
Certified in Risk and Information Systems Control
Domain 2Objective 3
Vulnerability Management CRISC Practice Questions (Page 4)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
31questions here
7free pages
6concepts
22%of the exam
Questions 16–20
- 16
What is the primary purpose of vulnerability reporting to stakeholders?
Select an answer first - 17
In vulnerability analysis, what does the 'exploitability' of a vulnerability primarily indicate?
Select an answer first - 18
A security analyst is reviewing a vulnerability scan report. The report lists a critical vulnerability in a web server that is exposed to the internet. However, the analyst knows that the web server is a honeypot designed to attract attackers. How should the analyst handle this finding?
Select an answer first - 19
Which of the following best describes the purpose of vulnerability prioritization?
Select an answer first - 20
A vulnerability scan of a financial services firm flags a critical-severity SQL injection in a legacy customer-facing web application and a high-severity TLS misconfiguration on an internal admin portal. The legacy app cannot be patched for 60 days due to vendor constraints. The risk team must decide remediation priorities. What should they do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.