Easter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 57

Which of the following should be the PRIMARY objective of promoting a risk-aware culture within an organization?

A.

Better understanding of the risk appetite

B.

Improving audit results

C.

Enabling risk-based decision making

D.

Increasing process control efficiencies

Full Access
Question # 58

The BEST way to justify the risk mitigation actions recommended in a risk assessment would be to:

A.

align with audit results.

B.

benchmark with competitor s actions.

C.

reference best practice.

D.

focus on the business drivers

Full Access
Question # 59

Which of the following is MOST important to the effectiveness of key performance indicators (KPIs)?

A.

Relevance

B.

Annual review

C.

Automation

D.

Management approval

Full Access
Question # 60

Establishing and organizational code of conduct is an example of which type of control?

A.

Preventive

B.

Directive

C.

Detective

D.

Compensating

Full Access
Question # 61

During implementation of an intrusion detection system (IDS) to monitor network traffic, a high number of alerts is reported. The risk practitioner should recommend to:

A.

reset the alert threshold based on peak traffic

B.

analyze the traffic to minimize the false negatives

C.

analyze the alerts to minimize the false positives

D.

sniff the traffic using a network analyzer

Full Access
Question # 62

Reviewing results from which of the following is the BEST way to identify information systems control deficiencies?

A.

Vulnerability and threat analysis

B.

Control remediation planning

C.

User acceptance testing (UAT)

D.

Control self-assessment (CSA)

Full Access
Question # 63

The PRIMARY benefit associated with key risk indicators (KRls) is that they:

A.

help an organization identify emerging threats.

B.

benchmark the organization's risk profile.

C.

identify trends in the organization's vulnerabilities.

D.

enable ongoing monitoring of emerging risk.

Full Access
Question # 64

A review of an organization s controls has determined its data loss prevention {DLP) system is currently failing to detect outgoing emails containing credit card data. Which of the following would be MOST impacted?

A.

Key risk indicators (KRls)

B.

Inherent risk

C.

Residual risk

D.

Risk appetite

Full Access
Go to page: