Mixed Review - 20 Questions

CRISC Practice: 20 Mixed Review Questions

CRISC Practice Questions

Mixed Review - 20 Questions
Interactive Quiz
Question 1 of 20 0%
Score: 0
Correct: 0
Wrong: 0
1 Shortly after performing the annual review and revision of corporate policies, a risk practitioner becomes aware that a new law may affect security requirements for the human resources system. The risk practitioner should:
Answer: A - Analyze in detail how the law may affect the enterprise Assessing how the law may affect the enterprise is the best course of action. The analysis must also determine whether existing controls already address the new requirements.
2 Which of the following choices provides the BEST view of risk management?
Answer: A - An interdisciplinary team Having an interdisciplinary team contribute to risk management ensures that all areas are adequately considered and included in the risk assessment processes to support an enterprise view of risk.
3 Which of the following choices is a PRIMARY consideration when developing an IT risk awareness program?
Answer: B - How technology risk can impact each attendee's area of business Stakeholders must understand how the IT-related risk impacts the overall business.
4 It is MOST important that risk appetite is aligned with business objectives to ensure that:
Answer: A - Resources are directed toward areas of low risk tolerance Risk appetite is the amount of risk that an enterprise is willing to take on in pursuit of value. Aligning it with business objectives allows an enterprise to evaluate and deploy valuable resources toward those objectives where the risk tolerance (for loss) is low.
5 The risk to an information system that supports a critical business process is owned by:
Answer: B - Senior management Senior management is responsible for the acceptance and mitigation of all risk.
6 Which of the following statements BEST describes the value of a risk register?
Answer: B - It drives the risk response plan Risk registers serve as the main reference for all risk-related information, supporting risk-related decisions such as risk response activities and their prioritization.
7 The MOST significant drawback of using quantitative risk analysis instead of qualitative risk analysis is the:
Answer: D - Higher cost Quantitative risk analysis is generally more complex and, therefore, more costly than qualitative risk analysis.
8 Risk scenarios are analyzed to determine the:
Answer: B - Likelihood and impact Risk scenarios are descriptions of events that can lead to a business impact and are evaluated to determine the likelihood and impact should the event occur.
9 The PRIMARY reason risk assessments should be repeated at regular intervals is:
Answer: C - Business threats are constantly changing As business objectives and methods change, the nature and relevance of threats also change. This is the primary reason to conduct periodic risk assessments.
10 Which of the following choices BEST helps identify information systems control deficiencies?
Answer: A - Gap analysis Controls are deployed to achieve the desired control objectives based on risk assessments and business requirements. The gap between desired control objectives and actual IS control design and operational effectiveness identifies IS control deficiencies.
11 Which of the following choices BEST assists a risk practitioner in measuring the existing level of development of risk-management processes against their desired state?
Answer: A - A capability maturity model A capability maturity model grades processes on a scale of 0 to 5, based on their maturity. It is commonly used by enterprises to measure their existing state and then to determine the desired one.
12 When a risk cannot be sufficiently mitigated through manual or automatic controls, which of the following options will BEST protect against the financial impact of the risk?
Answer: A - Insuring against the risk An insurance policy can compensate the enterprise monetarily for the impact of the risk by transferring the risk to the insurance company.
13 When responding to an identified risk event, the MOST important stakeholders involved in reviewing risk response options to an IT risk are the:
Answer: D - Business managers Business managers are accountable for managing the associated risk and will determine what actions to take based on the information provided by others.
14 Which of the following choices should be considered FIRST when designing information system controls?
Answer: A - The organizational strategic plan Review of the enterprise's strategic plan is the first step in designing effective IS controls that fit the enterprise's long-term plans.
15 Which of the following choices is the BEST measure of the operational effectiveness of risk-management process capabilities?
Answer: A - Key performance indicators Key performance indicators (KPIs) are assessment indicators that support judgment regarding the performance of a specific process.
16 Which of the following business requirements BEST relates to the need for resilient business and information systems processes?
Answer: D - Availability Availability relates to information being available when required by the business process - now and in the future. Resilience is the ability to provide and maintain an acceptable level of service during disasters or when facing operational challenges.
17 An information system that processes weather forecasts for public consumption is MOST likely to place its highest priority on:
Answer: C - Integrity A system that delivers weather forecasts is likely to place its highest priority on the integrity of the data. The risk practitioner should keep in mind that whether a forecast turns out to be accurate in its prediction is distinct from whether the data was accurately represented.
18 The BEST control to prevent unauthorized access to an enterprise's information is user:
Answer: D - Access rules Access rules with the appropriate identification and authentication methods prevent unauthorized access.
19 Which of the following controls BEST protects an enterprise from unauthorized individuals gaining access to sensitive information?
Answer: D - Providing access on a need-to-know basis Physical or logical system access should be assigned on a need-to-know basis (legitimate business requirements) and in ways that incorporate the least privilege and segregation of duties (SoD).
20 Which of the following defenses is BEST to use against phishing attacks?
Answer: C - End-user awareness Phishing attacks are a type of social engineering attack and are best defended by end-user awareness training.
🏆

Quiz Complete!

0 / 20
0
Correct
0
Wrong
20
Total
Quick Reference Summary
Topic Key Point
New Laws / Regulations Analyze impact first before making changes
Risk Management View Best provided by an interdisciplinary team
Risk Awareness Focus on business impact to each attendee
Risk Appetite Align with business objectives to direct resources
Risk Ownership Senior management owns all risk
Risk Register Drives the risk response plan
Quantitative Analysis More costly but more objective
Risk Scenarios Analyzed for likelihood and impact
Risk Assessment Frequency Threats are constantly changing
Control Deficiencies Identified via gap analysis
Maturity Measurement Capability maturity model (0-5 scale)
Risk Transfer Insurance compensates for financial impact
Risk Response Business managers are the key decision-makers
IS Control Design Start with the organizational strategic plan
Process Effectiveness Measured by KPIs
Resilience Relates to availability
Weather Forecast System Highest priority on integrity
Prevent Unauthorized Access Access rules are the best control
Sensitive Information Access Need-to-know basis with least privilege
Phishing Defense End-user awareness is best

Exam Tips

  1. New regulations - Always analyze impact before acting.
  2. Risk management - Best done by interdisciplinary teams, not a single department.
  3. Risk appetite - Must align with business objectives to direct resources effectively.
  4. Risk ownership - Senior management owns all risk.
  5. Risk register - Drives the risk response plan; it is more than just an inventory.
  6. Quantitative vs. qualitative - Quantitative is more costly but more objective.
  7. Risk assessments - Repeat regularly because threats constantly change.
  8. Gap analysis - Best tool for identifying control deficiencies.
  9. Capability maturity model - Measures current vs. desired state of processes.
  10. Risk transfer - Insurance is the best option for financial impact.
  11. Risk response - Business managers are the key decision-makers.
  12. Control design - Start with the organizational strategic plan.
  13. KPIs - Measure process performance and operational effectiveness.
  14. Availability - Supports resilience and business continuity.
  15. Integrity - Critical for data accuracy (e.g., weather forecasts).
  16. Access rules - Best control to prevent unauthorized access.
  17. Need-to-know - Best control for sensitive information access.
  18. Phishing - Best defense is end-user awareness training.
Share:

0 $type={blogger}:

Post a Comment

Follow Us on Facebook

Powered by Blogger.

Main Tags