Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 2Objective 1

Risk Events CRISC Practice Questions (Page 4)

Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.

28questions here
6free pages
7concepts
22%of the exam

Questions 16–20

  1. 16foundation · easy

    What are the two primary dimensions considered when analyzing a risk event?

    Select an answer first
  2. 17expert · hard

    A telecommunications company is monitoring a risk event: a potential cyberattack on its network infrastructure. The risk team has established key risk indicators (KRIs) to track the likelihood of an attack. Which action would be most effective in using KRIs to monitor this risk event?

    Select an answer first
  3. 18foundation · easy

    When analyzing a risk event, what does 'impact' refer to?

    Select an answer first
  4. 19application · medium

    A healthcare organization has identified a risk event: a ransomware attack that could encrypt patient records. The risk team is documenting this event in the risk register. Which set of attributes should be captured to ensure the risk register is useful for future analysis and response planning?

    Select an answer first
  5. 20application · medium

    A bank is analyzing the risk of a cyberattack on its online banking platform. The risk team has determined that the likelihood of an attack is high, but the impact is low because the platform has robust security controls. How should the risk team prioritize this risk event?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.