Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Isaca Certified in Risk and Information Systems Control CRISC Exam Questions

Page: 1 / 134 Total 2002 questions

Want more questions? Get Premium Access.

Question 1

A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner s NEXT step? r

Correct Answer: D. Update the risk register with the results.
Explanation:

The risk practitioner's next step after identifying risk owners and responses for newly identified risk scenarios in a recent risk workshop is to update the risk register with the results, as it involves documenting and communicating the risk information and decisions, and maintaining the accuracy and completeness of the risk register. Preparing a business case for the response options, identifying resources for implementing responses, and developing a mechanism for monitoring residual risk are possible steps, but they are not the next step, as they require the prior update of the risk register with the new risk information and decisions.Reference= CRISC Review Manual, 7th Edition, page 109.


Question 2

Which of the following is MOST important when developing key risk indicators (KRIs)?

Correct Answer: C. Properly set thresholds
Explanation:

The most important factor when developing key risk indicators (KRIs) is to properly set thresholds, which are the predefined values or ranges that indicate the acceptable or unacceptable level of risk1. Thresholds can help to:

Trigger alerts or actions when the risk level exceeds or falls below the threshold, and enable timely and appropriate risk responses2.

Measure and monitor the performance and effectiveness of the risk responses, and ensure that the residual risk is within the risk appetite and tolerance3.

Communicate and report the risk status and performance to the stakeholders, and facilitate the decision-making and accountability for the risk management4.

The other factors are not the most important when developing KRIs, because:

Alignment with regulatory requirements is a necessary but not sufficient factor when developing KRIs, as it ensures that the KRIs comply with the applicable laws, rules, or standards that govern the organization's activities and operations5. However, alignment with regulatory requirements does not guarantee that the KRIs are relevant and useful for the organization's specific risk profile and objectives.

Availability of qualitative data is a desirable but not essential factor when developing KRIs, as it provides additional information or insights that may not be captured by quantitative data, such as opinions, perceptions, or feedback. However, availability of qualitative data does not ensure that the KRIs are reliable and consistent, as qualitative data may be subjective and difficult to measure and compare.

Alignment with industry benchmarks is a useful but not critical factor when developing KRIs, as it provides a reference or a standard for comparing the organization's risk level and performance with its peers or competitors. However, alignment with industry benchmarks does not ensure that the KRIs are suitable and feasible for the organization's specific context and capabilities.

Reference=

Threshold - CIO Wiki

Risk Thresholds: How to Set Them and When to Use Them - ProjectManager.com

Risk Appetite and Tolerance - CIO Wiki

Risk Reporting - CIO Wiki

Regulatory Compliance - CIO Wiki

[Regulatory Risk - CIO Wiki]

[Qualitative Data - CIO Wiki


Question 3

The PRIMARY reason a risk practitioner would be interested in an internal audit report is to:

Correct Answer: B. evaluate maturity of the risk management process.
Explanation:

According to the CRISC Review Manual (Digital Version), the primary reason a risk practitioner would be interested in an internal audit report is to evaluate the maturity of the risk management process, as it provides an independent and objective assessment of the effectiveness and efficiency of the risk management activities and controls. An internal audit report helps to:

Identify and evaluate the strengths and weaknesses of the risk management process and its alignment with the organization's objectives and strategy

Detect and report any gaps, errors, or deficiencies in the risk identification, assessment, response, and monitoring processes and controls

Recommend and implement corrective actions or improvement measures to address the issues or findings in the risk management process

Communicate and coordinate the audit results and recommendations with the relevant stakeholders, such as the risk owners, the senior management, and the board

Enhance the accountability and transparency of the risk management process and its outcomes

Reference= CRISC Review Manual (Digital Version), Chapter 4: IT Risk Monitoring and Reporting, Section 4.2: IT Risk Reporting, pp.223-2241


Question 4

The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:

Correct Answer: C. identify critical business processes and the degree of reliance on support services.
Explanation:

