ISACA CRISCリアル試験問題テストエンジン問題集トレーニングには1426問あります [Q735-Q755]

Share

ISACA CRISCリアル試験問題テストエンジン問題集トレーニングには1426問あります

CRISC実際の問題解答PDFには100%カバー率リアル試験問題

質問 # 735
There are four inputs to the Monitoring and Controlling Project Risks process. Which one of the following will NOT help you, the project manager, to prepare for risk monitoring and controlling?

  • A. Risk register
  • B. Project management plan
  • C. Work Performance Information
  • D. Change requests

正解:D

解説:
Explanation/Reference:
Explanation:
Change requests are not one of the four inputs to the Risk Monitoring and Controlling Process. The four inputs are the risk register, the project management plan, work performance information, and performance reports.
Incorrect Answers:
A, B, C: These are the valid inputs to the Risk Monitoring and Controlling Process.


質問 # 736
An organization has been notified that a dis grunted, terminated IT administrator has tried to break into the corporate network. Which of the following discoveries should be of GREATEST concern to the organization?

  • A. An increase in support request has been observed
  • B. Authentication logs have been disabled
  • C. An external vulnerability scan has been detected
  • D. A brute force attack has been detected

正解:B

解説:
Section: Volume D
Explanation


質問 # 737
When reviewing a risk response strategy, senior management's PRIMARY focus should be placed on the:

  • A. cost-benefit analysis.
  • B. key performance indicators (KPIs).
  • C. alignment with risk appetite.
  • D. investment portfolio.

正解:C

解説:
According to the What To Look For When Assessing Your Organization's Security Risk Posture article, risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives. Risk appetite should be aligned with the organization's strategy, goals, and values, and should reflect the organization's risk culture and capabilities. When reviewing a risk response strategy, senior management's primary focus should be placed on the alignment with risk appetite, as this indicates how well the risk response strategy supports the organization's objectives and expectations, and how consistent it is with the organization's risk tolerance and risk profile. By ensuring the alignment with risk appetite, senior management can evaluate the effectiveness and efficiency of the risk response strategy, and determine if any adjustments or improvements are needed. References = What To Look For When Assessing Your Organization's Security Risk Posture


質問 # 738
Which of the following is the ULTIMATE objective of utilizing key control indicators (KCIs) in the risk management process?

  • A. To provide benchmarks for assessing control design effectiveness against industry peers
  • B. To provide early warning signs of a potential change in risk level
  • C. To provide a basis for determining the criticality of risk mitigation controls
  • D. To provide insight into the effectiveness of the internal control environment

正解:B

解説:
The ultimate objective of utilizing key control indicators (KCIs) in the risk management process is to provide early warning signs of a potential change in risk level, as they indicate the performance and adequacy of the controls, and alert the stakeholders to any control gaps or deficiencies that may affect the risk exposure and impact. The other options are not the ultimate objectives, as they are more related to the insight, basis, or benchmark of the risk management process, respectively, rather than the early warning sign of the risk management process. References = CRISC Review Manual, 7th Edition, page 110.


質問 # 739
It is MOST important to the effectiveness of an IT risk management function that the associated processes are:

  • A. reviewed and approved by senior management.
  • B. updated and monitored on a continuous basis.
  • C. aligned to an industry-accepted framework.
  • D. periodically assessed against regulatory requirements.

正解:B

解説:
The effectiveness of an IT risk management function depends on how well it can identify, analyze, evaluate, and treat the IT-related risks that may affect the organization's objectives and performance. To achieve this, the IT risk management function needs to have processes that are updated and monitored on a continuous basis, so that they can capture the changes in the IT environment, the business context, the risk appetite and tolerance, and the regulatory requirements. Updating and monitoring the IT risk management processes also helps to ensure that they are consistent, reliable, and efficient, and that they provide timely and accurate information for decision making and reporting12. Aligning the IT risk management processes to an industry-accepted framework is important, but not the most important factor for the effectiveness of the function. A framework provides a common language, structure, and methodology for IT risk management, but it does not guarantee that the processes are updated and monitored on a continuous basis. A framework also needs to be customized and adapted to the specific needs and context of the organization3. Reviewing and approving the IT risk management processes by senior management is important, but not the most important factor for the effectiveness of the function. Senior management support and endorsement are essential for establishing the tone and culture of IT risk management, as well as for allocating the necessary resources and authority for the function. However, senior management review and approval alone do not ensure that the processes are updated and monitored on a continuous basis. Senior management also need to oversee and evaluate the performance and outcomes of the IT risk management function4. Periodically assessing the IT risk management processes against regulatory requirements is important, but not the most important factor for the effectiveness of the function. Regulatory compliance is one of the objectives and drivers of IT risk management, and it requires the function to adhere to the applicable laws, rules, and standards. However, regulatory requirements are not the only source of IT risk, and they may not cover all the aspects and dimensions of IT risk management. Moreover, periodic assessment may not be sufficient to capture the dynamic and evolving nature of IT risk. Therefore, the IT risk management processes need to be updated and monitored on a continuous basis, not only to meet the regulatory requirements, but also to address the other sources and impacts of IT risk5. References = Risk and Information Systems Control Study Manual, Chapter
3: IT Risk Response, Section 3.1: Risk Response Process, pp. 121-123.


