Courseiva

CRISC · domain

Information Technology and Security

This domain covers IT governance and risk management frameworks, including COBIT 2019, NIST CSF, and IEC 62443. It tests your ability to apply these models to real-world scenarios, such as OT security and IoT risks, ensuring you can identify controls and optimize risk in complex environments.

152 questions33 easy72 medium47 hard

Focused practice

Practice Information Technology and Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information Technology and Security

You must apply governance and risk frameworks to scenarios. The most important thing is to correctly map controls to the right framework component, like using COBIT APO12 for risk optimization or IEC 62443 for OT security.

COBIT 2019 process APO12 for risk optimization

IEC 62443 security requirements for OT environments

NIST CSF Identify function components like asset management

IoT security risks in manufacturing like weak authentication

Watch out for

Common Information Technology and Security exam traps

  • ▸Confusing COBIT 2019 governance and management objectives, such as mixing APO12 with APO13.
  • ▸Assuming all IEC 62443 requirements apply equally to every OT zone, ignoring zone/conduit modeling.
  • ▸Overlooking that NIST CSF Identify includes risk assessment, not just asset inventory.

Question index

All Information Technology and Security questions (152)

Click any question to see the full explanation, or start a practice session above.

1

A risk practitioner is evaluating the effectiveness of the organization's IT change management process. Which of the following metrics would BEST indicate that the process is effectively reducing risk?

Easy
2

A risk practitioner is reviewing the organization's identity and access management (IAM) processes. The organization wants to reduce the risk of excessive access rights for employees who change roles internally. Which of the following controls is MOST effective for this risk?

Medium
3

A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time production monitoring. Which risk is most directly introduced by this convergence?

Medium
4

An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?

Medium
5

A risk manager is evaluating the potential impact of quantum computing on the organization's encryption infrastructure. The organization uses RSA-2048 for key exchanges and digital signatures. According to current quantum computing projections, what is the MOST urgent risk management action to take?

Hard
6

A risk practitioner is reviewing the organization's cryptographic key management practices after an audit finding. Which TWO of the following practices are MOST important to protect the confidentiality and integrity of cryptographic keys throughout their lifecycle? (Choose two.)

Medium
7

A risk manager is assessing the security posture of a containerized application deployment in a public cloud. The organization uses Kubernetes for orchestration. Which TWO of the following are the MOST significant risks specific to this environment? (Choose two.)

Hard
8

Which of the following is a key component of an IT risk management programme design?

Easy
9

A risk practitioner is evaluating the effectiveness of the organization's security awareness training program. The practitioner wants to determine whether the training is reducing the risk of phishing attacks. Which of the following metrics would be MOST indicative of the program's effectiveness?

Medium
10

Which of the following is a primary goal of the 'Protect' function in the NIST Cybersecurity Framework?

Easy
11

Which component of the NIST Cybersecurity Framework is primarily concerned with developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

Easy
12

A risk practitioner is reviewing the organization's vulnerability management programme. The vulnerability scan report shows thousands of findings, and remediation teams are overwhelmed. Which of the following is the MOST effective approach to prioritize remediation?

Easy
13

A risk practitioner is assessing the risk associated with the organization's use of third-party APIs that integrate with its core banking platform. The practitioner needs to determine the MOST effective way to monitor the risk exposure of these APIs on an ongoing basis. Which of the following approaches BEST addresses this requirement?

Medium
14

A risk manager at a retail bank is reviewing the security architecture of an internal API that moves funds between customer accounts. The API is reachable only from the bank's private network, and developers argue that mutual TLS and OAuth 2.0 token validation are unnecessary because external attackers cannot reach it. Which risk principle should the risk manager apply to challenge this reasoning?

Hard
15

A risk manager at a multinational bank is assessing the risk of a new third-party SaaS provider that will process customer transaction data. The provider stores data in a country with different data protection laws. Which of the following is the MOST critical risk factor to evaluate FIRST?

Hard
16

An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?

Medium
17

A retail company is migrating its customer loyalty application to a cloud provider. During a risk assessment, the risk practitioner notes that the provider's infrastructure is shared across many tenants. Which of the following is the MOST significant risk that this multi-tenancy introduces?

Medium
18

A financial institution is implementing a cloud-based data analytics platform. The data includes personally identifiable information (PII) of customers in multiple jurisdictions. Which of the following is the MOST critical risk consideration?

Hard
19

An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?

Hard
20

A company is implementing COBIT 2019 and wants to ensure that risk management activities are aligned with business objectives. Which governance objective is primarily responsible for evaluating, directing, and monitoring risk management?

Medium
21

A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?

Medium
22

An enterprise is migrating to a public cloud environment. Which THREE of the following are critical cloud-specific risk considerations?

Hard
23

A risk manager at a retail bank is assessing risks introduced by a new open-source container orchestration platform. The platform will host internal APIs that process non-public customer information. Which TWO of the following are the MOST significant risks that should be prioritized in the risk register? (Choose two.)

Hard
24

Which THREE of the following are typical exclusions in a cyber insurance policy?

Medium
25

A company is migrating critical applications to the cloud. The risk manager is assessing the shared responsibility model. Which risk is the customer typically responsible for?

Medium
26

A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?

Hard
27

Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?

Easy
28

A retail organization is migrating its point-of-sale (POS) processing to a cloud-hosted payment platform. The risk practitioner must select an encryption approach that protects cardholder data while it is actively being processed in memory by the payment application. Which of the following is the MOST appropriate control for this scenario?

Medium
29

Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)

Medium
30

A retail company is moving its customer loyalty application to a SaaS platform. The risk practitioner must ensure that the cloud provider's security controls are adequate. Which of the following is the MOST effective way to obtain assurance over the provider's controls?

Medium
31

A risk practitioner is reviewing the organization's vulnerability management process. The team currently relies on the Common Vulnerability Scoring System (CVSS) base score alone to prioritize remediation. The CISO asks for a more risk-based prioritization approach. Which of the following should the practitioner recommend as the MOST effective enhancement?

Medium
32

A university is deploying a new student information system that will store grades, financial aid records, and health center notes. The risk practitioner must determine the data classification that drives encryption, access, and retention requirements. Which factor is MOST important in setting that classification?

Medium
33

A hospital is implementing a new electronic health record (EHR) system. The risk practitioner is concerned about the risk of unauthorized access to patient data by internal staff. Which of the following controls is MOST effective in mitigating this risk?

Hard
34

A risk manager is evaluating the security of a new API gateway that will expose internal microservices to external partners. The gateway will handle authentication, rate limiting, and request routing. Which risk is MOST critical to address before go-live?

Hard
35

A risk manager is evaluating the organization's vulnerability management program. The organization scans its external-facing systems weekly but has no process for prioritizing vulnerabilities based on business impact. Which of the following should the risk manager recommend as the MOST effective improvement?

Hard
36

A risk practitioner is assessing the security of a new software-defined wide area network (SD-WAN) deployment that will carry regulated traffic between branch offices and a cloud environment. The vendor's controller is managed by a third party. Which of the following risks should the practitioner identify as the MOST significant?

Hard
37

A company is planning to migrate to post-quantum cryptography. What is the primary risk that quantum computing poses to current cryptographic systems?

Medium
38

A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?

Medium
39

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The identity team proposes implementing just-in-time (JIT) privileged access with automated approval workflows and session recording. Which risk is MOST effectively mitigated by this approach compared to standing privileged accounts?

Hard
40

A multinational manufacturer is migrating its disaster recovery capability for a core ERP system from a warm standby data center to a cloud-based recovery service. The risk practitioner is validating the recovery design. Which TWO of the following should be validated to confirm the recovery time objective can realistically be met? (Choose two.)

Hard
41

An organization is evaluating cyber insurance to mitigate financial risk from potential data breaches. Which factor would most likely increase the insurance premium?

Medium
42

A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?

Hard
43

A risk practitioner at a healthcare payer is reviewing the organization's identity and access management (IAM) controls. The practitioner discovers that several terminated employees still have active single sign-on (SSO) sessions and directory accounts. Which of the following is the MOST effective control to address this risk?

Medium
44

A risk manager is evaluating the risk of a distributed denial-of-service (DDoS) attack against the organization's public-facing web application. The organization has a 1 Gbps internet connection and no DDoS mitigation service. Which of the following is the MOST important factor in determining the potential impact of a volumetric DDoS attack?

Hard
45

Which enterprise architecture layer is most directly responsible for managing the storage and processing of data, and for which data classification and encryption controls are critical?

Easy
46

Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)

Easy
47

An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?

Hard
48

A risk practitioner is assessing the organization's backup and recovery controls for a critical on-premises database. The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is fifteen minutes. The current design replicates backups nightly to an offsite tape vault. Which finding is MOST significant?

Hard
49

A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?

Hard
50

An organization is deploying IoT devices in a smart building. Which of the following are significant security risks associated with IoT? (Choose THREE.)

Hard
51

A software company allows developers to push code directly to production using a CI/CD pipeline. A recent post-incident review found that a developer's compromised credentials were used to deploy malicious code that exfiltrated customer data. Which control would MOST effectively reduce the risk of this specific attack path recurring?

Medium
52

A power utility company is required to comply with NERC CIP standards. The risk manager is assessing the impact of connecting a remote substation's OT network to the corporate WAN. Which of the following is the MOST significant risk that must be addressed to comply with NERC CIP?

Hard
53

A power utility must comply with NERC CIP standards. Which of the following is a key requirement under these standards?

Hard
54

A risk analyst is reviewing the organization's identity and access management (IAM) processes after a recent audit finding. The finding states that terminated employees retained active directory accounts for up to 30 days. Which control should the analyst recommend to BEST address this risk?

Medium
55

An organization is deploying IoT devices for environmental monitoring in a manufacturing facility. Which THREE of the following are significant security risks that should be addressed? (Select THREE.)

Hard
56

A risk practitioner is assessing the security of the organization's software development lifecycle (SDLC). The organization wants to integrate security controls to reduce the risk of introducing vulnerabilities into production. Which TWO of the following are the MOST effective preventive controls to implement during the development phase? (Choose two.)

Medium
57

In the NIST Cybersecurity Framework, which function is primarily focused on developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

Easy
58

According to COBIT 2019, which governance objective is primarily concerned with evaluating, directing, and monitoring the management of IT risk?

Easy
59

A financial services firm is deploying a new customer portal on a public cloud. The security team proposes using digital certificates to authenticate the portal to clients and sign sensitive transaction data. The risk manager must evaluate the residual risk after certificate deployment. Which of the following is the MOST significant residual risk related to the certificate lifecycle?

Medium
60

A multinational corporation is migrating its customer relationship management (CRM) system to a public cloud provider. The data includes personally identifiable information (PII) from multiple jurisdictions. Which risk should be considered most critical during the cloud architecture review?

Hard
61

A hospital's radiology department wants to replace its on-premises PACS archive (DICOM images) with a vendor-hosted SaaS platform. The vendor stores images in its own multitenant cloud and provides a web viewer. Before signing, the risk practitioner must confirm which control MOST directly addresses the risk that a vendor-side compromise could expose patient images to other tenants.

Medium
62

A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?

Hard
63

A hospital's risk practitioner is evaluating a new telehealth platform that will process protected health information (PHI). The platform will be hosted by a third-party vendor. Which of the following is the MOST critical risk to address during contract negotiations?

Hard
64

An organization's data classification policy labels customer payment records as confidential. A risk practitioner is reviewing how the data is protected at rest in a public cloud object storage bucket. Which control BEST ensures that a misconfigured bucket does not expose the data to unauthorized parties?

Easy
65

A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?

Easy
66

An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?

Medium
67

A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?

Hard
68

A risk practitioner is helping a mid-sized healthcare organization update its IT risk register after migrating patient scheduling to a SaaS platform. The vendor's SOC 2 Type II report shows no exceptions, but the contract omits breach notification timelines and data deletion commitments. Which action BEST addresses the residual risk?

Medium
69

A risk practitioner is assessing the security of an organization's software development lifecycle (SDLC). The organization wants to integrate security early to reduce the cost and impact of fixing vulnerabilities. Which TWO of the following practices are MOST effective for achieving this goal? (Choose two.)

Medium
70

A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?

Medium
71

A risk practitioner is designing an IT risk management programme. Which of the following is the BEST sequence of components to establish?

Medium
72

A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?

Medium
73

During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?

Medium
74

An organization is implementing the NIST Cybersecurity Framework to manage cyber risk. The risk manager is mapping the 'Detect' function to existing risk management processes. Which of the following activities is MOST directly aligned with the 'Detect' function?

Medium
75

A global retailer is migrating its point-of-sale (POS) transaction processing to a public cloud provider. The risk practitioner must ensure that the organization's payment card data remains compliant with PCI DSS. Which of the following is the MOST appropriate control to implement FIRST?

Medium
76

Which TWO of the following are key functions of an Architecture Review Board (ARB) in managing risk?

Easy
77

A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?

