
Certified in Risk and Information Systems Control
Domain 4Objective 4
Security and Privacy CRISC Practice Questions (Page 6)
Part of the Domain 4: Technology and Security domain, which accounts for 20% of the CRISC exam.
32questions here
7free pages
8concepts
20%of the exam
Questions 26–30
- 26
A company is planning a security awareness campaign. They want to ensure that the training is effective for all employees, including those who are not technically savvy. Which approach would be most inclusive?
Select an answer first - 27
Which privacy regulation grants individuals the right to request the deletion of their personal data held by an organization?
Select an answer first - 28
A large enterprise is adopting a security framework to guide its risk management and improve communication with stakeholders. They need a framework that is not overly prescriptive and can be adapted to their specific risk appetite. Which framework would best meet this need?
Select an answer first - 29
Which security framework is widely used as a model for developing, implementing, and improving an organization's information security management system (ISMS)?
Select an answer first - 30
After delivering a security training program, the security team wants to evaluate its effectiveness. Which method would provide the most reliable evidence of learning?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.