ExamGecko
Home Home / Isaca / CRISC

Isaca CRISC Practice Test - Questions Answers, Page 80

Question list
Search
Search

Related questions











The acceptance of control costs that exceed risk exposure MOST likely demonstrates:

A.
corporate culture alignment
A.
corporate culture alignment
Answers
B.
low risk tolerance
B.
low risk tolerance
Answers
C.
high risk tolerance
C.
high risk tolerance
Answers
D.
corporate culture misalignment.
D.
corporate culture misalignment.
Answers
Suggested answer: C

Which of the following provides the MOST useful information when determining if a specific control should be implemented?

A.
Business impact analysis (BIA)
A.
Business impact analysis (BIA)
Answers
B.
Cost-benefit analysis
B.
Cost-benefit analysis
Answers
C.
Attribute analysis
C.
Attribute analysis
Answers
D.
Root cause analysis
D.
Root cause analysis
Answers
Suggested answer: B

Which of the following would provide the MOST useful information to a risk owner when reviewing the progress of risk mitigation?

A.
Key audit findings
A.
Key audit findings
Answers
B.
Treatment plan status
B.
Treatment plan status
Answers
C.
Performance indicators
C.
Performance indicators
Answers
D.
Risk scenario results
D.
Risk scenario results
Answers
Suggested answer: C

Employees are repeatedly seen holding the door open for others, so that trailing employees do not have to stop and swipe their own ID badges. This behavior BEST represents:

A.
a threat.
A.
a threat.
Answers
B.
a vulnerability.
B.
a vulnerability.
Answers
C.
an impact
C.
an impact
Answers
D.
a control.
D.
a control.
Answers
Suggested answer: B

Of the following, who is accountable for ensuing the effectiveness of a control to mitigate risk?

A.
Control owner
A.
Control owner
Answers
B.
Risk manager
B.
Risk manager
Answers
C.
Control operator
C.
Control operator
Answers
D.
Risk treatment owner
D.
Risk treatment owner
Answers
Suggested answer: A

When of the following is the BEST key control indicator (KCI) to determine the effectiveness of en intrusion prevention system (IPS)?

A.
Percentage of system uptime
A.
Percentage of system uptime
Answers
B.
Percentage of relevant threats mitigated
B.
Percentage of relevant threats mitigated
Answers
C.
Total number of threats identified
C.
Total number of threats identified
Answers
D.
Reaction time of the system to threats
D.
Reaction time of the system to threats
Answers
Suggested answer: B

Which of the following describes the relationship between Key risk indicators (KRIs) and key control indicators (KCIS)?

A.
KCIs are independent from KRIs KRIs.
A.
KCIs are independent from KRIs KRIs.
Answers
B.
KCIs and KRIs help in determining risk appetite.
B.
KCIs and KRIs help in determining risk appetite.
Answers
C.
KCIs are defined using data from KRIs.
C.
KCIs are defined using data from KRIs.
Answers
D.
KCIs provide input for KRIs
D.
KCIs provide input for KRIs
Answers
Suggested answer: D

What information is MOST helpful to asset owners when classifying organizational assets for risk assessment?

A.
Potential loss to tie business due to non-performance of the asset
A.
Potential loss to tie business due to non-performance of the asset
Answers
B.
Known emerging environmental threats
B.
Known emerging environmental threats
Answers
C.
Known vulnerabilities published by the asset developer
C.
Known vulnerabilities published by the asset developer
Answers
D.
Cost of replacing the asset with a new asset providing similar services
D.
Cost of replacing the asset with a new asset providing similar services
Answers
Suggested answer: A

The MOST important consideration when selecting a control to mitigate an identified risk is whether:

A.
the cost of control exceeds the mitigation value
A.
the cost of control exceeds the mitigation value
Answers
B.
there are sufficient internal resources to implement the control
B.
there are sufficient internal resources to implement the control
Answers
C.
the mitigation measures create compounding effects
C.
the mitigation measures create compounding effects
Answers
D.
the control eliminates the risk
D.
the control eliminates the risk
Answers
Suggested answer: A

Which of the following should be a risk practitioner's PRIMARY focus when tasked with ensuring organization records are being retained for a sufficient period of time to meet legal obligations?

A.
Data duplication processes
A.
Data duplication processes
Answers
B.
Data archival processes
B.
Data archival processes
Answers
C.
Data anonymization processes
C.
Data anonymization processes
Answers
D.
Data protection processes
D.
Data protection processes
Answers
Suggested answer: B
Total 1.200 questions
Go to page: of 120