live chatMcAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
Pass4Test 10%OFF Discount Code

ISACA Certified in Risk and Information Systems Control - CRISC Exam Questions

QUESTION NO: 1
Which of the following BEST indicates that additional or improved controls ate needed m the environment?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 2
The MOST important consideration when selecting a control to mitigate an identified risk is whether:
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 3
Which of the following controls would BEST mitigate the risk of user passwords being compromised by a man in the middle technique?
Correct Answer: A
QUESTION NO: 4
An organization practices the principle of least privilege. To ensure access remains appropriate, application owners should be required to review user access rights on a regular basis by obtaining:
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 5
Which of the following is the GREATEST benefit of centralizing IT systems?
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 6
A risk practitioner is concerned with potential data loss in the event of a breach at a hosted third-party provider. Which of the following is the BEST way to mitigate this risk?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 7
Which of the following should be the PRIMARY consideration when implementing controls for monitoring user activity logs?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 8
Which of the following is MOST helpful in aligning IT risk with business objectives?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 9
Which of the following should be the risk practitioner ' s FIRST course of action when an organization plans to adopt a cloud computing strategy?
Correct Answer: D
QUESTION NO: 10
A segregation of duties control was found to be ineffective because it did not account for all applicable functions when evaluating access. Who is responsible for ensuring the control is designed to effectively address risk?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 11
Which of the following is the BEST metric to measure employee adherence to organizational security policies?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).