Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 33

Senior management has asked the risk practitioner for the overall residual risk level for a process that contains numerous risk scenarios. Which of the following should be provided?

A.

The sum of residual risk levels for each scenario

B.

The loss expectancy for aggregated risk scenarios

C.

The highest loss expectancy among the risk scenarios

D.

The average of anticipated residual risk levels

Full Access
Question # 34

When developing risk treatment alternatives for a Business case, it is MOST helpful to show risk reduction based on:

A.

cost-benefit analysis.

B.

risk appetite.

C.

regulatory guidelines

D.

control efficiency

Full Access
Question # 35

Which of the following will BEST help to ensure implementation of corrective action plans?

A.

Contracting to third parties

B.

Establishing employee awareness training

C.

Setting target dates to complete actions

D.

Assigning accountability to risk owners

Full Access
Question # 36

Which of the following should be the PRIMARY basis for prioritizing risk responses?

A.

The impact of the risk

B.

The replacement cost of the business asset

C.

The cost of risk mitigation controls

D.

The classification of the business asset

Full Access
Question # 37

During the control evaluation phase of a risk assessment, it is noted that multiple controls are ineffective. Which of the following should be the risk practitioner's FIRST course of action?

A.

Compare the residual risk to the current risk appetite.

B.

Recommend risk remediation of the ineffective controls.

C.

Implement key control indicators (KCIs).

D.

Escalate the control failures to senior management.

Full Access
Question # 38

Reviewing which of the following BEST helps an organization gam insight into its overall risk profile''

A.

Risk register

B.

Risk appetite

C.

Threat landscape

D.

Risk metrics

Full Access
Question # 39

Which of the following is MOST important for effective communication of a risk profile to relevant stakeholders?

A.

Emphasizing risk in the risk profile that is related to critical business activities

B.

Customizing the presentation of the risk profile to the intended audience

C.

Including details of risk with high deviation from the risk appetite

D.

Providing information on the efficiency of controls for risk mitigation

Full Access
Question # 40

An organization has four different projects competing for funding to reduce overall IT risk. Which project should management defer?

A.

Project Charlie

B.

Project Bravo

C.

Project Alpha

D.

Project Delta

Full Access
Go to page: