Isaca CRISC Practice Test - Questions Answers, Page 133
List of questions
Question 1321
Which of the following is MOST important when identifying an organization's risk exposure associated with Internet of Things (loT) devices?
Question 1322
An organization has contracted with a cloud service provider to support the deployment of a new product. Of the following, who should own the associated risk?
Question 1323
A business impact analysis (BIA) has documented the duration of maximum allowable outage for each of an organization's applications. Which of the following MUST be aligned with the maximum allowable outage?
Question 1324
Who should be accountable for authorizing information system access to internal users?
Question 1325
It was discovered that a service provider's administrator was accessing sensitive information without the approval of the customer in an Infrastructure as a Service (laaS) model. Which of the following would BEST protect against a future recurrence?
Question 1326
Which group has PRIMARY ownership of reputational risk stemming from unethical behavior within the organization?
Question 1327
Which of the following is the MOST important reason to communicate control effectiveness to senior management?
Question 1328
Which of the following actions should a risk practitioner do NEXT when an increased industry trend of external cyber attacks is identified?
Question 1329
The PRIMARY benefit of selecting an appropriate set of key risk indicators (KRIs) is that they:
Question 1330
A large organization recently restructured the IT department and has decided to outsource certain functions. What action should the control owners in the IT department take?
Question