Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 2Objective 2

Threat Modeling and Threat Landscape CRISC Practice Questions (Page 5)

Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.

28questions here
6free pages
6concepts
22%of the exam

Questions 21–25

  1. 21application · medium

    A threat modeling exercise for a new online banking application has been completed. The team has identified several potential threats, including SQL injection, session hijacking, and data leakage. The risk management team now needs to incorporate these findings into the organization's risk register. What is the most appropriate next step?

    Select an answer first
  2. 22expert · hard

    A security operations center (SOC) is enhancing its threat intelligence program. The team wants to improve its ability to detect and respond to emerging threats that are specific to their industry. They have access to multiple sources, including open-source threat feeds, industry ISACs, and internal telemetry. The team has limited resources and must choose the most effective combination. Which approach is most balanced and effective?

    Select an answer first
  3. 23foundation · easy

    Which of the following is the first step in a typical threat modeling exercise?

    Select an answer first
  4. 24foundation · easy

    In which scenario would an attack tree be most appropriately used as a threat modeling technique?

    Select an answer first
  5. 25foundation · easy

    Why is it important for risk professionals to understand that the threat landscape evolves over time?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.