Skip to main content

CRISC Real Exam Questions

Certified in Risk and Information Systems Control

1,943 questions available · Page 1 of 195

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

The BEST metric to monitor the risk associated with changes deployed to production is the percentage of:

  1. A

    changes due to emergencies.

  2. B

    changes that cause incidents.

  3. C

    changes not requiring user acceptance testing.

  4. D

    personnel that have rights to make changes in production.

Show answer and explanation

Correct answer: B

Explanation

The percentage of production changes that cause incidents directly measures harmful outcomes from the change process. A rising value indicates that testing, approval, deployment, or rollback controls may not be effective. Emergency status and testing exemptions are contextual indicators, while the number of privileged personnel measures access risk rather than actual change failures.

Question 2 Single choice

Which of the following is the MOST effective control to maintain the integrity of system configuration files?

  1. A

    Recording changes to configuration files

  2. B

    Implementing automated vulnerability scanning

  3. C

    Restricting access to configuration documentation

  4. D

    Monitoring against the configuration standard

Show answer and explanation

Correct answer: D

Explanation

Configuration integrity depends on systems remaining consistent with an approved configuration standard. Monitoring against that standard detects unauthorized or unintended deviations so they can be investigated and corrected. Recording changes provides history, but it does not establish that the resulting configuration still matches the approved baseline.

Question 3 Single choice

Reviewing results from which of the following is the BEST way to identify information systems control deficiencies?

  1. A

    Vulnerability and threat analysis

  2. B

    Control remediation planning

  3. C

    User acceptance testing (UAT)

  4. D

    Control self-assessment (CSA)

Show answer and explanation

Correct answer: D

Explanation

A control self-assessment asks the people responsible for a process to evaluate controls against their requirements and document weaknesses in design or operation. Reviewing those results therefore provides a direct inventory of information-systems control deficiencies. Threat analysis identifies exposure, while remediation planning occurs after deficiencies have already been identified.

Question 4 Single choice

Several network user accounts were recently created without the required management approvals.

Which of the following would be the risk practitioner's BEST recommendation to address this situation?

  1. A

    Conduct a comprehensive compliance review.

  2. B

    Develop incident response procedures for noncompliance.

  3. C

    Investigate the root cause of noncompliance.

  4. D

    Declare a security breach and Inform management.

Show answer and explanation

Correct answer: C

Explanation

The immediate evidence is repeated noncompliance with the approval requirement, but the reason accounts bypassed that control is still unknown. Investigating the root cause identifies the process, system, or behavioral failure that must be corrected to prevent recurrence. A broad review or incident declaration does not directly determine why the approvals were omitted.

Question 5 Single choice

A risk practitioner has identified that the organization's secondary data center does not provide redundancy for a critical application.
Who should have the authority to accept the associated risk?

  1. A

    Business continuity director

  2. B

    Disaster recovery manager

  3. C

    Business application owner

  4. D

    Data center manager

Show answer and explanation

Correct answer: C

Explanation

The business application owner is accountable for the application and the business consequences of its unavailability. Because risk acceptance is a business decision, the person who owns the affected application must determine whether the lack of redundancy is tolerable. Continuity, recovery, and data center managers may advise or implement measures, but they do not own the business risk.

Question 6 Single choice

Which of the following can be interpreted from a single data point on a risk heat map?

  1. A

    Risk tolerance

  2. B

    Risk magnitude

  3. C

    Risk response

  4. D

    Risk appetite

Show answer and explanation

Correct answer: B

Explanation

A data point on a risk heat map represents a scenario's assessed position, commonly combining dimensions such as likelihood and impact. Its placement therefore communicates the risk magnitude associated with that scenario. Appetite and tolerance are organizational thresholds used to interpret the point, while the response is a management decision that cannot be derived from the point alone.

Question 7 Single choice

A risk assessment has identified that departments have installed their own WiFi access points on the enterprise network.

Which of the following would be MOST important to include in a report to senior management?

  1. A

    The network security policy

  2. B

    Potential business impact

  3. C

    The WiFi access point configuration

  4. D

    Planned remediation actions

Show answer and explanation

Correct answer: B

Explanation

Senior management needs to understand how unauthorized departmental WiFi access points could affect business objectives, operations, information, or obligations. Presenting the potential business impact translates the technical finding into decision-relevant risk and supports prioritization. Configuration details and policy text are supporting evidence, while actions should be selected in light of the assessed impact.

Question 8 Single choice

Which of the following is the MOST important outcome of a business impact analysis (BIA)?

  1. A

    Understanding and prioritization of critical processes

  2. B

    Completion of the business continuity plan (BCP)

  3. C

    Identification of regulatory consequences

  4. D

    Reduction of security and business continuity threats

Show answer and explanation

Correct answer: A

Explanation

A business impact analysis determines which processes are critical and evaluates the business consequences of their disruption. This understanding enables processes to be prioritized for continuity and recovery planning. It supplies an essential input to a business continuity plan, but it does not itself complete the plan or directly reduce threats.

Question 9 Single choice

An organization has completed a project to implement encryption on all databases that host customer data.

Which of the following elements of the risk register should be updated the reflect this change?

  1. A

    Risk likelihood

  2. B

    Inherent risk

  3. C

    Risk appetite

  4. D

    Risk tolerance

Show answer and explanation

Correct answer: A

Explanation

Database encryption is a control intended to reduce the chance that access to stored customer data results in readable disclosure. Its implementation therefore changes the assessed likelihood of the relevant risk under current controls. Inherent risk is measured before controls, while risk appetite and tolerance are management boundaries rather than effects of this project.

Question 10 Single choice

An organization has procured a managed hosting service and just discovered the location is likely to be flooded every 20 years. Of the following, who should be notified of this new information FIRST.

  1. A

    The risk owner who also owns the business service enabled by this infrastructure

  2. B

    The data center manager who is also employed under the managed hosting services contract

  3. C

    The site manager who is required to provide annual risk assessments under the contract

  4. D

    The chief information officer (CIO) who is responsible for the hosted services

Show answer and explanation

Correct answer: A

Explanation

The new flood information changes the exposure of the business service supported by the hosted infrastructure. The risk owner who also owns that service should be notified first because that role can evaluate the business impact and decide whether treatment, acceptance, or escalation is required. Operational managers and the CIO may contribute, but the accountable risk decision starts with the owner.