(May-2024) CRISC Exam Dumps Contains FREE Real Quesions from the Actual Exam
Free Test Engine Verified By Isaca Certificaton Certified Experts
NEW QUESTION # 635
Which of the following would BEST ensure that identified risk scenarios are addressed?
- A. Performing real-time monitoring of threats
- B. Performing regular risk control self-assessments
- C. Creating a separate risk register for key business units
- D. Reviewing the implementation of the risk response
Answer: D
Explanation:
Section: Volume D
NEW QUESTION # 636
Suppose you are working in Techmart Inc. which sells various products through its website. Due to some recent losses, you are trying to identify the most important risks to the Website. Based on feedback from several experts, you have come up with a list. You now want to prioritize these risks. Now in which category you would put the risk concerning the modification of the Website by unauthorized parties.
- A. Denial of service attack
- B. FTP Bounce Attack
- C. Web defacing
- D. Ping Flooding Attack
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Website defacing is an attack on a website by unauthorized party that changes the visual appearance of the site or a webpage. These are typically the work of system crackers, who break into a web server and replace the hosted website with one of their own.
Incorrect Answers:
A: Ping Flooding is the extreme of sending thousands or millions of pings per second. Ping Flooding attack can make system slow or even shut down an entire site.
C: A denial-of-service attack (DoS attack) is an attempt to make a computer or network resource unavailable to its intended users. One common method of attack involves saturating the target machine with external communications requests, such that it cannot respond to legitimate traffic, or responds so slowly as to be rendered effectively unavailable.
D: The FTP bounce attack is attack which slips past application-based firewalls. In this hacker uploads a file to the FTP server and then requests this file be sent to an internal server. This file may contain malicious software or a simple script that occupies the internal server and uses up all the memory and CPU resources.
NEW QUESTION # 637
What can be determined from the risk scenario chart?
- A. Capability of enterprise to implement
- B. Risk treatment options
- C. The multiple risk factors addressed by a chosen response
- D. Relative positions on the risk map
Answer: D
NEW QUESTION # 638
The MOST important reason to aggregate results from multiple risk assessments on interdependent information systems is to:
- A. facilitate communication to senior management
- B. identify critical information systems
- C. efficiently manage the scope of the assignment
- D. establish overall impact to the organization
Answer: D
NEW QUESTION # 639
To help ensure the success of a major IT project, it is MOST important to:
- A. obtain approval from business process owners
- B. align it with the organization's strategic plan
- C. obtain the appropriate stakeholders' commitment
- D. update the risk register on a regular basis
Answer: C
Explanation:
Section: Volume D
NEW QUESTION # 640
Which of the following is the MOST important data source for monitoring key risk indicators (KRIs)?
- A. Automated logs collected from different systems
- B. Trend analysis of external risk factors
- C. Audit reports from internal information systems audits
- D. Directives from legal and regulatory authorities
Answer: A
Explanation:
Section: Volume D
NEW QUESTION # 641
Accountability for a particular risk is BEST represented in a:
- A. risk scenario
- B. risk catalog
- C. RACI matrix.
- D. risk register.
Answer: D
NEW QUESTION # 642
A risk heat map is MOST commonly used as part of an IT risk analysis to facilitate risk:
- A. assessment.
- B. treatment.
- C. identification.
- D. communication
Answer: A
NEW QUESTION # 643
Which of the following BEST assists in justifying an investment in automated controls?
- A. Alignment of investment with risk appetite
- B. Cost-benefit analysis
- C. Reduction in personnel costs
- D. Elimination of compensating controls
Answer: B
NEW QUESTION # 644
An organization is measuring the effectiveness of its change management program to reduce the number of unplanned production changes. Which of the following would be the BEST metric to determine if the program is performing as expected?
- A. Ratio of emergency fixes to total changes
- B. Ratio of system changes to total changes
- C. Decrease in the time to move changes to production
- D. Decrease in number of changes without a fallback plan
Answer: A
NEW QUESTION # 645
Which of the following would BEST help to ensure that suspicious network activity is identified?
- A. Analyzing intrusion detection system (IDS) logs
- B. Analyzing server logs
- C. Using a third-party monitoring provider
- D. Coordinating events with appropriate agencies
Answer: C
NEW QUESTION # 646
A risk practitioner has become aware of production data being used in a test environment. Which of the following should be the practitioner's PRIMARY concern?
