Isaca CRISC Practice Test - Questions Answers, Page 133
List of questions
Question 1321

Which of the following is MOST important when identifying an organization's risk exposure associated with Internet of Things (loT) devices?
Question 1322

An organization has contracted with a cloud service provider to support the deployment of a new product. Of the following, who should own the associated risk?
Question 1323

A business impact analysis (BIA) has documented the duration of maximum allowable outage for each of an organization's applications. Which of the following MUST be aligned with the maximum allowable outage?
Question 1324

Who should be accountable for authorizing information system access to internal users?
Question 1325

It was discovered that a service provider's administrator was accessing sensitive information without the approval of the customer in an Infrastructure as a Service (laaS) model. Which of the following would BEST protect against a future recurrence?
Question 1326

Which group has PRIMARY ownership of reputational risk stemming from unethical behavior within the organization?
Question 1327

Which of the following is the MOST important reason to communicate control effectiveness to senior management?
Question 1328

Which of the following actions should a risk practitioner do NEXT when an increased industry trend of external cyber attacks is identified?
Question 1329

The PRIMARY benefit of selecting an appropriate set of key risk indicators (KRIs) is that they:
Question 1330

A large organization recently restructured the IT department and has decided to outsource certain functions. What action should the control owners in the IT department take?
Question