Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 1Objective 1

Governance Framework CRISC Practice Questions (Page 3)

Part of the Domain 1: Governance domain, which accounts for 26% of the CRISC exam.

27questions here
6free pages
5concepts
26%of the exam

Questions 11–15

  1. 11foundation · easy

    In a centralized organizational structure, how are risk and control responsibilities typically assigned?

    Select an answer first
  2. 12application · medium

    An organization's policy requires that all access to customer data be logged and reviewed. The IT team is unsure how often to review the logs. What should they consult?

    Select an answer first
  3. 13application · medium

    A multinational corporation operates with a matrix structure where regional managers report to both regional directors and global functional heads. A new IT risk policy is being rolled out. Which group is BEST positioned to ensure consistent implementation across all regions?

    Select an answer first
  4. 14expert · hard

    An organization has a policy that all data must be classified before storage. However, employees often skip classification because it is time-consuming. The policy is not being followed, and the risk of data leakage is increasing. What is the MOST EFFECTIVE way to improve compliance?

    Select an answer first
  5. 15expert · hard

    A global company is transitioning from a centralized to a federated governance model. Business units will gain more autonomy, but the enterprise risk team must still ensure compliance with corporate policies. What is the MOST EFFECTIVE way to maintain control while granting autonomy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.