[2025年05月]更新のGRCP試験問題と有効なGRCP問題集PDF [Q91-Q114]

Share

[2025年05月]更新のGRCP試験問題と有効なGRCP問題集PDF

GRCPブレーン問題集学習ガイドにはヒントとコツで試験合格を目指そう


OCEG GRCP 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Perform Component: This subsection emphasizes executing GRC activities and implementing controls to manage risks effectively. A key skill assessed is the ability to perform risk assessments and implement necessary actions.
トピック 2
  • GRC Key Concepts: This section of the exam measures the skills of GRC Governance Professionals and covers essential concepts related to reliably achieving objectives, addressing uncertainty, and acting with integrity. It also includes an understanding of the Lines of Accountability™ and the Integrated Action & Control Model™, which provide frameworks for governance and risk management. A key skill assessed is the ability to apply these concepts to enhance organizational performance.
トピック 3
  • Learn Component: This subsection focuses on the learning aspect of the GRC Capability Model, emphasizing foundational knowledge necessary for effective governance practices. A key skill assessed is understanding basic GRC principles to support strategic initiatives.
トピック 4
  • Align Component: This subsection covers aligning GRC practices with organizational objectives and regulatory requirements. A vital skill evaluated is the ability to integrate GRC processes into business operations effectively.

 

質問 # 91
What is the objective of improving actions and controls to address root causes and weaknesses associated with unfavorable events?

  • A. To ensure that future events of similar nature are less likely to occur and are less harmful.
  • B. To provide incentives to employees for favorable conduct.
  • C. To escalate incidents for investigation and identify them as in-house or external.
  • D. To determine if, when, how, and what to disclose regarding unfavorable events.

正解:A

解説:
The primary objective of improving actions and controls is to address root causes and weaknesses to prevent the recurrence of unfavorable events and mitigate their impact.
Key Objectives:
Reduce the likelihood of similar unfavorable events occurring in the future.
Minimize the harm caused by such events if they do occur.
Steps to Address Root Causes:
Conduct thorough investigations to identify the underlying issues.
Enhance or implement new controls to address identified gaps.
Why Other Options Are Incorrect:
A: Escalating incidents is part of incident management, not the improvement of controls.
B: Incentives promote favorable conduct but do not address root causes.
C: Disclosure decisions are a separate consideration from improving controls.
Reference:
COSO ERM Framework: Highlights addressing root causes to strengthen controls.
OCEG GRC Capability Model: Recommends continuous improvement of actions and controls.


質問 # 92
What is the primary goal of defining an education plan?

  • A. To develop a plan that is tailored to the specific needs of each audience.
  • B. To implement Bloom's Taxonomy in the education program.
  • C. To create a helpline for anonymous reporting and asking questions.
  • D. To evaluate the current skill level of the workforce.

正解:A

解説:
The primary goal of defining an education plan is to develop a tailored approach that addresses the specific learning needs of various audiences within the organization.
Key Aspects of an Education Plan:
Identify target audiences (e.g., roles, teams, departments).
Tailor content to align with the responsibilities, risks, and challenges relevant to each audience.
Ensure that learning objectives meet organizational priorities and compliance requirements.
Why Other Options Are Incorrect:
A: Evaluating skill levels is a step in the planning process, not the ultimate goal.
C: Helplines are supplemental to the education plan but are not the primary focus.
D: Bloom's Taxonomy can guide learning strategies but is not the goal of the education plan.
Reference:
OCEG GRC Capability Model: Highlights the importance of tailored education plans.
ISO 37001 (Anti-Bribery Management Systems): Recommends customized training for risk mitigation.


質問 # 93
What is the importance of gaining subordinate buy-in when setting the direction for an organization?

