
Certified in Risk and Information Systems Control
Domain 4Objective 2
Operations and Lifecycle Management CRISC Practice Questions (Page 3)
Part of the Domain 4: Technology and Security domain, which accounts for 20% of the CRISC exam.
41questions here
9free pages
12concepts
20%of the exam
Questions 11–15
- 11
A company is decommissioning a server that contains customer personal data. The asset management team has confirmed the server is at the end of its lifecycle. Which action is the MOST critical risk mitigation step before the physical hardware is disposed of?
Select an answer first - 12
A software company is adopting a DevOps model to accelerate feature delivery. The risk team is evaluating the impact of this change. Which risk is MOST likely to be introduced or increased by this transition?
Select an answer first - 13
A development team is using an Agile methodology and wants to integrate security testing into their process without slowing down their two-week sprints. Which approach BEST aligns with this goal?
Select an answer first - 14
A healthcare organization is required by regulation to retain patient medical records for seven years. After this period, the records must be destroyed. The organization has a mix of electronic and physical records. Which control is MOST important to ensure compliance at the end of the retention period?
Select an answer first - 15
What is the primary role of portfolio management in an organization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.