ISACA CRISC Übungsprüfungen
Zuletzt aktualisiert am 01.05.2026- Prüfungscode: CRISC
- Prüfungsname: Certified in Risk and Information Systems Control
- Zertifizierungsanbieter: ISACA
- Zuletzt aktualisiert am: 01.05.2026
What is the MAIN benefit of using a top-down approach to develop risk scenarios?
- A . It describes risk events specific to technology used by the enterprise.
- B . It establishes the relationship between risk events and organizational objectives.
- C . It uses hypothetical and generic risk events specific to the enterprise.
- D . It helps management and the risk practitioner to refine risk scenarios.
A large organization needs to report risk at all levels for a new centralized visualization project to reduce cost and improve performance.
Which of the following would MOST effectively represent the overall risk of the project to senior management?
- A . Aggregated key performance indicators (KPls)
- B . Key risk indicators (KRIs)
- C . Centralized risk register
- D . Risk heat map
Which of the following would BEST help to ensure that suspicious network activity is identified?
- A . Analyzing intrusion detection system (IDS) logs
- B . Analyzing server logs
- C . Using a third-party monitoring provider
- D . Coordinating events with appropriate agencies
An organization’s risk tolerance should be defined and approved by which of the following?
- A . The chief risk officer (CRO)
- B . The board of directors
- C . The chief executive officer (CEO)
- D . The chief information officer (CIO)
Which of the following would provide the BEST evidence of an effective internal control environment/?
- A . Risk assessment results
- B . Adherence to governing policies
- C . Regular stakeholder briefings
- D . Independent audit results
Which of the following statements in an organization’s current risk profile report is cause for further action by senior management?
- A . Key performance indicator (KPI) trend data is incomplete.
- B . New key risk indicators (KRIs) have been established.
- C . Key performance indicators (KPIs) are outside of targets.
- D . Key risk indicators (KRIs) are lagging.
Which of the following is MOST helpful in providing a high-level overview of current IT risk severity*?
- A . Risk mitigation plans
- B . heat map
- C . Risk appetite statement
- D . Key risk indicators (KRls)
Which of the following is the BEST way to determine whether system settings are in alignment with control baselines?
- A . Configuration validation
- B . Control attestation
- C . Penetration testing
- D . Internal audit review
Risk appetite should be PRIMARILY driven by which of the following?
- A . Enterprise security architecture roadmap
- B . Stakeholder requirements
- C . Legal and regulatory requirements
- D . Business impact analysis (BIA)
Which of the following would BEST help an enterprise prioritize risk scenarios?
- A . Industry best practices
- B . Placement on the risk map
- C . Degree of variances in the risk
- D . Cost of risk mitigation