Courseiva

CRISC · topic practice

Scenario practice questions

Practise Certified in Risk and Information Systems Control CRISC Scenario practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Scenario

What the exam tests

What to know about Scenario

Scenario questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Scenario exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Scenario questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full Scenario explanation →

An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is an example of:

Question 2hardmultiple choice
Read the full VPN explanation →

A global financial services firm has implemented a risk monitoring system that aggregates data from 50+ systems across three regions (Americas, EMEA, APAC). The system uses a centralized data lake and provides dashboards to regional risk committees. Recently, the APAC committee reported that their dashboard shows a spike in cyber risk indicators, but the Americas and EMEA dashboards show no change. The data source for the spike is a single system in APAC that tracks failed VPN logins. The risk owner for that system believes the spike is due to a misconfiguration during a recent patch. However, the APAC risk committee is concerned that this indicates a coordinated attack. The Chief Risk Officer (CRO) wants a clear assessment. Which course of action is most appropriate?

Question 3mediummultiple choice
Read the full Scenario explanation →

In developing a risk scenario, connecting a threat event to business impact is crucial. Which of the following is the BEST example of a properly connected risk scenario?

Question 4mediummulti select
Read the full Scenario explanation →

A risk practitioner is developing risk scenarios for a new cloud service. Which THREE of the following elements should be included in a complete risk scenario?

Question 5easymultiple choice
Read the full Scenario explanation →

Based on the exhibit, which of the following is the MOST likely risk scenario?

Exhibit

Refer to the exhibit.

syslog output:
```
Jan 15 14:23:45 server01 sshd[1234]: Failed password for root from 10.0.0.5 port 22 ssh2
Jan 15 14:23:50 server01 sshd[1234]: Failed password for root from 10.0.0.5 port 22 ssh2
Jan 15 14:23:55 server01 sshd[1234]: Failed password for root from 10.0.0.5 port 22 ssh2
```
Question 6mediummultiple choice
Read the full Scenario explanation →

A hospital uses a patient portal that allows patients to access their medical records. The portal has experienced multiple brute-force login attempts. The risk manager wants to identify the most critical risk scenario. Which of the following should be prioritized?

Question 7easymulti select
Read the full Scenario explanation →

In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?

Question 8mediummultiple choice
Read the full Scenario explanation →

An organization calculates the annualized loss expectancy (ALE) for a cyber attack scenario. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 2. What is the ALE?

Question 9easymultiple choice
Read the full Scenario explanation →

An IT risk assessment team is using a 5×5 risk matrix with likelihood and impact ratings. A risk scenario is rated as likelihood = 4 (likely) and impact = 5 (catastrophic). According to the typical heat map, what would be the risk rating?

Question 10hardmulti select
Read the full Scenario explanation →

An organization is updating its IT risk universe to include emerging threats. The CISO wants to ensure the risk register captures realistic risk scenarios. Which THREE components are essential for constructing a complete risk scenario according to ISACA's risk scenario template?

Question 11mediummulti select
Read the full Scenario explanation →

Which TWO of the following are recognized techniques for identifying IT risks? (Select exactly 2.)

Question 12hardmulti select
Read the full Scenario explanation →

Which TWO risk identification techniques are most appropriate for identifying emerging risks from new technologies?

Question 13mediummultiple choice
Read the full Scenario explanation →

A large healthcare organization is implementing a new electronic health record (EHR) system. During the risk identification process, the risk team discovers that the EHR vendor has a history of minor security incidents but has always resolved them quickly. The vendor’s data center is located in a region prone to earthquakes. Additionally, the EHR system will integrate with several legacy systems that have known vulnerabilities. The project sponsor is keen to proceed and believes the vendor is reputable. The risk team needs to ensure all relevant risks are identified and documented. Which of the following should be the PRIORITY for the risk team?

Question 14hardmulti select
Read the full Scenario explanation →

Which THREE of the following are key components of an IT risk assessment report as per ISACA guidelines?

Question 15mediummulti select
Read the full Scenario explanation →

A financial institution is identifying IT risks associated with a new mobile banking application. Which TWO threat modeling techniques are best suited for this scenario? (Select two.)

Question 16mediummulti select
Read the full Scenario explanation →

When developing realistic risk scenarios, which THREE components are essential according to the ISACA risk scenario template?

Question 17hardmultiple choice
Read the full Scenario explanation →

When developing IT risk scenarios, connecting them to business impact is critical. Which of the following BEST describes how a risk practitioner should link a technical scenario to business impact?

Question 18mediummultiple choice
Read the full Scenario explanation →

A risk scenario is being developed for a phishing attack leading to credential theft. Using ISACA's risk scenario template, which component would describe the 'threat event'?

Question 19hardmultiple choice
Read the full Scenario explanation →

A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?

Question 20mediummultiple choice
Read the full Scenario explanation →

An organization is assessing risks related to a new cloud-based CRM system. The risk team is developing a risk scenario. Which of the following is the BEST example of a complete risk scenario following the ISACA template?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Scenario sessions

Start a Scenario only practice session

Every question in these sessions is drawn from the Scenario domain — nothing else.

Related practice questions

Related CRISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CRISC exam test about Scenario?
Scenario questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Scenario questions in a focused session?
Yes — the session launcher on this page draws every question from the Scenario domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CRISC topics?
Use the topic links above to move to related areas, or go back to the CRISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CRISC exam covers. They are not copied from any real exam or dump site.