Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 89

Which risk response strategy could management apply to both positive and negative risk that has been identified?

A.

Transfer

B.

Accept

C.

Exploit

D.

Mitigate

Full Access
Question # 90

Which of the following is the MOST comprehensive resource for prioritizing the implementation of information systems controls?

A.

Data classification policy

B.

Emerging technology trends

C.

The IT strategic plan

D.

The risk register

Full Access
Question # 91

Which of the following provides the MOST useful information to assess the magnitude of identified deficiencies in the IT control environment?

A.

Peer benchmarks

B.

Internal audit reports

C.

Business impact analysis (BIA) results

D.

Threat analysis results

Full Access
Question # 92

Which of the following is the MOST important consideration for effectively maintaining a risk register?

A.

An IT owner is assigned for each risk scenario.

B.

The register is updated frequently.

C.

The register is shared with executive management.

D.

Compensating controls are identified.

Full Access
Question # 93

Which of the following can be used to assign a monetary value to risk?

A.

Annual loss expectancy (ALE)

B.

Business impact analysis

C.

Cost-benefit analysis

D.

Inherent vulnerabilities

Full Access
Question # 94

A risk owner has identified a risk with high impact and very low likelihood. The potential loss is covered by insurance. Which of the following should the risk practitioner do NEXT?

A.

Recommend avoiding the risk.

B.

Validate the risk response with internal audit.

C.

Update the risk register.

D.

Evaluate outsourcing the process.

Full Access
Question # 95

Within the three lines of defense model, the accountability for the system of internal control resides with:

A.

the chief information officer (CIO).

B.

the board of directors

C.

enterprise risk management

D.

the risk practitioner

Full Access
Question # 96

The BEST key performance indicator (KPI) to measure the effectiveness of a vendor risk management program is the percentage of:

A.

vendors providing risk assessments on time.

B.

vendor contracts reviewed in the past year.

C.

vendor risk mitigation action items completed on time.

D.

vendors that have reported control-related incidents.

Full Access
Go to page: