Go Back on CRISC Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

CRISC Practice Test


Page 12 out of 193 Pages

Topic 1 : Pool A

Employees are repeatedly seen holding the door open for others, so that trailing employees do not have to stop and swipe their own ID badges. This behavior BEST represents:


A.

a threat.


B.

a vulnerability.


C.

an impact


D.

a control.





A.
  

a threat.



Which of the following is the BEST way to determine software license compliance?


A.

List non-compliant systems in the risk register.


B.

Conduct periodic compliance reviews.


C.

Review whistlebtower reports of noncompliance.


D.

Monitor user software download activity.





B.
  

Conduct periodic compliance reviews.



A risk heat map is MOST commonly used as part of an IT risk analysis to facilitate risk:


A.

identification.


B.

treatment.


C.

communication.


D.

assessment





C.
  

communication.



Which of the following BEST indicates that an organization has implemented IT performance requirements?


A.

Service level agreements


B.

Vendor references


C.

Benchmarking data


D.

Accountability matrix





A.
  

Service level agreements



While reviewing a contract of a cloud services vendor, it was discovered that the vendor refuses to accept liability for a sensitive data breach. Which of the following controls will BES reduce the risk associated with such a data breach?


A.

Ensuring the vendor does not know the encryption key


B.

Engaging a third party to validate operational controls


C.

Using the same cloud vendor as a competitor


D.

Using field-level encryption with a vendor supplied key





A.
  

Ensuring the vendor does not know the encryption key




Page 12 out of 193 Pages
Previous