ISACA certification preparation

CRISC Practice Questions

Practice exam-style questions, check your answers, and review explanations and source references where they are available.

Exam
CRISC
Provider
ISACA
Full set
1,735 questions
Last Update Check

You need to pass the CRISC exam to receive your certification. To increase the effectiveness of your study and make you familiar with the actual exam pattern, we have prepared these CRISC sample questions, complete with answer explanations. Our free CRISC practice quiz will give you great insight into both the type and difficulty level of the actual questions. However, we strongly recommend practicing with our premium CRISC exam simulator to achieve the best score. Our premium exam questions are comprehensive, exam-oriented, scenario-based, and an exact match to the real test.

An organization has outsourced its ERP application to an external SaaS provider. Which of the following provides the MOST useful information to identify risk scenarios involving data loss?
Answer options
Which of the following is a PRIMARY benefit of engaging the risk owner during the risk assessment process?
Answer options
An organization uses a biometric access control system for authentication and access to its server room. Which control type has been implemented?
Answer options
An organization discovers significant vulnerabilities in a recently purchased commercial off-the-shelf software product which will not be corrected until the next release. Which of the following is the risk manager's BEST course of action?
Answer options
Which of the following is the BEST way to determine the value of information assets for risk management purposes?
Answer options
An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in the risk register and accepted. Who should be accountable for any related losses to the organization?
Answer options
When developing a response plan to address security incidents regarding sensitive data loss, it is MOST important
Answer options
Which of the following is the MOST important document regarding the treatment of sensitive data?
Answer options
Which of the following should be the PRIMARY goal of developing information security metrics?
Answer options
Which of the following BEST measures the impact of business interruptions caused by an IT service outage?
Answer options
Question 1 of 10

Source context

How this practice set is maintained

Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.

Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.

Scroll to Top