
Certified in Risk and Information Systems Control
Domain 2Objective 2
Threat Modeling and Threat Landscape CRISC Practice Questions (Page 4)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
28questions here
6free pages
6concepts
22%of the exam
Questions 16–20
- 16
A risk manager is reviewing the threat landscape for a critical infrastructure organization. The organization has seen an increase in attacks from nation-state actors, but also a rise in hacktivist activity. The risk manager needs to update the risk assessment to reflect these different threat actors. Which approach best captures the nuances of these threats?
Select an answer first - 17
A multinational corporation is updating its risk assessment. The security team observes a rise in ransomware attacks targeting similar organizations in their industry, with attackers using new evasion techniques. They need to incorporate this evolving threat landscape into their risk analysis. Which action best integrates this external threat intelligence into the risk assessment?
Select an answer first - 18
A risk analyst is updating the organization's threat landscape profile. They notice that a previously low-profile threat actor group has become more active and is now targeting the organization's sector with sophisticated phishing campaigns. The analyst needs to document this change for the risk assessment. Which component of the threat landscape is the analyst primarily updating?
Select an answer first - 19
A security architect is evaluating a new payment processing system. The team needs to understand the various ways an attacker could compromise the system, starting from a high-level goal and breaking it down into specific attack steps. They also want to visually represent these paths to communicate with stakeholders. Which threat modeling approach is best suited for this?
Select an answer first - 20
A security team is conducting a threat modeling exercise for a new cloud-based application. They have identified several threats and need to document them in a way that is useful for the risk assessment. The team is considering whether to use a structured format like a threat model document or a simple spreadsheet. Which approach is more effective for ensuring the threat modeling outputs are actionable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.