[Mar 30, 2025] CRISC PDF Questions and Testing Engine With 1519 Questions
Updated Exam Engine for CRISC Exam Free Demo & 365 Day Updates
NEW QUESTION # 911
Risks to an organization's image are referred to as what kind of risk?
- A. Operational
- B. Strategic
- C. Information
- D. Financial
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Strategic risks are those risks which have potential outcome of not fulfilling on strategic objectives of the organization as planned. Since the strategic objective will shape and impact the entire organization, the risk of not meeting that objective can impose a great threat on the organization.
Strategic risks can be broken down into external and internal risks:
External risks are those circumstances from outside the enterprise which will have a potentially
damaging or helpful impact on the enterprise. These risks include sudden change of economy, industry, or regulatory conditions. Some of the external risks are predictable while others are not. For instance, a recession may be predictable and the enterprise may be able to hedge against the dangers economically; but the total market failure may not as predictable and can be much more devastating.
Internal risks usually focus on the image or reputation of the enterprise. some of the risks that are
involved in this are public communication, trust, and strategic agreement from stakeholders and customers.
NEW QUESTION # 912
Which of the following IT key risk indicators (KRIs) provides management with the BEST feedback on IT capacity?
- A. Increased resource availability
- B. Trends in IT maintenance costs
- C. Trends in IT resource usage
- D. Increased number of incidents
Answer: C
Explanation:
IT capacity is the ability of an IT system or network to handle the current and future workload and performance demands. IT capacity can be affected by various factors, such as the number and type of users, applications, devices, data, transactions, etc. IT capacity management is the process of planning, monitoring, and optimizing the IT resources to ensure that they meet the business needs and objectives. IT capacity management can help prevent issues such as system slowdowns, outages, errors, or failures, and improve the efficiency, reliability, and security of the IT system or network. One of the IT key risk indicators (KRIs) that provides management with the best feedback on IT capacity is the trends in IT resource usage. IT resource usage is the measure of how much of the IT resources, such as CPU, memory, disk, bandwidth, etc., are being consumed by the IT system or network. Trends in IT resource usage can help monitor and analyze the changes in the IT capacity over time, and identify the patterns, peaks, and bottlenecks in the IT resource consumption.
Trends in IT resource usage can also help forecast the future IT capacity requirements, and plan for the appropriate IT resource allocation, optimization, or expansion. Trends in IT resource usage can provide management with valuable information on the current and potential IT capacity risks, and support the decision making and risk response for IT capacity management. References = Integrating KRIs and KPIs for Effective Technology Risk Management, p. 3-4.
NEW QUESTION # 913
When reporting risk assessment results to senior management, which of the following is MOST important to include to enable risk-based decision making?
- A. A list of assets exposed to the highest risk
- B. Potential losses compared to treatment cost
- C. Risk action plans and associated owners
- D. Recent audit and self-assessment results
Answer: B
Explanation:
When reporting risk assessment results to senior management, the most important information to include to enable risk-based decision making is the potential losses compared to treatment cost. This information helps to quantify the impact and likelihood of the risks, and to evaluate the cost and benefit of the risk responses.
This information also helps to prioritize and allocate resources for the risk management program, and to align the risk management program with the enterprise's objectives, strategy, and risk appetite. The other options are not as important as the potential losses compared to treatment cost, as they provide different types of information for the risk management process:
* Risk action plans and associated owners are the documents that specify the actions to be taken to address the identified risks, the resources required, the timelines, the owners, and the expected outcomes. This information helps to implement and monitor the risk management program, and to assign the authority and accountability for the risk management activities.
* Recent audit and self-assessment results are the outcomes of the independent and objective examination of the risk management program, such as by internal or external auditors, or by the risk owners or practitioners themselves. This information helps to provide assurance and feedback on the effectiveness and efficiency of the risk management program, and to identify the gaps or weaknesses that need to be addressed.
* A list of assets exposed to the highest risk are the resources that have the most value for the enterprise, such as hardware, software, data, or services, and that are affected by or contribute to the highest risks.