  • A. To help subordinate units understand and define ways to contribute to the organization's success, reducing the risk of strategic misalignment and engagement decay
  • B. To establish the organization's brand identity and image without conflict
  • C. To determine the organization's expansion and growth plans without internal conflict
  • D. To ensure that the organization has sufficient staff to take on defined tasks

正解:A

解説:
Gaining subordinate buy-in is critical to ensure organizational alignment, effective execution, and long-term success. Without buy-in, there is a risk of disengagement and misalignment, which can undermine strategic objectives.
* Importance of Buy-In:
* Understanding and Contribution:Subordinate units need to understand how their actions contribute to organizational success.
* Strategic Alignment:Helps ensure that all units are aligned with the organization's goals and priorities.
* Engagement:Increases employee commitment and reduces the risk of disengagement or
"engagement decay."
* Why Option D is Correct:
* Option D captures the importance of ensuring that subordinates understand their role and remain aligned and engaged.
* Options A and B are unrelated to subordinate buy-in and focus on external aspects like growth or branding.
* Option C (staffing) is a logistical concern and not directly related to the concept of buy-in.
* Relevant Frameworks and Guidelines:
* OCEG Principled Performance Framework:Recommends fostering engagement and alignment to support principled performance.
* ISO 30414 (Human Capital Reporting):Encourages employee engagement and alignment as part of workforce planning.
In summary, gaining subordinate buy-in helps subordinate units understand their contributions, align with strategic goals, and maintain engagement, reducing the risk of misalignment and disengagement.


質問 # 94
What is the importance of gaining subordinate buy-in when setting the direction for an organization?

  • A. To help subordinate units understand and define ways to contribute to the organization's success, reducing the risk of strategic misalignment and engagement decay
  • B. To establish the organization's brand identity and image without conflict
  • C. To determine the organization's expansion and growth plans without internal conflict
  • D. To ensure that the organization has sufficient staff to take on defined tasks

正解:A

解説:
Gaining subordinate buy-in is critical to ensure organizational alignment, effective execution, and long-term success. Without buy-in, there is a risk of disengagement and misalignment, which can undermine strategic objectives.
Importance of Buy-In:
Understanding and Contribution: Subordinate units need to understand how their actions contribute to organizational success.
Strategic Alignment: Helps ensure that all units are aligned with the organization's goals and priorities.
Engagement: Increases employee commitment and reduces the risk of disengagement or "engagement decay." Why Option D is Correct:
Option D captures the importance of ensuring that subordinates understand their role and remain aligned and engaged.
Options A and B are unrelated to subordinate buy-in and focus on external aspects like growth or branding.
Option C (staffing) is a logistical concern and not directly related to the concept of buy-in.
Relevant Frameworks and Guidelines:
OCEG Principled Performance Framework: Recommends fostering engagement and alignment to support principled performance.
ISO 30414 (Human Capital Reporting): Encourages employee engagement and alignment as part of workforce planning.
In summary, gaining subordinate buy-in helps subordinate units understand their contributions, align with strategic goals, and maintain engagement, reducing the risk of misalignment and disengagement.


質問 # 95
The difference between the current skill level and the target skill level is referred to as?

  • A. Skill Gap
  • B. Learning Objective
  • C. Educational Needs
  • D. Skill Set

正解:A


質問 # 96
What is the purpose of implementing policies within an organization?

  • A. To have individual regulation-specific policies instead of a generic Code of Conduct.
  • B. To reduce the need for defined procedures and guidelines within the organization.
  • C. To set clear expectations of conduct for key internal stakeholders and the extended enterprise.
  • D. To meet regulatory requirements and establish compliance.

正解:C

解説:
Policiesserve as essential tools within an organization to set clear expectations for behavior, actions, and decision-making.
* Primary Purpose:
* Establishclear expectations of conductfor employees, contractors, vendors, and other stakeholders.
* Provide guidance on acceptable behavior and operational standards across the organization.
* Significance:
* Policies align stakeholder actions with organizational values and objectives.
* They act as a foundation for procedures, controls, and compliance initiatives.
* Why Other Options Are Incorrect:
* B: While policies support compliance, their scope extends beyond regulatory requirements.
* C: Policies do not eliminate the need for procedures; they complement them.
* D: Generic policies like Codes of Conduct are essential, even with regulation-specific policies.
References:
* ISO 37301 (Compliance Management Systems): Emphasizes policies for setting conduct expectations.
* COSO ERM Framework: Highlights policies as governance tools for consistent behavior.


