Isaca CRISC Practice Test - Questions Answers, Page 2
List of questions
Question 11
An application owner has specified the acceptable downtime in the event of an incident to be much lower than the actual time required for the response team to recover the application. Which of the following should be the NEXT course of action?
Question 12
Which of the following is the MAIN reason to continuously monitor IT-related risk?
Question 13
An organization that has been the subject of multiple social engineering attacks is developing a risk awareness program. The PRIMARY goal of this program should be to:
Question 14
Which of the following is the MOST important factor affecting risk management in an organization?
Question 15
Which of the following is the MOST important consideration when sharing risk management updates with executive management?
Question 16
A risk practitioner has observed that there is an increasing trend of users sending sensitive information by email without using encryption. Which of the following would be the MOST effective approach to mitigate the risk associated with data loss?
Question 17
Risk management strategies are PRIMARILY adopted to:
Question 18
Which of the following would be MOST helpful when estimating the likelihood of negative events?
Question 19
Which of the following would be considered a vulnerability?
Question 20
Establishing and organizational code of conduct is an example of which type of control?
Question