Latest [Nov 16, 2021] ISACA CRISC Exam Practice Test To Gain Brilliante Result
Take a Leap Forward in Your Career by Earning ISACA CRISC
NEW QUESTION 89
When prioritizing risk response, management should FIRST:
- A. evaluate the organization s ability and expertise to implement the solution.
- B. determine which risk factors have high remediation costs
- C. evaluate the risk response of similar organizations.
- D. address high risk factors that have efficient and effective solutions.
Answer: D
NEW QUESTION 90
You are working with a vendor on your project. A stakeholder has requested a change for the project, which will add value to the project deliverables. The vendor that you're working with on the project will be affected by the change. What system can help you introduce and execute the stakeholder change request with the vendor?
- A. Schedule change control system
- B. Scope change control system
- C. Contract change control system
- D. Cost change control system
Answer: C
Explanation:
Section: Volume A
Explanation:
The contract change control system is part of the project's change control system. It addresses changes with the vendor that may affect the project contract. Change control system, a part of the configuration management system, is a collection of formal documented procedures that define how project deliverables and documentation will be controlled, changed, and approved.
Incorrect Answers:
B: The scope may change because of the stakeholder change request.
Vendor's relationship to the project, hence this choice is not the best answer.
C: The cost change control system manages changes to costs in the project.
D: There is no indication that the change could affect the project schedule.
NEW QUESTION 91
Which of the following would be the BEST justification to invest in the development of a governance, risk, and compliance (GRC) solution?
- A. Closing audit findings on a timely basis
- B. Demonstrating management commitment to mitigate risk
- C. Ensuring compliance to industry standards
- D. Facilitating risk-aware decision making by stakeholders
Answer: D
NEW QUESTION 92
Which of the following is a detective control?
- A. Limit check
- B. Access control software
- C. Rerun procedures
- D. Periodic access review
Answer: C
Explanation:
Section: Volume D
Explanation/Reference:
NEW QUESTION 93
Which of the following is the first MOST step in the risk assessment process?
- A. Identification of assets
- B. Identification of threat sources
- C. Identification of threats
- D. Identification of vulnerabilities
Answer: A
Explanation:
Section: Volume A
Explanation
Explanation:
Asset identification is the most crucial and first step in the risk assessment process. Risk identification, assessment and evaluation (analysis) should always be clearly aligned to assets. Assets can be people, processes, infrastructure, information or applications.
NEW QUESTION 94
A trusted third party service provider has determined that the risk of a client's systems being hacked is low.
Which of the following would be the client's BEST course of action?
- A. Perform their own risk assessment
- B. Implement additional controls to address the risk.
- C. Perform an independent audit of the third party.
- D. Accept the risk based on the third party's risk assessment
Answer: D
NEW QUESTION 95
Which of the following would qualify as a key performance indicator (KPI)?
- A. Aggregate risk of the organization
- B. Number of identified system vulnerabilities
- C. Number of attacks against the organization's website
- D. Number of exception requests processed in the past 90 days
Answer: B
NEW QUESTION 96
Which of the following is MOST effective in continuous risk management process improvement?
- A. Awareness training
- B. Periodic assessments
- C. Change management
- D. Policy updates
Answer: B
Explanation:
Section: Volume D
NEW QUESTION 97
An organization has recently been experiencing frequent data corruption incidents. Implementing a file corruption detection tool as a risk response strategy will help to:
- A. restore availability
- B. reduce the likelihood of future events
- C. address the root cause
- D. reduce the impact of future events
Answer: C
NEW QUESTION 98
A risk assessment has identified that an organization may not be in compliance with industry regulations. The BEST course of action would be to:
- A. identify necessary controls to ensure compliance.
- B. collaborate with management to meet compliance requirements.
- C. conduct a gap analysis against compliance criteria.
- D. modify internal assurance activities to include control validation.
Answer: C
NEW QUESTION 99
A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management the risk practitioner should explain:
- A. mitigation plans for threat events should be prepared in the current planning period.
- B. this risk scenario is equivalent to more frequent but lower impact risk scenarios.
- C. an increase in threat events could cause a loss sooner than anticipated.
- D. the current level of risk is within tolerance.
Answer: A
NEW QUESTION 100
During the initial risk identification process for a business application, it is MOST important to include which of the following stakeholders?
- A. Business process consumers
- B. Application architecture team
- C. Internal audit
- D. Business process owners
Answer: D
NEW QUESTION 101
Which of the following would be MOST helpful to a risk owner when making risk-aware decisions?
- A. Resource requirements for risk responses
- B. List of business areas affected by the risk
- C. Risk exposure expressed in business terms
- D. Recommendations for risk response options
Answer: C
NEW QUESTION 102
Which of the following is the BEST way to detect zero-day malware on an end user's workstation?
- A. Database activity monitoring
- B. An antivirus program
- C. Firewall log monitoring
- D. File integrity monitoring
Answer: B
NEW QUESTION 103
NIST SP 800-53 identifies controls in three primary classes. What are they?
- A. Technical, Administrative, and Environmental
- B. Preventative, Detective, and Corrective
- C. Technical, Operational, and Management
- D. Administrative, Technical, and Operational
Answer: C
Explanation:
Explanation/Reference:
Explanation:
NIST SP 800-53 is used to review security in any organization, that is, in reviewing physical security. The Physical and Environmental Protection family includes 19 different controls. Organizations use these controls for better physical security. These controls are reviewed to determine if they are relevant to a particular organization or not. Many of the controls described include additional references that provide more details on how to implement them. The National Institute of Standards and Technology (NIST) SP
800-53 rev 3 identifies 18 families of controls. It groups these controls into three classes:
Technical
Operational
Management
NEW QUESTION 104
Which of the following is NOT true for risk management capability maturity level 1?
