
Certified in Risk and Information Systems Control
Domain 2Objective 9
Inherent and Residual Risk CRISC Practice Questions (Page 2)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
25questions here
5free pages
6concepts
22%of the exam
Questions 6–10
- 6
A bank is assessing the risk of a new mobile banking application. The risk team estimates that without any controls, the likelihood of a data breach is 60% and the impact is $5 million. After implementing multi-factor authentication and encryption, the likelihood drops to 15% and the impact remains $5 million. What is the residual risk in monetary terms?
Select an answer first - 7
A risk analyst is calculating the residual risk for a new payment processing system. The inherent likelihood is 30% and the inherent impact is $2 million. The controls are expected to reduce likelihood by 50% and impact by 20%. What is the residual risk?
Select an answer first - 8
A risk analyst is documenting the risk for a new supplier relationship. The analyst notes that the risk is 'high' before considering any existing supplier management controls. What is the analyst describing?
Select an answer first - 9
A company has an inherent risk score of 70 for a new system. After implementing controls, the residual risk score is 35. However, the risk manager is concerned that the controls are not fully effective in all scenarios. What is the most appropriate action?
Select an answer first - 10
A risk manager is evaluating the residual risk of a new API gateway. The inherent likelihood is 20% and the inherent impact is $500,000. The controls are expected to reduce likelihood by 60% and impact by 30%. However, the control effectiveness is uncertain, with a possible range of 50-70% for likelihood reduction. What is the best estimate of residual risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.