Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 2Objective 5

Risk Assessment Concepts and Standards CRISC Practice Questions (Page 2)

Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.

12questions here
3free pages
2concepts
22%of the exam

Questions 6–10

  1. 6application · medium

    A company is assessing the risk of a data breach. They have identified that the likelihood is low, but the impact is very high. According to risk assessment concepts, what is the risk level?

    Select an answer first
  2. 7expert · hard

    An organization is required to conduct a risk assessment for a new system. The project manager wants to use ISO 31000, while the IT security team prefers NIST SP 800-30. The organization must also comply with industry regulations that require a specific risk assessment process. What is the best approach?

    Select an answer first
  3. 8application · medium

    A risk analyst is calculating the risk for a new application. The likelihood of a threat exploiting a vulnerability is rated as high, and the impact is rated as moderate. Using a qualitative risk matrix, what is the overall risk level?

    Select an answer first
  4. 9application · medium

    During a risk assessment, a security analyst identifies that a server has an unpatched vulnerability. An attacker could exploit this to gain unauthorized access. In this context, what is the unpatched vulnerability?

    Select an answer first
  5. 10expert · hard

    A risk analyst is assessing the risk of a data breach. The likelihood is low, but the impact is catastrophic. The organization has a low risk appetite. What should the analyst recommend?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.