
[May-2024] Download Real ISACA CRISC Exam Dumps Test Engine Exam Questions
New CRISC exam dumps Use Updated ISACA Exam
NEW QUESTION # 277
When reviewing a business continuity plan (BCP), which of the following would be the MOST significant deficiency?
- A. BCP testing is not in conjunction with the disaster recovery plan (DRP)
- B. Each business location has separate, inconsistent BCPs
- C. BCP is often tested using the walkthrough method
- D. Recovery time objectives (RTOs) do not meet business requirements
Answer: A
Explanation:
Section: Volume D
Explanation/Reference:
NEW QUESTION # 278
Which of the following would BEST help to address the risk associated with malicious outsiders modifying application data?
- A. Activation of control audits
- B. Acceptable use policies
- C. Multi-factor authentication
- D. Role-based access controls
Answer: D
Explanation:
Role-based access controls (RBAC) are a type of preventive control that limit the access and actions of users based on their roles and responsibilities within the organization. RBAC can help to address the risk of malicious outsiders modifying application data by restricting their access to the data and the functions they can perform on it. RBAC can also enforce the principle of least privilege, which means that users only have the minimum level of access required to perform their tasks. RBAC can be implemented through policies, procedures, and technical mechanisms such as access control lists, encryption, and authentication. References = Risk and Information Systems Control Study Manual, Chapter 4, Section 4.2.1.1, p. 178-179
NEW QUESTION # 279
A risk assessment has identified increased losses associated with an IT risk scenario. It is MOST important for the risk practitioner to:
- A. implement additional controls.
- B. develop new risk scenarios.
- C. update the risk rating.
- D. reevaluate inherent risk.
Answer: A
NEW QUESTION # 280
Which of the following is MOST important when conducting a post-implementation review as part of the system development life cycle (SDLC)?
- A. Verifying that project objectives are met
- B. Leveraging an independent review team
- C. Reviewing the project initiation risk matrix
- D. Identifying project cost overruns
Answer: A
NEW QUESTION # 281
Which of the following is the GREATEST concern associated with redundant data in an organization's inventory system?
- A. Unnecessary costs of program changes
- B. Data inconsistency
- C. Poor access control
- D. Unnecessary data storage usage
Answer: C
Explanation:
Section: Volume D
NEW QUESTION # 282
An organization is planning to outsource its payroll function to an external service provider Which of the following should be the MOST important consideration when selecting the provider?
- A. Transparency of key performance indicators (KPIs)
- B. Right to audit the provider
- C. Disaster recovery plan (DRP) of the system
- D. Internal controls to ensure data privacy
Answer: D
Explanation:
The most important consideration when selecting an external service provider for outsourcing the payroll function is the internal controls to ensure data privacy. The payroll function involves processing and storing sensitive personal and financial information of the employees, such as salaries, taxes, benefits, bank accounts, etc. This information needs to be protected from unauthorized access, disclosure, modification, or loss, as it may result in legal, regulatory, reputational, or financial consequences for the organization and the employees.
Therefore, the external service provider should have adequate internal controls, such as encryption, access control, backup, logging, monitoring, etc., to ensure data privacy and compliance with the organization's policies and standards. Disaster recovery plan, right to audit, and transparency of KPIs are also important considerations when selecting an external service provider, but they are not as important as internal controls to ensure data privacy. References = Risk and Information Systems Control Study Manual, 7th Edition, Chapter
5, Section 5.2.1.2, page 2461
1: ISACA Certified in Risk and Information Systems Control (CRISC) Exam Guide, Answer to Question
648.
NEW QUESTION # 283
Which of the following is MOST important for an organization to update following a change in legislation requiring notification to individuals impacted by data breaches?
- A. Risk appetite and tolerance
- B. Insurance coverage
- C. Policies and standards
- D. Security awareness training
Answer: C
NEW QUESTION # 284
Which of the following will BEST help to improve an organization's risk culture?
- A. Establishing a risk awareness program
- B. Allocating resources for risk remediation
- C. Rewarding employees for reporting security incidents
- D. Maintaining a documented risk register
Answer: A
Explanation:
A risk awareness program is a set of activities that aim to educate and inform employees about the organization's risk culture, policies, and procedures. A risk awareness program can help improve an organization's risk culture by enhancing the employees' understanding of risk, their roles and responsibilities in risk management, and the benefits of risk mitigation. A risk awareness program can also foster a culture of openness, trust, and collaboration among employees, managers, and stakeholders, which can improve the organization's risk performance and resilience.
Maintaining a documented risk register, rewarding employees for reporting security incidents, and allocating resources for risk remediation are also important aspects of risk management, but they do not directly address the organization's risk culture, which is the shared values, beliefs, and attitudes that influence how risk is perceived and handled within the organization.
NEW QUESTION # 285
Which of the following provides the MOST comprehensive information when developing a risk profile for a system?
- A. Results of a business impact analysis (BIA)
- B. Key performance indicators (KPIs)
- C. A mapping of resources to business processes
- D. Risk assessment results
Answer: D
NEW QUESTION # 286
When an organization's disaster recovery plan (DRP) has a reciprocal agreement, which of the following risk treatment options is being applied?
- A. Acceptance
- B. Mitigation
- C. Avoidance
- D. Transfer
Answer: B
NEW QUESTION # 287
Which of the following is the MOST effective way to integrate risk and compliance management?
