
Certified in Risk and Information Systems Control
Domain 1Objective 1
Governance Framework CRISC Practice Questions (Page 2)
Part of the Domain 1: Governance domain, which accounts for 26% of the CRISC exam.
27questions here
6free pages
5concepts
26%of the exam
Questions 6–10
- 6
An organization's policy states that 'all sensitive data must be encrypted.' The IT department is implementing encryption and needs specific technical requirements. What should the IT department use to define the exact encryption algorithms and key lengths?
Select an answer first - 7
In a decentralized organizational structure, each business unit has its own IT and risk management teams. A new regulation requires consistent risk reporting across the entire enterprise. What is the BEST approach to ensure consistency?
Select an answer first - 8
What is the primary impact of organizational culture on risk appetite?
Select an answer first - 9
A non-profit organization has a strategic goal to expand its services to a new region. The board is risk-averse and requires that any new initiative not jeopardize the organization's reputation. The executive director proposes a partnership with a local organization that has a mixed reputation. What is the BEST course of action?
Select an answer first - 10
A company has a flat organizational structure with few management layers. A new risk policy requires that all risk decisions be approved by a designated risk owner. However, employees are unsure who the risk owner is for their projects. What is the BEST way to resolve this ambiguity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.