

estimate anticipated financial impact of risk conditions.


D.

establish risk response options.


Expert Solution
Questions # 446:

Which of the following would BEST help an enterprise prioritize risk scenarios?

Options:

A.

Industry best practices


B.

Placement on the risk map


C.

Degree of variances in the risk


D.

Cost of risk mitigation


Expert Solution
Questions # 447:

Which of the following BEST describes the role of the IT risk profile in strategic IT-related decisions?

Options:

A.

It compares performance levels of IT assets to value delivered.


B.

It facilitates the alignment of strategic IT objectives to business objectives.


C.

It provides input to business managers when preparing a business case for new IT projects.


D.

It helps assess the effects of IT decisions on risk exposure


Expert Solution
Questions # 448:

Which of the following is the BEST approach for determining whether a risk action plan is effective?

Options:

A.

Comparing the remediation cost against budget


B.

Assessing changes in residual risk


C.

Assessing the inherent risk


D.

Monitoring changes of key performance indicators(KPIs)


Expert Solution
Questions # 449:

An organization is implementing Zero Trust architecture to improve its security posture. Which of the following is the MOST important input to develop the architecture?

Options:

A.

Cloud services risk assessments


B.

The organization ' s threat model


C.

Access control logs


D.

Multi-factor authentication (MFA) architecture


Expert Solution
Questions # 450:

The patch management process is MOST effectively monitored through which of the following key control indicators (KCIs)?

Options:

A.

Number of legacy servers out of support


B.

Percentage of patches deployed within the target time frame


C.

Number of patches deployed outside of business hours


D.

Percentage of patched systems tested


Expert Solution
Viewing page 9 out of 12 pages
Viewing questions 401-450 out of questions