CRISC Certified in Risk and Information Systems Control – Question344

You are the project manager of HJT project. You want to measure the operational effectiveness of risk management capabilities. Which of the following is the BEST option to measure the operational effectiveness?

A.
Key risk indicators
B. Capability maturity models
C. Key performance indicators
D. Metric thresholds

Correct Answer: C

Explanation:

Explanation:
Key performance indicators are a set of quantifiable measures that a company or industry uses to gauge or compare performance in terms of meeting their strategic and operational goals. Key performance indicators (KPIs) provide insights into the operational effectiveness of the concept or capability that they monitor.
Incorrect Answers:
A: Key risk Indicators (KRIs) only provide insights into potential risks that may exist or be realized within a concept or capability that they monitor.
B: Capability maturity models (CMMs) assess the maturity of a concept or capability and do not provide insights into operational effectiveness.
D: Metric thresholds are decision or action points that are enacted when a KPI or KRI reports a specific value or set of values.

CRISC Certified in Risk and Information Systems Control – Question343

Which of the following controls focuses on operational efficiency in a functional area sticking to management policies?

A.
Internal accounting control
B. Detective control
C. Administrative control
D. Operational control

Correct Answer: C

Explanation:

Explanation: Administrative control is one of the objectives of internal control and is concerned with ensuring efficiency and compliance with management policies.
Incorrect Answers:
A: It controls accounting operations, including safeguarding assets and financial records.
B: Detective control simply detects and reports on the occurrence of an error, omission or malicious act.
D: It focuses on day-to-day operations, functions, and activities. It also ensures that all the organization’s objectives are being accomplished.

CRISC Certified in Risk and Information Systems Control – Question342

Natural disaster is BEST associated to which of the following types of risk?

A.
Short-term
B. Long-term
C. Discontinuous
D. Large impact

Correct Answer: C

Explanation:

Explanation: Natural disaster can be a long-term or short-term and can have large or small impact on the company. However, as the natural disasters are unpredictable and infrequent, they are best considered as discontinuous.
Incorrect Answers:
A: Natural disaster can be a short-term, but it is not the best answer.
B: Natural disaster can be a long-term, but it is not the best answer.
D: Natural disaster can be of large impact depending upon its nature, but it is not the best answer.

CRISC Certified in Risk and Information Systems Control – Question341

You are the project manager of GHT project. A stakeholder of this project requested a change request in this project. What are your responsibilities as the project manager that you should do in order to approve this change request? Each correct answer represents a complete solution. Choose two.

A.
Archive copies of all change requests in the project file.
B. Evaluate the change request on behalf of the sponsor
C. Judge the impact of each change request on project activities, schedule and budget.
D. Formally accept the updated project plan

Correct Answer: AC

Explanation:

Explanation: Project manager responsibilities related to the change request approval process is judging the impact of each change request on project activities, schedule and budget, and also archiving copies of all change requests in the project file.
Incorrect Answers:
B: This is the responsibility of Change advisory board.
D: Pm has not the authority to formally accept the updated project plan. This is done by project sponsors so as to approve the change request.

CRISC Certified in Risk and Information Systems Control – Question340

You have been assigned as the Project Manager for a new project that involves building of a new roadway between the city airport to a designated point within the city. However, you notice that the transportation permit issuing authority is taking longer than the planned time to issue the permit to begin construction. What would you classify this as?

A.
Project Risk
B. Status Update
C. Risk Update
D. Project Issue

Correct Answer: D

Explanation:

Explanation:
This is a project issue. It is easy to confuse this as a project risk; however, a project risk is always in the future. In this case, the delay by the permitting agency has already happened; hence this is a project issue. The possible impact of this delay on the project cost, schedule, or performance can be classified as a project risk.
Incorrect Answers:
A: It is easy to confuse this as a project risk; however, a project risk is always in the future. In this case, the delay by the permitting agency has already happened; hence this is a project issue. B, C: These are options are not valid.

CRISC Certified in Risk and Information Systems Control – Question339

You are the project manager for GHT project. You need to perform the Qualitative risk analysis process. When you have completed this process, you will produce all of the following as part of the risk register update output except which one?

A.
Probability of achieving time and cost estimates
B. Priority list of risks
C. Watch list of low-priority risks
D. Risks grouped by categories

Correct Answer: A

Explanation:

Explanation: Probability of achieving time and cost estimates is an update that is produced from the Quantitative risk analysis process. In Qualitative risk analysis probability of occurrence of a specific risk is identified but not of achieving time and cost estimates.

CRISC Certified in Risk and Information Systems Control – Question338

You are the project manager in your enterprise. You have identified occurrence of risk event in your enterprise. You have pre-planned risk responses. You have monitored the risks that had occurred. What is the immediate step after this monitoring process that has to be followed in response to risk events?

A.
Initiate incident response
B. Update the risk register
C. Eliminate the risk completely
D. Communicate lessons learned from risk events

Correct Answer: A

Explanation:

Explanation:
When the risk events occur then following tasks have to done to react to it:

  • Maintain incident response plans
  • Monitor risk
  • Initiate incident response
  • Communicate lessons learned from risk events

CRISC Certified in Risk and Information Systems Control – Question337

Which of the following comes under phases of risk management?

A.
Assessing risk
B. Prioritization of risk
C. Identify risk
D. Monitoring risk
E. Developing risk

Correct Answer: ABCD

Explanation:

Explanation:
Risk management provides an approach for individuals and groups to make a decision on how to deal with potentially harmful situations. Following are the four phases involved in risk management: 1. Risk identification: The first thing we must do in risk management is to identify the areas of the project where the risks can occur. This is termed as risk identification. Listing all the possible risks is proved to be very productive for the enterprise as we can cure them before it can occur. In risk identification both threats and opportunities are considered, as both carry some level of risk with them.
2. Risk Assessment and Evaluation: Risk assessment use quantitative and qualitative analysis approaches to evaluate each significant risk identified.
3. Risk Prioritization and Response: As many risks are being identified in an enterprise, it is best to give each risk a score based on its likelihood and significance in form of ranking. This concludes whether the risk with high likelihood and high significance must be given greater attention as compared to similar risk with low likelihood and low significance. Hence, risks can be prioritized and appropriate responses to those risks are created.
4. Risk Monitoring: Risk monitoring is an activity which oversees the changes in risk assessment. Over time, the likelihood or significance originally attributed to a risk may change. This is especially true when certain responses, such as mitigation, have been made.

CRISC Certified in Risk and Information Systems Control – Question336

You work as a project manager for BlueWell Inc. You have declined a proposed change request because of the risk associated with the proposed change request. Where should the declined change request be documented and stored?

A.
Change request log
B. Project archives
C. Lessons learned
D. Project document updates

Correct Answer: A

Explanation:

Explanation: The change request log records the status of all change requests, approved or declined. The change request log is used as an account for change requests and as a means of tracking their disposition on a current basis. The change request log develops a measure of consistency into the change management process. It encourages common inputs into the process and is a common estimation approach for all change requests. As the log is an important component of project requirements, it should be readily available to the project team members responsible for project delivery. It should be maintained in a file with read-only access to those who are not responsible for approving or disapproving project change requests.
Incorrect Answers:
B: The project archive includes all project documentation and is created through the close project or phase process. It is not the best choice for this question.
C: Lessons learned are not the correct place to document the status of a declined, or approved, change request.
D: The project document updates is not the best choice for this to be fleshed into the project documents, but the declined changes are part of the change request log.

CRISC Certified in Risk and Information Systems Control – Question335

You are the project manager for BlueWell Inc. Your current project is a high priority and high profile project within your organization. You want to identify the project stakeholders that will have the most power in relation to their interest on your project. This will help you plan for project risks, stakeholder management, and ongoing communication with the key stakeholders in your project. In this process of stakeholder analysis, what type of a grid or model should you create based on these conditions?

A.
Stakeholder power/interest grid
B. Stakeholder register
C. Influence/impact grid
D. Salience model

Correct Answer: A

Explanation:

Explanation:
The power/interest grid groups stakeholders based on their level of authority (power) and their level of interest in your project. The power/interest grid forms a group of the stakeholders based on their level of authority (power) and their level of interest in the project. Interest accounts to what degree the stakeholders are affected by examining the project or policy change, and to what degree of interest or concern they have about it. Power accounts for the influence the stakeholders have over the project or policy, and to what degree they can help to accomplish, or block, the preferred change. Stakeholders, who have high power and interests associated with the project, are the people or organizations that are fully engaged with the project. When trying to generate strategic change, this community is the target of any operation.
Incorrect Answers:
B: The stakeholder register is a listing of stakeholder information and communication requirements.
C: The influence/impact grid charts is based on the stakeholder’s involvement and ability to effect changes to the project’s planning and execution.
D: The salience model groups the stakeholders based on their power, urgency, and legitimacy in the project.