
Certified in Risk and Information Systems Control
Domain 2Objective 3
Vulnerability Management CRISC Practice Questions (Page 6)
Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.
31questions here
7free pages
6concepts
22%of the exam
Questions 26–30
- 26
When prioritizing vulnerabilities for remediation, which factor should be considered alongside the technical severity of the vulnerability?
Select an answer first - 27
A vulnerability scan identifies a critical vulnerability in a database server that is part of a payment processing system. The patch requires a reboot, which will cause a brief outage. The system is expected to be highly available. What is the most appropriate remediation approach?
Select an answer first - 28
Which of the following is a common remediation action for a software vulnerability?
Select an answer first - 29
A vulnerability management team has completed a remediation cycle. They need to report to the board of directors on the effectiveness of the program. Which metric would be most meaningful to the board?
Select an answer first - 30
A vulnerability scan identifies a high-severity vulnerability in a web application. The application is behind a firewall that blocks all inbound traffic except HTTP/HTTPS. The vulnerability is a buffer overflow in the application's file upload feature. What is the most important factor in analyzing this vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.