Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Pass CRISC Exam Guide

Page: 39 / 136
Total 1810 questions

Certified in Risk and Information Systems Control Questions and Answers

Question 153

A risk practitioner is concerned with potential data loss in the event of a breach at a hosted third-party provider. Which of the following is the BEST way to mitigate this risk?

Options:

A.

Include an indemnification clause in the provider's contract.

B.

Monitor provider performance against service level agreements (SLAs).

C.

Purchase cyber insurance to protect against data breaches.

D.

Ensure appropriate security controls are in place through independent audits.

Question 154

Which of the following should be given the HIGHEST priority when developing a response plan for risk assessment results?

Options:

A.

Risk that has been untreated

B.

Items with a high inherent risk

C.

Items with the highest likelihood of occurrence

D.

Risk that exceeds risk appetite

Question 155

As part of an overall IT risk management plan, an IT risk register BEST helps management:

Options:

A.

align IT processes with business objectives.

B.

communicate the enterprise risk management policy.

C.

stay current with existing control status.

D.

understand the organizational risk profile.

Question 156

Which of the following presents the GREATEST challenge to managing an organization's end-user devices?

Options:

A.

Incomplete end-user device inventory

B.

Unsupported end-user applications

C.

Incompatible end-user devices

D.

Multiple end-user device models

Page: 39 / 136
Total 1810 questions