Go Back on CRISC Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

CRISC Practice Test


Page 35 out of 193 Pages

Topic 2 : Pool B Jul-Aug-Sep

The PRIMARY objective of The board of directors periodically reviewing the risk profile is to help ensure:


A.

the risk strategy is appropriate


B.

KRIs and KPIs are aligned


C.

performance of controls is adequate


D.

the risk monitoring process has been established





B.
  

KRIs and KPIs are aligned



Which of the following is MOST effective against external threats to an organizations confidential
information?


A.

Single sign-on


B.

Data integrity checking


C.

Strong authentication


D.

Intrusion detection system





C.
  

Strong authentication



The MAIN reason for creating and maintaining a risk register is to:


A.

assess effectiveness of different projects.


B.

define the risk assessment methodology.


C.

ensure assets have low residual risk.


D.

account for identified key risk factors.





D.
  

account for identified key risk factors.



Which of the following aspects of an IT risk and control self-assessment would be MOST important to include
in a report to senior management?


A.

Changes in control design


B.

A decrease in the number of key controls


C.

Changes in control ownership


D.

An increase in residual risk





D.
  

An increase in residual risk



After mapping generic risk scenarios to organizational security policies, the NEXT course of action should be
to:


A.

record risk scenarios in the risk register for analysis.


B.

validate the risk scenarios for business applicability.


C.

reduce the number of risk scenarios to a manageable set.


D.

perform a risk analysis on the risk scenarios.





B.
  

validate the risk scenarios for business applicability.




Page 35 out of 193 Pages
Previous