Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CRISC Exam Dumps - Certified in Risk and Information Systems Control

Go to page:
Question # 481

After a risk has been identified, who is in the BEST position to select the appropriate risk treatment option?

A.

The risk practitioner

B.

The business process owner

C.

The risk owner

D.

The control owner

Full Access
Question # 482

Which of the following is MOST important for senior management to review during an acquisition?

A.

Risk appetite and tolerance

B.

Risk framework and methodology

C.

Key risk indicator (KRI) thresholds

D.

Risk communication plan

Full Access
Question # 483

Which of the following offers the SIMPLEST overview of changes in an organization's risk profile?

A.

A risk roadmap

B.

A balanced scorecard

C.

A heat map

D.

The risk register

Full Access
Question # 484

The head of a business operations department asks to review the entire IT risk register. Which of the following would be the risk manager s BEST approach to this request before sharing the register?

A.

Escalate to senior management

B.

Require a nondisclosure agreement.

C.

Sanitize portions of the register

D.

Determine the purpose of the request

Full Access
Question # 485

An organization has outsourced its customer management database to an external service provider. Of the following, who should be accountable for ensuring customer data privacy?

A.

The organization's business process owner

B.

The organization's information security manager

C.

The organization's vendor management officer

D.

The vendor's risk manager

Full Access
Question # 486

Which of the following is MOST important to review when determining whether a potential IT service provider’s control environment is effective?

A.

Independent audit report

B.

Control self-assessment

C.

MOST important to update when an

D.

Service level agreements (SLAs)

Full Access
Question # 487

A risk practitioner has learned that the number of emergency change management tickets without subsequent approval has doubled from the same period of the previous year. Which of the following is the MOST important action for the risk practitioner to take?

A.

Review the cause of the control failure.

B.

Temporarily suspend emergency changes.

C.

Recommend remedial training.

D.

Initiate a review of the change management process.

Full Access
Question # 488

Which of the following is MOST helpful to understand the consequences of an IT risk event?

A.

Fault tree analysis

B.

Historical trend analysis

C.

Root cause analysis

D.

Business impact analysis (BIA)

Full Access
Go to page: