Excellent CRISC Updated 2021 Dumps With 100% Exam Passing Guarantee
Best way to practice test for ISACA CRISC
NEW QUESTION 263
Which of the following is an acceptable method for handling positive project risk?
- A. Exploit
- B. Mitigate
- C. Transfer
- D. Explanation:
Exploit is a method for handling positive project risk. - E. Avoid
Answer: A
Explanation:
B, and C are incorrect. These are all responses which is used for negative risks, and
not the positive risk.
NEW QUESTION 264
An organization has implemented a preventive control to lock user accounts after three unsuccessful login attempts. This practice has been proven to be unproductive, and a change in the control threshold value has been recommended. Who should authorize changing this threshold?
- A. Risk owner
- B. IT system owner
- C. Control owner
- D. IT security manager
Answer: C
NEW QUESTION 265
A risk practitioner is assisting with the preparation of a report on the organization s disaster recovery (DR) capabilities. Which information would have the MOST impact on the overall recovery profile?
- A. The number of systems requiring a recovery plan has increased.
- B. The percentage of systems meeting recovery target times has increased.
- C. The percentage of systems with long recovery target times has decreased.
- D. The number of systems tested in the last year has increased.
Answer: C
NEW QUESTION 266
An organization is considering acquiring a new line of business and wants to develop new IT risk scenarios to guide its decisions. Which of the following would add the MOST value to the new risk scenarios?
- A. Expected losses
- B. Audit findings
- C. Cost-benefit analysis
- D. Organizational threats
Answer: D
Explanation:
Section: Volume D
NEW QUESTION 267
According to the Section-302 of the Sarbanes-Oxley Act of 2002, what does certification of reports implies?
Each correct answer represents a complete solution. Choose three.
- A. The financial statement does not contain any materially untrue or misleading information.
- B. The signing officer has reviewed the report.
- C. The signing officer has presented in the report their conclusions about the effectiveness of their internal controls based on their evaluation as of that date.
- D. The signing officer has evaluated the effectiveness of the issuer's internal controls as of a date at the time to report.
Answer: A,B,C
Explanation:
Explanation/Reference:
Explanation:
Section 302 of Sarbanes-Oxley act has the tremendous impact on the risk management solution adopted by corporations. This section specifies that the reports must be certified by the CEO, CFO, or other senior officer performing similar functions.
Certification of reports establishes:
The signing officer has reviewed the report.
The financial statement do not contain, to the knowledge of signing officer, any materially untrue or
misleading information and represent fairly all financial conditions and results of the enterprise's operations.
The signing officers:
- are responsible for establishing and maintaining internal controls
- have designed such internal controls to ensure that material information relating to the issuer and its consolidated subsidiaries is made - known to such officers by others within those entities, particularly during the period in which the periodic reports are being prepared
- have evaluated the effectiveness of the issuer's internal controls as of a date within 90 days prior to the report
- have presented in the report their conclusions about the effectiveness of their internal controls base on their evaluation as of that date The signing officer have disclosed to external auditors, audit committee, and other directors:
- all significant deficiencies in the design or operation of internal controls which could adversely affect the reliability of the reported financial data
- any fraud, whether or not material, that involves management or other employees who have a significant role in the internal controls of the enterprise The signing officer have indicated in the report any internal controls or changes to those internal
controls which have been implemented since they were evaluated.
Incorrect Answers:
A: The signing officer has evaluated the effectiveness of the issuer's internal controls as of a date within 90 days prior to the report, not at the time of the report.
NEW QUESTION 268
When does the Identify Risks process take place in a project?
- A. At the Initiating stage.
- B. At the Planning stage.
- C. At the Executing stage.
- D. Throughout the project life-cycle.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Identify Risks is the process of determining which risks may affect the project. It also documents risks' characteristics. The Identify Risks process is part of the Project Risk Management knowledge area. As new risks may evolve or become known as the project progresses through its life cycle, Identify Risks is an iterative process. The process should involve the project team so that they can develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions. Risk Register is the only output of this process.
Incorrect Answers:
A, B, C: Identify Risks process takes place at all the stages of a project, because risk changes over time.
NEW QUESTION 269
Who is BEST suited to determine whether a new control properly mitigates data loss risk within a system?
- A. Risk owner
- B. System owner
- C. Data owner
- D. Control owner
Answer: D
NEW QUESTION 270
Risks with low ratings of probability and impact are included for future monitoring in which of the following?
- A. Explanation:
Watch-list contains risks with low rating of probability and impact. This list is useful for future monitoring of low risk factors. - B. Watch-list
- C. Risk register
- D. Observation list
- E. Risk alarm
- F. is incorrect. Risk register is a document that contains the results of the qualitative risk analysis, quantitative risk analysis, and risk response planning. Description, category, cause, probability of occurring, impact on objectives, proposed responses, owner, and the current status
of all identified risks are put in the risk register.
Answer: B
Explanation:
and B are incorrect. No such documents as risk alarm and observation list is prepared
during risk identification process.
NEW QUESTION 271
What are the various outputs of risk response?
- A. Risk register updates
- B. Risk-related contract decisions
- C. Project management plan and Project document updates
- D. Risk Priority Number
- E. Residual risk
Answer: A,B,C
Explanation:
Section: Volume B
Explanation:
The outputs of the risk response planning process are:
* Risk Register Updates: The risk register is written in detail so that it can be related to the priority ranking and the planned response.
* Risk Related Contract Decisions: Risk related contract decisions are the decisions to transmit risk, such as services, agreements for insurance, and other items as required. It provides a means for sharing risks.
* Project Management Plan Updates: Some of the elements of the project management plan updates are:
- Schedule management plan
- Cost management plan
- Quality management plan
- Procurement management plan
- Human resource management plan
- Work breakdown structure
- Schedule baseline
- Cost performance baseline
* Project Document Updates: Some of the project documents that can be updated includes:
- Assumption log updates
- Technical documentation updates
Incorrect Answers:
A: Risk priority number is not an output for risk response but instead it is done before applying response.
Hence it acts as one of the inputs of risk response and is not the output of it.
B: Residual risk is not an output of risk response. Residual risk is the risk that remains after applying controls.
It is not feasible to eliminate all risks from an organization. Instead, measures can be taken to reduce risk to an acceptable level. The risk that is left is residual risk. As, Risk = Threat Vulnerability and Total risk = Threat Vulnerability Asset Value Residual risk can be calculated with the following formula:
Residual Risk = Total Risk - Controls
Senior management is responsible for any losses due to residual risk. They decide whether a risk should be avoided, transferred, mitigated or accepted. They also decide what controls to implement. Any loss due to their decisions falls on their sides.
Residual risk assessments are conducted after mitigation to determine the impact of the risk on the enterprise.
For risk assessment, the effect and frequency is reassessed and the impact is recalculated.
NEW QUESTION 272
A risk practitioner has been asked to advise management on developing a log collection and correlation strategy. Which of the following should be the MOST important consideration when developing this strategy?
- A. Ensuring the inclusion of all computing resources as log sources.
- B. Ensuring time synchronization of log sources.
- C. Ensuring read-write access to all log sources
- D. Ensuring the inclusion of external threat intelligence log sources.
Answer: B
NEW QUESTION 273
FISMA requires federal agencies to protect IT systems and data. How often should compliance be audited by an external organization?
- A. Never
- B. Every three years
- C. Annually
- D. Quarterly
Answer: C
Explanation:
Section: Volume B
Explanation
Explanation:
Inspection of FISMA is required to be done annually. Each year, agencies must have an independent evaluation of their program. The objective is to determine the effectiveness of the program. These evaluations include:
* Testing for effectiveness: Policies, procedures, and practices are to be tested. This evaluation does not test every policy, procedure, and practice. Instead, a representative sample is tested.
* An assessment or report: This report identifies the agency's compliance as well as lists compliance with FISMA. It also lists compliance with other standards and guidelines.
Incorrect Answers:
B, C, D: Auditing of compliance by external organization is done annually, not quarterly or every three years.
NEW QUESTION 274
Which type of cloud computing deployment provides the consumer the GREATEST degree of control over the environment?
- A. Hybrid cloud
- B. Public cloud
- C. Community cloud
- D. Private cloud
Answer: D
NEW QUESTION 275
An IT control gap has been identified in a key process. Who would be the MOST appropriate owner of the risk associated with this gap?
