Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 329

Which of the following would MOST likely cause a risk practitioner to change the likelihood rating in the risk register?

A.

Risk appetite

B.

Control cost

C.

Control effectiveness

D.

Risk tolerance

Full Access
Question # 330

Determining if organizational risk is tolerable requires:

A.

mapping residual risk with cost of controls

B.

comparing against regulatory requirements

C.

comparing industry risk appetite with the organizations.

D.

understanding the organization's risk appetite.

Full Access
Question # 331

Of the following, who is accountable for ensuing the effectiveness of a control to mitigate risk?

A.

Control owner

B.

Risk manager

C.

Control operator

D.

Risk treatment owner

Full Access
Question # 332

Which of We following is the MOST effective control to address the risk associated with compromising data privacy within the cloud?

A.

Establish baseline security configurations with the cloud service provider.

B.

Require the cloud prowler 10 disclose past data privacy breaches.

C.

Ensure the cloud service provider performs an annual risk assessment.

D.

Specify cloud service provider liability for data privacy breaches in the contract

Full Access
Question # 333

Which of the following is the MOST important objective of establishing an enterprise risk management (ERM) function within an organization?

A.

To have a unified approach to risk management across the organization

B.

To have a standard risk management process for complying with regulations

C.

To optimize risk management resources across the organization

D.

To ensure risk profiles are presented in a consistent format within the organization

Full Access
Question # 334

A recent regulatory requirement has the potential to affect an organization's use of a third party to supply outsourced business services. Which of the following is the BEST course of action?

A.

Conduct a gap analysis.

B.

Terminate the outsourcing agreement.

C.

Identify compensating controls.

D.

Transfer risk to the third party.

Full Access
Question # 335

A multinational organization is considering implementing standard background checks to' all new employees A KEY concern regarding this approach

A.

fail to identity all relevant issues.

B.

be too costly

C.

violate laws in other countries

D.

be too line consuming

Full Access
Question # 336

Employees are repeatedly seen holding the door open for others, so that trailing employees do not have to stop and swipe their own ID badges. This behavior BEST represents:

A.

a threat.

B.

a vulnerability.

C.

an impact

D.

a control.

Full Access
Go to page: