Isaca CRISC Practice Test - Questions Answers, Page 101
List of questions
Question 1001
Which of the following is the BEST way for a risk practitioner to present an annual risk management update to the board''
Question 1002
Which of the following is MOST important to promoting a risk-aware culture?
Question 1003
The BEST metric to demonstrate that servers are configured securely is the total number of servers:
Question 1004
A risk practitioner has collaborated with subject matter experts from the IT department to develop a large list of potential key risk indicators (KRIs) for all IT operations within the organization of the following, who should review the completed list and select the appropriate KRIs for implementation?
Question 1005
If preventive controls cannot be Implemented due to technology limitations, which of the following should be done FIRST to reduce risk7
Question 1006
Which of the following resources is MOST helpful to a risk practitioner when updating the likelihood rating in the risk register?
Question 1007
A segregation of duties control was found to be ineffective because it did not account for all applicable functions when evaluating access. Who is responsible for ensuring the control is designed to effectively address risk?
Question 1008
Which of the following would be the BEST way for a risk practitioner to validate the effectiveness of a patching program?
Question 1009
The BEST indicator of the risk appetite of an organization is the
Question 1010
Which of the following is the BEST method to mitigate the risk of an unauthorized employee viewing confidential data in a database''
        
 
                                            
Question