[Sep 21, 2021] CRISC Dumps Full Questions - Exam Study Guide Isaca Certificaton Free Certification Exam Material from Prep4SureReview with 897 Questions NEW QUESTION 427 Which of the following steps ensure effective communication of the risk analysis results to relevant stakeholders? Each correct answer represents a complete solution. Choose three. A. Explanation:The result of risk analysis process [...]

[Sep 21, 2021] CRISC Dumps Full Questions - Exam Study Guide [Q427-Q452]

Share

[Sep 21, 2021] CRISC Dumps Full Questions - Exam Study Guide

Isaca Certificaton  Free Certification Exam Material from Prep4SureReview with 897 Questions

NEW QUESTION 427
Which of the following steps ensure effective communication of the risk analysis results to relevant stakeholders? Each correct answer represents a complete solution. Choose three.

  • A. Explanation:
    The result of risk analysis process is being communicated to relevant stakeholders. The steps that are involved in communication are: The results should be reported in terms and formats that are useful to support business decisions. Coordinate additional risk analysis activity as required by decision makers, like reportrejection and scope adjustment Communicate the risk-return context clearly, which include probabilities of loss and/or gain, ranges, and confidence levels (if possible) that enable management to balance risk-return. Identify the negative impacts of events that drive response decisions as well as positive impacts of events that represent opportunities which should channel back into the strategy and objective setting process. Provide decision makers with an understanding of worst-case and most probable scenarios, due diligence exposures and significant reputation, legal or regulatory considerations.
  • B. Communicate the negative impacts of the events only, it needs more consideration
  • C. Communicate the risk-return context clearly
  • D. Provide decision makers with an understanding of worst-case and most probable scenarios,due diligence exposures and significant reputation, legal or regulatory considerations
  • E. The results should be reported in terms and formats that are useful to support business decisions

Answer: A,C,D,E

Explanation:
is incorrect. Communicate the negative impacts of events that drive response decisions as well as positive impacts of events that represent opportunities which should channel back into the strategy and objective setting process, for effective communication. Only negative impacts are not considered alone.

 

NEW QUESTION 428
In which of the following conditions business units tend to point the finger at IT when projects are not delivered on time?

  • A. Existence of a blame culture
  • B. System failure
  • C. Explanation:
    In a blame culture, business units tend to point the finger at IT when projects are not delivered on time or do not meet expectations. In doing so, they fail to realize how the business unit's involvement up front affects project success. In extreme cases, the business unit may assign blame for a failure to meet the expectations that the unit never clearly communicated.
  • D. Misalignment between real risk appetite and translation into policies
  • E. Threat identification in project

Answer: A,C

Explanation:
C, and A are incorrect. These are not relevant to the pointing of finger at IT when projects are not delivered on time.

 

NEW QUESTION 429
Which of the following BEST facilitates the development of effective IT risk scenarios?

  • A. Validation by senior management
  • B. Utilization of a cross-functional team
  • C. Participation by IT subject matter experts
  • D. Integration of contingency planning

Answer: A

 

NEW QUESTION 430
Which of the following is MOST important to the integrity of a security log?

  • A. Inability to edit
  • B. Ability to overwrite
  • C. Encryption
  • D. Least privilege access

Answer: D

 

NEW QUESTION 431
One of the risk events you've identified is classified as force majeure. What risk response is likely to be used?

  • A. Mitigation
  • B. Enhance
  • C. Transference
  • D. Acceptance

Answer: D

Explanation:
Section: Volume B
Explanation:
Force majeure describes acts of God (Natural disaster), such as tornados and fires, and are usually accepted because there's little than can be done to mitigate these risks.
Incorrect Answers:
B: Transference transfers the risk ownership to a third party, usually for a fee.
C: Enhance is used for a positive risk event, not for force majeure.
D: Mitigation isn't the best choice, as this lowers the probability and/or impact of the risk event.

 

NEW QUESTION 432
You are the risk professional in Bluewell Inc. You have identified a risk and want to implement a specific risk mitigation activity. What you should PRIMARILY utilize?

  • A. Technical evaluation report
  • B. Budgetary requirements
  • C. Vulnerability assessment report
  • D. Business case

Answer: D

Explanation:
Explanation/Reference:
Explanation:
As business case includes business need (like new product, change in process, compliance need, etc.) and the requirements of the enterprise (new technology, cost, etc.), risk professional should utilize this for implementing specific risk mitigation activity. Risk professional must look at the costs of the various controls and compare them against the benefits that the organization will receive from the risk response.
Hence he/she needs to have knowledge of business case development to illustrate the costs and benefits of the risk response.
Incorrect Answers:
A, C, D: These all options are supplemental.

 

NEW QUESTION 433
An IT risk practitioner has been asked to regularly report on the overall status and effectiveness of the IT risk management program. Which of the following is MOST useful for this purpose?

  • A. Balanced scorecard
  • B. Control self-assessment (CSA)
  • C. Internal audit plan
  • D. Capability maturity level

Answer: A

Explanation:
Section: Volume D

 

NEW QUESTION 434
You work as a project manager for BlueWell Inc. You are preparing to plan risk responses for your project with your team. How many risk response types are available for a negative risk event in the project?

  • A. 0
  • B. 1
  • C. Explanation:
    Four risk response options are there to deal with negative risks or threats on the project objectives- avoid, transfer, mitigate, and accept. Risk avoidance Risk mitigation Risk transfer Risk acceptance
  • D. 2
  • E. 3

Answer: C,E

Explanation:
C, and B are incorrect. These are incorrect choices as only 4 risk response are available to deal with negative risks.

 

NEW QUESTION 435
Which of the following is true for Single loss expectancy (SLE), Annual rate of occurrence (ARO), and Annual loss expectancy (ALE)?

  • A. ALE= ARO*SLE
  • B. ARO= SLE/ALE
  • C. ALE= ARO/SLE
  • D. ARO= ALE*SLE

Answer: A

Explanation:
Section: Volume C
Explanation:
A quantitative risk assessment quantifies risk in terms of numbers such as dollar values. This involves gathering data and then entering it into standard formulas. The results can help in identifying the priority of risks. These results are also used to determine the effectiveness of controls. Some of the terms associated with quantitative risk assessments are:
* Single loss expectancy (SLE)-It refers to the total loss expected from a single incident. This incident can occur when vulnerability is being exploited by threat. The loss is expressed as a dollar value such as
$1,000. It includes the value of data, software, and hardware. SLE = Asset value * Exposure factor
* Annual rate of occurrence (ARO)-It refers to the number of times expected for an incident to occur in a year. If an incident occurred twice a month in the past year, the ARO is 24. Assuming nothing changes, it is likely that it will occur 24 times next year. Annual loss expectancy (ALE)-It is the expected loss for a year.
ALE is calculated by multiplying SLE with ARO. Because SLE is a given in a dollar value, ALE is also given in a dollar value. For example, if the SLE is $1,000 and the ARO is 24, the ALE is $24,000.
* ALE = SLE * ARO Safeguard value-This is the cost of a control. Controls are used to mitigate risk. For example, antivirus software of an average cost of $50 for each computer. If there are 50 computers, the safeguard value is $2,500. A, B, C: These are wrong formulas and are not used in quantitative risk assessment.

 

NEW QUESTION 436
In response to the threat of ransomware, an organization has implemented cybersecurity awareness activities.
The risk practitioner's BEST recommendation to further reduce the impact of ransomware attacks would be to implement:

  • A. two-factor authentication
  • B. encryption for data in motion
  • C. encryption for data at rest
  • D. continuous data backup controls

Answer: D

Explanation:
Section: Volume D

 

NEW QUESTION 437
Which of the following BEST indicates the condition of a risk management program?

  • A. Level of financial support
  • B. Number of controls
  • C. Amount of residual risk
  • D. Number of risk register entries

Answer: C

 

NEW QUESTION 438
Which of the following is MOST helpful in determining the effectiveness of an organization's IT risk mitigation efforts?

  • A. Assigning identification dates for risk scenarios in the risk register
  • B. Verifying whether risk action plans have been completed
  • C. Updating impact assessments for risk scenarios
  • D. Reviewing key risk indicators (KRIs)

Answer: D

 

NEW QUESTION 439
Which of the following aspects of an IT risk and control self-assessment would be MOST important to include in a report to senior management?

  • A. A decrease in the number of key controls
  • B. An increase in residual risk
  • C. Changes in control ownership
  • D. Changes in control design

Answer: C

 

NEW QUESTION 440
Your project team has completed the quantitative risk analysis for your project work. Based on their findings, they need to update the risk register with several pieces of information. Which one of the following components is likely to be updated in the risk register based on their analysis?

  • A. Qualitative analysis outcomes
  • B. Listing of risk responses
  • C. Risk ranking matrix
  • D. Listing of prioritized risks

Answer: D

Explanation:
Explanation/Reference:
Explanation:
The outcome of quantitative analysis can create a listing of prioritized risks that should be updated in the risk register. The project team will create and update the risk register with four key components:
probabilistic analysis of the project

probability of achieving time and cost objectives

list of quantified risks

trends in quantitative risk analysis

Incorrect Answers:
A, B, D: These subjects are not updated in the risk register as a result of quantitative risk analysis.

