CRISC Exam Question 341

An organization that has been the subject of multiple social engineering attacks is developing a risk awareness program. The PRIMARY goal of this program should be to:
  • CRISC Exam Question 342

    Which of the following sources is MOST relevant to reference when updating security awareness training materials?
  • CRISC Exam Question 343

    A large organization recently restructured the IT department and has decided to outsource certain functions.
    What action should the control owners in the IT department take?
  • CRISC Exam Question 344

    A poster has been displayed in a data center that reads. "Anyone caught taking photographs in the data center may be subject to disciplinary action." Which of the following control types has been implemented?
  • CRISC Exam Question 345

    A failure in an organization's IT system build process has resulted in several computers on the network missing the corporate endpoint detection and response (EDR) software. Which of the following should be the risk practitioner's IMMEDIATE concern?