
Certified in Risk and Information Systems Control
Domain 2Objective 3
Vulnerability Management CRISC Practice Questions (Page 2)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
31questions here
7free pages
6concepts
22%of the exam
Questions 6–10
- 6
Which of the following techniques is specifically designed to identify known vulnerabilities in software versions and configurations across an organization's systems?
Select an answer first - 7
Why is the vulnerability management process considered continuous?
Select an answer first - 8
A security team has a list of vulnerabilities from a recent scan. They need to decide which to remediate first. The team has limited staff and a 30-day deadline. Which factor should be the primary driver for prioritization?
Select an answer first - 9
A manufacturing company has a legacy SCADA system that cannot be patched without a costly production shutdown. A vulnerability scan identifies a critical remote code execution flaw in the system. The system is isolated on a separate network segment. What is the most appropriate remediation approach?
Select an answer first - 10
A security team has identified two critical vulnerabilities: one in a public-facing web application that is protected by a WAF, and another in an internal database that is not exposed to the internet but contains sensitive customer data. The team has limited resources to remediate only one this week. Which vulnerability should be prioritized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.