[2026年08月20日] 究極のCRISC準備ガイド!無料最新のISACA練習テスト問題集
今すぐゲットせよ!高評価ISACA CRISC試験問題集
CRISC認定は、リスク管理と情報セキュリティに関する個人の専門知識を示す貴重な指定です。それは雇用主から高く評価されており、情報技術分野での雇用機会の増加と給与の進歩につながる可能性があります。
CRISC認定は、情報システムの専門家に教育、擁護、および認定を提供するグローバルな組織である情報システム監査および制御協会(ISACA)によって提供されます。この認定は世界中で認識されており、ITリスク管理と情報セキュリティに取り組んでいる専門家にとって貴重な資産です。認定は3年間有効であり、個人は認定を維持するために毎年20時間の継続教育を完了する必要があります。
質問 # 101
Which of the following will be the GREATEST concern when assessing the risk profile of an organization?
- A. The risk profile was not updated after a recent incident
- B. The risk profile was last reviewed two years ago.
- C. The risk profile was developed without using industry standards.
- D. The risk profile does not contain historical loss data.
正解:B
解説:
The greatest concern when assessing the risk profile of an organization is that the risk profile was last
reviewed two years ago. A risk profile is a snapshot of the current risk exposure and appetite of the
organization, based on the identification, analysis, and evaluation of the risks that could affect the
achievement of the organization's objectives. A risk profile should be reviewed and updated regularly, atleast
annually, or whenever there are significant changes in the internal or external environment, such as new
projects, strategies, regulations, or incidents. A risk profile that was last reviewed two years ago may not
reflect the current risk situation and status of the organization, and may lead to inaccurate or incomplete risk
assessment and response. The risk profile not being updated after a recent incident, the risk profile being
developed without using industry standards, and the risk profile not containing historical loss data are also
concerns, but they are not as critical as the risk profile being outdated. References = CRISC Review Manual,
6th Edition, ISACA, 2015, page 48.
質問 # 102
Which among the following is the BEST reason for defining a risk response?
- A. To ensure that the residual risk is within the limits of the risk appetite and tolerance
- B. To mitigate risk
- C. To eliminate risk from the enterprise
- D. To overview current status of risk
正解:A
解説:
Section: Volume C
Explanation:
The purpose of defining a risk response is to ensure that the residual risk is within the limits of the risk appetite and tolerance of the enterprise. Risk response is based on selecting the correct, prioritized response to risk, based on the level of risk, the enterprise's risk tolerance and the cost or benefit of the particular risk response option.
Incorrect Answers:
A: Risk cannot be completely eliminated from the enterprise.
C: This is not a valid answer.
D: Mitigation of risk is itself the risk response process, not the reason behind this.
質問 # 103
What can be determined from the risk scenario chart?
- A. Risk treatment options
- B. Relative positions on the risk map
- C. Capability of enterprise to implement
- D. The multiple risk factors addressed by a chosen response
正解:B
質問 # 104
Which of the following is the GREATEST benefit for an organization with a strong risk awareness culture?
- A. Discussing and managing risk as a team
- B. Reducing the involvement by senior management
- C. Using more risk specialists
- D. Reducing the need for risk policies and guidelines
正解:A
解説:
Discussing and managing risk as a team is the greatest benefit for an organization with a strong risk awareness culture, as it enables the organization to share and communicate the risk information and knowledge among all the stakeholders, and to collaborate and coordinate the risk management activities and responsibilities.
Discussing and managing risk as a team can also help to foster a positive and proactive attitude toward risk, and to align the risk management process with the organization's strategy and objectives. Discussing and managing risk as a team can also enhance the risk governance and accountability, and support the risk learning and improvement. References = Most Asked CRISC Exam Questions and Answers. CRISC: Certified in Risk
& Information Systems Control Sample Questions, Question 252. ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, Question 252. CRISC by Isaca Actual Free Exam Q&As, Question 9.
質問 # 105
Which of the following risk register updates is MOST important for senior management to review?
- A. Extending the date of a future action plan by two months
- B. Retiring a risk scenario no longer used
- C. Changing a risk owner
- D. Avoiding a risk that was previously accepted
正解:D
解説:
A risk register is a document that records and tracks the information and status of the identified risks and their
responses. It includes the risk description, category, source, cause, impact, probability, priority, response,
owner, action plan, status, etc.
A risk register update is a change or modification to the information or status of the risks and their responses
in the risk register. It may be triggered by the occurrence or resolution of a risk event, the identification or
evaluation of a new or emerging risk, the implementation or completion of a risk response, the monitoring or
review of the risk performance, etc.
The most important risk register update for senior management to review is avoiding a risk that was
previously accepted, which means that the organization has decided to eliminate or withdraw from the risk
exposure or activity that may cause the risk, instead of tolerating or retaining the risk as before. This may
indicate a significant change in the organization's risk appetite, strategy, objectives, or environment, and it
may have a major impact on the organization's performance and value.
The other options are not the most important risk register updates for senior management to review, because
they do not indicate a significant change or impact on the organization's risk profile or performance.
Extending the date of a future action plan by two months means that the organization has postponed the
implementation or completion of the planned actions or measures to address the risk, due to some reasons or
constraints. This may indicate a delay or deviation from the expected or desired risk outcome, but it may not
have a major impact on the organization's performance and value, unless the risk is very urgent or critical.
Retiring a risk scenario no longer used means that the organization has removed or discarded the risk scenario
that is no longer relevant or applicable to the organization's objectives or operations, due to some changes or
developments. This may indicate a reduction or improvement in the organization's risk exposure or level, but
it may not have a major impact on the organization's performance and value, unless the risk scenario was very
significant or influential.
Changing a risk owner means that the organization has assigned or transferred the responsibility and
accountability for the risk and its response to a different person or role, due to some reasons or circumstances.
This may indicate a change or improvement in the organization's risk governance or culture, but it may not
have a major impact on the organization's performance and value, unless the risk owner was very ineffective
or inappropriate. References =
ISACA, CRISC Review Manual, 7th Edition, 2022, pp. 19-20, 23-24, 27-28, 31-32, 40-41, 47-48, 54-55, 58-
59, 62-63
ISACA, CRISC Review Questions, Answers & Explanations Database, 2022, QID 160
CRISC Practice Quiz and Exam Prep
質問 # 106
An organization is making significant changes to an application. At what point should the application risk
profile be updated?
- A. During backlog scheduling
- B. After user acceptance testing (UAT)
- C. When reviewing functional requirements
- D. Upon release to production
正解:C
解説:
The application risk profile should be updated when reviewing functional requirements. This will help to
identify and assess the potential risks that may arise from the changes to the application, and to plan and
implement appropriate risk responses. Updating the application risk profile at this stage will also help to
ensure that the changes are aligned with the organization's objectives, policies, and standards, and that they
meet the stakeholders' expectations and needs. Updating the application risk profile after user acceptance
testing, upon release to production, or during backlog scheduling are not the best points to update the risk
profile, as they may be too late or too early to capture the relevant risks and their impacts. References = Risk
and Information Systems Control Study Manual, 7th Edition, Chapter 2, Section 2.1.1.1, page 511
1: ISACA Certified in Risk and Information Systems Control (CRISC) Exam Guide, Answer to Question
655.
質問 # 107
You work as a project manager for BlueWell Inc. You have declined a proposed change request because of the risk associated with the proposed change request. Where should the declined change request be documented and stored?
- A. Lessons learned
- B. Project document updates
- C. Explanation:
The change request log records the status of all change requests, approved or declined. The change request log is used as an account for change requests and as a means of tracking their disposition on a current basis. The change request log develops a measure of consistency into the change management process. It encourages common inputs into the process and is a common estimation approach for all change requests. As the log is an important component of project requirements, it should be readily available to the project team members responsible for project delivery. It should be maintained in a file with read-only access to those who are not responsible for approving or disapproving project change requests. - D. Change request log
- E. Project archives
正解:D
解説:
is incorrect. Lessons learned are not the correct place to document the status of a declined, or approved, change request. Answer:B is incorrect. The project archive includes all project documentation and is created through the close project or phase process. It is not the best choice for this option D is incorrect. The project document updates is not the best choice for thisbe fleshed into the project documents, but the declined changes are part of the change request log.
質問 # 108
Which of the following is the MOST effective way to reduce potential losses due to ongoing expense fraud?
- A. Conduct fraud prevention awareness training.
- B. Implement user access controls
- C. Perform regular internal audits
- D. Develop and communicate fraud prevention policies
正解:D
解説:
Developing and communicating fraud prevention policies is the most effective way to reduce potential losses
due to ongoing expense fraud because it creates a culture of integrity and accountability, sets clear
expectations and consequences for employees, and deters fraudulent behavior. Implementing user access
controls, performing regular internal audits, and conducting fraud prevention awareness training are also
important controls, but they are more reactive and detective than preventive. References = Risk and
Information Systems Control Study Manual, Chapter 4, Section 4.3.2, page 4-26.
質問 # 109
Which of the following BEST indicates that an organization's disaster recovery plan (DRP) will mitigate the risk of the organization failing to recover from a major service disruption?
- A. A record of quarterly disaster recovery tests
- B. An experienced and certified disaster recovery team
- C. A defined recovery point objective (RPO)
- D. A comprehensive list of critical applications
正解:A
解説:
Frequent and well-documented testing of the DRP demonstrates the plan's effectiveness and readiness to handle real disruptions.
Reference:CRISC Manual - Domain 3, Slide 552-554
質問 # 110
A business impact analysis (BIA) enables an organization to determine appropriate IT risk mitigation actions by:
- A. identifying IT assets that support key business processes.
- B. validating whether critical IT risk has been addressed.
- C. defining the requirements for an IT risk-aware culture
- D. assigning accountability for IT risk to business functions.
正解:A
質問 # 111
Which of the following is the PRIMARY reason for sharing risk assessment reports with senior stakeholders?
- A. To support decision-making for risk response
- B. To hold risk owners accountable for risk action plans
- C. To enable senior management to compile a risk profile
- D. To secure resourcing for risk treatment efforts
正解:A
解説:
The primary reason for sharing risk assessment reports with senior stakeholders is to support decision-making
for risk response. Risk assessment reports are documents that summarize the results of the risk assessment
process, such as the risk sources, causes, impacts, likelihood, and levels. Risk assessment reports also provide
recommendations for risk response options, such as avoiding, reducing, transferring, or accepting the risk.
Sharing risk assessment reports with senior stakeholders helps to inform them of the current risk situation, and
to solicit their input, feedback, or approval for the risk response actions. The other options are not the primary
reason for sharing risk assessment reports, although they may be secondary reasons or
outcomes. References = Risk and Information Systems Control Study Manual, Chapter 4, Section 4.2.1, page
4-13.
質問 # 112
Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?
- A. Implement segregation of duties
- B. Enforce the use of digital signatures
- C. Enforce an internal data access policy
- D. Apply single sign-on for access control
正解:D
解説:
Section: Volume D
質問 # 113
Establishing and organizational code of conduct is an example of which type of control?
- A. Compensating
- B. Directive
- C. Detective
- D. Preventive
正解:B
質問 # 114
Which of the following statements is NOT true regarding the risk management plan?
- A. Explanation:
The risk management plan details how risk management processes will be implemented, monitored, and controlled throughout the life of the project. The risk management plan does not include responses to risks or triggers. Responses to risks are documented in the risk register as part of the Plan Risk Responses process. - B. The risk management plan is an input to all the remaining risk-planning processes.
- C. The risk management plan is an output of the Plan Risk Management process.
- D. The risk management plan includes thresholds, scoring and interpretation methods, responsible parties, and budgets.
- E. The risk management plan includes a description of the risk responses and triggers.
正解:E
解説:
D, and B are incorrect. These all statements are true for risk management plan. The risk management plan details how risk management processes will be implemented, monitored, and controlled throughout the life of the project. It includes thresholds, scoring and interpretation methods, responsible parties, and budgets. It also act as input to all the remaining risk-planning processes.
質問 # 115
Which of the following is the GREATEST benefit of incorporating IT risk scenarios into the corporate risk register?
- A. The organization-wide control budget is expanded.
- B. Corporate incident escalation protocols are established.
- C. Risk appetite cascades to business unit management
- D. Exposure is integrated into the organization's risk profile.
正解:D
解説:
* IT risk scenarios are hypothetical situations that describe the sources, causes, and consequences of IT-related risks, and the potential impacts on the organization's objectives, performance, and value creation12.
* A corporate risk register is a document that records and tracks the significant risks that the organization faces, and the responses and actions that are taken to address them34.
* The greatest benefit of incorporating IT risk scenarios into the corporate risk register is that exposure is integrated into the organization's risk profile, which is a comprehensive and integrated representation of the risks that may affect the organization's objectives, performance, and value creation56.
* Exposure is integrated into the organization's risk profile means that the organization has a complete and consistent view of the IT risk landscape, and the potential impacts and interdependencies of IT risks on other types of risks, such as financial, operational, strategic, or reputational risks56.
* Exposure is integrated into the organization's risk profile also means that the organization can make informed and balanced decisions on the risk responses and actions, and allocate the appropriate resources and priorities to the IT risk management and control processes56.
* The other options are not the greatest benefit, but rather possible outcomes or consequences of incorporating IT risk scenarios into the corporate risk register. For example:
* Corporate incident escalation protocols are established is an outcome of incorporating IT risk scenarios into the corporate risk register that indicates the organization has defined and implemented the procedures and mechanisms for reporting and resolving IT-related incidents, and for escalating them to the appropriate authorities or levels when necessary78. However, this outcome does not measure or reflect the exposure or the risk profile of the organization, which may depend on other factors such as the frequency, severity, or complexity of the incidents78.
* Risk appetite cascades to business unit management is a consequence of incorporating IT risk scenarios into the corporate risk register that indicates the organization has communicated and aligned the risk appetite, which is the amount and type of risk that the organization is willing to accept or pursue, to the business unit management, who are responsible for executing the risk strategy and objectives at the operational level . However, this consequence does not indicate or imply the exposure or the risk profile of the organization, which may vary depending on the context, environment, or stakeholder expectations .
* The organization-wide control budget is expanded is an outcome of incorporating IT risk scenarios into the corporate risk register that indicates the organization has increased the amount of resources and funds that are allocated to the control processes, which are the procedures and activities that aim to ensure the effectiveness and efficiency of the organization's operations, the reliability of its information, and the compliance with its policies and regulations . However, this outcome does not affect or determine the exposure or the risk profile of the organization, which is independent of the control budget . References =
* 1: IT Risk Scenarios - Morland-Austin3
* 2: Risk Scenarios Toolkit, ISACA, 2019
* 3: Risk Register Template and Examples | Prioritize and Manage Risk1
* 4: Risk Register Examples for Cybersecurity Leaders4
* 5: Risk IT Framework, ISACA, 2009
* 6: IT Risk Management Framework, University of Toronto, 2017
* 7: Security Incident Reporting and Response, University of Toronto, 2017
* 8: Security Incident Reporting and Response, ISACA, 2019
* : Risk Appetite: Linking Strategy, Risk and Performance, ISACA, 2012
* : Risk Appetite and Tolerance, ISACA Journal, Volume 4, 2013
* : The Control Process | Principles of Management2
* : Control Management: What it is + Why It's Essential | Adobe Workfront5
質問 # 116
Periodically reviewing and updating a risk register with details on identified risk factors PRIMARILY helps to:
- A. aggregate risk scenarios identified across different business units
- B. build a threat profile of the organization for management review
- C. minimize the number of risk scenarios for risk assessment
- D. provide a current reference to stakeholders for risk-based decisions
正解:D
解説:
Section: Volume D
Explanation/Reference:
質問 # 117
Who is accountable for risk treatment?
- A. Risk owner
- B. Business process owner
- C. Enterprise risk management team
- D. Risk mitigation manager
正解:B
質問 # 118
......
合格率取得する秘訣はCRISC認定試験エンジンPDF:https://www.goshiken.com/ISACA/CRISC-mondaishu.html
CRISC試験問題集で合格できるには更新されたテスト問題集:https://drive.google.com/open?id=17YcyENpWmSDqa-XFUudePVBmlbUuVtjK