質問 # 97
Why is it important for an organization to sense and analyze changes in context within the LEARN component?

  • A. To determine necessary changes to the organization and to understand which changes are significant and which are distractions
  • B. To comply with legal and regulatory requirements related to governance and risk management
  • C. To ensure that the organization's financial statements are accurate and up to date
  • D. To evaluate the effectiveness of the organization's risk management framework

正解:A

解説:
The LEARN component, as referenced in GRC principles (such as the OCEG Principled Performance Framework), emphasizes the need for organizations to continuously sense, analyze, and act upon changes in their external and internal contexts. This capability allows organizations to adapt proactively, ensuring relevance, compliance, and performance.
Why Sensing and Analyzing Changes in Context is Critical:
External Context: Changes in regulations, market trends, competitive dynamics, and societal expectations require organizations to adjust strategies and operations.
Internal Context: Shifts in organizational priorities, culture, or internal capabilities can affect alignment with goals and objectives.
Purpose of Sensing and Analyzing Changes:
To identify necessary adjustments to strategies, policies, and operations based on significant changes.
To differentiate meaningful changes (those requiring action) from distractions that could waste resources or create unnecessary disruption.
Why Option D is Correct:
Sensing and analyzing context is primarily about determining what changes matter to the organization and what actions are needed.
Options A, B, and C are narrower in scope and do not address the broader importance of prioritizing and filtering changes to drive organizational alignment and responsiveness.
Relevant Frameworks and Guidelines:
OCEG Principled Performance Framework: Highlights the importance of "LEARN" as a key component in responding to context changes effectively.
ISO 31000 (Risk Management): Recommends monitoring and reviewing external and internal contexts to adjust risk strategies.
In summary, the ability to sense and analyze changes in context enables organizations to make informed decisions about what adjustments are necessary to maintain alignment with their objectives, while filtering out distractions that do not contribute to performance or compliance.


質問 # 98
What is the purpose of proactively developing communication channels within an organization?

  • A. To limit communication to a single channel for simplicity and cost savings.
  • B. To ensure that the channels are available before they are needed.
  • C. To formalize the process so that employees know that anything they communicate will be kept in records.
  • D. To ensure that all communication is delivered in written form only.

正解:B

解説:
Proactively developing communication channels ensures that they areestablished, tested, and functional before a critical need arises.
* Purpose:
* Facilitates timely and effective communication during both routine and emergency situations.
* Ensures that communication processes do not face delays due to unprepared or unavailable channels.
* Benefits:
* Increases efficiency by having predefined methods for sharing information.
* Promotes clear and reliable communication across all organizational levels.
* Why Other Options Are Incorrect:
* A: Communication channels should accommodate multiple formats (written, verbal, digital, etc.).
* C: Record-keeping is important but not the primary purpose of proactive channel development.
* D: Limiting communication to a single channel reduces flexibility and can hindereffectiveness.
References:
* OCEG GRC Capability Model: Highlights the importance of proactive communication planning.
* ISO 31000 (Risk Management): Discusses the role of communication in risk and operational management.


質問 # 99
What does resilience measure in the context of the ALIGN component?

  • A. Resilience measures the organization's ability to maintain a positive reputation in the face of public scrutiny
  • B. Resilience measures the durability and longevity of the organization's physical assets
  • C. Resilience measures the organization's ability to recover from financial losses and setbacks
  • D. Resilience measures the ability to withstand stress and the capability to align after stress

