
Certified in Risk and Information Systems Control
Domain 2Objective 7
Risk Register CRISC Practice Questions (Page 5)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
34questions here
7free pages
7concepts
22%of the exam
Questions 21–25
- 21
When documenting a risk in the register, which of the following should be included as a data input?
Select an answer first - 22
A risk register entry for a critical vendor risk includes the risk description, likelihood, impact, and owner. The risk owner is leaving the company. What is the most important update to make to the register?
Select an answer first - 23
How does the risk register support communication of risk information to management?
Select an answer first - 24
A risk register is updated only once a year during the annual risk assessment. The company has experienced significant changes in its IT environment and threat landscape. What is the most appropriate way to maintain the register?
Select an answer first - 25
A risk register contains a risk with a high likelihood and high impact. The risk owner has proposed a control that is expected to reduce likelihood but not impact. The register currently shows the inherent risk level. What should be updated in the register to reflect the proposed response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.