Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 3Objective 3

Control Design and Implementation CRISC Practice Questions (Page 2)

Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.

42questions here
9free pages
14concepts
32%of the exam

Questions 6–10

  1. 6application · medium

    A financial services firm has a control requiring dual authorization for all wire transfers above $10,000. Due to a temporary staffing shortage, the operations manager requests a 30-day waiver to allow single authorization for transfers up to $25,000. What is the most appropriate first step for the risk manager?

    Select an answer first
  2. 7application · medium

    An auditor is testing a control that requires two employees to sign off on all cash disbursements. To verify that the control is operating effectively, the auditor selects a sample of disbursements and examines the signed approval forms. Which testing method is the auditor using?

    Select an answer first
  3. 8foundation · easy

    What is the purpose of an exception to a control requirement?

    Select an answer first
  4. 9application · medium

    A company is selecting a control to mitigate the risk of unauthorized access to its customer database. The risk is high, but the budget is limited. Which control selection is most appropriate?

    Select an answer first
  5. 10foundation · easy

    What is the purpose of collecting evidence during control testing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.