正解:D

解説:
In theALIGN component, resilience refers to theorganization's ability to adapt, recover, and continue aligning with its objectivesafter encountering stress or disruptions. Resilience is crucial for ensuring that the organization can remain operational and focused on its mission despite challenges.
Key Elements of Resilience in ALIGN:
* Withstanding Stress:
* The organization must maintain its stability and operational capabilities during adverse conditions, such as economic downturns, cyberattacks, or natural disasters.
* Realignment After Stress:
* Resilience involves more than surviving stress-it requires the ability to realign objectives, strategies, and operations to remain effective in achieving goals.
* Importance in ALIGN:
* The ALIGN component emphasizes strategic alignment, and resilience ensures that an organization can restore alignment and maintain progress despite disruptions.
Why Option C is Correct:
Resilience measures an organization's ability towithstand stressandrealign after stress. This definition directly aligns with the role of resilience in the ALIGN component.
Why the Other Options Are Incorrect:
* A: Resilience is not limited to physical assets; it encompasses the organization's overall adaptability.
* B: While financial recovery is part of resilience, the ALIGN context covers broader stressors and alignment capabilities.
* D: Maintaining reputation is important, but resilience in ALIGN focuses on operational and strategic realignment after stress.
References and Resources:
* COSO ERM Framework- Discusses resilience as a key factor in aligning strategy with risk management.
* ISO 22316:2017- Security and resilience guidelines.
* NIST Cybersecurity Framework (CSF)- Highlights resilience in the face of operational disruptions.


質問 # 100
Which category of actions & controls in the IACM includes formal statements and rules about organizational intentions and expectations?

  • A. Policy
  • B. Information
  • C. People
  • D. Technology

正解:A

解説:
The Policy category in the IACM encompasses formal statements, rules, and guidelines that articulate the organization's intentions and expectations.
Role of Policies:
Set boundaries and guidelines for behavior and decision-making.
Ensure consistency in actions and alignment with organizational goals.
Examples:
Code of conduct.
Data privacy and security policies.
Why Other Options Are Incorrect:
A: Information deals with data and communication, not formal statements.
B: People refer to human elements like roles and responsibilities.
C: Technology focuses on tools and systems.
References:
OCEG IACM Framework: Highlights the role of policies in formalizing organizational expectations.


質問 # 101
In the context of uncertainty, what is the difference between likelihood and impact?

  • A. Likelihood is the chance of an event occurring after controls are put in place, while impact measures the economic and non-economic consequences of the event.
  • B. Likelihood is a measure of the chance of an event occurring, while impact measures the economic and non-economic consequences of the event.
  • C. Likelihood is a measure of the chance of an event occurring, while impact is the location of the event within the organization.
  • D. Likelihood is a measure of the chance of an event occurring, while impact is the category or type of risk or reward from the event.

正解:B

解説:
Likelihood and impact are key factors in evaluating uncertainty, especially in the context of risk and reward.
Likelihood:
Measures the probability or chance of an event occurring.
Example: The likelihood of a data breach based on historical trends.
Impact:
Measures the economic and non-economic consequences of the event.
Examples: Financial losses, reputational damage, or operational disruptions.
Why Other Options Are Incorrect:
A: Impact refers to consequences, not the location of the event.
B: Impact is not limited to categories; it involves actual consequences.
D: Likelihood considers controls but is not exclusively post-control.
Reference:
ISO 31000 (Risk Management): Defines likelihood and impact as fundamental components of risk assessment.
COSO ERM Framework: Emphasizes assessing both likelihood and impact in risk evaluation.


質問 # 102
In the context of GRC, what is the importance of aligning objectives throughout the organization?

  • A. It eliminates the need for excessive communication and collaboration between different departments within the organization.
  • B. It ensures that superior-level objectives cascade to subordinate units and that subordinate units contribute to the most important objectives and priorities of the organization.
  • C. It enables the governing authority to only focus on the highest-level objectives that are tied to financial outcomes.
  • D. It frees the organization to focus solely on short-term financial performance.

正解:B

解説:
Aligning objectives across the organization ensures coherence and coordination in achieving strategic goals.
Cascade of Objectives:
High-level organizational objectives are broken down into actionable goals for departments and teams.
Ensures every part of the organization contributes to overarching priorities.
Integration and Collaboration:
Departments work together to achieve shared goals, fostering synergy and reducing silos.
Strategic Alignment:
Alignment ensures that all efforts are directed toward achieving the organization's mission and vision effectively.
Why Other Options Are Incorrect:
B: Alignment supports all objectives, not just financial outcomes.
C: It balances short-term and long-term goals.
D: Alignment necessitates communication and collaboration.
Reference:
OCEG GRC Capability Model: Stresses the importance of objective alignment for principled performance.
COSO ERM Framework: Highlights the role of strategic alignment in achieving objectives.


質問 # 103
Which are some considerations to keep in mind when establishing a communication framework?

  • A. Using only one communication channel for all types of messages so that sending and receipt can be tracked.
  • B. Reducing the frequency of communication to avoid information overload.
  • C. Ensuring external communications are always formal while most internal communication can be more informal.
  • D. Selecting the appropriate sender, recipient, intention, message, cadence, and channel.

正解:D

解説:
Establishing a communication framework involves defining clear and effective processes that consider the sender, recipient, intention, message, cadence, and channel.
Key Considerations:
Sender and Recipient: Ensuring the right people are involved in the communication process.
Intention: Clearly defining the purpose and goals of the communication.
Message: Crafting a clear and concise message tailored to the audience.
Cadence: Determining the appropriate frequency of communication to maintain engagement without causing overload.
Channel: Selecting the most effective medium for the message (email, meetings, instant messaging, etc.).
Why Other Options Are Incorrect:
A: Reducing frequency without assessing the need may hinder effective communication.
C: Formality depends on the context and audience, not the type of communication.
D: Limiting to one channel reduces flexibility and may not suit all scenarios.
Reference:
OCEG GRC Capability Model: Emphasizes the role of a comprehensive communication framework in achieving objectives.
ISO 31000 (Risk Management): Discusses communication as part of effective risk management practices.


質問 # 104
What is the goal of monitoring improvement initiatives?

  • A. To assess the level of employee satisfaction about the improvement initiatives
  • B. To evaluate the financial impact of the improvement initiatives
  • C. To ensure progress, verify completion, and address any necessary follow-up actions associated with the improvement initiatives
  • D. To determine the need for additional training associated with the improvement initiatives

正解:C

解説:
Monitoring improvement initiatives is a critical step in ensuring the success of continuous improvement efforts. The primary goal is to track progress, confirm that objectives are being met, and address any issues that arise during or after implementation.
Key Goals of Monitoring Improvement Initiatives:
Ensure Progress: Regularly assess whether the initiative is moving forward as planned.
Verify Completion: Confirm that the improvement initiative achieves its intended goals and objectives.
Address Follow-Up Actions: Identify and resolve any issues, obstacles, or additional requirements that arise during implementation.
Why Option C is Correct:
Option C captures the comprehensive goals of monitoring: tracking progress, verifying completion, and addressing follow-ups.
Option A (assessing employee satisfaction) is a subset of improvement monitoring but does not encompass the full purpose.
Option B (evaluating financial impact) is one of many aspects to monitor but is not the primary goal.
Option D (determining training needs) is an important consideration but not the overarching objective of monitoring improvement initiatives.
Relevant Frameworks and Guidelines:
ISO 9001 (Quality Management): Highlights the importance of monitoring and reviewing improvement initiatives to ensure their effectiveness.
COSO ERM Framework: Emphasizes the need to monitor and follow up on initiatives to ensure alignment with organizational objectives.
In summary, the goal of monitoring improvement initiatives is to ensure progress, verify completion, and address follow-up actions, ensuring that initiatives achieve their desired impact and contribute to organizational objectives.


質問 # 105
What is the role of identification criteria?

  • A. Identification criteria are used to focus on priority objectives and results.
  • B. Identification criteria are used to calculate the total budget for the organization based on priority objectives and the number of related obstacles and obligations.
  • C. Identification criteria are used to determine the order in which units undertake identification activities.
  • D. Identification criteria are used to establish the communication channels within the organization regarding opportunities, obstacles, and obligations.

正解:A

解説:
Identification criteria are tools used to guide the identification of elements critical to achieving objectives, such as opportunities, obstacles, and obligations.
Purpose of Identification Criteria:
Focus efforts on priority objectives and results that align with organizational goals.
Streamline the identification process to ensure efficiency and relevance.
Examples:
Criteria may include relevance to strategic objectives, potential impact, and urgency.
Why Other Options Are Incorrect:
A: Criteria are not about sequencing identification activities.
B: They do not directly calculate budgets but may inform resource allocation.
D: Establishing communication channels is a separate organizational function.
Reference:
OCEG GRC Capability Model: Highlights criteria to prioritize objectives and results in identification processes.
ISO 31000 (Risk Management): Discusses criteria for identifying risks and opportunities.


質問 # 106
In the LEARN component, what is the difference between external context and internal context?

  • A. External context represents the operating environment, while internal context represents capabilities and resources
  • B. External context encompasses the organization's mission and vision, while internal context encompasses its values and culture
  • C. External context includes the organization's risk management policies, while internal contextincludes its compliance procedures
  • D. External context refers to the organization's financial performance, while internal context refers to its governance structure

正解:A

解説:
In theLEARN component(used in governance, risk, and compliance frameworks), understanding the external and internal context is crucial for evaluating risks, identifying opportunities, and aligning the organization's objectives with its environment. These contexts provide the foundation for an effective GRC program.
Key Definitions:
* External Context:
* Represents theoperating environmentin which the organization functions.
* Includes external factors such as market conditions, regulations, competition, geopolitical influences, social trends, and economic conditions.
* Example: Changes in regulatory requirements (e.g., GDPR) that affect the organization's operations.
* Internal Context:
* Refers to the organization'scapabilities and resourcesthat influence its ability to achieve objectives.
* Includes factors like organizational structure, culture, technology, financial resources, and workforce skills.
* Example: The availability of resources for implementing new compliance requirements.
Why Option B is Correct:
External context focuses on theoperating environment(external factors such as regulations, competitors, or economic trends), while internal context focuses on the organization'scapabilities and resources(internal factors such as skills, financial capacity, and infrastructure).
Why the Other Options Are Incorrect:
* A: Risk management policies and compliance procedures are internal controls, not contexts.
* C: Financial performance and governance structure are part of internal factors, not distinguishing between external and internal contexts.
* D: Mission and vision are part of strategic planning, and values and culture are internal factors. These do not fully encompass the external and internal contexts as defined in LEARN.
References and Resources:
* ISO 31000:2018- Risk Management Guidelines: Context establishment.
* COSO ERM Framework- Understanding internal and external context for effective risk management.
* NIST RMF- Emphasizes the importance of evaluating both internal and external environments during risk assessment.


質問 # 107
What type of incentives include appreciation, status, and professional development?

  • A. Non-Economic Incentives
  • B. Personal Incentives
  • C. Contractual Incentives
  • D. Economic Incentives

正解:A

解説:
Non-Economic incentivesare non-financial rewards that motivate individuals by offering recognition, career growth, and personal fulfillment.
* Examples of Non-Economic Incentives:
* Appreciation: Public acknowledgment or awards for achievements.
* Status: Titles, promotions, or roles that elevate an individual's standing.
* Professional Development: Opportunities for learning, training, and career advancement.
* Why Other Options Are Incorrect:
* A: Economic incentives involve direct financial rewards.
* B: Contractual incentives pertain to obligations within formal agreements.
* C: Personal incentives focus on individual preferences but are not synonymous with non- economic incentives.
References:
* OCEG GRC Capability Model: Highlights non-economic incentives in promoting employee satisfaction.
* Employee Engagement Strategies: Discuss non-financial motivators like recognition and development.


質問 # 108
What is the difference between an organization's mission and vision?

  • A. The mission is a short-term goal or set of goals, while the vision is a long-term goal or set of goals.
  • B. The mission is an objective that states who the organization serves, what it does, and what it hopes to achieve, while the vision is an aspirational objective that states what the organization aspires to be and why it matters.
  • C. The mission is a financial target, while the vision is a non-financial target.
  • D. The mission is focused on external stakeholders, while the vision is focused on internal stakeholders.

正解:B

解説:
The mission and vision statements serve different but complementary purposes:
Mission:
Definition: Describes the organization's purpose, who it serves, and its core objectives.
Example: "To provide affordable healthcare solutions to underserved communities." Vision:
Definition: Outlines the aspirational future state of the organization and why it matters.
Example: "To be the world's leading provider of sustainable healthcare solutions." Why Other Options Are Incorrect:
A: Both mission and vision address both internal and external stakeholders.
B: Mission and vision are not strictly defined by short-term or long-term timeframes.
D: Neither is restricted to financial or non-financial targets.
Reference:
Balanced Scorecard Framework: Differentiates mission and vision in organizational strategy.
OCEG GRC Capability Model: Explains the alignment of mission and vision with strategic goals.


質問 # 109
In the IACM, what are the two types of Proactive Actions & Controls?

  • A. Prevent/Deter Actions & Controls and Promote/Enable Actions & Controls
  • B. Centralized Actions & Controls and Decentralized Actions & Controls
  • C. Reactive Actions & Controls and Passive Actions & Controls
  • D. Quantitative Actions & Controls and Qualitative Actions & Controls

正解:A

解説:
The two types of Proactive Actions & Controls in the IACM are:
Prevent/Deter Actions & Controls:
Focus on avoiding unfavorable events and reducing risks before they occur.
Example: Implementing security protocols to deter cyberattacks.
Promote/Enable Actions & Controls:
Facilitate the realization of opportunities and favorable outcomes.
Example: Employee training programs to improve productivity.
Why Other Options Are Incorrect:
A: Reactive and passive actions are not proactive by definition.
C: Centralization/decentralization pertains to organizational structure.
D: Quantitative and qualitative are methods, not categories of controls.
Reference:
OCEG IACM Framework: Details types of proactive controls for risk and opportunity management.


質問 # 110
How does the IACM address unfavorable events related to obstacles?

  • A. By focusing on opportunities
  • B. By implementing a flat organizational structure
  • C. By decreasing the ultimate likelihood and impact of harm
  • D. By conducting regular employee satisfaction surveys

正解:C

解説:
The Integrated Actions and Controls Model (IACM) addresses obstacles by reducing the likelihood and impact of harm through effective actions and controls.
Risk Mitigation:
Identify potential obstacles and implement measures to decrease their probability.
Minimize the negative impact of these events if they occur.
Examples:
Strengthening internal controls to prevent fraud.
Enhancing cybersecurity measures to reduce data breach risks.
Why Other Options Are Incorrect:
A: Opportunities relate to positive outcomes, not obstacles.
C: Organizational structure is unrelated to addressing obstacles.
D: Employee satisfaction surveys are not directly tied to managing obstacles.
Reference:
OCEG IACM Framework: Highlights reducing harm as a critical approach to handling obstacles.
ISO 31000 (Risk Management): Supports mitigating likelihood and impact of risks.


質問 # 111
Who are key external stakeholders that may significantly influence an organization?

  • A. Competitors, employees, and board members.
  • B. Marketing agencies, legal advisors, and auditors.
  • C. Customers, shareholders, creditors and lenders, government, and non-governmental organizations.
  • D. Distributors, resellers, and franchisees.

正解:C

解説:
Key external stakeholders include those who have significant influence over the organization's operations, strategy, and outcomes, such ascustomers, shareholders, creditors and lenders, government, and NGOs.
* External Stakeholder Roles:
* Customers: Drive revenue and product/service demand.
* Shareholders: Provide capital and influence strategic decisions.
* Creditors and Lenders: Affect financing and liquidity.
* Government and NGOs: Set regulatory frameworks and advocate for societal priorities.
* Why Other Options Are Incorrect:
* A: Distributors and resellers are part of supply chain stakeholders, not key external influencers.
* B: Employees and board members are internal stakeholders.
* C: Marketing agencies and auditors are third-party service providers, not primary external stakeholders.
References:
* Stakeholder Management Standards (ISO 26000): Discusses key stakeholder identification.
* COSO Framework: Emphasizes the importance of external stakeholder engagement in risk management and governance.


質問 # 112
What is the primary purpose of the ALIGN component in the GRC Capability Model?

