100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

CRIS Exam QUESTIONS WITH CORRECT ANSWERS

Rating
-
Sold
-
Pages
27
Grade
A+
Uploaded on
17-07-2025
Written in
2024/2025

CRIS Exam QUESTIONS WITH CORRECT ANSWERS

Institution
Cris
Module
Cris










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Cris
Module
Cris

Document information

Uploaded on
July 17, 2025
Number of pages
27
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CRIS Exam QUESTIONS WITH CORRECT |\ |\ |\ |\ |\




ANSWERS

Which of the following is MOST important to determine when
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\


defining risk management strategies? - CORRECT ANSWERS
|\ |\ |\ |\ |\ |\ |\


✔✔Business objectives and operations. |\ |\ |\




While defining risk management strategies, the risk practitioner
|\ |\ |\ |\ |\ |\ |\ |\


needs to analyze the enterprise's objectives and risk tolerance
|\ |\ |\ |\ |\ |\ |\ |\ |\


and define a risk management framework based on this analysis.
|\ |\ |\ |\ |\ |\ |\ |\ |\


Some enterprises may accept known risk, while others may
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\


invest in and apply mitigating controls to reduce risk.
|\ |\ |\ |\ |\ |\ |\ |\




Management wants to ensure that IT is successful in delivering |\ |\ |\ |\ |\ |\ |\ |\ |\ |\


against business requirements. Which of the following BEST
|\ |\ |\ |\ |\ |\ |\ |\


supports that effort? - CORRECT ANSWERS ✔✔An internal control
|\ |\ |\ |\ |\ |\ |\ |\ |\


system or framework. |\ |\




For IT to be successful in delivering against business
|\ |\ |\ |\ |\ |\ |\ |\ |\


requirements, management should develop an internal control |\ |\ |\ |\ |\ |\ |\


system that supports its business requirements.
|\ |\ |\ |\ |\




Which of the following risk assessment outputs is MOST suitable
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\


to help justify an enterprise information security program? -
|\ |\ |\ |\ |\ |\ |\ |\ |\


CORRECT ANSWERS ✔✔A list of appropriate controls for
|\ |\ |\ |\ |\ |\ |\ |\


addressing risk. |\

,A list of information security controls corresponding to risk
|\ |\ |\ |\ |\ |\ |\ |\ |\


scenarios identified during risk assessment is one of the primary
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\


deliverables of the risk assessment exercise. The list |\ |\ |\ |\ |\ |\ |\ |\


demonstrates due consideration of risk and applicable controls to |\ |\ |\ |\ |\ |\ |\ |\


address the risk and therefore helps justify a program predicated
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\


on risk mitigation.
|\ |\ |\




Whether a risk has been reduced to an acceptable level should
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\


be determined by: - CORRECT ANSWERS ✔✔Enterprise
|\ |\ |\ |\ |\ |\ |\


requirements.


Enterprise requirements as dictated by enterprise goals and
|\ |\ |\ |\ |\ |\ |\ |\


objectives should determine when a risk has been reduced to an
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\


acceptable level. Information systems and security requirements
|\ |\ |\ |\ |\ |\ |\


and standards may help inform enterprise requirements, but in
|\ |\ |\ |\ |\ |\ |\ |\ |\


themselves lack the critical context of enterprise business goals. |\ |\ |\ |\ |\ |\ |\ |\




Commitment and support of senior management for information |\ |\ |\ |\ |\ |\ |\ |\


security investment can BEST be accomplished by a business
|\ |\ |\ |\ |\ |\ |\ |\ |\


case that: - CORRECT ANSWERS ✔✔Ties security risk to
|\ |\ |\ |\ |\ |\ |\ |\ |\


enterprise business objectives. |\ |\




Senior management seeks to understand the business
|\ |\ |\ |\ |\ |\ |\


justification for investing in security. This can best be |\ |\ |\ |\ |\ |\ |\ |\ |\


accomplished by tying security to key business objectives. |\ |\ |\ |\ |\ |\ |\




The PRIMARY reason for developing an enterprise security
|\ |\ |\ |\ |\ |\ |\ |\


architecture is to: - CORRECT ANSWERS ✔✔Align security |\ |\ |\ |\ |\ |\ |\ |\


strategies among the functional areas of an enterprise and
|\ |\ |\ |\ |\ |\ |\ |\ |\


external entities. |\ |\

, The enterprise security architecture must align strategies and
|\ |\ |\ |\ |\ |\ |\ |\


objectives of diverse functional areas within the enterprise,
|\ |\ |\ |\ |\ |\ |\ |\


optimize the flow of information within an enterprise, and support
|\ |\ |\ |\ |\ |\ |\ |\ |\


all required communication with external partners, customers
|\ |\ |\ |\ |\ |\ |\ |\


and suppliers. |\




Which of the following signifies the need to review an
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\


enterprise's risk practices? - CORRECT ANSWERS ✔✔Business |\ |\ |\ |\ |\ |\ |\


owners regularly challenge risk assessment findings.
|\ |\ |\ |\ |\ |\




An enterprise's risk management practices must be clearly
|\ |\ |\ |\ |\ |\ |\ |\


understood and supported by business stakeholders. This |\ |\ |\ |\ |\ |\ |\


principle must be documented in the enterprise's risk
|\ |\ |\ |\ |\ |\ |\ |\


management policy/framework/plan with senior management |\ |\ |\ |\ |\


approval and direction. Business owners who challenge the risk
|\ |\ |\ |\ |\ |\ |\ |\ |\


assessment findings either do not support the findings or do not
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\


understand them clearly. |\ |\




Which of the following choices should drive the IT plan? -
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\


CORRECT ANSWERS ✔✔Strategic planning and business
|\ |\ |\ |\ |\ |\


requirements.


IT exists to support business objectives. Management of
|\ |\ |\ |\ |\ |\ |\ |\


enterprise IT should align the IT plan closely with the business.
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\




The GREATEST risk posed by an absence of strategic planning is:
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\


- CORRECT ANSWERS ✔✔Improper oversight of IT investment.
|\ |\ |\ |\ |\ |\ |\ |\

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EXAMSTUDYPLUG Stanford University
Follow You need to be logged in order to follow users or courses
Sold
308
Member since
3 year
Number of followers
107
Documents
18416
Last sold
4 days ago
GRADE BUDDY

Welcome to My Page! Are you looking for high-quality study resources to ace your exams or better understand your coursework? You've come to the right place! I'm passionate about sharing my knowledge and helping students succeed academically. Here, you'll find a wide range of well-organized notes, study guides, and helpful materials across various subjects, including Maths ,nursig, Biology, History, etc.. Each resource is carefully crafted with detailed explanations, clear examples, and relevant key points to help simplify complex concepts. Whether you're preparing for a test, reviewing lectures, or need extra support, my resources are designed to make your learning experience smoother and more effective. Let me be a part of your academic journey, and feel free to reach out if you have any questions or need personalized assistance!

Read more Read less
4.5

230 reviews

5
155
4
50
3
13
2
5
1
7

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Frequently asked questions