
Certified in Risk and Information Systems Control
Domain 3Objective 3
Control Design and Implementation CRISC Practice Questions (Page 3)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
42questions here
9free pages
14concepts
32%of the exam
Questions 11–15
- 11
A company is implementing a new access control system and wants to ensure it aligns with industry best practices. The risk manager suggests using a specific control standard to guide the implementation. Which standard is most relevant for information security controls?
Select an answer first - 12
When selecting a control, why is cost an important consideration?
Select an answer first - 13
Which control testing method involves asking questions of personnel to understand how a control is performed?
Select an answer first - 14
A company is implementing a new control environment and wants to use a framework that provides a structured approach to managing cybersecurity risk, including identifying, protecting, detecting, responding, and recovering. Which framework is most appropriate?
Select an answer first - 15
What is a key characteristic of good testing evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.