ISACA CRISC Übungsprüfungen
Zuletzt aktualisiert am 01.05.2026- Prüfungscode: CRISC
- Prüfungsname: Certified in Risk and Information Systems Control
- Zertifizierungsanbieter: ISACA
- Zuletzt aktualisiert am: 01.05.2026
What is senior management’s role in the RACI model when tasked with reviewing monthly status reports provided by risk owners?
- A . Accountable
- B . Informed
- C . Responsible
- D . Consulted
Which of the following is the BEST way to identify changes to the risk landscape?
- A . Internal audit reports
- B . Access reviews
- C . Threat modeling
- D . Root cause analysis
Which of the following is the BEST way to identify changes to the risk landscape?
- A . Internal audit reports
- B . Access reviews
- C . Threat modeling
- D . Root cause analysis
A contract associated with a cloud service provider MUST include:
- A . ownership of responsibilities.
- B . a business recovery plan.
- C . provision for source code escrow.
- D . the providers financial statements.
Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?
- A . Segregation of duties
- B . Monetary approval limits
- C . Clear roles and responsibilities
- D . Password policies
Which of the following is the BEST way to determine whether new controls mitigate security gaps in a business system?
- A . Complete an offsite business continuity exercise.
- B . Conduct a compliance check against standards.
- C . Perform a vulnerability assessment.
- D . Measure the change in inherent risk.
Which of the following statements BEST illustrates the relationship between key performance indicators (KPIs) and key control indicators (KCIs)?
- A . KPIs measure manual controls, while KCIs measure automated controls.
- B . KPIs and KCIs both contribute to understanding of control effectiveness.
- C . A robust KCI program will replace the need to measure KPIs.
- D . KCIs are applied at the operational level while KPIs are at the strategic level.
The PRIMARY objective for selecting risk response options is to:
- A . reduce risk 10 an acceptable level.
- B . identify compensating controls.
- C . minimize residual risk.
- D . reduce risk factors.
Which of the following provides the MOST useful information when determining if a specific control should be implemented?
- A . Business impact analysis (BIA)
- B . Cost-benefit analysis
- C . Attribute analysis
- D . Root cause analysis
Which of the following provides the BEST evidence that robust risk management practices are in place within an organization?
- A . A management-approved risk dashboard
- B . A current control framework
- C . A regularly updated risk register
- D . Regularly updated risk management procedures