
Certified in Risk and Information Systems Control
Domain 2Objective 3
Vulnerability Management CRISC Practice Questions (Page 1)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
31questions here
7free pages
6concepts
22%of the exam
Questions 1–5
- 1
Which of the following is a key characteristic of an effective vulnerability report?
Select an answer first - 2
After a vulnerability scan, the security team identifies a critical vulnerability in a customer-facing application. The team has prepared a detailed technical report. The executive steering committee needs to understand the business risk and required actions. What is the best way to communicate this finding?
Select an answer first - 3
A company has a vulnerability management program that relies on annual penetration tests and ad-hoc scans. After a breach, they find that a vulnerability was present for months. The company wants to improve its program. What is the most important change?
Select an answer first - 4
A security team is prioritizing vulnerabilities for remediation. They have identified the following vulnerabilities. Which factors should they consider when prioritizing? (Select all that apply.)
Select an answer first - 5
A vulnerability management team has identified a critical vulnerability in a third-party component used by multiple applications. The vendor has not yet released a patch. The team needs to communicate this to the application owners. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.