Easy
78

An organization is deploying IoT sensors in a manufacturing plant. Which of the following is the MOST significant security risk associated with these devices?

Medium
79

A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time data analytics. Which of the following represents the MOST significant risk introduced by this convergence?

Hard
80

A retail company's risk register lists 'unauthorized access to the customer loyalty database' with a likelihood of 4 and an impact of 5 on a 1-5 scale. The CISO asks the risk practitioner to reduce the risk to an acceptable level. Which action BEST represents risk treatment in this situation?

Easy
81

An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?

Medium
82

A risk practitioner is evaluating the organization's identity and access management (IAM) controls as part of an IT risk assessment. The organization has a hybrid environment with on-premises Active Directory and a cloud identity provider. Which TWO of the following are the MOST significant risks that should be prioritized? (Choose two.)

Medium
83

A company's risk management policy requires a risk register to be maintained. Which of the following is the primary purpose of a risk register?

Medium
84

Which standard is specifically designed for industrial automation and control systems security and provides a framework for addressing security in IACS?

Medium
85

A risk practitioner at a healthcare insurer is mapping the organization's IT risk register to the NIST Cybersecurity Framework (CSF) 2.0. Executive leadership wants assurance that the organization understands which assets and business processes depend on which systems before any risk treatment decisions are made. Which CSF 2.0 function and category BEST addresses this requirement?

Medium
86

An organization is reviewing its enterprise architecture to identify risks. In which IT architecture layer would a risk related to data classification and data sovereignty be primarily addressed?

Hard
87

Which of the following is a key component of the NIST Cybersecurity Framework's 'Identify' function?

Easy
88

An organization is implementing a bring your own device (BYOD) program. The risk practitioner is asked to identify the control that BEST reduces the risk of data leakage from lost or stolen mobile devices.

Easy
89

An organization is implementing a new cloud-based CRM system. The risk manager is reviewing the solution architecture for security risks. Which architectural layer should be evaluated to ensure data encryption at rest and in transit?

Medium
90

A risk manager is integrating risk management with IT governance. Which of the following are key elements of an IT risk management programme design? (Choose TWO.)

Medium
91

An architecture review board (ARB) is evaluating a new solution architecture that processes sensitive data. Which of the following should the ARB review to ensure security risks are addressed before implementation?

Medium
92

A financial institution is considering adopting a new AI/ML model for credit scoring. The model uses customer demographic data and transaction history. Which of the following risks is MOST likely to cause regulatory penalties if not addressed?

Medium
93

A risk practitioner is reviewing the organization's backup and recovery procedures for critical systems. The organization wants to ensure that backups are protected against ransomware attacks that could encrypt both production data and backups. Which of the following controls is MOST effective for this purpose?

Easy
94

A risk practitioner at a healthcare payer is reviewing the organization's disaster recovery (DR) strategy for its core claims adjudication system. The business owner has stated that the maximum tolerable downtime is 4 hours, but the current DR plan relies on restoring from nightly tape backups, which would take at least 30 hours. Which of the following is the MOST appropriate action for the risk practitioner to take FIRST?

Medium
95

A risk manager is evaluating IoT device risks for a smart building project. Which TWO of the following are significant IoT security risks?

Medium
96

An organization is planning to adopt post-quantum cryptography. Which TWO considerations are MOST important for migration planning?

Medium
97

An organization is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. Which of the following is the PRIMARY risk introduced by this IT/OT convergence?

Medium
98

An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?

Medium
99

An organization is considering cyber insurance to transfer residual risk. Which factor would MOST significantly influence the premium?

Medium
100

A software development company is adopting a DevSecOps approach. The risk manager wants to ensure that security risks are identified early in the development lifecycle. Which of the following practices is MOST effective for integrating risk identification into the CI/CD pipeline?

Medium
101

Which of the following is a key component of an IT risk management programme that documents identified risks, their likelihood, and impact?

Easy
102

A risk manager is evaluating the security of a new containerized application deployment in a hybrid cloud environment. The organization uses Kubernetes for orchestration and must ensure that container images are free from known vulnerabilities before deployment. Which of the following controls is MOST effective for this purpose?

Hard
103

A hospital's radiology department wants to let contracted teleradiologists read CT scans from home. The scans contain protected health information (PHI) and must remain within the hospital's HIPAA compliance boundary. The CIO asks the risk practitioner to recommend an access approach that minimizes the risk of PHI residing on unmanaged personal devices. Which of the following is the BEST recommendation?