This information helps to identify and protect the critical assets of the enterprise, and to reduce the exposure and impact of the risks to the assets. References = Risk and Information Systems Control Study Manual, 7th Edition, Chapter 2, Section 2.3.1.1, pp. 58-59.
NEW QUESTION # 914
A service provider is managing a client's servers. During an audit of the service, a noncompliant control is discovered that will not be resolved before the next audit because the client cannot afford the downtime required to correct the issue. The service provider's MOST appropriate action would be to:
- A. make a note for this item in the next audit explaining the situation
- B. insist that the remediation occur for the benefit of other customers
- C. ask the client to document the formal risk acceptance for the provider
- D. develop a risk remediation plan overriding the client's decision
Answer: C
Explanation:
A noncompliant control is a control that does not meet the requirements or standards of an audit, regulation, or policy. A noncompliant control can expose the organization to risks such as errors, fraud, or breaches.
When a noncompliant control is identified, the service provider and the client should work together to resolve the issue as soon as possible. However, sometimes the resolution may not be feasible or cost-effective, and the client may decide to accept the risk associated with the noncompliant control.
In this case, the service provider's most appropriate action would be to ask the client to document the formal risk acceptance for the provider. This means that the client should acknowledge the existence and consequences of the noncompliant control, and provide a written justification for accepting the risk. The risk acceptance document should also specify the roles and responsibilities of the service provider and the client, and the duration and conditions of the risk acceptance. The risk acceptance document should be signed by the client's senior management and the service provider's management, and kept as part of the audit evidence.
The other options are not appropriate actions for the service provider. Developing a risk remediation plan overriding the client's decision would be disrespectful and unprofessional, as it would ignore the client's authority and preference. Making a note for this item in the next audit explaining the situation would be insufficient and misleading, as it would imply that the issue is still unresolved and that the service provider is responsible for it. Insisting that the remediation occur for the benefit of other customers would be unreasonable and impractical, as it would disregard the client's business needs and constraints, and potentially harm the relationship between the service provider and the client. References =
* Risk Acceptance - Institute of Internal Auditors
* New Guidance on the Evaluation of Non-compliance with the Risk Assessment Standard and its Peer Review Impact - REVISED
* The Impact of Non-compliance: Understanding The Risks And Consequences
NEW QUESTION # 915
You work as the project manager for Company Inc. The project on which you are working has several risks that will affect several stakeholder requirements. Which project management plan will define who will be available to share information on the project risks?
- A. Resource Management Plan
- B. Communications Management Plan
- C. Stakeholder management strategy
- D. Risk Management Plan
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The Communications Management Plan defines, in regard to risk management, who will be available to share information on risks and responses throughout the project.
The Communications Management Plan aims to define the communication necessities for the project and how the information will be circulated. The Communications Management Plan sets the communication structure for the project. This structure provides guidance for communication throughout the project's life and is updated as communication needs change. The Communication Managements Plan identifies and defines the roles of persons concerned with the project. It includes a matrix known as the communication matrix to map the communication requirements of the project.
Incorrect Answers:
A: The Resource Management Plan does not define risk communications.
C: The Risk Management Plan deals with risk identification, analysis, response, and monitoring.
D: The stakeholder management strategy does not address risk communications.
NEW QUESTION # 916
Which of the following is the MOST important data attribute of key risk indicators (KRIs)?
- A. The data is calculated continuously.
- B. The data is automatically produced.
- C. The data is relevant.
- D. The data is measurable.
Answer: C
NEW QUESTION # 917
What type of policy would an organization use to forbid its employees from using organizational e-mail for personal use?
- A. Intellectual property policy
- B. Privacy policy
- C. Acceptable use policy
- D. Anti-harassment policy
Answer: C
Explanation:
Explanation/Reference:
Explanation:
An acceptable use policy is a set of rules applied by the owner/manager of a network, website or large computer system that restrict the ways in which the network site or system may be used. Acceptable Use Policies are an integral part of the framework of information security policies.
Incorrect Answers:
A, C: These two policies are not related to Information system security.
D: Privacy policy is a statement or a legal document (privacy law) that discloses some or all of the ways a party gathers, uses, discloses and manages a customer or client's data.
NEW QUESTION # 918
Which of the following is a risk practitioner's BEST course of action upon learning that a control under internal review may no longer be necessary?
- A. Consult the internal auditor for a second opinion.
- B. Obtain approval to retire the control.
- C. Verify the effectiveness of the original mitigation plan.
- D. Update the status of the control as obsolete
Answer: C
NEW QUESTION # 919
Which of the following is MOST effective in continuous risk management process improvement?
- A. Awareness training
- B. Policy updates
- C. Change management
- D. Periodic assessments
Answer: D
Explanation:
Section: Volume D
NEW QUESTION # 920
An organization practices the principle of least privilege. To ensure access remains appropriate, application owners should be required to review user access rights on a regular basis by obtaining:
- A. documentation indicating the intended users of the application
- B. an access control matrix and approval from the user's manager
- C. security logs to determine the cause of invalid login attempts
- D. business purpose documentation and software license counts
Answer: B
Explanation:
The best way to ensure that access remains appropriate for an organization that practices the principle of least privilege is to review user access rights on a regular basis by obtaining an access control matrix and approval from the user's manager. An access control matrix is a table that shows the access rights and permissions of each user or role for each resource or function. An access control matrix helps to verify that the users have the minimum level of access required to perform their duties, and to identify any unauthorized or excessive access rights. Approval from the user's manager helps to confirm that the user's access rights are consistent with their current role and responsibilities, and to authorize any changes or exceptions as needed. References
= Risk and Information Systems Control Study Manual, 7th Edition, Chapter 3, Section 3.2.2, page 1281
NEW QUESTION # 921
An organization striving to be on the leading edge in regard to risk monitoring would MOST likely implement:
- A. monitoring activities for all critical assets.
- B. real-time monitoring of risk events and control exceptions.
- C. a tool for monitoring critical activities and controls.
- D. procedures to monitor the operation of controls.
- E. Perform a controls assessment.
Answer: B
NEW QUESTION # 922
The head of a business operations department asks to review the entire IT risk register. Which of the following would be the risk manager's BEST approach to this request before sharing the register?
- A. Require a nondisclosure agreement.
- B. Escalate to senior management.
- C. Sanitize portions of the register.
- D. Determine the purpose of the request.
Answer: D
Explanation:
Section: Volume D
NEW QUESTION # 923
Which of the following statements in an organization's current risk profile report is cause for further action by senior management?
- A. New key risk indicators (KRIs) have been established.
- B. Key performance indicators (KPIs) are outside of targets.
- C. Key risk indicators (KRIs) are lagging.
- D. Key performance indicator (KPI) trend data is incomplete.
Answer: B
Explanation:
A risk profile report is a document that summarizes the current status and trends of the risks that an organization faces, as well as the actions taken or planned to manage them1. A risk profile report is a useful tool for senior management to monitor and oversee the organization's risk management performance and to make informed decisions and adjustments as needed2. One of the key components of a risk profile report is the key performance indicators (KPIs), which are metrics used to measure and evaluate the achievement of the organization's objectives and strategies3. KPIs are aligned with the organization's risk appetite and tolerance, and they have specific targets or benchmarks that indicate the desired level of performance4.
Therefore, if the KPIs are outside of targets, it means that the organization is not meeting its objectives and strategies, and that there may be gaps or issues in the risk management process or the risk response actions.
This is a cause for further action by senior management, as they need to investigate the root causes of the deviation, assess the impact and implications of the underperformance, and take corrective or preventive measures to improve the situation and bring the KPIs back to the targets. Incomplete KPI trend data, new KRIs, and lagging KRIs are not the most critical statements in a risk profile report that require further action by senior management, as they do not directly indicate a failure or a problem in the risk management performance or the achievement of the objectives and strategies. Incomplete KPI trend data means that there is missing or insufficient information on the historical or projected changes in the KPIs over time. This may affect the accuracy and reliability of the risk profile report, but it does not necessarily mean that the KPIs are outside of targets or that the objectives and strategies are not met. Senior management may need to request or obtain the complete KPI trend data, but this is not as urgent or important as addressing the KPIs that are outside of targets. New KRIs means that there are additional or revised metrics used to measure and monitor the level of risk associated with a particular process, activity, or system within the organization. This may reflect the changes or updates in the risk environment, the risk appetite and tolerance, or the risk assessment methodology. However, new KRIs do not directly indicate a failure or a problem in the risk management performance or the achievement of the objectives and strategies. Senior management may need to review and approve the new KRIs, but this is not as urgent or important as addressing the KPIs that are outside of targets.
Lagging KRIs means that there are metrics that measure and monitor the level of risk after a risk event has occurred or a risk response has been implemented. This may provide useful feedback and lessons learned for the risk management process, but it does not directly indicate a failure or a problem in the risk management performance or the achievement of the objectives and strategies. Senior management may need to analyze and evaluate the lagging KRIs, but this is not as urgent or important as addressing the KPIs that are outside of targets. References = Risk and Information Systems Control Study Manual, Chapter 4: Risk and Control Monitoring and Reporting, Section 4.3: Risk Reporting, pp. 201-205.
NEW QUESTION # 924
Which of the following observations from a third-party service provider review would be of GREATEST concern to a risk practitioner?
- A. Service level agreements (SLAs) have not been met over the last quarter.
- B. The service contract is up for renewal in less than thirty days.
- C. Key third-party personnel have recently been replaced.
- D. Monthly service charges are significantly higher than industry norms.
Answer: A
Explanation:
The observation from a third-party service provider review that would be of greatest concern to a risk practitioner is that the service level agreements (SLAs) have not been met over the last quarter, as it indicates a significant performance issue or breach that may affect the quality, functionality, or security of the outsourced services, and may require a remediation or escalation action. The other options are not the greatest concerns, as they may not indicate a performance issue or breach, but rather a contractual, personnel, or financial issue, respectively, that may not affect the outsourced services directly or significantly. References = CRISC Review Manual, 7th Edition, page 111.
NEW QUESTION # 925
Which of the following is the BEST way to help ensure risk will be managed properly after a business process has been re-engineered?
- A. Conducting a post-implementation review to determine lessons learned
- B. Reassessing control effectiveness of the process
- C. Establishing escalation procedures for anomaly events
- D. Reporting key performance indicators (KPIs) for core processes
Answer: B
Explanation:
Business process re-engineering is the radical redesign of a business process to achieve significant improvements in performance, quality, cost, or customer satisfaction. Business process re-engineering can introduce new or modified risks to the organization, as well as affect the existing controls and responses.
Therefore, the best way to help ensure risk will be managed properly after a business process has been re-engineered is to reassess the control effectiveness of the process, meaning that the organization should evaluate whether the controls are still adequate, appropriate, and functioning as intended to mitigate the risks.
Reassessing the control effectiveness can help to identify any gaps or weaknesses in the control environment, as well as to implement any necessary changes or improvements to the controls. References = Risk and Information Systems Control Study Manual, Chapter 5, Section 5.2.2, p. 229-230
NEW QUESTION # 926
An organization has been notified that a dis grunted, terminated IT administrator has tried to break into the corporate network. Which of the following discoveries should be of GREATEST concern to the organization?
- A. A brute force attack has been detected
- B. Authentication logs have been disabled
- C. An increase in support request has been observed
- D. An external vulnerability scan has been detected
Answer: B
Explanation:
Section: Volume D
NEW QUESTION # 927
Following a review of a third-party vendor, it is MOST important for an organization to ensure:
- A. identified findings are approved by the vendor.
- B. identified findings are reviewed by the organization.
- C. results of the review are validated by internal audit.
- D. results of the review are accurately reported to management.
Answer: D
Explanation:
A review of a third-party vendor is a process that involves examining and evaluating the performance, quality, and compliance of the vendor that provides a product or service to the organization1. A review of a third-party vendor can help to identify and address the risks and issues that may arise from the vendor relationship, such as data breaches, service disruptions, contract violations, or reputation damage2. Following a review of a third-party vendor, it is most important for an organization to ensure that the results of the review are accurately reported to management, as this will enable the management to make informed and timely decisions and actions based on the findings and recommendations of the review. Accurate reporting of the results of the review will also help to establish and maintain the trust and transparency between the organization and the vendor, and to demonstrate the accountability and responsibility of the organization for its vendor risk management3. Identified findings are reviewed by the organization, results of the review are validated by internal audit, and identified findings are approved by the vendor are not the most important things to ensure following a review of a third-party vendor, as they do not provide the same level of impact and value as accurate reporting of the results of the review. Identified findings are reviewed by the organization is a process that involves analyzing and interpreting the outcomes and implications of the review of a third-party vendor, and determining the appropriate risk responses and actions to address the findings4. This is an important step in the vendor risk management process, but it is not the most important thing to ensure following a review of a third-party vendor, as it does not communicate or inform the management or the vendor of the results of the review. Results of the review are validated by internal audit is a process that involves verifying and confirming the accuracy and reliability of the review of a third-party vendor, and providing assurance and advice on the adequacy and effectiveness of the vendor risk management. This is an important step in the vendor risk management process, but it is not the most important thing to ensure following a review of a third-party vendor, as it does not report or share the results of the review with the management or the vendor. Identified findings are approved by the vendor is a process that involves obtaining the consent and agreement of the vendor on the outcomes and recommendations of the review of a third-party vendor, and ensuring their cooperation and compliance with the risk responses and actions. This is an important step in the vendor risk management process, but it is not the most important thing to ensure following a review of a third-party vendor, as it does not report or inform the management of the results of the review. References = 1: The guide to third-party vendor reviews - TerraTrue HQ | TerraTrue2: 4 Tips For Organizations To Evaluate Third-Party Vendors - Forbes Advisor3: Vendor Risk Management: Best Practices for 2023 - Venminder4: [Risk and Information Systems Control Study Manual, Chapter 3: Risk Response, Section 3.1: Risk Response Options, pp. 113-115.] : [IT Risk Resources | ISACA] : Who Is Considered a Third Party or Vendor? - Venminder :
[Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.1: Risk Identification, pp. 57-59.] : [Risk and Information Systems Control Study Manual, Chapter 4: Risk and Control Monitoring and Reporting, Section 4.2: Risk Monitoring, pp. 189-191.] : [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section
5.1: Control Design, pp. 233-235.] : [Risk and Information Systems Control Study Manual, Chapter 5:
Information Systems Control Design and Implementation, Section 5.2: Control Implementation, pp. 243-245.]: [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section 5.3: Control Monitoring and Maintenance, pp. 251-253.]
NEW QUESTION # 928
The PRIMARY purpose of vulnerability assessments is to:
- A. detect weaknesses that could lead to system compromise.
- B. determine the impact of potential threats.
- C. test intrusion detection systems (IDS) and response procedures.
- D. provide clear evidence that the system is sufficiently secure.
Answer: A
Explanation:
The primary purpose of vulnerability assessments is to detect weaknesses that could lead to system compromise. A vulnerability assessment is a systematic review of security weaknesses in an information system. It evaluates if the system is susceptible to any known vulnerabilities, assigns severity levels to those vulnerabilities, and recommends remediation or mitigation, if and whenever needed1. By identifying and prioritizing the vulnerabilities, a vulnerability assessment helps to prevent or reduce the risk of cyberattacks that could exploit the vulnerabilities and compromise the system. The other options are not the primary purpose, but they may be secondary or tertiary outcomes or benefits of a vulnerability assessment. Providing clear evidence that the system is sufficiently secure is a result of a successful vulnerability assessment and remediation process, but it is not the main objective. Determining the impact of potential threats is a part of the risk assessment process, which complements the vulnerability assessment process, but it is not the same as detecting the vulnerabilities. Testing intrusion detection systems (IDS) and response procedures is a part of the penetration testing process, which simulates a real-world attack on the system to evaluate its security posture, but it is not the same as scanning the system for vulnerabilities. References = What is Vulnerability Assessment | VA Tools and Best Practices - Imperva
NEW QUESTION # 929
Which of the following is the BEST way for a risk practitioner to verify that management has addressed control issues identified during a previous external audit?
