Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 265

When reviewing the business continuity plan (BCP) of an online sales order system, a risk practitioner notices that the recovery time objective (RTO) has a shorter lime than what is defined in the disaster recovery plan (DRP). Which of the following is the BEST way for the risk practitioner to address this concern?

A.

Adopt the RTO defined in the BCR

B.

Update the risk register to reflect the discrepancy.

C.

Adopt the RTO defined in the DRP.

D.

Communicate the discrepancy to the DR manager for follow-up.

Full Access
Question # 266

Which of the following is MOST helpful in providing a high-level overview of current IT risk severity*?

A.

Risk mitigation plans

B.

heat map

C.

Risk appetite statement

D.

Key risk indicators (KRls)

Full Access
Question # 267

A multinational organization is considering implementing standard background checks to' all new employees A KEY concern regarding this approach

A.

fail to identity all relevant issues.

B.

be too costly

C.

violate laws in other countries

D.

be too line consuming

Full Access
Question # 268

Which of the following is MOST important to promoting a risk-aware culture?

A.

Regular testing of risk controls

B.

Communication of audit findings

C.

Procedures for security monitoring

D.

Open communication of risk reporting

Full Access
Question # 269

A risk practitioner has collaborated with subject matter experts from the IT department to develop a large list of potential key risk indicators (KRIs) for all IT operations within the organization of the following, who should review the completed list and select the appropriate KRIs for implementation?

A.

IT security managers

B.

IT control owners

C.

IT auditors

D.

IT risk owners

Full Access
Question # 270

Which risk response strategy could management apply to both positive and negative risk that has been identified?

A.

Transfer

B.

Accept

C.

Exploit

D.

Mitigate

Full Access
Question # 271

Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?

A.

Accountability may not be clearly defined.

B.

Risk ratings may be inconsistently applied.

C.

Different risk taxonomies may be used.

D.

Mitigation efforts may be duplicated.

Full Access
Question # 272

Which of the following is the MOST important consideration when communicating the risk associated with technology end-of-life to business owners?

A.

Cost and benefit

B.

Security and availability

C.

Maintainability and reliability

D.

Performance and productivity

Full Access
Go to page: