
Certified in Risk and Information Systems Control
Domain 2Objective 8
Risk Analysis Methodologies CRISC Practice Questions (Page 4)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
23questions here
5free pages
5concepts
22%of the exam
Questions 16–20
- 16
A hospital is assessing the risk of a medical device failure. The hospital has detailed maintenance logs and failure rates for the device, but the clinical impact of a failure is difficult to quantify in monetary terms. The risk team needs to decide whether to invest in a backup device. Which methodology is most appropriate?
Select an answer first - 17
A manufacturing company is assessing the risk of a production line failure. The asset value is $2,000,000, the exposure factor is 0.5, and the annualized rate of occurrence is 0.2. What is the annualized loss expectancy (ALE)?
Select an answer first - 18
An energy company is assessing risks across its portfolio of assets. The risk team has some quantitative data for certain assets but not for others. They need a consistent, repeatable method to compare risks across the entire portfolio and prioritize investments. Which methodology is most appropriate?
Select an answer first - 19
What is a common output of qualitative risk analysis?
Select an answer first - 20
A bank is assessing the risk of a phishing attack on its employees. The asset value of the affected systems is $2,000,000, and the exposure factor is 0.4. Historical data shows a successful phishing attack occurs once every 2 years. What is the annualized loss expectancy (ALE)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.