- A. Security of the test environment
- B. Readability of test data
- C. Sensitivity of the data
- D. Availability of data to authorized staff
Answer: C
NEW QUESTION # 647
Which of the following presents the GREATEST risk to change control in business application development over the complete life cycle?
- A. Bypassing quality requirements before go-live
- B. Lack of an integrated development environment (IDE) tool
- C. Introduction of requirements that have not been approved
- D. Emphasis on multiple application testing cycles
Answer: C
NEW QUESTION # 648
The BEST indication that risk management is effective is when risk has been reduced to meet:
- A. risk capacity.
- B. risk levels.
- C. risk appetite.
- D. risk budgets.
Answer: C
NEW QUESTION # 649
A risk practitioner is summarizing the results of a high-profile risk assessment sponsored by senior management. The BEST way to support risk-based decisions by senior management would be to:
- A. map findings to objectives.
- B. provide a quantified detailed analysts.
- C. quantify key risk indicators (KRls).
- D. recommend risk tolerance thresholds.
Answer: A
NEW QUESTION # 650
The BEST reason to classify IT assets during a risk assessment is to determine the:
- A. appropriate level of protection
- B. priority in the risk register
- C. business process owner
- D. enterprise risk profile
Answer: A
NEW QUESTION # 651
You are working in Bluewell Inc. which make advertisement Websites. Someone had made unauthorized changes to a your Website. Which of the following terms refers to this type of loss?
- A. Loss of integrity
- B. Loss of confidentiality
- C. Loss of revenue
- D. Loss of availability
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Loss of integrity refers to the following types of losses:
An e-mail message is modified in transit
A virus infects a file
Someone makes unauthorized changes to a Web site
Incorrect Answers:
A: Someone sees a password or a company's secret formula, this is referred to as loss of confidentiality.
C: An e-mail server is down and no one has e-mail access, or a file server is down so data files aren't available comes under loss of availability.
D: This refers to the events which would eventually cause loss of revenue.
NEW QUESTION # 652
Which of the following MOST effectively limits the impact of a ransomware attack?
- A. Cryptocurrency reserve
- B. End user training
- C. Data backups
- D. Cyber insurance
Answer: B
NEW QUESTION # 653
Which of the following is the MOST important objective of embedding risk management practices into the initiation phase of the project management life cycle?
- A. To assess risk throughout the project
- B. To deliver projects on time and on budget
- C. To include project risk in the enterprise-wide IT risk profit.
- D. To assess inherent risk
Answer: A
NEW QUESTION # 654
Which of the following events refer to loss of integrity?
Each correct answer represents a complete solution. Choose three.
- A. A virus infects a file
- B. Someone sees company's secret formula
- C. Someone makes unauthorized changes to a Web site
- D. An e-mail message is modified in transit
Answer: A,C,D
Explanation:
Section: Volume C
Explanation:
Loss of integrity refers to the following types of losses:
* An e-mail message is modified in transit A virus infects a file
* Someone makes unauthorized changes to a Web site
Incorrect Answers:
A: Someone sees company's secret formula or password comes under loss of confidentiality.
NEW QUESTION # 655
Which of the following is the BEST indicator of executive management's support for IT risk mitigation efforts?
- A. The number of executives attending IT security awareness training
- B. The percentage of incidents presented to the board
- C. The percentage of corporate budget allocated to IT risk activities
- D. The number of stakeholders involved in IT risk identification workshops
Answer: C
NEW QUESTION # 656
......
ISACA CRISC Exam Certification Details:
| Duration | 240 mins |
| Exam Code | CRISC |
| Books / Training | Virtual Instructor-Led Training In-Person Training & Conferences Customized, On-Site Corporate Training CRISC Planning Guide |
| Exam Name | ISACA Certified in Risk and Information Systems Control (CRISC) |
| Exam Price ISACA Nonmember | $760 (USD) |
| Passing Score | 450/800 |
| Sample Questions | ISACA CRISC Sample Questions |
| Exam Price ISACA Member | $575 (USD) |
| Number of Questions | 150 |
Use Real ISACA Achieve the CRISC Dumps - 100% Exam Passing Guarantee: https://www.passexamdumps.com/CRISC-valid-exam-dumps.html
Verified CRISC Q&As - Pass Guarantee CRISC Exam Dumps: https://drive.google.com/open?id=1SksGvKm1Pv5aYeJuUkhEFI5T2j2zCPfU
