Isaca Certificaton CRISC Dumps Full Questions with Free PDF Questions to Pass 100% Updated ISACA CRISC Enterprise PDF Dumps NEW QUESTION 339 You are the project manager of GHT project. A risk event has occurred in your project and you have identified it. Which of the following tasks you would do in reaction to risk event occurrence? Each correct answer represents a part of the solution. Choose three. [...]

Isaca Certificaton CRISC Dumps Full Questions with Free PDF Questions to Pass [Q339-Q364]

Share

Isaca Certificaton CRISC Dumps Full Questions with Free PDF Questions to Pass

100% Updated ISACA CRISC Enterprise PDF Dumps

NEW QUESTION 339
You are the project manager of GHT project. A risk event has occurred in your project and you have identified it. Which of the following tasks you would do in reaction to risk event occurrence? Each correct answer represents a part of the solution. Choose three.

  • A. Maintain and initiate incident response plans
  • B. Communicate lessons learned from risk events
  • C. Monitor risk
  • D. Update risk register

Answer: A,B,C

Explanation:
Section: Volume D
Explanation
Explanation:
When the risk events occur then following tasks have to done to react to it:
* Maintain incident response plans
* Monitor risk
* Initiate incident response
* Communicate lessons learned from risk events
Incorrect Answers:
C: Risk register is updated after applying appropriate risk response and at the time of risk event occurrence.

 

NEW QUESTION 340
Who is BEST suited to determine whether a new control properly mitigates data loss risk within a system?

  • A. Data owner
  • B. Risk owner
  • C. Control owner
  • D. System owner

Answer: C

 

NEW QUESTION 341
Which among the following is the BEST reason for defining a risk response?

  • A. is incorrect. Mitigation of risk is itself the risk response process, not the reason behind
    this.
  • B. is incorrect. Risk cannot be completely eliminated from the enterprise.
  • C. To eliminate risk from the enterprise
  • D. To overview current status of risk
  • E. Explanation:
    The purpose of defining a risk response is to ensure that the residual risk is within the limits of the
    risk appetite and tolerance of the enterprise. Risk response is based on selecting the correct,
    prioritized response to risk, based on the level of risk, the enterprise's risk tolerance and the cost
    or benefit of the particular risk response option.
  • F. To ensure that the residual risk is within the limits of the risk appetite and tolerance
  • G. To mitigate risk

Answer: F

Explanation:
is incorrect. This is not a valid answer.

 

NEW QUESTION 342
Which of the following should be included in a risk scenario to be used for risk analysis?

  • A. Risk appetite
  • B. Residual risk
  • C. Risk tolerance
  • D. Threat type

Answer: D

 

NEW QUESTION 343
Which key performance efficiency IKPI) BEST measures the effectiveness of an organization's disaster recovery program?

  • A. Percentage of critical systems recovered within tie recovery time objective (RTO)
  • B. Number of total systems recovered within tie recovery point objective (RPO)
  • C. Percentage of recovery issues identified during the exercise
  • D. Number of service level agreement (SLA) violations

Answer: A

 

NEW QUESTION 344
John is the project manager of the NHQ Project for his company. His project has 75 stakeholders, some of which are external to the organization. John needs to make certain that he communicates about risk in the most appropriate method for the external stakeholders. Which project management plan will be the best guide for John to communicate to the external stakeholders?

  • A. Risk Management Plan
  • B. Risk Response Plan
  • C. Communications Management Plan
  • D. Project Management Plan

Answer: C

Explanation:
Section: Volume D
Explanation
Explanation:
The Communications Management Plan will direct John on the information to be communicated, when to communicate, and how to communicate with external stakeholders.
The Communications Management Plan aims to define the communication necessities for the project and how the information will be circulated. The Communications Management Plan sets the communication structure for the project. This structure provides guidance for communication throughout the project's life and is updated as communication needs change. The Communication Managements Plan identifies and defines the roles of persons concerned with the project. It includes a matrix known as the communication matrix to map the communication requirements of the project.
Incorrect Answers:
A: The Risk Response Plan identifies how risks will be responded to.
C: The Project Management Plan is the parent of all subsidiary management plans and it is not the most accurate choice for this question D: The Risk Management Plan defines how risks will be identified, analyzed, responded to, and controlled throughout the project.

 

NEW QUESTION 345
An IT risk threat analysis is BEST used to establish

  • A. risk maps
  • B. risk appetite
  • C. risk scenarios
  • D. risk ownership.

Answer: C

 

NEW QUESTION 346
An internally developed payroll application leverages Platform as a Service (PaaS) infrastructure from the cloud. Who owns the related data confidentiality risk?

  • A. Human resources head
  • B. IT infrastructure head
  • C. Supplier management head
  • D. Application development head

Answer: A

 

NEW QUESTION 347
Your project team has completed the quantitative risk analysis for your project work. Based on their findings, they need to update the risk register with several pieces of information. Which one of the following components is likely to be updated in the risk register based on their analysis?

  • A. Listing of prioritized risks
  • B. Explanation:
    The outcome of quantitative analysis can create a listing of prioritized risks that should be updated
    in the risk register. The project team will create and update the risk register with fourkey
    components: probabilistic analysis of the project, probability of achieving time and cost objectives,
    list of quantified risks, and trends in quantitative risk analysis.
  • C. Qualitative analysis outcomes
  • D. Listing of risk responses
  • E. Risk ranking matrix

Answer: A

Explanation:
B, and A are incorrect. These subjects are not updated in the risk register as a result of
quantitative risk analysis.

 

NEW QUESTION 348
Which of the following would be MOST useful when measuring the progress of a risk response action plan?

  • A. An up-to-date risk register
  • B. Annual loss expectancy (ALE) changes
  • C. Percentage of mitigated risk scenarios
  • D. Resource expenditure against budget

Answer: C

Explanation:
Section: Volume D

 

NEW QUESTION 349
Which of the following is the PRIMARY purpose of periodically reviewing an organization's risk profile?

  • A. Enable risk-based decision making.
  • B. Update risk responses in the risk register
  • C. Align business objectives with risk appetite.
  • D. Design and implement risk response action plans.

Answer: A

 

NEW QUESTION 350
Which of the following is the STRONGEST indication an organization has ethics management issues?

  • A. The organization has only two lines of defense.
  • B. Employees face sanctions for not signing the organization's acceptable use policy.
  • C. Employees do not report IT risk issues for fear of consequences.
  • D. Internal IT auditors report to the chief information security officer (CISO).

Answer: C

 

NEW QUESTION 351
Which of the following helps ensure compliance with a non-repudiation policy requirement for electronic transactions?

  • A. Encrypted passwords
  • B. One-time passwords
  • C. Digital certificates
  • D. Digital signatures

Answer: D

Explanation:
Section: Volume D

 

NEW QUESTION 352
Which of the following items is considered as an objective of the three dimensional model within the framework described in COSO ERM?

  • A. Financial reporting
  • B. Risk assessment
  • C. Control environment
  • D. Monitoring

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The COSO ERM (Enterprise Risk Management) frame work is a 3-dimensional model. The dimensions and their components include:
Strategic Objectives - includes strategic, operations, reporting, and compliance.

Risk Components - includes Internal Environment, Objectives settings, Event identification, Risk

assessment, Risk response, Control activities, Information and communication, and monitoring.
Organizational Levels - include subsidiary, business unit, division, and entity-level.

The COSO ERM framework contains eight risk components:
Internal Environment

Objective Settings

Event Identification

Risk Assessment

Risk Response

Control Activities

Information and Communication

Monitoring

Section 404 of the Sarbanes-Oley act specifies a three dimensional model- COSO ERM, comprised of Internal control components, Internal control objectives, and organization entities. All the items listed are components except Financial reporting which is an internal control objective.
Incorrect Answers:
A, C, D: They are the Internal control components, not the Internal control objectives.

 

NEW QUESTION 353
In order to determining a risk is under-controlled the risk practitioner will need to

  • A. monitor and evaluate IT performance
  • B. determine the sufficiency of the IT risk budget
  • C. understand the risk tolerance
  • D. identify risk management best practices

Answer: C

 

NEW QUESTION 354
Which of the following steps ensure effective communication of the risk analysis results to relevant stakeholders? Each correct answer represents a complete solution. Choose three.

  • A. Communicate the negative impacts of the events only, it needs more consideration
  • B. Provide decision makers with an understanding of worst-case and most probable scenarios,due diligence exposures and significant reputation, legal or regulatory considerations
  • C. Communicate the risk-return context clearly
  • D. The results should be reported in terms and formats that are useful to support business decisions

Answer: B,C,D

Explanation:
Section: Volume B
Explanation:
The result of risk analysis process is being communicated to relevant stakeholders. The steps that are involved in communication are:
* The results should be reported in terms and formats that are useful to support business decisions.
* Coordinate additional risk analysis activity as required by decision makers, like report rejection and scope adjustment
* Communicate the risk-return context clearly, which include probabilities of loss and/or gain, ranges, and confidence levels (if possible) that enable management to balance risk-return.
* Identify the negative impacts of events that drive response decisions as well as positive impacts of events that represent opportunities which should channel back into the strategy and objective setting process.
* Provide decision makers with an understanding of worst-case and most probable scenarios, due diligence exposures and significant reputation, legal or regulatory considerations.
Incorrect Answers:
C: Communicate the negative impacts of events that drive response decisions as well as positive impacts of events that represent opportunities which should channel back into the strategy and objective setting process, for effective communication. Only negative impacts are not considered alone.

 

NEW QUESTION 355
Which of the following approaches to bring you own device (BYOD) service delivery provides the BEST protection from data loss?

  • A. Enforce strong passwords and data encryption
  • B. Implement remote monitoring
  • C. Enable data wipe capabilities
  • D. Penetration testing and session timeouts

Answer: B

Explanation:
Section: Volume D
Explanation

 

NEW QUESTION 356
Which of The following will BEST communicate the importance of risk mitigation initiatives to senior management?

  • A. Balanced scorecard
  • B. Heat map
  • C. Business case
  • D. Industry standards

Answer: C

 

NEW QUESTION 357
Which of the following BEST indicates the effectiveness of anti-malware software?

  • A. Number of patches made to anti-malware software.
  • B. Number of downtime hours in business critical servers.
  • C. Number of staff hours lost due to malware attacks.
  • D. Number of successful attacks by malicious software.

Answer: D

Explanation:
Section: Volume D

 

NEW QUESTION 358
You are the project manager of GHT project. You have initiated the project and conducted the feasibility study. What result would you get after conducting feasibility study?
Each correct answer represents a complete solution. (Choose two.)

  • A. Recommend alternatives and course of action
  • B. Risk response plan
  • C. Project management plan
  • D. Results of criteria analyzed, like costs, benefits, risk, resources required and organizational impact

Answer: A,D

Explanation:
Explanation/Reference:
Explanation:
The completed feasibility study results should include a cost/benefit analysis report that:
Provides the results of criteria analyzed (e.g., costs, benefits, risk, resources required and

organizational impact)
Recommends one of the alternatives and a course of action

Incorrect Answers:
B, C: Project management plan and risk response plan are the results of plan project management and plan risk response, respectively. They are not the result of feasibility study.

 

NEW QUESTION 359
Which of The following should be of GREATEST concern for an organization considering the adoption of a bring your own device (BYOD) initiative?

  • A. Malicious users
  • B. Data loss
  • C. Device corruption
  • D. User support

Answer: A

 

NEW QUESTION 360
An organization has received notification that it is a potential victim of a cybercrime that may have compromised sensitive customer data. What should be The FIRST course of action?

  • A. Invoke the business continuity plan (BCP).
  • B. Determine the business impact.
  • C. Invoke the incident response plan.
  • D. Conduct a forensic investigation.

Answer: C

 

NEW QUESTION 361
Which of the following is the MOST important reason to link an effective key control indicator (KCI) to relevant key risk indicators (KRIs)?

  • A. To provide input to management for the adjustment of risk appetite
  • B. To obtain business buy-in for investment in risk mitigation measures
  • C. To monitor the accuracy of threshold levels in metrics
  • D. To monitor changes in the risk environment

Answer: D

 

NEW QUESTION 362
Which of the following MUST be assessed before considering risk treatment options for a scenario with significant impact?

  • A. Incident probability
  • B. Risk appetite
  • C. Cost-benefit analysis
  • D. Risk magnitude

Answer: C

 

NEW QUESTION 363
Who should be responsible for implementing and maintaining security controls?

  • A. Data owner
  • B. Data custodian
  • C. End user
  • D. Internal auditor

Answer: B

Explanation:
Section: Volume D

 

NEW QUESTION 364
......

Use Valid Exam CRISC by BraindumpsVCE Books For Free Website: https://www.braindumpsvce.com/CRISC_exam-dumps-torrent.html

Free Isaca Certificaton CRISC Official Cert Guide PDF Download: https://drive.google.com/open?id=1Jl00L8ceKZHZ8YbsZFiPUvWtyTjajNZh