
Certified in Risk and Information Systems Control
Domain 4Objective 4
Security and Privacy CRISC Practice Questions (Page 2)
Part of the Domain 4: Technology and Security domain, which accounts for 20% of the CRISC exam.
32questions here
7free pages
8concepts
20%of the exam
Questions 6–10
- 6
A security auditor is reviewing an organization's security controls against a widely recognized standard that provides a comprehensive set of controls for information security. Which standard is the auditor most likely using?
Select an answer first - 7
A data protection officer is reviewing a new system that stores personal data. They want to ensure that the system is designed to protect the data throughout its lifecycle. Which principle is most relevant to this requirement?
Select an answer first - 8
A mobile app developer wants to collect user data for analytics. To comply with data privacy principles, what should they do to minimize the data they collect?
Select an answer first - 9
A security manager is designing a security awareness program for a global company with employees in different regions. They have limited budget and need to maximize the program's impact. Which approach would be most effective?
Select an answer first - 10
Which security standard is specifically designed to protect cardholder data and applies to organizations that handle credit card transactions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.