CRISC · domain
Information Technology and Security
This domain covers IT governance and risk management frameworks, including COBIT 2019, NIST CSF, and IEC 62443. It tests your ability to apply these models to real-world scenarios, such as OT security and IoT risks, ensuring you can identify controls and optimize risk in complex environments.
Focused practice
Practice Information Technology and Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Information Technology and Security
You must apply governance and risk frameworks to scenarios. The most important thing is to correctly map controls to the right framework component, like using COBIT APO12 for risk optimization or IEC 62443 for OT security.
COBIT 2019 process APO12 for risk optimization
IEC 62443 security requirements for OT environments
NIST CSF Identify function components like asset management
IoT security risks in manufacturing like weak authentication
Watch out for
Common Information Technology and Security exam traps
- ▸Confusing COBIT 2019 governance and management objectives, such as mixing APO12 with APO13.
- ▸Assuming all IEC 62443 requirements apply equally to every OT zone, ignoring zone/conduit modeling.
- ▸Overlooking that NIST CSF Identify includes risk assessment, not just asset inventory.
Question index
All Information Technology and Security questions (152)
Click any question to see the full explanation, or start a practice session above.
A risk practitioner is evaluating the effectiveness of the organization's IT change management process. Which of the following metrics would BEST indicate that the process is effectively reducing risk?
Easy2A risk practitioner is reviewing the organization's identity and access management (IAM) processes. The organization wants to reduce the risk of excessive access rights for employees who change roles internally. Which of the following controls is MOST effective for this risk?
Medium3A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time production monitoring. Which risk is most directly introduced by this convergence?
Medium4An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?
Medium5A risk manager is evaluating the potential impact of quantum computing on the organization's encryption infrastructure. The organization uses RSA-2048 for key exchanges and digital signatures. According to current quantum computing projections, what is the MOST urgent risk management action to take?
Hard6A risk practitioner is reviewing the organization's cryptographic key management practices after an audit finding. Which TWO of the following practices are MOST important to protect the confidentiality and integrity of cryptographic keys throughout their lifecycle? (Choose two.)
Medium7A risk manager is assessing the security posture of a containerized application deployment in a public cloud. The organization uses Kubernetes for orchestration. Which TWO of the following are the MOST significant risks specific to this environment? (Choose two.)
Hard8Which of the following is a key component of an IT risk management programme design?
Easy9A risk practitioner is evaluating the effectiveness of the organization's security awareness training program. The practitioner wants to determine whether the training is reducing the risk of phishing attacks. Which of the following metrics would be MOST indicative of the program's effectiveness?
Medium10Which of the following is a primary goal of the 'Protect' function in the NIST Cybersecurity Framework?
Easy11Which component of the NIST Cybersecurity Framework is primarily concerned with developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Easy12A risk practitioner is reviewing the organization's vulnerability management programme. The vulnerability scan report shows thousands of findings, and remediation teams are overwhelmed. Which of the following is the MOST effective approach to prioritize remediation?
Easy13A risk practitioner is assessing the risk associated with the organization's use of third-party APIs that integrate with its core banking platform. The practitioner needs to determine the MOST effective way to monitor the risk exposure of these APIs on an ongoing basis. Which of the following approaches BEST addresses this requirement?
Medium14A risk manager at a retail bank is reviewing the security architecture of an internal API that moves funds between customer accounts. The API is reachable only from the bank's private network, and developers argue that mutual TLS and OAuth 2.0 token validation are unnecessary because external attackers cannot reach it. Which risk principle should the risk manager apply to challenge this reasoning?
Hard15A risk manager at a multinational bank is assessing the risk of a new third-party SaaS provider that will process customer transaction data. The provider stores data in a country with different data protection laws. Which of the following is the MOST critical risk factor to evaluate FIRST?
Hard16An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?
Medium17A retail company is migrating its customer loyalty application to a cloud provider. During a risk assessment, the risk practitioner notes that the provider's infrastructure is shared across many tenants. Which of the following is the MOST significant risk that this multi-tenancy introduces?
Medium18A financial institution is implementing a cloud-based data analytics platform. The data includes personally identifiable information (PII) of customers in multiple jurisdictions. Which of the following is the MOST critical risk consideration?
Hard19An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?
Hard20A company is implementing COBIT 2019 and wants to ensure that risk management activities are aligned with business objectives. Which governance objective is primarily responsible for evaluating, directing, and monitoring risk management?
Medium21A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?
Medium22An enterprise is migrating to a public cloud environment. Which THREE of the following are critical cloud-specific risk considerations?
Hard23A risk manager at a retail bank is assessing risks introduced by a new open-source container orchestration platform. The platform will host internal APIs that process non-public customer information. Which TWO of the following are the MOST significant risks that should be prioritized in the risk register? (Choose two.)
Hard24Which THREE of the following are typical exclusions in a cyber insurance policy?
Medium25A company is migrating critical applications to the cloud. The risk manager is assessing the shared responsibility model. Which risk is the customer typically responsible for?
Medium26A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?
Hard27Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?
Easy28A retail organization is migrating its point-of-sale (POS) processing to a cloud-hosted payment platform. The risk practitioner must select an encryption approach that protects cardholder data while it is actively being processed in memory by the payment application. Which of the following is the MOST appropriate control for this scenario?
Medium29Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)
Medium30A retail company is moving its customer loyalty application to a SaaS platform. The risk practitioner must ensure that the cloud provider's security controls are adequate. Which of the following is the MOST effective way to obtain assurance over the provider's controls?
Medium31A risk practitioner is reviewing the organization's vulnerability management process. The team currently relies on the Common Vulnerability Scoring System (CVSS) base score alone to prioritize remediation. The CISO asks for a more risk-based prioritization approach. Which of the following should the practitioner recommend as the MOST effective enhancement?
Medium32A university is deploying a new student information system that will store grades, financial aid records, and health center notes. The risk practitioner must determine the data classification that drives encryption, access, and retention requirements. Which factor is MOST important in setting that classification?
Medium33A hospital is implementing a new electronic health record (EHR) system. The risk practitioner is concerned about the risk of unauthorized access to patient data by internal staff. Which of the following controls is MOST effective in mitigating this risk?
Hard34A risk manager is evaluating the security of a new API gateway that will expose internal microservices to external partners. The gateway will handle authentication, rate limiting, and request routing. Which risk is MOST critical to address before go-live?
Hard35A risk manager is evaluating the organization's vulnerability management program. The organization scans its external-facing systems weekly but has no process for prioritizing vulnerabilities based on business impact. Which of the following should the risk manager recommend as the MOST effective improvement?
Hard36A risk practitioner is assessing the security of a new software-defined wide area network (SD-WAN) deployment that will carry regulated traffic between branch offices and a cloud environment. The vendor's controller is managed by a third party. Which of the following risks should the practitioner identify as the MOST significant?
Hard37A company is planning to migrate to post-quantum cryptography. What is the primary risk that quantum computing poses to current cryptographic systems?
Medium38A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?
Medium39A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The identity team proposes implementing just-in-time (JIT) privileged access with automated approval workflows and session recording. Which risk is MOST effectively mitigated by this approach compared to standing privileged accounts?
Hard40A multinational manufacturer is migrating its disaster recovery capability for a core ERP system from a warm standby data center to a cloud-based recovery service. The risk practitioner is validating the recovery design. Which TWO of the following should be validated to confirm the recovery time objective can realistically be met? (Choose two.)
Hard41An organization is evaluating cyber insurance to mitigate financial risk from potential data breaches. Which factor would most likely increase the insurance premium?
Medium42A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?
Hard43A risk practitioner at a healthcare payer is reviewing the organization's identity and access management (IAM) controls. The practitioner discovers that several terminated employees still have active single sign-on (SSO) sessions and directory accounts. Which of the following is the MOST effective control to address this risk?
Medium44A risk manager is evaluating the risk of a distributed denial-of-service (DDoS) attack against the organization's public-facing web application. The organization has a 1 Gbps internet connection and no DDoS mitigation service. Which of the following is the MOST important factor in determining the potential impact of a volumetric DDoS attack?
Hard45Which enterprise architecture layer is most directly responsible for managing the storage and processing of data, and for which data classification and encryption controls are critical?
Easy46Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)
Easy47An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?
Hard48A risk practitioner is assessing the organization's backup and recovery controls for a critical on-premises database. The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is fifteen minutes. The current design replicates backups nightly to an offsite tape vault. Which finding is MOST significant?
