Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 2Objective 3

Vulnerability Management CRISC Practice Questions (Page 6)

Part of the Domain 2: Risk Assessment domain, which accounts for 22% of the CRISC exam.

31questions here
7free pages
6concepts
22%of the exam

Questions 26–30

  1. 26foundation · easy

    When prioritizing vulnerabilities for remediation, which factor should be considered alongside the technical severity of the vulnerability?

    Select an answer first
  2. 27application · medium

    A vulnerability scan identifies a critical vulnerability in a database server that is part of a payment processing system. The patch requires a reboot, which will cause a brief outage. The system is expected to be highly available. What is the most appropriate remediation approach?

    Select an answer first
  3. 28foundation · easy

    Which of the following is a common remediation action for a software vulnerability?

    Select an answer first
  4. 29application · medium

    A vulnerability management team has completed a remediation cycle. They need to report to the board of directors on the effectiveness of the program. Which metric would be most meaningful to the board?

    Select an answer first
  5. 30expert · hard

    A vulnerability scan identifies a high-severity vulnerability in a web application. The application is behind a firewall that blocks all inbound traffic except HTTP/HTTPS. The vulnerability is a buffer overflow in the application's file upload feature. What is the most important factor in analyzing this vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.