
Certified in Risk and Information Systems Control
Domain 3Objective 3
Control Design and Implementation CRISC Practice Questions (Page 1)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
42questions here
9free pages
14concepts
32%of the exam
Questions 1–5
- 1
A control that is designed to stop an error or fraud from occurring is classified as which type?
Select an answer first - 2
A company has a control that automatically blocks access to a system after three failed login attempts. The control is implemented in the system and does not require manual intervention. How should this control be classified, and what is the most appropriate testing method?
Select an answer first - 3
A company has a control requiring all employees to use multi-factor authentication (MFA) for remote access. A legacy system used by the finance team does not support MFA, and the system owner requests a permanent waiver from the requirement. The risk manager must decide between granting an exemption or an exception. What is the critical factor that determines the correct classification?
Select an answer first - 4
A control tester is documenting evidence that a control was tested. What is the most important characteristic of the evidence collected?
Select an answer first - 5
What is a common outcome of control analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.