Sign In
Home/ISACA/CRISC/Free questions

CRISC — Free Practice Questions

10 free sample questions from a bank of 2240, with the correct answers and explanations. No signup required — start practising right now.

1Which of the following is the MOST important reason to maintain key risk indicators (KRIs)?
  • In order to avoid risk
  • Complex metrics require fine-tuning
  • Risk reports need to be timely
  • Threats and vulnerabilities change over time
Answer: D
2Which of the following controls is an example of non-technical controls?
  • Access control
  • Physical security
  • Intrusion detection system
  • Encryption
Answer: B
3Which of the following is the MOST important consideration when developing risk strategies?
  • Long-term organizational goals
  • Organization's industry sector
  • Concerns of the business process owners
  • History of risk events
Answer: A
4Which of the following would BEST facilitate the implementation of data classification requirements?
  • Implementing technical controls over the assets
  • Implementing a data loss prevention (DLP) solution
  • Scheduling periodic audits
  • Assigning a data owner
Answer: D
5An organization has used generic risk scenarios to populate its risk register. Which of the following presents the GREATEST challenge to assigning ownership of the associated risk entries?
  • The volume of risk scenarios is too large.
  • Risk scenarios are not applicable.
  • The risk analysis for each scenario is incomplete.
  • Risk aggregation has not been completed.
Answer: B
6An organization's business process requires the verbal verification of personal information in an environment where other customers may overhear this information. Which of the following is the MOST significant risk?
  • The customer may view the process negatively.
  • The information could be used for identity theft.
  • The process could result in intellectual property theft.
  • The process could result in compliance violations.
Answer: B
7An organization has initiated a project to launch an IT-based service to customers and take advantage of being the first to market. Which of the following should be of GREATEST concern to senior management?
  • The project is likely to deliver the product late.
  • More time has been allotted for testing.
  • A new project manager is handling the project.
  • The cost of the project will exceed the allotted budget.
Answer: A
8Which of the following is the MOST important objective of embedding risk management practices into the initiation phase of the project management life cycle?
  • To deliver projects on time and on budget
  • To assess inherent risk
  • To assess risk throughout the project
  • To include project risk in the enterprise-wide IT risk profile
Answer: C
9Which of the following is the MOST significant indicator of the need to perform a penetration test?
  • An increase in the number of infrastructure changes
  • An increase in the number of security incidents
  • An increase in the number of high-risk audit findings
  • An increase in the percentage of turnover in IT personnel
Answer: A
10Which of the following provides the MOST reliable information to ensure a newly acquired company has appropriate IT controls in place?
  • Vulnerability assessment
  • Information system audit
  • Penetration testing
  • IT risk assessment
Answer: D

Want the full bank of 2240 questions for CRISC? See all practice exams.