[2023年11月10日] 手に入れよう!最新CRISC認定された有効な試験問題集解答 [Q421-Q446]

Share

[2023年11月10日] 手に入れよう!最新CRISC認定された有効な試験問題集解答

100%合格率保証付きの素晴らしいCRISC試験問題PDF


リスクと情報システムコントロール(CRISC)認定は、情報システム監査および制御協会(ISACA)が提供する専門家の指定です。この認定は、組織の情報技術システム内のリスクを管理および特定する責任がある個人を対象としています。リスク管理と情報セキュリティに関する包括的な理解を提供し、効果的なリスク管理戦略を開発および実施する能力を提供します。


ISACA CRISC(リスクおよび情報システム制御の認定)認定試験は、リスク管理および情報システム管理の分野で最も尊敬され、求められている認定の1つです。この試験は、組織の情報システムとテクノロジーに関連するリスクの管理を担当する専門家の知識とスキルをテストするように設計されています。


ISACA CRISC(リスクおよび情報システム制御の認定)試験は、ITとビジネスリスクの管理と特定の専門知識を持つ個人を認識する認定プログラムです。この試験は、ITガバナンス、リスク管理、および情報セキュリティで働く専門家向けに設計されています。認定は、組織内のリスクを特定、評価、評価する個人の能力を示しています。

 

質問 # 421
The PRIMARY reason for periodic penetration testing of Internet-facing applications is to:

  • A. ensure policy and regulatory compliance.
  • B. assess the proliferation of new threats.
  • C. verify Internet firewall control settings.
  • D. identify vulnerabilities in the system.

正解:B


質問 # 422
There are five inputs to the quantitative risk analysis process. Which one of the following is NOT an input to quantitative risk analysis process?

  • A. Explanation:
    Enterprise environmental factor is not an input to the quantitative risk analysis process. The five inputs to the perform quantitative risk analysis process are: risk register, risk management plan, cost management plan, schedule management plan, and organizational process assets.
  • B. Cost management plan
  • C. Risk management plan
  • D. Risk register
  • E. Enterprise environmental factors

正解:E

解説:
A, and C are incorrect. These are the valid inputs to the perform quantitative risk analysis process.


質問 # 423
Which of the following is the BEST indication of an effective risk management program?

  • A. Residual risk is within the organizational risk appetite
  • B. Risk action plans are approved by senior management.
  • C. Mitigating controls are designed and implemented.
  • D. Risk is recorded and tracked in the risk register

正解:A


質問 # 424
A risk practitioner observes that hardware failure incidents have been increasing over the last few months.
However, due to built-in redundancy and fault-tolerant architecture, there have been no interruptions to business operations. The risk practitioner should conclude that:

  • A. no action is required as there was no impact
  • B. hardware needs to be upgraded
  • C. controls are effective for ensuring continuity
  • D. a root cause analysis is required

正解:D


質問 # 425
An IT organization is replacing the customer relationship management (CRM) system. Who should own the risk associated with customer data leakage caused by insufficient IT security controls for the new system?

  • A. Chief risk officer
  • B. Chief information security officer
  • C. Business process owner
  • D. IT controls manager

正解:C


質問 # 426
Fred is the project manager of a large project in his organization. Fred needs to begin planning the risk management plan with the project team and key stakeholders. Which plan risk management process tool and technique should Fred use to plan risk management?

  • A. Data gathering and representation techniques
  • B. Variance and trend analysis
  • C. Planning meetings and analysis
  • D. Information gathering techniques

正解:C

解説:
Explanation/Reference:
Explanation:
There is only one tool and technique available for Fred to plan risk management: planning meetings and analysis. Planning Meeting and Analysis is a tool and technique in the Plan Risk Management process.
Planning meetings are organized by the project teams to develop the risk management plan. Attendees at these meetings include the following:
Project manager

Selected project team members

Stakeholders

Anybody in the organization with the task to manage risk planning

Sophisticated plans for conducting the risk management activities are defined in these meetings, responsibilities related to risk management are assigned, and risk contingency reserve application approaches are established and reviewed.
Incorrect Answers:
A, B, D: These are not plan risk management tools and techniques.


質問 # 427
A risk practitioner recently discovered that sensitive data from the production environment is required for testing purposes in non-production environments. Which of the following i the BEST recommendation to address this situation?

  • A. Enable data encryption in the test environment
  • B. Prevent the use of production data for test purposes
  • C. Implement equivalent security in the test environment.
  • D. Mask data before being transferred to the test environment.

正解:C


質問 # 428
Which of the following is the PRIMARY role of a data custodian in the risk management process?

  • A. Being accountable for control design
  • B. Performing periodic data reviews according to policy
  • C. Reporting and escalating data breaches to senior management
  • D. Ensuring data is protected according to the classification

正解:D


質問 # 429
The only output of qualitative risk analysis is risk register updates. When the project manager updates the risk register he will need to include several pieces of information including all of the following except for which one?

  • A. Risks grouped by categories
  • B. Trends in qualitative risk analysis
  • C. Watchlist of low-priority risks
  • D. Risk probability-impact matrix

正解:D

解説:
Section: Volume A
Explanation
Explanation:
The risk matrix is not included as part of the risk register updates. There are seven things that can be updated in the risk register as a result of qualitative risk analysis: relating ranking of project risks, risks grouped by categories, causes of risks, list of near-term risks, risks requiring additional analysis, watchlist of low-priority risks, trends in qualitative risk analysis.
Incorrect Answers:
A: Trends in qualitative risk analysis are part of the risk register updates.
C: Risks grouped by categories are part of the risk register updates.
D: Watchlist of low-priority risks is part of the risk register updates.


質問 # 430
You are the project manager of HJT project. Important confidential files of your project are stored on a computer. Keeping the unauthorized access of this computer in mind, you have placed a hidden CCTV in the room, even on having protection password. Which kind of control CCTV is?

  • A. Physical control
  • B. Administrative control
  • C. Technical control
  • D. Explanation:
    CCTV is a physical control. Physical controls protect the physical environment. They include basics such as locks to protect access to secure areas. They also include environmental controls. This section presents the following examples of physical controls: Locked doors, guards, access logs, and closed-circuit television Fire detection and suppression Temperature and humidity detection Electrical grounding and circuit breakers Water detection
  • E. Management control

正解:A

解説:
A, and D are incorrect. CCTV is a physical control.


質問 # 431
Which of the following control audit is performed to assess the efficiency of the productivity in the operations environment?

  • A. Financial
  • B. Operational
  • C. Specialized
  • D. Administrative

正解:D

解説:
Section: Volume C
Explanation:
The administrative audit is used to assess the efficiency of the productivity in the operations environment.
Incorrect Answers:
A: It evaluates the internal control structure of process of functional area.
B: Audits that assesses the correctness of financial statements is called financial audit.
D: They are the IS audits with specific intent to examine areas, such as processes, services, or technologies, usually by third party auditors.


質問 # 432
Which of the following type of risk could result in bankruptcy?

  • A. Critical
  • B. Catastrophic
  • C. Marginal
  • D. Negligible

正解:B

解説:
Section: Volume B
Explanation:
Catastrophic risk causes critical financial losses that have the possibility of bankruptcy.
Incorrect Answers:
A: Marginal risk causes financial loss in a single line of business and a reduced return on IT investment.
B: It causes minimal impact on a single line of business affecting their ability to deliver services or products.
C: Critical risk causes serious financial losses in more than one line of business with a loss in productivity.


質問 # 433
Which of the following activities BEST facilitates effective risk management throughout the organization?

  • A. Performing frequent audits
  • B. Conducting periodic risk assessments
  • C. Performing a business impact analysis (BIA)
  • D. Reviewing risk-related process documentation

正解:B


質問 # 434
Which of the following is MOST important to understand when determining an appropriate risk assessment approach?

  • A. Management culture
  • B. Complexity of the IT infrastructure
  • C. Threats and vulnerabilities
  • D. Value of information assets

正解:D


質問 # 435
Which of the following BEST ensures that a firewall is configured in compliance with an enterprise's security policy?

  • A. Review the actual procedures.
  • B. Explanation:
    A review of the parameter settings will provide a good basis for comparison of the actual configuration to the security policy and will provide reliable audit evidence documentation.
  • C. Review the device's log file for recent attacks.
  • D. Review the parameter settings.
  • E. Interview the firewall administrator.

正解:B、D

解説:
is incorrect. While procedures may provide a good understanding of how the firewall is supposed to be managed, they do not reliably confirm that the firewall configuration complies with the enterprise's security policy. Answer: A is incorrect. While interviewing the firewall administrator may provide a good process overview, it does not reliably confirm that the firewall configuration complies with the enterprise's security policy. Answer: C is incorrect. While reviewing the device's log file for recent attacks may provide indirect evidence about the fact that logging is enabled, it does not reliably confirm that the firewall configuration complies with the enterprise's security policy.


質問 # 436
There are five inputs to the quantitative risk analysis process. Which one of the following is NOT an input to quantitative risk analysis process?

  • A. Cost management plan
  • B. Risk management plan
  • C. Risk register
  • D. Enterprise environmental factors

正解:D

解説:
Explanation/Reference:
Explanation:
Enterprise environmental factor is not an input to the quantitative risk analysis process. The five inputs to the perform quantitative risk analysis process are: risk register, risk management plan, cost management plan, schedule management plan, and organizational process assets.
Incorrect Answers:
A, C, D: These are the valid inputs to the perform quantitative risk analysis process.


質問 # 437
Which of the following are parts of SWOT Analysis?
Each correct answer represents a complete solution. (Choose four.)

  • A. Strengths
  • B. Tools
  • C. Threats
  • D. Weaknesses
  • E. Opportunities

正解:A、C、D、E

解説:
Section: Volume D
Explanation:
SWOT analysis is a strategic planning method used to evaluate the Strengths, Weaknesses, Opportunities, and Threats involved in a project or in a business venture. It involves specifying the objective of the business venture or project and identifying the internal and external factors that are favorable and unfavorable to achieving that objective. The technique is credited to Albert Humphrey, who led a research project at Stanford University in the 1960s and 1970s using data from Fortune 500 companies.
Incorrect Answers:
B: Tools are not the parts of SWOT analysis.


質問 # 438
Natural disaster is BEST associated to which of the following types of risk?

  • A. Short-term
  • B. Long-term
  • C. Discontinuous
  • D. Large impact

正解:C

解説:
Explanation/Reference:
Explanation:
Natural disaster can be a long-term or short-term and can have large or small impact on the company.
However, as the natural disasters are unpredictable and infrequent, they are best considered as discontinuous.
Incorrect Answers:
A: Natural disaster can be a short-term, but it is not the best answer.
B: Natural disaster can be a long-term, but it is not the best answer.
D: Natural disaster can be of large impact depending upon its nature, but it is not the best answer.


質問 # 439
Which of the following would be a risk practitioner's BEST recommendation upon learning of an updated cybersecurity regulation that could impact the organization?

  • A. Perform a gap analysis
  • B. Conduct system testing
  • C. Update security policies
  • D. Implement compensating controls

正解:A


質問 # 440
Which of the following provides an organization with the MOST insight with regard to operational readiness associated with risk?

  • A. Self-assessment of capabilities
  • B. Benchmarking against industry standards
  • C. Minutes of the enterprise risk committee meetings
  • D. Capability maturity assessment results

正解:A


質問 # 441
Which of the following is the PRIMARY reason for a risk practitioner to use global standards related to risk management?

  • A. To identify gaps in risk management practices
  • B. To continuously improve risk management processes
  • C. To build an organizational risk-aware culture
  • D. To comply with legal and regulatory requirements

正解:B

解説:
Section: Volume D
Explanation


質問 # 442
Due to a change in business processes, an identified risk scenario no longer requires mitigation. Which of the following is the MOST important reason the risk should remain in the risk register?

  • A. To support regulatory requirements
  • B. To track historical risk assessment results
  • C. To monitor for potential changes to the risk scenario
  • D. To prevent the risk scenario in the current environment

正解:C


質問 # 443
After mapping generic risk scenarios to organizational security policies, the NEXT course of action should be to:

  • A. reduce the number of risk scenarios to a manageable set.
  • B. perform a risk analysis on the risk scenarios.
  • C. record risk scenarios in the risk register for analysis.
  • D. validate the risk scenarios for business applicability.

正解:D


質問 # 444
The best way to test the operational effectiveness of a data backup procedure is to:

  • A. conduct an audit of files stored offsite
  • B. demonstrate a successful recovery from backup files
  • C. inspect a selection of audit trails and backup logs
  • D. interview employees to compare actual with expected procedures

正解:B

解説:
Section: Volume D


質問 # 445
Marie has identified a risk event in her project that needs a mitigation response. Her response actually creates a new risk event that must now be analyzed and planned for. What term is given to this newly created risk event?

  • A. Infinitive risk
  • B. is incorrect. Populated risk event is not a valid project management term.
  • C. Residual risk
  • D. is incorrect. A residual risk event is similar to a secondary risk, but is often small in
    probability and impact, so it may just be accepted.
  • E. Populated risk
  • F. Secondary risk
  • G. Explanation:
    Secondary risks are the risks that come about as a result of implementing a risk response. This
    new risk event must be recorded, analyzed, and planned for management.

正解:F

解説:
is incorrect. Infinitive risk is not a valid project management term.


質問 # 446
......

無料CRISC別格な問題集をダウンロード:https://www.goshiken.com/ISACA/CRISC-mondaishu.html

CRISC問題集で2023年最新のISACA試験問題:https://drive.google.com/open?id=13_n16AcmQZzFQ17pNKWlMe75jEEsGI8C