
更新されたPDF(2023年最新)実際にあるISACA CRISC試験問題
検証済みのCRISC試験問題集PDF[2023年最新] 成功の秘訣はJPNTest
CRISC認定試験は、自分の組織でITリスクを管理し、情報システムコントロールを実装する責任を持つ専門家を対象として設計されています。これには、ITリスクマネージャー、IT監査人、ITセキュリティプロフェッショナル、ITコンサルタントが含まれます。また、これらの役割で働きたいという志望者にも適しています。CRISC認定は世界的に認められ、さまざまな産業の雇用主から高く評価されています。
質問 # 454
John is the project manager of the NHQ Project for his company. His project has 75 stakeholders, some of which are external to the organization. John needs to make certain that he communicates about risk in the most appropriate method for the external stakeholders. Which project management plan will be the best guide for John to communicate to the external stakeholders?
- A. Risk Response Plan
- B. Risk Management Plan
- C. Project Management Plan
- D. Communications Management Plan
正解:D
解説:
Section: Volume D
Explanation:
The Communications Management Plan will direct John on the information to be communicated, when to communicate, and how to communicate with external stakeholders.
The Communications Management Plan aims to define the communication necessities for the project and how the information will be circulated. The Communications Management Plan sets the communication structure for the project. This structure provides guidance for communication throughout the project's life and is updated as communication needs change. The Communication Managements Plan identifies and defines the roles of persons concerned with the project. It includes a matrix known as the communication matrix to map the communication requirements of the project.
Incorrect Answers:
A: The Risk Response Plan identifies how risks will be responded to.
C: The Project Management Plan is the parent of all subsidiary management plans and it is not the most accurate choice for this question D: The Risk Management Plan defines how risks will be identified, analyzed, responded to, and controlled throughout the project.
質問 # 455
While developing obscure risk scenarios, what are the requirements of the enterprise?
Each correct answer represents a part of the solution. Choose two.
- A. Be in a position that it can observe anything going wrong
- B. Explanation:
The enterprise must consider risk that has not yet occurred and should develop scenarios around unlikely, obscure or non-historical events. Such scenarios can be developed by considering two things: Visibility Recognition For the fulfillment of this task enterprise must: Be in a position that it can observe anything going wrong Have the capability to recognize an observed event as something wrong - C. Have sufficient number of analyst
- D. Have capability to cure the risk events
- E. Have capability to recognize an observed event as something wrong
正解:A、B、E
解説:
and A are incorrect. These are not the direct requirements for developing obscure risk scenarios, like curing risk events comes under process of risk management. Hence capability of curing risk event does not lay any impact on the process of development of risk scenarios.
質問 # 456
A control owner has completed a year-long project To strengthen existing controls. It is MOST important for the risk practitioner to:
- A. conduct and document a business impact analysis (BIA).
- B. update the risk register to reflect the correct level of residual risk.
- C. verify cost-benefit of the new controls being implemented.
- D. ensure risk monitoring for the project is initiated.
正解:B
質問 # 457
It is MOST important for a risk practitioner to have an awareness of an organization s processes in order to:
- A. establish risk guidelines.
- B. perform a business impact analysis.
- C. understand control design.
- D. identify potential sources of risk.
正解:D
質問 # 458
An organization is considering allowing users to access company data from their personal devices. Which of the following is the MOST important factor when assessing the risk?
- A. Volume of data
- B. Classification of the data
- C. Remote management capabilities
- D. Type of device
正解:B
質問 # 459
Which of the following is true for risk management frameworks, standards and practices?
Each correct answer represents a part of the solution. Choose three.
- A. They act as a guide to focus efforts of variant teams.
- B. They provide a systematic view of "things to be considered" that could harm clients or an enterprise.
- C. They assist in achieving business objectives quickly and easily.
- D. They result in increase in cost of training, operation and performance improvement.
