
Certified in Risk and Information Systems Control
Domain 2Objective 8
Risk Analysis Methodologies CRISC Practice Questions (Page 5)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
23questions here
5free pages
5concepts
22%of the exam
Questions 21–23
- 21
A government agency is assessing risks for a new citizen portal. The agency has some historical data on system outages but lacks data on new attack vectors. The risk team must produce a prioritized list of risks that is defensible to auditors and can be updated as new data becomes available. Which methodology is most appropriate?
Select an answer first - 22
A non-profit organization is conducting a risk assessment for its donor database. The organization has no historical incident data and the risk team is small, but they need to quickly identify which risks require immediate attention. They decide to rate each risk as high, medium, or low for likelihood and impact. What is the primary advantage of this qualitative approach?
Select an answer first - 23
In quantitative risk analysis, what does the annualized loss expectancy (ALE) represent?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CRISC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.