CRISC Certified in Risk and Information Systems Control practice questions

251 free questions with answers and explanations.

Practice test
  1. 201.A healthcare organization is implementing a new electronic health record (EHR) system. Senior management has designated the Chief Medical Information Officer (CMIO) as the individual responsible for ensuring that all risks associated with patient data privacy and system availability are appropriately managed throughout the system's lifecycle. This designation best describes the role of a:Risk Response and Reporting
  2. 202.A global e-commerce company is evaluating its control environment for financial reporting. The company relies on a complex, interconnected system of applications and databases across multiple regions. The risk practitioner observes that while individual application controls are well-documented, there is a lack of clear ownership and accountability for the overall end-to-end financial reporting process, especially concerning data integrity as it flows between systems. Which of the following is the MOST significant risk exposure arising from this observation?Risk Response and Reporting
  3. 203.A financial institution is reviewing its risk response strategies for potential cyberattacks. They have implemented advanced intrusion detection systems, firewalls, and regular employee training. However, the residual risk of a successful, sophisticated attack remains. The risk practitioner recommends purchasing a cyber insurance policy to cover potential financial losses from such an event. Which of the following risk response strategies is being employed by purchasing the insurance policy?Risk Response and Reporting
  4. 204.An organization is evaluating the effectiveness of its control environment for financial reporting. A recent audit revealed several instances where journal entries were posted without proper managerial approval, leading to minor financial discrepancies. The risk practitioner recommends implementing a workflow system that digitally routes all journal entries to the appropriate manager for approval before posting. This is an example of improving which aspect of control effectiveness?Risk Response and Reporting
  5. 205.A retail company has identified that its point-of-sale (POS) systems are vulnerable to malware attacks, potentially leading to credit card data breaches. The risk committee decides to implement endpoint detection and response (EDR) software across all POS terminals and conduct monthly vulnerability scans. Which control objective is primarily addressed by these actions?Risk Response and Reporting
  6. 206.During a quarterly risk report presentation, the board of directors expresses concern that several high-priority risks identified in the previous quarter have not shown significant improvement in their residual risk levels. The risk practitioner has confirmed that the agreed-upon mitigation strategies were implemented as planned. What is the MOST likely underlying issue the risk practitioner should investigate?Risk Response and Reporting
  7. 207.An organization relies heavily on a third-party vendor for its critical cloud infrastructure. The risk practitioner is conducting a review of the vendor's disaster recovery capabilities. The vendor's Service Level Agreement (SLA) specifies a Recovery Point Objective (RPO) of 4 hours and a Recovery Time Objective (RTO) of 8 hours. The organization's internal business continuity plan requires an RPO of 2 hours and an RTO of 4 hours for this critical service. What is the MOST appropriate action for the CRISC practitioner to recommend?Risk Response and Reporting
  8. 208.A software development company uses a continuous integration/continuous delivery (CI/CD) pipeline. During a recent audit, it was found that security testing is only performed at the final stage before deployment, missing vulnerabilities introduced earlier in the development lifecycle. To strengthen control monitoring and effectiveness, the risk manager recommends integrating automated security testing (e.g., SAST, DAST) at earlier stages of the pipeline. This recommendation primarily aims to improve which aspect of control effectiveness?Risk Response and Reporting
  9. 209.A healthcare organization is subject to strict data privacy regulations, including HIPAA. The risk management team is documenting controls for its electronic health record (EHR) system. They have identified a control requiring all patient data access to be logged and reviewed weekly for suspicious activity. Which of the following is the MOST appropriate classification for this control in terms of its timing?Risk Response and Reporting
  10. 210.A company has identified a critical vulnerability in a legacy system that processes sensitive customer data. Due to the system's age and complexity, patching is not feasible, and replacing it will take 18-24 months. The risk owner decides to implement a temporary solution involving network segmentation, enhanced logging, and continuous monitoring by a dedicated security team. This approach is an example of which risk response strategy?Risk Response and Reporting
  11. 211.A healthcare organization is implementing a new electronic health record (EHR) system. Senior management has designated the Chief Medical Officer (CMO) as the 'risk owner' for risks related to patient data accuracy and clinical workflow disruption. Which of the following best describes the CMO's primary responsibility in this role?Risk Response and Reporting
  12. 212.A large pharmaceutical company is developing a new drug. The project involves significant regulatory compliance requirements (e.g., FDA regulations) and complex clinical trials. To manage the risk of non-compliance, the company establishes a dedicated regulatory affairs department responsible for interpreting regulations, developing compliance procedures, and conducting internal audits. This department's ongoing activities are an example of which type of control?Risk Response and Reporting
  13. 213.A large pharmaceutical company is developing a new drug. The project involves significant regulatory compliance requirements and intellectual property (IP) protection. The risk practitioner is tasked with designing controls for the research and development (R&D) phase. To prevent unauthorized access to sensitive research data and ensure regulatory adherence, the practitioner recommends implementing strict role-based access controls (RBAC), mandatory data encryption for all R&D data, and regular training on data handling policies. These controls are primarily examples of which of the following?Risk Response and Reporting
