CRISC Domain 2 - IT Risk Assessment
|Accurate Verified
Qualitative analysis of threats - ANSWER-Provides MOST valuable input to incident
response efforts
What is the MOST beneficial to the improvement of an enterprise's risk
management process - ANSWER-Maturity model
Maturity model - ANSWER-Helps identify the status quo as well as the desired state
What is the PRIMARY reason for having the risk management process reviewed by
independent risk auditors/assessors? - ANSWER-To ensure that the risk factors and
risk profile are well defined
Compliance testing - ANSWER-Used to determine whether unauthorized changes
were made to the production programs
What should be in place before black box testing penetration begins? - ANSWER-A
clearly stated definition and scope
What is the BEST way to ensure that a corporate network is adequately secured
against external attack? - ANSWER-By performing periodic penetration testing
A third party is engaged to develop a BAP. What is the BEST measure for the
existence of back doors? - ANSWER-Security code reviews for the entire application
Security code review - ANSWER-The best measure and involve reviewing the entire
source code to detect all instances of back doors
Substantive test - ANSWER-Includes gathering evidence to evaluate the integrity of
an individual transaction, data or other information
Compliance test - ANSWER-Tests control designed to obtain audit evidence on both
the effectiveness of the controls and their operation during the audit period
What is MOST important during the quantitative risk analysis process? - ANSWER-
Expected Monetary Value (EMV)
Expected Monetary Value (EMV) - ANSWER-The weighted average of probable
outcomes. It represents the expected average payoff if you made that decision,
using the same payoffs and probabilities, an infinite number of times
|Accurate Verified
Qualitative analysis of threats - ANSWER-Provides MOST valuable input to incident
response efforts
What is the MOST beneficial to the improvement of an enterprise's risk
management process - ANSWER-Maturity model
Maturity model - ANSWER-Helps identify the status quo as well as the desired state
What is the PRIMARY reason for having the risk management process reviewed by
independent risk auditors/assessors? - ANSWER-To ensure that the risk factors and
risk profile are well defined
Compliance testing - ANSWER-Used to determine whether unauthorized changes
were made to the production programs
What should be in place before black box testing penetration begins? - ANSWER-A
clearly stated definition and scope
What is the BEST way to ensure that a corporate network is adequately secured
against external attack? - ANSWER-By performing periodic penetration testing
A third party is engaged to develop a BAP. What is the BEST measure for the
existence of back doors? - ANSWER-Security code reviews for the entire application
Security code review - ANSWER-The best measure and involve reviewing the entire
source code to detect all instances of back doors
Substantive test - ANSWER-Includes gathering evidence to evaluate the integrity of
an individual transaction, data or other information
Compliance test - ANSWER-Tests control designed to obtain audit evidence on both
the effectiveness of the controls and their operation during the audit period
What is MOST important during the quantitative risk analysis process? - ANSWER-
Expected Monetary Value (EMV)
Expected Monetary Value (EMV) - ANSWER-The weighted average of probable
outcomes. It represents the expected average payoff if you made that decision,
using the same payoffs and probabilities, an infinite number of times