- A. Risk appetite and tolerance are applied only during episodic risk assessments
- B. There is an understanding that risk is important and needs to be managed, but it is viewed as a technical issue and the business primarily considers the downside of IT risk
- C. Decisions involving risk lack credible information
- D. Risk management skills exist on an ad hoc basis, but are not actively developed
Answer: C
Explanation:
Section: Volume A
Explanation:
The enterprise with risk management capability maturity level 0 makes decisions without having much knowledge about the risk credible information. In level 1, enterprise takes decisions on the basis of risk credible information.
Incorrect Answers:
A, C, D: An enterprise's risk management capability maturity level is 1 when:
* There is an understanding that risk is important and needs to be managed, but it is viewed as a technical issue and the business primarily considers the downside of IT risk.
* Any risk identification criteria vary widely across the enterprise.
* Risk appetite and tolerance are applied only during episodic risk assessments.
* Enterprise risk policies and standards are incomplete and/or reflect only external requirements and lack defensible rationale and enforcement mechanisms.
* Risk management skills exist on an ad hoc basis, but are not actively developed.
* Ad hoc inventories of controls that are unrelated to risk are dispersed across desktop applications.
NEW QUESTION 105
Numerous media reports indicate a recently discovered technical vulnerability is being actively exploited. Which of the following would be the BEST response to this scenario?
- A. Assess the vulnerability management process.
- B. Reassess the inherent risk of the target.
- C. Conduct a vulnerability assessment.
- D. Conduct a control serf-assessment.
Answer: B
NEW QUESTION 106
Which of the following statements is true for risk analysis?
- A. Risk analysis should give more weight to the likelihood than the size of loss.
- B. Risk analysis should assume an equal degree of protection for all assets.
- C. Risk analysis should address the potential size and likelihood of loss.
- D. Risk analysis should limit the scope to a benchmark of similar companies
Answer: C
Explanation:
Section: Volume D
Explanation:
A risk analysis deals with the potential size and likelihood of loss. A risk analysis involves identifying the most probable threats to an organization and analyzing the related vulnerabilities of the organization to these threats.
A risk from an organizational perspective consists of:
* Threats to various processes of organization.
* Threats to physical and information assets.
* Likelihood and frequency of occurrence from threat.
* Impact on assets from threat and vulnerability.
* Risk analysis allows the auditor to do the following tasks :
* Identify threats and vulnerabilities to the enterprise and its information system.
* Provide information for evaluation of controls in audit planning.
* Aids in determining audit objectives.
* Supporting decision based on risks.
Incorrect Answers:
A: Assuming equal degree of protection would only be rational in the rare event that all the assets are similar in sensitivity and criticality. Hence this is not practiced in risk analysis.
B: Since the likelihood determines the size of the loss, hence both elements must be considered in the calculation.
C: A risk analysis would not normally consider the benchmark of similar companies as providing relevant information other than for comparison purposes.
NEW QUESTION 107
You work as a project manager for BlueWell Inc. You are preparing for the risk identification process. You will need to involve several of the project's key stakeholders to help you identify and communicate the identified risk events. You will also need several documents to help you and the stakeholders identify the risk events.
Which one of the following is NOT a document that will help you identify and communicate risks within the project?
- A. Stakeholder registers
- B. Activity cost estimates
- C. Activity duration estimates
- D. Risk register
Answer: D
Explanation:
Section: Volume D
Explanation:
Risk register is not an input to risk identification, but it is an output of risk identification.
Incorrect Answers:
A, B, C: These are an input to risk identification.
Identify Risks is the process of determining which risks may affect the project. It also documents risks' characteristics. The Identify Risks process is part of the Project Risk Management knowledge area. As new risks may evolve or become known as the project progresses through its life cycle, Identify Risks is an iterative process. The process should involve the project team so that they can develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions. Risk Register is the only output of this process.
NEW QUESTION 108
The BEST way to obtain senior management support for investment in a control implementation would be to articulate the reduction in:
- A. vulnerabilities.
- B. residual risk.
- C. detected incidents.
- D. inherent risk.
Answer: D
NEW QUESTION 109
An organization has four different projects competing for funding to reduce overall IT risk. Which project should management defer?
- A. Project Alpha
- B. Project Charlie
- C. Project Bravo
- D. Project Delta
Answer: B
NEW QUESTION 110
While reviewing a contract of a cloud services vendor, it was discovered that the vendor refuses to accept liability for a sensitive data breach. Which of the following controls will BES reduce the risk associated with such a data breach?
- A. Engaging a third party to validate operational controls
- B. Using field-level encryption with a vendor supplied key
- C. Using the same cloud vendor as a competitor
- D. Ensuring the vendor does not know the encryption key
Answer: A
NEW QUESTION 111
The acceptance of control costs that exceed risk exposure MOST likely demonstrates:
- A. corporate culture alignment
- B. low risk tolerance
- C. high risk tolerance
- D. corporate culture misalignment.
Answer: C
NEW QUESTION 112
A global organization is considering the acquisition of a competitor. Senior management has requested a review of the overall risk profile from the targeted organization. Which of the following components of this review would provide the MOST useful information?
- A. Risk management policies
- B. Risk appetite statement
- C. Enterprise risk management framework
- D. Risk register
Answer: D
NEW QUESTION 113
......
Authentic Best resources for CRISC Online Practice Exam: https://www.prep4sureguide.com/CRISC-prep4sure-exam-guide.html
Updates Up to 365 days On Developing CRISC Braindumps: https://drive.google.com/open?id=1dqlcq-A1xcVyabx3_WlVyWd3RI0gHL0C