Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 209

IT management has asked for a consolidated view into the organization's risk profile to enable project prioritization and resource allocation. Which of the following materials would

be MOST helpful?

A.

IT risk register

B.

List of key risk indicators

C.

Internal audit reports

D.

List of approved projects

Full Access
Question # 210

Which of the following is the MOST important consideration when performing a risk assessment of a fire suppression system within a data center?

A.

Insurance coverage

B.

Onsite replacement availability

C.

Maintenance procedures

D.

Installation manuals

Full Access
Question # 211

Which of the following is the BEST method for determining an enterprise's current appetite for risk?

A.

Comparative analysis of peer companies

B.

Reviews of brokerage firm assessments

C.

Interviews with senior management

D.

Trend analysis using prior annual reports

Full Access
Question # 212

An organization uses a vendor to destroy hard drives. Which of the following would BEST reduce the risk of data leakage?

A.

Require the vendor to degauss the hard drives

B.

Implement an encryption policy for the hard drives.

C.

Require confirmation of destruction from the IT manager.

D.

Use an accredited vendor to dispose of the hard drives.

Full Access
Question # 213

Which stakeholder is MOST important to include when defining a risk profile during me selection process for a new third party application'?

A.

The third-party risk manager

B.

The application vendor

C.

The business process owner

D.

The information security manager

Full Access
Question # 214

Which of the following provides the MOST useful information to senior management about risk mitigation status?

A.

Risk strategy

B.

Risk register

C.

Gap analysis

D.

Business impact analysis (BIA)

Full Access
Question # 215

A risk practitioner has identified that the agreed recovery time objective (RTO) with a Software as a Service (SaaS) provider is longer than the business expectation. Which of the following is the risk practitioner's BEST course of action?

A.

Collaborate with the risk owner to determine the risk response plan.

B.

Document the gap in the risk register and report to senior management.

C.

Include a right to audit clause in the service provider contract.

D.

Advise the risk owner to accept the risk.

Full Access
Question # 216

Which of the following would be a weakness in procedures for controlling the migration of changes to production libraries?

A.

The programming project leader solely reviews test results before approving the transfer to production.

B.

Test and production programs are in distinct libraries.

C.

Only operations personnel are authorized to access production libraries.

D.

A synchronized migration of executable and source code from the test environment to the production environment is allowed.

Full Access
Go to page: