Book Image

ISACA Certified in Risk and Information Systems Control (CRISC®) Exam Guide

By : Shobhit Mehta
5 (1)
Book Image

ISACA Certified in Risk and Information Systems Control (CRISC®) Exam Guide

5 (1)
By: Shobhit Mehta

Overview of this book

For beginners and experienced IT risk professionals alike, acing the ISACA CRISC exam is no mean feat, and the application of this advanced skillset in your daily work poses a challenge. The ISACA Certified in Risk and Information Systems Control (CRISC®) Certification Guide is a comprehensive guide to CRISC certification and beyond that’ll help you to approach these daunting challenges with its step-by-step coverage of all aspects of the exam content and develop a highly sought-after skillset in the process. This book is divided into six sections, with each section equipped with everything you need to get to grips with the domains covered in the exam. There’ll be no surprises on exam day – from GRC to ethical risk management, third-party security concerns to the ins and outs of control design, and IDS/IPS to the SDLC, no stone is left unturned in this book’s systematic design covering all the topics so that you can sit for the exam with confidence. What’s more, there are chapter-end self-assessment questions for you to test all that you’ve learned, as well as two book-end practice quizzes to really give you a leg up. By the end of this CRISC exam study guide, you’ll not just have what it takes to breeze through the certification process, but will also be equipped with an invaluable resource to accompany you on your career path.
Table of Contents (28 chapters)
1
Part 1: Governance, Risk, and Compliance and CRISC
4
Part 2: Organizational Governance, Three Lines of Defense, and Ethical Risk Management
8
Part 3: IT Risk Assessment, Threat Management, and Risk Analysis
13
Part 4: Risk Response, Reporting, Monitoring, and Ownership
18
Part 5: Information Technology, Security, and Privacy
23
Part 6: Practice Quizzes
24
Chapter 18: Practice Quiz – Part 1
25
Chapter 19: Practice Quiz – Part 2

Review questions

  1. A project is budgeted in which phase of the SDLC?
    1. Development
    2. Disposal
    3. Initiation
    4. Maintenance
  2. End user training is an integral part of which phase of the SDLC?
    1. Development
    2. Disposal
    3. Initiation
    4. Implementation
  3. Which of the following is the final stage of the SDLC?
    1. Development
    2. Disposal
    3. Initiation
    4. Maintenance
  4. The key difference between project risk and SDLC risk is that ___.
    1. Project risk relates to project objectives, while SDLC risk relates to time.
    2. Project risk relates to project objectives, while SDLC risk relates to development objectives.
    3. Project risk relates to development objectives, while SDLC risk relates to project objectives.
    4. There is no difference; both are the same.
  5. An organization would like to achieve a certification of compliance for its product. Which of the following is a must to achieve certification?
    1. A risk manager
    2. An internal audit team
    3. Policies
    4. An external audit firm
  6. The practice of allowing employees to use personal laptops to access organizational...