[2024] Pass ISACA CRISC Test Practice Test Questions Exam Dumps
Verified CRISC dumps Q&As - CRISC dumps with Correct Answers
ISACA CRISC (Certified in Risk and Information Systems Control) certification exam is designed to test an individual's knowledge of risk management and information systems control. Certified in Risk and Information Systems Control certification is highly sought after by professionals who want to demonstrate their ability to identify, assess, and evaluate risks to their organization's information systems. CRISC exam covers four domains: risk identification, assessment, response, and monitoring.
NEW QUESTION # 252
Which of the following is MOST important to have in place to ensure the effectiveness of risk and security metrics reporting?
- A. Incident reporting procedures.
- B. Organizational reporting process.
- C. Incident management policy.
- D. Regularly scheduled audits.
Answer: A
Explanation:
Section: Volume D
NEW QUESTION # 253
Which of the following would present the GREATEST challenge when assigning accountability for control ownership?
- A. Unclear reporting relationships
- B. Senior management scrutiny
- C. Complex regulatory environment
- D. Weak governance structures
Answer: A
Explanation:
Section: Volume D
Explanation
NEW QUESTION # 254
When it appears that a project risk is going to happen, what is this term called?
- A. Issue
- B. Trigger
- C. Contingency response
- D. Threshold
Answer: B
Explanation:
Explanation/Reference:
Explanation:
A trigger is a warning sign or a condition that a risk event is likely to occur within the project.
Incorrect Answers:
A: Issues are events that come about as a result of risk events. Risks become issues only after they have actually occurred.
B: A contingency response is a pre-planned response for a risk event, such as a rollback plan.
D: A threshold is a limit that the risk passes to actually become an issue in the project.
NEW QUESTION # 255
Which of the following is the BEST way to ensure that outsourced service providers comply with the enterprise's information security policy?
- A. Periodic audits
- B. Service level monitoring
- C. Penetration testing
- D. Security awareness training
Answer: A
Explanation:
Section: Volume A
Explanation:
As regular audits can spot gaps in information security compliance, periodic audits can ensure that outsourced service provider comply with the enterprise's information security policy.
Incorrect Answers:
A: Penetration testing can identify security vulnerability, but cannot ensure information compliance.
B: Service level monitoring can only identify operational issues in the enterprise's operational environment. It does not play any role in ensuring that outsourced service provider complies with the enterprise's information security policy.
C: Training can increase user awareness of the information security policy, but is less effective than periodic auditing.
NEW QUESTION # 256
Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?
- A. Apply single sign-on for access control.
- B. Enforce an internal data access policy.
- C. Implement segregation of duties.
- D. Enforce the use of digital signatures.
Answer: B
NEW QUESTION # 257
What are the requirements for creating risk scenarios? Each correct answer represents a part of the solution. Choose three.
- A. Determination of cause and effect
- B. Potential threats and vulnerabilities that could cause loss
- C. Determination of the value of an asset
- D. Determination of the value of business process at risk
Answer: B,C,D
Explanation:
Explanation/Reference:
Explanation:
Creating a scenario requires determination of the value of an asset or a business process at risk and the potential threats and vulnerabilities that could cause loss. The risk scenario should be assessed for relevance and realism, and then entered into the risk register if found to be relevant.
In practice following steps are involved in risk scenario development:
First determine manageable set of scenarios, which include:
- Frequently occurring scenarios in the industry or product area.
- Scenarios representing threat sources that are increasing in count or severity level.
- Scenarios involving legal and regulatory requirements applicable to the business.
After determining manageable risk scenarios, perform a validation against the business objectives of
the entity.
Based on this validation, refine the selected scenarios and then detail them to a level in line with the
criticality of the entity.
Lower down the number of scenarios to a manageable set. Manageable does not signify a fixed
number, but should be in line with the overall importance and criticality of the unit.
Risk factors kept in a register so that they can be reevaluated in the next iteration and included for
detailed analysis if they have become relevant at that time.
Risk factors kept in a register so that they can be reevaluated in the next iteration and included for
detailed analysis if they have become relevant at that time.
Include an unspecified event in the scenarios, that is, address an incident not covered by other
scenarios.
Incorrect Answers:
A: Cause-and-effect analysis is a predictive or diagnostic analytical tool used to explore the root causes or factors that contribute to positive or negative effects or outcomes. It is used during the process of exposing risk factors.
NEW QUESTION # 258
Which of the following is MOST important to promoting a risk-aware culture?
- A. Open communication of risk reporting
- B. Procedures for security monitoring
- C. Regular testing of risk controls
- D. Communication of audit findings
Answer: A
NEW QUESTION # 259
Which of the following will BEST help to ensure key risk indicators (KRIs) provide value to risk owners?
- A. Ongoing training
- B. Timely notification
- C. Cost minimization
- D. Return on investment (ROI)
Answer: B
NEW QUESTION # 260
An organization's business gap analysis reveals the need for a robust IT risk strategy. Which of the following should be the risk practitioner's PRIMARY consideration when participating in development of the new strategy?
- A. Scale of technology
- B. Risk indicators
- C. Proposed risk budget
- D. Risk culture
Answer: D
NEW QUESTION # 261
Which of the following is an administrative control?
- A. Data loss prevention program
- B. Water detection
- C. Session timeout
- D. Reasonableness check
Answer: A
Explanation:
Explanation/Reference:
Explanation:
NEW QUESTION # 262
Your project is an agricultural-based project that deals with plant irrigation systems. You have
discovered a byproduct in your project that your organization could use to make a profit. If your organization seizes this opportunity it would be an example of what risk response?
- A. Exploiting
- B. Positive
- C. Enhancing
- D. Explanation:
This is an example of exploiting a positive risk - a by-product of a project is an excellent example of exploiting a risk. Exploit response is one of the strategies to negate risks or threats that appear in a project. This strategy may be selected for risks with positive impacts where the organization wishes to ensure that the opportunity is realized. Exploiting a risk event provides opportunities for positive impact on a project. Assigning more talented resources to the project to reduce the time to completion is an example of exploit response. - E. Opportunistic
Answer: A,D
Explanation:
is incorrect. Opportunistic is not a valid risk response. Answer: B is incorrect. This is an example of a positive risk, but positive is not a risk response. Answer: A is incorrect. Enhancing is a positive risk response that describes actions taken to increase the odds of a risk event to happen.
NEW QUESTION # 263
You are the project manager of GHT project. A risk event has occurred in your project and you have identified it. Which of the following tasks you would do in reaction to risk event occurrence? Each correct answer represents a part of the solution. Choose three.
- A. Communicate lessons learned from risk events
- B. Monitor risk
- C. Maintain and initiate incident response plans
- D. Update risk register
- E. Explanation:
When the risk events occur then following tasks have to done to react to it: Maintain incident response plans Monitor risk Initiate incident response Communicate lessons learned from risk events
Answer: A,B,C,E
Explanation:
is incorrect. Risk register is updated after applying appropriate risk response and at the time of risk event occurrence.
NEW QUESTION # 264
An organization has outsourced its billing function to an external service provider. Who should own the risk of customer data leakage caused by the service provider?
- A. Business process owner
- B. Vendor risk manager
- C. The service provider
- D. Legal counsel
Answer: A
NEW QUESTION # 265
Which of the following issues should be of GREATEST concern when evaluating existing controls during a risk assessment?
- A. Redundant compensating controls are in place.
- B. A high number of approved exceptions exist with compensating controls.
- C. Successive assessments have the same recurring vulnerabilities.
- D. Asset custodians are responsible for defining controls instead of asset owners.
Answer: C
Explanation:
Section: Volume D
NEW QUESTION # 266
Which of the following events refer to loss of integrity?
Each correct answer represents a complete solution. Choose three.
- A. Someone sees company's secret formula
- B. A virus infects a file
- C. An e-mail message is modified in transit
- D. Someone makes unauthorized changes to a Web site
Answer: B,C,D
Explanation:
Section: Volume A
Explanation:
Loss of integrity refers to the following types of losses:
* An e-mail message is modified in transit A virus infects a file
* Someone makes unauthorized changes to a Web site
Incorrect Answers:
A: Someone sees company's secret formula or password comes under loss of confidentiality.
