
Certified in Risk and Information Systems Control
Domain 2Objective 1
Risk Events CRISC Practice Questions (Page 3)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
28questions here
6free pages
7concepts
22%of the exam
Questions 11–15
- 11
What is the primary purpose of documenting risk events in a risk register?
Select an answer first - 12
A hospital is assessing the risk of a ransomware attack on its patient records system. The risk team has determined that the likelihood is moderate, but the impact is very high, as it could compromise patient safety and lead to regulatory fines. The hospital has limited budget for risk mitigation. Which risk response strategy would be most appropriate?
Select an answer first - 13
An organization wants to identify risk events by reviewing past incidents and lessons learned. Which technique is most appropriate?
Select an answer first - 14
Which technique for identifying risk events involves gathering a group of stakeholders to generate a wide range of potential events without immediate criticism?
Select an answer first - 15
A company experiences a fire in its data center that destroys critical servers. How would this risk event be categorized by nature?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.