  14. 214.A manufacturing company relies heavily on its operational technology (OT) systems for production. A recent risk assessment identified that these systems are highly vulnerable to cyberattacks due to outdated software and network isolation challenges. The company decides to invest in a dedicated OT security monitoring solution and implement strict access controls. Furthermore, it establishes a formal incident response plan specifically for OT systems. This comprehensive approach to risk management for OT systems primarily demonstrates the application of:Risk Response and Reporting
  15. 215.A financial institution is preparing its annual risk report for the board of directors. The report includes key risk indicators (KRIs), control effectiveness metrics, and a summary of residual risks. The board members express concern that the report often presents a fragmented view, with different departments reporting on their risks using inconsistent methodologies and terminology, making it difficult to gain a holistic understanding of the organization's overall risk posture. Which characteristic of effective risk reporting is primarily lacking?Risk Response and Reporting
  16. 216.A multinational corporation uses a centralized Security Information and Event Management (SIEM) system to aggregate security logs from all its global subsidiaries. The security team reviews alerts daily, but there's concern that the sheer volume of data makes it difficult to detect sophisticated, low-volume attacks. To optimize control monitoring, which of the following approaches should the risk practitioner recommend FIRST?Risk Response and Reporting
  17. 217.A large retail company is preparing its annual risk report for the audit committee. The report includes a summary of the top 10 risks, their current residual risk levels, and the status of mitigation efforts. To ensure the report provides comprehensive and actionable information, what critical element should the risk practitioner also ensure is clearly articulated for each risk?Risk Response and Reporting
  18. 218.An organization relies heavily on a third-party vendor for its critical cloud infrastructure. The risk assessment identifies that a data breach at the vendor's side could lead to significant regulatory fines and reputational damage for the organization. To address this, the organization updates its contract with the vendor to include clauses that mandate specific security controls, regular independent audits, and a financial liability clause requiring the vendor to pay penalties if a breach occurs due to their negligence. The financial liability clause primarily represents which risk response strategy?Risk Response and Reporting
  19. 219.An organization has implemented a new access control system. As part of control monitoring, the risk practitioner reviews audit logs daily for failed login attempts. This activity is primarily intended to assess which of the following aspects of the control?Risk Response and Reporting
  20. 220.An organization relies on a legacy system for critical business operations. A recent vulnerability assessment identified several high-risk vulnerabilities that cannot be fully patched due to vendor discontinuation and system instability concerns. The business unit manager, who is the risk owner, decides to continue operating the system, implementing compensating controls such as network segmentation and enhanced monitoring, and explicitly documenting the remaining risks and acceptance by senior management. This approach BEST exemplifies which of the following?Risk Response and Reporting
  21. 221.A large pharmaceutical company is developing a new drug. The project involves significant regulatory compliance requirements, including strict data integrity and auditability of all research and development (R&D) data. The company implements a blockchain-based ledger for tracking all experimental results and changes, ensuring an immutable and verifiable record. This control is primarily designed to achieve which of the following control objectives?Risk Response and Reporting
  22. 222.An organization has implemented a new data loss prevention (DLP) solution to monitor and block sensitive data from leaving the corporate network. As part of control monitoring, the risk practitioner regularly reviews logs and alerts generated by the DLP system and finds that 95% of the alerts are false positives. While the DLP system technically blocks data, the high volume of false positives renders the system ineffective in practice, as legitimate business operations are frequently disrupted, and security analysts are overwhelmed. This scenario primarily indicates a failure in which aspect of the control?Risk Response and Reporting
  23. 223.A global manufacturing company uses a Supervisory Control and Data Acquisition (SCADA) system for its production lines. A recent audit highlighted that the SCADA system, being a legacy system, lacks modern authentication mechanisms and is directly accessible from the corporate network, increasing the risk of unauthorized operational changes. The risk practitioner recommends isolating the SCADA network, implementing a jump server for access, and regularly patching the operating system. These actions primarily aim to address which aspect of the risk?Risk Response and Reporting
  24. 224.A healthcare organization uses a legacy electronic health record (EHR) system that has known vulnerabilities and is difficult to patch. Replacing the system is cost-prohibitive in the short term. To manage the risk, the organization implements strict network segmentation, restricts access to the system, and performs frequent integrity checks on the data. These actions primarily represent which control strategy?Risk Response and Reporting
  25. 225.A multinational corporation is preparing its annual risk report for the executive management and board of directors. The report aims to provide a clear, concise, and comprehensive overview of the organization's risk posture. Which of the following risk reporting metrics is MOST crucial to include to demonstrate the effectiveness of implemented controls and the overall success of the risk management program?Risk Response and Reporting
  26. 226.A multinational corporation uses a shared service center for its IT operations. The risk management team has identified a critical dependency on this center for disaster recovery. To ensure the center's controls are effective, the corporation requires the center to provide an annual SOC 2 Type II report. This requirement primarily supports which aspect of risk management?Risk Response and Reporting
  27. 227.A retail company has identified that its point-of-sale (POS) systems are vulnerable to malware attacks, which could compromise sensitive customer credit card data. The risk practitioner recommends implementing endpoint detection and response (EDR) solutions on all POS terminals and configuring them to automatically quarantine suspicious processes. The primary control objective being addressed by this recommendation is:Risk Response and Reporting
  28. 228.A financial institution has identified a significant risk related to unauthorized access to customer data through its online banking portal. The risk management team proposes implementing multi-factor authentication (MFA) for all login attempts. Which of the following risk responses does this action primarily represent?Risk Response and Reporting
  29. 229.A manufacturing company uses a Supervisory Control and Data Acquisition (SCADA) system for its production lines. A recent risk assessment identified a critical vulnerability in the SCADA system's remote access module that could allow unauthorized control over operations, leading to significant safety and production risks. The company decides to implement a two-factor authentication (2FA) system, restrict remote access to specific IP addresses, and conduct weekly security patch reviews. These actions primarily address which aspect of the risk?Risk Response and Reporting
  30. 230.A global manufacturing company uses a third-party cloud provider for its critical enterprise resource planning (ERP) system. The company's risk assessment identifies a significant risk related to the cloud provider's data sovereignty practices and compliance with GDPR for European customer data. The cloud provider's standard contract does not include specific GDPR clauses or guarantees for data location. Which of the following is the MOST effective approach for the company's risk practitioner to address this identified risk?Risk Response and Reporting
  31. 231.A multinational corporation is evaluating its control environment for financial reporting. An internal audit reveals that while access controls to the ERP system are robust, there is no formal process for reviewing user access rights when employees change roles or leave the company. This omission has led to several instances of former employees retaining access for weeks. Which type of control weakness does this scenario primarily represent?Risk Response and Reporting
  32. 232.A pharmaceutical company is developing a new drug. The project involves significant regulatory compliance risks. The risk management team needs to ensure that all relevant regulations (e.g., FDA, EMA) are considered and that controls are designed to meet these requirements. Which type of control is MOST critical to implement to ensure proactive adherence to these external mandates throughout the drug development lifecycle?Risk Response and Reporting
  33. 233.A financial services organization has identified a high risk of unauthorized access to its critical customer database. To address this, they implement multi-factor authentication (MFA) for all database administrators, regular security awareness training, and an intrusion detection system (IDS) to alert on suspicious activities. During a recent review, the risk practitioner notes that the IDS frequently generates alerts, but these alerts are often ignored or dismissed without proper investigation due to their high volume and lack of context. Which of the following is the MOST significant implication of this situation?Risk Response and Reporting
  34. 234.An organization has implemented a new data loss prevention (DLP) solution. As part of control monitoring, the risk practitioner is reviewing the DLP logs. They notice a significant number of alerts indicating attempts to transfer sensitive data to unauthorized external cloud storage services, but these transfers were successfully blocked by the DLP. What is the MOST important implication of these findings for the organization's risk posture?Risk Response and Reporting
  35. 235.A global technology company has outsourced its entire IT infrastructure to a major cloud service provider (CSP). The service level agreement (SLA) with the CSP specifies strict uptime guarantees, data residency requirements, and security incident response times. However, the company's risk assessment reveals that while the CSP is generally secure, a catastrophic regional outage at the CSP's data centers could still lead to significant business disruption for the company, even with the SLA in place. The company decides to implement a multi-cloud strategy, distributing critical workloads across different CSPs in separate geographical regions. This decision is an example of which risk response strategy?Risk Response and Reporting
  36. 236.A global technology company has outsourced its entire IT infrastructure to a major cloud service provider (CSP). As part of the contractual agreement, the CSP is responsible for all aspects of infrastructure security, including patching, vulnerability management, and physical security of data centers. The technology company retains responsibility for data classification and access management within its applications. This arrangement primarily demonstrates which risk response strategy for infrastructure security?Risk Response and Reporting
  37. 237.During a quarterly risk committee meeting, the CISO presents a report indicating that the organization's residual risk for ransomware attacks remains high, despite implementing endpoint detection and response (EDR) solutions and regular backups. The committee asks for a strategy to further reduce this residual risk to an acceptable level. Which of the following strategies would be MOST appropriate for addressing high residual risk?Risk Response and Reporting
  38. 238.A telecommunications company uses a centralized Security Information and Event Management (SIEM) system to collect and analyze security logs from across its entire infrastructure. The SIEM is configured to generate alerts for specific suspicious activities, such as multiple failed login attempts from a single IP address or unusual data egress patterns. However, the security operations center (SOC) team frequently struggles with a high volume of low-priority, unactionable alerts, leading to 'alert fatigue' and a risk of legitimate threats being missed. Which of the following is the MOST appropriate immediate action for the CRISC professional to recommend to improve the effectiveness of control monitoring?Risk Response and Reporting
  39. 239.A financial institution is preparing its quarterly risk report for the board of directors. The report needs to include information on emerging risks, the status of key controls, and the effectiveness of risk response strategies. The board has also requested an update on the organization's overall risk appetite. Which of the following is the MOST critical characteristic for the information presented in this report to ensure effective governance?Risk Response and Reporting
  40. 240.A financial institution is implementing a new customer relationship management (CRM) system. During the risk assessment, it is identified that the system's default security settings are insufficient to protect sensitive customer data from unauthorized access, potentially leading to significant reputational damage and regulatory fines. The risk practitioner recommends configuring stricter access controls, enabling multi-factor authentication, and encrypting data at rest and in transit. Which of the following risk responses is being applied?Risk Response and Reporting
  41. 241.A manufacturing company relies heavily on its operational technology (OT) systems for production. A recent risk assessment identified a high likelihood of a cyber-attack disrupting these systems, leading to significant production downtime and financial losses. The company has decided to implement a comprehensive incident response plan, including regular drills and a dedicated OT security team. Which of the following risk response types does this action MOST closely represent?Risk Response and Reporting
  42. 242.A software development company is migrating its entire code repository to a new cloud-based version control system. A critical risk identified is 'Data loss during migration due to unforeseen compatibility issues or human error.' The risk owner, in consultation with the CRISC practitioner, decides to implement a detailed migration plan, perform multiple test migrations with simulated data, and establish a comprehensive rollback strategy. These actions represent which of the following risk response strategies?Risk Response and Reporting
  43. 243.A financial services organization has implemented a new security awareness training program for all employees. The program includes regular phishing simulations and modules on data handling best practices. Which of the following risk response strategies does this program primarily represent?Risk Response and Reporting
  44. 244.A global manufacturing company is conducting its annual IT risk assessment. The risk team identifies a potential supply chain disruption due to a cyber-attack on a critical third-party logistics provider. To ensure this risk scenario is comprehensive and actionable, which of the following elements is MOST crucial to include?IT Risk Assessment
  45. 245.During a quarterly risk committee meeting, the CISO presents a report indicating that despite implementing a new firewall and intrusion prevention system, the organization's exposure to external cyber threats remains high, primarily due to unpatched legacy applications. The committee decides to allocate additional budget to accelerate the patching cycle for these applications. What type of control is accelerating the patching cycle primarily considered?Risk Response and Reporting
  46. 246.A financial services organization is assessing the risks associated with its new cloud-based customer relationship management (CRM) system. One identified risk is 'unauthorized access to sensitive customer data due to a misconfigured cloud storage bucket.' The risk team is trying to determine the most effective mitigation strategy for this specific risk. Which of the following risk response strategies is MOST appropriate for directly addressing this scenario?IT Risk Assessment
  47. 247.A global e-commerce company uses a third-party payment gateway to process all customer transactions. As part of its risk management framework, the company regularly reviews the payment gateway's security certifications, audit reports, and incident response plans. Which of the following control monitoring activities is the company primarily performing?Risk Response and Reporting
  48. 248.A financial services organization is assessing the risks associated with its new cloud-based customer relationship management (CRM) system. During the risk analysis, it is determined that a critical vulnerability exists in the system's authentication module. Remediation efforts are estimated to cost $50,000, and the likelihood of a successful exploit resulting in a data breach is 20% annually. If a data breach occurs, the estimated loss is $2,000,000. What is the Annualized Loss Expectancy (ALE) for this specific risk, assuming the vulnerability is NOT remediated?IT Risk Assessment
  49. 249.A manufacturing company relies heavily on its operational technology (OT) systems for production. A recent risk assessment identified a significant vulnerability in a legacy OT system that, if exploited, could halt production for an extended period. The company decides to implement an isolated network segment for this system, along with strict access controls and continuous monitoring, but acknowledges that a residual risk of disruption remains due to the system's age. Which of the following best describes the company's approach to this risk?Risk Response and Reporting
  50. 250.A financial institution is implementing a new customer relationship management (CRM) system. To ensure data privacy and regulatory compliance, the project team is documenting all data flows, access permissions, and encryption standards for sensitive customer information within the new system. This documentation will be regularly reviewed and updated. Which of the following is the primary purpose of this control documentation?Risk Response and Reporting