Isaca CRISC Practice Test - Questions Answers, Page 136
List of questions
Question 1351

An organization has outsourced its backup and recovery procedures to a third-party cloud provider. Which of the following should be the risk practitioner's NEXT course of action?
Question 1352

An organization uses a web application hosted by a cloud service that is populated by data sent to the vendor via email on a monthly basis. Which of the following should be the FIRST consideration when analyzing the risk associated with the application?
Question 1353

Which of the following is the BEST way to determine the value of information assets for risk management purposes?
Question 1354

Which of the following BEST facilitates the development of relevant risk scenarios?
Question 1355

Which of the following is the PRIMARY purpose of a risk register?
Question 1356

A risk practitioner notes control design changes when comparing risk response to a previously approved action plan. Which of the following is MOST important for the practitioner to confirm?
Question 1357

The software version of an enterprise's critical business application has reached end-of-life and is no longer supported by the vendor. IT has decided to develop an in-house replacement application. Which of the following should be the PRIMARY concern?
Question 1358

An organization recently implemented new technologies that enable the use of robotic process automation. Which of the following is MOST important to reassess?
Question 1359

The PRIMARY focus of an ongoing risk awareness program should be to:
Question 1360

An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization's risk appetite and tolerance, which of the following is the risk practitioner's BEST recommendation?
Question