
Certified in Risk and Information Systems Control
Domain 3Objective 4
Risk Monitoring and Reporting CRISC Practice Questions (Page 4)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
44questions here
9free pages
14concepts
32%of the exam
Questions 16–20
- 16
In a standard risk heatmap, what do the two axes typically represent?
Select an answer first - 17
An organization has implemented a new control requiring all access requests to be approved by the data owner. Management wants to measure whether this control is operating effectively over time. Which metric is most appropriate?
Select an answer first - 18
What is the primary difference between a Key Performance Indicator (KPI) and a Key Risk Indicator (KRI)?
Select an answer first - 19
A risk team has collected data on control failures from multiple business units. What is the primary purpose of aggregating this data before analysis?
Select an answer first - 20
On a risk heatmap, what does the color red typically indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.