ISC Certified in Governance Risk and Compliance - CGRC Exam Practice Test

Developmental testing and evaluation is a type of control Assessment and its activities include the following except one.
Response:
Correct Answer: D
What is not a responsibility of the Risk Executive (Function) in an organization's ISCM?
Response:
Correct Answer: C
__________ of Effort will drive size of testing team, rigor of testing, & amount of documentation required.
Response:
Correct Answer: C
One of the main objectives of testing is to avoid ______________ of normal operations.
Response:
Correct Answer: C
The authorization approach that is employed when multiple organizational officials either from the same organization or different organizations, have a shared interest in authorizing an information system.
Response:
Correct Answer: B
What essential documentation should be included in the system authorization package?
Response:
Correct Answer: C,D,F,G,H
What does avoidance mean with respect to risk response?
Response:
Correct Answer: D
Which National Institute of Standards and Technology Special Publication (NIST SP) 800 series document is concerned with continuous monitoring for federal information systems and organizations? Response:
Correct Answer: D
Amy is the project manager for her company. In her current project the organization has a very low tolerance for risk events that will affect the project schedule. Management has asked Amy to consider the affect of all the risks on the project schedule.
What approach can Amy take to create a bias against risks that will affect the schedule of the project? Response:
Correct Answer: D
A continuous monitoring strategy for a new system is developed during which phase of the system development life cycle?
Response:
Correct Answer: A
Who is primarily responsible for categorizing the Information System? Response:
Correct Answer: D
0
0
0
0