
Certified in Risk and Information Systems Control
Domain 2Objective 9
Inherent and Residual Risk CRISC Practice Questions (Page 5)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
25questions here
5free pages
6concepts
22%of the exam
Questions 21–25
- 21
A risk assessment team is evaluating a new business process. They have limited time and resources. The team is debating whether to assess inherent risk first or go directly to residual risk. What is the best approach?
Select an answer first - 22
A risk manager is deciding whether to accept a risk or implement additional controls. The inherent risk is high, but the residual risk after current controls is within the organization's risk appetite. What should the risk manager do?
Select an answer first - 23
A risk assessment team is evaluating a new data center. They have identified the inherent risk and are now evaluating the effectiveness of the existing physical and logical controls. What should they do next?
Select an answer first - 24
During a risk assessment, a team is evaluating a new customer relationship management (CRM) system. They have identified the inherent risk and are now considering the existing security controls. What is the next step in the process?
Select an answer first - 25
In a risk assessment process, which of the following is typically performed FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CRISC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.