(Aug-2026) Get professional help from our CRISC Dumps PDF
Give You Free Regular Updates on CRISC Exam Questions
Obtaining the CRISC certification demonstrates an individual's commitment to excellence and professionalism in the field of information systems risk management. Certified in Risk and Information Systems Control certification demonstrates that the individual possesses the knowledge and skills necessary to identify, assess, and manage information systems risks, and to design and implement information systems controls. The CRISC certification also provides a competitive advantage in the job market, as it is widely recognized and respected by employers around the world.
The CRISC certification is highly respected in the industry and can lead to career advancement opportunities in both the private and public sectors. It demonstrates a professional's commitment to staying up-to-date with the latest trends and best practices in risk management and information systems control. By passing the exam, candidates can showcase their ability to identify and mitigate risks to their organization's information systems, which is an essential element of successful business operations in today's digital world.
NEW QUESTION # 302
A risk practitioner is summarizing the results of a high-profile risk assessment sponsored by senior management. The BEST way to support risk-based decisions by senior management would be to:
- A. quantify key risk indicators (KRls).
- B. provide quantified detailed analysis
- C. recommend risk tolerance thresholds.
- D. map findings to objectives.
Answer: D
Explanation:
The best way to support risk-based decisions by senior management would be to map findings to objectives, because this would help them understand how the identified risks affect the achievement of the organization's goals and priorities. Mapping findings to objectives would also help senior management evaluate the trade-offs between different risk responses and allocate resources accordingly. By linking risks to objectives, the risk practitioner can communicate the value and impact of risk management in a clear and relevant way.
References = Risk IT Framework, ISACA, 2022, p. 17
NEW QUESTION # 303
Which of the following aspects are included in the Internal Environment Framework of COSO ERM?
Each correct answer represents a complete solution. Choose three.
- A. Enterprise's working environment
- B. Enterprise's human resource standards
- C. Enterprise's integrity and ethical values
- D. Enterprise's risk appetite
Answer: B,C,D
Explanation:
The internal environment for risk management is the foundational level of the COSO ERM framework, which describes the philosophical basics of managing risks within the implementing enterprise. The different aspects of the internal environment include theenterprise's: Philosophy on risk management Risk appetite Attitudes of Board of Directors Integrity and ethical values Commitment to competence Organizational structure Authority and responsibility Human resource standards
NEW QUESTION # 304
An organization allows programmers to change production systems in emergency situations. Which of the
following is the BEST control?
- A. Periodically reviewing operator logs
- B. Reviewing the programmers' emergency change reports
- C. Implementing an emergency change authorization process
- D. Limiting the number of super users
Answer: C
Explanation:
Implementing an emergency change authorization process is the best control for an organization that allows
programmers to change production systems in emergency situations, because it helps to ensure that the
changes are justified, approved, documented, and tested before they are implemented, and that they are
monitored and reviewed after they are implemented. An emergency change is a change that is required to
resolve or prevent a critical issue or incident that may affect the availability, performance, or security of the
production systems. A production system is a system that is used to support or enable the operational or
business functions or processes of the organization. An emergency change authorization process is a process
that defines the roles and responsibilities, criteria and procedures, and tools and techniques for managing and
controlling the emergency changes. Implementing an emergency change authorization process is the best
control, as it helps to minimize the risks and impacts of theemergency changes, and to maintain the integrity
and reliability of the production systems. Periodically reviewing operator logs, limiting the number of super
users, and reviewing the programmers' emergency change reports are all possible controls for an organization
that allows programmers to change production systems in emergency situations, but they are not the best
control, as they do not provide a comprehensive and consistent approach to the emergency change
management. References = Risk and Information Systems Control Study Manual, Chapter 5, Section 5.4.1,
page 208
NEW QUESTION # 305
Which of the following is the BEST method for discovering high-impact risk types?
- A. Quantitative risk analysis
- B. Delphi technique
- C. Failure modes and effects analysis
- D. Qualitative risk analysis
Answer: C
Explanation:
Section: Volume B
Explanation:
Failure modes and effects analysis is used in discovering high-impact risk types.
FMEA:
* Is one of the tools used within the Six Sigma methodology to design and implement a robust process to:
- Identify failure modes
- Establish a risk priority so that corrective actions can be put in place to address and reduce the risk
- Helps in identifying and documenting where in the process the source of the failure impacts the (internal or external) customer
- Is used to determine failure modes and assess risk posed by the process and thus, to the enterprise as a whole' Incorrect Answers:
A, D: These two are the methods of analyzing risk, but not specifically for high-impact risk types. Hence is not the best answer.
