Isaca CRISC Practice Test - Questions Answers, Page 2

List of questions
Question 11

An application owner has specified the acceptable downtime in the event of an incident to be much lower than the actual time required for the response team to recover the application. Which of the following should be the NEXT course of action?
Question 12

Which of the following is the MAIN reason to continuously monitor IT-related risk?
Question 13

An organization that has been the subject of multiple social engineering attacks is developing a risk awareness program. The PRIMARY goal of this program should be to:
Question 14

Which of the following is the MOST important factor affecting risk management in an organization?
Question 15

Which of the following is the MOST important consideration when sharing risk management updates with executive management?
Question 16

A risk practitioner has observed that there is an increasing trend of users sending sensitive information by email without using encryption. Which of the following would be the MOST effective approach to mitigate the risk associated with data loss?
Question 17

Risk management strategies are PRIMARILY adopted to:
Question 18

Which of the following would be MOST helpful when estimating the likelihood of negative events?
Question 19

Which of the following would be considered a vulnerability?
Question 20

Establishing and organizational code of conduct is an example of which type of control?
Question