The primary goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to identify critical business processes and the degree of reliance on support services. A BIA is a process of assessing the potential impact and consequences of a disruption or interruption of the business activities, operations, or functions. A continuity planning processis a process of developing, implementing, and maintaining a plan to ensure the continuity and recovery of the business activities, operations, or functions in the event of a disruption or interruption. The primary goal of conducting a BIA is to identify critical business processes and the degree of reliance on support services, which are the business processes that are essential for the survival and success of the business, and the support services that are required to enable or facilitate the critical business processes, such as IT systems, human resources, facilities, or suppliers. Identifying critical business processes and the degree of reliance on support services helps to determine the priorities and requirements for the continuity and recovery of the business activities, operations, or functions, and to select and implement the appropriate continuity andrecovery strategies and solutions. Obtaining the support of executive management, mapping the business processes to supporting IT and other corporate resources, and documenting the disaster recovery process are not the primary goals of conducting a BIA, as they are either the benefits or the outputs of the BIA process, and they do not address the primary need of assessing the impact and consequences of the business disruption or interruption.Reference= CRISC Review Manual, 6th Edition, ISACA, 2015, page 50.


Question 5

Which of the following is the PRIMARY benefit of using a risk map with stakeholders?

Correct Answer: C. Correlates risk scenarios to risk appetite
Explanation:

Arisk maphelps stakeholders understand how risk scenarios align with the organization'srisk appetite. This visualization facilitates informed decision-making and ensures risk responses are consistent with organizational priorities.


Question 6

A risk heat map is MOST commonly used as part of an IT risk analysis to facilitate risk:

Correct Answer: D. assessment.
Explanation:

A risk heat map is a tool that shows the likelihood and impact of different risks on a matrix, using colors to indicate the level of risk.A risk heat map is most commonly used as part of an IT risk analysis to facilitate risk assessment, which is the process of estimating the probability and consequences of the risks, and comparing them against the risk criteria1.A risk heat map can help to visualize, communicate, and prioritize the risks, as well as to evaluate the effectiveness of the risk response actions2. The other options are not the best choices for describing the purpose of a risk heat map, as they are either less specific or less relevant than risk assessment.Risk communication is the process of sharing and exchanging information about the risks among the stakeholders3. A risk heat map can support risk communication by providing a clear and concise representation of the risks, but it is not the main objective of the tool.Riskidentification is the process of finding, recognizing, and describing the risks that may affect the organization4. A risk heat map can help to identify the risks by categorizing them into different domains or sources, but it is not the primary function of the tool.Risk treatment is the process of selecting and implementing the appropriate measures to modify the risk5. A risk heat map can help to guide the risk treatment by showing the risk ratings and thresholds, but it is not the core purpose of the tool.Reference= Risk and Information Systems Control Study Manual, 7th Edition, Chapter 2, Section 2.1.1, Page 47.


Question 7

Which of the following is the PRIMARY concern related to using pseudonymization for the protection of an organization's processed privacy data?

Correct Answer: C. Individual data subjects can be re-identified.
Explanation:

Pseudonymizationreplaces identifying fields in a data record with artificial identifiers or pseudonyms. However, unlike full anonymization,re-identification remains possibleif the pseudonym can be matched with external or hidden reference data.

CRISC and privacy-risk guidance (aligned with GDPR principles) emphasize that:

''The primary concern when using pseudonymization as a privacy safeguard is the potential for re-identification of individual data subjects.''

Pseudonymized data can still be linked back to individuals if the mapping key or auxiliary datasets are compromised.

True anonymization eliminates any reasonable means of re-identification, but pseudonymization does not.

Therefore, while pseudonymization reduces exposure, it doesnot fully eliminateprivacy risk.

Options A, B, and D are not inherent to pseudonymization:

Authorized access and update restrictions are policy issues, not intrinsic to pseudonymization.

Other information disclosure (D) could occur through inference but is secondary to direct re-identification.

Hence,C. Individual data subjects can be re-identifiedis the correct and verified answer as per CRISC and GDPR-aligned data protection practices.


Question 8

Which of the following BEST supports ethical IT risk management practices?

Correct Answer: A. Robust organizational communication channels
Explanation:

Robust organizational communication channels are the best way to support ethical IT risk management practices, as they enable transparent and consistent sharing of risk information anddecisions among all stakeholders. Ethical IT risk management requires that the risk management process and outcomes are aligned with the enterprise's values, objectives, and obligations, and that the risk management activities are conducted with integrity, accountability, and respect. Robust organizational communication channels facilitate these aspects by ensuring that the risk management roles and responsibilities are clearly defined and communicated, that the risk management policies and procedures are widely disseminated and understood, that the risk management performance and results are regularly reported and reviewed, and that the risk management feedback and improvement suggestions are solicited and addressed. Mapping of key risk indicators (KRIs) to corporate strategy, capability maturity models integrated with risk management frameworks, and rigorously enforced operational service level agreements (SLAs) are not directly related to ethical IT risk management practices, but rather to the effectiveness and efficiency of the risk management process.Reference=CRISC Certified in Risk and Information Systems Control -- Question201;ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, question 201.


Question 9

Which of the following is the MOST important benefit of implementing a data classification program?

Correct Answer: B. Reduction in processing times
Explanation:

A data classification program helpsidentify appropriate controlsby categorizing data based on sensitivity and criticality. This ensures that data protection measures are aligned with its value and risk level, improving overall security posture.


Question 10

A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:

Correct Answer: B. validating the risk scenarios.
Explanation:

According to the CRISC Review Manual, the most important time to involve business stakeholders in the development of bottom-up IT risk scenarios is when validating the risk scenarios, as they can provide valuable input on the relevance, completeness, and accuracy of the scenarios and their impact on the business objectives and processes2

1: CRISC Review Questions, Answers & Explanations Database, Question ID: 100001 2: CRISC Review Manual, 7th Edition, page 97


Question 11

When developing IT risk scenarios, it is MOST important to consider:

Correct Answer: D. Organizational objectives.
Explanation:

According to the CRISC Manual, developing IT risk scenarios must align with business objectives to ensure the scenarios are relevant and meaningful. A top-down approach driven by organizational objectives ensures scenarios are contextually appropriate and address what matters most to the enterprise. This ensures that risk management supports the enterprise's ability to achieve its mission and goals.


Question 12

Which of the following should be the PRIMARY focus of an independent review of a risk management process?

Correct Answer: D. Maturity of the process
Explanation:

The primary focus of an independent review of a risk management process is to evaluate the maturity of the process, which means the extent to which the process is aligned with the organization's objectives, culture, and governance, and how well it is integrated, implemented, and monitored across the organization. A mature risk management process is one that is consistent, effective, efficient, and adaptable to changing circumstances and environments. A maturity assessment can help to identify the strengths and weaknesses of the risk management process, as well as the opportunities and challenges for improvement. The other options are not the primary focus, but they may be secondary or tertiary aspects of the review. Accuracy of risk tolerance levels is a measure of how well the organization defines and communicates its risk appetite and risk limits, which are important inputs for the risk management process, but not the main outcome. Consistency of risk process results is a measure of how reliable and repeatable the risk management process is, which reflects the quality and validity of the data, assumptions, methods, and tools used in the process, but not the overall effectiveness and efficiency of the process. Participation of stakeholders is a measure of how well the organization engages and involves its internal and external stakeholders in the risk management process, which enhancesthe awareness, ownership, andaccountability of the process, but not the alignment and integration of the process.Reference=Assessing the Risk Management Process, p. 9-10.


Question 13

An organization has just started accepting credit card payments from customers via the corporate website. Which of the following is MOST likely to increase as a result of this new initiative?

Correct Answer: C. Inherent risk
Explanation:

Inherent risk is the most likely to increase as a result of the new initiative, because it is the risk that exists before any controls or mitigating factors are applied. Inherent risk reflects the natural or raw level of exposure that the organization faces from a given risk source or scenario. Accepting credit card payments from customers via the corporate website introduces new sources and types of risk, such as fraud, theft, data breach, or non-compliance, that increase the inherent risk level of the organization. Risk tolerance, risk appetite, and residual risk are all related to the risk management process, but they are not the most likely to increase as a result of the new initiative, as they depend on the organization's risk strategy, objectives, and controls. Reference = Risk and Information Systems Control Study Manual, Chapter 2, Section 2.3.1, page 51


Question 14

Which of the following is the PRIMARY benefit of identifying and communicating with stakeholders at the onset of an IT risk assessment?

