Isaca

CRISC practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 1329-question bank.

Provider
Isaca
Question bank
1329
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CRISC, a certification listed under Isaca. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isaca. The certification credential is issued by Isaca, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following is the MOST important reason to maintain key risk indicators (KRIs)?

    Choose one answer.

    • In order to avoid risk
    • Complex metrics require fine-tuning
    • Risk reports need to be timely
    • Threats and vulnerabilities change over time
  2. Question 2 · 1

    Which of the following controls is an example of non-technical controls?

    Choose one answer.

    • Access control
    • Physical security
    • Intrusion detection system
    • Encryption
    Read explanation

    Physical security is an example of non-technical control. It comes under the family of operational controls. Incorrect Answers: A, C, D: Intrusion detection system, access control, and encryption are the safeguards that are incorporated into computer hardware, software or firmware, hence they refer to as technical controls.

  3. Question 3 · 1

    Which of the following is the MOST important consideration when developing risk strategies?

    Choose one answer.

    • Long-term organizational goals
    • Organization's industry sector
    • Concerns of the business process owners
    • History of risk events
  4. Question 4 · 1

    Which of the following would BEST facilitate the implementation of data classification requirements?

    Choose one answer.

    • Implementing technical controls over the assets
    • Implementing a data loss prevention (DLP) solution
    • Scheduling periodic audits
    • Assigning a data owner
  5. Question 5 · 1

    An organization has used generic risk scenarios to populate its risk register. Which of the following presents the GREATEST challenge to assigning ownership of the associated risk entries?

    Choose one answer.

    • The volume of risk scenarios is too large.
    • Risk scenarios are not applicable.
    • The risk analysis for each scenario is incomplete.
    • Risk aggregation has not been completed.
  6. Question 6 · 1

    An organization's business process requires the verbal verification of personal information in an environment where other customers may overhear this information. Which of the following is the MOST significant risk?

    Choose one answer.

    • The customer may view the process negatively.
    • The information could be used for identity theft.
    • The process could result in intellectual property theft.
    • The process could result in compliance violations.
  7. Question 7 · 1

    An organization has initiated a project to launch an IT-based service to customers and take advantage of being the first to market. Which of the following should be of GREATEST concern to senior management?

    Choose one answer.

    • The project is likely to deliver the product late.
    • More time has been allotted for testing.
    • A new project manager is handling the project.
    • The cost of the project will exceed the allotted budget.
  8. Question 8 · 1

    Which of the following is the MOST important objective of embedding risk management practices into the initiation phase of the project management life cycle?

    Choose one answer.

    • To deliver projects on time and on budget
    • To assess inherent risk
    • To assess risk throughout the project
    • To include project risk in the enterprise-wide IT risk profile
  9. Question 9 · 1

    Which of the following is the MOST significant indicator of the need to perform a penetration test?

    Choose one answer.

    • An increase in the number of infrastructure changes
    • An increase in the number of security incidents
    • An increase in the number of high-risk audit findings
    • An increase in the percentage of turnover in IT personnel
  10. Question 10 · 1

    Which of the following provides the MOST reliable information to ensure a newly acquired company has appropriate IT controls in place?

    Choose one answer.

    • Vulnerability assessment
    • Information system audit
    • Penetration testing
    • IT risk assessment
  11. Question 11 · 1

    Print jobs containing confidential information are sent to a shared network printer located in a secure room. Which of the following is the BEST control to prevent the inappropriate disclosure of confidential information?

    Choose one answer.

    • Ensuring printer parameters are properly configured
    • Using video surveillance in the printer room
    • Using physical controls to access the printer room
    • Requiring a printer access code for each user
  12. Question 12 · 1

    Which of the following would be MOST helpful when communicating roles associated with the IT risk management process?

    Choose one answer.

    • Skills matrix
    • RACI chart
    • Organizational chart
    • Job descriptions
  13. Question 13 · 1

    Fred is the project manager of a large project in his organization. Fred needs to begin planning the risk management plan with the project team and key stakeholders. Which plan risk management process tool and technique should Fred use to plan risk management?

    Choose one answer.

    • Information gathering techniques
    • Data gathering and representation techniques
    • Planning meetings and analysis
    • Variance and trend analysis
    Read explanation

    There is only one tool and technique available for Fred to plan risk management: planning meetings and analysis. Planning Meeting and Analysis is a tool and technique in the Plan Risk Management process. Planning meetings are organized by the project teams to develop the risk management plan. Attendees at these meetings include the following: ✑ Project manager ✑ Selected project team members ✑ Stakeholders ✑ Anybody in the organization with the task to manage risk planning Sophisticated plans for conducting the risk management activities are defined in these meetings, responsibilities related to risk management are assigned, and risk contingency reserve application approaches are established and reviewed. Incorrect Answers: A, B, D: These are not plan risk management tools and techniques.

  14. Question 14 · 1

    The PRIMARY benefit of conducting a risk workshop using a top-down approach instead of a bottom-up approach is the ability to:

    Choose one answer.

    • incorporate subject matter expertise.
    • identify specific project risk.
    • understand risk associated with complex processes.
    • obtain a holistic view of IT strategy risk.
  15. Question 15 · 1

    A bank recently incorporated blockchain technology with the potential to impact known risk within the organization. Which of the following is the risk practitioner's BEST course of action?

    Choose one answer.

    • Analyze and update control assessments with the new processes.
    • Conduct testing of the controls that mitigate the existing risk.
    • Determine whether risk responses are still adequate.
    • Analyze the risk and update the risk register as needed.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free