[2025年03月20日] 検証済みのCRISC問題集と1519格別な問題
CRISC問題集合格保証付きの合格できるCRISC試験2025年更新
質問 # 638
You are the project manager of GHT project. You have identified a risk event on your project that could save $100,000 in project costs if it occurs. Which of the following statements BEST describes this risk event?
- A. This risk event should be mitigated to take advantage of the savings.
- B. This risk event is an opportunity to the project and should be exploited.
- C. This risk event should be avoided to take full advantage of the potential savings.
- D. This is a risk event that should be accepted because the rewards outweigh the threat to the project.
正解:B
解説:
Explanation/Reference:
Explanation:
This risk event has the potential to save money on project costs, so it is an opportunity, and the appropriate strategy to use in this case is the exploit strategy. The exploit response is one of the strategies to negate risks or threats appear in a project. This strategy may be selected for risks with positive impacts where the organization wishes to ensure that the opportunity is realized. Exploiting a risk event provides opportunities for positive impact on a project. Assigning more talented resources to the project to reduce the time to completion is an example of exploit response.
Incorrect Answers:
A, C: Mitigation and avoidance risk response is used in case of negative risk events, and not in positive risk events. Here in this scenario, as it is stated that the event could save $100,000, hence it is a positive risk event. Therefore should not be mitigated or avoided.
B: To accept risk means that no action is taken relative to a particular risk; loss is accepted if it occurs. But as this risk event bring an opportunity, it should me exploited and not accepted.
質問 # 639
You are the project manager of HWD project. It requires installation of some electrical machines. You and the project team decided to hire an electrician as electrical work can be too dangerous to perform. What type of risk response are you following?
- A. Transference
- B. Mitigation
- C. Avoidance
- D. Acceptance
正解:A
解説:
Section: Volume B
Explanation:
As the risk is transferred to the third party (electrician), hence this type of risk response is transference.
Incorrect Answers:
A: Risk avoidance means to evade risk altogether, eliminate the cause of the risk event, or change the project plan to protect the project objectives from the risk event. Risk avoidance is applied when the level of risk, even after the applying controls, would be greater than the risk tolerance level of the enterprise.
C: Risk mitigation attempts to reduce the probability of a risk event and its impacts to an acceptable level. Risk mitigation can utilize various forms of control carefully integrated together.
D: Risk acceptance means that no action is taken relative to a particular risk; loss is accepted if it occurs.
質問 # 640
Which of the following activities is a responsibility of the second line of defense?
- A. Developing controls to manage risk scenarios
- B. Establishing organizational risk appetite
- C. Challenging risk decision making
- D. Implementing risk response plans
正解:C
解説:
The second line of defense is responsible for challenging the risk decision making of the first line of defense, which is the business process owners and managers. The second line of defense also provides oversight, guidance, and support to the first line of defense in implementing and maintaining effective risk management practices. The second line of defense includes functions such as risk management, compliance, quality assurance, and internal audit. References = Risk and Information Systems Control Study Manual, Chapter 1:
IT Risk Identification, Section 1.2: IT Risk Management Roles and Responsibilities, Page 14.
質問 # 641
Which of the following BEST enables the risk profile to serve as an effective resource to support business objectives?
- A. Updating the risk profile with risk assessment results
- B. Engaging external risk professionals to periodically review the risk
- C. Prioritizing global standards over local requirements in the risk profile
- D. Assigning quantitative values to qualitative metrics in the risk register
正解:A
解説:
A risk profile is a summary of the key risks that affect an organization, a business unit, a process, or a project.
A risk profile can help stakeholders understand the current and potential exposure to various sources of uncertainty, and prioritize the risk response accordingly. A risk profile should be aligned with the business objectives, which are the desired outcomes or results that the organization or the business unit wants to achieve. Updating the risk profile with risk assessment results best enables the risk profile to serve as an effective resource to support business objectives, because it ensures that the risk profile reflects the most accurate and up-to-date information about the risks and their impacts. Risk assessment is the process of analyzing and evaluating the likelihood and consequences of the identified risks, and comparing them with the risk criteria and appetite. Risk assessment results can provide valuable insights into the risk level, trend, and exposure, and help identify the most critical and relevant risks that need attention and action. Updating the risk profile with risk assessment results can help align the risk profile with the business objectives, by showing how the risks may affect the achievement of the objectives, and how the risk response can support or enhance the objectives. Updating the risk profile with risk assessment results can also help communicate and justify the risk profile to the business stakeholders, and obtain their feedback and approval. References = Risk Management Essentials: How to Develop a Risk Profile (TRN2-J07), Risk Assessment and Analysis Methods:
Qualitative and Quantitative - ISACA, Using Risk Assessment to Support Decision Making - ISACA.
質問 # 642
A risk assessment has identified that departments have installed their own WiFi access points on the enterprise network. Which of the following would be MOST important to include in a report to senior management?
- A. The WiFi access point configuration
- B. The network security policy
- C. Potential business impact
- D. Planned remediation actions
正解:C
解説:
* A risk assessment is a process of identifying, analyzing, and evaluating the risks that may affect the enterprise's objectives and operations. It involves determining the likelihood and impact of various risk scenarios, and prioritizing them based on their significance and urgency.
* A WiFi access point is a device that allows wireless devices to connect to a wired network using radio signals. It can provide convenience and flexibility for users, but it can also introduce security risks, such as unauthorized access, data leakage, malware infection, or denial of service attacks.
* If departments have installed their own WiFi access points on the enterprise network, without proper authorization, configuration, or monitoring, it means that they have bypassed the network security policy and controls, and created potential vulnerabilities and exposures for the enterprise.
* The most important information to include in a report to senior management is the potential business impact of this risk, which is the estimated loss or damage that the enterprise may suffer if the risk materializes. The potential business impact can be expressed in terms of financial, operational, reputational, or legal consequences, and it can help senior management to understand the severity and urgency of the risk, and to decide on the appropriate risk response and allocation of resources.
* The other options are not the most important information to include in a report to senior management, because they do not convey the magnitude and significance of the risk, and they may not be relevant or actionable for senior management.
* The network security policy is the set of rules and guidelines that define the security objectives, requirements, and responsibilities for the enterprise network. It is important to have a clear and comprehensive network security policy, and to ensure that it is communicated, enforced, and monitored across the enterprise, but it is not the most important information to include in a report to senior management, because it does not indicate the actual or potential impact of the risk, and it may not reflect the current or desired state of the network security.
* The WiFi access point configuration is the set of parameters and settings that define the functionality, performance, and security of the WiFi access point. It is important to have a secure and consistent WiFi access point configuration, and to follow the best practices and standards for wireless network security, but it is not the most important information to include in a report to senior management, because it does not indicate the actual or potential impact of the risk, and it may not be relevant or understandable for senior management.
* The planned remediation actions are the steps and measures that are intended to mitigate, transfer, avoid, or accept the risk, and to restore the normal operation and security of the enterprise network. It is important to have a feasible and effective plan for remediation actions, and to implement and monitor them in a timely and efficient manner, but it is not the most important information to include in a report to senior management, because it does not indicate the actual or potential impact of the risk, and it may not be feasible or appropriate without senior management's approval or support. References =
* ISACA, CRISC Review Manual, 7th Edition, 2022, pp. 19-20, 23-24, 27-28, 31-32, 40-41, 47-48
* ISACA, CRISC Review Questions, Answers & Explanations Database, 2022, QID 146
質問 # 643
A business impact analysis (BIA) enables an organization to determine appropriate IT risk mitigation actions by:
- A. assigning accountability for IT risk to business functions.
- B. validating whether critical IT risk has been addressed.
- C. defining the requirements for an IT risk-aware culture
- D. identifying IT assets that support key business processes.
正解:D
質問 # 644
Which of the following is the PRIMARY reason to have the risk management process reviewed by a third party?
- A. Ensure the risk profile is defined and communicated.
- B. Validate the threat management process.
- C. Obtain an objective view of process gaps and systemic errors.
- D. Obtain objective assessment of the control environment.
正解:C
質問 # 645
You are the risk official in Techmart Inc. You are asked to perform risk assessment on the impact of losing a server. For this assessment you need to calculate monetary value of the server. On which of the following bases do you calculate monetary value?
