CRISC 51-100 Topic3 Questions and Answers
1 of 49
Definition
D. Undefined assignment of responsibility.
Give this one a try later!
Question #:97 - (Exam Topic 3)
The BEST way to mitigate the high cost of retrieving electronic evidence associated
with potential litigation is to implement policies and procedures for.
A. data logging and monitoring
B. data mining and analytics
C. data classification and labeling
D. data retention and destruction
Question #:98 - (Exam Topic 3)
Which of the following is the PRIMARY benefit of stakeholder involvement in risk
scenario development?
A. Ability to determine business impact
B. Up-to-date knowledge on risk responses
,C. Decision-making authority for risk treatment
D. Awareness of emerging business threats
Question #:91 - (Exam Topic 3)
Which of the following would present the MOST significant risk to an
organization when updating the incident response plan?
A. Obsolete response documentation
B. Increased stakeholder turnover
C. Failure to audit third-party providers
D. Undefined assignment of responsibility
Question #:95 - (Exam Topic 3)
The PRIMARY objective of collecting information and reviewing documentation
when performing periodic risk analysis should be to:
A. Identify new or emerging risk issues.
B. Satisfy audit requirements.
C. Survey and analyze historical risk data.
D. Understand internal and external threat agents.
Don't know?
, 2 of 49
Term
Question #:71 - (Exam Topic 3)
An organization practices the principle of least privilege. To ensure
access remains appropriate, application owners should be required to
review user access rights on a regular basis by obtaining:
A. business purpose documentation and software license counts
B. an access control matrix and approval from the user's manager
C. documentation indicating the intended users of the application
D. security logs to determine the cause of invalid login attempts
Give this one a try later!
D. Implementing a process for
C. Introduction of requirements that
ongoing monitoring of control
have not been approved.
effectiveness.
B. an access control matrix and
B. Require business users to sign
approval from the user's
acknowledgment of the poises.
manager.
Don't know?
3 of 49
Term
Question #:67 - (Exam Topic 3)
Which of the following is the BEST control to detect an advanced
, persistent threat (APT)?
A. Utilizing antivirus systems and firewalls
B. Conducting regular penetration tests
C. Monitoring social media activities
D. Implementing automated log monitoring
Give this one a try later!
A. Key performance indicators (KPIs). C. Conduct a root cause analysis.
B. Conducting regular
D. defined roles and responsibilities.
penetration tests
Don't know?
4 of 49
Definition
C. Average number of access privilege exceptions.
Give this one a try later!
Question #:52 - (Exam Topic 3)
Which of the following BEST indicates the efficiency of a process for granting
access privileges?
A. Average time to grant access privileges
B. Number of changes in access granted to users
1 of 49
Definition
D. Undefined assignment of responsibility.
Give this one a try later!
Question #:97 - (Exam Topic 3)
The BEST way to mitigate the high cost of retrieving electronic evidence associated
with potential litigation is to implement policies and procedures for.
A. data logging and monitoring
B. data mining and analytics
C. data classification and labeling
D. data retention and destruction
Question #:98 - (Exam Topic 3)
Which of the following is the PRIMARY benefit of stakeholder involvement in risk
scenario development?
A. Ability to determine business impact
B. Up-to-date knowledge on risk responses
,C. Decision-making authority for risk treatment
D. Awareness of emerging business threats
Question #:91 - (Exam Topic 3)
Which of the following would present the MOST significant risk to an
organization when updating the incident response plan?
A. Obsolete response documentation
B. Increased stakeholder turnover
C. Failure to audit third-party providers
D. Undefined assignment of responsibility
Question #:95 - (Exam Topic 3)
The PRIMARY objective of collecting information and reviewing documentation
when performing periodic risk analysis should be to:
A. Identify new or emerging risk issues.
B. Satisfy audit requirements.
C. Survey and analyze historical risk data.
D. Understand internal and external threat agents.
Don't know?
, 2 of 49
Term
Question #:71 - (Exam Topic 3)
An organization practices the principle of least privilege. To ensure
access remains appropriate, application owners should be required to
review user access rights on a regular basis by obtaining:
A. business purpose documentation and software license counts
B. an access control matrix and approval from the user's manager
C. documentation indicating the intended users of the application
D. security logs to determine the cause of invalid login attempts
Give this one a try later!
D. Implementing a process for
C. Introduction of requirements that
ongoing monitoring of control
have not been approved.
effectiveness.
B. an access control matrix and
B. Require business users to sign
approval from the user's
acknowledgment of the poises.
manager.
Don't know?
3 of 49
Term
Question #:67 - (Exam Topic 3)
Which of the following is the BEST control to detect an advanced
, persistent threat (APT)?
A. Utilizing antivirus systems and firewalls
B. Conducting regular penetration tests
C. Monitoring social media activities
D. Implementing automated log monitoring
Give this one a try later!
A. Key performance indicators (KPIs). C. Conduct a root cause analysis.
B. Conducting regular
D. defined roles and responsibilities.
penetration tests
Don't know?
4 of 49
Definition
C. Average number of access privilege exceptions.
Give this one a try later!
Question #:52 - (Exam Topic 3)
Which of the following BEST indicates the efficiency of a process for granting
access privileges?
A. Average time to grant access privileges
B. Number of changes in access granted to users