Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 2Objective 7

Risk Register CRISC Practice Questions (Page 6)

Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.

34questions here
7free pages
7concepts
22%of the exam

Questions 26–30

  1. 26application · medium

    A risk owner is updating the register for a risk that has been mitigated by implementing a new access control system. Which information should be captured to reflect the current state?

    Select an answer first
  2. 27foundation · easy

    Which of the following is an essential field in a risk register that identifies the individual responsible for managing a specific risk?

    Select an answer first
  3. 28application · medium

    A company's risk register currently contains only high-level summaries of risks, such as 'potential data breach' and 'supply chain disruption.' The CISO wants to use the register to track risk treatment progress and to support quarterly risk reviews. Which action best aligns the register with its intended purpose?

    Select an answer first
  4. 29application · medium

    During a risk assessment, a risk is identified that is currently mitigated by an existing control. The control is documented in the register. What additional information should be captured to support future risk response decisions?

    Select an answer first
  5. 30expert · hard

    A company has a risk register that is integrated with its risk management framework. A new regulation requires the company to demonstrate that risks are reviewed and updated at least quarterly. The current process updates the register only after a risk materializes. What is the best way to align the register with the framework and the regulation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.