Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 25

Which of the following controls would BEST reduce the risk of account compromise?

A.

Enforce password changes.

B.

Enforce multi-factor authentication (MFA).

C.

Enforce role-based authentication.

D.

Enforce password encryption.

Full Access
Question # 26

A risk action plan has been changed during the risk mitigation effort. Which of the following is MOST important for the risk practitioner to verify?

A.

Impact of the change on inherent risk

B.

Approval for the change by the risk owner

C.

Business rationale for the change

D.

Risk to the mitigation effort due to the change

Full Access
Question # 27

An organization has procured a managed hosting service and just discovered the location is likely to be flooded every 20 years. Of the following, who should be notified of this new information FIRST.

A.

The risk owner who also owns the business service enabled by this infrastructure

B.

The data center manager who is also employed under the managed hosting services contract

C.

The site manager who is required to provide annual risk assessments under the contract

D.

The chief information officer (CIO) who is responsible for the hosted services

Full Access
Question # 28

The PRIMARY objective for selecting risk response options is to:

A.

reduce risk 10 an acceptable level.

B.

identify compensating controls.

C.

minimize residual risk.

D.

reduce risk factors.

Full Access
Question # 29

The BEST way to demonstrate alignment of the risk profile with business objectives is through:

A.

risk scenarios.

B.

risk tolerance.

C.

risk policy.

D.

risk appetite.

Full Access
Question # 30

Which of the following is the MOST important outcome of reviewing the risk management process?

A.

Assuring the risk profile supports the IT objectives

B.

Improving the competencies of employees who performed the review

C.

Determining what changes should be made to IS policies to reduce risk

D.

Determining that procedures used in risk assessment are appropriate

Full Access
Question # 31

Establishing and organizational code of conduct is an example of which type of control?

A.

Preventive

B.

Directive

C.

Detective

D.

Compensating

Full Access
Question # 32

A business unit is updating a risk register with assessment results for a key project. Which of the following is MOST important to capture in the register?

A.

The team that performed the risk assessment

B.

An assigned risk manager to provide oversight

C.

Action plans to address risk scenarios requiring treatment

D.

The methodology used to perform the risk assessment

Full Access
Go to page: