CRISC Exam Questions

Free crisc practice questions and answers to pass free crisc exam questions. For crisc certification practice questions free you must go through real exam. For that we provide Free crisc Practice Exam real test. We discuss in these Free Examination for Certified in Risk and Information Systems Control (CRISC) Test Questions from different topics like crisc questions, crisc certification intensive review .

crisc prep test

In this test you have to answer crisc practice test free. To get pass crisc exam practice test you must answers correct. So Enjoy these crisc certification exam review to get enough knowledge for crisc practice test attempt. You will get mock test answers after click submit button at bottom. If any question wrong just click on go back button to correct it. Easy Na!




Disclaimer:-
Certified in Risk and Information Systems Control® (CRISC®) trademarks and/or service marks of Information Systems Audit and Control Association® (ISACA®). ISACA® does not endorse and is not affiliated in any way with Test-Questions.com or its products and services.

Practice CRISC Exam

crisc questions and answers pdf crisc sample questions


Q:1-Which of the following is the MOST important reason to maintain key risk indicators (KRIs)?
Mark one answer:

In order to avoid risk
Complex metrics require fine-tuning
Risk reports need to be timely
Threats and vulnerabilities change over time



Q:2-Your project team has completed the quantitative risk analysis for your project work. Based on their findings, they need to update the risk register with several pieces of information. Which one of the following components is likely to be updated in the risk register based on their analysis?
Mark one answer:

Listing of risk responses
Risk ranking matrix
Listing of prioritized risks
Qualitative analysis outcomes


Q:3-You work as a project manager for BlueWell Inc. Management has asked you to work with the key project stakeholder to analyze the risk events you have identified in the project. They would like you to analyze the project risks with a goal of improving the project's performance as a whole. What approach can you use to achieve this goal of improving the project's performance through risk analysis with your project stakeholders?
Mark one answer:

Involve subject matter experts in the risk analysis activities
Involve the stakeholders for risk identification only in the phases where the project directly affects them
Use qualitative risk analysis to quickly assess the probability and impact of risk events
Focus on the high-priority risks through qualitative risk analysis


Q:4-Which of the following is NOT true for risk management capability maturity level 1?
Mark one answer:

There is an understanding that risk is important and needs to be managed, but it is viewed as a technical issue and the business primarily considers the downside of IT risk
Decisions involving risk lack credible information
Risk appetite and tolerance are applied only during episodic risk assessments
Risk management skills exist on an ad hoc basis, but are not actively developed


Q:5-You are the project manager of a large construction project. This project will last for 18 months and will cost $750,000 to complete. You are working with your project team, experts, and stakeholders to identify risks within the project before the project work begins. Management wants to know why you have scheduled so many risk identification meetings throughout the project rather than just initially during the project planning. What is the best reason for the duplicate risk identification sessions?
Mark one answer:

The iterative meetings allow all stakeholders to participate in the risk identification processes throughout the project phases.
The iterative meetings allow the project manager to discuss the risk events which have passed the project and which did not happen.
The iterative meetings allow the project manager and the risk identification participants to identify newly discovered risk events throughout the project.
The iterative meetings allow the project manager to communicate pending risks events during project execution.


test-questions.com

Q:6-Harry is the project manager of HDW project. He has identified a risk that could injure project team members. He does not want to accept any risk where someone could become injured on this project so he hires a professional vendor to complete this portion of the project work. What type of risk response is Harry implementing?
Mark one answer:

Transference
Mitigation
Acceptance
Avoidance


Q:7-Which of the following is the MOST effective method for indicating that the risk level is approaching a high or unacceptable level of risk?
Mark one answer:

Risk register
Cause and effect diagram
Risk indicator
Return on investment


Q:8-Which of the following events refer to loss of integrity?
Mark one answer:

A virus infects a file
Someone makes unauthorized changes to a Web site
An e-mail message is modified in transit
All of the above


Q:9-Your project spans the entire organization. You would like to assess the risk of your project but worried about that some of the managers involved in the project could affect the outcome of any risk identification meeting. Your consideration is based on the fact that some employees would not want to publicly identify risk events that could declare their supervision as poor. You would like a method that would allow participants to anonymously identify risk events. What risk identification method could you use?
Mark one answer:

Delphi technique
Root cause analysis
Isolated pilot groups
SWOT analysis


Q:10-Which of the following BEST ensures that a firewall is configured in compliance with an enterprise's security policy?
Mark one answer:

Interview the firewall administrator.
Review the actual procedures.
Review the device's log file for recent attacks.
Review the parameter settings.



Free        Premium    


crisc questions crisc sample exam questions