CRISC Exam Question 291
The design of procedures to prevent fraudulent transactions within an enterprise resource planning (ERP) system should be based on:
Correct Answer: D
Fraudulent transactions are those that involve deception, manipulation, or misrepresentation of information or data to obtain an unauthorized or improper benefit or advantage1. Fraudulenttransactions can pose significant risks and losses for an organization, such as financial damages, legal liabilities, reputational damages, or operational disruptions2.
Enterprise resource planning (ERP) systems are integrated software applications that support the core business processes and functions of an organization, such as accounting, finance, human resources, supply chain, inventory, or customer relationship management3. ERP systems can facilitate the efficiency, accuracy, and security of business transactions, but they can also be vulnerable to fraudulent transactions, such as:
Creating fake vendors or customers and processing false invoices or payments Manipulating or falsifying financial or accounting data or reports Changing or deleting critical or sensitive information or records Abusing or misusing access privileges or credentials Bypassing or compromising the system controls or security measures4 The design of procedures to prevent fraudulent transactions within an ERP system should be based on the control environment. The control environment is the set of standards, processes, and structures that provide the basis for carrying out internal control across the organization. The control environment comprises the following elements:
The tone at the top, which reflects the leadership's commitment and attitude towards internal control and ethical conduct The organizational structure, which defines the roles and responsibilities, reporting lines, and authority levels for internal control The human resource policies and practices, which ensure that the staff have the appropriate skills, competencies, and incentives for internal control The risk assessment process, which identifies and evaluates the potential risks and threats to the organization' s objectives and transactions The control activities, which are the specific policies, procedures, and mechanisms that prevent, detect, or correct errors or fraud in transactions The information and communication systems, which provide reliable and timely data and information for internal control and decision-making The monitoring and evaluation activities, which measure and report the performance and effectiveness of internal control and ensure continuous improvement By basing the design of procedures to prevent fraudulent transactions within an ERP system on the control environment, the organization can:
Ensure that the procedures are aligned with the organization's objectives, values, and expectations regarding internal control and fraud prevention Provide clear and consistent guidance and instructions for the staff and stakeholders involved in the transactions and the ERP system Implement adequate and appropriate controls and safeguards to mitigate the risks and vulnerabilities of the transactions and the ERP system Monitor and evaluate the compliance and effectiveness of the procedures and the ERP system, and identify and address any issues or gaps References = What is Fraud?, Fraud Risk Management - AICPA, What is ERP?, ERP Fraud: How to Prevent It - ERP Focus, [COSO - Control Environment - Deloitte], [How to use COSO to assess IT controls - Journal of Accountancy]
Enterprise resource planning (ERP) systems are integrated software applications that support the core business processes and functions of an organization, such as accounting, finance, human resources, supply chain, inventory, or customer relationship management3. ERP systems can facilitate the efficiency, accuracy, and security of business transactions, but they can also be vulnerable to fraudulent transactions, such as:
Creating fake vendors or customers and processing false invoices or payments Manipulating or falsifying financial or accounting data or reports Changing or deleting critical or sensitive information or records Abusing or misusing access privileges or credentials Bypassing or compromising the system controls or security measures4 The design of procedures to prevent fraudulent transactions within an ERP system should be based on the control environment. The control environment is the set of standards, processes, and structures that provide the basis for carrying out internal control across the organization. The control environment comprises the following elements:
The tone at the top, which reflects the leadership's commitment and attitude towards internal control and ethical conduct The organizational structure, which defines the roles and responsibilities, reporting lines, and authority levels for internal control The human resource policies and practices, which ensure that the staff have the appropriate skills, competencies, and incentives for internal control The risk assessment process, which identifies and evaluates the potential risks and threats to the organization' s objectives and transactions The control activities, which are the specific policies, procedures, and mechanisms that prevent, detect, or correct errors or fraud in transactions The information and communication systems, which provide reliable and timely data and information for internal control and decision-making The monitoring and evaluation activities, which measure and report the performance and effectiveness of internal control and ensure continuous improvement By basing the design of procedures to prevent fraudulent transactions within an ERP system on the control environment, the organization can:
Ensure that the procedures are aligned with the organization's objectives, values, and expectations regarding internal control and fraud prevention Provide clear and consistent guidance and instructions for the staff and stakeholders involved in the transactions and the ERP system Implement adequate and appropriate controls and safeguards to mitigate the risks and vulnerabilities of the transactions and the ERP system Monitor and evaluate the compliance and effectiveness of the procedures and the ERP system, and identify and address any issues or gaps References = What is Fraud?, Fraud Risk Management - AICPA, What is ERP?, ERP Fraud: How to Prevent It - ERP Focus, [COSO - Control Environment - Deloitte], [How to use COSO to assess IT controls - Journal of Accountancy]
CRISC Exam Question 292
The MOST important characteristic of an organization s policies is to reflect the organization's:
Correct Answer: B
An organization's policies are the set of rules and guidelines that define the organization's objectives, expectations, and responsibilities for its activities and operations. They provide the direction and framework for the organization's governance, risk management, and compliance functions.
The most important characteristic of an organization's policies is to reflect the organization's risk appetite, which is the amount and type of risk that the organization is willing to accept in pursuit of its goals. The risk appetite is usually expressed as a range or a threshold, and it is aligned with the organization's strategy and culture.
Reflecting the organization's risk appetite in its policies ensures that the policies are consistent, appropriate, and proportional to the level and nature of the risks that the organization faces, and that they support the organization's objectives and values. It also helps to optimize the balance between risk and return, and to create and protect value for the organization and its stakeholders.
The other options are not the most important characteristic of an organization's policies, because they do not address the fundamental question of whether the policies are suitable and acceptable for the organization.
The risk assessment methodology is the process of identifying, analyzing, and evaluating the risks that may affect the organization's objectives and operations. It involves determining the likelihood and impact of various risk scenarios, and prioritizing them based on their significance and urgency. The risk assessment methodology is important to inform and support the organization's policies, but it is not the most important characteristic of the policies, because it does not indicate whether the policies are aligned with the organization's risk appetite.
The capabilities are the resources and abilities that the organization has or can acquire to achieve its objectives and manage its risks. They include the people, processes, technologies, and assets that the organization uses or relies on. The capabilities are important to enable and implement theorganization's policies, but they are not the most important characteristic of the policies, because they do not indicate whether the policies are aligned with the organization's risk appetite.
The asset value is the worth or importance of the assets that the organization owns or controls, and that may be affected by the risks that the organization faces. The assets include the tangible and intangible resources that the organization uses or relies on, such as data, information, systems, infrastructure, reputation, etc. The asset value is important to measure and monitor the organization's policies, but it is not the most important characteristic of the policies, because itdoes not indicate whether the policies are aligned with the organization's risk appetite. References = ISACA, CRISC Review Manual, 7th Edition, 2022, pp. 29-30, 34-35, 38-39, 44-45, 50-51, 54-55 ISACA, CRISC Review Questions, Answers & Explanations Database, 2022, QID 148 CRISC Practice Quiz and Exam Prep
The most important characteristic of an organization's policies is to reflect the organization's risk appetite, which is the amount and type of risk that the organization is willing to accept in pursuit of its goals. The risk appetite is usually expressed as a range or a threshold, and it is aligned with the organization's strategy and culture.
Reflecting the organization's risk appetite in its policies ensures that the policies are consistent, appropriate, and proportional to the level and nature of the risks that the organization faces, and that they support the organization's objectives and values. It also helps to optimize the balance between risk and return, and to create and protect value for the organization and its stakeholders.
The other options are not the most important characteristic of an organization's policies, because they do not address the fundamental question of whether the policies are suitable and acceptable for the organization.
The risk assessment methodology is the process of identifying, analyzing, and evaluating the risks that may affect the organization's objectives and operations. It involves determining the likelihood and impact of various risk scenarios, and prioritizing them based on their significance and urgency. The risk assessment methodology is important to inform and support the organization's policies, but it is not the most important characteristic of the policies, because it does not indicate whether the policies are aligned with the organization's risk appetite.
The capabilities are the resources and abilities that the organization has or can acquire to achieve its objectives and manage its risks. They include the people, processes, technologies, and assets that the organization uses or relies on. The capabilities are important to enable and implement theorganization's policies, but they are not the most important characteristic of the policies, because they do not indicate whether the policies are aligned with the organization's risk appetite.
The asset value is the worth or importance of the assets that the organization owns or controls, and that may be affected by the risks that the organization faces. The assets include the tangible and intangible resources that the organization uses or relies on, such as data, information, systems, infrastructure, reputation, etc. The asset value is important to measure and monitor the organization's policies, but it is not the most important characteristic of the policies, because itdoes not indicate whether the policies are aligned with the organization's risk appetite. References = ISACA, CRISC Review Manual, 7th Edition, 2022, pp. 29-30, 34-35, 38-39, 44-45, 50-51, 54-55 ISACA, CRISC Review Questions, Answers & Explanations Database, 2022, QID 148 CRISC Practice Quiz and Exam Prep
CRISC Exam Question 293
Which of the following is the PRIMARY advantage of having a single integrated business continuity plan (BCP) rather than each business unit developing its own BCP?
Correct Answer: A
CRISC Exam Question 294
Which of the following would provide the MOST reliable evidence of the effectiveness of security controls implemented for a web application?
Correct Answer: A
The most reliable evidence of the effectiveness of security controls implemented for a web application is penetration testing. Penetration testing is a process that simulates an attack on the web application by exploiting its vulnerabilities, using the same tools and techniques as real attackers. Penetration testing helps to evaluate the effectiveness of security controls, because it helps to verify that the security controls can prevent, detect, or mitigate the attack, and to measure the impact and severity of the attack. Penetration testing also helps to identify and address any weaknesses or gaps in the security controls, and to provide recommendations and solutions for improving the security of the web application. The other options are not as reliable as penetration testing, although they may provide some evidence of the effectiveness of security controls. IT general controls audit, vulnerability assessment, and fault tree analysis are all examples of analytical or evaluative methods, which may help to assess or estimate the effectiveness of security controls, but they do not necessarily test or measure the effectiveness of security controls in a realistic scenario. References = 10
CRISC Exam Question 295
Which of the following is the MOST important consideration when performing a risk assessment of a fire suppression system within a data center?
Correct Answer: C
The MOST important consideration when performing a risk assessment of a fire suppression system within a data center is the maintenance procedures, because they ensure that the fire suppression system is functioning properly and reliably, and that it can prevent or minimize the damage caused by fire incidents. The maintenance procedures should include regular testing, inspection, and servicing of the fire suppression system components, such as sprinklers, detectors, alarms, and extinguishers. The other options are not as important as the maintenance procedures, because:
Option A: Insurance coverage is a financial measure that can compensate for the loss or damage caused by fire incidents, but it does not prevent or reduce the likelihood or impact of the fire incidents. Insurance coverage is also dependent on the terms and conditions of the insurance policy, which may not cover all the scenarios or costs of the fire incidents.
Option B: Onsite replacement availability is a contingency measure that can facilitate the recovery or restoration of the fire suppression system after a fire incident, but it does not prevent or reduce the likelihood or impact of the fire incidents. Onsite replacement availability is alsodependent on the availability and compatibility of the replacement parts, which may not match the original fire suppression system specifications or requirements.
Option D: Installation manuals are a reference source that can provide guidance on how to install or configure the fire suppression system, but they do not ensure that the fire suppression system is functioning properly and reliably. Installation manuals are also static documents that may not reflect the current or updated fire suppression system standards or practices. References = Risk and Information Systems Control Study Manual, 7th Edition, ISACA, 2020, p. 211.
Option A: Insurance coverage is a financial measure that can compensate for the loss or damage caused by fire incidents, but it does not prevent or reduce the likelihood or impact of the fire incidents. Insurance coverage is also dependent on the terms and conditions of the insurance policy, which may not cover all the scenarios or costs of the fire incidents.
Option B: Onsite replacement availability is a contingency measure that can facilitate the recovery or restoration of the fire suppression system after a fire incident, but it does not prevent or reduce the likelihood or impact of the fire incidents. Onsite replacement availability is alsodependent on the availability and compatibility of the replacement parts, which may not match the original fire suppression system specifications or requirements.
Option D: Installation manuals are a reference source that can provide guidance on how to install or configure the fire suppression system, but they do not ensure that the fire suppression system is functioning properly and reliably. Installation manuals are also static documents that may not reflect the current or updated fire suppression system standards or practices. References = Risk and Information Systems Control Study Manual, 7th Edition, ISACA, 2020, p. 211.
- Other Version
- 1893ISACA.CRISC.v2026-07-15.q907
- 2292ISACA.CRISC.v2026-03-31.q857
- 2624ISACA.CRISC.v2026-01-15.q649
- 4856ISACA.CRISC.v2025-08-27.q675
- 6863ISACA.CRISC.v2025-01-04.q999
- 3569ISACA.CRISC.v2024-06-13.q683
- 4848ISACA.CRISC.v2024-04-02.q999
- 4567ISACA.CRISC.v2023-07-10.q544
- 7039ISACA.CRISC.v2022-05-25.q338
- 76ISACA.Actual4dump.CRISC.v2022-04-12.by.newman.349q.pdf
- 6677ISACA.CRISC.v2022-02-22.q349
- 6862ISACA.CRISC.v2021-10-27.q295
- 42ISACA.Updatedumps.CRISC.v2021-09-05.by.bonnie.114q.pdf
- Latest Upload
- 234Microsoft.AI-300.v2026-08-08.q76
- 172Splunk.SPLK-1004.v2026-08-08.q55
- 148Oracle.1Z0-1075-26.v2026-08-08.q22
- 159VMware.3V0-21.25.v2026-08-08.q35
- 255APICS.CPIM-8.0.v2026-08-08.q264
- 234Cisco.300-720.v2026-08-08.q115
- 199Splunk.SPLK-1003.v2026-08-08.q94
- 178ISACA.AAIR.v2026-08-07.q41
- 164Microsoft.70-123.v2026-08-07.q37
- 187AMP.CRL.v2026-08-07.q61
[×]
Download PDF File
Enter your email address to download ISACA.CRISC.v2025-09-26.q726 Practice Test
