
Certified in Risk and Information Systems Control
Domain 3Objective 3
Control Design and Implementation CRISC Practice Questions (Page 4)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
42questions here
9free pages
14concepts
32%of the exam
Questions 16–20
- 16
A control that is performed by a system without human intervention is classified as which type?
Select an answer first - 17
What is the purpose of analyzing control effectiveness?
Select an answer first - 18
In the context of risk response, what is the most accurate definition of an issue?
Select an answer first - 19
During a security review, an analyst discovers that a firewall rule intended to block a known malicious IP address was not applied correctly, leaving the network exposed. The analyst files an issue. What is the most appropriate next step in the issue management process?
Select an answer first - 20
A company wants to prevent unauthorized changes to its production application code. The security team proposes a control that requires all code changes to be reviewed and approved by a senior developer before deployment. How should this control be classified?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.