
Certified in Risk and Information Systems Control
Domain 3Objective 1
Risk Response and Mitigation CRISC Practice Questions (Page 3)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
22questions here
5free pages
5concepts
32%of the exam
Questions 11–15
- 11
An organization decides to discontinue a business process because the risk associated with it exceeds the risk appetite and cannot be cost-effectively reduced. Which risk response option is being applied?
Select an answer first - 12
A healthcare organization has approved a risk action plan to mitigate the risk of ransomware attacks. The plan includes deploying endpoint detection and response (EDR) tools, conducting employee phishing simulations, and establishing offline backups. The risk owner has assigned the EDR deployment to the IT operations manager, phishing simulations to the security awareness team, and backup configuration to the data center manager. What is the most important element to include in the action plan to ensure successful implementation?
Select an answer first - 13
A pharmaceutical company is evaluating the risk of a data breach in its clinical trial data. The risk owner has proposed two responses: (1) implement advanced encryption and access controls at a cost of $2 million, reducing the expected annual loss from $10 million to $1 million; (2) purchase cyber insurance with a premium of $1.5 million, covering up to $8 million of losses. The company's risk appetite is low for clinical data breaches. Which response is most appropriate from a cost-benefit perspective?
Select an answer first - 14
When should an escalation procedure be triggered in the context of a risk action plan?
Select an answer first - 15
Which component is essential in a risk action plan to ensure that progress can be tracked?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.