Exam Questions Answers Braindumps CRISC Exam Dumps PDF Questions
Download Free ISACA CRISC Real Exam Questions
NEW QUESTION # 556
Which of the following is the BEST method for assessing control effectiveness against technical vulnerabilities that could be exploited to compromise an information system?
- A. Systems log correlation analysis
- B. Penetration testing
- C. Vulnerability scanning
- D. Monitoring of intrusion detection system (IDS) alerts
Answer: B
NEW QUESTION # 557
An organization operates in an environment where reduced time-to-market for new software products is a top business priority. Which of the following should be the risk practitioner's GREATEST concern?
- A. Sufficient resources are not assigned to IT development projects.
- B. Customer support help desk staff does not have adequate training.
- C. Email infrastructure does not have proper rollback plans.
- D. The corporate email system does not identify and store phishing emails.
Answer: A
NEW QUESTION # 558
Which of the following is the MAIN benefit of involving stakeholders in the selection of key risk indicators (KRIs)?
- A. Optimizing risk treatment decisions
- B. Obtaining buy-in from risk owners
- C. Leveraging existing metrics
- D. Improving risk awareness
Answer: B
NEW QUESTION # 559
Which of the following BEST enables a risk practitioner to understand management's approach to organizational risk?
- A. Risk appetite and risk tolerance
- B. Industry best practices for risk management
- C. Organizational structure and job descriptions
- D. Prior year's risk assessment results
Answer: A
NEW QUESTION # 560
Which of the following would be of MOST concern to a risk practitioner reviewing risk action plans for documented IT risk scenarios?
- A. Senior management approved multiple changes to several action plans.
- B. Target dates for completion are missing from some action plans.
- C. Many action plans were discontinued after senior management accepted the risk.
- D. Individuals outside IT are managing action plans for the risk scenarios.
Answer: B
NEW QUESTION # 561
Which of the following BEST facilities the alignment of IT risk management with enterprise risk management (ERM)?
- A. Adopting quantitative enterprise risk assessment methods
- B. Adopting qualitative enterprise risk assessment methods
- C. Linking IT risk scenarios to technology objectives
- D. linking IT risk scenarios to enterprise strategy
Answer: D
NEW QUESTION # 562
What are the requirements of monitoring risk?
Each correct answer represents a part of the solution. Choose three.
- A. Information of various stakeholders
- B. Identifying the risk to be monitored
- C. Defining the project's scope
- D. Explanation:
It is important to first understand the risk to be monitored, prepare a detailed plan and define the project's scope for monitoring risk. In the case of a monitoring project, this step should involve process owners, data owners, system custodians and other process stakeholders. - E. Preparation of detailed monitoring plan
Answer: B,C,D,E
Explanation:
is incorrect. Data regarding stakeholders of the project is not required in any phase of risk monitoring.
NEW QUESTION # 563
You are the project manager of the GHT project. You are accessing data for further analysis. You have chosen such a data extraction method in which management monitors its own controls. Which of the following data extraction methods you are using here?
- A. Extracting data from risk register
- B. and D are incorrect. These are not data extraction methods.
- C. Extracting data from lesson learned register
- D. Extracting data from the system custodian (IT) after system owner approval
- E. Extracting data directly from the source systems after system owner approval
- F. Explanation:
Direct extraction from the source system involves management monitoring its own controls,
instead of auditors/third parties monitoring management's controls. It is preferable over extraction
from the system custodian.
Answer: E
Explanation:
is incorrect. Extracting data from the system custodian (IT) after system owner approval,
involves auditors or third parties monitoring management's controls. Here, in this management
does not monitors its own control.
NEW QUESTION # 564
An organization has four different projects competing for funding to reduce overall IT risk. Which project should management defer?
- A. Project Delta
- B. Project Bravo
- C. Project Alpha
- D. Project Charlie
Answer: D
Explanation:
Section: Volume D
NEW QUESTION # 565
Which of the following statements is NOT true regarding the risk management plan?
- A. The risk management plan includes a description of the risk responses and triggers.
- B. The risk management plan is an output of the Plan Risk Management process.
- C. The risk management plan is an input to all the remaining risk-planning processes.
- D. The risk management plan includes thresholds, scoring and interpretation methods, responsible parties, and budgets.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The risk management plan details how risk management processes will be implemented, monitored, and controlled throughout the life of the project. The risk management plan does not include responses to risks or triggers. Responses to risks are documented in the risk register as part of the Plan Risk Responses process.
Incorrect Answers:
A, B, D: These all statements are true for risk management plan. The risk management plan details how risk management processes will be implemented, monitored, and controlled throughout the life of the project. It includes thresholds, scoring and interpretation methods, responsible parties, and budgets. It also acts as input to all the remaining risk-planning processes.
NEW QUESTION # 566
You are the project manager for BlueWell Inc. Your current project is a high priority and high profile project within your organization. You want to identify the project stakeholders that will have the most power in relation to their interest on your project. This will help you plan for project risks, stakeholder management, and ongoing communication with the key stakeholders in your project. In this process of stakeholder analysis, what type of a grid or model should you create based on these conditions?
- A. Stakeholder power/interest grid
- B. is incorrect. The stakeholder register is a listing of stakeholder information and
communication requirements. - C. Stakeholder register
- D. Explanation:
The power/interest grid groups stakeholders based on their level of authority (power) and their
level of interest in your project. The power/interest grid forms a group of the stakeholders based
on their level of authority (power) and their level of interest in the project.
Interest accounts to what degree the stakeholders are affected by examining the project or policy
change, and to what degree of interest or concern they have about it. Power accounts for the
influence the stakeholders have over the project or policy, and to what degree they can help to
accomplish, or block, the preferred change.
Stakeholders, who have high power and interests associated with the project, are the people or
organizations that are fully engaged with the project. When trying to generate strategic change,
this community is the target of any operation. - E. is incorrect. The salience model groups the stakeholders based on their power,
urgency, and legitimacy in the project. - F. Influence/impact grid
- G. Salience model
Answer: A
Explanation:
is incorrect. The influence/impact grid charts is based on the stakeholders involvement
and ability to effect changes to the project's planning and execution.
NEW QUESTION # 567
Which of the following should be the GREATEST concern to a risk practitioner when process documentation is incomplete?
- A. Inability to identify the risk owner
- B. Inability to allocate resources efficiently
- C. Inability to complete the risk register
- D. Inability to identify process experts
Answer: A
NEW QUESTION # 568
You are the project manager of the GHY Project for your company. You need to complete a project management process that will be on the lookout for new risks, changing risks, and risks that are now outdated. Which project management process is responsible for these actions?
- A. Risk monitoring and controlling
- B. Risk planning
- C. Risk analysis
- D. Explanation:
The risk monitoring and controlling is responsible for identifying new risks, determining the status
of risks that may have changed, and determining which risks may be outdated in the project. - E. is incorrect. Risk planning creates the risk management plan and determines how risks
will be identified, analyzed, monitored and controlled, and responded to. - F. Risk identification
- G. is incorrect. Risk identification is a process that identifies risk events in the project.
Answer: A
Explanation:
is incorrect. Risk analysis helps determine the severity of the risk events, the risks'
priority, and the probability and impact of risks.
NEW QUESTION # 569
Mary is the project manager for the BLB project. She has instructed the project team to assemble, to review the risks. She has included the schedule management plan as an input for the quantitative risk analysis process. Why is the schedule management plan needed for quantitative risk analysis?
- A. Mary will utilize the schedule controls to determine how risks may be allowed to change the project schedule.
- B. Mary will utilize the schedule controls and the nature of the schedule for the quantitative analysis of the schedule.
- C. Mary will schedule when the identified risks are likely to happen and affect the project schedule.
- D. Mary will use the schedule management plan to schedule the risk identification meetings throughout the remaining project.
Answer: B
Explanation:
Section: Volume B
Explanation:
The controls within the schedule management plan can shape how quantitative risk analysis will be performed on the schedule.
Schedule management plan also describes how the schedule contingencies will be reported and assessed.
Incorrect Answers:
A: When risks are likely to happen is important, but it is not the best answer for this question C: This is not a valid answer for this question throughout the project, but it is not scheduled during the quantitative risk analysis process.
D: Risks may affect the project schedule, but this is not the best answer for the question.
NEW QUESTION # 570
Which negative risk response usually has a contractual agreement?
- A. Transference
- B. Sharing
- C. Mitigation
- D. Exploiting
Answer: A
Explanation:
Section: Volume D
Explanation:
Transference is the risk response that transfers the risk to a third party, usually for a fee. Insurance and subcontracting of dangerous works are two common examples of transference with a contractual obligation.
Incorrect Answers:
A: Sharing is a positive risk response. Note that sharing may also have contractual obligations, sometimes called teaming agreements.
C: Mitigation is a negative risk response used to lower the probability and/or impact of a risk event.
D: Exploiting is a positive risk response and not a negative response and doesn't have contractual obligations.
NEW QUESTION # 571
Which one of the following is the only output for the qualitative risk analysis process?
- A. Risk register updates
- B. Enterprise environmental factors
- C. Project management plan
- D. Organizational process assets
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Risk register update is the only output of the choices presented for the qualitative risk analysis process.
The four inputs for the qualitative risk analysis process are the risk register, risk management plan, project scope statement, and organizational process assets. The output of perform qualitative risk analysis process is Risk Register Updates. Risk register is updated with the information from perform qualitative risk analysis and the updated risk register is included in the project documents. Updates include the following important elements:
Relative ranking or priority list of project risks
Risks grouped by categories
Causes of risk or project areas requiring particular attention
List of risks requiring response in the near-term
List of risks for additional analysis and response
Watchlist of low priority risks
Trends in qualitative risk analysis results
Incorrect Answers:
A, C, D: These are not the valid outputs for the qualitative risk analysis process.
NEW QUESTION # 572
Which of the following approaches to bring you own device (BYOD) service delivery provides the BEST protection from data loss?
- A. Enforce strong passwords and data encryption
- B. Penetration testing and session timeouts
- C. Implement remote monitoring
- D. Enable data wipe capabilities
Answer: C
Explanation:
Section: Volume D
NEW QUESTION # 573
Which of the following is MOST important when discussing risk within an organization?
- A. Adopting a common risk taxonomy
- B. Using key performance indicators (KPIs)
- C. Using key risk indicators (KRIs)
- D. Creating a risk communication policy
Answer: A
NEW QUESTION # 574
Following an acquisition, the acquiring company's risk practitioner has been asked to update the organization's IT risk profile What is the MOST important information to review from the acquired company to facilitate this task?
- A. Risk assessment and risk register
- B. Risk disclosures in financial statements
- C. Internal and external audit reports
- D. Business objectives and strategies
Answer: A
NEW QUESTION # 575
Which of the following would be MOST useful to senior management when determining an appropriate risk response?
- A. A comparison of current risk levels with estimated inherent risk levels
- B. A comparison of cost variance with defined response strategies
- C. A comparison of current risk levels with established tolerance
- D. A comparison of accepted risk scenarios associated with regulatory compliance
Answer: C
NEW QUESTION # 576
Which of the following is the GREATEST concern when using a generic set of IT risk scenarios for risk analysis?
- A. Implementation costs might increase
- B. Risk factors might not be relevant to the organization
- C. Quantitative analysis might not be possible
- D. Inherent risk might not be considered
Answer: B
Explanation:
Section: Volume D
NEW QUESTION # 577
A risk practitioner has established that a particular control is working as desired, but the annual cost of maintenance has increased and now exceeds the expected annual loss exposure. The result is that the control is:
- A. ineffective.
- B. inefficient.
- C. mature
- D. optimized.
Answer: A
NEW QUESTION # 578
Which of the following is the PRIMARY reason to update a risk register with risk assessment results?
- A. To communicate the level and priority of assessed risk to management
- B. To provide a comprehensive inventory of risk across the organization
- C. To enable the creation of action plans to address nsk
- D. To assign a risk owner to manage the risk
Answer: A
NEW QUESTION # 579
Which of the following is the BEST control to detect an advanced persistent threat (APT)?
- A. Conducting regular penetration tests
- B. Implementing automated log monitoring
- C. Monitoring social media activities
- D. Utilizing antivirus systems and firewalls
Answer: B
NEW QUESTION # 580
......
Latest ISACA CRISC Real Exam Dumps PDF: https://prepcram.pass4guide.com/CRISC-dumps-questions.html