• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 20 páginas
Examen

CRISC (Actual) Exam Questions and Answers

Document preview thumbnail
Vista previa 3 fuera de 20 páginas

CRISC (Actual) Exam Questions and Answers

Vista previa del contenido

CRISC (Actual) Exam Questions and Answers


An enterprise recently developed a breakthrough technology that could provide a
significant competitive edge. Which of the following FIRST governs how this
information is to be protected from within the enterprise?

A. The data classification policy
B. The acceptable use policy
C. Encryption standards
D. The access control policy - ANSWER-A. Data classification policy describes the
data classification categories; levels of protection to be provided for each category
of data; and roles and responsibilities of potential users, including data owners

Which of the following is the BEST way to ensure that an accurate risk register is
maintained over time?

A. Monitor KRIs and record findings in the risk register
B. Publish the risk register centrally with workflow features that periodically poll risk
assessors
C. Distribute the risk register to business process owners for review and updating
D. Utilize audit personnel to perform regular audits and to maintain the risk register
- ANSWER-B. Centrally publishing the risk register and enabling periodic polling of
risk assessors through workflow features will ensure accuracy of content. A
knowledge management platform with workflow and polling features will automate
the process of maintaining the risk register

Which of the following is the MOST important requirement for setting up an
information security infrastructure for a new system?

A. Performing a BIA
B. Considering personal devices as part of the security policy
C. Basing the information security infrastructure on a risk assessment
D. Initiating IT security training and familiarization - ANSWER-C. The information
security infrastructure should be based on a risk assessment

The MAIN objective of IT risk management is to:

A. prevent loss of IT assets
B. provide timely management reports
C. ensure regulatory compliance
D. enable risk-aware business decisions - ANSWER-D. IT risk management should
be conducted as part of enterprise risk management (ERM), the ultimate objective
of which is to enable risk-aware business decisions

,Which of the following is the PRIMARY reason that a risk practitioner determines the
security boundary prior to conducting a risk assessment?

A. To determine which laws and regulations apply
B. To determine the scope of the risk assessment
C. To determine the business owner(s) of the system
D. To decide between conducting a quantitative or qualitative analysis - ANSWER-B.
The primary reason for determining the security boundary is to establish what
systems and components are included in the risk assessment

The PRIMARY advantage of creating and maintaining a risk register is to:

A. ensure than an inventory of potential risk is maintained
B. record all risk scenarios considered during the risk identification process
C. collect similar data on all risk identified within the organization
D. run reports based on various risk scenarios - ANSWER-A. Once important assets
and the risk that may impact these assets are identified, the risk register is used as
an inventory of that risk. The risk register can help enterprises accelerate their risk
decision making and establish accountability for specific risk

The board of directors of a one-year-old start-up company has asked their CIO to
create all of the enterprise's IT policies and procedures. Which of the following
should the CIO create FIRST?

A. The strategic IT plan
B. The data classification scheme
C. The information architecture document
D. The technology infrastructure plan - ANSWER-A. The strategic IT plan is the first
policy to be created when setting up an enterprise's governance model

A BIA is primarily used to:

A. estimate the resources required to resume and return to normal operations after
a disruption
B. evaluate the impact of a disruption to an enterprise's ability to operate over time
C. calculate the likelihood and impact of known threats on specific functions
D. evaluate high-level business requirements - ANSWER-B

Which of the following is the BIGGEST concern for a CISO regarding
interconnections with systems outside of the enterprise?

A. Requirements to comply with each other's contractual security requirements
B. Uncertainty that the other system will be available as needed
C. The ability to perform risk assessments on the other system
D. Ensuring that communication between the two systems is encrypted through a
VPN - ANSWER-A

, Which of the following BEST determines compliance with the risk appetite of an
enterprise?

A. Balance between preventive and detective controls
B. Inherent risk and acceptable risk level
C. Residual risk level and acceptable risk level
D. Balance between countermeasures and preventive controls - ANSWER-C

Risk scenarios should be created primarily based on which of the following:

A. Input from senior management
B. Previous security incidents
C. Threats that the enterprise faces
D. Results of the risk analysis - ANSWER-C

Which of the following is the BEST indicator of an effective information risk
management program?

A. The security policy is made widely available
B. Risk is considered before all decisions
C. Security procedures are updated annually
D. Risk assessments occur on an annual basis - ANSWER-B

A review of an enterprise's IT projects find that projects frequently go over time or
budget by nearly 10 percent. On review, management advises the risk practitioner
that a deviation of 15 percent is acceptable. This is an example of:

A. risk avoidance
B. risk tolerance
C. risk acceptance
D. risk mitigation - ANSWER-B

Which of the following is a MAJOR risk associated with the use of governance, risk
and compliance (GRC) tools?

A. Misinterpretation of the dashboard's output
B. Poor authentication mechanism
C. Obsolescence of content
D. Complex integration of the diverse requirements - ANSWER-C

Which of the following examples of risk should be addressed during application
design?

A. A lack of skilled resources
B. The risk of migration to a new system
C. Incomplete technical specifications
D. Third-party supplier risk - ANSWER-A

Información del documento

Subido en
1 de septiembre de 2026
Número de páginas
20
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$12.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
CLOUNDLite
3.9
(128)
Vendido
659
Seguidores
389
Artículos
12325
Última venta
1 semana hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes