
Certified in Risk and Information Systems Control
Domain 3Objective 3
Control Design and Implementation CRISC Practice Questions (Page 9)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
42questions here
9free pages
14concepts
32%of the exam
Questions 41–42
- 41
A company is designing a control to mitigate the risk of data exfiltration from its cloud storage. The risk appetite is low, but the business requires rapid data sharing with external partners. The control must balance security with operational efficiency. Which control design is most appropriate?
Select an answer first - 42
A company has a control that requires all financial transactions above $5,000 to be approved by a manager. During a review, the risk team finds that the control is being applied inconsistently: some transactions are approved by a supervisor, not a manager. What is the most appropriate analysis of this situation?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CRISC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.