Pass ISACA CRISC PDF Dumps Recently Updated 1745 Questions [Q365-Q383]

Share

Pass ISACA CRISC PDF Dumps | Recently Updated 1745 Questions

Updated Test Engine to Practice CRISC Dumps & Practice Exam

NEW QUESTION # 365
Which of the following components ensures that risks are examined for all new proposed change requests in the change control system?

  • A. Risk monitoring and control
  • B. Integrated change control
  • C. Explanation:
    Integrated change control is the component that is responsible for reviewing all aspects of a change's impact on a project - including risks that may be introduced by the new change. Integrated change control is a way to manage the changes incurred during a project. It is a method that manages reviewing the suggestions for changes and utilizing the tools and techniques to evaluate whether the change should be approved or rejected. Integrated change control is a primary component of the project's change control system that examines the affect of a proposed change on the entire project.
  • D. Scope change control
  • E. Configuration management

Answer: B,C

Explanation:
is incorrect. Configuration management controls and documents changes to the features and functions of the product scope. Answer:B is incorrect. Scope change control focuses on the processes to allow changes to enter the project scope. Answer:C is incorrect. Risk monitoring and control is not part of the change control system, so this choice is not valid.


NEW QUESTION # 366
Which of the following would qualify as a key performance indicator (KPI)?

  • A. Number of identified system vulnerabilities
  • B. Number of exception requests processed in the past 90 days
  • C. Aggregate risk of the organization
  • D. Number of attacks against the organization's website

Answer: A

Explanation:
A key performance indicator (KPI) is a measurable value that demonstrates how effectively an organization is achieving its key objectives. A KPI should be relevant, specific, measurable, achievable, and time-bound. The number of identified system vulnerabilities is a KPI that measures the security posture and performance of the organization's information systems. It also helps to identify the areas that need improvement or remediation.
The number of identified system vulnerabilities is relevant to the organization's objective of protecting its information assets, specific to the system level, measurable by using tools or methods, achievable by implementing security controls or practices, and time-bound by setting a target or threshold. Aggregate risk of the organization, number of exception requests processed in the past 90 days, and number of attacks against the organization's website are not KPIs, as they are either too broad, not relevant, or not measurable. References = Risk and Information Systems Control Study Manual, 7th Edition, Chapter 4, Section 4.1.1.1, page 1741
1: ISACA Certified in Risk and Information Systems Control (CRISC) Exam Guide, Answer to Question
647.


NEW QUESTION # 367
An organization has been made aware of a newly discovered critical vulnerability in a regulatory reporting system. Which of the following is the risk practitioner's BEST course of action?

  • A. Perform an impact assessment.
  • B. Perform a penetration test.
  • C. Escalate the risk to senior management.
  • D. Request an external audit.

Answer: A

Explanation:
The risk practitioner's best course of action when an organization has been made aware of a newly discovered critical vulnerability in a regulatory reporting system is to perform an impact assessment, as it involves estimating the potential consequences or damage that the vulnerability may cause to the system and its related business processes, and prioritizing the risk response accordingly. The other options are not the best courses of action, as they may not address the urgency or severity of the vulnerability, or may require the prior knowledge of the impact or risk level, respectively. References = CRISC Review Manual, 7th Edition, page
100.


NEW QUESTION # 368
The BEST key performance indicator (KPI) to measure the effectiveness of a vulnerability remediation
program is the number of:

  • A. vulnerabilities remediated,
  • B. recurring vulnerabilities.
  • C. vulnerability scans.
  • D. new vulnerabilities identified.

Answer: A

Explanation:
According to the Key Performance Indicators for Vulnerability Management article, the number of
vulnerabilities remediated is a key performance indicator that measures the effectiveness of a vulnerability
remediation program. This KPI indicates how many vulnerabilities have been successfully mitigated or fixed
within a given time frame. A higher number can imply that the organization is effectively managing its
exposures and reducing its risk level. The number of vulnerabilities remediated can also be compared with the
number of new vulnerabilities identified to evaluate the progress and performance of the vulnerability
remediation program. References = Key Performance Indicators for Vulnerability Management


NEW QUESTION # 369
You are the project manager of HWD project. It requires installation of some electrical machines. You and the project team decided to hire an electrician as electrical work can be too dangerous to perform. What type of risk response are you following?

  • A. Transference
  • B. Acceptance
  • C. Mitigation
  • D. Avoidance

Answer: A

Explanation:
Section: Volume B
Explanation:
As the risk is transferred to the third party (electrician), hence this type of risk response is transference.
Incorrect Answers:
A: Risk avoidance means to evade risk altogether, eliminate the cause of the risk event, or change the project plan to protect the project objectives from the risk event. Risk avoidance is applied when the level of risk, even after the applying controls, would be greater than the risk tolerance level of the enterprise.
C: Risk mitigation attempts to reduce the probability of a risk event and its impacts to an acceptable level. Risk mitigation can utilize various forms of control carefully integrated together.
D: Risk acceptance means that no action is taken relative to a particular risk; loss is accepted if it occurs.


NEW QUESTION # 370
Which of the following BEST enables detection of ethical violations committed by employees?

  • A. Access control attestation
  • B. Whistleblower program
  • C. Periodic job rotation
  • D. Transaction log monitoring

Answer: B

Explanation:
* Whistleblower Program:
* Definition: A whistleblower program allows employees to report unethical or illegal activities within the organization anonymously.
* Detection of Ethical Violations: Employees are often in the best position to observe unethical behavior. A well-structured whistleblower program encourages them to report such behavior without fear of retaliation.
* Anonymity and Protection: Providing anonymity and protection to whistleblowers increases the likelihood that employees will report violations, thus enabling the organization to detect and address ethical issues more effectively.
* Comparison with Other Options:
* Transaction Log Monitoring: While useful for detecting anomalies and potential fraud, it is not specifically focused on ethical violations and may not capture all types of unethical behavior.
* Access Control Attestation: This ensures that users have the correct access permissions but does not directly detect unethical behavior.
* Periodic Job Rotation: This can help prevent fraud by reducing the risk of collusion and providing fresh perspectives on processes, but it does not directly detect ethical violations.
* Best Practices:
* Clear Reporting Channels: Ensure that the whistleblower program has clear and accessible reporting channels.
* Training and Awareness: Regularly train employees on the importance of reporting unethical behavior and the protections offered by the whistleblower program.
* Follow-up and Action: Ensure that reports are investigated thoroughly and appropriate actions are taken to address verified violations.
References:
* CRISC Review Manual: Emphasizes the importance of ethical behavior and the role of whistleblower programs in detecting and addressing ethical violations within organizations.
* ISACA Guidelines: Support the implementation of whistleblower programs as a key component of a comprehensive risk management and ethical governance framework.


NEW QUESTION # 371
An organization maintains independent departmental risk registers that are not automatically aggregated.
Which of the following is the GREATEST concern?

  • A. The same risk factor may be identified in multiple areas.
  • B. Management may be unable to accurately evaluate the risk profile.
  • C. Multiple risk treatment efforts may be initiated to treat a given risk.
  • D. Resources may be inefficiently allocated.

Answer: B

Explanation:
The greatest concern of maintaining independent departmental risk registers that are not automatically aggregated is that management may be unable to accurately evaluate the risk profile. The risk profile is the overall view of the risks that the organization faces and their impact on the organization's objectives. It helps management to prioritize and allocate resources for risk management and to align the risk appetite and strategy. If the departmental risk registers are not aggregated, management may not have a complete and consistent picture of the risks across the organization. They may miss some important risks, overestimate or underestimate some risks, or have conflicting or redundant risk information. This may lead to poor risk management decisions and outcomes. The other options are also concerns, but they are not as critical as the inability to evaluate the risk profile. References = Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.2: IT Risk Analysis, page 63.


NEW QUESTION # 372
A control for mitigating risk in a key business area cannot be implemented immediately. Which of the
following is the risk practitioner's BEST course of action when a compensating control needs to be applied?

  • A. Record the risk as accepted in the risk register.
  • B. Inform senior management.
  • C. update the risk response plan.
  • D. Obtain the risk owner's approval.

Answer: D

Explanation:
A compensating control is a temporary or alternative control that is implemented when the primary control
for mitigating a risk is not feasible or available. A compensating control should provide a similar level of
protection and assurance as the primary control, and should be aligned with the risk appetite and tolerance of
the organization. The risk practitioner's best course of action when a compensating control needs to be
applied is to obtain the risk owner's approval. The risk owner is the person who has the authority and
accountability for managing a specific risk, and who is responsible for ensuring that the risk is within the
acceptable level. The risk practitioner should consult with the risk owner to explain the situation, proposethe
compensating control, and seek their approval before implementing it. This way, the risk practitioner can
ensure that the compensating control is appropriate, effective, and acceptable for the risk owner, and that the
risk owner is aware of and agrees with the change in the risk treatment. The other options are not the best
course of action, as they do not involve the risk owner's approval or input. Recording the risk as accepted in
the risk register implies that the risk is not treated or reduced, which may not be the case with a compensating
control. Informing senior management may be a good practice, but it does not ensure that the risk owner is
involved or agrees with the compensating control. Updating the risk response plan may be a necessary step
after implementing the compensating control, but it does not require the risk owner's approval or
consultation. References = 5 Key Risk Mitigation Strategies (With Examples), Risk Management 101:
Process, Examples, Strategies


NEW QUESTION # 373
An internal audit report reveals that a legacy system is no longer supported Which of the following is the risk practitioner's MOST important action before recommending a risk response'

  • A. Review historical application down me and frequency
  • B. Assess the potential impact and cost of mitigation
  • C. Explore the feasibility of replacing the legacy system
  • D. identify other legacy systems within the organization

Answer: B


NEW QUESTION # 374
Which of the following is the MOST important objective of regularly presenting the project risk register to the project steering committee?

  • A. To ensure the project timeline is on target
  • B. To allocate budget for resolution of risk issues
  • C. To determine if new risk scenarios have been identified
  • D. To track the status of risk mitigation actions

Answer: D


NEW QUESTION # 375
An internal audit report reveals that not all IT application databases have encryption in place. Which of the following information would be MOST important for assessing the risk impact?

  • A. The reason some databases have not been encrypted
  • B. The cost required to enforce encryption
  • C. The number of users who can access sensitive data
  • D. A list of unencrypted databases which contain sensitive data

Answer: D

Explanation:
According to the CRISC Review Manual, a list of unencrypted databases which contain sensitive data would be the most important information for assessing the risk impact, because it would help to determine the extent and severity of the potential data breach or loss. The risk impact is the effect or consequence of the risk occurrence on the business objectives and operations. A list of unencrypted databases which contain sensitive data would indicate the scope and magnitude of the risk exposure and the potential damage to the confidentiality, integrity, and availability of the data. The other options are not the most important information for assessing the risk impact, as they are less relevant or less specific than a list of unencrypted databases which contain sensitive data. The number of users who can access sensitive data would indicate the level of access control and the likelihood of unauthorized access, but it would not indicate the type and value of the data. The reason some databases have not been encrypted would indicate the cause and rationale of the risk, but it would not indicate the effect or consequence of the risk. The cost required to enforce encryption would indicate the feasibility and affordability of the risk response, but it would not indicate the potential loss or harm of the risk. References = CRISC Review Manual, 7th Edition, Chapter 2, Section 2.2.2, page 78.


NEW QUESTION # 376
A bank is experiencing an increasing incidence of customer identity theft. Which of the following is the BEST way to mitigate this risk?

  • A. Conduct an awareness campaign.
  • B. Implement monitoring techniques.
  • C. Implement layered security.
  • D. Outsource to a local processor.

Answer: C

Explanation:
The best way to mitigate the risk of customer identity theft is to implement layered security. Layered security is a defense-in-depth approach that applies multiple and diverse security controls at different levels and stages of the information system and the data lifecycle. Layered security can include physical, technical, and administrative controls, such as locks, firewalls, encryption, authentication, authorization, backup, audit, and policy. Layered security can help to protect the customer data and identity from unauthorized access, use, modification, disclosure, or destruction, by creating multiple barriers and deterrents for potential attackers, and by reducing the impact and likelihood of a successful breach. Layered security can also help to comply with the legal and regulatory requirements and standards for data privacy and protection, such as the Gramm-Leach-Bliley Act (GLBA), the Fair Credit Reporting Act (FCRA), and the Payment Card Industry Data Security Standard (PCI DSS)123. The other options are not the best way to mitigate the risk of customer identity theft, although they may be useful or complementary to layered security. Implementing monitoring techniques is a part of the layered security approach, but it is not sufficient, as it mainly focuses on detecting and responding to the incidents, rather than preventing or deterring them. Outsourcing to a local processor is a business decision that may or may not improve the security of the customer data and identity, depending on the quality and reliability of the service provider, and the terms and conditions of the outsourcing contract.
Conducting an awareness campaign is a good practice that can help to educate and inform the customers and the employees about the common types, methods, and indicators of identity theft, and the best practices and precautions to prevent or report it, but it does not directly apply or enforce any security controls to the information system or the data.


NEW QUESTION # 377
Risk acceptance of an exception to a security control would MOST likely be justified when:

  • A. the end-user license agreement has expired.
  • B. business benefits exceed the loss exposure.
  • C. the control is difficult to enforce in practice.
  • D. automation cannot be applied to the control

Answer: B

Explanation:
The most likely justification for risk acceptance of an exception to a security control is when the business benefits exceed the loss exposure. Risk acceptance is a risk response strategy that involves acknowledging and tolerating the risk, without taking any action to reduce or transfer the risk. An exception to a security control is a deviation or non-compliance from the established security policy or standard, due to a valid business reason or circumstance. Risk acceptance of an exception to a security control may be justified when the business benefits exceed the loss exposure, which means that the value or advantage of the exception outweighs the potential cost or harm of the risk. For example, an exception to a security control may enable faster or easier access to the system or data, which may improve the productivity, efficiency, or satisfaction of the users or customers, and generate more revenue or profit for the business. The business benefits of the exception may exceed the loss exposure of the risk, which may be low or negligible, or may be mitigated by other controls or factors. Therefore, risk acceptance of an exception to a security control may be a reasonable and rational decision, based on the cost-benefit analysis of the exception and the risk. Automation cannot be applied to the control, the end-user license agreement has expired, and the control is difficult to enforce in practice are not the most likely justifications for risk acceptance of an exception to a security control, as they are either irrelevant or insufficient reasons, and they do not consider the business benefits or the loss exposure of the exception and the risk. References = CRISC Review Manual, 6th Edition, ISACA, 2015, page 50.


NEW QUESTION # 378
You are working on a project in an enterprise. Some part of your project requires e-commerce, but your enterprise choose not to engage in e-commerce. This scenario is demonstrating which of the following form?

  • A. risk avoidance
  • B. risk acceptance
  • C. risk transfer
  • D. risk treatment

Answer: A

Explanation:
Section: Volume A
Explanation:
Each business process involves inherent risk. Not engaging in any activity avoids the inherent risk associated with the activity. Hence this demonstrates risk avoidance.
Incorrect Answers:
B: Risk treatment means that action is taken to reduce the frequency and impact of a risk.
C: Acceptance means that no action is taken relative to a particular risk, and loss is accepted when/if it occurs.
This is different from being ignorant of risk; accepting risk assumes that the risk is known, i.e., an informed decision has been made by management to accept it as such.
D: Risk transfer/sharing means reducing either risk frequency or impact by transferring or otherwise sharing a portion of the risk. Common techniques include insurance and outsourcing. These techniques do not relieve an enterprise of a risk, but can involve the skills of another party in managing the risk and reducing the financial consequence if an adverse event occurs.


NEW QUESTION # 379
An organization is subject to a new regulation that requires nearly real-time recovery of its services following
a disruption. Which of the following is the BEST way to manage the risk in this situation?

  • A. Outsource disaster recovery services to a third-party IT service provider.
  • B. Obtain insurance and ensure sufficient funds are available for disaster recovery.
  • C. Move redundant IT infrastructure to a closer location.
  • D. Review the business continuity plan (BCP) and align it with the new business needs.

Answer: D

Explanation:
Updating the BCP to align with real-time recovery requirements ensures the organization's resilience to
disruptions while meeting regulatory standards. This action reflectsBusiness Continuity and Disaster
Recovery Planningbest practices.


NEW QUESTION # 380
Which of the following would be the BEST way to help ensure the effectiveness of a data loss prevention (DLP) control that has been implemented to prevent the loss of credit card data?

  • A. Testing the transmission of credit card numbers
  • B. Testing the DLP rule change control process
  • C. Reviewing logs for unauthorized data transfers
  • D. Configuring the DLP control to block credit card numbers

Answer: A

Explanation:
A data loss prevention (DLP) control is a technology that tries to detect and stop sensitive data breaches, or data leakage incidents, in an organization. A DLP control is used to prevent sensitive data, such as credit card numbers, from being disclosed to an unauthorized person, whether it is deliberate or accidental1. The best way to help ensure the effectiveness of a DLP control that has been implemented to prevent the loss of credit card data is to test the transmission of credit card numbers. This is a technique to verify that the DLP control can successfully identify and block the credit card data when it is sent or received through various channels, such as email, messaging, or file transfers. Testing the transmission of credit card numbers can help to evaluate the accuracy and reliability of the DLP control, as well as to identify and correct any false positives or false negatives. The other options are not the best ways to help ensure the effectiveness of a DLP control that has been implemented to prevent the loss of credit card data, although they may be helpful and complementary. Reviewing logs for unauthorized data transfers is a technique to monitor and analyze the DLP control activities and incidents, such as who, what, when, where, and how the data was transferred.
However, reviewing logs is a reactive and passive approach, while testing the transmission is a proactive and active approach. Configuring the DLP control to block credit card numbers is a technique to set up the DLP control rules and policies, such as defining the data patterns, the detection methods, and the response actions.
However, configuring the DLP control is a prerequisite and a preparation step, while testing the transmission is a validation and a verification step. Testing the DLP rule change control process is a technique to ensure that the DLP control rules and policies are updated and maintained in a controlled and coordinated manner, such as obtaining approval, documenting the changes, testing the changes, and communicating the changes. However, testing the DLP rule change control process is a quality and governance step, while testing the transmission is a performance and functionality step. References = What is Data Loss Prevention (DLP)? | Digital Guardian1; CRISC Review Manual, pages 164-1652; CRISC Review Questions, Answers & Explanations Manual, page 833


NEW QUESTION # 381
In an organization with a mature risk management program, which of the following would provide the BEST evidence that the IT risk profile is up to date?

  • A. Management assertion
  • B. Risk questionnaire
  • C. Compliance manual
  • D. Risk register

Answer: D

Explanation:
A risk register is a tool that records and tracks the risks that may affect the organization, as well as the actions that are taken or planned to manage them1. A risk register provides the best evidence that the IT risk profile is up to date, because it reflects the current and potential IT risks that the organization faces, as well as their likelihood, impact, severity, owner, status, and response2. An IT risk profile is a document that describes the types, amounts, and priority of IT risk that the organization finds acceptable and unacceptable3. An IT risk profile is developed collaboratively with various stakeholders within the organization, including business leaders, data and process owners, enterprise risk management, internal and external audit, legal, compliance, privacy, and IT risk management and security4. By maintaining and updating the risk register regularly, the organization can ensure that the IT risk profile is aligned with the changing IT risk environment, and that the IT risk management activities and performance are consistent and effective. The other options are not the best evidence that the IT risk profile is up to date, as they are either less comprehensive or less relevant than the risk register. A risk questionnaire is a tool that collects and analyzes the opinions and perceptions of the stakeholders about the risks that may affect the organization5. A risk questionnaire can help to identify and assess the risks, as well as to communicate and report on the risk status and issues. However, a risk questionnaire is not the best evidence that the IT risk profile is up to date, as it may not capture all the IT risks that the organization faces, or reflect the actual or objective level and nature of the IT risks. A management assertion is a statement or declaration made by the management about the accuracy and completeness of the information or data that they provide or report. A management assertion can help to increase the confidence and trust of the stakeholders and auditors in the information or data, as well as to demonstrate the accountability and responsibility of the management. However, a management assertion is not the best evidence that the IT risk profile is up to date, as it does not provide the details or outcomes of the IT risk management activities or performance, or verify the validity and reliability of the IT risk information or data.
A compliance manual is a document that contains the policies, procedures, and standards that the organization must follow to meet the legal, regulatory, or contractual requirements that apply to its activities or operations.
A compliance manual can help to ensure the quality and consistency of the organization's compliance activities or performance, as well as to avoid or reduce the penalties or sanctions for non-compliance.
However, a compliance manual is not the best evidence that the IT risk profile is up to date, as it does not address the IT risks that the organization faces, or the IT risk management activities or performance.
References = Risk and Information Systems Control Study Manual, 7th Edition, Chapter 2, Section 2.1.5, Page
55.


NEW QUESTION # 382
An unauthorized individual has socially engineered entry into an organization's secured physical premises.
Which of the following is the BEST way to prevent future occurrences?

  • A. Require security access badges.
  • B. Install security cameras.
  • C. Employ security guards.
  • D. Conduct security awareness training.

Answer: D


NEW QUESTION # 383
......

ISACA CRISC Dumps Cover Real Exam Questions: https://www.prep4sureguide.com/CRISC-prep4sure-exam-guide.html

Dumps Collection CRISC Test Engine Dumps Training With 1745 Questions: https://drive.google.com/open?id=1s03nA7DGLXV07wuNOVlloxIqSsrZZgA4