  • A. To review and improve the organization's policies and controls and ensure they are aligned to the operations of the business.
  • B. To coordinate the monitoring and evaluation of the organization's governance, risk, and compliance activities.
  • C. To establish communication channels and provide education to stakeholders about how the organization aligns its business operations to their needs.
  • D. To define the direction and objectives of an organization and design an integrated plan to address opportunities, obstacles, and obligations.

正解:D

解説:
TheALIGN componentin theGRC Capability Modelfocuses on setting the organization'sstrategic direction and objectives while ensuring that governance, risk management, and compliance activities are integrated into a cohesive plan.
* Primary Purpose:
* Define organizational direction and objectives.
* Develop an integrated strategy to addressopportunities,obstacles, andobligations.
* Significance of ALIGN:
* ALIGN ensures that organizational efforts are coherent and support long-term goals.
* Provides a roadmap to align processes, controls, and initiatives with the mission and vision.
* Why Other Options Are Incorrect:
* A: Monitoring and evaluation are part of the RESPOND component.
* C: While communication is important, ALIGN focuses on planning and direction, not stakeholder education.
* D: Policy review is part of the EVALUATE component, not ALIGN.
References:
* OCEG GRC Capability Model: Details the ALIGN component's role in strategic planning and integration.
* COSO ERM Framework: Highlights the importance of aligning risk and strategy.


質問 # 113
What does agility in the context of the PERFORM component refer to?

  • A. The capability to manage and resolve conflicts and disputes regarding Perform actions and controls
  • B. The capacity to innovate and develop new ways to implement Perform actions and controls
  • C. The ability to quickly change direction in Perform actions and controls when things change
  • D. The proficiency in building and maintaining relationships with partners and suppliers who must implement Perform actions and controls

正解:C

解説:
In the context of thePERFORM component,agilityrefers to the organization's ability toadapt quickly and effectively to changesin the environment, risks, or circumstances that may impact the implementation of Perform actions and controls. It ensures that the organization remains responsive, resilient, and aligned with its objectives, even when faced with uncertainty or disruptions.
Key Aspects of Agility in PERFORM:
* Quick Adaptation:
* Agility enables the organization to pivot or adjust actions and controls when external or internal changes occur.
* Example: Adjusting cybersecurity controls in response to an emerging threat or vulnerability.
* Flexibility in Execution:
* Agile organizations can modify their Perform processes without significant disruption, ensuring continuity and effectiveness.
* Example: Revising compliance protocols to address sudden regulatory updates.
* Focus on Continuous Improvement:
* Agility supports iterative improvement of actions and controls to maintain alignment with organizational goals and external demands.
* Alignment with GRC Frameworks:
* Frameworks likeCOSO ERMandISO 31000emphasize agility as a critical capability for effective risk and performance management.
Why Option B is Correct:
Agility in the context of the PERFORM component specifically refers to theability to quickly change directionin Perform actions and controls when circumstances or priorities change, ensuring the organization remains effective and aligned.
Why the Other Options Are Incorrect:
* A. Building relationships with partners and suppliers: While collaboration is important,agility focuses on adaptability, not relationship management.
* C. Innovating and developing new ways: Innovation is valuable, but agility is about responding quickly to change, not creating new solutions.
* D. Managing and resolving conflicts: Conflict resolution is a separate capability and not directly tied to agility.
References and Resources:
* COSO ERM Framework- Discusses agility as a key attribute for adapting to change in risk and performance management.
* ISO 31000:2018- Emphasizes the importance of flexibility and responsiveness in risk treatment and performance execution.
* NIST Cybersecurity Framework (CSF)- Highlights the importance of agility in adapting controls to evolving threats.


質問 # 114
......

GRCP試験問題無料PDFダウンロード 最近更新された問題です:https://www.goshiken.com/OCEG/GRCP-mondaishu.html

GRCP認定試験問題集には214練習テスト問題:https://drive.google.com/open?id=1QrX6KQ9NrDBwmebw6Xg1zGLXw0_yWPhD