NEW QUESTION # 267
You are using Information system. You have chosen a poor password and also sometimes transmits data over unprotected communication lines. What is this poor quality of password and unsafe transmission refers to?
- A. Impacts
- B. Vulnerabilities
- C. Threats
- D. Probabilities
Answer: B
Explanation:
Section: Volume A
Explanation:
Vulnerabilities represent characteristics of information resources that may be exploited by a threat. The given scenario describes such a situation, hence it is a vulnerability.
Incorrect Answers:
A: Probabilities represent the likelihood of the occurrence of a threat, and this scenario does not describe a probability.
B: Threats are circumstances or events with the potential to cause harm to information resources. This scenario does not describe a threat.
D: Impacts represent the outcome or result of a threat exploiting a vulnerability. The stem does not describe an impact.
NEW QUESTION # 268
Capability maturity models are the models that are used by the enterprise to rate itself in terms of the least mature level to the most mature level. Which of the following capability maturity levels shows that the enterprise does not recognize the need to consider the risk management or the business impact from IT risk?
- A. Level 2
- B. Level 0
- C. Level 3
- D. Level 1
Answer: B
Explanation:
Explanation/Reference:
Explanation:
0 nonexistent: An enterprise's risk management capability maturity level is 0 when:
The enterprise does not recognize the need to consider the risk management or the business impact
from IT risk.
Decisions involving risk lack credible information.
Awareness of external requirements for risk management and integration with enterprise risk
management (ERM) do not exists.
Incorrect Answers:
A, C, D: These all are higher levels of capability maturity model and in this enterprise is mature enough to recognize the importance of risk management.
NEW QUESTION # 269
Which of the following come under the management class of controls?
Each correct answer represents a complete solution. (Choose two.)
- A. Program management control
- B. Risk assessment control
- C. Identification and authentication control
- D. Audit and accountability control
Answer: A,B
Explanation:
Explanation/Reference:
Explanation:
The Management class of controls includes five families. These families include over 40 individual controls.
Following is a list of each of the families in the Management class:
Certification, Accreditation, and Security Assessment (CA): This family of controls addresses steps to
implement a security and assessment program. It includes controls to ensure only authorized systems are allowed on a network. It includes details on important security concepts, such as continuous monitoring and a plan of action and milestones.
Planning (PL): The PL family focuses on security plans for systems. It also covers Rules of Behaviour
for users. Rules of Behaviour are also called an acceptable use policy.
Risk Assessment (RA): This family of controls provides details on risk assessments and vulnerability
scanning.
System and Services Acquisition (SA): The SA family includes any controls related to the purchase of
products and services. It also includes controls related to software usage and user installed software.
Program Management (PM): This family is driven by the Federal Information Security Management Act
(FISMA). It provides controls to ensure compliance with FISMA. These controls complement other controls. They don't replace them.
Incorrect Answers:
B, D: Identification and authentication, and audit and accountability control are technical class of controls.
NEW QUESTION # 270
What should be PRIMARILY responsible for establishing an organization's IT risk culture?
- A. Business process owner
- B. IT management
- C. Risk management
- D. Executive management
Answer: D
Explanation:
Section: Volume D
Explanation/Reference: https://www.casact.org/education/infocus/2014/handouts/Paper_3464_handout_2190_0.pdf
NEW QUESTION # 271
Which of the following is the FIRST step in managing the risk associated with the leakage of confidential data?
- A. Define and implement a data classification policy
- B. Conduct an awareness program for data owners and users.
- C. Implement mandatory encryption on data
- D. Maintain and review the classified data inventor.
Answer: A
NEW QUESTION # 272
......
CRISC certification guide Q&A from Training Expert TestValid: https://www.testvalid.com/CRISC-exam-collection.html
The Best Isaca Certificaton Study Guide for the CRISC Exam: https://drive.google.com/open?id=1E2LccpAQVpkASrlb0UtP3Pw7q_1KwUR2