- A. Embedding risk management into compliance decision-making
- B. Designing corrective actions to improve risk response capabilities
- C. Conducting regular self-assessments to verify compliance
- D. Embedding risk management into processes that are aligned with business drivers
Answer: D
Explanation:
Embedding risk management into processes that are aligned with business drivers is the most effective way to integrate risk and compliance management, as it ensures that the risk management objectives and activities are consistent and supportive of the enterprise's strategic goals and values. It also enables the identification and management of risks and compliance requirements across the enterprise, and the optimization of risk and compliance resources and performance. Embedding risk management into compliance decision-making, designing corrective actions to improve risk response capabilities, and conducting regular self-assessments to verify compliance are not ways to integrate risk and compliance management, but rather components or outcomes of the risk and compliance management process. References = CRISC Practice Quiz and Exam Prep; CRISC: Certified in Risk & Information Systems Control Sample Questions, question 202.
NEW QUESTION # 288
Which of the following is the BEST way to protect sensitive data from administrators within a public cloud?
- A. Use an encrypted tunnel lo connect to the cloud.
- B. Encrypt physical hard drives within the cloud.
- C. Encrypt the data in the cloud database.
- D. Encrypt data before it leaves the organization.
Answer: D
NEW QUESTION # 289
Which of the following considerations should be taken into account while selecting risk indicators that ensures greater buy-in and ownership?
- A. Stakeholder
- B. Lag indicator
- C. Lead indicator
- D. Root cause
- E. Explanation:
To ensure greater buy-in and ownership, risk indicators should be selected with the involvement of relevant stakeholders. Risk indicators should be identified for all stakeholders and should not focus solely on the more operational or strategic side of risk.
Answer: A,E
Explanation:
is incorrect. Lead indicators indicate which capabilities are in place to prevent events from occurring. They do not play any role in ensuring greater buy-in and ownership. Answer: A is incorrect. Role of lag indicators is to ensure that risk after events have occurred is being indicated. Answer: C is incorrect. Root cause is considered while selecting risk indicator but it does not ensure greater buy-in or ownership.
NEW QUESTION # 290
Who should have the authority to approve an exception to a control?
- A. Control owner
- B. Risk owner
- C. information security manager
- D. Risk manager
Answer: A
NEW QUESTION # 291
Which of the following would MOST likely drive the need to review and update key performance indicators (KPIs) for critical IT assets?
- A. Findings from continuous monitoring
- B. Outcomes of periodic risk assessments
- C. Changes in service level objectives
- D. The outsourcing of related IT processes
Answer: D
NEW QUESTION # 292
To communicate the risk associated with IT in business terms, which of the following MUST be defined?
- A. Organizational objectives
- B. Compliance objectives
- C. Inherent and residual risk
- D. Risk appetite of the organization
Answer: A
NEW QUESTION # 293
From a risk management perspective, which of the following is the PRIMARY benefit of using automated system configuration validation tools?
- A. Residual risk is reduced.
- B. Staff costs are reduced.
- C. Inherent risk is reduced.
- D. Operational costs are reduced.
Answer: A
NEW QUESTION # 294
A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:
- A. updating the risk register
- B. validating the risk scenarios
- C. documenting the risk scenarios.
- D. identifying risk mitigation controls.
Answer: B
NEW QUESTION # 295
You have been assigned as the Project Manager for a new project that involves building of a new roadway between the city airport to a designated point within the city. However, you notice that the transportation permit issuing authority is taking longer than the planned time to issue the permit to begin construction.
What would you classify this as?
- A. Risk Update
- B. Project Issue
- C. Project Risk
- D. Status Update
Answer: B
Explanation:
Explanation/Reference:
Explanation:
This is a project issue. It is easy to confuse this as a project risk; however, a project risk is always in the future. In this case, the delay by the permitting agency has already happened; hence this is a project issue.
The possible impact of this delay on the project cost, schedule, or performance can be classified as a project risk.
Incorrect Answers:
A: It is easy to confuse this as a project risk; however, a project risk is always in the future. In this case, the delay by the permitting agency has already happened; hence this is a project issue.
B, C: These are options are not valid.
NEW QUESTION # 296
Which of the following is the way to verify control effectiveness?
- A. Its reliability.
- B. Explanation:
Control effectiveness requires a process to verify that the control process worked as intended and
meets the intended control objectives.
Hence the test result of intended objective helps in verifying effectiveness of control. - C. is incorrect. The type of control, like preventive or detective, does not help determine
control effectiveness. - D. Whether it is preventive or detective.
- E. The capability of providing notification of failure.
- F. is incorrect. Reliability is not an indication of control strength; weak controls can be
highly reliable, even if they do not meet the control objective. - G. The test results of intended objectives.
Answer: B,C,F,G
Explanation:
is incorrect. Notification of failure does not determine control strength, hence this option
is not correct.
NEW QUESTION # 297
The PRIMARY benefit of conducting continuous monitoring of access controls is the ability to identify.
- A. leading or lagging key risk indicators (KRIs)
- B. unknown threats to undermine existing access controls
- C. possible noncompliant activities that lead to data disclosure
- D. inconsistencies between security policies and procedures
Answer: A
Explanation:
Section: Volume D
Explanation/Reference: https://www.isaca.org/Journal/archives/2015/Volume-2/Pages/a-practical-approach-to-continuous- control-monitoring.aspx
NEW QUESTION # 298
......
Pass Your CRISC Dumps as PDF Updated on 2024 With 1426 Questions: https://www.testkingfree.com/ISACA/CRISC-practice-exam-dumps.html
Verified CRISC Dumps Q&As - CRISC Test Engine with Correct Answers: https://drive.google.com/open?id=1AjU8jSEGR5vJlvd0DXrfkw-AWWdO85EM