Sample questions
Certified in Risk and Information Systems Control CRISC practice questions
Which TWO are characteristics of inherent risk?
An organization is implementing a new access control system to prevent unauthorized access to sensitive data. Which type of control is being implemented?
A Key Risk Indicator (KRI) for vulnerability management is the "average patch lag time" (number of days between patch release and deployment). In the last month, this metric increa…
A risk manager discovers that a business unit has been using an unapproved software-as-a-service (SaaS) application for three months. The application stores customer PII. Which of…
A company's control monitoring dashboard shows that a key control has been operating effectively for six months. However, a recent audit revealed a material weakness. Which of the…
A database error log shows repeated login failures followed by a successful authentication. Which control failure is MOST likely?
A university is implementing a new online learning management system (LMS) that will store student records, grades, and personal information. During the risk assessment, the IT tea…
Your organization is undergoing a merger and acquisition. The IT risk assessment team is tasked with evaluating the target company's IT environment. During the assessment, you disc…
During a risk assessment, an organization identifies that its remote workforce uses personal devices for work. The risk manager is concerned about data leakage. The organization ha…
An organization is updating its asset inventory to improve IT risk identification. Which of the following asset attributes is MOST critical for assessing cybersecurity risk?
Arrange the steps for performing a vulnerability assessment.
A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose…
Sequence the steps for implementing a new control based on risk assessment findings.
In the context of IT governance, which COBIT 2019 process is specifically focused on ensuring risk optimization?
Which THREE of the following are key considerations when designing a risk reporting framework? (Choose three.)
Order the steps for implementing a risk treatment plan.
During a risk assessment for a critical financial application, the IT risk manager identifies a vulnerability in the application's authentication module. The exploit would require…
A company is integrating its IT risk management program with the enterprise risk management (ERM) program. What is the primary benefit of this integration?
A multinational corporation has deployed a centralized log management system that collects security events from all subsidiaries. The CRO notices that the number of critical alerts…
A company is conducting an IT risk assessment for the first time. Which of the following should be the FIRST step?
An organization has a risk indicator that shows the number of failed login attempts per day. The threshold is 100. Last week, the number spiked to 200 on two days. What does this i…
Which THREE of the following are essential components of a risk register that should be documented during risk identification? (Select exactly 3.)
What is the primary purpose of a control self-assessment (CSA)?
A security awareness program is being designed to promote a risk-aware culture. Which TWO elements are most critical for the program's success?