 

NEW QUESTION 441
Which of the following is the GREATEST advantage of implementing a risk management program?

  • A. Improving security governance
  • B. Reducing residual risk
  • C. Promoting a risk-aware culture
  • D. Enabling risk-aware decisions

Answer: D

 

NEW QUESTION 442
Reviewing results from which of the following is the BEST way to identify information systems control deficiencies?

  • A. Control self-assessment (CSA)
  • B. User acceptance testing (UAT)
  • C. Control remediation planning
  • D. Vulnerability and threat analysis

Answer: D

Explanation:
Section: Volume D

 

NEW QUESTION 443
Which of the following is the BEST control to detect an advanced persistent threat (APT)?

  • A. Conducting regular penetration tests
  • B. Monitoring social media activities
  • C. Implementing automated log monitoring
  • D. Utilizing antivirus systems and firewalls

Answer: C

 

NEW QUESTION 444
An organization has decided to implement an emerging technology and incorporate the new capabilities into its strategic business plan. Business operations for the technology will be outsourced. What will be the risk practitioner's PRIMARY role during the change?

  • A. Developing risk scenarios
  • B. Managing the threat landscape
  • C. Managing third-party risk
  • D. Updating risk appetite

Answer: A

 

NEW QUESTION 445
Print jobs containing confidential information are sent to a shared network printer located in a secure room. Which of the following is the BEST control to prevent the inappropriate disclosure of confidential information?

  • A. Requiring a printer access code for each user
  • B. Using video surveillance in the printer room
  • C. Using physical controls to access the printer room
  • D. Ensuring printer parameters are properly configured

Answer: A

 

NEW QUESTION 446
The PRIMARY basis for selecting a security control is:

  • A. the materiality of the risk.
  • B. to achieve the desired level of maturity.
  • C. the cost of the control.
  • D. the ability to mitigate risk.

Answer: D

 

NEW QUESTION 447
Which negative risk response usually has a contractual agreement?

  • A. Mitigation
  • B. Sharing
  • C. Transference
  • D. Exploiting

Answer: C

Explanation:
Section: Volume D
Explanation:
Transference is the risk response that transfers the risk to a third party, usually for a fee. Insurance and subcontracting of dangerous works are two common examples of transference with a contractual obligation.
Incorrect Answers:
A: Sharing is a positive risk response. Note that sharing may also have contractual obligations, sometimes called teaming agreements.
C: Mitigation is a negative risk response used to lower the probability and/or impact of a risk event.
D: Exploiting is a positive risk response and not a negative response and doesn't have contractual obligations.

 

NEW QUESTION 448
You are the project manager of the GHY project for your organization. You are working with your project team to begin identifying risks for the project. As part of your preparation for identifying the risks within the project you will need eleven inputs for the process. Which one of the following is NOT an input to the risk identification process?

  • A. Quality management plan
  • B. Procurement management plan
  • C. Stakeholder register
  • D. Cost management plan

Answer: B

Explanation:
The procurement management plan is not one of the eleven inputs for the risk identification
process. The eleven inputs to this process are:
risk management plan, activity cost estimates, activity duration estimates, scope baseline,
stakeholder register, cost management plan, schedule management plan, quality management
plan, project documents, enterprise environmental factors, and organizational process assets.

 

NEW QUESTION 449
Which of the following should be the MOST important consideration when performing a vendor risk assessment?

  • A. Risk tolerance of the vendor
  • B. Inherent risk of the business process supported by the vendor
  • C. Results of the last risk assessment of the vendor
  • D. Length of time since the last risk assessment of the vendor

Answer: B

 

NEW QUESTION 450
During a routine check, a system administrator identifies unusual activity indicating an intruder within a firewall.
Which of the following controls has MOST likely been compromised?

  • A. Data validation
  • B. Authentication
  • C. Data integrity
  • D. Identification

Answer: B

Explanation:
Section: Volume D

 

NEW QUESTION 451
Key risk indicators (KRIs) are MOST useful during which of the following risk management phases?

  • A. Monitoring
  • B. Analysis
  • C. Response selection
  • D. Identification

Answer: A

 

NEW QUESTION 452
......

Dumps Brief Outline Of The CRISC Exam: https://www.prep4surereview.com/CRISC-latest-braindumps.html

Use Real CRISC - 100% Cover Real Exam Questions: https://drive.google.com/open?id=11UTQzwvVPoXKhtk9gQCzgBHitAufkvP9