
Certified in Risk and Information Systems Control
Domain 4Objective 2
Operations and Lifecycle Management CRISC Practice Questions (Page 1)
Part of the Domain 4: Technology and Security domain, which accounts for 20% of the CRISC exam.
41questions here
9free pages
12concepts
20%of the exam
Questions 1–5
- 1
A project team is in the requirements gathering phase of a new customer-facing application. The risk practitioner is asked to provide input. Which security activity is MOST appropriate to perform during this phase?
Select an answer first - 2
Which of the following is the FIRST step in the incident management process?
Select an answer first - 3
What is a key security consideration during the design phase of the SDLC?
Select an answer first - 4
How does portfolio management help in managing risk?
Select an answer first - 5
A multinational company must comply with data residency requirements that mandate customer data for a specific region must be stored within that region's borders. The company uses a global cloud provider. The risk team is evaluating a new application that will process this regional data. Which control is MOST critical to ensure compliance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.