Month End Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Helping Hand Questions for CRISC

Page: 14 / 131
Total 1745 questions

Certified in Risk and Information Systems Control Questions and Answers

Question 53

Which of the following provides The BEST information when determining whether to accept residual risk of a critical system to be implemented?

Options:

A.

Single loss expectancy (SLE)

B.

Cost of the information system

C.

Availability of additional compensating controls

D.

Potential business impacts are within acceptable levels

Question 54

Before assigning sensitivity levels to information it is MOST important to:

Options:

A.

define recovery time objectives (RTOs).

B.

define the information classification policy

C.

conduct a sensitivity analyse

D.

Identify information custodians

Question 55

Which of the following is the MOST important reason to communicate risk assessments to senior management?

Options:

A.

To ensure actions can be taken to align assessment results to risk appetite

B.

To ensure key risk indicator (KRI) thresholds can be adjusted for tolerance

C.

To ensure awareness of risk and controls is shared with key decision makers

D.

To ensure the maturity of the assessment program can be validated

Question 56

Which of the following BEST indicates how well a web infrastructure protects critical information from an attacker?

Options:

A.

Failed login attempts

B.

Simulating a denial of service attack

C.

Absence of IT audit findings

D.

Penetration test

Page: 14 / 131
Total 1745 questions