Sample questions
Certified in Risk and Information Systems Control CRISC practice questions
During a risk assessment for a critical financial application, the IT risk manager identifies a vulnerability in the application's authentication module. The exploit would require…
When integrating IT risk into the enterprise risk management (ERM) program, what is the PRIMARY benefit?
During a third-party risk assessment, a vendor is classified as 'critical' due to its access to sensitive customer data. According to the organization's vendor risk appetite, what…
A risk register is being updated after a quarterly risk assessment. One risk has decreased in likelihood due to new controls. However, the risk score remains unchanged because the…
Which risk identification technique relies on analyzing past incidents to predict future risks?
A risk manager discovers that a business unit has been using an unapproved software-as-a-service (SaaS) application for three months. The application stores customer PII. Which of…
An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood…
An organization is implementing a new cloud-based customer relationship management (CRM) system. The risk practitioner is designing the control monitoring plan. Which approach BEST…
During a risk assessment, the risk owner identifies that the residual risk level is higher than the risk appetite. Which of the following actions should the risk owner take FIRST?
Refer to the exhibit. Based on the KRI data for the current week, what action should the risk manager take FIRST?
A database error log shows repeated login failures followed by a successful authentication. Which control failure is MOST likely?
A global company uses a critical third-party vendor for data processing. The inherent risk is high, but the vendor has implemented robust controls. However, due to recent geopoliti…
A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which ri…
After a risk assessment, a company decides to stop using a third-party service that has high residual risk. This is an example of:
A SIEM event shows multiple failed logins followed by a successful login for the service account 'svc-backup'. The risk practitioner is evaluating the controls. Which finding is MO…
A company monitors key risk indicators (KRIs) using a dashboard. The risk manager notices that a KRI has a green status but the underlying control testing shows a high failure rate…
Which TWO of the following are examples of control monitoring activities?
Refer to the exhibit. Which type of attack is MOST likely indicated by these log entries?
An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is…
An external audit finds that a control is not operating as designed. The auditor recommends corrective action. What should the risk practitioner do FIRST?
Which of the following is the BEST indicator that a risk assessment's results are reliable?
A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose…
A global financial services firm has implemented a risk monitoring system that aggregates data from 50+ systems across three regions (Americas, EMEA, APAC). The system uses a centr…
Based on the exhibit, which risk response should be prioritized?