Hard CRISC practice questions
Challenge — multi-step scenarios, trade-offs, and subtle distinctions. 28 hard questions available — no sign-up, always free.
A mid-sized financial services firm has just acquired a smaller fintech company that operated with an informal, spreadsheet-based approach to risk tracking. The acquiring firm uses a mature enterprise risk management (ERM) program aligned to a formal framework. The board wants the acquired entity's risks reflected in enterprise reporting within one quarter. As the risk practitioner leading integration, what should be your FIRST priority?
During a business impact analysis for an order-processing application, the business owner asserts that the application must be recovered within one hour. However, analysis shows that manual workarounds can sustain operations for up to eight hours before customer contractual penalties and irreversible reputational damage begin to accrue. Which value should the risk practitioner use to establish the maximum tolerable downtime (MTD) for this application?
A risk practitioner is supporting a business impact analysis (BIA) for a mid-sized insurer. Two applications are being evaluated: a claims-processing system that generates most revenue but can tolerate up to 24 hours of downtime before material financial loss, and an internal HR portal that has near-zero revenue impact but must be restored within 4 hours to meet a labor regulation. Management wants to use the BIA to prioritize recovery investment. Which factor should MOST influence the recovery time objective (RTO) assigned to each system?
A multinational retailer processes customer data across several countries. The risk practitioner discovers that a new data-localization law in one country directly conflicts with a data-sharing clause in a signed contract with a global cloud provider, and that the marketing department has continued cross-border transfers to meet campaign deadlines. What should the risk practitioner do FIRST?
A risk practitioner is reviewing a proposed control to mitigate a data-integrity risk. The annual cost of implementing and operating the control is estimated at $250,000, while the control is expected to reduce annualized loss expectancy from $180,000 to $40,000. Management is eager to proceed because the risk relates to a high-visibility system. What should the risk practitioner recommend?
During a risk assessment, an analyst discovers that a critical database server was compromised despite having patch management, access controls, and network segmentation in place. Investigation reveals that the patch management tool had not successfully applied updates for six months because a service account had expired, and no one monitored the tool's job completion status. What should the analyst identify as the most significant control deficiency to document in the risk register?
During a risk assessment of a payment processing application, a CRISC practitioner discovers that a mandated data encryption control is configured but has been failing silently for three months due to an expired certificate. Management asks how this finding should be reflected in the risk analysis. What is the MOST accurate way to characterize this situation?
During quarterly control monitoring, a risk analyst notices that the same access-provisioning control has generated approved exceptions in each of the last four quarters, always for the same business unit citing 'urgent operational need.' Each exception was individually approved within policy and expired on schedule. What should the analyst do FIRST?
A multinational retailer plans to transfer customer personal data from its European subsidiary to a cloud analytics platform hosted in a country that the European Commission has NOT deemed to provide an adequate level of data protection. The privacy officer must ensure the transfer is lawful before it begins. Which action should the privacy officer take FIRST to enable this cross-border transfer?
A risk analyst is designing a dashboard for the IT operations risk area. Management wants a metric that will warn them before unpatched systems create a significant likelihood of a successful exploit. The analyst must choose which single metric best serves this early-warning purpose and identify who should be accountable for acting on threshold breaches. Which combination is most appropriate?
A financial services firm currently protects customer data at rest and in transit using RSA-2048 and ECC-based encryption. During a technology horizon-scanning exercise, the risk practitioner learns that advances in quantum computing may eventually render these asymmetric algorithms breakable. The firm retains encrypted customer records for a legally mandated retention period of 15 years. What should the risk practitioner emphasize FIRST when advising leadership on this emerging risk?
After implementing a new set of controls on a customer-facing payment application, a risk analyst measures the residual risk and finds it is still slightly above the organization's stated risk appetite. The cost of implementing additional controls to close the remaining gap would exceed the projected annualized loss from the residual exposure by a wide margin. What should the risk analyst recommend to management?
A risk analyst is comparing two quantitative risk scenarios for a board presentation. Both scenarios have an identical annualized loss expectancy (ALE) of $500,000. However, Scenario A involves frequent, small, predictable losses, while Scenario B involves a rare but catastrophic single loss event. The board asks the analyst which measure best captures the difference in risk between the two scenarios that a single ALE figure hides. Which additional analysis output should the analyst emphasize?
