Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 2Objective 5

Risk Assessment Concepts and Standards CRISC Practice Questions (Page 3)

Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.

12questions here
3free pages
2concepts
22%of the exam

Questions 11–12

  1. 11application · medium

    A financial services firm is evaluating the risk of a new online banking platform. The risk team has identified a vulnerability in the authentication module and a threat actor who could exploit it. They are now estimating the potential financial loss if the exploit succeeds. Which risk assessment concept are they quantifying?

    Select an answer first
  2. 12application · medium

    A risk analyst is documenting the risk of a phishing attack. They note that the attacker is an external actor with moderate skill, and the vulnerability is the lack of email filtering. What is the threat in this scenario?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CRISC

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.