Free CRISC Exam Braindumps (page: 48)

Page 47 of 451

You are the risk official in Techmart Inc. You are asked to perform risk assessment on the impact of losing a network connectivity for 1 day. Which of the following factors would you include?

  1. Aggregate compensation of all affected business users.
  2. Hourly billing rate charged by the carrier
  3. Value that enterprise get on transferring data over the network
  4. Financial losses incurred by affected business units

Answer(s): D

Explanation:

The impact of network unavailability is the cost it incurs to the enterprise. As the network is unavailable for 1 day, it can be considered as the failure of some business units that rely on this network. Hence financial losses incurred by this affected business unit should be considered.

Incorrect Answers:
A, B, C: These factors in combination contribute to the overall financial impact, i.e., financial losses incurred by affected business units.



Beth is a project team member on the JHG Project. Beth has added extra features to the project and this has introduced new risks to the project work. The project manager of the JHG project elects to remove the features Beth has added. The process of removing the extra features to remove the risks is called what?

  1. Detective control
  2. Preventive control
  3. Corrective control
  4. Scope creep

Answer(s): C



You are the project manager of the GHT project. This project will last for 18 months and has a project budget of $567,000. Robert, one of your stakeholders, has introduced a scope change request that will likely have an impact on the project costs and schedule. Robert assures you that he will pay for the extra time and costs associated with the risk event. You have identified that change request may also affect other areas of the project other than just time and cost. What project management component is responsible for evaluating a change request and its impact on all of the project management knowledge areas?

  1. Configuration management
  2. Integrated change control
  3. Risk analysis
  4. Project change control system

Answer(s): B

Explanation:

Integrated change control is responsible for evaluating a proposed change and determining its impact on all areas of the project: scope, time, cost, quality, human resources, communication, risk, and procurement.

Incorrect Answers:
A: Configuration management defines the management, control, and documentation of the features and functions of the project's product.

C: Risk analysis is not responsible for reviewing the change aspects for the entire project.

D: The project change control system defines the workflow and approval process for proposed changes to the project scope, time, cost, and contracts.



While developing obscure risk scenarios, what are the requirements of the enterprise? Each correct answer represents a part of the solution. Choose two.

  1. Have capability to cure the risk events
  2. Have capability to recognize an observed event as something wrong
  3. Have sufficient number of analyst
  4. Be in a position that it can observe anything going wrong

Answer(s): B,D

Explanation:

The enterprise must consider risk that has not yet occurred and should develop scenarios around unlikely, obscure or non-historical events.

Such scenarios can be developed by considering two things: Visibility
Recognition
For the fulfillment of this task enterprise must:
Be in a position that it can observe anything going wrong
Have the capability to recognize an observed event as something wrong

Incorrect Answers:
A, C: These are not the direct requirements for developing obscure risk scenarios, like curing risk events comes under process of risk management. Hence capability of curing risk event does not lay any impact on the process of development of risk scenarios.






Post your Comments and Discuss ISACA CRISC exam with other Community members:

CRISC Discussions & Posts