Study HIGH Quality CRISC Free Study Guides and Exams Tutorials [Q694-Q709]

Share

Study HIGH Quality CRISC  Free Study Guides and Exams Tutorials

Download ISACA CRISC Exam Dumps to Pass Exam Easily

NEW QUESTION # 694
Risk appetite should be PRIMARILY driven by which of the following?

  • A. Business impact analysis (BIA)
  • B. Stakeholder requirements
  • C. Legal and regulatory requirements
  • D. Enterprise security architecture roadmap

Answer: B


NEW QUESTION # 695
You are the project manager for TTP project. You are in the Identify Risks process. You have to create the risk register. Which of the following are included in the risk register?
Each correct answer represents a complete solution. (Choose two.)

  • A. List of identified risks
  • B. List of potential responses
  • C. List of mitigation techniques
  • D. List of key stakeholders

Answer: A,B

Explanation:
Explanation/Reference:
Explanation:
Risk register primarily contains the following:
List of identified risks: A reasonable description of the identified risks is noted in the risk register. The

description includes event, cause, effect, impact related to the risks identified. In addition to the list of identified risks, the root causes of those risks may appear in the risk register.
List of potential responses: Potential responses to a risk may be identified during the Identify Risks

process. These responses are useful as inputs to the Plan Risk Responses process.
Incorrect Answers:
B: This is not a valid content of risk register.
A risk register is an inventory of risks and exposure associated with those risks. Risks are commonly found in project management practices, and provide information to identify, analyze, and manage risks. Typically a risk register contains:
A description of the risk

The impact should this event actually occur

The probability of its occurrence

Risk Score (the multiplication of Probability and Impact)

A summary of the planned response should the event occur

A summary of the mitigation (the actions taken in advance to reduce the probability and/or impact of the

event)
Ranking of risks by Risk Score so as to highlight the highest priority risks to all involved.

C: Risk register do contain the summary of mitigation, but only after the applying risk response. Here in this scenario you are in risk identification phase, hence mitigation techniques cannot be documented at this situation.


NEW QUESTION # 696
Which of the following phases is involved in the Data Extraction, Validation, Aggregation and Analysis?

  • A. Risk identification, Risk assessment, Risk response and Risk monitoring
  • B. Risk response and Risk monitoring
  • C. Requirements gathering, Data access, Data validation, Data analysis, and Reporting and corrective action
  • D. Data access and Data validation
  • E. Explanation:
    The basic concepts related to data extraction, validation, aggregation and analysis is important as KRIs often rely on digital information from diverse sources. The phases which are involved in this are: Requirements gathering: Detailed plan and project's scope is required for monitoring risks. In the case of a monitoring project, this step should involve process owners, data owners, system custodians and other process stakeholders. Data access: In the data access process, management identifies which data are available and how they can be acquired in a format that can be used for analysis. There are two options for data extraction: Extracting data directly from the source systems after system owner approval Receiving data extracts from the system custodian (IT) after system owner approval Direct extraction is preferred, especially since this involves management monitoring its own controls, instead of auditors/third parties monitoring management's controls. If it is not feasible to get direct access, a data access request form should be submitted to the data owners that detail the appropriate data fields to be extracted. The request should specify the method of delivery for the file. Data validation: Data validation ensures that extracted data are ready for analysis. One of its important objective is to perform tests examining the data quality to ensure data are valid complete and free of errors. This may also involve making data from different sources suitable for comparative analysis. Following concepts should be considered while validating data: Ensure the validity, i.e., data match definitions in the table layout Ensure that the data are complete Ensure that extracted data contain only the data requested Identify missing data, such as gaps in sequence or blank records Identify and confirm the validity of duplicates Identify the derived values Check if the data given is reasonable or not Identify the relationship between table fields Record, in a transaction or detail table, that the record has no match in a master table Data analysis: Analysis of data involves simple set of steps or complex combination of commands and other functionality. Data analysis is designed in such a way to achieve the stated objectives from the project plan. Although this may be applicable to any monitoring activity, it would be beneficial to consider transferability and scalability. This may include robust documentation, use of software development standards and naming conventions. Reporting and corrective action: According to the requirements of the monitoring objectives and the technology being used, reporting structure and distribution are decided. Reporting procedures indicate to whom outputs from the automated monitoring process are distributed so that they are directed to the right people, in the right format, etc. Similar to the data analysis stage, reporting may also identify areas in which changes to the sensitivity of the reporting parameters or the timing and frequency of the monitoring activity may be required.

Answer: C

Explanation:
is incorrect. These are the phases that are involved in risk management.


NEW QUESTION # 697
Which of the following is the BEST key performance indicator (KPI) to measure the maturity of an organization's security incident handling process?

  • A. The number of recurring security incidents
  • B. The number of newly identified security incidents
  • C. The number of security incidents escalated to senior management
  • D. The number of resolved security incidents

Answer: A

Explanation:
* A security incident handling process is a set of procedures and activities that aim to identify, analyze, contain, eradicate, recover from, and learn from security incidents that affect the confidentiality, integrity, or availability of information assets12.
* The maturity of a security incident handling process is the degree to which the process is defined, managed, measured, controlled, and improved, and the extent to which it meets the organization's objectives and expectations34.
* The best key performance indicator (KPI) to measure the maturity of a security incident handling process is the number of recurring security incidents, which is the frequency or rate of security incidents that are repeated or reoccur after being resolved or closed56.
* The number of recurring security incidents is the best KPI because it reflects the effectiveness and efficiency of the security incident handling process, and the ability of the process to prevent or reduce the recurrence of security incidents through root cause analysis, corrective actions, and continuous improvement56.
* The number of recurring security incidents is also the best KPI because it is directly related to the organization's objectives and expectations, such as minimizing the impact and cost of security incidents, enhancing the security posture and resilience of the organization, and complying with the relevant standards and regulations56.
* The other options are not the best KPIs, but rather possible metrics that may support or complement the measurement of the maturity of the security incident handling process. For example:
* The number of security incidents escalated to senior management is a metric that indicates the severity or complexity of security incidents, and the involvement or awareness of the senior management in the security incident handling process56. However, this metric does not measure the effectiveness or efficiency of the process, or the ability of the process to prevent or reduce security incidents56.
* The number of resolved security incidents is a metric that indicates the output or outcome of the security incident handling process, and the performance or productivity of the security incident handling team56. However, this metric does not measure the quality or sustainability of the resolution, or the ability of the process to prevent or reduce security incidents56.
* The number of newly identified security incidents is a metric that indicates the input or demand of the security incident handling process, and the capability or capacity of the security incident detection and identification mechanisms56. However, this metric does not measure the effectiveness or efficiency of the process, or the ability of the process to prevent or reduce security incidents56. References =
* 1: Computer Security Incident Handling Guide, NIST Special Publication 800-61, Revision 2, August
2012
* 2: ISO/IEC 27035:2016 Information technology - Security techniques - Information security incident management
* 3: Capability Maturity Model Integration (CMMI) for Services, Version 1.3, November 2010
* 4: COBIT 2019 Framework: Introduction and Methodology, ISACA, 2018
* 5: KPIs for Security Operations & Incident Response, SecurityScorecard Blog, June 7, 2021
* 6: Key Performance Indicators (KPIs) for Security Operations and Incident Response, DFLabs White Paper, 2018


NEW QUESTION # 698
Which group has PRIMARY ownership of reputational risk stemming from unethical behavior within the
organization?

  • A. Risk management committee
  • B. Board of directors
  • C. Audit committee
  • D. Human resources (HR)

Answer: B

Explanation:
The group that has primary ownership of reputational risk stemming from unethical behavior within the
organization is A. Board of directors. According to the CFA Institute, the board of directors is responsible for
setting the tone at the top and ensuring that the company adheres to high ethical standards and values. The
board of directors also oversees the company's culture, governance, and risk management practices, and holds
the management accountable for any misconduct or breach of trust1 The board of directors may delegate
some of its oversight functions to other committees, such as the human resources, risk management, or audit
committee, but ultimately, the board of directors bears the ultimate responsibility for the company's
reputation and integrity


NEW QUESTION # 699
Which of the following is the MOST important use of KRIs?

  • A. Providing an indication of the enterprise's risk appetite and tolerance
  • B. Providing a backward-looking view on risk events that have occurred
  • C. Enabling the documentation and analysis of trends
  • D. Providing an early warning signal

Answer: D

Explanation:
Section: Volume A
Explanation:
Key Risk Indicators are the prime monitoring indicators of the enterprise. KRIs are highly relevant and possess a high probability of predicting or indicating important risk. KRIs help in avoiding excessively large number of risk indicators to manage and report that a large enterprise may have.
As KRIs are the indicators of risk, hence its most important function is to effectively give an early warning signal that a high risk is emerging to enable management to take proactive action before the risk actually becomes a loss.
Incorrect Answers:
A: This is one of the important functions of KRIs which can help management to improve but is not as important as giving early warning.
C: KRIs provide an indication of the enterprise's risk appetite and tolerance through metric setting, but this is not as important as giving early warning.
D: This is not as important as giving early warning.


NEW QUESTION # 700
An unauthorized individual has socially engineered entry into an organization's secured physical premises.
Which of the following is the BEST way to prevent future occurrences?

