Isaca CRISC Practice Test - Questions Answers, Page 55
List of questions
Question 541
Which of the following should be done FIRST when information is no longer required to support business objectives?
Question 542
When developing a new risk register, a risk practitioner should focus on which of the following risk management activities?
Question 543
Which of the following BEST indicates whether security awareness training is effective?
Question 544
An organizations chief technology officer (CTO) has decided to accept the risk associated with the potential loss from a denial-of-service (DoS) attack. In this situation, the risk practitioner's BEST course of action is to:
Question 545
Several network user accounts were recently created without the required management approvals. Which of the following would be the risk practitioner's BEST recommendation to address this situation?
Question 546
Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?
Question 547
A risk practitioner has become aware of production data being used in a test environment. Which of the following should be the practitioner's PRIMARY concern?
Question 548
Which of the following is the GREATEST advantage of implementing a risk management program?
Question 549
When updating the risk register after a risk assessment, which of the following is MOST important to include?
Question 550
The GREATEST benefit of including low-probability, high-impact events in a risk assessment is the ability to:
Question