Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Download Full Version CRISC Isaca Exam

Page: 38 / 136
Total 1810 questions

Certified in Risk and Information Systems Control Questions and Answers

Question 149

Which of the following risk scenarios should be considered in a disaster recovery plan (DRP)?

Options:

A.

A pandemic situation requiring remote work

B.

A ransomware attack affecting critical systems

C.

A vendor failing to notify the organization of a data breach

D.

Hacking activity leading to theft of sensitive data

Question 150

Which of the following is the MOST effective way 10 identify an application backdoor prior to implementation'?

Options:

A.

User acceptance testing (UAT)

B.

Database activity monitoring

C.

Source code review

D.

Vulnerability analysis

Question 151

During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?

Options:

A.

Escalate the non-cooperation to management

B.

Exclude applicable controls from the assessment.

C.

Review the supplier's contractual obligations.

D.

Request risk acceptance from the business process owner.

Question 152

Which of the following BEST supports the integration of IT risk management into an organization's strategic planning?

Options:

A.

Clearly defined organizational goals and objectives

B.

Incentive plans that reward employees based on IT risk metrics

C.

Regular organization-wide risk awareness training

D.

A comprehensive and documented IT risk management plan

Page: 38 / 136
Total 1810 questions