Free CRISC Certification Questions and Answers — Questions and Answers
Question 1: When defining risk management methods, which of the following should be determined as being MOST important?
- IT architecture complexity
- Business objectives and operations (Correct answer)
- Risk assessment criteria
- Enterprise disaster recovery plan
Correct answer: Business objectives and operations
Effective risk management must always align with and support the organization's strategic business objectives and operational goals. Understanding these elements ensures that risk management efforts prioritize risks that could most significantly impact the business's success and continuity. Without this alignment, risk management can become a disconnected exercise.
Question 2: The BIGGEST danger associated with not having a strategy is:
- improper oversight of IT investment (Correct answer)
- increase in the number of licensing violation
- unresolved current and past problems
- increase in the number of obsolete systems
Correct answer: improper oversight of IT investment
Without a clear strategy, IT investments can become ad-hoc and misaligned with business needs, leading to wasted resources and a lack of accountability. A strategy provides a framework for prioritizing, allocating, and monitoring IT spending to ensure it delivers value and supports organizational goals. Improper oversight of IT investment is a significant danger that arises from this lack of direction.
Question 3: Where would the data ethics function MOST likely reside in an enterprise, based on the three lines of defense model?
- The third line of defense
- The first line of defense
- The board of directors
- The second line of defense (Correct answer)
Correct answer: The second line of defense
The second line of defense is responsible for overseeing risk management and compliance, including establishing policies and monitoring their adherence. Data ethics, which involves setting standards for responsible data use and ensuring compliance, fits well within this oversight function. The first line executes, and the third provides independent assurance.
Question 4: Which of the following factors should the cost-benefit analysis of a two-factor authentication system contain the MOST?
- The frequency of incidents
- The annual loss expectancy of security incidents
- The total cost of ownership (Correct answer)
- The approved budget of the project
Correct answer: The total cost of ownership
A comprehensive cost-benefit analysis for a security system like two-factor authentication must consider the total cost of ownership (TCO). TCO includes not only initial purchase and implementation costs but also ongoing expenses like maintenance, support, training, and potential integration challenges. This holistic view provides a more accurate financial picture and ensures all costs are accounted for.
Question 5: Which of the following BEST guarantees that identified information system vulnerabilities are appropriately mitigated?
- Incorporating the findings into the annual report to shareholders.
- Presenting root cause analysis to the management of the enterprise
- Assigning action plans with deadlines to responsible personnel. (Correct answer)
- Implementing software to input the action points.
Correct answer: Assigning action plans with deadlines to responsible personnel.
To ensure mitigation, vulnerabilities need clear accountability and a structured approach. Assigning specific action plans with deadlines to responsible personnel creates ownership and a timeline for resolution. This structured approach facilitates tracking, follow-up, and ultimately, the effective closure of identified vulnerabilities, providing the best guarantee of mitigation.
Question 6: What is the MOST crucial protection that needs to be in place to prevent abuse of the company's social media account?
- Two-factor authentication (Correct answer)
- Awareness training
- Strong passwords
- Social media account monitoring
Correct answer: Two-factor authentication
Two-factor authentication (2FA) significantly enhances security by requiring a second verification method beyond just a password. This makes it much harder for unauthorized individuals to gain access to social media accounts, even if they compromise a password, thereby preventing abuse. It's a strong preventative control against unauthorized access and account takeover.
Question 7: After the likelihood of a loss event has been estimated, which of the following criteria should be evaluated?
- Compensating controls
- Residual risk
- Risk tolerance
- Magnitude of impact (Correct answer)
Correct answer: Magnitude of impact
Risk is typically calculated as the product of likelihood and impact. Once the likelihood (probability) of a loss event has been estimated, the next logical step in a risk assessment is to determine the potential magnitude of its impact. This allows for a complete understanding of the risk's severity and helps prioritize mitigation efforts.
When defining risk management methods, which of the following should be determined as being MOST important?