100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
CRISC CERTIFICATION EXAM ACTUAL EXAM QUESTIONS AND DETAILED CORRECT ANSWERS WIT RATIONALES | A+ GRADE STUDYGUIDE $22.99   Add to cart

Exam (elaborations)

CRISC CERTIFICATION EXAM ACTUAL EXAM QUESTIONS AND DETAILED CORRECT ANSWERS WIT RATIONALES | A+ GRADE STUDYGUIDE

 0 view  0 purchase
  • Course
  • CRISC CERTIFICATION
  • Institution
  • CRISC CERTIFICATION

CRISC CERTIFICATION EXAM ACTUAL EXAM QUESTIONS AND DETAILED CORRECT ANSWERS WIT RATIONALES | A+ GRADE STUDYGUIDE

Preview 4 out of 130  pages

  • November 4, 2024
  • 130
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
  • CRISC CERTIFICATION
  • CRISC CERTIFICATION
avatar-seller
TUTORWAC
CRISC CERTIFICATION EXAM 2024-2025
ACTUAL EXAM QUESTIONS AND
DETAILED CORRECT ANSWERS WIT
RATIONALES | A+ GRADE STUDYGUIDE

R1-1 Which of the following is MOST important to
determine when defining risk management strategies?
A. Risk assessment criteria
B. IT architecture complexity
C. An enterprise disaster recovery plan
D. Business objectives and operations Correct Answer D
is the Correct Answer.
Justification:
A. Information on the internal and external environment
must be collected to define a strategy and identify its
impact. Risk assessment criteria alone are not sufficient.
B. IT architecture complexity is more directly related to
assessing risk than defining strategies.
C. An enterprise disaster recovery plan is more directly
related to mitigating the risk.
D. While defining risk management strategies, the risk
practitioner needs to analyze the organization's
objectives and risk tolerance and define a risk
management framework based on this analysis. Some
organizations may accept known risk, while others may
invest in and apply mitigating controls to
reduce risk.

,R1-2 Which of the following is the MOST important
information to include in a risk management strategic
plan?
A. Risk management staffing requirements
B. The risk management mission statement
C. Risk mitigation investment plans
D. The current state and desired future state Correct
Answer D is the Correct Answer.
Justification:
A. Risk management staffing requirements are generally
driven by a robust understanding of the current and
desired future state.
B. The risk management mission statement is important
but is not an actionable part of a risk management
strategic plan.
C. Risk mitigation investment plans are generally driven by
a robust understanding of the current and desired
future state.
D. It is most important to paint a vision for the future and
then draw a road map from the starting point;
therefore, this requires that the current state and desired
future state be fully understood.

R1-3 Information that is no longer required to support the
main purpose of the business from an information security
perspective should be:
A. analyzed under the retention policy.
B. protected under the information classification policy.
C. analyzed under the backup policy.
D. protected under the business impact analysis. Correct
Answer A is the Correct Answer.

,Justification:
A. Information that is no longer required should be
analyzed under the retention policy to determine
whether the organization is required to maintain the data
for business, legal or regulatory reasons.
Keeping data that are no longer required unnecessarily
consumes resources; may be in breach of
legal and regulatory obligations regarding retention of
data; and, in the case of sensitive personal
information, can increase the risk of data compromise.
B. The information classification policy should specify
retention and destruction of information that is no longer
of value to the core business, as applicable.
C. The backup policy is generally based on recovery point
objectives. The information classification policy
should specify retention and destruction of backup media.
D. A business impact analysis can help determine that this
information does not support the main objective of the
business, but does not indicate the action to take.

R1-4 An enterprise has outsourced the majority of its IT
department to a third party whose servers are in a foreign
country. Which of the following is the MOST critical
security consideration?
A. A security breach notification may get delayed due to
the time difference.
B. Additional network intrusion detection sensors should
be installed, resulting in additional cost.
C. The enterprise could be unable to monitor compliance
with its internal security and privacy guidelines.

, D. Laws and regulations of the country of origin may not
be enforceable in the foreign country. Correct Answer D is
the Correct Answer.
Justification:
A. Security breach notification is not a problem. Time
difference does not play a role in a 24/7 environment.
Mobile devices (smartphones, tablets, etc.) are usually
available to communicate a notification.
B. The need for additional network intrusion sensors is a
manageable problem that requires additional funding,
but can be addressed.
C. Outsourcing does not remove the enterprise's
responsibility regarding internal requirements.
D. Laws and regulations of the country of origin may not
be enforceable in the foreign country.
Conversely, the laws and regulations of the foreign vendor
may also affect the enterprise. Potential
violation of local laws applicable to the enterprise or the
vendor may not be recognized or remedied due
to the lack of knowledge of local laws and/or inability to
enforce them.

R1-5 An enterprise recently developed a breakthrough
technology that could provide a significant competitive
edge.
Which of the following FIRST governs how this information
is to be protected from within the enterprise?
A. The data classification policy
B. The acceptable use policy
C. Encryption standards

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller TUTORWAC. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $22.99. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

75759 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$22.99
  • (0)
  Add to cart