- A. Cost of software stored
- B. Annual loss expectancy
- C. Original cost to acquire
- D. Cost to obtain replacement
正解:D
解説:
Explanation/Reference:
Explanation:
The monetary value of the server should be based on the cost of its replacement. However, the financial impact to the enterprise may be much broader, based on the function that the server performs for the business and the value it brings to the enterprise.
Incorrect Answers:
B, C, D: Cost of software is not been counted because it can be restored from the back-up media. On the other hand' Ale for all risk related to the server does not represent the server's value. Lastly, the original cost may be significantly different from the current cost and, therefore, not relevant to this.
質問 # 646
The following is the snapshot of a recently approved IT risk register maintained by an organization's information security department.
After implementing countermeasures listed in ''Risk Response Descriptions'' for each of the Risk IDs, which of the following component of the register MUST change?
- A. Risk Impact Rating
- B. Risk Exposure
- C. Risk Likelihood Rating
- D. Risk Owner
正解:B
解説:
Risk exposure is the product of risk likelihood and risk impact ratings. It represents the potential loss or damage that may result from a risk event. After implementing countermeasures, the risk likelihood and/or impact ratings may change, depending on the effectiveness of the countermeasures. Therefore, the risk exposure must also change to reflect the updated risk ratings. The other components of the register, such as risk owner, risk impact rating, and risk likelihood rating, may or may not change depending on the nature and scope of the countermeasures. References = Risk and Information Systems Control Study Manual, Chapter 2:
IT Risk Assessment, Section 2.4: IT Risk Response, page 87.
質問 # 647
An enterprise has identified risk events in a project. While responding to these identified risk events, which among the following stakeholders is MOST important for reviewing risk response options to an IT risk.
- A. Incident response team members
- B. Internal auditors
- C. Information security managers
- D. Business managers
正解:D
解説:
Explanation/Reference:
Explanation:
Business managers are accountable for managing the associated risk and will determine what actions to take based on the information provided by others.
Incorrect Answers:
A: Information security managers may best understand the technical tactical situation, but business managers are accountable for managing the associated risk and will determine what actions to take based on the information provided by others, which includes collaboration with, and support from, lT security managers.
C: The incident response team must ensure open communication to management and stakeholders to ensure that business managers understand the associated risk and are provided enough information to make informed risk-based decisions. They are not responsible for reviewing risk response options.
質問 # 648
You are the project manager of your enterprise. You have introduced an intrusion detection system for the control. You have identified a warning of violation of security policies of your enterprise. What type of control is an intrusion detection system (IDS)?
- A. Corrective
- B. Recovery
- C. Preventative
- D. Detective
正解:D
解説:
Explanation/Reference:
Explanation:
An intrusion detection system (IDS) is a device or software application that monitors network and/or system activities for malicious activities or policy violations and produces reports to a Management Station.
Some systems may attempt to stop an intrusion attempt but this is neither required nor expected of a monitoring system. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, and reporting attempts. In addition, organizations use IDPS for other purposes, such as identifying problems with security policies, documenting existing threats, and deterring individuals from violating security policies.
As IDS detects and gives warning when the violation of security policies of the enterprise occurs, it is a detective control.
Incorrect Answers:
B: These controls make effort to reduce the impact of a threat from problems discovered by detective controls. As IDS only detects but not reduce the impact, hence it is not a corrective control.
C: As IDS only detects the problem when it occurs and not prior of its occurrence, it is not preventive control.
D: These controls make efforts to overcome the impact of the incident on the business, hence IDS is not a recovery control.
質問 # 649
You are the project manager for Bluewell Inc. You are studying the documentation of project plan. The documentation states that there are twenty-five stakeholders with the project. What will be the number of communication channel s for the project?
- A. 0
- B. 1
- C. 2
- D. 3
正解:B
解説:
Section: Volume C
Explanation:
Communication channels are paths of communication with stakeholders in a project. The number of communication channels shows the complexity of a project's communication and can be derived through the formula shown below:
Total Number of Communication Channels = n (n-1)/2
where n is the number of stakeholders.
Hence, a project having five stakeholders will have ten communication channels. Putting the value of the number of stakeholders in the formula will provide the number of communication channels.
Hence,
Number of communication channel = (n (n-1)) / 2
= (25 (25-1)) / 2
= (25 x 24) / 2
= 600 / 2
= 300
Incorrect Answers:
A, B, C: These are not valid number of communication channels for the given scenario.
質問 # 650
A risk practitioner has observed that risk owners have approved a high number of exceptions to the information security policy. Which of the following should be the risk practitioner's GREATEST concern?
- A. Security policies are being reviewed infrequently.
- B. Controls are not operating efficiently.
- C. Aggregate risk is approaching the tolerance threshold
- D. Vulnerabilities are not being mitigated
正解:C
解説:
An exception to the information security policy is a permission to continue operating a system, service, or product that cannot comply with the established information security standards and requirements1. A risk owner is a person or entity that has the authority and accountability for a risk and its management2. A risk practitioner is a person or entity that has the knowledge and skills to perform risk management activities3. A high number of exceptions to the information security policy indicates that there are many systems, services, or products that do not meet the expected level of security and pose potential risks to the organization. The risk practitioner's greatest concern should be that the aggregate risk, which is the total amount of risk that the organization faces from all sources, is approaching the tolerance threshold, which is the limit beyond which the organization does not want to tolerate the risk4. If the aggregate risk is approaching the tolerance threshold, it means that the organization is exposed to a high level of risk that may exceed its risk appetite, which is the amount of risk that the organization is willing to accept to achieve its objectives5. This may result in negative consequences for the organization, such as breaches, losses, damages, or reputational harm.
Therefore, the risk practitioner should monitor and report the aggregate risk level and the tolerance threshold, and advise the risk owners and the management on the appropriate risk responses and actions to reduce the aggregate risk to an acceptable level. Security policies are being reviewed infrequently, controls are not operating efficiently, and vulnerabilities are not being mitigated are not the risk practitioner's greatest concern, as they are not directly related to the aggregate risk level and the tolerance threshold. Security policies are being reviewed infrequently is a condition that indicates that the organization's security policies are not updated or revised regularly to reflect the changes and updates in the security environment and the security requirements6. This may affect the relevance and effectiveness of the security policies, but it does not necessarily increase the aggregate risk level or the tolerance threshold. Controls are not operating efficiently is a condition that indicates that the organization's controls, which are the measures or actions taken to manage or mitigate the risks, are not performing well or optimally7. This may affect the quality and performance of the controls, but it does not necessarily increase the aggregate risk level or the tolerance threshold. Vulnerabilities are not being mitigated is a condition that indicates that the organization's vulnerabilities, which are the weaknesses or gaps that may be exploited by the threats, are not being addressed or reduced8. This may increase the likelihood or impact of the risks, but it does not necessarily increase the aggregate risk level or the tolerance threshold. References = 1: IT/Information Security Exception Request Process2: [Risk Ownership - Risk Management] 3: [Risk Practitioner - ISACA] 4: Risk Threshold: Definition, Meaning & Example - PM Study Circle5: Risk Appetite vs Risk Tolerance vs Risk Threshold - projectcubicle6: [Security Policy Review and Update - SANS Institute] 7: [Control Effectiveness and Efficiency - ISACA] 8: [Vulnerability Management - ISACA] : [Risk and Information Systems Control Study Manual, Chapter 1: IT Risk Identification, Section 1.1: IT Risk Concepts, pp. 17-19.] : [Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.1: Risk Identification, pp. 57-59.] :
[Risk and Information Systems Control Study Manual, Chapter 4: Risk and Control Monitoring and Reporting, Section 4.2: Risk Monitoring, pp. 189-191.] : [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section 5.1: Control Design, pp. 233-235.] : [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section 5.2: Control Implementation, pp. 243-245.] : [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section 5.3: Control Monitoring and Maintenance, pp. 251-253.]
質問 # 651
When is the BEST to identify risk associated with major project to determine a mitigation plan?
- A. Project execution phase
- B. Project closing phase
- C. Project planning phase
- D. Project initiation phase
正解:D
解説:
The best time to identify the risk associated with a major project to determine a mitigation plan is the project initiation phase. The project initiation phase is the first phase of the project management process, where the project is defined, authorized, and planned. The project initiation phase includes the activities of developing the project charter, identifying the stakeholders, and defining the scope and objectives of the project. The project initiation phase is the best time to identify the risk associated with the project, as it provides the opportunity to understand the project context, requirements, and expectations, and to establish the risk management framework, process, and plan. By identifying the risk early in the project, the mitigation plan can be integrated with the project plan, and the resources, budget, and schedule can be allocated accordingly. The other options are not as optimal as the project initiation phase, as they are related to the execution, closing, or planning of the project, not the definition or authorization of the project. References = Risk and Information Systems Control Study Manual, Chapter 1: IT Risk Identification, Section 1.1: IT Risk Management Process, page 15.
質問 # 652
Which of the following should be of MOST concern to a risk practitioner reviewing an organization risk register after the completion of a series of risk assessments?
- A. Many risk scenarios are owned by the same senior manager.
- B. Risk associated with many assets is only expressed in qualitative terms.
- C. Several risk action plans have missed target completion dates.
- D. Senior management has accepted more risk than usual.
正解:C
質問 # 653
Which of the following risk register updates is MOST important for senior management to review?
- A. Avoiding a risk that was previously accepted
- B. Retiring a risk scenario no longer used
- C. Extending the date of a future action plan by two months
- D. Changing a risk owner
正解:C
質問 # 654
You are the project manager of a SGT project. You have been actively communicating and working with the project stakeholders. One of the outputs of the "manage stakeholder expectations" process can actually create new risk events for your project. Which output of the manage stakeholder expectations process can create risks?
- A. is incorrect. The project management plan updates do not create new risks.
- B. Project management plan updates
- C. Explanation:
The manage stakeholder expectations process can create change requests for the project, which
can cause new risk events to enter into the project.
Change requests are requests to expand or reduce the project scope, modify policies, processes,
plans, or procedures, modify costs or budgets or revise schedules. These requests for a change
can be direct or indirect, externally or internally initiated, and legally or contractually imposed or
optional. A Project Manager needs to ensure that only formally documented requested changes
are processed and
only approved change requests are implemented. - D. Change requests
- E. Project document updates
- F. is incorrect. The project document updates do not create new risks.
- G. An organizational process asset updates
正解:D
解説:
is incorrect. The organizational process assets updates do not create new risks.
質問 # 655
Which of the following provides the MOST useful information to trace the impact of aggregated risk across an organization's technical environment?
- A. Organizational risk appetite statement
- B. Business case documentation
- C. Organizational hierarchy
- D. Enterprise architecture (EA) documentation
正解:D
解説:
Enterprise architecture (EA) documentation provides the most useful information to trace the impact of aggregated risk across the organization's technical environment, because it describes the structure and behavior of the organization's IT systems, applications, infrastructure, and processes, and how they support and enable the organization's strategy and objectives. EA documentation also defines the principles, standards, and guidelines that govern the design and implementation of the IT solutions and services. Aggregated risk is the total or combined level of risk that the organization faces from multiple or interrelated sources or scenarios. Aggregated risk may have a greater impact than the sum of the individual risks, due to the synergistic or compounding effects of the risks. The technical environment is the set of IT components and capabilities that support the organization's business functions and processes. Tracing the impact of aggregated risk across the technical environment is a process of identifying and assessing the potential or actual consequences of the aggregated risk on the performance, functionality, or security of the IT systems, applications, infrastructure, or processes. EA documentation provides the most useful information, as it helps to understand and analyze the interdependencies and relationships of the IT components and capabilities, and to evaluate the effect of the aggregated risk on the alignment and integration of IT with the organization's strategy and objectives. Business case documentation, organizational risk appetite statement, and organizational hierarchy are all possible sources of information to trace the impact of aggregated risk, but they are not the most useful information, as they do not provide a comprehensive and detailed view of the technical environment and its architecture. References = Risk and Information Systems Control Study Manual, Chapter
5, Section 5.2.1, page 183
質問 # 656
......
最新100%合格率保証付きの素晴らしいCRISC試験問題PDF:https://www.jpntest.com/shiken/CRISC-mondaishu
CRISC試験問題集を試そう!ベストCRISC試験問題:https://drive.google.com/open?id=1IIP029X_TNxO6kL5eVXCQievb4xtxx0B