Isaca CRISC Practice Test - Questions Answers, Page 19

List of questions
Question 181

Which of the following is MOST helpful in identifying gaps between the current and desired state of the IT risk environment?
Question 182

A control owner responsible for the access management process has developed a machine learning model to automatically identify excessive access privileges. What is the risk practitioner's BEST course of action?
Question 183

The PRIMARY reason for periodic penetration testing of Internet-facing applications is to:
Question 184

A control owner has completed a year-long project To strengthen existing controls. It is MOST important for the risk practitioner to:
Question 185

A large organization is replacing its enterprise resource planning (ERP) system and has decided not to deploy the payroll module of the new system. Instead, the current payroll system will continue to be used. Of the following, who should own the risk if the ERP and payroll system fail to operate as expected?
Question 186

Which of the following is MOST important to review when determining whether a potential IT service provider's control environment is effective?
Question 187

Which of the following provides the MOST helpful information in identifying risk in an organization?
Question 188

Which stakeholders are PRIMARILY responsible for determining enterprise IT risk appetite?
Question 189

Which of The following will BEST communicate the importance of risk mitigation initiatives to senior management?
Question 190

An organization has outsourced its backup and recovery procedures to a third-party cloud provider. Which of the following is the risk practitioner s BEST course of action?
Question