Medium
104

An organization is implementing COBIT 2019 and the board has requested assurance that risk management activities are aligned with business objectives. Which governance objective is primarily focused on ensuring risk optimization through evaluation, direction, and monitoring?

Medium
105

An organization is designing an IT risk management program. Which of the following should be the PRIMARY consideration when developing a risk register?

Medium
106

A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?

Medium
107

Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?

Easy
108

A risk manager is evaluating the risk of quantum computing for the organization's encryption. The organization uses RSA-2048 for data encryption. What is the PRIMARY consideration in planning for post-quantum cryptography migration?

Hard
109

A healthcare organization is migrating its electronic health records (EHR) to a SaaS provider. The provider offers a standard contract with a 99.9% uptime SLA but no right to audit. The risk manager is concerned about data integrity and availability. Which of the following is the BEST risk response to address the lack of audit rights?

Hard
110

An insurance company's risk committee is reviewing a new mobile claims application. A penetration test found that the app stores authentication tokens in plaintext in the device's shared application storage, where any other app on a rooted or jailbroken device can read them. The development team proposes to add certificate pinning. Which of the following is the MOST appropriate risk response?

Hard
111

A manufacturing company is evaluating the risks of connecting its OT network to the IT network. Which THREE risks are MOST significant due to IT/OT convergence?

Hard
112

A retail company is implementing a new point-of-sale (POS) system that will process credit card transactions. The risk manager is reviewing the network architecture and notes that the POS devices will be on the same flat network as employee workstations and guest Wi-Fi. Which of the following is the MOST effective risk mitigation to protect cardholder data?

Easy
113

According to the NIST Cybersecurity Framework, which function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

Medium
114

In the context of IT governance, which COBIT 2019 process is specifically focused on ensuring risk optimization?

Easy
115

A financial services firm is adopting a DevSecOps model. The risk practitioner wants to ensure that security risks are identified and addressed as early as possible in the software development lifecycle. Which of the following practices BEST supports this objective?

Hard
116

A global company is moving its critical applications to a public cloud. Which THREE of the following are key risk considerations in the shared responsibility model?

Hard
117

A risk manager is evaluating the application of IEC 62443 for industrial control systems. Which THREE of the following are key security requirements addressed by this standard?

Medium
118

An organization is developing a new cloud-based application that will process personal data of EU citizens. The risk manager is assessing the shared responsibility model with the cloud service provider (CSP). Which of the following is the MOST critical risk to address in the risk assessment?

Medium
119

An organization is planning for post-quantum cryptography migration. Which THREE of the following are key considerations for this migration?

Hard
120

A risk manager is designing an IT risk management programme. Which THREE of the following are essential components of a risk management policy?

Medium
121

A financial services firm is migrating its customer relationship management (CRM) system to a SaaS provider. The risk practitioner must assess the provider's security posture. Which of the following is the MOST reliable source of assurance?

Medium
122

Which of the following is a primary concern when using AI/ML models for decisions subject to regulatory oversight?

Easy
123

During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?

Medium
124

Which COBIT 2019 governance objective focuses on ensuring that the enterprise's risk appetite and tolerance are understood, articulated, and communicated, and that risk is managed appropriately?

Easy
125

When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?

Easy
126

Which of the following is a characteristic of IoT devices that increases cybersecurity risk?

Easy
127

Which of the following is the PRIMARY purpose of a risk register in an IT risk management program?

Easy
128

A hospital network is deploying a new medical imaging archive. The risk practitioner learns that the vendor's support engineers require remote access to the archive for maintenance. Which of the following is the BEST control to manage the third-party access risk?

Hard
129

A manufacturing company is integrating its operational technology (OT) network with the corporate IT network to enable real-time data analytics. Which of the following risks should be prioritized during the risk assessment?

Medium
130

A risk analyst is assessing the risk of a legacy application that stores customer data in plaintext. The application is scheduled for decommissioning in 18 months, but until then it must remain operational. Which of the following is the BEST risk response?

Easy
131

A hospital is deploying IoT medical devices that connect to the network. Which risk is MOST concerning from a cybersecurity perspective?

Medium
132

An organization is implementing a new identity and access management (IAM) system. The risk practitioner is asked to identify the control that would BEST reduce the risk of unauthorized access due to compromised user credentials.

Easy
133

A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?

