Updated May-2024 Exam Engine for CRISC Exam Free Demo & 365 Day Updates
Exam Passing Guarantee CRISC Exam with Accurate Quastions!
NEW QUESTION # 63
The annualized loss expectancy (ALE) method of risk analysis:
- A. uses qualitative risk rankings such as low. medium and high.
- B. can be used m a cost-benefit analysts
- C. can be used to determine the indirect business impact.
- D. helps in calculating the expected cost of controls
Answer: B
NEW QUESTION # 64
Which of the following will BEST help an organization select a recovery strategy for critical systems?
- A. Analyze previous disaster recovery reports.
- B. Create a business continuity plan.
- C. Conduct a root cause analysis.
- D. Review the business impact analysis.
Answer: D
NEW QUESTION # 65
Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of an anti-virus program?
- A. Number of alerts generated by the anti-virus software
- B. Frequency of anti-virus software updates
- C. Number of false positives detected over a period of time
- D. Percentage of IT assets with current malware definitions
Answer: D
NEW QUESTION # 66
An organization has opened a subsidiary in a foreign country. Which of the following would be the BEST way to measure the effectiveness of the subsidiary's IT systems controls?
- A. Review metrics and key performance indicators (KPIs).
- B. Implement IT systems in alignment with business objectives.
- C. Evaluate compliance with legal and regulatory requirements.
- D. Review design documentation of IT systems.
Answer: A
NEW QUESTION # 67
Which of the following activities would BEST contribute to promoting an organization-wide risk-aware culture?
- A. Participating in peer reviews and implementing best practices
- B. Communicating components of risk and their acceptable levels
- C. Conducting risk assessments and implementing controls
- D. Performing a benchmark analysis and evaluating gaps
Answer: C
Explanation:
Section: Volume D
Explanation/Reference:
Reference: https://m.isaca.org/Certification/CRISC-Certified-in-Risk-and-Information-Systems-Control/ Documents/CRISC-Additional-Verification-Form-2015-Later-frm_Eng_0818.pdf
NEW QUESTION # 68
An organization's risk tolerance should be defined and approved by which of the following?
- A. The chief information officer (CIO)
- B. The chief risk officer (CRO)
- C. The chief executive officer (CEO)
- D. The board of directors
Answer: D
NEW QUESTION # 69
Risk management strategies are PRIMARILY adopted to:
- A. achieve acceptable residual risk levels
- B. achieve compliance with legal requirements
- C. avoid risk for business and IT assets
- D. take necessary precautions for claims and losses
Answer: D
Explanation:
Section: Volume D
NEW QUESTION # 70
Which of the following is the PRIMARY role of a data custodian in the risk management process?
- A. Ensuring data is protected according to the classification
- B. Performing periodic data reviews according to policy
- C. Reporting and escalating data breaches to senior management
- D. Being accountable for control design
Answer: A
NEW QUESTION # 71
Risk appetite should be PRIMARILY driven by which of the following?
- A. Stakeholder requirements
- B. Business impact analysis (BIA)
- C. Legal and regulatory requirements
- D. Enterprise security architecture roadmap
Answer: A
NEW QUESTION # 72
FISMA requires federal agencies to protect IT systems and data. How often should compliance be audited by an external organization?
- A. Every three years
- B. Annually
- C. Explanation:
Inspection of FISMA is required to be done annually. Each year, agencies must have an independent evaluation of their program. The objective is to determine the effectiveness of the program. These evaluations include: Testing for effectiveness: Policies, procedures, and practices are to be tested. This evaluation does not test every policy, procedure, and practice. Instead, a representative sample is tested. An assessment or report: This report identifies the agency's compliance as well as lists compliance with FISMA. It also lists compliance with other standards and guidelines. - D. Quarterly
- E. Never
Answer: B
Explanation:
B, and C are incorrect. Auditing of compliance by external organization is done annually, not quarterly or every three year.
NEW QUESTION # 73
Who should be accountable for monitoring the control environment to ensure controls are effective?
- A. System owner
- B. Security monitoring operations
- C. Impacted data owner
- D. Risk owner
Answer: B
Explanation:
Section: Volume D
Explanation/Reference:
NEW QUESTION # 74
Which of the following is the MOST important consideration when multiple risk practitioners capture risk scenarios in a single risk register?
- A. Using a consistent method for risk assessment
- B. Developing risk escalation and reporting procedures
- C. Maintaining up-to-date risk treatment plans
- D. Aligning risk ownership and control ownership
Answer: A
NEW QUESTION # 75
Which of the following is the BEST indication of an improved risk-aware culture following the implementation of a security awareness training program for all employees?
- A. A reduction in the number of user access resets
- B. An increase in the number of incidents reported
- C. An increase in the number of identified system flaws
- D. A reduction in the number of help desk calls
Answer: C
NEW QUESTION # 76
You are the project manager of GHT project. You are performing cost and benefit analysis of control. You come across the result that costs of specific controls exceed the benefits of mitigating a given risk. What is the BEST action would you choose in this scenario?
- A. The enterprise should adopt corrective control.
- B. The enterprise should exploit the risk.
- C. The enterprise may apply the appropriate control anyway.
- D. The enterprise may choose to accept the risk rather than incur the cost of mitigation.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
If the costs of specific controls or countermeasures (control overhead) exceed the benefits of mitigating a given risk the enterprise may choose to accept the risk rather than incur the cost of mitigation. This is done according to the principle of proportionality described in:
Generally accepted security systems principles (GASSP)
Generally accepted information security principles (GAISP)
Incorrect Answers:
A: When the cost of specific controls exceeds the benefits of mitigating a given risk, then controls are not applied, rather risk is being accepted.
B: As the cost of control exceeds the benefits of mitigating a given risk, hence no control should be applied.
Corrective control is a type of control and hence it should not be adopted.
D: The risk is being exploited when there is an opportunity, i.e., the risk is positive. But here in this case, negative risk exists as it needs mitigation. So, exploitation cannot be done.
NEW QUESTION # 77
Which of the following is the PRIMARY reason for an organization to include an acceptable use banner when users log in?
- A. To eliminate the possibility of insider threat
- B. To enable rapid discovery of insider threat
- C. To reduce the likelihood of insider threat
- D. To reduce the impact of insider threat
Answer: C
NEW QUESTION # 78
An organization is considering modifying its system to enable acceptance of credit card payments. To reduce the risk of data exposure, which of the following should the organization do FIRST?
- A. Update the security strategy
- B. Implement additional controls
- C. Conduct a risk assessment
- D. Update the risk register
Answer: C
Explanation:
Section: Volume D
NEW QUESTION # 79
The PRIMARY reason for periodic penetration testing of Internet-facing applications is to:
- A. verify Internet firewall control settings.
- B. assess the proliferation of new threats.
- C. ensure policy and regulatory compliance.
- D. identify vulnerabilities in the system.
Answer: B
NEW QUESTION # 80
Who is at the BEST authority to develop the priorities and identify what risks and impacts would occur if there were loss of the organization's private information?
- A. Internal auditor
- B. External regulatory agencies
- C. Business process owners
- D. Security management
- E. Explanation:
Business process owners are in best position to judge the risks and impact, as they are most knowledgeable concerning their systems. Hence they are most suitable for developing and identifying risks on business.
Answer: C
Explanation:
D, and A are incorrect. Internal auditors, security managers, external regulators would not understand the impact on business to the extent that business owners could. Hence business owner is the best authority.
NEW QUESTION # 81
A chief information officer (CIO) has identified risk associated with shadow systems being maintained by business units to address specific functionality gaps in the organization's enterprise resource planning (ERP) system. What is the BEST way to reduce this risk going forward?
- A. Implement an enterprise architecture (EA).
- B. Define the software development life cycle (SDLC).
- C. Align applications to business processes.
- D. Define enterprise-wide system procurement requirements.
Answer: A
NEW QUESTION # 82
When developing IT risk scenarios, it is CRITICAL to involve:
- A. process owners
- B. internal auditors
- C. IT managers
- D. senior management
Answer: C
Explanation:
Section: Volume D
NEW QUESTION # 83
Which of the following would provide the MOST useful input when evaluating the appropriateness of risk responses?
- A. Cost-benefit analysis
- B. Incident reports
- C. Risk tolerance
- D. Control objectives
Answer: A
NEW QUESTION # 84
Who is BEST suited to determine whether a new control properly mitigates data loss risk within a system?
- A. Control owner
- B. Data owner
- C. System owner
- D. Risk owner
Answer: C
Explanation:
Section: Volume D
Explanation
NEW QUESTION # 85
The effectiveness of a control has decreased. What is the MOST likely effect on the associated risk?
- A. The risk classification changes.
- B. The residual risk changes.
- C. The inherent risk changes.
- D. The risk impact changes.
Answer: D
NEW QUESTION # 86
A risk owner should be the person accountable for:
- A. implementing actions
- B. the risk management process
- C. managing controls
- D. the business process
Answer: A
Explanation:
Section: Volume D
NEW QUESTION # 87
Which of the following is the MOST important data attribute of key risk indicators (KRIs)?
- A. The data is measurable.
- B. The data is automatically produced.
- C. The data is relevant.
- D. The data is calculated continuously.
Answer: C
NEW QUESTION # 88
......
The CRISC certification is ideal for IT professionals who are involved in the management of risks related to information systems and technology. This includes individuals who are responsible for designing, implementing, and maintaining systems and processes that help to mitigate risks and protect sensitive data. CRISC exam covers a wide range of topics, including risk identification and assessment, risk response and mitigation, and risk monitoring and reporting. It also covers topics related to information security and data privacy, including network security, access control, and data encryption.
Exam Questions for CRISC Updated Versions With Test Engine: https://www.actual4exams.com/CRISC-valid-dump.html
Test Engine to Practice Test for CRISC Valid and Updated Dumps: https://drive.google.com/open?id=1Acl_pF5MuZCX2XGsJXjAs-xdlLdOUs4p