Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 449

When assessing the maturity level of an organization's risk management framework, which of the following should be of GREATEST concern to a risk practitioner?

A.

Reliance on qualitative analysis methods

B.

Lack of a governance, risk, and compliance (GRC) tool

C.

Lack of senior management involvement

D.

Use of multiple risk registers

Full Access
Question # 450

Which of the following is the BEST metric to demonstrate the effectiveness of an organization's patch management process?

A.

Average time to implement patches after vendor release

B.

Number of patches tested prior to deployment

C.

Increase in the frequency of patches deployed into production

D.

Percent of patches implemented within established timeframe

Full Access
Question # 451

A user has contacted the risk practitioner regarding malware spreading laterally across the organization's corporate network. Which of the following is the risk practitioner’s BEST course of action?

A.

Review all log files generated during the period of malicious activity.

B.

Perform a root cause analysis.

C.

Notify the cybersecurity incident response team.

D.

Update the risk register.

Full Access
Question # 452

The risk to an organization's reputation due to a recent cybersecurity breach is PRIMARILY considered to be:

A.

financial risk.

B.

data risk.

C.

operational risk.

D.

strategic risk.

Full Access
Question # 453

Warning banners on login screens for laptops provided by an organization to its employees are an example of which type of control?

A.

Corrective

B.

Preventive

C.

Detective

D.

Deterrent

Full Access
Question # 454

Which of the following is the MOST significant indicator of the need to perform a penetration test?

A.

An increase in the number of high-risk audit findings

B.

An increase in the number of security incidents

C.

An increase in the percentage of turnover in IT personnel

D.

An increase in the number of infrastructure changes

Full Access
Question # 455

The PRIMARY reason to implement a formalized risk taxonomy is to:

A.

reduce subjectivity in risk management.

B.

comply with regulatory requirements.

C.

demonstrate best industry practice.

D.

improve visibility of overall risk exposure.

Full Access
Question # 456

An organization requires a third party for processing customer personal data. Which of the following is the BEST approach when sharing data over a public network?

A.

Include a nondisclosure agreement (NDA) for personal data in the contract.

B.

Implement a digital rights protection tool to monitor data.

C.

Use a virtual private network (VPN) to communicate data.

D.

Transfer a read-only version of the data.

Full Access
Go to page: