[Jul 29, 2022] New Updated CRISC Exam Questions 2022 [Q382-Q400]

Share

[Jul 29, 2022] New Updated CRISC Exam Questions 2022

Updated Free ISACA CRISC Test Engine Questions with 967 Q&As


Risk Response Mitigation: 23%

  • Discuss with or help the risk owners on risk action development plans to incorporate key elements in development plans;
  • Certify the execution of risk responses based on risk action plans.
  • Help the control owners to develop control mechanisms and documentation for effective and efficient control execution;

 

NEW QUESTION 382
Which of the following would be MOST helpful to a risk practitioner when ensuring that mitigated risk remains within acceptable limits?

  • A. Building an organizational risk profile after updating the risk register
  • B. Ensuring risk owners participate in a periodic control testing process
  • C. Designing a process for risk owners to periodically review identified risk
  • D. Implementing a process for ongoing monitoring of control effectiveness

Answer: B

 

NEW QUESTION 383
You work as the project manager for Bluewell Inc. Your project has several risks that will affect several stakeholder requirements. Which project management plan will define who will be available to share information on the project risks?

  • A. Communications Management Plan
  • B. Risk Management Plan
  • C. Stakeholder management strategy
  • D. Resource Management Plan

Answer: A

Explanation:
Section: Volume A
Explanation:
The Communications Management Plan defines, in regard to risk management, who will be available to share information on risks and responses throughout the project.
The Communications Management Plan aims to define the communication necessities for the project and how the information will be circulated. The Communications Management Plan sets the communication structure for the project. This structure provides guidance for communication throughout the project's life and is updated as communication needs change. The Communication Managements Plan identifies and defines the roles of persons concerned with the project. It includes a matrix known as the communication matrix to map the communication requirements of the project.
Incorrect Answers:
A: The Resource Management Plan does not define risk communications.
B: The Risk Management Plan defines risk identification, analysis, response, and monitoring.
C: The stakeholder management strategy does not address risk communications.

 

NEW QUESTION 384
John is the project manager of the NHQ Project for his company. His project has 75 stakeholders, some of which are external to the organization. John needs to make certain that he communicates about risk in the most appropriate method for the external stakeholders. Which project management plan will be the best guide for John to communicate to the external stakeholders?

  • A. Communications Management Plan
  • B. Project Management Plan
  • C. Risk Response Plan
  • D. Risk Management Plan

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The Communications Management Plan will direct John on the information to be communicated, when to communicate, and how to communicate with external stakeholders.
The Communications Management Plan aims to define the communication necessities for the project and how the information will be circulated. The Communications Management Plan sets the communication structure for the project. This structure provides guidance for communication throughout the project's life and is updated as communication needs change. The Communication Managements Plan identifies and defines the roles of persons concerned with the project. It includes a matrix known as the communication matrix to map the communication requirements of the project.
Incorrect Answers:
A: The Risk Response Plan identifies how risks will be responded to.
C: The Project Management Plan is the parent of all subsidiary management plans and it is not the most accurate choice for this question D: The Risk Management Plan defines how risks will be identified, analyzed, responded to, and controlled throughout the project.

 

NEW QUESTION 385
You are the project manager of HFD project. You have identified several project risks. You have adopted alternatives to deal with these risks which do not attempt to reduce the probability of a risk event or its impacts.
Which of the following response have you implemented?

  • A. Contingent response
  • B. Mitigation
  • C. Acceptance
  • D. Avoidance

Answer: A

Explanation:
Section: Volume D
Explanation:
Contingent response strategy, also known as contingency planning, involves adopting alternatives to deal with the risks in case of their occurrence. Unlike the mitigation planning in which mitigation looks to reduce the probability of the risk and its impact, contingency planning doesn't necessarily attempt to reduce the probability of a risk event or its impacts. Contingency comes into action when the risk event actually occurs.
Incorrect Answers:
A: Risk acceptance means that no action is taken relative to a particular risk; loss is accepted if it occurs. If an enterprise adopts a risk acceptance, it should carefully consider who can accept the risk. Risk should be accepted only by senior management in relationship with senior management and the board. There are two alternatives to the acceptance strategy, passive and active.
* Passive acceptance means that enterprise has made no plan to avoid or mitigate the risk but willing to accept the consequences of the risk.
* Active acceptance is the second strategy and might include developing contingency plans and reserves to deal with risks.
B: Risk mitigation attempts to reduce the probability of a risk event and its impacts to an acceptable level. Risk mitigation can utilize various forms of control carefully integrated together. The main control types are:
* Managerial(e.g.,policies)
* Technical (e.g., tools such as firewalls and intrusion detection systems)
* Operational (e.g., procedures, separation of duties)
* Preparedness activities
C: Risk avoidance means to evade risk altogether, eliminate the cause of the risk event, or change the project plan to protect the project objectives from the risk event.

 

NEW QUESTION 386
FISMA requires federal agencies to protect IT systems and data. How often should compliance be audited by an external organization?

  • A. Annually
  • B. Never
  • C. Quarterly
  • D. Every three years

Answer: A

Explanation:
Section: Volume B
Explanation:
Inspection of FISMA is required to be done annually. Each year, agencies must have an independent evaluation of their program. The objective is to determine the effectiveness of the program. These evaluations include:
* Testing for effectiveness: Policies, procedures, and practices are to be tested. This evaluation does not test every policy, procedure, and practice. Instead, a representative sample is tested.
* An assessment or report: This report identifies the agency's compliance as well as lists compliance with FISMA. It also lists compliance with other standards and guidelines.
Incorrect Answers:
B, C, D: Auditing of compliance by external organization is done annually, not quarterly or every three years.

 

NEW QUESTION 387
Which of the following is the MOST important component of effective security incident response?

  • A. Network time protocol synchronization
  • B. Identification of attack sources
  • C. Early detection of breaches
  • D. A documented communications plan

Answer: C

 

NEW QUESTION 388
You are completing the qualitative risk analysis process with your project team and are relying on the risk management plan to help you determine the budget, schedule for risk management, and risk categories. You discover that the risk categories have not been created. When the risk categories should have been created?

  • A. Create work breakdown structure process
  • B. Risk identification process
  • C. Define scope process
  • D. Plan risk management process
  • E. Explanation:
    The plan risk management process is when risk categories were to be defined. If they were not defined, as in this scenario, it is acceptable to define the categories as part of the qualitative risk analysis process. Plan risk management is the process of defining the way to conduct the risk management activities. Planning is essential for providing sufficient resources and time for risk management activities, and to establish a agreed-upon basis of evaluating risks. This process should start as soon as project is conceived and should be completed early during project planning.

Answer: D

Explanation:
is incorrect. Risk categories are not defined through the define scope process. Answer: D is incorrect. Risk categories are not defined through the create work breakdown structure process. Answer: B is incorrect. Risk categories are not defined through the risk identification process.

 

NEW QUESTION 389
Which of the following should be an element of the risk appetite of an organization?

  • A. The residual risk affected by preventive controls
  • B. The enterprise's capacity to absorb loss
  • C. The effectiveness of compensating controls
  • D. The amount of inherent risk considered appropriate

Answer: B

 

NEW QUESTION 390
Which of the following are the security plans adopted by the organization?
Each correct answer represents a complete solution. (Choose three.)

  • A. Backup plan
  • B. Project management plan
  • C. Business continuity plan
  • D. Disaster recovery plan

Answer: A,C,D

Explanation:
Explanation/Reference:
Explanation:
Organizations create different security plans to address different scenarios. Many of the security plans are common to most organizations.
Most used security plans found in many organizations are:
Business continuity plan

Disaster recovery plan

Backup plan

Incident response plan

Incorrect Answers:
D: Project management plan is not a security plan, but a plan which describes the implementation of the project.

 

NEW QUESTION 391
What is the GREATEST concern with maintaining decentralized risk registers instead of a consolidated risk register?

  • A. Duplicate resources may be used to manage risk registers.
  • B. Standardization of risk management practices may be difficult to enforce.
  • C. Risk analysis may be inconsistent due to non-uniform impact and likelihood scales.
  • D. Aggregated risk may exceed the enterprise's risk appetite and tolerance.

Answer: C

Explanation:
Section: Volume D

 

NEW QUESTION 392
You are the project manager of the HGT project in Bluewell Inc. The project has an asset valued at $125,000 and is subjected to an exposure factor of 25 percent. What will be the Single Loss Expectancy of this project?

  • A. $ 125,025
  • B. $ 31,250
  • C. $ 5,000
  • D. $ 3,125,000

Answer: B

Explanation:
Section: Volume A
Explanation:
The Single Loss Expectancy (SLE) of this project will be $31,250.
Single Loss Expectancy is a term related to Quantitative Risk Assessment. It can be defined as the monetary value expected from the occurrence of a risk on an asset. It is mathematically expressed as follows:
Single Loss Expectancy (SLE) = Asset Value (AV) * Exposure Factor (EF)
where the Exposure Factor represents the impact of the risk over the asset, or percentage of asset lost. As an example, if the Asset Value is reduced two third, the exposure factor value is .66. If the asset is completely lost, the Exposure Factor is 1.0. The result is a monetary value in the same unit as the Single Loss Expectancy is expressed.
Therefore,
SLE = Asset Value * Exposure Factor
= 125,000 * 0.25
= $31,250
Incorrect Answers:
A, C, D: These are not SLEs of this project.