質問 # 740
An organization with a large number of applications wants to establish a security risk assessment program.
Which of the following would provide the MOST useful information when determining the frequency of risk assessments?

  • A. Results of a benchmark analysis
  • B. Feedback from end users
  • C. Prioritization from business owners
  • D. Recommendations from internal audit

正解:C


質問 # 741
Which of the following approaches to bring you own device (BYOD) service delivery provides the BEST protection from data loss?

  • A. Penetration testing and session timeouts
  • B. Implement remote monitoring
  • C. Enforce strong passwords and data encryption
  • D. Enable data wipe capabilities

正解:B

解説:
Section: Volume D
Explanation


質問 # 742
Which of the following come under the management class of controls?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Identification and authentication control
  • B. Risk assessment control
  • C. Program management control
  • D. Explanation:
    The Management class of controls includes five families. These families include over 40 individual controls. Following is a list of each of the families in the Management class: Certification, Accreditation, and Security Assessment (CA): This family of controls addresses steps to implement a security and assessment program. It includes controls to ensure only authorized systems are allowed on a network. It includes details on important security concepts, such as continuous monitoring and a plan of action and milestones. Planning (PL): The PL family focuses on security plans for systems. It also covers Rules of Behaviour for users. Rules of Behaviour are also called an acceptable use policy. Risk Assessment (RA): This family of controls provides details on risk assessments and vulnerability scanning. System and Services Acquisition (SA): The SA family includes any controls related to the purchase of products and services. It also includes controls related to software usage and user installed software. Program Management (PM): This family is driven by the Federal Information Security Management Act (FISMA). It provides controls to ensure compliance with FISMA. These controls complement other controls. They don't replace them.
  • E. Audit and accountability control

正解:B、C

解説:
and B are incorrect. Identification and authentication, and audit and accountability control are technical class of controls.


質問 # 743
During a routine check, a system administrator identifies unusual activity indicating an intruder within a firewall. Which of the following controls has MOST likely been compromised?

  • A. Identification
  • B. Authentication
  • C. Data validation
  • D. Data integrity

正解:B

解説:
Authentication is a control that verifies the identity of a user or a system that tries to access a computer system or network. Authentication can be based on something the user or system knows (such as a password or a PIN), something the user or system has (such as a token or a smart card), or something the user or system is (such as a fingerprint or a retina scan). Authentication is a crucial control for preventing unauthorized or malicious access to a system or network, as well as for ensuring the accountability and traceability of the actions performed by the user or system. If the authentication control is compromised, it means that the user or system can bypass or break the verification process and gain access to the system or network without being identified or authorized. This can expose the system or network to various threats, such as data theft, data corruption, data leakage, or denial of service. Therefore, the authentication control has most likely been compromised if a system administrator identifies unusual activity indicating an intruder within a firewall. A firewall is a device or a software that monitors and filters the incoming and outgoing network traffic based on predefined rules and policies. A firewall can help to protect the system or network from external or internal attacks by blocking or allowing the traffic based on the source, destination, protocol, or content. However, a firewall cannot prevent an intruder from accessing the system or network if the intruder has already authenticated or impersonated a legitimate user or system. The other options are not the most likely controls to be compromised if a system administrator identifies unusual activity indicating an intruder within a firewall, although they may be affected or related. Data validation is a control that checks the accuracy, completeness, and quality of the data that is entered, processed, or stored by a system or a network. Data validation can help to prevent or detect data errors, anomalies, or inconsistencies that may affect the performance, functionality, or reliability of the system or network. However, data validation does not prevent or detect unauthorized or malicious access to the system or network, as it only focuses on the data, not the user or system. Identification is a control that assigns a unique identifier to a user or a system that tries to access a computer system or network. Identification can be based on a username, an email address, a phone number, or a certificate.
Identification is a necessary but not sufficient control for preventing unauthorized or malicious access to a system or network, as it only declares who or what the user or system is, but does not prove it. Identification needs to be combined with authentication to verify the identity of the user or system. Data integrity is a control that ensures that the data is accurate, consistent, and complete throughout its lifecycle. Data integrity can be achieved by implementing various controls, such as encryption, hashing, checksum, digital signature, or backup. Data integrity can help to protect the data from unauthorized or accidental modification, deletion, or corruption that may affect the value, meaning, or usability of the data. However, data integrity does not prevent or detect unauthorized or malicious access to the system or network, as it only protects the data, not the user or system. References = CRISC Review Manual, pages 164-1651; CRISC Review Questions, Answers & Explanations Manual, page 952; What is Authentication? - Definition from Techopedia3; What is a Firewall? - Definition from Techopedia4


質問 # 744
Which of the following is a risk practitioner's BEST recommendation to address an organization's need to secure multiple systems with limited IT resources?

  • A. Conduct a business impact analysis (BIA)
  • B. Schedule a penetration test.
  • C. Perform a vulnerability analysis.
  • D. Apply available security patches.

正解:C

解説:
The best recommendation to address an organization's need to secure multiple systems with limited IT resources is to perform a vulnerability analysis. A vulnerability analysis is a process of identifying, assessing, and prioritizing the weaknesses or flaws in the systems that could be exploited by threats or risks. A vulnerability analysis helps to determine the level and nature of the exposure and impact of the systems, and to select and implement the appropriate security controls or mitigations. Performing a vulnerability analysis is the best recommendation, as it helps to optimize the use of the limited IT resources, by focusing on the most critical or significant vulnerabilities, and by applying the most effective or efficient security solutions.
Performing a vulnerability analysis also helps to improve the security posture and performance of the systems, and to reduce the likelihood and consequences of security incidents or breaches. Applying available security patches, scheduling a penetration test, and conducting a business impact analysis (BIA) are not the best recommendations, as they are either the outputs or the inputs of the vulnerability analysis process, and they do not address the primary need of securing the systems with limited IT resources. References = CRISC Review Manual, 6th Edition, ISACA, 2015, page 217.


質問 # 745
You are the project manager for BlueWell Inc. You have noticed that the risk level in your project increases above the risk tolerance level of your enterprise. You have applied several risk responses. Now you have to update the risk register in accordance to risk response process. All of the following are included in the risk register except for which item?

  • A. Network diagram analysis of critical path activities
  • B. Risk triggers
  • C. Agreed-upon response strategies
  • D. Risk owners and their responsibility

正解:A

解説:
Section: Volume B
Explanation:
The risk register does not examine the network diagram and the critical path. There may be risks associated with the activities on the network diagram, but it does not address the network diagram directly.
The risk register is updated at the end of the plan risk response process with the information that was discovered during the process. The response plans are recorded in the risk register. In the risk register, risk is stated in order of priority, i.e., those with the highest potential for threat or opportunity first. Some risks might not require response plans at all, but then too they should be put on a watch list and monitored throughout the project. Following elements should appear in the risk register:
* List of identified risks, including their descriptions, root causes, and how the risks impact the project objectives
* Risk owners and their responsibility
* Outputs from the Perform Qualitative Analysis process
* Agreed-upon response strategies
* Risk triggers
* Cost and schedule activities needed to implement risk responses
* Contingency plans
* Fallback plans, which are risk response plans that are executed when the initial risk response plan proves to be ineffective
* Contingency reserves
* Residual risk, which is a leftover risk that remains after the risk response strategy has been implemented
* Secondary risks, which are risks that come about as a result of implementing a risk response


質問 # 746
Prudent business practice requires that risk appetite not exceed:

  • A. risk tolerance.
  • B. residual risk.
  • C. inherent risk.
  • D. risk capacity.

正解:D

解説:
Section: Volume D


質問 # 747
Implementing which of the following controls would BEST reduce the impact of a vulnerability that has been exploited?

  • A. Deterrent control
  • B. Preventive control
  • C. Corrective control
  • D. Detective control

正解:D


質問 # 748
The PRIMARY focus of an ongoing risk awareness program should be to:

  • A. expand understanding of risk indicators.
  • B. define appropriate controls to mitigate risk.
  • C. determine impact of risk scenarios.
  • D. enable better risk-based decisions.

正解:D

解説:
The primary focus of an ongoing risk awareness program should be to enable better risk-based decisions, as this can help the organization to achieve its objectives, optimize its performance, and manage its risks effectively. An ongoing risk awareness program is a process of educating, communicating, and engaging the stakeholders about the organization's risk management framework, methodology, and practices. An ongoing risk awareness program can help the stakeholders to understand the risk context, criteria, appetite, and profile of the organization, and to identify, assess, treat, monitor, and review the risks that may affect their roles and responsibilities. By doing so, an ongoing risk awareness program can empower the stakeholders to make informed and rational decisions that balance the benefits and costs of risk-taking, and that align with the organization's strategy and goals.
References:
*ISACA, Risk IT Framework, 2nd Edition, 2019, p. 761
*ISACA, Managing Human Risk Requires More Than Just Awareness Training2


質問 # 749
Which of the following is the BEST way for a risk practitioner to verify that management has addressed control issues identified during a previous external audit?

  • A. Interview control owners.
  • B. Inspect external audit documentation.
  • C. Observe the control enhancements in operation.
  • D. Review management's detailed action plans.

正解:C


質問 # 750
Which of the following laws applies to organizations handling health care information?

  • A. GLBA
  • B. SOX
  • C. FISMA
  • D. HIPAA

正解:D

解説:
Explanation/Reference:
Explanation:
HIPAA handles health care information of an organization.
The Health Insurance Portability and Accountability Act (HIPAA) were introduced in 1996. It ensures that health information data is protected. Before HIPAA, personal medical information was often available to anyone. Security to protect the data was lax, and the data was often misused.
If your organization handles health information, HIPAA applies. HIPAA defines health information as any data that is created or received by health care providers, health plans, public health authorities, employers, life insurers, schools or universities, and health care clearinghouses.
HIPAA defines any data that is related to the health of an individual, including past/present/future health, physical/mental health, and past/present/future payments for health care.
Creating a HIPAA compliance plan involves following phases:
Assessment: An assessment helps in identifying whether organization is covered by HIPAA. If it is, then

further requirement is to identify what data is needed to protect.
Risk analysis: A risk analysis helps to identify the risks. In this phase, analyzing method of handling

data of organization is done.
Plan creation: After identifying the risks, plan is created. This plan includes methods to reduce the risk.

Plan implementation: In this plan is being implemented.

Continuous monitoring: Security in depth requires continuous monitoring. Monitor regulations for

changes. Monitor risks for changes. Monitor the plan to ensure it is still used.
Assessment: Regular reviews are conducted to ensure that the organization remains in compliance.

Incorrect Answers:
A: GLBA is not used for handling health care information.
C: SOX designed to hold executives and board members personally responsible for financial data.
D: FISMA ensures protection of data of federal agencies.


質問 # 751
Which of the following BEST reduces the probability of laptop theft?

  • A. Asset tag with GPS
  • B. Cable lock
  • C. Acceptable use policy
  • D. Data encryption

正解:B


質問 # 752
An organization has received notification that it is a potential victim of a cybercrime that may have compromised sensitive customer data. What should be The FIRST course of action?

  • A. Invoke the business continuity plan (BCP).
  • B. Conduct a forensic investigation.
  • C. Invoke the incident response plan.
  • D. Determine the business impact.

正解:C


質問 # 753
Which of the following steps ensure effective communication of the risk analysis results to relevant stakeholders? Each correct answer represents a complete solution. Choose three.

  • A. The results should be reported in terms and formats that are useful to support business decisions
  • B. Communicate the negative impacts of the events only, it needs more consideration
  • C. Communicate the risk-return context clearly
  • D. Provide decision makers with an understanding of worst-case and most probable scenarios,due diligence exposures and significant reputation, legal or regulatory considerations

正解:A、C、D

解説:
Explanation/Reference:
Explanation:
The result of risk analysis process is being communicated to relevant stakeholders. The steps that are involved in communication are:
The results should be reported in terms and formats that are useful to support business decisions.

Coordinate additional risk analysis activity as required by decision makers, like report rejection and

scope adjustment
Communicate the risk-return context clearly, which include probabilities of loss and/or gain, ranges, and

confidence levels (if possible) that enable management to balance risk-return.
Identify the negative impacts of events that drive response decisions as well as positive impacts of

events that represent opportunities which should channel back into the strategy and objective setting process.
Provide decision makers with an understanding of worst-case and most probable scenarios, due

diligence exposures and significant reputation, legal or regulatory considerations.
Incorrect Answers:
C: Communicate the negative impacts of events that drive response decisions as well as positive impacts of events that represent opportunities which should channel back into the strategy and objective setting process, for effective communication. Only negative impacts are not considered alone.


質問 # 754
Which of the following is the MOST important reason to link an effective key control indicator (KCI) to relevant key risk indicators (KRIs)?

  • A. To obtain business buy-in for investment in risk mitigation measures
  • B. To provide input to management for the adjustment of risk appetite
  • C. To monitor changes in the risk environment
  • D. To monitor the accuracy of threshold levels in metrics

正解:C


質問 # 755
......

JPNTest CRISC試験練習テスト問題:https://www.jpntest.com/shiken/CRISC-mondaishu

CRISC試験問題解答:https://drive.google.com/open?id=1JXIw6tgIczqe9wERi33J4N0W9QKKX9HB

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