ISACA IT Risk Fundamentals Certification Sample Questions

IT Risk Fundamentals Dumps, IT Risk Fundamentals PDF, IT Risk Fundamentals VCE, ISACA IT Risk Fundamentals VCE, ISACA IT Risk Fundamentals PDFThe purpose of this Sample Question Set is to provide you with information about the ISACA IT Risk Fundamentals exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the IT Risk Fundamentals certification test. To get familiar with real exam environment, we suggest you try our Sample ISACA IT Risk Fundamentals Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISACA IT Risk Fundamentals certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISACA IT Risk Fundamentals exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium ISACA IT Risk Fundamentals Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISACA IT Risk Fundamentals Sample Questions:

01. During a risk identification workshop, a participant proposes leaving out a possible failure of a supplier's data feed, saying that it is very unlikely to happen. What should the facilitator do FIRST?
a) Agree to exclude the risk and note the reasoning in the workshop minutes
b) Remove the supplier feed from the workshop scope
c) Ask the participant to estimate the likelihood before the risk is recorded
d) Record the risk and leave the likelihood judgment to analysis
 
02. An enterprise asks its risk and compliance function to carry out the annual independent review of the control framework that the same function designed and maintains. What is the GREATEST concern with this arrangement?
a) The risk and compliance function may lack the technical skills the review requires
b) The review would lack independence
c) The findings may be reported to the wrong audience
d) The review will duplicate work that operational management already performs
 
03. In one enterprise the payroll manager configures and runs the access controls for the payroll system, the compliance team checks whether those controls meet enterprise policy, and internal audit tests a sample of them each year. Which of these activities belongs to the second line of defense?
a) The compliance team's check of the controls against enterprise policy
b) The board's approval of the enterprise policy
c) The payroll manager's daily operation of the controls
d) Internal audit's annual testing of a sample of the payroll access controls
 
04. Controls are sometimes grouped by their nature as well as by their purpose. Which group is made up of controls that work through documented policies, procedures and staff training?
a) Physical controls protecting premises and equipment
b) Compensating controls used where another control cannot be applied
c) Administrative controls set by management
d) Technical controls within systems
 
05. Each reporting cycle, an enterprise works through its risk register: the status of open entries is updated, owners are confirmed, target dates are checked, and entries for exposures that no longer exist are closed with the reason recorded. How is this work BEST described?
a) A risk monitoring activity that keeps the recorded exposure current
b) An assurance activity that confirms whether the recorded controls still operate as designed
c) Administrative upkeep of a document held outside risk management
d) A risk identification exercise repeated each cycle
 
06. A serious outage of a new online booking service is investigated. The investigation finds that the possible failure of the service's single database instance was written in the project's own risk log a year earlier, but that the enterprise risk register holds no entry for it. The project was closed two weeks before the service went live.
Which conclusion is BEST supported by these facts?
a) The enterprise's identification techniques were not capable of finding a risk of this kind.
b) Identified risks were not carried over from the project into ongoing records.
c) The outage was caused by a control that failed to operate.
d) The operations team judged the exposure too small to warrant a register entry.
 
07. Malware encrypts files on a shared drive. The response team isolates the affected server, removes the malware and recovers the files from the previous night's backup so that the business can carry on working. The recovery of the files is BEST classified as which type of control?
a) A corrective control restoring normal operation
b) A compensating control replacing the unavailable backup process
c) A preventive control blocking the malware from executing
d) A detective control identifying the encrypted files
 
08. An enterprise has finished implementing the access controls it agreed as its response to a risk, and the controls are operating as designed. What should be done before the response is treated as complete?
a) Close the risk on the register
b) Re-assess the risk and record the residual level that remains
c) Confirm the controls were delivered within budget
d) Record the inherent risk rating that applied before the controls were implemented
 
09. Whenever staff at an enterprise report a near-miss in the payment system, they are asked to explain in writing why they did not prevent it. Over the following two quarters the number of near-misses reported falls to almost none, while the number of payment incidents recorded is unchanged.
Which conclusion is BEST supported?
a) The enterprise's risk appetite has been lowered by the fall in reported events.
b) The payment system has become less reliable over the two quarters.
c) The reporting process has reduced the number of errors that staff make.
d) The enterprise's view of its risk has become less complete.
 
10. A manufacturer identified its IT risks by working through the IT asset inventory, covering servers, network devices, applications and databases. The finance and production managers were not involved, and the register that resulted lists technology failures only.
What is the GREATEST shortcoming of this identification exercise?
a) No owner was recorded for the entries that resulted
b) Exposure to the business objectives the technology supports was never identified
c) Likelihood and impact were not estimated for each of the technology failures recorded
d) The exercise duplicated the asset inventory instead of producing a separate technology register

Answers:

Question: 01
Answer: d
Question: 02
Answer: b
Question: 03
Answer: a
Question: 04
Answer: c
Question: 05
Answer: a
Question: 06
Answer: b
Question: 07
Answer: a
Question: 08
Answer: c
Question: 09
Answer: d
Question: 10
Answer: b

Note: For any error in ISACA IT Risk Fundamentals certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 5 / 5 (81 votes)