Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

OCEG GRCP - GRC Professional Certification Exam

Page: 6 / 9
Total 271 questions

What are some key practices involved in managing policies within an organization?

A.

Having internal audit design standard policy templates to make assessment of their effectiveness easier

B.

Delegating policy management to each unit of the organization so there is a sense of accountability established

C.

Implementing, communicating, enforcing, and auditing policies and related procedures to ensure that they operate as intended and remain relevant

D.

Establishing policy management technology that has pre-populated templates so the organization’s policies meet industry standards

Can the Second Line provide assurance over First Line activities, and under what conditions?

A.

No, the Second Line cannot provide assurance over First Line activities because it is focused on strategic planning and long-term goals, not on assurance activities

B.

Yes, the Second Line can provide assurance over First Line activities regardless of the design or performance of the activities because it has a higher level of authority and the necessary skills

C.

Yes, the Second Line may provide assurance over First Line activities so long as the activities under examination were not designed or performed by the Second Line, and the Second Line personnel have the required degree of Assurance Objectivity and Assurance Competence relative to the subject matter and desired Level of Assurance

D.

No, the Second Line cannot provide assurance over First Line activities because it lacks the necessary authority and jurisdiction

What are some examples of non-economic incentives that can be used to encourage favorable conduct?

A.

Appreciation, status, professional development

B.

Stock options, salary increases, bonuses, and profit-sharing

C.

Gift baskets, extra vacation time, and employee competitions

D.

Health insurance, retirement plans, paid time off, and sick leave

How do values influence the way an organization operates?

A.

They establish the organization’s code of conduct

B.

They set voluntary boundaries for how the organization operates and often explain design decisions about the operating model

C.

They dictate the organization’s pricing strategy and revenue generation

D.

They determine the organization's market share and competitive positioning as part of assessing its financial value to shareholders

What is the difference between reasonable assurance and limited assurance?

A.

Reasonable assurance is provided by external auditors as part of a financial audit and indicates conformity to suitable criteria and freedom from material error, while limited assurance results from reviews, compilations, and other activities performed by competent personnel who are sufficiently objective about the subject matter.

B.

Reasonable assurance is provided by internal auditors as part of a risk assessment, while limited assurance results from external audits and regulatory examinations.

C.

Reasonable assurance is provided by the Board of Directors as part of governance activities, while limited assurance results from employee self-assessments.

D.

Reasonable assurance is provided by management as part of strategic planning, while limited assurance results from operational reviews and performance evaluations.

(How is effectiveness measured in the context of the REVIEW component?)

A.

Through the design and operating effectiveness of the capabilities to monitor the capability, provide assurance, and learn from prior mistakes and improve

B.

Through the number of new products launched

C.

Through the organization’s stock price and market capitalization

D.

Through the number of employees and their job satisfaction

What types of actions and controls are included in the PERFORM component of the GRC Capability Model?

A.

Internal, external, and hybrid actions and controls.

B.

Mandatory, voluntary, and optional actions and controls.

C.

Proactive, detective, and responsive actions and controls.

D.

Reactive, preventive, and corrective actions and controls.

(What type of policy provides instructions on what actions should be taken by the organization?)

A.

Prescriptive Policy

B.

Proscriptive Policy

C.

Ethical Conduct Policy

D.

Procedural Policy

Who are key external stakeholders that may significantly influence an organization?

A.

Distributors, resellers, and franchisees.

B.

Competitors, employees, and board members.

C.

Marketing agencies, legal advisors, and auditors.

D.

Customers, shareholders, creditors and lenders, government, and non-governmental organizations.

(What is the significance of establishing ethical decision-making guidelines within an organization?)

A.

Ethical decision guidelines are optional and have no impact on the organization’s decision-making process

B.

Ethical decision guidelines are used instead of policies and procedures so employees learn how to make the right choices

C.

Ethical decision guidelines are only applicable to the organization’s external stakeholders

D.

Ethical decision guidelines help people decide what to do without an explicit policy or procedure when the circumstances are not explicitly covered