
Certified in Risk and Information Systems Control
Domain 2Objective 1
Risk Events CRISC Practice Questions (Page 2)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
28questions here
6free pages
7concepts
22%of the exam
Questions 6–10
- 6
An organization identifies that a lack of employee training is increasing the likelihood of data breaches. In risk terminology, this lack of training is best classified as a:
Select an answer first - 7
An e-commerce company is identifying risk events for its new payment processing system. The risk team has documented a scenario where a hacker exploits a vulnerability in the system to steal customer credit card data. They also note that the system has not been updated with the latest security patches. In this context, what is the risk event?
Select an answer first - 8
A pharmaceutical company is evaluating the risk of a new drug failing to receive regulatory approval. The risk team has determined that the likelihood is low, but the impact is very high, as it would result in a significant loss of investment. The company decides to proceed with the development, acknowledging the risk and not taking any specific action to reduce it. Which risk response strategy is the company applying?
Select an answer first - 9
Why is it important to monitor risk events over time?
Select an answer first - 10
A manufacturing company is conducting a risk assessment for its new production line. The risk manager wants to identify potential risk events that might not be obvious from historical data. Which technique would be most effective for generating a broad list of novel risk events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.