Give You Free Regular Updates on CRISC Exam Questions Feb 09, 2024 [Q641-Q659]

Share

Give You Free Regular Updates on CRISC Exam Questions Feb 09, 2024

Achieve the CRISC Exam Best Results with Help from ISACA Certified Experts


ISACA CRISC certification is an essential credential for IT risk management professionals. Certified in Risk and Information Systems Control certification demonstrates an individual's ability to design, implement, monitor and maintain effective risk management programs. The CRISC certification exam is a comprehensive exam that covers four domains and requires a passing score of 450 out of 800 points.


ISACA CRISC (Certified in Risk and Information Systems Control) certification exam is a globally recognized certification that focuses on risk management and information systems control. Certified in Risk and Information Systems Control certification is designed for IT professionals who are responsible for identifying, evaluating, and managing information systems and technology risks. CRISC certification holders are expected to possess expertise in risk management and control, as well as proficiency in the design, implementation, and monitoring of information systems.

 

NEW QUESTION # 641
An IT risk practitioner has determined that mitigation activities differ from an approved risk action plan.
Which of the following is the risk practitioner's BEST course of action?

  • A. Revert the implemented mitigation measures until approval is obtained
  • B. Update the risk register with the implemented risk mitigation actions.
  • C. Validate the adequacy of the implemented risk mitigation measures.
  • D. Report the observation to the chief risk officer (CRO).

Answer: D


NEW QUESTION # 642
Which of the following will BEST support management repotting on risk?

  • A. Key performance Indicators
  • B. Control self-assessment
  • C. Risk policy requirements
  • D. A risk register

Answer: D


NEW QUESTION # 643
Which of the following is the BEST course of action when risk is found to be above the acceptable risk appetite?

  • A. Maintain the current controls.
  • B. Analyze the effectiveness of controls.
  • C. Execute the risk response plan.
  • D. Review risk tolerance levels.

Answer: B

Explanation:
Section: Volume D


NEW QUESTION # 644
You are the project manager of HGT project. You have identified project risks and applied appropriate response for its mitigation. You noticed a risk generated as a result of applying response. What this resulting risk is known as?

  • A. Pure risk
  • B. High risk
  • C. is incorrect. A pure risk is a risk that has only a negative effect on the project. Pure risks
    are activities that are dangerous to complete and manage such as construction, electrical work, or
    manufacturing.
  • D. Secondary risk
  • E. Explanation:
    Secondary risk is a risk that is generated as the result of risk response.
  • F. Response risk

Answer: D

Explanation:
and D are incorrect. These terms are not applied for the risk that is generated as a
result of risk response.


NEW QUESTION # 645
Which of the following is the PRIMARY benefit of stakeholder involvement in risk scenario development?

  • A. Awareness of emerging business threats
  • B. Ability to determine business impact
  • C. Up-to-date knowledge on risk responses
  • D. Decision-making authority for risk treatment

Answer: B


NEW QUESTION # 646
Which of the following conditions presents the GREATEST risk to an application?

  • A. Source code is escrowed.
  • B. Application development is outsourced.
  • C. Application controls are manual.
  • D. Developers have access to production environment.

Answer: D


NEW QUESTION # 647
Which of the following is the PRIMARY reason for a risk practitioner to use global standards related to risk management?

  • A. To identify gaps in risk management practices
  • B. To continuously improve risk management processes
  • C. To build an organizational risk-aware culture
  • D. To comply with legal and regulatory requirements

Answer: B


NEW QUESTION # 648
An organization has allowed several employees to retire early in order to avoid layoffs Many of these employees have been subject matter experts for critical assets Which type of risk is MOST likely to materialize?

  • A. Institutional knowledge loss
  • B. Unauthorized access
  • C. Intellectual property loss
  • D. Confidentiality breach

Answer: A


NEW QUESTION # 649
You are the project manager of the HGT project in Bluewell Inc. The project has an asset valued at
$125,000 and is subjected to an exposure factor of 25 percent. What will be the Single Loss Expectancy of this project?

  • A. $ 31,250
  • B. $ 5,000
  • C. $ 125,025
  • D. $ 3,125,000

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The Single Loss Expectancy (SLE) of this project will be $31,250.
Single Loss Expectancy is a term related to Quantitative Risk Assessment. It can be defined as the monetary value expected from the occurrence of a risk on an asset. It is mathematically expressed as follows:
Single Loss Expectancy (SLE) = Asset Value (AV) * Exposure Factor (EF)
where the Exposure Factor represents the impact of the risk over the asset, or percentage of asset lost. As an example, if the Asset Value is reduced two third, the exposure factor value is .66. If the asset is completely lost, the Exposure Factor is 1.0. The result is a monetary value in the same unit as the Single Loss Expectancy is expressed.
Therefore,
SLE = Asset Value * Exposure Factor
= 125,000 * 0.25
= $31,250
Incorrect Answers:
A, C, D: These are not SLEs of this project.


NEW QUESTION # 650
Which of the following is true for risk evaluation?

  • A. Risk evaluation is done only when there is significant change.
  • B. Risk evaluation is done annually or when there is significant change.
  • C. Risk evaluation is done every four to six months for critical business processes.
  • D. Risk evaluation is done once a year for every business processes.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Due to the reason that risk is constantly changing, it is being evaluated annually or when there is significant change. This gives best alternative as it takes into consideration a reasonable time frame of one year, and meanwhile it also addresses significant changes (if any).
Incorrect Answers:
A: Evaluating risk only when there are significant changes do not take into consideration the effect of time.
As the risk is changing constantly, small changes do occur with time that would affect the overall risk.
Hence risk evaluation should be done annually too.
B: Evaluating risk once a year is not sufficient in the case when some significant change takes place. This significant change should be taken into account as it affects the overall risk.
D: Risk evaluation need not to be done every four to six months for critical processes, as it does not address important changes in timely manner.


NEW QUESTION # 651
Which of the following aspects of an IT risk and control self-assessment would be MOST important to include in a report to senior management?

  • A. Changes in control design
  • B. A decrease in the number of key controls
  • C. Changes in control ownership
  • D. An increase in residual risk

Answer: B


NEW QUESTION # 652
You are the project manager of the GHY project for your company. This project has a budget of $543,000 and is expected to last 18 months. In this project, you have identified several risk events and created risk response plans. In what project management process group will you implement risk response plans?

  • A. Executing
  • B. Planning
  • C. In any process group where the risk event resides
  • D. Monitoring and Controlling

Answer: D

Explanation:
Section: Volume D
Explanation:
The monitor and control project risk process resides in the monitoring and controlling project management process group. This process is responsible for implementing risk response plans, tracking identified risks, monitoring residual risks, identifying new risks, and evaluating risk process effectiveness through the project.
Incorrect Answers:
B: Risk response plans are implemented as part of the monitoring and controlling process group.
C: Risk response plans are not implemented as part of project planning.
D: Risk response plans are not implemented as part of project execution.


NEW QUESTION # 653
Which of following is NOT used for measurement of Critical Success Factors of the project?

  • A. Productivity
  • B. Quality
  • C. Quantity
  • D. Customer service

Answer: C

Explanation:
Section: Volume C
Explanation/Reference:
Incorrect Answers:
A, B, D: Productivity, quality and customer service are used for evaluating critical service factor of any particular project.


NEW QUESTION # 654
Which of the following should be an element of the risk appetite of an organization?

  • A. The effectiveness of compensating controls
  • B. The amount of inherent risk considered appropriate
  • C. The enterprise's capacity to absorb loss
  • D. The residual risk affected be preventive controls

Answer: C

Explanation:
Section: Volume D


NEW QUESTION # 655
Which of the following statements are true for risk communication? Each correct answer represents a complete solution. Choose three.

  • A. It helps in allocating the information concerning risk among the decision-makers.
  • B. Explanation:
    Risk communication is the process of exchanging information and views about risks among stakeholders, such as groups, individuals, and institutions. Risk communication is mostly concerned with the nature of risk or expressing concerns, views, or reactions to risk managers or institutional bodies for risk management. The key plan to consider and communicate risk is to categorize and impose priorities, and acquire suitable measures to reduce risks. It is important throughout any crisis to put across multifaceted information in a simple and clear manner. Risk communication helps in switching or allocating the information concerning risk among the decision-maker and the stakeholders. Risk communication can be explained more clearly with the help of the following definitions: It defines the issue of what a group does, not just what it says. It must take into account the valuable element in user's perceptions of risk. It will be more valuable if it is thought of as conversation, not instruction. Risk communication is a fundamental and continuing element of the risk analysis exercise, and the involvement of the stakeholder group is from the beginning. It makes the stakeholders conscious of the process at each phase of the risk assessment. It helps to guarantee that the restrictions, outcomes, consequence, logic, and risk assessment are undoubtedly understood by all the stakeholders.
  • C. It requires a practical and deliberate scheduling approach to identify stakeholders, actions, and concerns.
  • D. It defines the issue of what a stakeholders does, not just what it says.
  • E. It requires investigation and interconnectivity of procedural, legal, social, political, and economic factors.

Answer: B,C,D,E

Explanation:
is incorrect. It helps in allocating the information concerning risk not only among the decision-makers but also stakeholders.


NEW QUESTION # 656
What are the key control activities to be done to ensure business alignment?
Each correct answer represents a part of the solution. Choose two.

  • A. Establish an independent test task force that keeps track of all events
  • B. Conduct IT continuity tests on a regular basis or when there are major changes in the IT infrastructure
  • C. Periodically identify critical data that affect business operations
  • D. Define the business requirements for the management of data by IT

Answer: C,D

Explanation:
Section: Volume D
Explanation:
Business alignment require following control activities:
* Defining the business requirements for the management of data by IT.
* Periodically identifying critical data that affect business operations, in alignment with the risk management model and IT service as well as the business continuity plan.
Incorrect Answers:
B: Conducting IT continuity tests on a regular basis or when there are major changes in the IT infrastructure is done for testing IT continuity plan. It does not ensure alignment with business.
D: This is not a valid answer.


NEW QUESTION # 657
You are the project manager of your enterprise. You have identified several risks. Which of the following responses to risk is considered the MOST appropriate?

  • A. Avoiding
  • B. Any of the above
  • C. Accepting
  • D. Insuring

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The appropriate response to the risk is decided by the risk itself, the company's attitude and appetite of risk, and the threat and opportunity combination of the risk.
Incorrect Answers:
B, C, D: Depending upon the condition, that is, the risk itself, the company's attitude and appetite of risk, and the threat and opportunity combination of the risk, these response options can be chosen.


NEW QUESTION # 658
Walter is the project manager of a large construction project. He'll be working with several vendors on the project. Vendors will be providing materials and labor for several parts of the project. Some of the works in the project are very dangerous so Walter has implemented safety requirements for all of the vendors and his own project team. Stakeholders for the project have added new requirements, which have caused new risks in the project. A vendor has identified a new risk that could affect the project if it comes into fruition. Walter agrees with the vendor and has updated the risk register and created potential risk responses to mitigate the risk. What should Walter also update in this scenario considering the risk event?

  • A. is incorrect. The contractual relationship won't change with the vendor as far as project
    risks are concerned.
  • B. Project management plan
  • C. Project contractual relationship with the vendor
  • D. Explanation:
    When new risks are identified as part of the scope additions, Walter should update the risk register
    and the project management plan to reflect the responses to the risk event.
  • E. Project scope statement
  • F. is incorrect. The project scope statement is changed as part of the scope approval that
    has already happened.
  • G. Project communications plan

Answer: B

Explanation:
is incorrect. The project communications management plan may be updated if there's a
communication need but the related to the risk event, not the communication of the risks.


NEW QUESTION # 659
......

Detailed New CRISC Exam Questions for Concept Clearance: https://www.actual4labs.com/ISACA/CRISC-actual-exam-dumps.html

Provide CRISC Practice Test Engine for Preparation: https://drive.google.com/open?id=1-e2zZAp_kGO1-EA1lTxxEgqh11m8VyqP

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now