Courseiva
Back to Certified in Risk and Information Systems Control CRISC questions

Scenario-based practice

Hard Difficulty Questions

Practise Certified in Risk and Information Systems Control CRISC practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CRISC
exam code
ISACA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CRISC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

During a third-party risk assessment, a vendor is classified as 'critical' due to its access to sensitive customer data. According to the organization's vendor risk appetite, what is the minimum security requirement for this vendor?

Question 2hardmultiple choice
Full question →

A risk manager discovers that a business unit has been using an unapproved software-as-a-service (SaaS) application for three months. The application stores customer PII. Which of the following risk identification techniques should the risk manager use to understand the full extent of the risk?

Question 3hardmultiple choice
Full question →

An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?

Question 4hardmultiple choice
Full question →

An organization is implementing a new cloud-based customer relationship management (CRM) system. The risk practitioner is designing the control monitoring plan. Which approach BEST ensures continuous monitoring of controls across both the application and infrastructure layers?

Question 5hardmultiple choice
Full question →

A SIEM event shows multiple failed logins followed by a successful login for the service account 'svc-backup'. The risk practitioner is evaluating the controls. Which finding is MOST significant?

Exhibit

Refer to the exhibit.
CLI output from SIEM:
Event Time: 2024-03-15 08:23:45 UTC
Source IP: 203.0.113.5
User: svc-backup
Action: Failed login (password)
Target: db-admin@company.com
Count: 15 (last 5 minutes)
Event Time: 2024-03-15 08:24:12 UTC
Source IP: 203.0.113.5
User: svc-backup
Action: Successful login (password)
Target: db-admin@company.com
Question 6hardmultiple choice
Full question →

A company monitors key risk indicators (KRIs) using a dashboard. The risk manager notices that a KRI has a green status but the underlying control testing shows a high failure rate. What action should the risk manager take FIRST?

Question 7hardmultiple choice
Full question →

Refer to the exhibit. Which type of attack is MOST likely indicated by these log entries?

Exhibit

Refer to the exhibit.

Exhibit: Error log from a web application

```
2024-07-22 14:23:45 ERROR: org.hibernate.exception.ConstraintViolationException: could not execute statement
2024-07-22 14:23:45 ERROR: java.sql.SQLException: Duplicate entry 'admin' for key 'username'
2024-07-22 14:23:46 INFO: User 'admin' login successful
```
Question 8hardmultiple choice
Full question →

An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is an example of:

Question 9hardmultiple choice
Read the full VPN explanation →

A global financial services firm has implemented a risk monitoring system that aggregates data from 50+ systems across three regions (Americas, EMEA, APAC). The system uses a centralized data lake and provides dashboards to regional risk committees. Recently, the APAC committee reported that their dashboard shows a spike in cyber risk indicators, but the Americas and EMEA dashboards show no change. The data source for the spike is a single system in APAC that tracks failed VPN logins. The risk owner for that system believes the spike is due to a misconfiguration during a recent patch. However, the APAC risk committee is concerned that this indicates a coordinated attack. The Chief Risk Officer (CRO) wants a clear assessment. Which course of action is most appropriate?

Question 10hardmulti select
Full question →

Which THREE factors should be considered when determining the inherent risk level of a new IT project prior to any controls?

Question 11hardmulti select
Full question →

Which THREE of the following are key considerations when designing a risk reporting framework? (Choose three.)

Question 12hardmulti select
Full question →

Which THREE factors should be considered when determining the likelihood of a threat exploiting a vulnerability?

Question 13hardmultiple choice
Full question →

A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?

Question 14hardmultiple choice
Full question →

A multinational corporation has deployed a centralized log management system that collects security events from all subsidiaries. The CRO notices that the number of critical alerts from the Asia-Pacific region has dropped significantly over the past week. Upon investigation, the log source status shows that 30% of the devices in that region have not sent any logs in 48 hours. What is the MOST likely cause?

Question 15hardmulti select
Full question →

Which THREE of the following are effective risk treatment strategies?

Question 16hardmultiple choice
Full question →

A power utility company is required to comply with NERC CIP standards. The risk manager is assessing the impact of connecting a remote substation's OT network to the corporate WAN. Which of the following is the MOST significant risk that must be addressed to comply with NERC CIP?

Question 17hardmulti select
Full question →

Which THREE of the following are essential components of a risk register that should be documented during risk identification? (Select exactly 3.)

Question 18hardmultiple choice
Full question →

After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:

Question 19hardmultiple choice
Full question →

An organization is implementing continuous monitoring of its network using SIEM rules. Which of the following is the PRIMARY benefit of this approach over periodic manual testing?

Question 20hardmulti select
Full question →

A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)

These CRISC practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CRISC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.