exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 786 discussion

Actual exam question from Isaca's CRISC
Question #: 786
Topic #: 1
[All CRISC Questions]

Which of the following is the BEST indicator of the effectiveness of IT risk management processes?

  • A. Time between when IT risk scenarios are identified and the enterprise's response.
  • B. Percentage of business users completing risk training.
  • C. Percentage of high-risk scenarios for which risk action plans have been developed.
  • D. Number of key risk indicators (KRIs) defined.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Raj1510
Highly Voted 2 years, 4 months ago
I would rather go with A , as effectiveness point with implementation
upvoted 6 times
...
eblue
Most Recent 8 months, 2 weeks ago
Selected Answer: A
A. Time between when IT risk scenarios are identified and the enterprise's response. The promptness of response after identifying IT risk scenarios is a strong indicator of the effectiveness of the IT risk management processes. It signifies how agile and proactive the organization is in addressing and mitigating risks. While the other options provide some insight into the organization's risk management maturity, the ability to swiftly react to identified risks is a more direct measure of process effectiveness.
upvoted 1 times
...
CbtL
1 year, 1 month ago
Selected Answer: A
Agree it is A
upvoted 1 times
...
john_boogieman
1 year, 3 months ago
Selected Answer: C
7th CRISC manual, 'alignment of risk response with business objectives': [...] first determine the best response and then develop the action plan and implementation strategy. The best indicator of effectiveness is the implementation of the plan.
upvoted 1 times
...
Ceecil1959
2 years, 1 month ago
A: is my choice I would think that it effectiveness refers to the time between identifying IT scenarios and enterprises' response. C: Just having an Risk action plan for High risk scenarios may not be IT scenarios as the questions asks
upvoted 1 times
...
tsangckl
2 years, 2 months ago
I stand with C. effectiveness of IT risk management processes, even the time of risk identify and response is fast. But the risk is for currently identified and make a priority. The risk response can not be decrease the risk. I pick C. As high risk is address, the total risk can be effectively address and reduce the resident risk to acceptable level.
upvoted 3 times
...
AllaAlla
2 years, 3 months ago
also thik a is more suitable
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...