
Certified in Risk and Information Systems Control
Domain 2Objective 9
Inherent and Residual Risk CRISC Practice Questions (Page 1)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
25questions here
5free pages
6concepts
22%of the exam
Questions 1–5
- 1
An organization assesses an inherent risk with a likelihood of 4 (on a 1-5 scale) and an impact of 5. After applying controls, the likelihood is reduced to 2 and the impact remains 5. What is the residual risk score?
Select an answer first - 2
How is residual risk derived from inherent risk?
Select an answer first - 3
Which of the following statements correctly describes the relationship between inherent risk and residual risk?
Select an answer first - 4
An organization is conducting a risk assessment for its new cloud storage service. The risk team first evaluates the risk without considering any existing security measures, then evaluates the risk after applying the current controls. What is the correct sequence of steps?
Select an answer first - 5
A risk manager is explaining to a new analyst why the risk register includes both inherent and residual risk for each risk. What is the main reason for this distinction?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.