- A. Chief information security officer (CISO)
- B. Key control owner
- C. Operational risk manager
- D. Business process owner
Answer: B
NEW QUESTION 276
Which of the following is the final step in the policy development process?
- A. Management approval
- B. Maintenance and review
- C. Continued awareness activities
- D. Explanation:
Organizations should create a structured ISG document development process. A formal process gives many areas the opportunity to comment on a policy. This is very important for high-level policies that apply to the whole organization. A formal process also makes surethat final policies are communicated to employees. It also provides organizations with a way to make sure that policies are reviewed regularly. In general, a policy development process should include the following steps: In general, a policy development process should include the following steps: 1.Development 2.Stakeholder review 3.Management approval 4.Communication to employees 5.Documentation of compliance or exceptions 6.Continued awareness activities 7.Maintenance and review - E. Communication to employees
Answer: B,D
Explanation:
B, and C are incorrect. These are the earlier phases in policy development process.
NEW QUESTION 277
The BEST metric to monitor the risk associated with changes deployed to production is the percentage of:
- A. changes due to emergencies.
- B. changes not requiring user acceptance testing.
- C. changes that cause incidents.
- D. personnel that have rights to make changes in production.
Answer: C
NEW QUESTION 278
Which of the following controls would BEST decrease exposure if a password is compromised?
- A. Passwords have format restrictions
- B. Passwords are encrypted
- C. Passwords are masked
- D. Password changes are mandated
Answer: B
Explanation:
Section: Volume D
NEW QUESTION 279
Which of the following processes addresses the risks by their priorities, schedules the project management plan as required, and inserts resources and activities into the budget?
- A. Qualitative Risk Analysis
- B. Identify Risks
- C. Plan risk response
- D. Monitor and Control Risk
Answer: C
Explanation:
Section: Volume C
Explanation:
The plan risk response project management process aims to reduce the threats to the project objectives and to increase opportunities. It follows the perform qualitative risk analysis process and perform quantitative risk analysis process. Plan risk response process includes the risk response owner to take the job for each agreed- to and funded risk response. This process addresses the risks by their priorities, schedules the project management plan as required, and inserts resources and activities into the budget. The inputs to the plan risk response process are as follows:
Risk register
Risk management plan
Incorrect Answers:
A: Monitor and Control Risk is the process of implementing risk response plans, tracking identified risks, monitoring residual risk, identifying new risks, and evaluating risk process effectiveness throughout the project.
It can involve choosing alternative strategies, executing a contingency or fallback plan, taking corrective action, and modifying the project management plan.
C: Identify Risks is the process of determining which risks may affect the project. It also documents risks' characteristics. The Identify Risks process is part of the Project Risk Management knowledge area. As new risks may evolve or become known as the project progresses through its life cycle, Identify Risks is an iterative process. The process should involve the project team so that they can develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions. Risk Register is the only output of this process.
* D: Qualitative analysis is the definition of risk factors in terms of high/medium/low or a numeric scale (1 to
10). Hence it determines the nature of risk on a relative scale.
* Some of the qualitative methods of risk analysis are:
* Scenario analysis- This is a forward-looking process that can reflect risk for a given point in time.
* Risk Control Self -assessment (RCSA) - RCSA is used by enterprises (like banks) for the identification and evaluation of operational risk exposure. It is a logical first step and assumes that business owners and managers are closest to the issues and have the most expertise as to the source of the risk. RCSA is a constructive process in compelling business owners to contemplate, and then explain, the issues at hand with the added benefit of increasing their accountability.
NEW QUESTION 280
Which of the following statements is NOT true regarding the risk management plan?
- A. The risk management plan includes thresholds, scoring and interpretation methods, responsible parties, and budgets.
- B. The risk management plan includes a description of the risk responses and triggers.
- C. The risk management plan is an input to all the remaining risk-planning processes.
- D. The risk management plan is an output of the Plan Risk Management process.
- E. Explanation:
The risk management plan details how risk management processes will be implemented, monitored, and controlled throughout the life of the project. The risk management plan does not include responses to risks or triggers. Responses to risks are documented in the risk register as part of the Plan Risk Responses process.
Answer: B
Explanation:
D, and B are incorrect. These all statements are true for risk management plan. The risk management plan details how risk management processes will be implemented, monitored, and controlled throughout the life of the project. It includes thresholds, scoring and interpretation methods, responsible parties, and budgets. It also act as input to all the remaining risk-planning processes.
