Free Certification Practice Questions

ISACA-CRISC

Loading…
Isaca's CRISC Which of the following provides the MOST useful information to determine risk exposure following control implementations?
#661
Isaca's CRISC Reviewing historical risk events is MOST useful for which of the following processes within the risk management life cycle?
#662
Isaca's CRISC Which of the following is the BEST key control indicator (KCI) for a vulnerability management program?
#663
Isaca's CRISC Which of the following is the BESTapproach when a risk practitioner has been asked by a business unit manager for special consideration during a risk assessment of a system?
#664
Isaca's CRISC Upon learning that the number of failed back-up attempts continually exceeds the current risk threshold, the risk practitioner should:
#665
Isaca's CRISC A highly regulated organization acquired a medical technology startup company that processes sensitive personal information with weak data protection controls.Which of the following is the BEST way for the acquiring company to reduce its risk while still enabling the flexibility needed by the startup company?
#666
Isaca's CRISC An organization has outsourced its billing function to an external service provider. Who should own the risk of customer data leakage caused by the service provider?
#667
Isaca's CRISC Which of the following is the MOST important component in a risk treatment plan?
#668
Isaca's CRISC Which of the following is the BEST course of action to help reduce the probability of an incident recurring?
#669
Isaca's CRISC An organization is preparing to transfer a large number of customer service representatives to the sales department. Of the following, who is responsible for mitigating the risk associated with residual system access?
#670
Isaca's CRISC Which of the following would BEST assist in reconstructing the sequence of events following a security incident across multiple IT systems in the organization's network?
#671
Isaca's CRISC Which of the following should be done FIRST when information is no longer required to support business objectives?
#672
Isaca's CRISC A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management, the risk practitioner should explain:
#673
Isaca's CRISC Which of the following is the MOST important reason to link an effective key control indicator (KCI) to relevant key risk indicators (KRIs)?
#674
Isaca's CRISC Which of the following BEST facilitates the mitigation of identified gaps between current and desired risk environment states?
#675
Isaca's CRISC The MOST important objective of information security controls is to:
#676
Isaca's CRISC Which of the following controls BEST enables an organization to ensure a complete and accurate IT asset inventory?
#677
Isaca's CRISC Which of the following scenarios represents a threat?
#678
Isaca's CRISC Which of the following is the GREATEST risk associated with an environment that lacks documentation of the architecture?
#679
Isaca's CRISC Which of the following will be MOST effective in uniquely identifying the originator of electronic transactions?
#680
Isaca's CRISC Which of the following BEST assists in justifying an investment in automated controls?
#681
Isaca's CRISC Which of the following statements BEST illustrates the relationship between key performance indicators (KPIs) and key control indicators (KCIs)?
#682
Isaca's CRISC Which of the following is necessary to enable an IT risk register to be consolidated with the rest of the organization's risk register?
#683
Isaca's CRISC The GREATEST benefit of including low-probability, high-impact events in a risk assessment is the ability to:
#684
Isaca's CRISC Which of the following will BEST help in communicating strategic risk priorities?
#685
Isaca's CRISC What is the PRIMARY purpose of a business impact analysis (BIA)?
#686
Isaca's CRISC Which of the following is the BEST way to determine whether new controls mitigate security gaps in a business system?
#687
Isaca's CRISC Which of the following criteria associated with key risk indicators (KRIs) BEST enables effective risk monitoring?
#688
Isaca's CRISC Which of the following is the BEST indication of a mature organizational risk culture?
#689
Isaca's CRISC The BEST key performance indicator (KPI) for monitoring adherence to an organization's user accounts provisioning practices is the percentage of:
#690