A newly appointed CRO finds that the enterprise has a board-approved risk appetite statement, but individual business units continue to make risk decisions based on their own informal thresholds. As a result, one aggressive business unit is accepting risks that exceed enterprise-level limits, while a conservative unit is rejecting profitable opportunities well within acceptable bounds. Which action would MOST effectively address the root cause of this inconsistency?
A financial services company's board has approved a formal statement declaring that the enterprise will accept minimal risk to customer data confidentiality but is willing to pursue moderate operational risk to enable rapid product innovation. During a project review, a risk practitioner finds a proposed feature that would expose customer personal data to a level exceeding the defined threshold, though it stays within the enterprise's overall ability to absorb a loss without threatening solvency. What is the practitioner's BEST course of action?
A retail bank's board has set a risk appetite statement that limits acceptable operational losses to a low level relative to net revenue. Management defines a tolerance threshold allowing monthly fraud losses to fluctuate up to 15% above the target before escalation is required. In one month, fraud losses spike to 12% above target due to a seasonal promotion, then return to normal the following month. The CRO is deciding how to respond. What is the MOST appropriate action?
A manufacturing company's board wants to enter a new overseas market that requires significant upfront investment in unfamiliar regulatory environments. The CRO notes that while the enterprise's stated risk appetite would comfortably permit the venture, the company's current cash reserves, insurance coverage, and available skilled compliance staff are already heavily committed to existing operations. Which concept should the CRO emphasize to the board to most accurately frame the concern about this expansion?
A CRISC practitioner reviews a business unit that consistently meets its financial targets but has repeatedly bypassed formal change-management approvals to accelerate product releases. Management informally rewards staff who 'get things done fast,' and employees perceive that raising control concerns will harm their careers. Which underlying factor is MOST important for the risk practitioner to address to improve control effectiveness in this unit?
A newly appointed CRO at a mid-sized insurer discovers that although a comprehensive risk management framework was formally adopted two years ago, business unit managers routinely bypass risk assessment procedures when launching new products, viewing them as an administrative burden imposed by the risk function. Executive leadership expresses surprise, believing the framework was operating effectively. Which action by the CRO would MOST effectively address the underlying governance weakness?
A manufacturing company's board recently approved an aggressive expansion into a new geographic market. Six months later, the risk practitioner notices that the enterprise risk profile now shows significantly elevated exposure in supply chain, currency, and regulatory compliance areas that were minor before the expansion. What is the MOST important action for the risk practitioner to take?
A risk analyst is reviewing a risk register that lists several separate entries: a data center power failure, a single ISP link outage, and a HVAC cooling system failure — each individually rated 'low' likelihood and 'moderate' impact. The analyst notes all three depend on the same aging on-premises facility and could plausibly occur together during a heat wave. What should the analyst do to most accurately represent the risk to management?
A CRISC-certified risk analyst is reviewing a business unit's qualitative risk assessment. Twelve individually low-likelihood, low-impact risks all relate to the same aging legacy database platform. Each is plotted separately in the green zone of the heat map, so management has declined to fund any remediation. The analyst believes the true exposure is understated. Which action would MOST effectively address this concern?
A manufacturing company implemented a mitigation control to reduce the risk of unplanned downtime from aging equipment. Post-implementation testing shows the control reduced the likelihood significantly, but the residual risk still sits slightly above the stated risk tolerance. The plant is scheduled for a full equipment replacement in 18 months, which will eliminate the risk source entirely. What is the MOST appropriate next step for the risk practitioner to recommend?
A mitigating control for a high-risk payment process was implemented 18 months ago and initially reduced residual risk to within appetite. During a recent quarterly review, the risk practitioner notices that the number of manual override transactions has steadily increased and now exceeds the control's assumed operating baseline. No control failures have been formally reported. What should the risk practitioner do FIRST?
A financial services firm has identified a risk scenario involving a catastrophic data center flood: the estimated likelihood is very low, but a single occurrence would exceed the organization's risk capacity and threaten solvency. Mitigation controls have been implemented to their practical limit, yet the residual exposure remains beyond appetite. Which risk response should the risk practitioner recommend the organization consider next?