Isaca CRISC Practice Test - Questions Answers, Page 33

List of questions
Question 321

Which of the following would BEST help identify the owner for each risk scenario in a risk register?
Question 322

A key risk indicator (KRI) indicates a reduction in the percentage of appropriately patched servers. Which of the following is the risk practitioner's BEST course of action?
Question 323

Implementing which of the following will BEST help ensure that systems comply with an established baseline before deployment?
Question 324

Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of an anti-virus program?
Question 325

During the control evaluation phase of a risk assessment, it is noted that multiple controls are ineffective. Which of the following should be the risk practitioner's FIRST course of action?
Question 326

Performing a background check on a new employee candidate before hiring is an example of what type of control?
Question 327

When reporting risk assessment results to senior management, which of the following is MOST important to include to enable risk-based decision making?
Question 328

A business unit has decided to accept the risk of implementing an off-the-shelf, commercial software package that uses weak password controls. The BEST course of action would be to:
Question 329

Which of the following is the BEST way for a risk practitioner to verify that management has addressed control issues identified during a previous external audit?
Question 330

Who is accountable for risk treatment?
Question