CRISC Review Questions | 160 Questions with 100% Correct Answers | Updated & Verified | 107 Pages
R1-1 Which of the following is MOST important to determine when defining risk management strategies? A. Risk assessment criteria B. IT architecture complexity C. An enterprise disaster recovery plan D. Business objectives and operations - ANS - D is the correct answer. Justification: A. Information on the internal and external environment must be collected to define a strategy and identify its impact. Risk assessment criteria alone are not sufficient. B. IT architecture complexity is more directly related to assessing risk than defining strategies. C. An enterprise disaster recovery plan is more directly related to mitigating the risk. D. While defining risk management strategies, the risk practitioner needs to analyze the organization's objectives and risk tolerance and define a risk management framework based on this analysis. Some organizations may accept known risk, while others may invest in and apply mitigating controls to reduce risk. R1-2 Which of the following is the MOST important information to include in a risk management strategic plan? A. Risk management staffing requirements B. The risk management mission statement C. Risk mitigation investment plans D. The current state and desired future state - ANS - D is the correct answer. Justification: A. Risk management staffing requirements are generally driven by a robust understanding of the current and
Document information
- Uploaded on
- November 26, 2022
- Number of pages
- 107
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers