Isaca CRISC Practice Test - Questions Answers, Page 49

List of questions
Question 481

An organization is unable to implement a multi-factor authentication requirement until the next fiscal year due to budget constraints. Consequently, a policy exception must be submitted. Which of the following is MOST important to include in the analysis of the exception?
Question 482

Business areas within an organization have engaged various cloud service providers directly without assistance from the IT department. What should the risk practitioner do?
Question 483

A bank is experiencing an increasing incidence of customer identity theft. Which of the following is the BEST way to mitigate this risk?
Question 484

Which of the following is the BEST method for identifying vulnerabilities?
Question 485

An organization striving to be on the leading edge in regard to risk monitoring would MOST likely implement:
Question 486

Which of the following is a crucial component of a key risk indicator (KRI) to ensure appropriate action is taken to mitigate risk?
Question 487

Which of the following would MOST likely cause a risk practitioner to reassess risk scenarios?
Question 488

Which of the following should be the risk practitioner s FIRST course of action when an organization has decided to expand into new product areas?
Question 489

An organization's HR department has implemented a policy requiring staff members to take a minimum of five consecutive days leave per year to mitigate the risk of malicious insider activities. Which of the following is the BEST key performance indicator (KPI) of the effectiveness of this policy?
Question 490

An organization operates in a jurisdiction where heavy fines are imposed for leakage of customer data. Which of the following provides the BEST input to assess the inherent risk impact?
Question