[Dec 18, 2021] CRISC Exam Dumps - ISACA Practice Test Questions [Q154-Q169]

Share

[Dec 18, 2021] CRISC Exam Dumps - ISACA Practice Test Questions

New Real CRISC Exam Dumps Questions


Exam Syllabus

The ISACA CRISC exam is aimed at those professionals who want to build a career in the field of IT and, in particular, in the risk management domain. The test validates that the candidates possess the basic knowledge and skills in the area of risk and information systems control. The topics covered in the exam are highlighted below:

Information Technology Risk Identification: 27%

  • Identify possible vulnerabilities and threats to people, process, and technology of an organization;
  • Identify the domain of IT risk and contribute to the IT risk management strategy execution to support the business objectives while aligning with the enterprise risk management strategy;
  • Gather and analyze information, such as existing documentation to identify possible IT risk or its impact on the business operations and objectives of an organization;
  • Recognize risk appetite and tolerance as defined by the key stakeholders and senior leadership to align with the business objectives.

For more info visit:

CRISC Exam Reference

 

NEW QUESTION 154
John works as a project manager for BlueWell Inc. He is determining which risks can affect the project.
Which of the following inputs of the identify risks process is useful in identifying risks associated to the time allowances for the activities or projects as a whole, with a width of the range indicating the degrees of risk?

  • A. Activity cost estimates
  • B. Activity duration estimates
  • C. Schedule management plan
  • D. Risk management plan

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The activity duration estimates review is valuable in identifying risks associated to the time allowances for the activities or projects as a whole, with a width of the range indicating the degrees of risk.
Incorrect Answers:
B: The activity cost estimates review is valuable in identifying risks as it provides a quantitative assessment of the expected cost to complete scheduled activities and is expressed as a range, with a width of the range indicating the degrees of risk.
C: A Risk management plan is a document arranged by a project manager to estimate the effectiveness, predict risks, and build response plans to mitigate them. It also consists of the risk assessment matrix.
D: It describes how the schedule contingencies will be reported and assessed.

 

NEW QUESTION 155
What can be determined from the risk scenario chart?

  • A. Capability of enterprise to implement
  • B. Relative positions on the risk map
  • C. The multiple risk factors addressed by a chosen response
  • D. Risk treatment options

Answer: C

 

NEW QUESTION 156
The PRIMARY benefit associated with key risk indicators (KRIs) is that they:

  • A. benchmark the organization's risk profile
  • B. identify trends in the organization's vulnerabilities
  • C. provide ongoing monitoring of emerging risk
  • D. help an organization identify emerging threats

Answer: D

Explanation:
Section: Volume D
Explanation/Reference: https://www.isaca.org/COBIT/Documents/Risk-IT-Framework_fmk_Eng_0610.pdf

 

NEW QUESTION 157
You are the project manager in your enterprise. You have identified occurrence of risk event in your enterprise.
You have pre-planned risk responses. You have monitored the risks that had occurred. What is the immediate step after this monitoring process that has to be followed in response to risk events?

  • A. Communicate lessons learned from risk events
  • B. Initiate incident response
  • C. Eliminate the risk completely
  • D. Update the risk register

Answer: B

Explanation:
Section: Volume D
Explanation:
When the risk events occur then following tasks have to done to react to it:
* Maintain incident response plans
* Monitor risk
* Initiate incident response
* Communicate lessons learned from risk events

 

NEW QUESTION 158
Your project spans the entire organization. You would like to assess the risk of your project but worried about that some of the managers involved in the project could affect the outcome of any risk identification meeting.
Your consideration is based on the fact that some employees would not want to publicly identify risk events that could declare their supervision as poor. You would like a method that would allow participants to anonymously identify risk events. What risk identification method could you use?

  • A. Delphi technique
  • B. Isolated pilot groups
  • C. Root cause analysis
  • D. SWOT analysis

Answer: A

Explanation:
Section: Volume A
Explanation:
The Delphi technique uses rounds of anonymous surveys to build consensus on project risks. Delphi is a technique to identify potential risk. In this technique, the responses are gathered via a question and their inputs are organized according to their contents. The collected responses are sent back to these experts for further input, addition, and comments. The final list of risks in the project is prepared after that. The participants in this technique are anonymous and therefore it helps prevent a person from unduly influencing the others in the group. The Delphi technique helps in reaching the consensus quickly.
Incorrect Answers:
B: Root cause analysis is not an anonymous approach to risk identification.
C: Isolated pilot groups is not a valid risk identification activity.
D: SWOT analysis evaluates the strengths, weaknesses, opportunities, and threats of the project.

 

NEW QUESTION 159
When developing a new risk register, a risk practitioner should focus on which of the following risk management activities?

  • A. Risk monitoring and control
  • B. Risk identification
  • C. Risk management strategy planning
  • D. Risk response planning

Answer: C

 

NEW QUESTION 160
Which of the following will BEST help in communicating strategic risk priorities?

  • A. Heat map
  • B. Balanced scotecard
  • C. Business impact analysis
  • D. Risk register

Answer: A

 

NEW QUESTION 161
Analyzing trends in key control indicators (KCIs) BEST enables a risk practitioner to proactively identify impacts on an organization's:

  • A. risk culture
  • B. risk classification methods
  • C. risk portfolio
  • D. risk-based capital allocation

Answer: C

 

NEW QUESTION 162
You are the project manager of GHT project. You have applied certain control to prevent the unauthorized changes in your project. Which of the following control you would have applied for this purpose?

  • A. Physical and environment protection control
  • B. Configuration management control
  • C. Access control
  • D. Personnel security control

Answer: B

Explanation:
Section: Volume B
Explanation
Explanation:
Configuration management control is a family of controls that addresses both configuration management and change management. Change control practices prevent unauthorized changes. They include goals such as configuring systems for least functionality as a primary method of hardening systems.
Incorrect Answers:
A: The Personal security control is family of controls that includes aspects of personnel security. It includes personnel screening, termination, and transfer.
B: Access control is the family of controls that helps an organization implement effective access control. They ensure that users have the rights and permissions they need to perform their jobs, and no more. It includes principles such as least privilege and separation of duties.
D: Physical and environment protection control are the family that provides an extensive number of controls related to physical security.

 

NEW QUESTION 163
Which of the following guidelines should be followed for effective risk management?
Each correct answer represents a complete solution. Choose three.

  • A. Explanation:
    The primary function of the enterprise is to meet its objective. Each business activity for fulfilling
    enterprise's objective carries both risk and opportunity, therefore objective should be considered
    while managing risk.
    Open and fair communication should me there for effective risk management. Open, accurate,
    timely and transparent information on lT risk is exchanged and serves as the basis for all risk-
    related decisions.
    Cost-benefit analysis should be done for proper weighing the total costs expected against the total
    benefits expected, which is the major aspect of risk management.
  • B. Focus on enterprise's objective
  • C. Promote fair and open communication
  • D. Promote and support consistent performance in risk management
  • E. Balance the costs and benefits of managing risk

Answer: A,B,C,E

Explanation:
is incorrect. For effective risk management, there should be continuous improvement,
not consistent. Because of the dynamic nature of risk, risk management is an iterative, perpetual
and ongoing process; that's why, continuous improvement is required.

 

NEW QUESTION 164
Which of the following control detects problem before it can occur?

  • A. Deterrent control
  • B. Compensation control
  • C. Preventative control
  • D. Detective control
  • E. Explanation:
    Preventative controls are the controls that detect the problem before it occurs. They attempt to predict potential problems and make adjustments to prevent those problems to occur in near future. This prediction is being made by monitoring both the system's operations and its inputs.

Answer: C,E

Explanation:
is incorrect. Deterrent controls are similar to the preventative controls, but they diminish or reverse the attraction of the environment to prevent risk from occurring instead of making adjustments to the environment. Answer: C is incorrect. Compensation controls ensure that normal business operations continue by applying appropriate resource. Answer: B is incorrect. Detective controls simply detect and report on the occurrence of a problems. They identify specific symptoms to potential problems.

 

NEW QUESTION 165
Fred is the project manager of a large project in his organization. Fred needs to begin planning the risk management plan with the project team and key stakeholders. Which plan risk management process tool and technique should Fred use to plan risk management?

  • A. Planning meetings and analysis
  • B. Data gathering and representation techniques
  • C. Information gathering techniques
  • D. Variance and trend analysis

Answer: A

Explanation:
Section: Volume B
Explanation:
There is only one tool and technique available for Fred to plan risk management: planning meetings and analysis. Planning Meeting and Analysis is a tool and technique in the Plan Risk Management process.
Planning meetings are organized by the project teams to develop the risk management plan. Attendees at these meetings include the following:
* Project manager
* Selected project team members
* Stakeholders
* Anybody in the organization with the task to manage risk planning
Sophisticated plans for conducting the risk management activities are defined in these meetings, responsibilities related to risk management are assigned, and risk contingency reserve application approaches are established and reviewed.
Incorrect Answers:
A, B, D: These are not plan risk management tools and techniques.

 

NEW QUESTION 166
In which of the following risk management capability maturity levels does the enterprise takes major business decisions considering the probability of loss and the probability of reward? Each correct answer represents a complete solution. Choose two.

  • A. Level 4
  • B. Level 5
  • C. Level 2
  • D. Level 0

Answer: A,B

Explanation:
Explanation/Reference:
Explanation:
Enterprise having risk management capability maturity level 4 and 5 takes business decisions considering the probability of loss and the probability of reward, i.e., considering all the aspects of risk.
Incorrect Answers:
A: Enterprise having risk management capability maturity level 0 takes business decisions without considering risk credential information.
B: At this low level of risk management capability the enterprise take decisions considering specific risk issues within functional and business silos (e.g., security, business continuity, operations).

 

NEW QUESTION 167
Which of the following key risk indicators (KRIs) is MOST effective for monitoring risk related to a bring your own device (BYOD) program?

  • A. Number of users who have signed a BYOD acceptable use policy
  • B. Number of devices enrolled in the BYOD program
  • C. Number of incidents originating from BYOD devices
  • D. Budget allocated to the BYOD program security controls

Answer: C

Explanation:
Section: Volume D

 

NEW QUESTION 168
Which of the following process ensures that extracted data are ready for analysis?

  • A. Data access
  • B. Data gathering
  • C. Data validation
  • D. Data analysis

Answer: C

Explanation:
Section: Volume B
Explanation:
Data validation ensures that extracted data are ready for analysis. One objective is to perform data quality tests to ensure data are valid complete and free of errors. This may also involve making data from different sources suitable for comparative analysis.
Incorrect Answers:
A: Analysis of data involves simple set of steps or complex combination of commands and other functionality.
Data analysis is designed in such a way to achieve the stated objectives from the project plan. Although this may be applicable to any monitoring activity, it would be beneficial to consider transferability and scalability.
This may include robust documentation, use of software development standards and naming conventions.
C: Data gathering is the process of collecting data on risk to be monitored, prepare a detailed plan and define the project's scope. In the case of a monitoring project, this step should involve process owners, data owners, system custodians and other process stakeholders.
D: In the data access process, management identifies which data are available and how they can be acquired in a format that can be used for analysis. There are two options for data extraction:
* Extracting data directly from the source systems after system owner approval
* Receiving data extracts from the system custodian (IT) after system owner approval

 

NEW QUESTION 169
......

CRISC Certification Exam Dumps Questions in here: https://drive.google.com/open?id=1PDqpJ4URjTMVWLFtlm8xwLbIa8M-LiAL

Pass Your CRISC Exam Easily with Accurate PDF Questions: https://www.validvce.com/CRISC-exam-collection.html