Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 177

Which of the following should be the PRIMARY recipient of reports showing the

progress of a current IT risk mitigation project?

A.

Senior management

B.

Project manager

C.

Project sponsor

D.

IT risk manager

Full Access
Question # 178

A bank is experiencing an increasing incidence of customer identity theft. Which of the following is the BEST way to mitigate this risk?

A.

Implement monitoring techniques.

B.

Implement layered security.

C.

Outsource to a local processor.

D.

Conduct an awareness campaign.

Full Access
Question # 179

Which of the following is the BEST way to support communication of emerging risk?

A.

Update residual risk levels to reflect the expected risk impact.

B.

Adjust inherent risk levels upward.

C.

Include it on the next enterprise risk committee agenda.

D.

Include it in the risk register for ongoing monitoring.

Full Access
Question # 180

Which of the following would prompt changes in key risk indicator {KRI) thresholds?

A.

Changes to the risk register

B.

Changes in risk appetite or tolerance

C.

Modification to risk categories

D.

Knowledge of new and emerging threats

Full Access
Question # 181

Who is PRIMARILY accountable for risk treatment decisions?

A.

Risk owner

B.

Business manager

C.

Data owner

D.

Risk manager

Full Access
Question # 182

Risk aggregation in a complex organization will be MOST successful when:

A.

using the same scales in assessing risk

B.

utilizing industry benchmarks

C.

using reliable qualitative data for risk Hems

D.

including primarily low-level risk factors

Full Access
Question # 183

The BEST way to test the operational effectiveness of a data backup procedure is to:

A.

conduct an audit of files stored offsite.

B.

interview employees to compare actual with expected procedures.

C.

inspect a selection of audit trails and backup logs.

D.

demonstrate a successful recovery from backup files.

Full Access
Question # 184

The effectiveness of a control has decreased. What is the MOST likely effect on the associated risk?

A.

The risk impact changes.

B.

The risk classification changes.

C.

The inherent risk changes.

D.

The residual risk changes.

Full Access
Go to page: