
Certified in Risk and Information Systems Control
Domain 2Objective 2
Threat Modeling and Threat Landscape CRISC Practice Questions (Page 6)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
28questions here
6free pages
6concepts
22%of the exam
Questions 26–28
- 26
What is the primary purpose of threat modeling in the context of information systems risk assessment?
Select an answer first - 27
A startup is developing a new IoT device that collects health data. The team is new to security and wants to understand the potential threats to their device before launch. They have limited budget and need a cost-effective way to get started. Which action is most aligned with the purpose of threat modeling?
Select an answer first - 28
How can vulnerability databases, such as the National Vulnerability Database (NVD), be used in risk assessment?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CRISC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.