Isaca CRISC Practice Test - Questions Answers, Page 5
List of questions
What is the BEST information to present to business control owners when justifying costs related to controls?
A review of an organization s controls has determined its data loss prevention {DLP) system is currently failing to detect outgoing emails containing credit card data. Which of the following would be MOST impacted?
A data processing center operates in a jurisdiction where new regulations have significantly increased penalties for data breaches. Which of the following elements of the risk register is MOST important to update to reflect this change?
Which of the following is the MOST important benefit of key risk indicators (KRIs)'
IT risk assessments can BEST be used by management:
A risk practitioner has identified that the organization's secondary data center does not provide redundancy for a critical application. Who should have the authority to accept the associated risk?
Which of the following will BEST quantify the risk associated with malicious users in an organization?
Which of the following is the MOST important element of a successful risk awareness training program?
Whether the results of risk analyses should be presented in quantitative or qualitative terms should be based PRIMARILY on the:
An organization has identified a risk exposure due to weak technical controls in a newly implemented HR system. The risk practitioner is documenting the risk in the risk register. The risk should be owned by the:
Question