
Certified in Risk and Information Systems Control
Domain 2Objective 4
Risk Scenario Development and Evaluation CRISC Practice Questions (Page 4)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
31questions here
7free pages
8concepts
22%of the exam
Questions 16–20
- 16
A risk analyst is documenting risk scenarios for a bank's mobile banking application. To ensure the documentation supports clear communication and consistent analysis, which of the following is the most important practice?
Select an answer first - 17
A multinational corporation is evaluating risk scenarios for its new cloud-based customer relationship management (CRM) system. The company operates in a jurisdiction with strict data residency requirements. Two scenarios have been developed: Scenario A involves a data breach due to a misconfigured cloud storage bucket, and Scenario B involves a prolonged outage of the cloud service provider. The company's risk appetite is low for data breaches but moderate for service outages. Which scenario should be prioritized?
Select an answer first - 18
How are risk scenarios used within the overall risk assessment process?
Select an answer first - 19
Which statement best defines a risk scenario in the context of risk assessment?
Select an answer first - 20
A risk manager has developed a set of risk scenarios for a telecommunications company. After six months, the company has adopted new technologies and the threat landscape has changed. What is the most appropriate action regarding the risk scenarios?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.