
Certified in Risk and Information Systems Control
Domain 2Objective 1
Risk Events CRISC Practice Questions (Page 1)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
28questions here
6free pages
7concepts
22%of the exam
Questions 1–5
- 1
Which activity is an example of monitoring risk events?
Select an answer first - 2
A financial institution is considering the risk of a new regulation that could significantly increase compliance costs. The risk team has determined that the likelihood of the regulation being enacted is high, and the impact is high. The institution has a limited budget for compliance. Which risk response strategy would be most appropriate?
Select an answer first - 3
A software company is assessing the risk of a data breach. The risk team has identified a specific event: an attacker exploits a vulnerability in the company's customer database. They estimate that the likelihood of this event occurring in the next year is 20%, and the impact on customer trust and regulatory fines is estimated at $2 million. What is the risk exposure for this risk event?
Select an answer first - 4
A financial services firm has a risk register that includes a risk event: a regulatory change that could increase compliance costs. The risk team reviews the register quarterly. During a review, they notice that the likelihood of this event has increased from 'unlikely' to 'possible' due to recent legislative proposals. What should the risk team do?
Select an answer first - 5
Which of the following attributes is typically captured in a risk register for a risk event?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.