Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 193

A risk practitioner observed Vial a high number of pokey exceptions were approved by senior management. Which of the following is the risk practitioner’s BEST course of action to determine root cause?

A.

Review the risk profile

B.

Review pokey change history

C.

interview the control owner

D.

Perform control testing

Full Access
Question # 194

During the risk assessment of an organization that processes credit cards, a number of existing controls have been found to be ineffective and do not meet industry standards. The overall control environment may still be effective if:

A.

compensating controls are in place.

B.

a control mitigation plan is in place.

C.

risk management is effective.

D.

residual risk is accepted.

Full Access
Question # 195

Which of the following methods would BEST contribute to identifying obscure risk scenarios?

A.

Brainstorming sessions

B.

Control self-assessments

C.

Vulnerability analysis

D.

Monte Carlo analysis

Full Access
Question # 196

The risk associated with an asset before controls are applied can be expressed as:

A.

a function of the likelihood and impact

B.

the magnitude of an impact

C.

a function of the cost and effectiveness of control.

D.

the likelihood of a given threat

Full Access
Question # 197

Establishing and organizational code of conduct is an example of which type of control?

A.

Preventive

B.

Directive

C.

Detective

D.

Compensating

Full Access
Question # 198

Which of the following is the GREATEST risk associated with the misclassification of data?

A.

inadequate resource allocation

B.

Data disruption

C.

Unauthorized access

D.

Inadequate retention schedules

Full Access
Question # 199

An organization has allowed its cyber risk insurance to lapse while seeking a new insurance provider. The risk practitioner should report to management that the risk has been:

A.

transferred

B.

mitigated.

C.

accepted

D.

avoided

Full Access
Question # 200

Which of the following would BEST facilitate the implementation of data classification requirements?

A.

Assigning a data owner

B.

Scheduling periodic audits

C.

Implementing technical controls over the assets

D.

Implementing a data loss prevention (DLP) solution

Full Access
Go to page: