Isaca CRISC Practice Test - Questions Answers, Page 134
List of questions
Question 1331

Which of the following risk activities is BEST facilitated by enterprise architecture (EA)?
Question 1332

A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization's data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?
Question 1333

An organization's risk management team wants to develop IT risk scenarios to show the impact of collecting and storing credit card information. Which of the following is the MOST comprehensive approach to capture this scenario?
Question 1334

The BEST way to validate that a risk treatment plan has been implemented effectively is by reviewing:
Question 1335

An organization has restructured its business processes, and the business continuity plan (BCP) needs to be revised accordingly. Which of the following should be identified FIRST?
Question 1336

An organization is moving its critical assets to the cloud. Which of the following is the MOST important key performance indicator (KPI) to include in the service level agreement (SLA)?
Question 1337

Which of the following is the MOST important criteria for selecting key risk indicators (KRIs)?
Question 1338

Which of the following is the BEST metric to demonstrate the effectiveness of an organization's patch management process?
Question 1339

What is the MOST important consideration when selecting key performance indicators (KPIs) for control monitoring?
Question 1340

Within the three lines of defense model, the responsibility for managing risk and controls resides with:
Question