Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 2Objective 3

Vulnerability Management CRISC Practice Questions (Page 5)

Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.

31questions here
7free pages
6concepts
22%of the exam

Questions 21–25

  1. 21expert · hard

    A company has a critical vulnerability in a legacy application that is end-of-life and cannot be patched. The application is essential for business operations. The risk team has proposed several options. Which option best balances risk reduction and business continuity?

    Select an answer first
  2. 22foundation · easy

    During vulnerability analysis, what is the primary purpose of determining the Common Vulnerability Scoring System (CVSS) score of a vulnerability?

    Select an answer first
  3. 23application · medium

    A company has a vulnerability management program that includes quarterly scans and manual patching. After a security incident, they realize that a known vulnerability was not patched because it was missed in the scan. What is the most important improvement to the program?

    Select an answer first
  4. 24foundation · easy

    Which of the following best describes the vulnerability management lifecycle?

    Select an answer first
  5. 25expert · hard

    A company has a critical vulnerability in a custom application. The vendor has released a patch, but the patch is known to cause compatibility issues with another application. The security team must decide how to proceed. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.