
Certified in Risk and Information Systems Control
Domain 2Objective 5
Risk Assessment Concepts and Standards CRISC Practice Questions (Page 2)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
12questions here
3free pages
2concepts
22%of the exam
Questions 6–10
- 6
A company is assessing the risk of a data breach. They have identified that the likelihood is low, but the impact is very high. According to risk assessment concepts, what is the risk level?
Select an answer first - 7
An organization is required to conduct a risk assessment for a new system. The project manager wants to use ISO 31000, while the IT security team prefers NIST SP 800-30. The organization must also comply with industry regulations that require a specific risk assessment process. What is the best approach?
Select an answer first - 8
A risk analyst is calculating the risk for a new application. The likelihood of a threat exploiting a vulnerability is rated as high, and the impact is rated as moderate. Using a qualitative risk matrix, what is the overall risk level?
Select an answer first - 9
During a risk assessment, a security analyst identifies that a server has an unpatched vulnerability. An attacker could exploit this to gain unauthorized access. In this context, what is the unpatched vulnerability?
Select an answer first - 10
A risk analyst is assessing the risk of a data breach. The likelihood is low, but the impact is catastrophic. The organization has a low risk appetite. What should the analyst recommend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.