
Certified in Risk and Information Systems Control
Domain 2Objective 2
Threat Modeling and Threat Landscape CRISC Practice Questions (Page 3)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
28questions here
6free pages
6concepts
22%of the exam
Questions 11–15
- 11
A healthcare organization is conducting a threat modeling exercise for a new patient data exchange platform. The team has identified the system's components, data flows, and trust boundaries. They are now at the stage where they need to systematically identify potential threats to each component and data flow. Which step of the threat modeling process are they performing?
Select an answer first - 12
What is the purpose of documenting the results of a threat modeling exercise?
Select an answer first - 13
A large e-commerce company is redesigning its authentication system. The security team must choose a threat modeling approach. They need to identify threats that could compromise user accounts, and they also need to prioritize which threats to address first based on the potential damage. The team has limited time and wants a methodology that combines both identification and prioritization in a structured way. Which approach is most suitable?
Select an answer first - 14
A security analyst is reviewing the threat landscape for a financial institution. They notice that a new ransomware group has emerged that specifically targets financial institutions and uses advanced evasion techniques. The analyst needs to update the risk assessment to reflect this new threat. Which action is most appropriate?
Select an answer first - 15
In the context of risk assessment, what is the role of threat modeling in risk identification?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.