Which of the following is the MOST important reason to link an effective key control indicator (KCI) to
relevant key risk indicators(KRIs)?
Correct Answer: A
Explanation:
Key control indicators (KCIs) are metrics that measure how well a specific control is performing in
reducing the causes, consequences, or likelihood of a risk1. Key risk indicators (KRIs) are metrics that
measure changes in the risk exposure or the potential impact of a risk2. By linkingan effective KCI to
relevant KRIs, the organization can monitor changes in the risk environment and assess how the
control is influencing the risk level3. This can help the organization to:
Identify emerging or escalating risks and take timely and appropriate actions
Evaluate the effectiveness and efficiency of the control and make improvements if needed
Align the control with the risk appetite and tolerance of the organization
Communicate the risk and control status to stakeholders and regulators
Reference = Risk and Information Systems Control Study Manual, Chapter 6: Risk Response and
Mitigation4
Question 2
While reviewing an organization's monthly change management metrics, a risk practitioner notes
that the number of emergency changes has increased substantially Which of the following would be
the BEST approach for the risk practitioner to take?
Correct Answer: C
Explanation:
According to the CRISC Review Manual, a root cause analysis is a technique that identifies the
underlying causes of an event or a problem. It helps to determine the most effective actions to
prevent or mitigate the recurrence of the event or problem. A root cause analysis is the best
approach for the risk practitioner to take in this scenario, because it will help to understand why the
number of emergency changes has increased substantially and what can be done to address the
issue. The other options are not the best approaches, because they do not address the underlying
causes of the problem. Temporarily suspending emergency changes may disrupt the business
operations and create more risks. Documenting the control deficiency in the risk register is a passive
action that does not resolve the problem. Continuing monitoring change management metrics is an
ongoing activity that does not provide any insight into the problem. Reference = CRISC Review
Manual, 7th Edition, Chapter 3, Section 3.2.4, page 130.
Question 3
An organization plans to implement a new Software as a Service (SaaS) speech-to-text solution
Which of the following is MOST important to mitigate risk associated with data privacy?
Correct Answer: A
Explanation:
Utilizing secure encryption protocols is the most important factor to mitigate risk associated with
data privacy when implementing a new Software as a Service (SaaS) speech-to-text solution, as it
ensures that the data is protected from unauthorized access, interception, or modification during the
transmission and storage in the cloud. Setting up multi-factor authentication for users, approving the
solution architecture by IT, and including a risk transfer clause in the contract are not the most
important factors, as they may not address the data privacy issue, but rather the data access, quality,
or liability issue, respectively. Reference = CRISC Review Manual, 7th Edition, page 153.
Demo Practice Mode
You are viewing only the questions marked as Demo.