
Latest Nov-2021 ISACA CRISC Dumps Updated 930 Questions
PDF Download Free of CRISC Valid Practice Test Questions
Risk and Control Monitoring & Reporting: 22%
- Monitor and evaluate KPIs to identify trends or changes as they relate to control environments and establish the effectiveness and efficiency of the controls;
- Monitor and evaluate KRI to establish trends or changes in IT risk profile to help the relevant stakeholders;
- Identify and ascertain key risk indicators and thresholds according to present data to allow for monitoring of risk changes;
- Assist in the identification of KPIs and metrics to allow for the evaluation of control performance;
- Constantly supervise and report on IT risks and controls to the appropriate stakeholders to sustain continuous effectiveness and efficiency of the strategy on IT risk management and ensure that it is in alignment with the business objectives;
- Account for the performance, trends, or changes to the overall control environment and risk profile to the appropriate stakeholders for decision making.
How to study the CRISC Exam
PassTestking expert team recommends you to prepare some notes on these topics along with it don’t forget to practice ISACA CRISC Exam dumps which been written by our expert team, Both these will help you a lot to clear this exam with good marks.
NEW QUESTION 434
Where are all risks and risk responses documented as the project progresses?
- A. Project management plan
- B. Risk management plan
- C. Risk response plan
- D. Risk register
Answer: D
Explanation:
Section: Volume C
Explanation:
All risks, their responses, and other characteristics are documented in the risk register. As the project progresses and the conditions of the risk events change, the risk register should be updated to reflect the risk conditions.
Incorrect Answers:
A: The risk management plan addresses the project management's approach to risk management, risk identification, analysis, response, and control.
B: The project management plan is the overarching plan for the project, not the specifics of the risk responses and risk identification.
C: The risk response plan only addresses the planned risk responses for the identified risk events in the risk register.
NEW QUESTION 435
Which of the following risks refer to probability that an actual return on an investment will be lower than the investor's expectations?
- A. Integrity risk
- B. Project ownership risk
- C. Expense risk
- D. Relevance risk
Answer: C
Explanation:
Section: Volume A
Explanation:
Probability that an actual return on an investment will be lower than the investor's expectations is termed as investment risk or expense risk. All investments have some level of risk associated with it due to the unpredictability of the market's direction. This includes consideration of the overall IT investment portfolio.
Incorrect Answers:
A: The risk that data cannot be relied on because they are unauthorized, incomplete or inaccurate is termed as integrity risks.
B: The risk of IT projects failing to meet objectives due to lack of accountability and commitment is referring to as project risk ownership.
C: The risk associated with not receiving the right information to the right people (or process or systems) at the right time to allow the right action to be taken is termed as relevance risk.
NEW QUESTION 436
Which of the following is the GREATEST benefit of analyzing logs collected from different systems?
- A. A record of incidents is maintained.
- B. Security violations can be identified.
- C. Forensic investigations are facilitated.
- D. Developing threats are detected earlier.
Answer: B
NEW QUESTION 437
An organization has allowed its cyber risk insurance to lapse while seeking a new insurance provider. The risk practitioner should report to management that the risk has been:
- A. transferred
- B. accepted
- C. avoided
- D. mitigated
Answer: B
Explanation:
Section: Volume D
Explanation
NEW QUESTION 438
What are the responsibilities of the CRO?
Each correct answer represents a complete solution. Choose three.
- A. Implement corrective actions
- B. Managing the risk assessment process
- C. Advising Board of Directors
- D. Managing the supporting risk management function
Answer: A,B,D
Explanation:
Chief Risk Officer is the executive-level manager in an organization. They provide corporate, guidance, governance, and oversight over the enterprise's risk management activities. The main priority for the CRO is to ensure that the organization is in full compliance with applicable regulations. They may also deal with areas regarding insurance, internal auditing, corporate investigations, fraud, and information security. CRO's responsibilities include: Managing the risk assessment process Implementation of corrective actions Communicate risk management issues Supporting the risk management functions
NEW QUESTION 439
Which of the following processes addresses the risks by their priorities, schedules the project management plan as required, and inserts resources and activities into the budget?
