
[Sep 29, 2021] Latest CRISC Exam with Accurate Certified in Risk and Information Systems Control PDF Questions
Practice To CRISC - Test4Engine Remarkable Practice On your Certified in Risk and Information Systems Control Exam
NEW QUESTION 255
IT stakeholders have asked a risk practitioner for IT risk profile reports associated with specific departments to allocate resources for risk mitigation. The BEST way to address this request would be to use:
- A. the cost associated with each control.
- B. historical risk assessments.
- C. key risk indicators (KRls).
- D. information from the risk register.
Answer: C
NEW QUESTION 256
The Identify Risk process determines the risks that affect the project and document their characteristics. Why should the project team members be involved in the Identify Risk process?
- A. They are the individuals that are most affected by the risk events.
- B. They are the individuals that will most likely cause and respond to the risk events.
- C. They are the individuals that will have the best responses for identified risks events within the project.
- D. They are the individuals that will need a sense of ownership and responsibility for the risk events.
Answer: D
Explanation:
Section: Volume A
Explanation:
The project team members should be involved in the risk identification so that they will develop a sense of ownership and responsibility for the risk events and the associated risk responses.
Identify Risks is the process of determining which risks may affect the project. It also documents risks' characteristics. The Identify Risks process is part of the Project Risk Management knowledge area. As new risks may evolve or become known as the project progresses through its life cycle, Identify Risks is an iterative process. The process should involve the project team so that they can develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions. Risk Register is the only output of this process.
Incorrect Answers:
A, B, C: These are not the valid answers for this question.
NEW QUESTION 257
Which of the following would provide the BEST guidance when selecting an appropriate risk treatment plan?
- A. Business Impact analysis
- B. Cost-benefit analysis
- C. Risk mitigation budget
- D. Return on investment
Answer: A
NEW QUESTION 258
You are the project manager of the NNN Project. Stakeholders in the two-year project have requested to send status reports to them via. email every week. You have agreed and send reports every Thursday.
After six months of the project, the stakeholders are pleased with the project progress and they would like you to reduce the status reports to every two weeks. What process will examine the change to this project process and implement it in the project?
- A. Perform integrated change control process
- B. Communications management
- C. Configuration management
- D. Project change control process
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Although this appears to be a simple change the project manager must still follow the rules of the project's change control system.
Integrated change control is a way to manage the changes incurred during a project. It is a method that manages reviewing the suggestions for changes and utilizing the tools and techniques to evaluate whether the change should be approved or rejected. Integrated change control is a primary component of the project's change control system that examines the affect of a proposed change on the entire project.
Incorrect Answers:
A: Configuration management is the documentation and control of the product's features and functions.
B: Communications management is the execution of the communications management plan.
D: The project change control process not valid as it's the parent of the integrated change control process, which is more accurate for this question.
NEW QUESTION 259
A global organization is considering the acquisition of a competitor. Senior management has requested a review of the overall risk profile from the targeted organization.
Which of the following components of this review would provide the MOST useful information?
- A. Risk management policies
- B. Risk appetite statement
- C. Enterprise risk management framework
- D. Risk register
Answer: C
Explanation:
Section: Volume D
Explanation/Reference:
NEW QUESTION 260
Which of the following would be the BEST key performance indicator (KPI) for monitoring the effectiveness of the IT asset management process?
- A. The number of IT assets securely disposed during the past year
- B. Percentage of unpatched IT assets
- C. Percentage of IT assets without ownership
- D. The number of IT assets procured during the previous month
Answer: A
Explanation:
Section: Volume D
NEW QUESTION 261
Which of the following aspects of an IT risk and control self-assessment would be MOST important to include in a report to senior management?
- A. A decrease in the number of key controls
- B. An increase in residual risk
- C. Changes in control ownership
- D. Changes in control design
Answer: C
NEW QUESTION 262
You are the project manager of GFT project. Your project involves the use of electrical motor. It was stated in its specification that if its temperature would increase to 500 degree Fahrenheit the machine will overheat and have to be shut down for 48 hours. If the machine overheats even once it will delay the project's arrival date. So to prevent this you have decided while creating response that if the temperature of the machine reach 450, the machine will be paused for at least an hour so as to normalize its temperature. This temperature of 450 degree is referred to as?
- A. Risk response
- B. Risk trigger
- C. Risk event
- D. Risk identification
Answer: B
Explanation:
Explanation/Reference:
Explanation:
A risk trigger is a warning sign or condition that a risk event is about to happen. Here the warning temperature is 450 degree Fahrenheit, therefore it is referred as risk trigger.
Incorrect Answers:
A: Risk identification is the process of the identifying the risks. This process identifies the risk events that could affect the project adversely or would act as opportunity.
C: Here risk event is 500 degree temperature, as when machine reaches this temperature it should have to be shut-down for 48 hours, which in turn will laid a great impact on the working of project.
D: Risk response here is shutting off of machine when its temperature reaches 450 degree Fahrenheit, so as to prevent the occurring of risk event.
NEW QUESTION 263
An organization has identified a risk exposure due to weak technical controls in a newly implemented HR system. The risk practitioner is documenting the risk in the risk register. The risk should be owned by the:
- A. chief information officer.
- B. chief risk officer.
- C. project manager.
- D. business process owner.
Answer: D
Explanation:
Section: Volume D
NEW QUESTION 264
Which of the following is the MOST important consideration when selecting key risk indicators (KRIs) to monitor risk trends over time?
- A. Ability to aggregate data
- B. Availability of automated reporting systems
- C. Ability to predict trends
- D. Ongoing availability of data
Answer: B
NEW QUESTION 265
You are the risk professional in Bluewell Inc. You have identified a risk and want to implement a specific risk mitigation activity. What you should PRIMARILY utilize?
- A. Technical evaluation report
- B. Budgetary requirements
- C. Vulnerability assessment report
- D. Business case
Answer: D
Explanation:
Explanation/Reference:
Explanation:
As business case includes business need (like new product, change in process, compliance need, etc.) and the requirements of the enterprise (new technology, cost, etc.), risk professional should utilize this for implementing specific risk mitigation activity. Risk professional must look at the costs of the various controls and compare them against the benefits that the organization will receive from the risk response.
Hence he/she needs to have knowledge of business case development to illustrate the costs and benefits of the risk response.
Incorrect Answers:
A, C, D: These all options are supplemental.
NEW QUESTION 266
Accountability for a particular risk is BEST represented in a:
- A. risk register.
- B. RACI matrix.
- C. risk catalog
- D. risk scenario
Answer: B
NEW QUESTION 267
What is the IMMEDIATE step after defining set of risk scenarios?
- A. Risk management
- B. Risk monitoring
- C. Risk analysis
- D. Risk mitigation
Answer: C
Explanation:
Section: Volume B
Explanation:
Once the set of risk scenarios is defined, it can be used for risk analysis. In risk analysis, likelihood and impact of the scenarios are assessed. Important components of this assessment are the risk factors.
Incorrect Answers:
A: Risk mitigation is the latter step after analyzing risk.
B: Risk monitoring is the latter step after risk analysis and risk mitigation.
C: Risk analysis comes under risk management, therefore management is a generalized term, and is not the best answer for this question.
NEW QUESTION 268
Your project team has completed the quantitative risk analysis for your project work. Based on their findings, they need to update the risk register with several pieces of information. Which one of the following components is likely to be updated in the risk register based on their analysis?
- A. Qualitative analysis outcomes
- B. Listing of risk responses
- C. Risk ranking matrix
- D. Listing of prioritized risks
Answer: D
Explanation:
Section: Volume A
Explanation:
The outcome of quantitative analysis can create a listing of prioritized risks that should be updated in the risk register. The project team will create and update the risk register with four key components:
* probabilistic analysis of the project
* probability of achieving time and cost objectives
* list of quantified risks
* trends in quantitative risk analysis
Incorrect Answers:
A, B, D: These subjects are not updated in the risk register as a result of quantitative risk analysis.
NEW QUESTION 269
The acceptance of control costs that exceed risk exposure is MOST likely an example of:
- A. low risk tolerance.
- B. corporate culture alignment
- C. high risk tolerance.
- D. corporate culture misalignment.
Answer: A
Explanation:
Section: Volume D
NEW QUESTION 270
When reporting risk assessment results to senior management, which of the following is MOST important to include to enable risk-based decision making?
- A. Recent audit and self-assessment results
- B. Risk action plans and associated owners
- C. A list of assets exposed to the highest risk
- D. Potential losses compared to treatment cost
Answer: D
NEW QUESTION 271
The BEST way to obtain senior management support for investment in a control implementation would be to articulate the reduction in:
- A. residual risk.
- B. vulnerabilities.
- C. detected incidents.
- D. inherent risk.
Answer: A
NEW QUESTION 272
According to the Section-302 of the Sarbanes-Oxley Act of 2002, what does certification of reports implies?
Each correct answer represents a complete solution. Choose three.
- A. The financial statement does not contain any materially untrue or misleading information.
- B. The signing officer has reviewed the report.
- C. The signing officer has presented in the report their conclusions about the effectiveness of their internal controls based on their evaluation as of that date.
- D. The signing officer has evaluated the effectiveness of the issuer's internal controls as of a date at the time to report.
Answer: A,B,C
Explanation:
Section: Volume B
Explanation:
Section 302 of Sarbanes-Oxley act has the tremendous impact on the risk management solution adopted by corporations. This section specifies that the reports must be certified by the CEO, CFO, or other senior officer performing similar functions.
Certification of reports establishes:
* The signing officer has reviewed the report.
* The financial statement does not contain, to the knowledge of signing officer, any materially untrue or misleading information and represent fairly all financial conditions and results of the enterprise's operations.
* The signing officers:
- are responsible for establishing and maintaining internal controls
- have designed such internal controls to ensure that material information relating to the issuer and its consolidated subsidiaries is made - known to such officers by others within those entities, particularly during the period in which the periodic reports are being prepared
- have evaluated the effectiveness of the issuer's internal controls as of a date within 90 days prior to the report
- have presented in the report their conclusions about the effectiveness of their internal controls base on their evaluation as of that date
* The signing officer have disclosed to external auditors, audit committee, and other directors:
- all significant deficiencies in the design or operation of internal controls which could adversely affect the reliability of the reported financial data
- any fraud, whether or not material, that involves management or other employees who have a significant role in the internal controls of the enterprise
* The signing officer have indicated in the report any internal controls or changes to those internal controls which have been implemented since they were evaluated.
Incorrect Answers:
A: The signing officer has evaluated the effectiveness of the issuer's internal controls as of a date within 90 days prior to the report, not at the time of the report.
NEW QUESTION 273
Henry is the project sponsor of the JQ Project and Nancy is the project manager. Henry has asked Nancy to start the risk identification process for the project, but Nancy insists that the project team be involved in the process. Why should the project team be involved in the risk identification?
- A. So that the project team can develop a sense of ownership for the risks and associated risk responsibilities.
- B. So that the project team and the project manager can work together to assign risk ownership.
- C. So that the project manager can identify the risk owners for the risks within the project and the needed risk responses.
- D. So that the project manager isn't the only person identifying the risk events within the project.
Answer: A
Explanation:
Section: Volume D
Explanation
Explanation:
The best answer to include the project team members is that they'll need to develop a sense of ownership for the risks and associated risk responsibilities.
Incorrect Answers:
B: The reason to include the project team is that the project team needs to develop a sense of ownership for the risks and associated risk responsibilities, not to assign risk ownership and risk responses at this point.
C: While the project manager shouldn't be the only person to identify the risk events, this isn't the best answer.
D: The reason to include the project team is that the project team needs to develop a sense of ownership for the risks and associated risk responsibilities, not to assign risk ownership.
NEW QUESTION 274
A risk practitioner's PRIMARY focus when validating a risk response action plan should be that risk response:
- A. quantifies risk impact.
- B. aligns with business strategy.
- C. advances business objectives.
- D. reduces risk to an acceptable level.
Answer: B
Explanation:
Section: Volume D
NEW QUESTION 275
You and your project team are identifying the risks that may exist within your project. Some of the risks are small risks that won't affect your project much if they happen. What should you do with these identified risk events?
- A. All risks must have a valid, documented risk response.
- B. These risks can be added to a low priority risk watch list.
- C. These risks can be dismissed.
- D. These risks can be accepted.
Answer: B
Explanation:
Section: Volume C
Explanation/Reference:
Explanation:
Low-impact, low-probability risks can be added to the low priority risk watch list.
Incorrect Answers:
A: These risks are not dismissed; they are still documented on the low priority risk watch list.
B: While these risks may be accepted, they should be documented on the low priority risk watch list. This list will be periodically reviewed and the status of the risks may change.
D: Not every risk demands a risk response, so this choice is incorrect.
NEW QUESTION 276
Which of the following is MOST important to sustainable development of secure IT services?
- A. Secure coding practices
- B. Security training for systems development staff
- C. Security architecture principles
- D. \Well-documented business cases
Answer: C
NEW QUESTION 277
Which of the following would present the GREATEST challenge when assigning accountability for control ownership?
- A. Senior management scrutiny
- B. Complex regulatory environment
- C. Weak governance structures
- D. Unclear reporting relationships
Answer: C
NEW QUESTION 278
......
Exam Questions and Answers for CRISC Study Guide Questions and Answers!: https://www.test4engine.com/CRISC_exam-latest-braindumps.html
Practice To CRISC - Test4Engine Remarkable Practice On your Certified in Risk and Information Systems Control Exam: https://drive.google.com/open?id=1SUgbBoNNAAOTFCsFQElzjhdVXRr72Fgb