Hard49A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?
Hard50An organization is deploying IoT devices in a smart building. Which of the following are significant security risks associated with IoT? (Choose THREE.)
Hard51A software company allows developers to push code directly to production using a CI/CD pipeline. A recent post-incident review found that a developer's compromised credentials were used to deploy malicious code that exfiltrated customer data. Which control would MOST effectively reduce the risk of this specific attack path recurring?
Medium52A power utility company is required to comply with NERC CIP standards. The risk manager is assessing the impact of connecting a remote substation's OT network to the corporate WAN. Which of the following is the MOST significant risk that must be addressed to comply with NERC CIP?
Hard53A power utility must comply with NERC CIP standards. Which of the following is a key requirement under these standards?
Hard54A risk analyst is reviewing the organization's identity and access management (IAM) processes after a recent audit finding. The finding states that terminated employees retained active directory accounts for up to 30 days. Which control should the analyst recommend to BEST address this risk?
Medium55An organization is deploying IoT devices for environmental monitoring in a manufacturing facility. Which THREE of the following are significant security risks that should be addressed? (Select THREE.)
Hard56A risk practitioner is assessing the security of the organization's software development lifecycle (SDLC). The organization wants to integrate security controls to reduce the risk of introducing vulnerabilities into production. Which TWO of the following are the MOST effective preventive controls to implement during the development phase? (Choose two.)
Medium57In the NIST Cybersecurity Framework, which function is primarily focused on developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Easy58According to COBIT 2019, which governance objective is primarily concerned with evaluating, directing, and monitoring the management of IT risk?
Easy59A financial services firm is deploying a new customer portal on a public cloud. The security team proposes using digital certificates to authenticate the portal to clients and sign sensitive transaction data. The risk manager must evaluate the residual risk after certificate deployment. Which of the following is the MOST significant residual risk related to the certificate lifecycle?
Medium60A multinational corporation is migrating its customer relationship management (CRM) system to a public cloud provider. The data includes personally identifiable information (PII) from multiple jurisdictions. Which risk should be considered most critical during the cloud architecture review?
Hard61A hospital's radiology department wants to replace its on-premises PACS archive (DICOM images) with a vendor-hosted SaaS platform. The vendor stores images in its own multitenant cloud and provides a web viewer. Before signing, the risk practitioner must confirm which control MOST directly addresses the risk that a vendor-side compromise could expose patient images to other tenants.
Medium62A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?
Hard63A hospital's risk practitioner is evaluating a new telehealth platform that will process protected health information (PHI). The platform will be hosted by a third-party vendor. Which of the following is the MOST critical risk to address during contract negotiations?
Hard64An organization's data classification policy labels customer payment records as confidential. A risk practitioner is reviewing how the data is protected at rest in a public cloud object storage bucket. Which control BEST ensures that a misconfigured bucket does not expose the data to unauthorized parties?
Easy65A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?
Easy66An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?
Medium67A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?
Hard68A risk practitioner is helping a mid-sized healthcare organization update its IT risk register after migrating patient scheduling to a SaaS platform. The vendor's SOC 2 Type II report shows no exceptions, but the contract omits breach notification timelines and data deletion commitments. Which action BEST addresses the residual risk?
Medium69A risk practitioner is assessing the security of an organization's software development lifecycle (SDLC). The organization wants to integrate security early to reduce the cost and impact of fixing vulnerabilities. Which TWO of the following practices are MOST effective for achieving this goal? (Choose two.)
Medium70A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?
Medium71A risk practitioner is designing an IT risk management programme. Which of the following is the BEST sequence of components to establish?
Medium72A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?
Medium73During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?
Medium74An organization is implementing the NIST Cybersecurity Framework to manage cyber risk. The risk manager is mapping the 'Detect' function to existing risk management processes. Which of the following activities is MOST directly aligned with the 'Detect' function?
Medium75A global retailer is migrating its point-of-sale (POS) transaction processing to a public cloud provider. The risk practitioner must ensure that the organization's payment card data remains compliant with PCI DSS. Which of the following is the MOST appropriate control to implement FIRST?
Medium76Which TWO of the following are key functions of an Architecture Review Board (ARB) in managing risk?
Easy77A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?
Easy78An organization is deploying IoT sensors in a manufacturing plant. Which of the following is the MOST significant security risk associated with these devices?
Medium79A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time data analytics. Which of the following represents the MOST significant risk introduced by this convergence?
Hard80A retail company's risk register lists 'unauthorized access to the customer loyalty database' with a likelihood of 4 and an impact of 5 on a 1-5 scale. The CISO asks the risk practitioner to reduce the risk to an acceptable level. Which action BEST represents risk treatment in this situation?
Easy81An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?
Medium82A risk practitioner is evaluating the organization's identity and access management (IAM) controls as part of an IT risk assessment. The organization has a hybrid environment with on-premises Active Directory and a cloud identity provider. Which TWO of the following are the MOST significant risks that should be prioritized? (Choose two.)
Medium83A company's risk management policy requires a risk register to be maintained. Which of the following is the primary purpose of a risk register?
Medium84Which standard is specifically designed for industrial automation and control systems security and provides a framework for addressing security in IACS?
Medium85A risk practitioner at a healthcare insurer is mapping the organization's IT risk register to the NIST Cybersecurity Framework (CSF) 2.0. Executive leadership wants assurance that the organization understands which assets and business processes depend on which systems before any risk treatment decisions are made. Which CSF 2.0 function and category BEST addresses this requirement?
Medium86An organization is reviewing its enterprise architecture to identify risks. In which IT architecture layer would a risk related to data classification and data sovereignty be primarily addressed?
Hard87Which of the following is a key component of the NIST Cybersecurity Framework's 'Identify' function?
Easy88An organization is implementing a bring your own device (BYOD) program. The risk practitioner is asked to identify the control that BEST reduces the risk of data leakage from lost or stolen mobile devices.
Easy89An organization is implementing a new cloud-based CRM system. The risk manager is reviewing the solution architecture for security risks. Which architectural layer should be evaluated to ensure data encryption at rest and in transit?
Medium90A risk manager is integrating risk management with IT governance. Which of the following are key elements of an IT risk management programme design? (Choose TWO.)
Medium91An architecture review board (ARB) is evaluating a new solution architecture that processes sensitive data. Which of the following should the ARB review to ensure security risks are addressed before implementation?
Medium92A financial institution is considering adopting a new AI/ML model for credit scoring. The model uses customer demographic data and transaction history. Which of the following risks is MOST likely to cause regulatory penalties if not addressed?
Medium93A risk practitioner is reviewing the organization's backup and recovery procedures for critical systems. The organization wants to ensure that backups are protected against ransomware attacks that could encrypt both production data and backups. Which of the following controls is MOST effective for this purpose?
Easy94A risk practitioner at a healthcare payer is reviewing the organization's disaster recovery (DR) strategy for its core claims adjudication system. The business owner has stated that the maximum tolerable downtime is 4 hours, but the current DR plan relies on restoring from nightly tape backups, which would take at least 30 hours. Which of the following is the MOST appropriate action for the risk practitioner to take FIRST?
Medium95A risk manager is evaluating IoT device risks for a smart building project. Which TWO of the following are significant IoT security risks?
Medium96An organization is planning to adopt post-quantum cryptography. Which TWO considerations are MOST important for migration planning?
Medium97An organization is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. Which of the following is the PRIMARY risk introduced by this IT/OT convergence?
Medium98An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?
Medium99An organization is considering cyber insurance to transfer residual risk. Which factor would MOST significantly influence the premium?
Medium100A software development company is adopting a DevSecOps approach. The risk manager wants to ensure that security risks are identified early in the development lifecycle. Which of the following practices is MOST effective for integrating risk identification into the CI/CD pipeline?
Medium101Which of the following is a key component of an IT risk management programme that documents identified risks, their likelihood, and impact?
Easy102A risk manager is evaluating the security of a new containerized application deployment in a hybrid cloud environment. The organization uses Kubernetes for orchestration and must ensure that container images are free from known vulnerabilities before deployment. Which of the following controls is MOST effective for this purpose?
Hard103A hospital's radiology department wants to let contracted teleradiologists read CT scans from home. The scans contain protected health information (PHI) and must remain within the hospital's HIPAA compliance boundary. The CIO asks the risk practitioner to recommend an access approach that minimizes the risk of PHI residing on unmanaged personal devices. Which of the following is the BEST recommendation?
