Go Back on CRISC Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

CRISC Practice Test


Page 40 out of 193 Pages

Topic 2 : Pool B Jul-Aug-Sep

Which stakeholders are PRIMARILY responsible for determining enterprise IT risk appetite?


A.

Audit and compliance management


B.

The chief information officer (CIO) and the chief financial officer (CFO)


C.

Enterprise risk management and business process owners


D.

Executive management and the board of directors





D.
  

Executive management and the board of directors



A risk practitioner is reporting on an increasing trend of ransomware attacks in the industry. Which of the
following information is MOST important to include to enable an informed response decision by key
stakeholders?


A.

Methods of attack progression


B.

Losses incurred by industry peers


C.

Most recent antivirus scan reports


D.

Potential impact of events





D.
  

Potential impact of events



Which of the following BEST measures the efficiency of an incident response process?


A.

Number of incidents escalated to management


B.

Average time between changes and updating of escalation matrix


C.

Average gap between actual and agreed response times


D.

Number of incidents lacking responses





C.
  

Average gap between actual and agreed response times



Which of the following is MOST effective in continuous risk management process improvement?


A.

Periodic assessments


B.

Change management


C.

Awareness training


D.

Policy updates





C.
  

Awareness training



Which of the following provides the MOST up-to-date information about the effectiveness of an organization's
overall IT control environment?


A.

Key performance indicators (KPIs)


B.

Risk heat maps


C.

Internal audit findings


D.

Periodic penetration testing





A.
  

Key performance indicators (KPIs)




Page 40 out of 193 Pages
Previous