Correct Answer: B. Defining the risk assessment scope
Explanation:

An IT risk assessment is a process that involves identifying, analyzing, and evaluating the IT-related risks and their potential impacts on the organization's objectives and performance1.Identifying and communicating with stakeholders at the onset of an IT risk assessment is the process of determining and engaging the persons or entities that have an interest or influence in the IT risk management, such as the IT users, owners, managers, orproviders2.The primary benefit of identifying and communicating with stakeholders at the onset of an IT risk assessment is to define the risk assessment scope, which is theboundary or extent of the IT risk assessment, such as the IT systems, processes, or functions that are included or excluded from the assessment3. By identifying and communicating with stakeholders at the onset of an IT risk assessment, the organization can ensure that the risk assessment scope is relevant, realistic, and aligned with the organization's strategy, vision, and mission, and that it reflects the current and emerging IT risks and their potential consequences. Identifying and communicating with stakeholders at the onset of an IT risk assessment can also help to establish and communicate the roles and responsibilities of the stakeholders, and to enforce the accountability and performance of the IT risk management. Obtaining funding support, selecting the risk assessment framework, and establishing inherent risk are not the primary benefits of identifying and communicating with stakeholders at the onset of an IT risk assessment, as they do not provide the same level of insight and relevance as defining the risk assessment scope.Obtaining funding support is the process of securing and providing the necessary funds or resources that are required to support or enable the IT risk assessment4. Obtaining funding support can enhance the quality and performance of the IT risk assessment, but it is not the primary benefit of identifying and communicating with stakeholders at the onset of an IT risk assessment, as it does not determine or influence the boundary or extent of the IT risk assessment.Selecting the risk assessment framework is the process of choosing or developing a set of principles, methods, and tools that guide and facilitate the IT risk assessment5. Selecting the risk assessment framework can improve the reliability and consistency of the IT risk assessment, but it is not the primary benefit of identifying and communicating with stakeholders at the onset of an IT risk assessment, as it does not define or affect the scope or coverage of the IT risk assessment. Establishing inherent risk is the process of assessing the level of risk that exists before any controls or mitigating factors are considered.Establishing inherent risk can help to understand and prioritize the IT risks and their impacts, but it is not the primary benefit of identifying and communicating with stakeholders at the onset of an IT risk assessment, as it doesnot specify or limit the scope or range of the IT risk assessment.Reference=1:IT Risk Assessment - an overview | ScienceDirect Topics2:Stakeholder Requirements - an overview | ScienceDirect Topics3:Risk Assessment Scope - an overview | ScienceDirect Topics4:Funding Support - an overview | ScienceDirect Topics5:Risk Assessment Framework - an overview | ScienceDirect Topics: [Inherent Risk - an overview | ScienceDirect Topics] : [Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.1: Risk Identification, pp. 57-59.] : [Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.2: Risk Analysis, pp. 67-69.] : [Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.3: Risk Evaluation, pp. 77-79.] : [Risk and Information Systems Control Study Manual, Chapter 3: Risk Response, Section 3.1: RiskResponse Options, pp. 113-115.] : [Risk and Information Systems Control Study Manual, Chapter 4: Risk and Control Monitoring and Reporting, Section 4.1: Key Risk Indicators, pp. 181-185.] : [Risk and Information Systems Control Study Manual, Chapter 4: Risk and ControlMonitoring and Reporting, Section 4.2: Risk Monitoring, pp. 189-191.] : [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section 5.1: Control Design, pp. 233-235.] : [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section 5.2: Control Implementation, pp. 243-245.] : [Risk and Information Systems Control Study Manual, Chapter 5: Information Systems Control Design and Implementation, Section 5.3: Control Monitoring and Maintenance, pp. 251-253.]


Question 15

A risk practitioner is reviewing accountability assignments for data risk in the risk register. Which of the following would pose the GREATEST concern?

Correct Answer: C. The risk owner is listed as the department responsible for decision-making.
Explanation:

The risk owner is listed as the department responsible for decision making would pose the greatest concern for a risk practitioner who is reviewing accountability assignments for data risk in the risk register, as it indicates a lack of clarity and specificity on who is accountable for the risk and its response. The risk owner should be an individual, not a department, who has the authority and responsibility to manage the risk and its associated controls. The other options are not the greatest concern, as they do not necessarily imply a lack of accountability, but rather a possible difference in roles and responsibilities between the risk owner and the control owner, the business unit and the IT department, or the staff member and the department manager.Reference= CRISC Review Manual, 7th Edition, page 101.