
Certified in Risk and Information Systems Control
Domain 2Objective 5
Risk Assessment Concepts and Standards CRISC Practice Questions (Page 1)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
12questions here
3free pages
2concepts
22%of the exam
Questions 1–5
- 1
An organization wants to adopt a risk management framework that provides principles and guidelines but does not prescribe a specific process. They want flexibility to tailor the approach to their context. Which framework is most suitable?
Select an answer first - 2
Which of the following standards is specifically designed to provide a framework for conducting risk assessments in federal information systems in the United States?
Select an answer first - 3
An organization wants to adopt a risk management framework that integrates risk considerations into its overall corporate governance and strategy, covering all types of risk across the enterprise. Which framework is most appropriate for this purpose?
Select an answer first - 4
After implementing a new firewall, a company re-evaluates the risk of an external intrusion. The risk score has decreased from 25 to 10. What is the remaining risk of 10 called?
Select an answer first - 5
A risk manager is evaluating the risk of a new cloud service. The inherent risk is high, but after implementing encryption and access controls, the residual risk is medium. The manager must decide whether to accept the residual risk. What is the most important factor in this decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.