Isaca CRISC Practice Test - Questions Answers, Page 101

List of questions
Question 1001

Which of the following is the BEST way for a risk practitioner to present an annual risk management update to the board''
Question 1002

Which of the following is MOST important to promoting a risk-aware culture?
Question 1003

The BEST metric to demonstrate that servers are configured securely is the total number of servers:
Question 1004

A risk practitioner has collaborated with subject matter experts from the IT department to develop a large list of potential key risk indicators (KRIs) for all IT operations within the organization of the following, who should review the completed list and select the appropriate KRIs for implementation?
Question 1005

If preventive controls cannot be Implemented due to technology limitations, which of the following should be done FIRST to reduce risk7
Question 1006

Which of the following resources is MOST helpful to a risk practitioner when updating the likelihood rating in the risk register?
Question 1007

A segregation of duties control was found to be ineffective because it did not account for all applicable functions when evaluating access. Who is responsible for ensuring the control is designed to effectively address risk?
Question 1008

Which of the following would be the BEST way for a risk practitioner to validate the effectiveness of a patching program?
Question 1009

The BEST indicator of the risk appetite of an organization is the
Question 1010

Which of the following is the BEST method to mitigate the risk of an unauthorized employee viewing confidential data in a database''
Question