- A. Identify Risks
- B. Monitor and Control Risk
- C. Explanation:
The plan risk response project management process aims to reduce the threats to the project objectives and to increase opportunities. It follows the perform qualitative risk analysis process and perform quantitative risk analysis process. Plan risk response process includes the risk response owner to take the job for each agreed-to and funded risk response. This process addresses the risks by their priorities, schedules the project management plan as required, and inserts resources and activities into the budget. The inputs to the plan risk response process are as follows: Risk register Risk management plan
Answer C
is incorrect. Identify Risks is the process of determining which risks may affect the project. It also documents risks' characteristics. The Identify Risks process is part of the Project Risk Management knowledge area. As new risks may evolve or become known as the project progresses through its life cycle, Identify Risks is an iterative process. The process should involve the project team so that they can develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions. Risk Register is the only output of this process. - D. Plan risk response
- E. Qualitative Risk Analysis
Answer: D
Explanation:
A is incorrect. Monitor and Control Risk is the process of implementing risk response plans, tracking identified risks, monitoring residual risk, identifying new risks, and evaluating risk process effectiveness throughout the project. It can involve choosing alternative strategies, executing a contingency or fallback plan, taking corrective action, and modifying the project management plan. Answer: D is incorrect. Qualitative analysis is the definition of risk factors in terms of high/medium/low or a numeric scale (1 to 10). Hence it determines the nature of risk on a relative scale. Some of the qualitative methods of risk analysis are: Scenario analysis- This is a forward-looking process that can reflect risk for a given point in time. Risk Control Self -assessment (RCSA) - RCSA is used by enterprises (like banks) for the identification and evaluation of operational risk exposure. It is a logical first step and assumes that business owners and managers are closest to the issues and have the most expertise as to the source of the risk. RCSA is a constructive process in compelling business owners to contemplate, and then explain, the issues at hand with the added benefit of increasing their accountability.
NEW QUESTION 440
Judy has identified a risk event in her project that will have a high probability and a high impact. Based on the requirements of the project, Judy has asked to change the project scope to remove the associated requirement and the associated risk. What type of risk response is this?
- A. Avoidance
- B. Exploit
- C. Transference
- D. Not a risk response, but a change request
Answer: A
Explanation:
Section: Volume C
Explanation:
Risk avoidance involves changing the project management plan to eliminate the threat entirely. The project manager may also isolate the project objectives from the risk's impact or change the objective that is in jeopardy. Examples of this include extending the schedule, changing the strategy, or reducing the scope. The most radical avoidance strategy is to shut down the project entirely. Some risks that arise early in the project can be avoided by clarifying requirements, obtaining information, improving communication, or acquiring expertise.
Incorrect Answers:
A: Exploit risk response is used for positive risk or opportunity, not for negative risk.
B: This risk response does require a change request, in some instances, but it's the avoidance risk response and not just a change request.
D: Transference allows the risk to be transferred, not removed from the project, to a third party. Transference usually requires a contractual relationship with the third party.
NEW QUESTION 441
A control for mitigating risk in a key business area cannot be implemented immediately. Which of the following is the risk practitioner's BEST course of action when a compensating control needs to be applied?
- A. Record the risk as accepted in the risk register.
- B. Update the risk response plan.
- C. Inform senior management.
- D. Obtain the risk owner's approval.
Answer: D
Explanation:
Section: Volume D
NEW QUESTION 442
Implementing which of the following will BEST help ensure that systems comply with an established baseline before deployment?
- A. Vulnerability scanning
- B. Continuous monitoring and alerting
- C. Configuration management
- D. Access controls and active logging
Answer: C
NEW QUESTION 443
You work as a project manager for BlueWell Inc. You are involved with the project team on the different risk issues in your project. You are using the applications of IRGC model to facilitate the understanding and managing the rising of the overall risks that have impacts on the economy and society. One of your team members wants to know that what the need to use the IRGC is. What will be your reply?
- A. IRGC addresses the development of resilience and the capacity of organizations and people to face unavoidable risks.
- B. IRGC models aim at building robust, integrative inter-disciplinary governance models for emerging and existing risks.
- C. Explanation:
IRGC is aimed at building robust, integrative inter-disciplinary governance models for emerging and existing risks. The International Risk Governance Council (IRGC) is a self-governing organization whose principle is to facilitate the understanding and managing the rising overall risks that have impacts on the economy and society, human health and safety, the environment at large. IRGC's effort is to build and develop concepts of risk governance, predict main risk issues and present risk governance policy recommendations for the chief decision makers. IRGC mainly emphasizes on rising, universal risks for which governance deficits exist. Its goal is to present recommendations for how policy makers can correct them. IRGC models at constructing strong, integrative interdisciplinary governance models for up-coming and existing risks. - D. IRGC is both a concept and a tool.
- E. IRGC addresses understanding of the secondary impacts of a risk.
Answer: B
Explanation:
is incorrect. As IRGC is aimed at building robust, integrative inter-disciplinary governance models for emerging and existing risks, so it is the best answer for this options D and C are incorrect. Risk governance addresses understanding of the secondary impacts of a risk, the development of resilience and the capacity of organizations and people to face unavoidable risks.
NEW QUESTION 444
An effective control environment is BEST indicated by controls that:
- A. are cost-effective to implement
- B. minimize senior management's risk tolerance.
- C. reduce the thresholds of key risk indicators (KRIs).
- D. manage risk within the organization's risk appetite.
Answer: D
NEW QUESTION 445
Which of the following should be the PRIMARY consideration when assessing the automation of control monitoring?
- A. Cost-benefit analysis of automation
- B. Impact due to failure of control
- C. Contingency plan for residual risk
- D. Frequency of failure of control
Answer: B
Explanation:
Section: Volume D
NEW QUESTION 446
Which of the following BEST describes the utility of a risk?
- A. Explanation:
The utility of the risk describes the usefulness of a particular risk to an individual. Moreover, the
same risk can be utilized by two individuals in different ways. Financial outcomes are one of the
methods for measuring potential value for taking a risk. For example, if the individual's economic
wealth increases, the potential utility of the risk will decrease. - B. is incorrect. Determining financial incentive is one of the method to measure the
potential value for taking a risk, but it is not the valid definition for utility of risk. - C. is incorrect. It is not the valid definition.
- D. The potential opportunity of the risk
- E. The mechanics of how a risk works
- F. The finance incentive behind the risk
- G. The usefulness of the risk to individuals or groups
Answer: A,B,C,G
Explanation:
is incorrect. It is not the valid definition.
NEW QUESTION 447
Which of The following should be of GREATEST concern for an organization considering the adoption of a bring your own device (BYOD) initiative?
- A. User support
- B. Malicious users
- C. Data loss
- D. Device corruption
Answer: C
NEW QUESTION 448
What are the MOST important criteria to consider when developing a data classification scheme to facilitate risk assessment and the prioritization of risk mitigation activities?
- A. Mitigation and control value
- B. Recovery point objective (RPO) and recovery time objective (RTO)
- C. Volume and scope of data generated daily
- D. Business criticality and sensitivity
Answer: D
NEW QUESTION 449
You are the project manager of GHT project. You have identified a risk event on your current project that could save $670,000 in project costs if it occurs. Your organization is considering hiring a vendor to help establish proper project management techniques in order to assure it realizes these savings. Which of the following statements is TRUE for this risk event?
- A. This risk event should be accepted because the rewards outweigh the threat to the project.
- B. This risk event is an opportunity to the project and should be exploited.
- C. is incorrect. This risk event is not accepted as this event has potential to save money as
well as it is shared with a vendor so that all these savings are being realized. - D. Explanation:
This risk event has the potential to save money on project costs and organization is hiring a vendor to assure that all these saving are being realized. Hence this risk event involves sharing with a third party to help assure that the opportunity take place. - E. is incorrect. This risk event can be exploited but as here in this scenario, it is stated that
organization is hiring vendor, therefore event is being shared not exploited. - F. This risk event should be mitigated to take advantage of the savings.
- G. This is a risk event that should be shared to take full advantage of the potential savings.
Answer: C,D,E,G
Explanation:
is incorrect. The risk event is mitigated when it has negative impacts. But here it is
positive consequences (i.e., saving), therefore it is not mitigated.
NEW QUESTION 450
Which of the following BEST reduces the probability of laptop theft?
- A. Asset tag with GPS
- B. Cable lock
- C. Data encryption
- D. Acceptable use policy
Answer: A
NEW QUESTION 451
A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management, the risk practitioner should explain:
- A. this risk scenario is equivalent to more frequent, but lower impact risk scenarios.
- B. an increase in threat events could cause a loss sooner than anticipated.
- C. mitigation plans for threat events should be prepared in the current planning period.
- D. the current level of risk is within tolerance.
Answer: B
Explanation:
Section: Volume D
NEW QUESTION 452
......
CRISC Test Engine files, CRISC Dumps PDF : https://www.passtestking.com/ISACA/CRISC-practice-exam-dumps.html
Latest ISACA CRISC PDF and Dumps (2021) Free Exam Questions Answers: https://drive.google.com/open?id=1u1_cMF2XG6SR1je_6_ooxSKA43LI8h-0