Easy
134

An organization is implementing IEC 62443 for its industrial control systems. Which THREE of the following are key requirements of IEC 62443? (Select three.)

Hard
135

A risk practitioner is evaluating the organization's vulnerability management programme. The organization scans its internal network weekly, but the CIO is concerned that critical internet-facing services are not adequately covered. Which TWO of the following changes would MOST improve the identification of exploitable vulnerabilities on externally exposed assets? (Choose two.)

Medium
136

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The organization uses role-based access control (RBAC) but has experienced several incidents where employees retained access to systems after transferring to different departments. Which of the following is the MOST effective control to address this risk?

Medium
137

A bank is adopting a third-party API gateway to expose account balance services to fintech partners. The risk practitioner must ensure that a partner's excessive or unusual API consumption cannot degrade service for other partners or core banking systems. Which control is MOST appropriate to address this risk?

Hard
138

An organization is evaluating cyber insurance options. Which of the following factors is MOST likely to influence the insurance premium?

Medium
139

A risk manager is assessing the potential impact of quantum computing on the organization's cryptographic infrastructure. What is the MOST immediate action the organization should take?

Hard
140

An organization is migrating its customer relationship management (CRM) system to a SaaS provider. The vendor's audit report shows a SOC 2 Type II opinion with no exceptions, but the report's period ended eight months ago. The risk practitioner must assess whether the residual risk is acceptable. Which action BEST addresses the gap in assurance?

Medium
141

An organization is designing its identity and access management architecture. The risk practitioner wants to reduce the risk of credential theft leading to unauthorized access to critical systems. Which of the following is the MOST effective control to address this risk?

Medium
142

A risk manager is assessing IT/OT convergence risks at a manufacturing plant. Which TWO of the following are primary risks introduced by connecting industrial control systems to the corporate network?

Hard
143

A risk practitioner is documenting how the organization handles the risk that a critical SaaS vendor could suffer an outage that halts order processing. The vendor publishes a 99.9% uptime commitment and will credit service fees if it is missed. Which action BEST addresses the residual business impact that the credit does not cover?

Easy
144

A financial services firm is deploying a security information and event management (SIEM) platform. The risk practitioner is asked to advise on how to keep the alert pipeline trustworthy so that detection and response decisions rest on reliable data. Which of the following is the MOST important control to prioritize?

Hard
145

An organization is considering adopting the NIST Cybersecurity Framework to manage cybersecurity risk. Which of the following are core functions of the framework? (Choose TWO.)

Easy
146

A risk practitioner is assessing a proposed bring-your-own-device (BYOD) programme for a law firm where attorneys will access matter files containing privileged client data. The CISO asks which controls are MOST important to reduce the risk of data leakage from lost or compromised personal devices. (Choose two.)

Hard
147

A risk manager is using the FAIR model to quantify cyber risk. After analyzing a ransomware scenario, the probable loss event frequency (LEF) is estimated at 0.2 per year, and the probable loss magnitude (LM) is $5 million. What is the annualized loss expectancy (ALE) in this scenario?

Hard
148

A risk practitioner is assessing the security of an organization's use of public cloud infrastructure. The organization stores sensitive data in object storage buckets. Which TWO of the following are the MOST significant risks related to misconfigured cloud storage? (Choose two.)

Hard
149

A hospital's radiology department wants to let referring physicians upload imaging orders through a new web portal that stores protected health information (PHI). The risk practitioner must ensure the portal meets the HIPAA Security Rule. Which of the following is the MOST appropriate control to implement first?

Medium
150

An OT environment is being assessed for compliance with IEC 62443. Which TWO of the following are key security requirements of this standard?

Medium
151

A retail company is migrating its e-commerce order database to a public cloud provider. The database stores customer names, addresses, and partial payment card numbers. The risk practitioner must determine who is accountable for protecting this data once it resides with the provider. Which of the following principles BEST guides this determination?

Easy
152

A risk manager is using the FAIR model to quantify cyber risk. Which of the following inputs is MOST directly used to calculate probable financial loss?

Medium

Frequently asked questions

What does the Information Technology and Security domain cover on the CRISC exam?
You must apply governance and risk frameworks to scenarios. The most important thing is to correctly map controls to the right framework component, like using COBIT APO12 for risk optimization or IEC 62443 for OT security.
How many questions are in this domain?
This page lists all 152 Information Technology and Security questions in the CRISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information Technology and Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-crisc ISACA-CRISC crisc it security Practice Questions