
Certified in Risk and Information Systems Control
Domain 4Objective 2
Operations and Lifecycle Management CRISC Practice Questions (Page 2)
Part of the Domain 4: Technology and Security domain, which accounts for 20% of the CRISC exam.
41questions here
9free pages
12concepts
20%of the exam
Questions 6–10
- 6
A security operations center (SOC) receives an alert about a potential malware infection on a user's workstation. The SOC analyst is unsure if the alert is a true positive or a false positive. The user is a senior executive who is currently in an important meeting. What is the MOST appropriate action for the analyst?
Select an answer first - 7
What is a key risk implication of poor project planning?
Select an answer first - 8
A development team is building a new customer portal using an Agile methodology. The team wants to release a minimum viable product (MVP) quickly to gain market share. The risk team is concerned about security vulnerabilities in the initial release. Which approach BEST balances the need for speed with the need for security?
Select an answer first - 9
A company has a limited IT budget. The portfolio management office (PMO) is evaluating two projects: Project A is a mandatory regulatory compliance project with a low return on investment (ROI), and Project B is an innovative project with a high potential ROI but a higher risk profile. The company's risk appetite is 'conservative'. Which project should the PMO prioritize?
Select an answer first - 10
Which of the following is a key component of IT asset management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.