Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 4Objective 4

Security and Privacy CRISC Practice Questions (Page 5)

Part of the Domain 4: Technology and Security domain, which accounts for 20% of the CRISC exam.

32questions here
7free pages
8concepts
20%of the exam

Questions 21–25

  1. 21application · medium

    A financial institution is designing a system to store customer transaction data. They must ensure that the data is not altered during transmission and that only authorized personnel can access it. Which data protection principles are they primarily addressing?

    Select an answer first
  2. 22application · medium

    A company that operates in the EU is transferring personal data of EU citizens to a subsidiary in a country that has not been deemed adequate by the European Commission. What should they do to ensure compliance with GDPR?

    Select an answer first
  3. 23application · medium

    A company has experienced multiple phishing incidents where employees clicked on malicious links. The security team wants to reduce these incidents. Which approach would be most effective in addressing the human-related risk?

    Select an answer first
  4. 24foundation · easy

    What is the primary purpose of using a security framework such as NIST or ISO 27001 in an organization?

    Select an answer first
  5. 25foundation · easy

    Why is it important to tailor security training to different audiences within an organization?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.