Isaca CRISC - Certified in Risk and Information Systems Control
An organization is conducting a review of emerging risk. Which of the following is the BEST input for this exercise?
An organization has established a single enterprise-wide risk register that records high-level risk scenarios. The IT risk department has created its own register to record more granular scenarios applicable to IT. Which of the following is the BEST way to ensure alignment between these two registers?
Which of the following is the GREATEST advantage of implementing a risk management program?
Employees are repeatedly seen holding the door open for others, so that trailing employees do not have to stop and swipe their own ID badges. This behavior BEST represents:
Which of the following is MOST helpful in verifying that the implementation of a risk mitigation control has been completed as intended?
When assessing the maturity level of an organization's risk management framework, which of the following should be of GREATEST concern to a risk practitioner?
Which of the following is PRIMARILY a risk management responsibly of the first line of defense?
Which of the following is MOST important when identifying an organization's risk exposure associated with Internet of Things (loT) devices?
Which of the following is the MAIN reason to continuously monitor IT-related risk?
Which of the following BEST confirms the existence and operating effectiveness of information systems controls?
When an organization is having new software implemented under contract, which of the following is key to controlling escalating costs?
A global organization is considering the transfer of its customer information systems to an overseas cloud service provider in the event of a disaster. Which of the following should be the MOST important risk consideration?
Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of a disaster recovery plan (DRP)?
Which of the following should be accountable for ensuring that media containing financial information are adequately destroyed per an organization's data disposal policy?
Which of the following is the MAIN purpose of monitoring risk?
The risk to an organization's reputation due to a recent cybersecurity breach is PRIMARILY considered to be:
Which of the following BEST supports the management of identified risk scenarios?
Whether the results of risk analyses should be presented in quantitative or qualitative terms should be based PRIMARILY on the: