CRISC Certified in Risk and Information Systems Control practice questions
251 free questions with answers and explanations.
- 151.An organization's risk register contains over 500 entries, many of which are outdated, duplicates, or lack sufficient detail for actionable decision-making. A CRISC professional is tasked with optimizing the risk register to make it a more effective risk management tool. Which of the following approaches should be prioritized FIRST?IT Risk Assessment
- 152.A manufacturing company relies heavily on a single third-party vendor for its operational technology (OT) software. The vendor recently announced a significant price increase and mandatory migration to a new, proprietary platform. This situation presents a heightened risk of being unable to switch to an alternative vendor without incurring substantial costs and operational disruption. Which type of risk does this scenario BEST describe?IT Risk Assessment
- 153.A software development company is migrating its code repositories to a new platform. The risk manager is populating the risk register with potential issues. Which of the following risk statements BEST adheres to the FAIR (Factor Analysis of Information Risk) ontology for effective risk analysis?IT Risk Assessment
- 154.A global manufacturing company is consolidating its regional IT infrastructure into a single, cloud-based platform. The project team identifies a significant risk related to vendor lock-in with the chosen cloud provider. Which of the following risk response strategies would be MOST effective in addressing this specific concern?IT Risk Assessment
- 155.A healthcare organization is developing a risk scenario for 'Unauthorized Access to Patient Records via a Phishing Attack'. Which component of a well-structured risk scenario MOST accurately describes the motivation and capabilities of the threat actor?IT Risk Assessment
- 156.A multinational corporation is updating its IT risk register. The current register includes entries like 'Risk of Phishing Attacks' and 'Risk of Malware Infection'. The risk manager wants to improve the specificity and actionability of these entries to better support risk response planning. Which of the following is the BEST example of an improved risk scenario for 'Risk of Phishing Attacks'?IT Risk Assessment
- 157.A company is developing a risk scenario for 'Unauthorized Access to Sensitive Customer Data via a Vulnerable Web Application Interface'. Which of the following elements BEST represents the 'threat' component of this scenario?IT Risk Assessment
- 158.During an IT risk analysis, a critical application is identified as being hosted on an outdated operating system with known vulnerabilities. The organization has acknowledged this risk but has decided to postpone patching due to budget constraints and the complexity of testing the legacy application. Which risk response strategy has the organization adopted?IT Risk Assessment
- 159.A multinational corporation is developing a detailed risk scenario for a 'Supply Chain Cyber-Attack that Disrupts Global Operations'. To make this scenario actionable and useful for risk response planning, which of the following elements is MOST crucial to include beyond just the threat and impact?IT Risk Assessment
- 160.A financial institution is evaluating the risk associated with a new mobile banking application. During the risk identification phase, the team considers potential vulnerabilities in the application's code, the underlying operating system, and the network infrastructure. Which of the following risk identification techniques is being primarily applied in this scenario?IT Risk Assessment
- 161.An organization relies heavily on a third-party cloud provider for its critical data storage. The risk management team has identified 'Vendor Lock-in' as a significant risk. During the risk analysis and evaluation phase, which of the following would be the MOST effective approach to assess the impact of this risk?IT Risk Assessment
- 162.An IT department is implementing a new customer relationship management (CRM) system. During the risk analysis, the team identifies a potential risk: 'Loss of customer data due to insufficient access controls'. The inherent risk is determined to be 'High'. After implementing granular role-based access controls and conducting user training, the residual risk is assessed as 'Medium'. What is the MOST critical next step for the risk manager regarding this specific risk?IT Risk Assessment
- 163.A newly appointed CRISC professional is reviewing an organization's risk register. They notice that many entries lack clear ownership, making it difficult to track progress on risk responses. Which section of a well-maintained risk register should the CRISC professional recommend updating to address this issue?IT Risk Assessment
- 164.A financial institution is implementing a new online banking platform. During the IT risk identification phase, the risk manager needs to ensure all potential threats and vulnerabilities are considered. Which of the following techniques is MOST effective for identifying novel and emerging risks that may not be apparent from historical data?IT Risk Assessment
- 165.A project manager is reviewing the risk register for a critical system upgrade. They notice several entries describing generic risks such as 'system failure' or 'data loss' without specifying the cause, affected assets, or potential impact. Which aspect of effective risk scenario development is MOST lacking in these entries?IT Risk Assessment
- 166.A global e-commerce company is evaluating the risk of a major data breach involving customer credit card information. The risk analysis team has identified the potential impact as 'Critical' and the likelihood as 'High' based on a qualitative risk matrix. Given the organization's risk appetite, which states that 'risks with Critical impact and High likelihood are unacceptable and require immediate action', what is the MOST appropriate next step for the risk manager?IT Risk Assessment
- 167.A newly implemented enterprise resource planning (ERP) system has undergone a comprehensive risk assessment. Several high-risk items were identified, and management decided to implement new security controls to mitigate these risks. After the controls are in place, the residual risk is still deemed 'High' due to the system's criticality and the remaining inherent vulnerabilities. What is the MOST appropriate next step for the CRISC professional?IT Risk Assessment
- 168.A global conglomerate is performing a quantitative risk analysis for its cloud infrastructure. The risk manager is struggling to obtain precise historical data for the Annualized Rate of Occurrence (ARO) for specific cloud-native security incidents. Which of the following approaches would be MOST appropriate to estimate ARO in this situation?IT Risk Assessment
- 169.A healthcare organization is conducting an IT risk assessment for its new patient portal. During the risk identification phase, the team uses a systematic approach to uncover potential threats and vulnerabilities. Which of the following techniques is BEST suited for identifying both known and unknown risks by breaking down the system into its components and analyzing potential failure points?IT Risk Assessment
- 170.A software development company is migrating its code repositories to a new platform. The risk team is using a qualitative risk analysis approach to assess potential impacts. They are categorizing risks based on a matrix that considers likelihood and impact. Which of the following factors is MOST critical to ensure the consistency and objectivity of the qualitative risk ratings across different assessors?IT Risk Assessment
- 171.A security operations center (SOC) manager is reviewing their organization's risk register. They notice that many identified risks lack clear descriptions of the existing controls in place to mitigate them, or the residual risk level post-control implementation. This omission makes it difficult to prioritize remediation efforts and understand the organization's true risk posture. Which essential element of a comprehensive risk register is MOST overlooked in this situation?IT Risk Assessment
- 172.A global e-commerce company is evaluating the risk of a major data breach involving customer credit card information. The risk manager has estimated the Single Loss Expectancy (SLE) for such an event to be $5,000,000. Based on industry benchmarks and internal security assessments, they anticipate that a major data breach is likely to occur once every five years. What is the Annualized Loss Expectancy (ALE) for this risk?IT Risk Assessment
- 173.A large e-commerce company is evaluating the risk of a major data breach. The risk manager calculates the Annualized Loss Expectancy (ALE) for this scenario. Given an Asset Value (AV) of $10,000,000, an Exposure Factor (EF) of 0.75, and an Annualized Rate of Occurrence (ARO) of 0.05, what is the ALE for this data breach scenario?IT Risk Assessment
- 174.A software development company is migrating its code repositories to a new platform. The risk team is conducting a qualitative risk assessment. To ensure consistency and objectivity across different assessors, which of the following practices is MOST important for evaluating risk likelihood and impact?IT Risk Assessment
- 175.A manufacturing company is assessing the risk of a cyber-attack disrupting its production line. The risk management team uses a qualitative risk matrix, where 'likelihood' is rated from 1 (rare) to 5 (almost certain) and 'impact' is rated from 1 (insignificant) to 5 (catastrophic). A specific scenario, 'Ransomware Attack on Production Control Systems', is assessed as having a likelihood of 4 and an impact of 5. The company's risk appetite states that any risk with a total score (likelihood × impact) above 15 is unacceptable. What is the MOST appropriate immediate action for this risk?IT Risk Assessment
- 176.An organization is developing a risk scenario for 'Unauthorized Access to Customer Data via a Third-Party Vendor Compromise.' Which of the following elements, if omitted, would MOST likely hinder the effective analysis and response planning for this specific scenario?IT Risk Assessment
- 177.A security operations center (SOC) manager is reviewing their organization's risk register. They find an entry: 'Risk ID: R-015, Risk Description: Unauthorized access to internal network, Likelihood: High, Impact: Critical, Risk Owner: IT Operations.' The manager notes that there are no specific mitigation steps or controls documented. What is the MOST critical missing element for effective risk management of R-015?IT Risk Assessment
- 178.A multinational corporation is updating its IT risk register. The current register includes entries for 'Data Breach,' 'System Outage,' and 'Malware Infection.' The CRISC professional observes that these entries are too broad and lack specific details for effective management. To improve the risk register, which of the following actions should the CRISC professional prioritize?IT Risk Assessment
- 179.A manufacturing company is assessing the risk of a cyber-attack disrupting its production line. The likelihood of such an event is estimated to be 'Medium' (3 on a scale of 1-5), and the impact is rated as 'High' (4 on a scale of 1-5) due to significant financial losses and reputational damage. Using a qualitative risk matrix, what would be the MOST appropriate risk level designation?IT Risk Assessment
- 180.An organization's risk register currently contains over 200 identified risks, many of which have similar characteristics and potential impacts. The risk management team spends considerable time reviewing and updating these entries. To improve efficiency and focus on material risks, which action should the risk manager prioritize?IT Risk Assessment
- 181.A financial services organization is performing an IT risk assessment. A key finding is that several critical legacy systems are approaching end-of-life and lack vendor support for security patches. Migrating these systems to modern infrastructure is cost-prohibitive in the short term. The risk management team decides to implement compensating controls, such as network segmentation and enhanced intrusion detection, and to increase monitoring. Which risk response strategy does this BEST represent?IT Risk Assessment
- 182.An organization is using the Factor Analysis of Information Risk (FAIR) methodology to quantify the risk of a cyber-attack leading to a data breach. The risk team is currently estimating the frequency with which a threat agent (e.g., a hacker group) is likely to initiate an attack against the organization's assets. Which FAIR component is the team primarily focused on determining at this stage?IT Risk Assessment
- 183.A financial institution is evaluating the risk of a denial-of-service (DoS) attack on its online banking platform. The risk team estimates the likelihood of such an attack occurring in a given year is 20%, and the potential financial loss from a successful attack is $500,000. What is the Annualized Loss Expectancy (ALE) for this specific risk?IT Risk Assessment
- 184.A telecommunications company is evaluating the risk of a major service outage due to a natural disaster. The risk management team estimates the likelihood of such an event occurring once every 10 years and the potential financial impact to be $5,000,000 per occurrence. The company's current insurance policy covers 60% of the financial impact for such events. What is the Annualized Loss Expectancy (ALE) for this risk AFTER considering the insurance coverage?IT Risk Assessment
- 185.An organization has implemented an intrusion detection system (IDS) to alert security personnel of suspicious network activity. This IDS is configured to log all alerts and send notifications to a security operations center (SOC) for immediate review. What type of control is this IDS primarily functioning as?Risk Response and Reporting
- 186.A financial services organization is implementing a new customer relationship management (CRM) system. To ensure data integrity, the control design includes automated reconciliation checks between the CRM and the core banking system at the end of each business day. Additionally, a manual review of reconciliation exceptions is performed by a data analyst. Which principle of control design is BEST exemplified by the combination of these automated and manual reconciliation processes?Risk Response and Reporting
- 187.A global manufacturing company is implementing a new enterprise resource planning (ERP) system. The project team has identified a high risk of data integrity issues due to potential errors during data migration from legacy systems. To address this, they plan to implement automated data validation scripts, conduct reconciliation checks after migration, and establish a clear data ownership matrix. Which type of control is primarily being designed and implemented for the reconciliation checks?Risk Response and Reporting
- 188.During a quarterly risk committee meeting, the CISO presents a report indicating that the organization's residual risk related to external cyber threats has increased significantly due to newly identified zero-day vulnerabilities. The board expresses concern and asks for immediate action. What is the MOST appropriate next step for the risk committee to recommend?Risk Response and Reporting
- 189.A global manufacturing company is implementing a new enterprise resource planning (ERP) system. The project manager identifies a risk that customizations to the ERP system could introduce security vulnerabilities. To address this, the company mandates that all custom code undergo a static application security testing (SAST) review by an independent security team before deployment. Which control design principle is primarily demonstrated by this action?Risk Response and Reporting
- 190.A financial institution is implementing a new online banking platform. During the risk assessment, a high-impact, medium-likelihood risk of unauthorized access to customer accounts via a zero-day exploit is identified. The cost of implementing a robust intrusion prevention system (IPS) and advanced threat intelligence feeds to mitigate this risk is estimated at $500,000. The potential financial loss from a single successful breach is estimated at $10 million, with a 5% chance of occurring annually if no controls are implemented. What is the most appropriate risk response strategy for the institution to adopt?Risk Response and Reporting
- 191.A global manufacturing company is implementing a new enterprise resource planning (ERP) system. During the risk assessment, a critical risk is identified: 'Failure of data migration from legacy systems leading to significant operational disruption.' The project manager proposes assigning a dedicated data migration team, conducting multiple pilot migrations, and implementing a rollback plan. Which of the following best describes the primary goal of these actions?Risk Response and Reporting
- 192.A financial services organization has identified a significant risk of data exfiltration due to sophisticated phishing attacks targeting its employees. The current controls include email filters and basic security awareness training. To effectively reduce this risk, which of the following control enhancements would be MOST appropriate for implementation?Risk Response and Reporting
- 193.An organization is migrating its data center to a co-location facility. The risk practitioner is reviewing the service level agreement (SLA) with the co-location provider. The SLA specifies a guaranteed uptime of 99.999% and a maximum response time of 30 minutes for critical incidents. This contractual agreement primarily serves as a mechanism for which risk response strategy?Risk Response and Reporting
- 194.A software development company uses a continuous integration/continuous delivery (CI/CD) pipeline for deploying its applications. To enhance security, the company integrates automated security testing tools (e.g., static application security testing - SAST, dynamic application security testing - DAST) into the early stages of the development cycle, immediately after code is committed and before deployment to production. This approach aligns with which security concept?Risk Response and Reporting
- 195.A financial institution has identified a high risk of unauthorized access to its core banking systems, which could lead to significant financial losses and reputational damage. The current controls include strong passwords and basic intrusion detection. The risk committee mandates a more robust control environment. Which of the following control design principles would be MOST effective in strengthening the overall security posture against this risk?Risk Response and Reporting
- 196.A retail company has implemented a new point-of-sale (POS) system across all its stores. To ensure the system processes transactions accurately and securely, the company has implemented several controls: encryption for card data, daily reconciliation of transactions, and quarterly vulnerability scans. After six months, an internal audit reveals that while encryption is working, the daily reconciliation process is often delayed, and vulnerability scan reports are not consistently reviewed. Which of the following statements BEST describes the overall control effectiveness for the POS system?Risk Response and Reporting
- 197.A retail company has identified that its point-of-sale (POS) systems are vulnerable to malware attacks, potentially leading to credit card data theft. To address this, the company implements end-to-end encryption for all credit card transactions, tokenization of cardholder data, and strict network segmentation for POS devices. These controls are primarily designed to achieve which of the following control objectives?Risk Response and Reporting
- 198.A cloud service provider (CSP) offers enterprise-grade services with built-in security features, including encryption at rest and in transit, and robust identity and access management (IAM) controls. A client organization using this CSP is able to reduce its own investment in certain security controls due to the CSP's offerings. This scenario best illustrates which aspect of risk response?Risk Response and Reporting
- 199.An organization has implemented a new data loss prevention (DLP) solution to monitor and block the exfiltration of sensitive data. As part of control monitoring, the risk manager reviews weekly reports showing a significant number of DLP alerts, but further investigation reveals that most of these are false positives or legitimate business activities. What conclusion should the risk manager draw regarding the DLP control's effectiveness and its impact on risk reporting?Risk Response and Reporting
- 200.A software development company is migrating its entire code repository to a new cloud-based version control system. A risk assessment identifies that a critical risk exists if proper access controls are not implemented, potentially leading to unauthorized code modification or intellectual property theft. The risk practitioner recommends implementing multi-factor authentication (MFA) and least privilege access as part of the new system's control design. These controls are primarily designed to address which aspect of the risk?Risk Response and Reporting