
Certified in Risk and Information Systems Control
Domain 3Objective 4
Risk Monitoring and Reporting CRISC Practice Questions (Page 2)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
44questions here
9free pages
14concepts
32%of the exam
Questions 6–10
- 6
Which risk reporting format is best suited for providing a comprehensive, periodic summary of risk and control performance metrics to management?
Select an answer first - 7
Which of the following is an example of a Key Risk Indicator (KRI)?
Select an answer first - 8
A cybersecurity team wants to provide executives with a live view of the organization's security posture, including the number of active threats, the status of critical patches, and the results of recent vulnerability scans. The data is updated continuously from multiple sources. Which reporting approach is most appropriate?
Select an answer first - 9
Which technique is most effective for validating the reliability of risk data collected from a manual data entry process?
Select an answer first - 10
A risk practitioner needs to gather data on recent cybersecurity incidents, audit findings, and changes in the external threat landscape to support ongoing risk monitoring. Which combination of sources would provide the most relevant data for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.