Medium CRISC practice questions
Applied — put a concept to work in a realistic situation. 122 medium questions available — no sign-up, always free.
A manufacturing company recently redesigned its procurement process to speed up vendor onboarding, allowing purchasing managers to approve new suppliers within hours. Six months later, the risk practitioner notices that several onboarded vendors were never screened for sanctions-list or conflict-of-interest issues, though the corporate policy still requires such screening. What is the MOST significant governance concern the risk practitioner should raise?
A newly appointed CRISC-certified risk practitioner reviews the enterprise risk register and finds that many identified risks are documented in technical terms with no reference to how they could affect the organization's stated growth and market-expansion strategy. Senior management complains that risk reports are not useful for decision-making. What should the practitioner do FIRST to address this concern?
A newly appointed CRISC-certified risk practitioner reviews the information security department's annual goals. The goals emphasize maximizing the number of vulnerabilities patched and increasing firewall rule counts, but make no reference to the enterprise's stated strategic objective of expanding into new digital markets. Which action should the practitioner recommend FIRST to improve governance?
A risk practitioner is conducting a risk assessment for a customer-facing e-commerce platform. During the initial data-gathering phase, the practitioner discovers that the asset inventory used to scope the assessment only lists production servers and databases, but omits the CI/CD pipeline, cloud storage buckets holding customer data, and third-party payment integration components. What is the GREATEST concern this poses to the validity of the risk assessment?
A risk analyst is assessing the likelihood of a targeted intrusion against a customer-facing payment portal. Historical internal incident data is sparse because the organization has never suffered a successful breach of this system. To produce a defensible likelihood estimate for the risk register, which combination of inputs should the analyst rely on MOST?
A risk practitioner is conducting a business impact analysis (BIA) for an order-processing application. Business owners assert the system is 'mission critical,' but they cannot agree on how severe an outage would be. To produce a defensible prioritization that the steering committee can use to allocate recovery investment, what should the practitioner do FIRST?
A financial services firm is deploying a smart contract on a public blockchain to automate loan disbursements. During a pre-deployment risk review, a risk practitioner notes that once deployed, the contract code cannot be modified. Which risk implication should the practitioner prioritize when advising the project team?
A newly appointed CRISC-certified risk manager discovers that the enterprise has a formally approved code of conduct, but employees routinely bypass its requirements around gift acceptance from vendors, and no disciplinary action has ever been taken. Senior leadership acknowledges the code exists but treats it as guidance rather than a binding rule. Which action should the risk manager recommend FIRST to strengthen the organization's risk governance?
A manufacturing company has automated a previously manual invoice-approval business process, introducing a workflow tool that routes approvals electronically. Three months later, an internal audit finds employees are still following the outdated documented standard that references manual sign-offs, creating confusion about who is accountable for approvals. As the risk practitioner, what should you recommend as the MOST appropriate first action to address the governance gap?
An organization is migrating a customer-facing application to a public cloud provider using an Infrastructure-as-a-Service (IaaS) model. During the risk assessment, the risk practitioner notices that the project team assumes the cloud provider will handle all security patching, including the guest operating systems and application layers. Which action should the risk practitioner recommend FIRST to address this concern?
A financial services firm outsources its customer data processing to a third-party cloud provider. The contract includes a service-level agreement (SLA) requiring 99.9% availability and specific data-breach notification timelines mandated by the firm's regulator. During a governance review, the risk manager notes that no internal party has been formally assigned to monitor the provider's adherence to these contractual and regulatory obligations. Which action should the risk manager recommend FIRST?
During a review of a newly implemented access-recertification control, a risk analyst confirms that the control was thoughtfully designed to require quarterly manager sign-off on user entitlements. However, over the past two quarters, managers approved recertifications in bulk without reviewing individual entitlements, and several terminated employees retained active access. Which conclusion best describes the state of this control?
During a risk assessment of a payment processing application, an analyst determines the inherent likelihood and impact of fraudulent transactions is very high. After documenting the automated fraud-detection controls, transaction monitoring, and dual-authorization requirements, the assessed likelihood drops significantly. When the analyst updates the risk register, which value should be recorded as the residual risk?
A risk practitioner is reviewing a remediation action where the IT team reports that a new privileged-access monitoring control has been fully deployed to close a high-rated finding. The finding owner has requested that the corresponding risk register entry be updated to 'closed.' Before agreeing to close the entry, what is the MOST important action the practitioner should take?
A financial services firm processes thousands of high-value wire transfers daily. Management is concerned that a manual quarterly review of transactions exceeding approval thresholds is failing to catch unauthorized transfers before funds leave the organization. The risk practitioner is asked to recommend an improvement to the monitoring approach. Which recommendation BEST addresses management's concern?
A financial institution processes thousands of high-value wire transfers daily. The risk practitioner is designing a monitoring approach for the fraud-detection control governing these transfers. Given the transaction volume and the potential for large, rapid financial loss from a single fraudulent transfer, which monitoring approach should the practitioner recommend?
A risk manager is designing a monitoring program for a payment processing system that has more than 40 documented controls. Resource constraints prevent continuous monitoring of every control. To provide the most meaningful assurance to management with limited resources, which approach should the risk manager prioritize?
During a risk response review, a newly appointed control owner for a data-loss-prevention (DLP) system tells the risk committee that because the control is operating effectively, the associated data-leakage risk is now fully 'owned and closed' by their team. The risk manager wants to correct the misunderstanding before it is documented in the risk register. Which statement best clarifies the accountability relationship the risk manager should communicate?
A newly implemented data loss prevention (DLP) control was deployed by the security engineering team to reduce the risk of confidential customer data leaving the organization. During a post-implementation review, the risk practitioner notes that no one has been formally designated as responsible for the ongoing operation, tuning, and monitoring of the DLP control. Which action should the risk practitioner recommend FIRST?
A financial services firm has identified a risk that employees may fraudulently alter payment amounts in the accounts payable system. Management wants to select a control response. The organization already has manual monthly reconciliations that catch discrepancies after payments are made, but losses have already occurred by that point. Which control approach should the risk practitioner recommend to most effectively reduce the likelihood of this risk materializing?
A risk manager wants to increase business unit engagement in control monitoring while reducing reliance on periodic internal audit reviews. Operational managers currently view control assessment as a compliance burden imposed by others. Which approach would BEST address this situation?
A risk practitioner is designing the ongoing monitoring plan for a portfolio of internal controls. Management wants an efficient approach that focuses testing effort where it matters most. Which factor should PRIMARILY determine how frequently each control is tested?
A risk manager is preparing a consolidated enterprise risk report for the board by combining risk data submitted independently by five business units. Each unit uses its own 1-to-5 scoring scale, but the definitions of what constitutes a '4' or '5' differ significantly between units (e.g., one unit defines '5' as a $1M loss while another defines it as a $10M loss). What should the risk manager do FIRST before aggregating the data?
A financial services firm is rolling out a new data protection program. The security team wants to apply encryption, access restrictions, and retention rules across all repositories. However, they find that data across shared drives, databases, and cloud storage is treated uniformly, making it unclear which datasets warrant the strongest safeguards. What should the risk practitioner recommend the organization establish FIRST to guide the assignment of protection controls?
A financial services firm retains seven years of transaction data to satisfy regulatory obligations. Most queries touch only the last 90 days, but the entire dataset currently resides on high-performance production storage that is nearing capacity. The risk practitioner is asked to advise on managing this data through its lifecycle. Which recommendation BEST balances cost, performance, and risk?