Isaca CRISC Practice Test - Questions Answers, Page 55

List of questions
Question 541

Which of the following should be done FIRST when information is no longer required to support business objectives?
Question 542

When developing a new risk register, a risk practitioner should focus on which of the following risk management activities?
Question 543

Which of the following BEST indicates whether security awareness training is effective?
Question 544

An organizations chief technology officer (CTO) has decided to accept the risk associated with the potential loss from a denial-of-service (DoS) attack. In this situation, the risk practitioner's BEST course of action is to:
Question 545

Several network user accounts were recently created without the required management approvals. Which of the following would be the risk practitioner's BEST recommendation to address this situation?
Question 546

Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?
Question 547

A risk practitioner has become aware of production data being used in a test environment. Which of the following should be the practitioner's PRIMARY concern?
Question 548

Which of the following is the GREATEST advantage of implementing a risk management program?
Question 549

When updating the risk register after a risk assessment, which of the following is MOST important to include?
Question 550

The GREATEST benefit of including low-probability, high-impact events in a risk assessment is the ability to:
Question