B: Delphi is a technique to identify potential risk. In this technique, the responses are gathered via a question:
and their inputs are organized according to their contents. The collected responses are sent back to these experts for further input, addition, and comments. The final list of risks in the project is prepared after that. The participants in this technique are anonymous and therefore it helps prevent a person from unduly influencing the others in the group. The Delphi technique helps in reaching the consensus quickly.
NEW QUESTION # 306
A key risk indicator (KRI) threshold has reached the alert level, indicating data leakage incidents are highly probable. What should be the risk practitioner's FIRST course of action?
- A. Update the KRI threshold.
- B. Recommend additional controls.
- C. Review incident handling procedures.
- D. Perform a root cause analysis.
Answer: C
Explanation:
A key risk indicator (KRI) is a metric that measures the level of risk exposure or the likelihood of a risk event1. A KRI threshold is a predefined value or range that triggers an alert or action when the KRI reaches or exceeds it2. A data leakage incident is an unauthorized or accidental exposure of sensitive or confidential data to external parties3.
When a KRI threshold reaches the alert level, indicating that data leakage incidents are highly probable, the risk practitioner's first course of action should be to review the incident handling procedures. Incident handling procedures are the plans and actions to be taken in the event of a data breach or security incident, such as data leakage4. Reviewing the incident handling procedures can help the risk practitioner to:
* Verify the roles and responsibilities of the incident response team and other stakeholders
* Confirm the communication and escalation channels and protocols
* Identify the tools and resources available for incident detection, containment, analysis, eradication, recovery, and reporting
* Evaluate the readiness and preparedness of the organization to respond to a data leakage incident
* Update or revise the procedures as needed to reflect the current situation and risk level Reviewing the incident handling procedures can help the risk practitioner to ensure that the organization can respond to a data leakage incident effectively and efficiently, minimizing the potential or expected impact on the organization's operations, reputation, or objectives.
The other options are not the first course of action for the risk practitioner, although they may be relevant or necessary at later stages of the risk management process. Updating the KRI threshold, which means adjusting the value or range that triggers an alert or action, may be appropriate if the KRI threshold is too high or too low, but it does not address the imminent risk of data leakage or the response plan. Recommending additional controls, which means suggesting new or improved measures to prevent, detect, or mitigate data leakage, may be useful for reducing the risk exposure or impact, but it does not ensure that the organization is ready or capable to handle a data leakage incident. Performing a root cause analysis, which means finding and identifying the underlying factors that contributed to the risk event, may be helpful for learning from the incident and improving the risk management strategy, but it is usually done after the incident has occurred and resolved, not before.
References = Key Risk Indicators: Definition, Examples, and Best Practices, KRI Framework for Operational Risk Management | Workiva, What is Data Leakage? Definition, Causes, and Prevention, Incident Response Planning: Best Practices for Businesses
NEW QUESTION # 307
Business areas within an organization have engaged various cloud service providers directly without assistance from the IT department. What should the risk practitioner do?
- A. Recommend the IT department remove access to the cloud services.
- B. Recommend a risk assessment be conducted.
- C. Escalate to the risk committee.
- D. Engage with the business area managers to review controls applied.
Answer: B
Explanation:
The best action for the risk practitioner to take when business areas within an organization have engaged various cloud service providers directly without assistance from the IT department is to recommend a risk assessment be conducted. A risk assessment is a process of identifying, analyzing, and evaluating the risks associated with the use of cloud services, such as financial, privacy, compliance, security, performance, quality, and technical risks12. A risk assessment can help to determine the current and potential risk exposure and impact of the cloud services, as well as the effectiveness and efficiency of the existing or proposed controls. A risk assessment can also help to prioritize the risks and to develop and implement appropriate risk response strategies and plans, such as risk avoidance, reduction, sharing, or acceptance. Recommending a risk assessment is the best action, because it can provide valuable information and guidance to the business areas and the IT department for managing the cloud services in a consistent, effective, and efficient manner, and for aligning the cloud services with the organizational objectives, strategy, and risk appetite. The other options are not the best action, although they may be related or subsequent steps in the risk management process.
Recommending the IT department remove access to the cloud services is a drastic and impractical action, as it may disrupt the business operations and services, and it may not address the underlying causes or drivers of the cloud service adoption. Engaging with the business area managers to review controls applied is a useful and collaborative action, as it can help to understand and evaluate the current state and practices of the cloud service usage, and to identify and address any gaps or issues in the control environment. However, this action should be based on or supported by a risk assessment, rather than preceding or replacing it. Escalating to the risk committee is a reporting and communication action, as it can help to inform and involve the senior management and other stakeholders in the risk management process, and to obtain their support and approval for the risk response actions. However, this action should be done after or along with a risk assessment, rather than before or instead of it. References = Best Practices to Manage Risks in the Cloud - ISACA, Cloud Risk Management - PwC UK
NEW QUESTION # 308
Which of the following risk impacts should be the PRIMARY consideration for determining recovery priorities in a disaster recovery situation?
- A. Recovery costs
- B. Data security
- C. Business disruption
- D. Recovery resource availability
Answer: C
Explanation:
The primary consideration for determining recovery priorities in a disaster recovery situation is the impact of business disruption on the organization's mission, objectives, and stakeholders. Business disruption can result in loss of revenue, reputation, customer satisfaction, market share, and competitive advantage. Therefore, the recovery priorities should be based on the criticality of the business processes and functions that support the organization's value proposition and strategic goals. Data security (A), recovery costs (B), and recovery resource availability (D) are important factors, but they are secondary to the impact of business disruption.
Data security should be ensured throughout the recovery process, but it does not determine the recovery order.
Recovery costs should be balanced with the benefits of restoring the business operations, but they do not reflect the urgency of the recovery. Recovery resource availability should be assessed and allocated according to the recovery priorities, but it does not define the recovery sequence. (Risk and Information Systems Control Review Questions, Answers & Explanations Manual, 5th Edition, page 982)
NEW QUESTION # 309
Risks to an organization's image are referred to as what kind of risk?
- A. Operational
- B. Strategic
- C. Financial
- D. Information
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Strategic risks are those risks which have potential outcome of not fulfilling on strategic objectives of the organization as planned. Since the strategic objective will shape and impact the entire organization, the risk of not meeting that objective can impose a great threat on the organization.
Strategic risks can be broken down into external and internal risks:
External risks are those circumstances from outside the enterprise which will have a potentially
damaging or helpful impact on the enterprise. These risks include sudden change of economy, industry, or regulatory conditions. Some of the external risks are predictable while others are not. For instance, a recession may be predictable and the enterprise may be able to hedge against the dangers economically; but the total market failure may not as predictable and can be much more devastating.
Internal risks usually focus on the image or reputation of the enterprise. some of the risks that are
involved in this are public communication, trust, and strategic agreement from stakeholders and customers.
NEW QUESTION # 310
Which of the following is the MOST important consideration when communicating the risk associated with technology end-of-life to business owners?
- A. Security and availability
- B. Cost and benefit
- C. Maintainability and reliability
- D. Performance and productivity
Answer: B
Explanation:
The most important consideration when communicating the risk associated with technology end-of-life to business owners is the cost and benefit of the risk response options. Technology end-of-life is the situation when a technology product or service is no longer supported by the vendor or manufacturer, and may pose security, compatibility, or performance issues. The risk practitioner should communicate the cost and benefit of the possible risk responses, such as replacing, upgrading, or maintaining the technology, to the business owners, and help them to make informed and rational decisions. Security and availability, maintainability and reliability, and performance and productivity are other possible considerations, but they are not as important as the cost and benefit. References = ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, question 8; CRISC Review Manual, 6th Edition, page 97.
NEW QUESTION # 311
Which of the following statements in an organization's current risk profile report is cause for further action by senior management?
- A. Key performance indicator (KPI) trend data is incomplete.
- B. New key risk indicators (KRIs) have been established.
- C. Key performance indicators (KPIs) are outside of targets.
- D. Key risk indicators (KRIs) are lagging.
Answer: C
Explanation:
A risk profile report is a document that summarizes the current status and trends of the risks that an organization faces, as well as the actions taken or planned to manage them1. A risk profile report is a useful tool for senior management to monitor and oversee the organization's risk management performance and to make informed decisions and adjustments as needed2. One of the key components of a risk profile report is the key performance indicators (KPIs), which are metrics used to measure and evaluate the achievement of the organization's objectives and strategies3. KPIs are aligned with the organization's risk appetite and tolerance, and they have specific targets or benchmarks that indicate the desired level of performance4. Therefore, if the KPIs are outside of targets, it means that the organization is not meeting its objectives and strategies, and that there may be gaps or issues in the risk management process or the risk response actions. This is a cause for further action by senior management, as they need to investigate the root causes of the deviation, assess the impact and implications of the underperformance, and take corrective or preventive measures to improve the situation and bring the KPIs back to the targets. Incomplete KPI trend data, new KRIs, and lagging KRIs are not the most critical statements in a risk profile report that require further action by senior management, as they do not directly indicate a failure or a problem in the risk management performance or the achievement of the objectives and strategies. Incomplete KPI trend data means that there is missing or insufficient information on the historical or projected changes in the KPIs over time. This may affect the accuracy and reliability of the risk profile report, but it does not necessarily mean that the KPIs are outside of targets or that the objectives and strategies are not met. Senior management may need to request or obtain the complete KPI trend data, but this is not as urgent or important as addressing the KPIs that are outside of targets. New KRIs means that there are additional or revised metrics used to measure and monitor the level of risk associated with a particular process, activity, or system within the organization. This may reflect the changes or updates in the risk environment, the risk appetite and tolerance, or the risk assessment methodology. However, new KRIs do not directly indicate a failure or a problem in the risk management performance or the achievement of the objectives and strategies. Senior management may need to review and approve the new KRIs, but this is not as urgent or important as addressing the KPIs that are outside of targets. Lagging KRIs means that there are metrics that measure and monitor the level of risk after a risk event has occurred or a risk response has been implemented. This may provide useful feedback and lessons learned for the risk management process, but it does not directly indicate a failure or a problem in the risk management performance or the achievement of the objectives and strategies. Senior management may need to analyze and evaluate the lagging KRIs, but this is not as urgent or important as addressing the KPIs that are outside of targets. References = Risk and Information Systems Control Study Manual, Chapter 4: Risk and Control Monitoring and Reporting, Section
4.3: Risk Reporting, pp. 201-205.
NEW QUESTION # 312
After a significant change in organizational structure, what is the first step in ensuring proper alignment with the organization's risk management approach?
- A. Revalidate the corporate risk appetite.
- B. Review and adjust key risk indicators (KRIs).
- C. Communicate the new risk profile.
- D. Implement a new risk assessment process.
Answer: A
Explanation:
Changes in organizational structure often affect risk appetite, which defines the amount and type of risk an organization is willing to accept. Revalidating the corporate risk appetite ensures that the organization's risk- taking aligns with its new structure, strategic goals, and culture. While reviewing KRIs and communicating the risk profile are important, they follow after confirming risk appetite alignment. Implementing a new assessment process is not always necessary unless structural changes fundamentally affect risk assessment scope#5:83, 5:104 CRISC_SentenceinNOTE30.pptx#.
NEW QUESTION # 313
Which of the following is the PRIMARY objective of providing an aggregated view of IT risk to business management?
- A. To provide consistent and clear terminology
- B. To allow for proper review of risk tolerance
- C. To identify dependencies for reporting risk
- D. To enable consistent data on risk to be obtained
Answer: D
Explanation:
According to the CRISC Review Manual, the primary objective of providing an aggregated view of IT risk to business management is to enable consistent data on risk to be obtained, because it helps to ensure that the risk information is comparable, reliable, and accurate across the organization. An aggregated view of IT risk is a consolidated and comprehensive representation of the IT risk exposure and impact at the enterprise level, based on the risk identification, analysis, and evaluation processes. Providing an aggregated view of IT risk to business management allows them to understand the overall IT risk profile and performance, and to make informed decisions about the risk management strategies and priorities. The other options are not the primary objective of providing an aggregated view of IT risk, as they are related to other benefits or outcomes of the risk aggregation process. Allowing for proper review of risk tolerance is the objective of establishing the risk context, which defines the scope and boundaries of the risk management activities. Identifying dependencies for reporting risk is the outcome of the risk aggregation process, as it provides a clear and consistent structure and format for the risk communication and reporting. Providing consistent and clear terminology is the objective of developing the risk taxonomy, which is the system of classification and categorization of risks based on common characteristics and attributes. References = CRISC Review Manual, 7th Edition, Chapter 2, Section 2.1.2, page 69.
NEW QUESTION # 314
An unauthorized individual has socially engineered entry into an organization's secured physical premises.
Which of the following is the BEST way to prevent future occurrences?
- A. Require security access badges.
- B. Conduct security awareness training.
- C. Install security cameras.
- D. Employ security guards.
Answer: B
Explanation:
* Social engineering is a technique that involves manipulating or deceiving people into performing actions or divulging information that may compromise the security of an organization or its data12.
* Entry into an organization's secured physical premises is a form of physical access that allows an unauthorized individual to access, steal, or damage the organization's assets, such as equipment, documents, or systems34.
* The best way to prevent future occurrences of social engineering entry into an organization's secured physical premises is to conduct security awareness training, which is an educational program that aims to equip the organization's employees with the knowledge and skills they need to protect the organization's data and sensitive information from cyber threats, such as hacking, phishing, or other breaches56.
* Security awareness training is the best way because it helps the employees to recognize and resist the common and emerging social engineering techniques, such as tailgating, impersonation, or pretexting, that may be used by the attackers to gain physical access to the organization's premises56.
* Security awareness training is also the best way because it fosters a culture of security and responsibility among the employees, and encourages them to follow the best practices and policies for physical security, such as locking the doors, verifying the identity of visitors, or reporting any suspicious activities or incidents56.
* The other options are not the best way, but rather possible measures or controls that may supplement or enhance the security awareness training. For example:
* Employing security guards is a measure that involves hiring or contracting professional personnel who are trained and authorized to monitor, patrol, and protect the organization's premises from unauthorized access or intrusion78. However, this measure is not the best way because it may not be sufficient or effective to prevent or deter all types of social engineering attacks, especially if the attackers are able to bypass, deceive, or coerce the security guards78.
* Installing security cameras is a control that involves using electronic devices that capture and record the visual images of the organization's premises, and provide evidence or alerts of any unauthorized access or activity . However, this control is not the best way because it is reactive rather than proactive, and may not prevent or stop the social engineering attacks before they cause any harm or damage to the organization .
* Requiring security access badges is a control that involves using physical or electronic cards that identify and authenticate the employees or authorized visitors who are allowed to enter the organization's premises, and restrict or deny the access to anyone else . However, this control is not the best way because it may not be foolproof or reliable to prevent or detect the social engineering attacks, especially if the attackers are able to steal, forge, or clone the security access badges . References =
* 1: What is Social Engineering? | Types & Examples of Social Engineering Attacks1
* 2: Social Engineering: What It Is and How to Prevent It | Digital Guardian2
* 3: What is physical Social Engineering and why is it important? - Integrity3603
* 4: What Is Tailgating (Piggybacking) In Cyber Security? - Wlan Labs4
* 5: What Is Security Awareness Training and Why Is It Important? - Kaspersky5
* 6: Security Awareness Training - Cybersecurity Education Online | Proofpoint US6
* 7: Security Guard - Wikipedia7
* 8: Security Guard Services - Allied Universal8
* : Security Camera - Wikipedia
* : Security Camera Systems - The Home Depot
* : Access Badge - Wikipedia
* : Access Control Systems - HID Global
NEW QUESTION # 315
Numerous media reports indicate a recently discovered technical vulnerability is being actively exploited.
Which of the following would be the BEST response to this scenario?
- A. Assess the vulnerability management process.
- B. Conduct a control serf-assessment.
- C. Reassess the inherent risk of the target.
- D. Conduct a vulnerability assessment.
Answer: D
Explanation:
* A technical vulnerability is a weakness or flaw in the design or implementation of an information system or resource that can be exploited or compromised by a threat or source of harm that may affect the organization's objectives or operations. A technical vulnerability may be caused by various factors, such as human error, system failure, process inefficiency, resource limitation, etc.
* A vulnerability assessment is a process of identifying and evaluating the technical vulnerabilities that exist or may arise in the organization's information systems or resources, and determining their severity and impact. A vulnerability assessment can help the organization to assess and prioritize the risks, and to design and implement appropriate controls or countermeasures to mitigate or prevent the risks.
* The best response to the scenario of a recently discovered technical vulnerability being actively
* exploited is to conduct a vulnerability assessment, because it can help the organization to address the following questions:
* What is the nature and extent of the technical vulnerability, and how does it affect the functionality or security of the information system or resource?
* How is the technical vulnerability being exploited or compromised, and by whom or what?
* What are the potential consequences or impacts of the exploitation or compromise of the technical vulnerability for the organization and its stakeholders?
* How can the technical vulnerability be detected and reported, and what are the available or feasible options or solutions to address or correct it?
* Conducting a vulnerability assessment can help the organization to improve and optimize the information system or resource quality and performance, and to reduce or eliminate the technical vulnerability. It can also help the organization to align the information system or resource with the organization's objectives and requirements, and to comply with the organization's policies and standards.
* The other options are not the best responses to the scenario of a recently discovered technical vulnerability being actively exploited, because they do not address the main purpose and benefit of conducting a vulnerability assessment, which is to identify and evaluate the technical vulnerability, and to determine its severity and impact.
* Assessing the vulnerability management process is a process of evaluating and verifying the adequacy and effectiveness of the process that is used to identify, analyze, evaluate, and communicate the technical vulnerabilities, and to align them with the organization's objectives and requirements. Assessing the vulnerability management process can help the organization to improve and optimize the process, and to reduce or eliminate the gaps or weaknesses in the process, but it is not the best response to the scenario, because it does not indicate the nature and extent of the technical vulnerability, and how it affects the organization and its stakeholders.
* Conducting a control self-assessment is a process of evaluating and verifying the adequacy and effectiveness of the controls that are intended to ensure the confidentiality, integrity, availability, and reliability of the information systems and resources, using the input and feedback from the individuals or groups that are involved or responsible for the information systems activities or functions. Conducting a control self-assessment can help the organization to identify and document the control deficiencies, and to align them with the organization's objectives and requirements, but it is not the best response to the scenario, because it does not indicate the nature and extent of the technical vulnerability, and how it affects the organization and its stakeholders.
* Reassessing the inherent risk of the target is a process of reevaluating and recalculating the amount and type of risk that exists in the absence of any controls, and that is inherent to the nature or characteristics of the target, which is the information system or resource that is affected by the technical vulnerability. Reassessing the inherent risk of the target can help the organization to understand and document the risk exposure or level, and to align it with the organization's risk appetite and tolerance, but it is not the best response to the scenario, because it does not indicate the nature and extent of the technical vulnerability, and how it affects the organization and its stakeholders. References =
* ISACA, CRISC Review Manual, 7th Edition, 2022, pp. 40-41, 47-48, 54-55, 58-59, 62-63
* ISACA, CRISC Review Questions, Answers & Explanations Database, 2022, QID 195
* CRISC Practice Quiz and Exam Prep
NEW QUESTION # 316
Which of the following serve as the authorization for a project to begin?
- A. Approval of project management plan
- B. Approval of a risk response document
- C. Approval of risk management document
- D. Approval of a project request document
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Approval of a project initiation document (PID) or a project request document (PRD) is the authorization for a project to begin.
Incorrect Answers:
A: Project management plan is being made after the project is being authorized.
B: Risk response document comes under risk management process, hence the latter phase in project development process.
C: Risk management document is being prepared later after the project initiation, during the risk management plan. It has no scope during project initialization.
NEW QUESTION # 317
You are the project manager of HJT project. Important confidential files of your project are stored on a computer. Keeping the unauthorized access of this computer in mind, you have placed a hidden CCTV in the room, even on having protection password. Which kind of control CCTV is?
- A. Administrative control
- B. Physical control
- C. Management control
- D. Explanation:
CCTV is a physical control. Physical controls protect the physical environment. They include basics such as locks to protect access to secure areas. They also include environmental controls. This section presents the following examples of physical controls: Locked doors, guards, access logs, and closed-circuit television Fire detection and suppression Temperature and humidity detection Electrical grounding and circuit breakers Water detection - E. Technical control
Answer: B
Explanation:
A, and D are incorrect. CCTV is a physical control.
NEW QUESTION # 318
Which of the following is the MOST effective way for a large and diversified organization to minimize risk
associated with unauthorized software on company devices?
- A. Perform frequent internal audits of enterprise IT infrastructure.
- B. Scan end points for applications not included in the asset inventory.
- C. Prohibit the use of cloud-based virtual desktop software.
- D. Conduct frequent reviews of software licenses.
Answer: B
Explanation:
The most effective way for a large and diversified organization to minimize risk associated with unauthorized
software on company devices is to scan end points for applications not included in the asset inventory. An
asset inventory is a document that records and tracks all the hardware and software assets that are owned,
used, or managed by the organization, such as laptops, tablets, smartphones, servers, applications, etc. An
asset inventory helps to identify and classify the assets based on their type, model, location, owner, status, etc.
An asset inventory also helps to monitor and control the assets, such as enforcing security policies, applying
patches and updates, detecting and resolving issues, etc. Scanningend points for applications not included in
the asset inventory helps to minimize the risk of unauthorized software, because it helps to discover and
remove any software that is not approved, authorized, or licensed by the organization, and that may pose
security, legal, or operational risks, such as malware, spyware, pirated software, etc. The other options are not
as effective as scanning end points for applications not included in the asset inventory, although they may
provide some protection or compliance for the software assets. Prohibiting the use of cloud-based virtual
desktop software, conducting frequent reviews of software licenses, and performing frequent internal audits of
enterprise IT infrastructure are all examples of preventive or detective controls, which may help to prevent or
deter the installation or use of unauthorized software, or to verify or validate the software assets, but they do
not necessarily discover or remove the unauthorized software. References = Risk and Information Systems
Control Study Manual, Chapter 3, Section 3.2.1, page 3-11.
NEW QUESTION # 319
Which of the following would be a risk practitioner's BEST course of action when a project team has accepted
a risk outside the established risk appetite?
- A. Document the risk decision in the project risk register.
- B. Escalate the risk decision to the project sponsor for review.
- C. Reject the risk acceptance and require mitigating controls.
- D. Monitor the residual risk level of the accepted risk.
Answer: B
Explanation:
Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its
objectives. Risk appetite can be expressed in qualitative or quantitative terms, and can vary depending on the
context and the stakeholder. Risk appetite should be defined and communicated by the senior management or
the board of directors, and should guide the risk management decisions and actions throughout the
organization. When a project team has accepted a risk outside the established risk appetite, the risk
practitioner's best course of action is to escalate the risk decision to the project sponsor for review, meaning
that the risk practitioner should report the risk acceptance and its rationale to the project sponsor, who is the
person or group that provides the resources and support for the project, and is accountable for its success. The
project sponsor should review the risk decision and determine whether it is aligned with the organization's
objectives and strategy, and whether it requires any further approval or action. References = Risk and
Information Systems Control Study Manual, Chapter 1, Section 1.3.1, p. 25-26
NEW QUESTION # 320
When formulating a social media policy lo address information leakage, which of the following is the MOST important concern to address?
- A. Using social media for personal purposes during working hours
- B. Using social media to maintain contact with business associates
- C. Sharing company information on social media
- D. Sharing personal information on social media
Answer: C
Explanation:
The most important concern to address when formulating a social media policy to address information leakage is sharing company information on social media. Information leakage is the unauthorized or unintentional disclosure of confidential or sensitive information to unauthorized parties. Social media is a platform that enables the users to create and share content, such as text, images, videos, or links, with other users or the public. Sharing company information on social media is the most important concern, as it could expose the company's trade secrets, intellectual property, customer data, financial data, or strategic plans to competitors, hackers, or regulators. Sharing company information on social media could also damage the company's reputation, trust, or credibility, and result in legal or regulatory penalties, fines, or lawsuits. Therefore, a social media policy should clearly define what constitutes company information, and what are the rules and guidelines for sharing or not sharing company information on social media. A social media policy should also specify the roles and responsibilities of the employees, managers, and the social media team, and the consequences and sanctions for violating the policy. Sharing personal information on social media, using social media to maintain contact with business associates, and using social media for personal purposes during working hours are not as important as sharing company information on social media, as they do not directly involve the leakage of company information, and they may not have significant impact or risk on the company. References = CRISC Review Manual, 6th Edition, ISACA, 2015, page 217
NEW QUESTION # 321
......
ISACA CRISC (Certified in Risk and Information Systems Control) Exam is a certification exam for professionals who are seeking to demonstrate their expertise in the field of risk management and information systems control. Certified in Risk and Information Systems Control certification is offered by the Information Systems Audit and Control Association (ISACA), which is a global organization that provides guidance, certifications, and training for professionals in the information technology (IT) field. The CRISC certification is highly respected and recognized in the industry, and passing the exam can help individuals advance their careers in IT risk management and information systems control.
Achieve the CRISC Exam Best Results with Help from ISACA Certified Experts: https://examsboost.dumpstorrent.com/CRISC-exam-prep.html