Go Back on CRISC Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

CRISC Practice Test


Page 21 out of 193 Pages

Topic 2 : Pool B Jul-Aug-Sep

An organization has engaged a third party to provide an Internet gateway encryption service that protects sensitive data uploaded to a cloud service. This is an example of risk:


A.

mitigation.


B.

avoidance.


C.

transfer.


D.

acceptance.





A.
  

mitigation.



Which of the following would be the BEST key performance indicator (KPI) for monitoring the effectiveness of the IT asset management process?


A.

Percentage of unpatched IT assets


B.

Percentage of IT assets without ownership


C.

The number of IT assets securely disposed during the past year


D.

The number of IT assets procured during the previous month





B.
  

Percentage of IT assets without ownership



Which of the following is the MOST important factor when deciding on a control to mitigate risk exposure? 


A.

Relevance to the business process


B.

Regulatory compliance requirements


C.

Cost-benefit analysis


D.

Comparison against best practice





B.
  

Regulatory compliance requirements



Which of the following would be a risk practitioners BEST recommendation for preventing cyber intrusion?


A.

Establish a cyber response plan


B.

Implement data loss prevention (DLP) tools.


C.

Implement network segregation.


D.

Strengthen vulnerability remediation efforts





D.
  

Strengthen vulnerability remediation efforts



Which of the following is an IT business owner's BEST course of action following an unexpected increase in emergency changes?


A.

Evaluating the impact to control objectives


B.

Conducting a root cause analysis


C.

Validating the adequacy of current processes


D.

Reconfiguring the IT infrastructure





B.
  

Conducting a root cause analysis




Page 21 out of 193 Pages
Previous