Isaca CRISC Practice Test - Questions Answers, Page 77

List of questions
Question 761

A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:
Question 762

A department allows multiple users to perform maintenance on a system using a single set of credentials. A risk practitioner determined this practice to be high-risk. Which of the following is the MOST effective way to mitigate this risk?
Question 763

The PRIMARY benefit associated with key risk indicators (KRls) is that they:
Question 764

Which of the following BEST informs decision-makers about the value of a notice and consent control for the collection of personal information?
Question 765

Which of the following is MOST important for a risk practitioner to verify when evaluating the effectiveness of an organization's existing controls?
Question 766

Which of the following would be the BEST key performance indicator (KPI) for monitoring the effectiveness of the IT asset management process?
Question 767

An organization's IT infrastructure is running end-of-life software that is not allowed without exception approval. Which of the following would provide the MOST helpful information to justify investing in updated software?
Question 768

Which of the following BEST indicates that an organization has implemented IT performance requirements?
Question 769

The BEST reason to classify IT assets during a risk assessment is to determine the:
Question 770

Which of the following would be MOST useful to senior management when determining an appropriate risk response?
Question