 

NEW QUESTION 393
A trusted third party service provider has determined that the risk of a client's systems being hacked is low.
Which of the following would be the client's BEST course of action?

  • A. Implement additional controls to address the risk.
  • B. Accept the risk based on the third party's risk assessment
  • C. Perform an independent audit of the third party.
  • D. Perform their own risk assessment

Answer: B

 

NEW QUESTION 394
To reduce costs, an organization is combining the second and third tines of defense in a new department that reports to a recently appointed C-level executive. Which of the following is the GREATEST concern with this situation?

  • A. The independence of the internal third line of defense may be compromised.
  • B. The risk governance approach of the second and third lines of defense may differ.
  • C. Cost reductions may negatively impact the productivity of other departments.
  • D. The new structure is not aligned to the organization's internal control framework.

Answer: A

 

NEW QUESTION 395
Senior management has asked a risk practitioner to develop technical risk scenarios related to a recently developed enterprise resource planning (ERP) system. These scenarios will be owned by the system manager. Which of the following would be the BEST method to use when developing the scenarios?

  • A. Bottom-up approach
  • B. Cause-and-effect diagram
  • C. Delphi technique
  • D. Top-down approach

Answer: B

 

NEW QUESTION 396
Which of the following is the BEST indication that an organization is following a mature risk management process?

  • A. A dashboard has been developed for senior management to provide real-time risk values.
  • B. Executive management receives periodic risk awareness training.
  • C. Attributes of each risk scenario have been documented within the risk register.
  • D. The risk register is frequently utilized for decision-making.

Answer: A

Explanation:
Section: Volume D

 

NEW QUESTION 397
The following is the snapshot of a recently approved IT risk register maintained by an organization's information security department.

After implementing countermeasures listed in ''Risk Response Descriptions'' for each of the Risk IDs, which of the following component of the register MUST change?

  • A. Risk Impact Rating
  • B. Risk Likelihood Rating
  • C. Risk Owner
  • D. Risk Exposure

Answer: C

 

NEW QUESTION 398
You are the risk control professional of your enterprise. You have implemented a tool that correlates information from multiple sources. To which of the following do this monitoring tool focuses?

  • A. Configuration settings
  • B. System changes
  • C. Transaction data
  • D. Explanation:
    Monitoring tools that focuses on transaction data generally correlate information from one system to another, such as employee data from the human resources (HR) system with spending information from the expense system or the payroll system.
  • E. Process integrity

Answer: C

Explanation:
is incorrect. Process integrity is confirmed within the system, it dose not need monitoring. Answer: D is incorrect. System changes are compared from a previous state to the current state, it dose not correlate information from multiple sources. Answer: C is incorrect. Configuration settings are generally compared against predefined values and not based on the correlation between multiple souces.

 

NEW QUESTION 399
Malicious code protection is which type control?

  • A. Personal security control
  • B. System and information integrity control
  • C. Media protection control
  • D. Configuration management control

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Malware, short for malicious software, is software designed to disrupt computer operation, gather sensitive information, or gain unauthorized access to computer systems. As malicious code protection lists steps to protect against malware, it preserves the information integrity of the enterprise.
Hence Malicious code protection is System and information integrity control. This family of controls provides information to maintain the integrity of systems and data.
Incorrect Answers:
A: Malicious code protection is not a Configuration management control.
Configuration management control is the family of controls that addresses both configuration management and change management. Change control practices prevent unauthorized changes.
C: Malicious code protection is not a Media protection control.
Media Protection includes removable digital media such as tapes, external hard drives, and USB flash drives. It also includes non-digital media such as paper and film. This family of controls covers the access, marking, storage, transport, and sanitization of media.
D: Malicious code protection is not a Personal security control.
The Personal security control is a family of controls including aspects of personnel security. It includes personnel screening, termination, and transfer.

 

NEW QUESTION 400
......


For more info visit:

CRISC Exam Reference

 

Try 100% Updated CRISC Exam Questions [2022]: https://www.examprepaway.com/ISACA/braindumps.CRISC.ete.file.html

The Best Isaca Certificaton CRISC Professional Exam Questions: https://drive.google.com/open?id=1xYU1NFQSisZFq8mo_bQUEZbf2w3pXQl6