NEW QUESTION 281
David is the project manager of HRC project. He concluded while HRC project is in process that if he adopts e- commerce, his project can be more fruitful. But he did not engage in electronic commerce (e-commerce) so that he would escape from risk associated with that line of business. What type of risk response had he adopted?
- A. Enhance
- B. Exploit
- C. Acceptance
- D. Avoidance
Answer: D
Explanation:
Section: Volume D
Explanation:
As David did not engage in e-commerce in order to avoid risk, hence he is following risk avoidance strategy.
NEW QUESTION 282
Which of the following roles would be MOST helpful in providing a high-level view of risk related to customer data loss?
- A. Customer data custodian
- B. Customer database manager
- C. Data privacy officer
- D. Audit committee
Answer: A
NEW QUESTION 283
You are the project manager of RFT project. You have identified a risk that the enterprise's IT system and application landscape is so complex that, within a few years, extending capacity will become difficult and maintaining software will become very expensive. To overcome this risk the response adopted is re-architecture of the existing system and purchase of new integrated system. In which of the following risk
prioritization options would this case be categorized?
- A. Business case to be made
- B. Contagious risk
- C. Explanation:
This is categorized as a Business case to be made because the project cost is very large. The response to be implemented requires quite large investment. Therefore it comes under business case to be made. - D. Quick win
- E. Deferrals
Answer: A
Explanation:
is incorrect. Quick win is very effective and efficient response that addresses medium to high risk. But in this the response does not require large investments. Answer: A is incorrect. It addresses costly risk response to a low risk. But here the response is less costly than that of business case to be made. Answer: D is incorrect. This is not risk response prioritization option, instead it is a type of risk that happen with the several of the enterprise's business partners within a very short time frame.
NEW QUESTION 284
Henry is the project manager of the QBG Project for his company. This project has a budget of $4,576,900 and is expected to last 18 months to complete. The CIO, a stakeholder in the project, has introduced a scope change request for additional deliverables as part of the project work. What component of the change control system would review the proposed changes' impact on the features and functions of the project's product?
- A. Configuration management system
- B. Scope change control system
- C. Integrated change control
- D. Cost change control system
Answer: A
Explanation:
Section: Volume D
Explanation:
The configuration management system ensures that proposed changes to the project's scope are reviewed and evaluated for their affect on the project's product.
Configure management process is important in achieving business objectives. Ensuring the integrity of hardware and software configurations requires the establishment and maintenance of an accurate and complete configuration repository. This process includes collecting initial configuration information, establishing baselines, verifying and auditing configuration information, and updating the configuration repository as needed. Effective configuration management facilitates greater system availability minimizes production issues and resolves issues more quickly.
Incorrect Answers:
A: The cost change control system is responsible for reviewing and controlling changes to the project costs.
C: The scope change control system focuses on reviewing the actual changes to the project scope. When a change to the project's scope is proposed, the configuration management system is also invoked.
D: Integrated change control examines the affect of a proposed change on the project as a whole.
NEW QUESTION 285
When determining which control deficiencies are most significant, which of the following would provide the MOST useful information?
- A. Vulnerability assessment results
- B. Benchmarking assessments
- C. Risk analysis results
- D. Exception handling policy
Answer: C
Explanation:
Section: Volume D
NEW QUESTION 286
Risk acceptance of an exception to a security control would MOST likely be justified when:
- A. automation cannot be applied to the control
- B. the end-user license agreement has expired.
- C. business benefits exceed the loss exposure.
- D. the control is difficult to enforce in practice.
Answer: C
NEW QUESTION 287
Which of the following would MOST effectively enable a business operations manager to identify events exceeding risk thresholds?
- A. Transaction logging
- B. A control self-assessment
- C. Continuous monitoring
- D. Benchmarking against peers
Answer: C
NEW QUESTION 288
......
Certified in Risk and Information Systems Control Certification Sample Questions and Practice Exam: https://www.briandumpsprep.com/CRISC-prep-exam-braindumps.html
Real Exam Questions & Answers - ISACA CRISC Dump is Ready: https://drive.google.com/open?id=1-ODQDvPaPTRDIO_2SmpLGwg9Hd9pmStv
