Leads4pass > Isaca > Isaca Certifications > CRISC > CRISC Online Practice Questions and Answers

CRISC Online Practice Questions and Answers

Questions 4

Which of the following establishes mandatory rules, specifications and metrics used to measure compliance against quality, value, etc.?

A. Framework

B. Legal requirements

C. Standard

D. Practices

Buy Now
Questions 5

Which of the following is the MOST important consideration when determining whether to accept residual risk after security controls have been implemented on a critical system?

A. Cost versus benefit of additional mitigating controls

B. Annualized loss expectancy (ALE) for the system

C. Frequency of business impact

D. Cost of the Information control system

Buy Now
Questions 6

The PRIMARY objective of a risk identification process is to:

A. evaluate how risk conditions are managed.

B. determine threats and vulnerabilities.

C. estimate anticipated financial impact of risk conditions.

D. establish risk response options.

Buy Now
Questions 7

The BEST metric to monitor the risk associated with changes deployed to production is the percentage of:

A. changes due to emergencies.

B. changes that cause incidents.

C. changes not requiring user acceptance testing.

D. personnel that have rights to make changes in production.

Buy Now
Questions 8

Which of the following is MOST effective against external threats to an organizations confidential information?

A. Single sign-on

B. Data integrity checking

C. Strong authentication

D. Intrusion detection system

Buy Now
Questions 9

A web-based service provider with a low risk appetite for system outages is reviewing its current risk profile for online security. Which of the following observations would be MOST relevant to escalate to senior management?

A. An increase in attempted distributed denial of service (DDoS) attacks

B. An increase in attempted website phishing attacks

C. A decrease in achievement of service level agreements (SLAs)

D. A decrease in remediated web security vulnerabilities

Buy Now
Questions 10

An organization's business process requires the verbal verification of personal information in an environment where other customers may overhear this information. Which of the following is the MOST significant risk?

A. The customer may view the process negatively.

B. The information could be used for identity theft.

C. The process could result in intellectual property theft.

D. The process could result in compliance violations.

Buy Now
Questions 11

Which of the following BEST enables senior management to compare the ratings of risk scenarios?

A. Control self-assessment (CSA)

B. Key risk indicators (KRIs)

C. Risk heat map

D. Key performance indicators (KPIs)

Buy Now
Questions 12

Which of the following is MOST important for the organization to consider before implementing a new in-house developed artificial intelligence (AI) solution?

A. Data feeds

B. Expected algorithm outputs

C. Industry trends in AI

D. Alert functionality

Buy Now
Questions 13

Which of the following is MOST important to review when evaluating the ongoing effectiveness of the IT risk register?

A. The timeframes for risk response actions

B. The costs associated with mitigation options

C. The cost-benefit analysis of each risk response

D. The status of identified risk scenarios

Buy Now
Exam Code: CRISC
Exam Name: Certified in Risk and Information Systems Control
Last Update: Feb 22, 2025
Questions: 2246
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99