
Certified in Risk and Information Systems Control
Domain 1Objective 2
Risk Management CRISC Practice Questions (Page 4)
Part of the Domain 1: Governance domain, which accounts for 26% of the CRISC exam.
26questions here
6free pages
6concepts
26%of the exam
Questions 16–20
- 16
A large energy company is developing its risk profile for the upcoming fiscal year. The company operates in multiple countries with varying regulatory environments. The risk team has identified that the company's risk exposure in the area of environmental compliance is within the overall risk appetite, but the tolerance for a specific country is much lower due to local regulations. The risk profile currently aggregates all environmental risks into a single figure. What is the most appropriate action for the risk team?
Select an answer first - 17
A financial services firm is updating its risk appetite statement. The board has approved a risk appetite that allows for moderate risk-taking in new product development to remain competitive, but the firm must also comply with strict capital adequacy regulations. The risk team is now setting specific limits for how much capital can be allocated to new product ventures. Which of the following best describes what the risk team is defining?
Select an answer first - 18
What is the impact of contractual requirements on risk management?
Select an answer first - 19
A global technology company is expanding its operations into a new country. The legal department has identified that the new country's data protection law requires that personal data of its citizens be stored within the country's borders. The company's current risk appetite allows for moderate risk-taking, but the board has stated that regulatory compliance is a top priority. What is the most appropriate initial action for the risk management team?
Select an answer first - 20
A healthcare organization is preparing its annual risk profile report for the board. The organization has identified that its risk exposure in the area of patient data privacy is higher than its established risk tolerance, due to recent changes in data protection regulations. According to best practices, what should the organization do with this information in the risk profile?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.