- A. Interview control owners.
- B. Observe the control enhancements in operation.
- C. Inspect external audit documentation.
- D. Review management's detailed action plans.
Answer: B
NEW QUESTION # 930
Which of the following is MOST important for developing effective key risk indicators (KRIs)?
- A. Utilizing data and resources internal to the organization
- B. Including input from risk and business unit management
- C. Developing in collaboration with internal audit
- D. Engaging sponsorship by senior management
Answer: B
Explanation:
Key risk indicators (KRIs) are metrics used by organizations to monitor and assess potential risks that may impact their objectives and performance. KRIs also provide early warning signals that help organizations identify, analyze, and address risks before they escalate into significant issues1. Effective KRIs are those that are relevant, measurable, predictable, comparable, and informational2. The most important factor for developing effective KRIs is including input from risk and business unit management, as they are the persons who have the best understanding of the risk environment, the risk appetite and tolerance, and the risk factors and impacts of the organization. By including input from risk and business unit management, the organization can ensure that the KRIs are aligned with the organization's strategy, vision, and mission, and that they reflect the current and emerging risks and their potential consequences. Engaging sponsorship by senior management, utilizing data and resources internal to the organization, and developing in collaboration with internal audit are not the most important factors for developing effective KRIs, as they do not provide the same level of insight and relevance as including input from risk and business unit management. Engaging sponsorship by senior management is a factor that involves obtaining the support and approval of the senior leaders who have the authority and accountability for the organization's performance and governance. Engaging sponsorship by senior management can help to promote the importance and value of KRIs, and to ensure their communication and implementation across the organization, but it does not ensure that the KRIs are appropriate and accurate for the organization's risk profile. Utilizing data and resources internal to the organization is a factor that involves using the information and assets that are available within the organization to support or enable the development of KRIs. Utilizing data and resources internal to the organization can help to enhance the quality and reliability of KRIs, and to reduce the cost and complexity of obtaining external data and resources, but it does not ensure that the KRIs are comprehensive and consistent with the organization's risk environment.
Developing in collaboration with internal audit is a factor that involves working with the internal audit function that provides independent and objective assurance and advice on the adequacy and effectiveness of the organization's risk management. Developing in collaboration with internal audit can help to improve the validity and compliance of KRIs, and to provide feedback and recommendations for improvement, but it does not ensure that the KRIs are relevant and realistic for the organization's risk objectives and strategies.
References = 1: Key Risk Indicators: A Practical Guide | SafetyCulture2: KRI Framework for Operational Risk Management | Workiva3: [Risk and Information Systems Control Study Manual, Chapter 4: Risk and Control Monitoring and Reporting, Section 4.1: Key Risk Indicators, pp. 181-185.]
NEW QUESTION # 931
Which of the following would require updates to an organization's IT risk register?
- A. Management review of key risk indicators (KRIs)
- B. Completion of the latest internal audit
- C. Discovery of an ineffectively designed key IT control
- D. Changes to the team responsible for maintaining the register
Answer: C
NEW QUESTION # 932
Which of the following is the BEST key performance indicator (KPI) to measure the maturity of an organization's security incident handling process?
- A. The number of recurring security incidents
- B. The number of resolved security incidents
- C. The number of newly identified security incidents
- D. The number of security incidents escalated to senior management
Answer: B
NEW QUESTION # 933
An organization has four different projects competing for funding to reduce overall IT risk. Which project should management defer?
- A. Project Charlie
- B. Project Delta
- C. Project Bravo
- D. Project Alpha
Answer: A
NEW QUESTION # 934
Which of the following is the MOST cost-effective way to test a business continuity plan?
- A. Conduct a tabletop exercise.
- B. Conduct a full functional exercise.
- C. Conduct a disaster recovery exercise.
- D. Conduct interviews with key stakeholders.
Answer: A
Explanation:
* A business continuity plan (BCP) is a document that describes the procedures and actions that an organization will take to ensure the continuity of its critical functions and operations in the event of a disruption or disaster12.
* Testing a business continuity plan is a method of evaluating the effectiveness and readiness of the BCP, and identifying and addressing any gaps or weaknesses in the plan34.
* The most cost-effective way to test a business continuity plan is to conduct a tabletop exercise, which is a type of simulation that involves gathering the key stakeholders and participants of the BCP, and discussing and reviewing the roles, responsibilities, and actions that they will take in response to a hypothetical scenario of a disruption or disaster56.
* A tabletop exercise is the most cost-effective way because it requires minimal resources and time, and can be conducted in a regular meeting room or online platform56.
* A tabletop exercise is also the most cost-effective way because it provides a high-level overview and assessment of the BCP, and can identify and address the major issues or challenges that may arise in the implementation of the plan56.
* The other options are not the most cost-effective ways, but rather possible alternatives or supplements that may have different levels of complexity or cost. For example:
* Conducting interviews with key stakeholders is a way of testing a business continuity plan that involves asking and answering questions about the BCP, and collecting feedback and suggestions from the people who are involved or affected by the plan78. However, this way is not the most cost-effective because it may not cover all the aspects or scenarios of the BCP, and may not facilitate the interaction or collaboration among the stakeholders78.
* Conducting a disaster recovery exercise is a way of testing a business continuity plan that involves activating and executing the BCP in a realistic and controlled environment, and measuring the
* outcomes and impacts of the plan . However, this way is not the most cost-effective because it requires a lot of resources and time, and may disrupt or interfere with the normal operations of the organization .
* Conducting a full functional exercise is a way of testing a business continuity plan that involves simulating and testing the BCP in a live and dynamic environment, and involving the external entities and stakeholders that are part of the plan . However, this way is not the most cost-effective because it requires the most resources and time, and may pose the highest risk or challenge to the organization . References =
* 1: Business Continuity Plan (BCP) Definition1
* 2: Business Continuity Planning - Ready.gov2
* 3: Testing, testing: how to test your business continuity plan4
* 4: Comprehensive Guide to Business Continuity Testing | Agility5
* 5: How to Conduct a Tabletop Exercise for Business Continuity3
* 6: Tabletop Exercises: A Guide to Success6
* 7: How to Conduct Testing of a Business Continuity Plan7
* 8: Business Continuity Plan Testing: Interviewing Techniques8
* : Disaster Recovery Testing: A Step-by-Step Guide
* : Disaster Recovery Testing Scenarios: A Guide to Success
* : Functional Exercises: A Guide to Success
* : Functional Exercise Toolkit
NEW QUESTION # 935
You are the project manager for your organization. You are preparing for the quantitative risk analysis. Mark, a project team member, wants to know why you need to do quantitative risk analysis when you just completed qualitative risk analysis. Which one of the following statements best defines what quantitative risk analysis is?
- A. Quantitative risk analysis is the process of prioritizing risks for further analysis or action by assessing and combining their probability of occurrence and impact.
- B. Quantitative risk analysis is the process of numerically analyzing the effect of identified risks on overall project objectives.
- C. Quantitative risk analysis is the review of the risk events with the high probability and the highest impact on the project objectives.
- D. Quantitative risk analysis is the planning and quantification of risk responses based on probability and impact of each risk event.
Answer: B
Explanation:
Section: Volume C
Explanation:
Quantitative risk analysis is the process of numerically analyzing the effect of identified risks on overall project objectives. It is performed on risk that have been prioritized through the qualitative risk analysis process.
Incorrect Answers:
A: While somewhat true, this statement does not completely define the quantitative risk analysis process.
B: This is actually the definition of qualitative risk analysis.
D: This is not a valid statement about the quantitative risk analysis process. Risk response planning is a separate project management process.
NEW QUESTION # 936
......
Exam Passing Guarantee CRISC Exam with Accurate Quastions: https://www.pass4guide.com/CRISC-exam-guide-torrent.html
Test Engine to Practice Test for CRISC Valid and Updated Dumps: https://drive.google.com/open?id=1G8I9Ofp8cuynKVsoeVsSTeLEfMqj7pAM