Medium104An organization is implementing COBIT 2019 and the board has requested assurance that risk management activities are aligned with business objectives. Which governance objective is primarily focused on ensuring risk optimization through evaluation, direction, and monitoring?
Medium105An organization is designing an IT risk management program. Which of the following should be the PRIMARY consideration when developing a risk register?
Medium106A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?
Medium107Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?
Easy108A risk manager is evaluating the risk of quantum computing for the organization's encryption. The organization uses RSA-2048 for data encryption. What is the PRIMARY consideration in planning for post-quantum cryptography migration?
Hard109A healthcare organization is migrating its electronic health records (EHR) to a SaaS provider. The provider offers a standard contract with a 99.9% uptime SLA but no right to audit. The risk manager is concerned about data integrity and availability. Which of the following is the BEST risk response to address the lack of audit rights?
Hard110An insurance company's risk committee is reviewing a new mobile claims application. A penetration test found that the app stores authentication tokens in plaintext in the device's shared application storage, where any other app on a rooted or jailbroken device can read them. The development team proposes to add certificate pinning. Which of the following is the MOST appropriate risk response?
Hard111A manufacturing company is evaluating the risks of connecting its OT network to the IT network. Which THREE risks are MOST significant due to IT/OT convergence?
Hard112A retail company is implementing a new point-of-sale (POS) system that will process credit card transactions. The risk manager is reviewing the network architecture and notes that the POS devices will be on the same flat network as employee workstations and guest Wi-Fi. Which of the following is the MOST effective risk mitigation to protect cardholder data?
Easy113According to the NIST Cybersecurity Framework, which function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Medium114In the context of IT governance, which COBIT 2019 process is specifically focused on ensuring risk optimization?
Easy115A financial services firm is adopting a DevSecOps model. The risk practitioner wants to ensure that security risks are identified and addressed as early as possible in the software development lifecycle. Which of the following practices BEST supports this objective?
Hard116A global company is moving its critical applications to a public cloud. Which THREE of the following are key risk considerations in the shared responsibility model?
Hard117A risk manager is evaluating the application of IEC 62443 for industrial control systems. Which THREE of the following are key security requirements addressed by this standard?
Medium118An organization is developing a new cloud-based application that will process personal data of EU citizens. The risk manager is assessing the shared responsibility model with the cloud service provider (CSP). Which of the following is the MOST critical risk to address in the risk assessment?
Medium119An organization is planning for post-quantum cryptography migration. Which THREE of the following are key considerations for this migration?
Hard120A risk manager is designing an IT risk management programme. Which THREE of the following are essential components of a risk management policy?
Medium121A financial services firm is migrating its customer relationship management (CRM) system to a SaaS provider. The risk practitioner must assess the provider's security posture. Which of the following is the MOST reliable source of assurance?
Medium122Which of the following is a primary concern when using AI/ML models for decisions subject to regulatory oversight?
Easy123During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?
Medium124Which COBIT 2019 governance objective focuses on ensuring that the enterprise's risk appetite and tolerance are understood, articulated, and communicated, and that risk is managed appropriately?
Easy125When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?
Easy126Which of the following is a characteristic of IoT devices that increases cybersecurity risk?
Easy127Which of the following is the PRIMARY purpose of a risk register in an IT risk management program?
Easy128A hospital network is deploying a new medical imaging archive. The risk practitioner learns that the vendor's support engineers require remote access to the archive for maintenance. Which of the following is the BEST control to manage the third-party access risk?
Hard129A manufacturing company is integrating its operational technology (OT) network with the corporate IT network to enable real-time data analytics. Which of the following risks should be prioritized during the risk assessment?
Medium130A risk analyst is assessing the risk of a legacy application that stores customer data in plaintext. The application is scheduled for decommissioning in 18 months, but until then it must remain operational. Which of the following is the BEST risk response?
Easy131A hospital is deploying IoT medical devices that connect to the network. Which risk is MOST concerning from a cybersecurity perspective?
Medium132An organization is implementing a new identity and access management (IAM) system. The risk practitioner is asked to identify the control that would BEST reduce the risk of unauthorized access due to compromised user credentials.
Easy133A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?
Easy134An organization is implementing IEC 62443 for its industrial control systems. Which THREE of the following are key requirements of IEC 62443? (Select three.)