  • A. Conduct security awareness training.
  • B. Require security access badges.
  • C. Employ security guards.
  • D. Install security cameras.

Answer: A

Explanation:
* Social engineering is a technique that involves manipulating or deceiving people into performing actions or divulging information that may compromise the security of an organization or its data12.
* Entry into an organization's secured physical premises is a form of physical access that allows an unauthorized individual to access, steal, or damage the organization's assets, such as equipment, documents, or systems34.
* The best way to prevent future occurrences of social engineering entry into an organization's secured physical premises is to conduct security awareness training, which is an educational program that aims to equip the organization's employees with the knowledge and skills they need to protect the organization's data and sensitive information from cyber threats, such as hacking, phishing, or other breaches56.
* Security awareness training is the best way because it helps the employees to recognize and resist the common and emerging social engineering techniques, such as tailgating, impersonation, or pretexting, that may be used by the attackers to gain physical access to the organization's premises56.
* Security awareness training is also the best way because it fosters a culture of security and responsibility among the employees, and encourages them to follow the best practices and policies for physical security, such as locking the doors, verifying the identity of visitors, or reporting any suspicious activities or incidents56.
* The other options are not the best way, but rather possible measures or controls that may supplement or enhance the security awareness training. For example:
* Employing security guards is a measure that involves hiring or contracting professional personnel who are trained and authorized to monitor, patrol, and protect the organization's premises from unauthorized access or intrusion78. However, this measure is not the best way because it may not be sufficient or effective to prevent or deter all types of social engineering attacks, especially if the attackers are able to bypass, deceive, or coerce the security guards78.
* Installing security cameras is a control that involves using electronic devices that capture and record the visual images of the organization's premises, and provide evidence or alerts of any unauthorized access or activity . However, this control is not the best way because it is reactive rather than proactive, and may not prevent or stop the social engineering attacks before they cause any harm or damage to the organization .
* Requiring security access badges is a control that involves using physical or electronic cards that identify and authenticate the employees or authorized visitors who are allowed to enter the organization's premises, and restrict or deny the access to anyone else . However, this control is not the best way because it may not be foolproof or reliable to prevent or detect the social
* engineering attacks, especially if the attackers are able to steal, forge, or clone the security access badges . References =
* 1: What is Social Engineering? | Types & Examples of Social Engineering Attacks1
* 2: Social Engineering: What It Is and How to Prevent It | Digital Guardian2
* 3: What is physical Social Engineering and why is it important? - Integrity3603
* 4: What Is Tailgating (Piggybacking) In Cyber Security? - Wlan Labs4
* 5: What Is Security Awareness Training and Why Is It Important? - Kaspersky5
* 6: Security Awareness Training - Cybersecurity Education Online | Proofpoint US6
* 7: Security Guard - Wikipedia7
* 8: Security Guard Services - Allied Universal8
* : Security Camera - Wikipedia
* : Security Camera Systems - The Home Depot
* : Access Badge - Wikipedia
* : Access Control Systems - HID Global


NEW QUESTION # 701
What should a risk practitioner do NEXT if an ineffective key control is identified on a critical system?

  • A. Escalate to senior management.
  • B. Propose acceptance of the risk.
  • C. Conduct a gap analysis.
  • D. Revalidate the risk assessment.

Answer: C

Explanation:
Section: Volume D
Explanation/Reference:


NEW QUESTION # 702
A company has recently acquired a customer relationship management (CRM) application from a certified software vendor. Which of the following will BE ST help lo prevent technical vulnerabilities from being exploded?

  • A. Update the software with the latest patches and updates
  • B. Verity me software agreement indemnifies the company from losses
  • C. implement code reviews and Quality assurance on a regular basis
  • D. Review the source coda and error reporting of the application

Answer: A

Explanation:
The best way to prevent technical vulnerabilities from being exploited is to update the software with the latest patches and updates. Patches and updates are software modifications that fix the known bugs, errors, or flaws in the software. They also improve the performance, functionality, and security of the software. By updating the software with the latest patches and updates, the company can reduce the exposure and likelihood of the technical vulnerabilities, and protect the software from potential attacks or exploits. The other options are not as effective as updating the software with the latest patches and updates, as they are related to the quality assurance, legal protection, or error handling of the software, not the prevention or mitigation of the technical vulnerabilities. References = Risk and Information Systems Control Study Manual, Chapter 3: IT Risk Response, Section 3.3: IT Risk Response Implementation, page 145.


NEW QUESTION # 703
An organization recently implemented an automated interface for uploading payment files to its banking
system to replace manual processing. Which of the following elements of the risk register is MOST
appropriate for the risk practitioner to update to reflect the improved control?

  • A. Risk scenarios
  • B. Risk ownership
  • C. Risk likelihood
  • D. Risk impact

Answer: C

Explanation:
Updating the risk likelihood in the risk register is appropriate when an improved control, such as an
automated interface, is implemented. This change affects the probability of the risk occurring, thus reflecting
the enhanced control environment.


NEW QUESTION # 704
A maturity model will BEST indicate:

  • A. effectiveness and efficiency.
  • B. confidentiality and integrity.
  • C. availability and reliability.
  • D. certification and accreditation.

Answer: A

Explanation:
According to Wikipedia1, a maturity model is a framework for measuring an organization's maturity, or that of a business function within an organization, with maturity being defined as a measurement of the ability of an organization for continuous improvement in a particular discipline. A maturity model will best indicate the effectiveness and efficiency of an organization or a business function, as it helps to evaluate how well they achieve their intended objectives with minimum resources, time, and cost. A maturity model also helps to identify and prioritize the areas and opportunities for improvement, and to establish and communicate the standards and best practices for the discipline. References = Wikipedia1


NEW QUESTION # 705
An organization has implemented a system capable of comprehensive employee monitoring. Which of the following should direct how the system is used?

  • A. Industry best practices
  • B. Employee code of conduct
  • C. Organizational strategy
  • D. Organizational policy

Answer: D

Explanation:
The best answer is D. Organizational policy. An organizational policy is a set of rules and guidelines that defines how the organization operates and conducts its activities. An organizational policy should direct how the employee monitoring system is used, because it can specify the purpose, scope, methods, and limitations of the monitoring, as well as the roles and responsibilities of the parties involved, the data protection and privacy measures, and the consequences of non-compliance. An organizational policy can also help to ensure that the employee monitoring system is aligned with the organization's objectives, values, and culture, and that it complies with the relevant laws and regulations. The other options are not the best answer, although they may be related or influential to the organizational policy. Organizational strategy is a plan of action that outlines the organization's vision, mission, goals, and initiatives, but it does not provide the details or the rules of how the employee monitoring system is used. Employee code of conduct is a document that describes the expected behavior and ethics of the employees, but it does not address the specific aspects or the procedures of the employee monitoring system. Industry best practices are the proven methods and standards that are adopted by the leading organizations in a specific field or sector, but they may not be applicable or suitable for every organization or situation. References = Workplace Monitoring Policy Template - CurrentWare, The All-In-One Guide to Employee Monitoring - G2


NEW QUESTION # 706
Which of the following will provide the BEST measure of compliance with IT policies?

  • A. Conduct regular independent reviews.
  • B. Test staff on their compliance responsibilities.
  • C. Evaluate past policy review reports.
  • D. Perform penetration testing.

Answer: A

Explanation:
Conducting regular independent reviews will provide the best measure of compliance with IT policies, as this ensures that the policies are implemented and followed consistently and effectively across the organization.
Independent reviews can also identify any gaps, weaknesses, or violations in the compliance process, and recommend corrective actions or improvements. Independent reviews can be performed by internal or external auditors, regulators, or consultants, depending on the scope and purpose of the review. Evaluating past policy review reports, performing penetration testing, and testing staff on their complianceresponsibilities are not the best measures of compliance with IT policies, although they may be useful or complementary methods. Evaluating past policy review reports can provide some historical and comparative data, but it may not reflect the current or accurate situation of the compliance status. Performing penetration testing can assess the security and vulnerability of the IT systems and networks, but it does not measure the compliance with all the IT policies, such as those related to governance, operations, or quality. Testing staff on their compliance responsibilities can evaluate the awareness and knowledge of the staff, but it does not measure the actual behaviour or performance of the staff in complying with the IT policies. References = Risk and Information Systems Control Study Manual, Chapter 5: Risk and Control Monitoring and Reporting, page 187.


NEW QUESTION # 707
A risk owner should be the person accountable for:

  • A. managing controls
  • B. the risk management process
  • C. the business process
  • D. implementing actions

Answer: D

Explanation:
Section: Volume D


NEW QUESTION # 708
A risk practitioner is advising management on how to update the IT policy framework to account for the organization s cloud usage. Which of the following should be the FIRST step in this process?

  • A. Determine gaps between the current state and target framework.
  • B. Evaluate adherence to existing IT policies and standards.
  • C. Consult with industry peers regarding cloud best practices.
  • D. Adopt an industry-leading cloud computing framework.

Answer: B


NEW QUESTION # 709
......

Get 100% Real Free Isaca Certificaton CRISC Sample Questions: https://pass4sure.trainingquiz.com/CRISC-training-materials.html