Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 4Objective 4

Security and Privacy CRISC Practice Questions (Page 1)

Part of the Domain 4: Technology and Security domain, which accounts for 20% of the CRISC exam.

32questions here
7free pages
8concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    An e-commerce company collects customer data for order processing. They want to use the same data to send promotional emails. Under GDPR, what must they do before using the data for this new purpose?

    Select an answer first
  2. 2expert · medium

    A security architect is designing a system that must ensure that a user cannot deny having performed a financial transaction. They also need to ensure that the transaction data has not been tampered with. Which combination of security concepts should be implemented?

    Select an answer first
  3. 3foundation · easy

    What does the privacy principle of 'purpose limitation' require of an organization?

    Select an answer first
  4. 4foundation · easy

    Which data privacy principle requires that an organization only collect personal data that is necessary for its stated purpose?

    Select an answer first
  5. 5application · medium

    A US-based company that is not a financial institution collects personal data from California residents. They want to ensure compliance with the California Consumer Privacy Act (CCPA). Which of the following rights must they provide to California consumers?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.