Risk Assessment
Drill 20 practice questions focused entirely on Risk Assessment for the ISACA CRISC exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A risk practitioner is conducting a risk assessment for a customer-facing e-commerce platform. During the initial data-gathering phase, the practitioner discovers that the asset inventory used to scope the assessment only lists production servers and databases, but omits the CI/CD pipeline, cloud storage buckets holding customer data, and third-party payment integration components. What is the GREATEST concern this poses to the validity of the risk assessment?
A risk analyst is assessing the likelihood of a targeted intrusion against a customer-facing payment portal. Historical internal incident data is sparse because the organization has never suffered a successful breach of this system. To produce a defensible likelihood estimate for the risk register, which combination of inputs should the analyst rely on MOST?
A risk practitioner is conducting a business impact analysis (BIA) for an order-processing application. Business owners assert the system is 'mission critical,' but they cannot agree on how severe an outage would be. To produce a defensible prioritization that the steering committee can use to allocate recovery investment, what should the practitioner do FIRST?
During a business impact analysis for an order-processing application, the business owner asserts that the application must be recovered within one hour. However, analysis shows that manual workarounds can sustain operations for up to eight hours before customer contractual penalties and irreversible reputational damage begin to accrue. Which value should the risk practitioner use to establish the maximum tolerable downtime (MTD) for this application?
A risk practitioner is supporting a business impact analysis (BIA) for a mid-sized insurer. Two applications are being evaluated: a claims-processing system that generates most revenue but can tolerate up to 24 hours of downtime before material financial loss, and an internal HR portal that has near-zero revenue impact but must be restored within 4 hours to meet a labor regulation. Management wants to use the BIA to prioritize recovery investment. Which factor should MOST influence the recovery time objective (RTO) assigned to each system?
During a risk assessment, an analyst discovers that a critical database server was compromised despite having patch management, access controls, and network segmentation in place. Investigation reveals that the patch management tool had not successfully applied updates for six months because a service account had expired, and no one monitored the tool's job completion status. What should the analyst identify as the most significant control deficiency to document in the risk register?
During a risk assessment of a payment processing application, a CRISC practitioner discovers that a mandated data encryption control is configured but has been failing silently for three months due to an expired certificate. Management asks how this finding should be reflected in the risk analysis. What is the MOST accurate way to characterize this situation?
During a risk assessment of a payment processing application, an analyst determines the inherent likelihood and impact of fraudulent transactions is very high. After documenting the automated fraud-detection controls, transaction monitoring, and dual-authorization requirements, the assessed likelihood drops significantly. When the analyst updates the risk register, which value should be recorded as the residual risk?
A risk analyst must estimate the likelihood and impact of a rare but severe supply-chain disruption for which the organization has no historical loss data. Management wants to avoid the situation where a single dominant senior executive skews the group's estimates during a live workshop. Which risk analysis approach BEST addresses this concern?
A risk analyst is documenting a new risk in the organization's risk register. The analyst has identified the threat, mapped the affected assets, and now must record the level of risk that would exist assuming NO controls are in place. Which risk value should the analyst record for this field?
A risk analyst at a mid-sized bank is estimating the likelihood of a ransomware event for the risk register. The organization has been operating for only three years and has experienced no ransomware incidents, so internal historical loss data is sparse. Management wants a defensible frequency estimate. Which approach BEST improves the credibility of the likelihood estimate?
A risk analyst must quantify the potential financial loss from a proposed cloud migration where multiple variables — outage frequency, per-hour revenue loss, and recovery duration — each have wide ranges of uncertainty. Senior management wants a probability distribution of possible loss outcomes rather than a single point estimate. Which risk analysis technique is MOST appropriate?
A risk practitioner is reviewing the organization's qualitative risk analysis results. Several business units rated similar risks very differently — one unit labeled a data-entry error risk as 'High' while another rated an almost identical risk as 'Low.' The differences appear to stem from how each assessor interpreted the rating scale. Which of the following BEST addresses the underlying weakness in the current approach?
A risk analyst is quantifying the exposure of a customer database to ransomware. Historical data indicates a successful ransomware incident occurs approximately once every four years, and each incident is estimated to cause $800,000 in recovery, downtime, and notification costs. Management asks the analyst to express the risk in a form that supports a cost-benefit comparison against a proposed $150,000-per-year backup and detection solution. Which figure should the analyst present?
A risk practitioner is assessing risks for a newly launched digital payments platform. Historical loss data for fraud events is scarce because the platform is new, but subject matter experts have strong opinions about the relative likelihood and impact of various threat scenarios. Management wants an assessment delivered quickly to prioritize the top risks for remediation. Which risk analysis approach is MOST appropriate given these constraints?
After implementing a new data loss prevention (DLP) solution, a risk analyst reassesses a data exfiltration scenario. The inherent risk was rated High. Following control implementation, the residual risk is rated Medium, but the organization's documented risk appetite for data exfiltration is Low. What should the risk analyst recommend as the MOST appropriate next step?
After implementing a new set of controls on a customer-facing payment application, a risk analyst measures the residual risk and finds it is still slightly above the organization's stated risk appetite. The cost of implementing additional controls to close the remaining gap would exceed the projected annualized loss from the residual exposure by a wide margin. What should the risk analyst recommend to management?
A retailer's risk analyst is evaluating two data-related risks for the risk register. Risk A involves a rare but catastrophic breach of the entire customer database, estimated once every 20 years, with a loss of $10 million per occurrence. Risk B involves frequent minor payment-processing errors occurring about 40 times per year, each costing roughly $8,000. Management wants to know which risk should receive higher priority for treatment based on expected annual loss. Which conclusion should the analyst present?
A risk analyst is comparing two quantitative risk scenarios for a board presentation. Both scenarios have an identical annualized loss expectancy (ALE) of $500,000. However, Scenario A involves frequent, small, predictable losses, while Scenario B involves a rare but catastrophic single loss event. The board asks the analyst which measure best captures the difference in risk between the two scenarios that a single ALE figure hides. Which additional analysis output should the analyst emphasize?
A financial services firm currently performs enterprise risk assessments on a fixed annual cycle. Over the past year, the organization migrated several core services to a cloud provider, acquired a fintech startup, and faced a surge in targeted phishing campaigns. During the most recent annual assessment, several risks were found to have materialized months earlier without detection. What should the risk practitioner recommend to best address this gap?
More CRISC practice
Keep going with the other ISACA CRISC — Certified in Risk and Information Systems Control domains, or take a full timed mock exam.
← Back to CRISC overview