[UPDATED 2024] Free ISACA CRISC Exam Questions Self-Assess Preparation [Q380-Q395]

Share

[UPDATED 2024] Free ISACA CRISC Exam Questions Self-Assess Preparation

CRISC Free Sample Questions to Practice One Year Update

NEW QUESTION # 380
The acceptance of control costs that exceed risk exposure MOST likely demonstrates:

  • A. high risk tolerance
  • B. low risk tolerance
  • C. corporate culture misalignment.
  • D. corporate culture alignment

Answer: A


NEW QUESTION # 381
When a risk cannot be sufficiently mitigated through manual or automatic controls, which of the following options will BEST protect the enterprise from the potential financial impact of the risk?

  • A. Improving staff-training in the risk area
  • B. Updating the IT risk registry
  • C. Insuring against the risk
  • D. Outsourcing the related business process to a third party

Answer: C

Explanation:
Explanation/Reference:
Explanation:
An insurance policy can compensate the enterprise up to 100% by transferring the risk to another company. Hence in this stem risk is being transferred.
Incorrect Answers:
A: Updating the risk registry (with lower values for impact and probability) will not actually change the risk, only management's perception of it.
C: Outsourcing the process containing the risk does not necessarily remove or change the risk. While on other hand, insurance will completely remove the risk.
D: Staff capacity to detect or mitigate the risk may potentially reduce the financial impact, but insurance allows for the risk to be mitigated up to 100%.


NEW QUESTION # 382
Which of the following should be the PRIMARY focus of an IT risk awareness program?

  • A. Demonstrate regulatory compliance
  • B. Communicate IT risk policy to the participants
  • C. Ensure compliance with the organization's internal policies
  • D. Cultivate long-term behavioral change

Answer: D

Explanation:
Section: Volume D
Explanation/Reference:


NEW QUESTION # 383
An organization must make a choice among multiple options to respond to a risk. The stakeholders cannot agree and decide to postpone the decision. Which of the following risk responses has the organization adopted?

  • A. Avoidance
  • B. Mitigation
  • C. Transfer
  • D. Acceptance

Answer: D

Explanation:
Section: Volume D


NEW QUESTION # 384
Which of the following is the MOST important data attribute of key risk indicators (KRIs)?

  • A. The data is automatically produced.
  • B. The data is calculated continuously.
  • C. The data is relevant.
  • D. The data is measurable.

Answer: C


NEW QUESTION # 385
Which of the following will BEST help to ensure implementation of corrective action plans?

  • A. Selling target dates to complete actions
  • B. Establishing employee awareness training
  • C. Contracting to third parties
  • D. Assigning accountability to risk owners

Answer: D


NEW QUESTION # 386
What is the MOST important consideration when aligning IT risk management with the enterprise risk management (ERM) framework?

  • A. Senior management participation
  • B. Risk and control ownership
  • C. Business unit support
  • D. Risk nomenclature and taxonomy

Answer: D

Explanation:
According to the CRISC Review Manual1, risk nomenclature and taxonomy is the set of terms and definitions that are used to describe and classify risks and their attributes. Risk nomenclature and taxonomy is the most important consideration when aligning IT risk management with the enterprise risk management (ERM) framework, as it helps to ensure a common and consistent understanding and communication of risks across the organization. Risk nomenclature and taxonomy also helps to integrate and harmonize the IT risk management processes and activities with the ERM framework, and to facilitate the aggregation and reporting of risks at different levels of the organization. References = CRISC Review Manual1, page 197.


NEW QUESTION # 387
You and your project team are identifying the risks that may exist within your project. Some of the risks are small risks that won't affect your project much if they happen. What should you do with these identified risk events?

  • A. These risks can be dismissed.
  • B. All risks must have a valid, documented risk response.
  • C. These risks can be added to a low priority risk watch list.
  • D. These risks can be accepted.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Low-impact, low-probability risks can be added to the low priority risk watch list.
Incorrect Answers:
A: These risks are not dismissed; they are still documented on the low priority risk watch list.
B: While these risks may be accepted, they should be documented on the low priority risk watch list. This list will be periodically reviewed and the status of the risks may change.
D: Not every risk demands a risk response, so this choice is incorrect.


NEW QUESTION # 388
The GREATEST benefit of including low-probability, high-impact events in a risk assessment is the ability to:

  • A. perform an aggregated cost-benefit analysis.
  • B. develop a comprehensive risk mitigation strategy.
  • C. identify root causes for relevant events.
  • D. develop understandable and realistic risk scenarios.

Answer: B

Explanation:
Section: Volume D


NEW QUESTION # 389
Which of the following BEST indicates the condition of a risk management program?

  • A. Level of financial support
  • B. Number of controls
  • C. Number of risk register entries
  • D. Amount of residual risk

Answer: D

Explanation:
The best indicator of the condition of a risk management program is the amount of residual risk. Residual risk is the risk that remains after the implementation of risk responses. Residual risk reflects the effectiveness and efficiency of the risk management program in reducing the risk exposure to an acceptable level, and in aligning the risk profile with the risk appetite and tolerance of the enterprise. A low amount of residual risk indicates that the risk management program is performing well, and that the controls are adequate and appropriate. A high amount of residual risk indicates that the risk management program is not functioning properly, and that the controls are insufficient or ineffective. References = Risk and Information Systems Control Study Manual, 7th Edition, Chapter 1, Section 1.2.2, page 191


NEW QUESTION # 390
An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in the risk register and accepted. Who should be accountable for any related losses to the organization?

  • A. Risk owner
  • B. Risk practitioner
  • C. Server administrator
  • D. IT risk manager

Answer: A

Explanation:
The risk owner is the person who should be accountable for any related losses to the organization, because they are the person who has the authority and responsibility to manage the risk and its associated controls. The risk owner is also the person who accepts the risk and its residual level, and who monitors and reports on the risk status and performance. The IT risk manager, the server administrator, and the risk practitioner are all involved in the risk management process, but they are not the person who should be accountable for the risk and its outcomes, as they do not have the ultimate decision-making power and accountability for the risk.
References = Risk and Information Systems Control Study Manual, Chapter 3, Section 3.1.1, page 79


NEW QUESTION # 391
You are the project manager of the NKJ Project for your company. The project's success or failure will have a significant impact on your organization's profitability for the coming year. Management has asked you to identify the risk events and communicate the event's probability and impact as early as possible in the project. Management wants to avoid risk events and needs to analyze the cost-benefits of each risk event in this project. What term is assigned to the low-level of stakeholder tolerance in this project?

  • A. is incorrect. This is not a valid project management and risk management term.
  • B. Mitigation-ready project management
  • C. Explanation:
    Risk utility function is assigned to the low-level of stakeholder tolerance in this project.
    The risk utility function describes a person's or organization's willingness to accept risk. It is
    synonymous with stakeholder tolerance to risk.
    Risk utility function facilitates the selection and acceptance of risk and provides opportunity to
    merge the approach with setting thresholds
    of risk acceptability and using utility-risk ratios if necessary.
  • D. Risk-reward mentality
  • E. Risk avoidance
  • F. Risk utility function
  • G. is incorrect. Risk avoidance is a risk response to avoid negative risk events.

Answer: F

Explanation:
is incorrect. Risk-reward describes the balance between accepting risks and the
expected reward for the risk event. Risk-reward mentality is not a valid project management term.


NEW QUESTION # 392
You are the project manager of your enterprise. You have introduced an intrusion detection system for the control. You have identified a warning of violation of security policies of your enterprise. What type of control is an intrusion detection system (IDS)?

  • A. Recovery
  • B. Detective
  • C. Corrective
  • D. Preventative

Answer: B

Explanation:
Explanation/Reference:
Explanation:
An intrusion detection system (IDS) is a device or software application that monitors network and/or system activities for malicious activities or policy violations and produces reports to a Management Station.
Some systems may attempt to stop an intrusion attempt but this is neither required nor expected of a monitoring system. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, and reporting attempts. In addition, organizations use IDPS for other purposes, such as identifying problems with security policies, documenting existing threats, and deterring individuals from violating security policies.
As IDS detects and gives warning when the violation of security policies of the enterprise occurs, it is a detective control.
Incorrect Answers:
B: These controls make effort to reduce the impact of a threat from problems discovered by detective controls. As IDS only detects but not reduce the impact, hence it is not a corrective control.
C: As IDS only detects the problem when it occurs and not prior of its occurrence, it is not preventive control.
D: These controls make efforts to overcome the impact of the incident on the business, hence IDS is not a recovery control.


NEW QUESTION # 393
A vulnerability assessment of a vendor-supplied solution has revealed that the software is susceptible to cross-site scripting and SQL injection attacks. Which of the following will BEST mitigate this issue?

  • A. Monitor the databases for abnormal activity
  • B. Require the software vendor to remediate the vulnerabilities
  • C. Accept the risk and let the vendor run the software as is
  • D. Approve exception to allow the software to continue operating

Answer: B

Explanation:
Cross-site scripting (XSS) and SQL injection are two common types of web application attacks that can compromise the confidentiality, integrity, and availability of data and systems. XSS allows an attacker to inject malicious code into a web page that is viewed by other users, while SQL injection allows an attacker to execute arbitrary commands on a database server by manipulating the input parameters of a web application.
Both attacks can result in data theft, unauthorized access, defacement, denial of service, and more.
To mitigate these attacks, the best option is to require the software vendor to remediate the vulnerabilities by applying secure coding practices, such as input validation, output encoding, parameterized queries, and HTML sanitization. These techniques can prevent or limit the impact of XSS and SQL injection by ensuring that user input is not interpreted as code or commands by the web browser or the database server. The software vendor should also provide regular updates and patches to fix any known or newly discovered vulnerabilities.
The other options are not effective or acceptable ways to mitigate these attacks. Monitoring the databases for abnormal activity can help detect and respond to SQL injection attacks, but it does not prevent them from happening or address the root cause of the vulnerability. Approving an exception to allow the software to continue operating can expose the organization to unnecessary risks and liabilities, as well as violate compliance requirements and standards. Accepting the risk and letting the vendor run the software as is can also have serious consequences for the organization, as it implies that the potential impact and likelihood of the attacks are low or acceptable, which may not be the case. References =
* IT Risk Resources | ISACA
* CRISC Certification | Certified in Risk and Information Systems Control | ISACA
* Cross Site Scripting Prevention Cheat Sheet - OWASP
* A novel technique to prevent SQL injection and cross-site scripting attacks using Knuth-Morris-Pratt string match algorithm | EURASIP Journal on Information Security | Full Text
* Difference Between XSS and SQL Injection - GeeksforGeeks


NEW QUESTION # 394
When of the following standard operating procedure (SOP) statements BEST illustrates appropriate risk register maintenance?

  • A. Remove risk when mitigation results in residual risk within tolerance levels
  • B. Remove risk that has been mitigated by third-party transfer
  • C. Remove risk that management has decided to accept
  • D. Remove risk only following a significant change in the risk environment

Answer: A

Explanation:
The standard operating procedure (SOP) statement that best illustrates appropriate risk register maintenance is to remove risk when mitigation results in residual risk within tolerance levels. Residual risk is the risk that remains after the risk response or mitigation has been applied. Tolerance levels are the acceptable or allowable ranges of variation or deviation from the expected or desired outcomes or objectives. When the mitigation results in residual risk within tolerance levels, it means that the risk has been reduced or managed to an acceptable or satisfactory level, and that no further action or monitoring is required. Therefore, the risk can be removed from the risk register, as it is no longer a significant or relevant risk for the organization. The other options are not as appropriate as removing risk when mitigation results in residual risk within tolerance levels, as they are related to the transfer, acceptance, or change of the risk, not the removal of the risk. References = Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.4: IT Risk Response, page 87.


NEW QUESTION # 395
......

Real exam questions are provided for Isaca Certificaton tests, which can make sure you 100% pass: https://www.validvce.com/CRISC-exam-collection.html

Download CRISC exam with ISACA CRISC Real Exam Questions: https://drive.google.com/open?id=1PDqpJ4URjTMVWLFtlm8xwLbIa8M-LiAL