Hard135A risk practitioner is evaluating the organization's vulnerability management programme. The organization scans its internal network weekly, but the CIO is concerned that critical internet-facing services are not adequately covered. Which TWO of the following changes would MOST improve the identification of exploitable vulnerabilities on externally exposed assets? (Choose two.)
Medium136A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The organization uses role-based access control (RBAC) but has experienced several incidents where employees retained access to systems after transferring to different departments. Which of the following is the MOST effective control to address this risk?
Medium137A bank is adopting a third-party API gateway to expose account balance services to fintech partners. The risk practitioner must ensure that a partner's excessive or unusual API consumption cannot degrade service for other partners or core banking systems. Which control is MOST appropriate to address this risk?
Hard138An organization is evaluating cyber insurance options. Which of the following factors is MOST likely to influence the insurance premium?
Medium139A risk manager is assessing the potential impact of quantum computing on the organization's cryptographic infrastructure. What is the MOST immediate action the organization should take?
Hard140An organization is migrating its customer relationship management (CRM) system to a SaaS provider. The vendor's audit report shows a SOC 2 Type II opinion with no exceptions, but the report's period ended eight months ago. The risk practitioner must assess whether the residual risk is acceptable. Which action BEST addresses the gap in assurance?
Medium141An organization is designing its identity and access management architecture. The risk practitioner wants to reduce the risk of credential theft leading to unauthorized access to critical systems. Which of the following is the MOST effective control to address this risk?
Medium142A risk manager is assessing IT/OT convergence risks at a manufacturing plant. Which TWO of the following are primary risks introduced by connecting industrial control systems to the corporate network?
Hard143A risk practitioner is documenting how the organization handles the risk that a critical SaaS vendor could suffer an outage that halts order processing. The vendor publishes a 99.9% uptime commitment and will credit service fees if it is missed. Which action BEST addresses the residual business impact that the credit does not cover?
Easy144A financial services firm is deploying a security information and event management (SIEM) platform. The risk practitioner is asked to advise on how to keep the alert pipeline trustworthy so that detection and response decisions rest on reliable data. Which of the following is the MOST important control to prioritize?
Hard145An organization is considering adopting the NIST Cybersecurity Framework to manage cybersecurity risk. Which of the following are core functions of the framework? (Choose TWO.)
Easy146A risk practitioner is assessing a proposed bring-your-own-device (BYOD) programme for a law firm where attorneys will access matter files containing privileged client data. The CISO asks which controls are MOST important to reduce the risk of data leakage from lost or compromised personal devices. (Choose two.)
Hard147A risk manager is using the FAIR model to quantify cyber risk. After analyzing a ransomware scenario, the probable loss event frequency (LEF) is estimated at 0.2 per year, and the probable loss magnitude (LM) is $5 million. What is the annualized loss expectancy (ALE) in this scenario?
Hard148A risk practitioner is assessing the security of an organization's use of public cloud infrastructure. The organization stores sensitive data in object storage buckets. Which TWO of the following are the MOST significant risks related to misconfigured cloud storage? (Choose two.)
Hard149A hospital's radiology department wants to let referring physicians upload imaging orders through a new web portal that stores protected health information (PHI). The risk practitioner must ensure the portal meets the HIPAA Security Rule. Which of the following is the MOST appropriate control to implement first?
Medium150An OT environment is being assessed for compliance with IEC 62443. Which TWO of the following are key security requirements of this standard?
Medium151A retail company is migrating its e-commerce order database to a public cloud provider. The database stores customer names, addresses, and partial payment card numbers. The risk practitioner must determine who is accountable for protecting this data once it resides with the provider. Which of the following principles BEST guides this determination?
Easy152A risk manager is using the FAIR model to quantify cyber risk. Which of the following inputs is MOST directly used to calculate probable financial loss?
MediumOther domains
All CRISC exam domains
Frequently asked questions
- What does the Information Technology and Security domain cover on the CRISC exam?
- You must apply governance and risk frameworks to scenarios. The most important thing is to correctly map controls to the right framework component, like using COBIT APO12 for risk optimization or IEC 62443 for OT security.
- How many questions are in this domain?
- This page lists all 152 Information Technology and Security questions in the CRISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Information Technology and Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.