Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CRISC questions bank; complete accurate quizzes with verified answers

Rating
-
Sold
-
Pages
163
Grade
A+
Uploaded on
02-04-2026
Written in
2025/2026

This document contains CRISC practice questions with verified answers, focusing on IT risk management, governance, and control frameworks. It covers key topics such as risk response, threat modeling, control effectiveness, risk ownership, and business alignment. The material is structured in a Q&A format to support efficient studying and exam readiness. It aligns with core CRISC domains and typical certification exam expectations.

Show more Read less
Institution
CRISC
Course
CRISC

Content preview

CRISC QUESTIONS BANK; COMPLETE
ACCURATE QUIZZES WITH VERIFIED ANSWERS


A business case developed to support risk mitigation efforts for a
complex application development project should
be retained until:
A. the project is approved.
B. user acceptance of the application.
C. the application is deployed.
D. the application's end of life - correct answer- D


A business impact analysis (BIA) is PRIMARILY used to:
A. estimate the resources required to resume and return to
normal operations after a disruption.
B. evaluate the impact of a disruption to an enterprise's ability
to operate over time.
C. calculate the likelihood and impact of known threats on
specific functions.
D. evaluate high-level business requirements. - correct
answer- B

,A chief information security officer (CISO) has recommended
several controls such as anti-malware to protect the
enterprise's information systems. Which approach to handling
risk is the CIsa recommending?
A. Risk transference
B. Risk mitigation
C. Risk acceptance
D. Risk avoidance - correct answer- B


A company has set the unacceptable error level at 10 percent.
Which of the following tools can be used to trigger a
warning when the error level reaches eight percent?
A. A fault tree analysis
B. Statistical process control (SPC)
C. A key performance indicator (KPI)
D. A failure modes and effects analysis (FMEA) - correct
answer- C


A company is confident about the state of its organizational
security and compliance program. Many improvements
have been made since the last security review was conducted
one year ago. What should the company do to evaluate

,its current risk profile?
A. Review previous findings and ensure that all issues have been
resolved.
B. Conduct follow-up audits in areas that were found deficient in
the previous review.
C. Monitor the results of the key risk indicators (KRJs) and use
those to develop targeted assessments.
D. Perform a new enterprise risk assessment using an
independent expert. - correct answer- D


A database administrator notices that the externally hosted,
web-based corporate address book application requires
users to authenticate, but that the traffic between the
application and users is not encrypted. The MOST appropriate
course of action is to:
A. notify the business owner and the security manager of the
discovery and propose an addition to the
risk register.
B. contact the application administrators and request that they
enable encryption of the application's web traffic.
C. alert all staff about the vulnerability and advise them not to
log on from public networks.

, D. accept that current controls are suitable for nonsensitive
business data. - correct answer- A


A global enterprise that is subject to regulation by multiple
governmental jurisdictions with differing
requirements should:
A. bring all locations into conformity with the aggregate
requirements of all governmental jurisdictions.
B. bring all locations into conformity with a generally accepted
set of industry best practices.
C. establish a baseline standard incorporating those
requirements that all jurisdictions have in common.
D. establish baseline standards for all locations and add
supplemental standards as required. - correct answer- D


A global financial institution has decided not to take any further
action on a denial-of-service (DoS) vulnerability
found by the risk assessment team. The MOST likely reason for
making this decision is that:
A. the needed countermeasure is too complicated to deploy.
B. there are sufficient safeguards in place to prevent this risk
from happening.
C. the likelihood of the risk occurring is unknown.

Written for

Institution
CRISC
Course
CRISC

Document information

Uploaded on
April 2, 2026
Number of pages
163
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$17.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Delmahubcham Chamberlain College Of Nursing
Follow You need to be logged in order to follow users or courses
Sold
50
Member since
1 year
Number of followers
0
Documents
3902
Last sold
6 days ago
NURSING : testbanks, study guides, study questions, sammary and many others

Welcome to Delmahubcham – Your Nursing Exam Hub! At Delmahubcham, we specialize in high-quality nursing exam materials, study guides, and past papers designed to help you excel with confidence. Whether you’re preparing for clinical assessments, pharmacology, or fundamental nursing exams, you’ll find everything you need to succeed. ✨ Special Offer: Buy any two exams and get one exam FREE!

4.4

12 reviews

5
8
4
1
3
3
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions