Isaca CRISC Practice Test - Questions Answers, Page 102

List of questions
Question 1011

Which of the following is the BEST approach for an organization in a heavily regulated industry to comprehensively test application functionality?
Question 1012

An organization has agreed to a 99% availability for its online services and will not accept availability that falls below 98.5%. This is an example of:
Question 1013

Which of the following is the PRIMARY purpose of creating and documenting control procedures?
Question 1014

Of the following, who is responsible for approval when a change in an application system is ready for release to production?
Question 1015

During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?
Question 1016

Which of the following findings of a security awareness program assessment would cause the GREATEST concern to a risk practitioner?
Question 1017

Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?
Question 1018

When preparing a risk status report for periodic review by senior management, it is MOST important to ensure the report includes
Question 1019

Following an acquisition, the acquiring company's risk practitioner has been asked to update the organization's IT risk profile What is the MOST important information to review from the acquired company to facilitate this task?
Question 1020

An organization has experienced several incidents of extended network outages that have exceeded tolerance. Which of the following should be the risk practitioner's FIRST step to address this situation?
Question