
Certified in Risk and Information Systems Control
Domain 2Objective 3
Vulnerability Management CRISC Practice Questions (Page 3)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
31questions here
7free pages
6concepts
22%of the exam
Questions 11–15
- 11
A retail company has a mature vulnerability management program. After a recent patch cycle, the security team wants to ensure that all critical vulnerabilities have been remediated and that no new vulnerabilities have been introduced. What is the most appropriate next step?
Select an answer first - 12
A vulnerability scan of a web server identifies a medium-severity vulnerability in an outdated library. The library is used only in a non-critical internal tool that is not internet-facing. The security team has limited resources. What should they do with this finding?
Select an answer first - 13
An organization needs to identify vulnerabilities in a custom-built web application. Which assessment technique is most appropriate for this purpose?
Select an answer first - 14
A company wants to establish a vulnerability management program. They have a mix of cloud and on-premises assets, including containers and serverless functions. What is the most important consideration for vulnerability identification?
Select an answer first - 15
When a patch for a vulnerability is not yet available, which of the following is an example of a compensating control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.