
Certified in Risk and Information Systems Control
Domain 1Objective 2
Risk Management CRISC Practice Questions (Page 3)
Part of the Domain 1: Governance domain, which accounts for 26% of the CRISC exam.
26questions here
6free pages
6concepts
26%of the exam
Questions 11–15
- 11
A technology startup has a high risk appetite for innovation but must comply with the Payment Card Industry Data Security Standard (PCI DSS) for its payment processing. The board has set a risk tolerance that allows for no more than one PCI DSS compliance violation per year. During a quarterly review, the risk team finds that the company has already had two violations this year. What should the risk team do first?
Select an answer first - 12
How do legal and regulatory requirements influence an organization's risk posture?
Select an answer first - 13
What is the primary purpose of Enterprise Risk Management (ERM)?
Select an answer first - 14
Which of the following is typically included in a risk profile?
Select an answer first - 15
A large insurance company is implementing an ERM program. The company has a decentralized structure with business units operating independently. The ERM team is tasked with integrating risk management across the organization. The business units are resistant to a centralized approach because they believe it will slow down decision-making. What is the most effective strategy for the ERM team to overcome this resistance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.