Isaca CRISC Practice Test - Questions Answers, Page 102
List of questions
Which of the following is the BEST approach for an organization in a heavily regulated industry to comprehensively test application functionality?
An organization has agreed to a 99% availability for its online services and will not accept availability that falls below 98.5%. This is an example of:
Which of the following is the PRIMARY purpose of creating and documenting control procedures?
Of the following, who is responsible for approval when a change in an application system is ready for release to production?
During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?
Which of the following findings of a security awareness program assessment would cause the GREATEST concern to a risk practitioner?
Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?
When preparing a risk status report for periodic review by senior management, it is MOST important to ensure the report includes
Following an acquisition, the acquiring company's risk practitioner has been asked to update the organization's IT risk profile What is the MOST important information to review from the acquired company to facilitate this task?
An organization has experienced several incidents of extended network outages that have exceeded tolerance. Which of the following should be the risk practitioner's FIRST step to address this situation?
Question