正解:A、B、C
解説:
Section: Volume C
Explanation:
Frameworks, standards and practices are necessary as:
* They provide a systematic view of "things to be considered" that could harm clients or an enterprise.
* They act as a guide to focus efforts of variant teams.
* They save time and revenue, such as training costs, operational costs and performance improvement costs.
* They assist in achieving business objectives quickly and easily.
質問 # 460
The only output of qualitative risk analysis is risk register updates. When the project manager updates the risk register he will need to include several pieces of information including all of the following except for which one?
- A. Risk probability-impact matrix
- B. Watchlist of low-priority risks
- C. Risks grouped by categories
- D. Trends in qualitative risk analysis
正解:A
解説:
Section: Volume A
Explanation/Reference:
Explanation:
The risk matrix is not included as part of the risk register updates. There are seven things that can be updated in the risk register as a result of qualitative risk analysis: relating ranking of project risks, risks grouped by categories, causes of risks, list of near-term risks, risks requiring additional analysis, watchlist of low-priority risks, trends in qualitative risk analysis.
Incorrect Answers:
A: Trends in qualitative risk analysis are part of the risk register updates.
C: Risks grouped by categories are part of the risk register updates.
D: Watchlist of low-priority risks is part of the risk register updates.
質問 # 461
How residual risk can be determined?
- A. By determining remaining vulnerabilities after countermeasures are in place.
- B. By risk assessment
- C. By threat analysis
- D. By transferring all risks.
正解:B
解説:
Explanation/Reference:
Explanation:
All risks are determined by risk assessment, regardless whether risks are residual or not.
Incorrect Answers:
A: Determining remaining vulnerabilities after countermeasures are in place says nothing about threats, therefore risk cannot be determined.
B: Transferring all the risks in not relevant to determining residual risk. It is one of the method of risk management.
C: Risk cannot be determined by threat analysis alone, regardless whether it is residual or not.
質問 # 462
Numerous media reports indicate a recently discovered technical vulnerability is being actively exploited. Which of the following would be the BEST response to this scenario?
- A. Reassess the inherent risk of the target.
- B. Assess the vulnerability management process.
- C. Conduct a vulnerability assessment.
- D. Conduct a control serf-assessment.
正解:A
質問 # 463
Which of the following is the MOST important consideration for effectively maintaining a risk register?
- A. An IT owner is assigned for each risk scenario.
- B. Compensating controls are identified.
- C. The register is updated frequently.
- D. The register is shared with executive management.
正解:C
質問 # 464
Accountability for a particular risk is BEST represented in a:
- A. risk catalog
- B. RACI matrix.
- C. risk scenario
- D. risk register.
正解:B
質問 # 465
Which of the following would be considered a vulnerability?
- A. Delayed removal of employee access
- B. Corruption of files due to malware
- C. Server downtime due to a denial of service (DoS) attack
- D. Authorized administrative access to HR files
正解:A
質問 # 466
You work as a Project Manager for www.company.com Inc. You have to measure the probability, impact, and risk exposure. Then, you have to measure how the selected risk response can affect the probability and impact of the selected risk event. Which of the following tools will help you to accomplish the task?
- A. Decision tree analysis
- B. Project network diagrams
- C. Cause-and-effect diagrams
- D. Delphi technique
正解:A
解説:
Section: Volume B
Explanation:
Decision tree analysis is a risk analysis tool that can help the project manager in determining the best risk response. The tool can be used to measure probability, impact, and risk exposure and how the selected risk response can affect the probability and/or impact of the selected risk event. It helps to form a balanced image of the risks and opportunities connected with each possible course of action. This makes them mostly useful for choosing between different strategies, projects, or investment opportunities particularly when the resources are limited. A decision tree is a decision support tool that uses a tree-like graph or model of decisions and their possible consequences, including chance event outcomes, resource costs, and utility.
Incorrect Answers:
A: Project network diagrams help the project manager and stakeholders visualize the flow of the project work, but they are not used as a part of risk response planning.
B: The Delphi technique can be used in risk identification, but generally is not used in risk response planning.
The Delphi technique uses rounds of anonymous surveys to identify risks.
D: Cause-and-effect diagrams are useful for identifying root causes and risk identification, but they are not the most effective ones for risk response planning.
質問 # 467
A risk practitioner learns that the organization s industry is experiencing a trend of rising security incidents. Which of the following is the BEST course of action?
- A. Evaluate the relevance of the evolving threats.
- B. Research industry published studies.
- C. Review past internal audit results.
- D. Respond to organizational security threats.
正解:A
質問 # 468
Which of the following aspects of an IT risk and control self-assessment would be MOST important to include in a report to senior management?
- A. Changes in control design
- B. Changes in control ownership
- C. An increase in residual risk
- D. A decrease in the number of key controls
正解:C
質問 # 469
What are the three PRIMARY steps to be taken to initialize the project?
Each correct answer represents a complete solution. (Choose three.)
- A. Conduct a feasibility study
- B. Define requirements
- C. Acquire software
- D. Plan risk management
正解:A、B、C
解説:
Section: Volume B
Explanation:
Projects are initiated by sponsors who gather the information required to gain approval for the project to be created. Information often compiled into the terms of a project charter includes the objective of the project, business case and problem statement, stakeholders in the system to be produced, and project manager and sponsor.
Following are the steps to initiate the project:
* Conduct a feasibility study: Feasibility study starts once initial approval has been given to move forward with a project, and includes an analysis to clearly define the need and to identify alternatives for addressing the need. A feasibility study involves:
- Analyzing the benefits and solutions for the identified problem area
- Development of a business case that states the strategic benefits of implementing the system either in productivity gains or in future cost avoidance and identifies and quantifies the cost savings of the new system.
- Estimation of a payback schedule for the cost incurred in implementing the system or shows the projected return on investment (ROI)
* Define requirements: Requirements include:
- Business requirements containing descriptions of what a system should do
- Functional requirements and use case models describing how users will interact with a system
- Technical requirements and design specifications and coding specifications describing how the system will interact, conditions under which the system will operate and the information criteria the system should meet.
* Acquire software: Acquiring software involves building new or modifying existing hardware or software after final approval by the stakeholder, which is not a phase in the standard SDLC process. If a decision was reached to acquire rather than develop software, this task should occur after defining requirements.
Incorrect Answers:
D: Risk management is planned latter in project development process, and not during initialization.
質問 # 470
Which of the following activities should be performed FIRST when establishing IT risk management processes?
- A. Identify the risk appetite of the organization.
- B. Assess the goals and culture of the organization.
- C. Collect data of past incidents and lessons learned.
- D. Conduct a high-level risk assessment based on the nature of business.
正解:B
質問 # 471
During a risk assessment, a risk practitioner learns that an IT risk factor is adequately mitigated by compensating controls in an associated business process. Which of the following would enable the MOST effective management of the residual risk?
- A. Report the use of compensating controls to senior management.
- B. Schedule periodic reviews of the compensating controls' effectiveness.
- C. Request that ownership of the compensating controls is reassigned to IT
- D. Recommend additional IT controls to further reduce residual risk.
正解:B
質問 # 472
......
試験を受けるためには、候補者はリスクマネジメントまたは情報システムコントロールの分野で少なくとも3年の経験を持ち、これらの分野の原則と実践の固体な理解を持っている必要があります。さらに、候補者は特定の教育要件を満たし、ISACAの職業倫理規定に従うことに同意する必要があります。
ベストを体験せよ!CRISC試験問題トレーニングを提供しています:https://www.jpntest.com/shiken/CRISC-mondaishu
練習サンプルと問題集と秘訣には2023年最新のCRISC有効なテスト問題集:https://drive.google.com/open?id=1js91OMgWF2szAd_Go_S4HroWPAqXuLKm