ISACA CRISC — Certified in Risk and Information Systems Control · Domain 2 · 22% of exam

Risk Assessment

Drill 20 practice questions focused entirely on Risk Assessment for the ISACA CRISC exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A risk practitioner is conducting a risk assessment for a customer-facing e-commerce platform. During the initial data-gathering phase, the practitioner discovers that the asset inventory used to scope the assessment only lists production servers and databases, but omits the CI/CD pipeline, cloud storage buckets holding customer data, and third-party payment integration components. What is the GREATEST concern this poses to the validity of the risk assessment?

Reviewed for accuracy · Report an issue
Question 2 of 20

A risk analyst is assessing the likelihood of a targeted intrusion against a customer-facing payment portal. Historical internal incident data is sparse because the organization has never suffered a successful breach of this system. To produce a defensible likelihood estimate for the risk register, which combination of inputs should the analyst rely on MOST?

Reviewed for accuracy · Report an issue
Question 3 of 20

A risk practitioner is conducting a business impact analysis (BIA) for an order-processing application. Business owners assert the system is 'mission critical,' but they cannot agree on how severe an outage would be. To produce a defensible prioritization that the steering committee can use to allocate recovery investment, what should the practitioner do FIRST?

Reviewed for accuracy · Report an issue
Question 4 of 20

During a business impact analysis for an order-processing application, the business owner asserts that the application must be recovered within one hour. However, analysis shows that manual workarounds can sustain operations for up to eight hours before customer contractual penalties and irreversible reputational damage begin to accrue. Which value should the risk practitioner use to establish the maximum tolerable downtime (MTD) for this application?

Reviewed for accuracy · Report an issue
Question 5 of 20

A risk practitioner is supporting a business impact analysis (BIA) for a mid-sized insurer. Two applications are being evaluated: a claims-processing system that generates most revenue but can tolerate up to 24 hours of downtime before material financial loss, and an internal HR portal that has near-zero revenue impact but must be restored within 4 hours to meet a labor regulation. Management wants to use the BIA to prioritize recovery investment. Which factor should MOST influence the recovery time objective (RTO) assigned to each system?

Reviewed for accuracy · Report an issue
Question 6 of 20

During a risk assessment, an analyst discovers that a critical database server was compromised despite having patch management, access controls, and network segmentation in place. Investigation reveals that the patch management tool had not successfully applied updates for six months because a service account had expired, and no one monitored the tool's job completion status. What should the analyst identify as the most significant control deficiency to document in the risk register?

Reviewed for accuracy · Report an issue
Question 7 of 20

During a risk assessment of a payment processing application, a CRISC practitioner discovers that a mandated data encryption control is configured but has been failing silently for three months due to an expired certificate. Management asks how this finding should be reflected in the risk analysis. What is the MOST accurate way to characterize this situation?

Reviewed for accuracy · Report an issue
Question 8 of 20

During a risk assessment of a payment processing application, an analyst determines the inherent likelihood and impact of fraudulent transactions is very high. After documenting the automated fraud-detection controls, transaction monitoring, and dual-authorization requirements, the assessed likelihood drops significantly. When the analyst updates the risk register, which value should be recorded as the residual risk?

Reviewed for accuracy · Report an issue
Question 9 of 20

A risk analyst must estimate the likelihood and impact of a rare but severe supply-chain disruption for which the organization has no historical loss data. Management wants to avoid the situation where a single dominant senior executive skews the group's estimates during a live workshop. Which risk analysis approach BEST addresses this concern?

Reviewed for accuracy · Report an issue
Question 10 of 20

A risk analyst is documenting a new risk in the organization's risk register. The analyst has identified the threat, mapped the affected assets, and now must record the level of risk that would exist assuming NO controls are in place. Which risk value should the analyst record for this field?

Reviewed for accuracy · Report an issue
Question 11 of 20

A risk analyst at a mid-sized bank is estimating the likelihood of a ransomware event for the risk register. The organization has been operating for only three years and has experienced no ransomware incidents, so internal historical loss data is sparse. Management wants a defensible frequency estimate. Which approach BEST improves the credibility of the likelihood estimate?

Reviewed for accuracy · Report an issue
Question 12 of 20

A risk analyst must quantify the potential financial loss from a proposed cloud migration where multiple variables — outage frequency, per-hour revenue loss, and recovery duration — each have wide ranges of uncertainty. Senior management wants a probability distribution of possible loss outcomes rather than a single point estimate. Which risk analysis technique is MOST appropriate?

Reviewed for accuracy · Report an issue
Question 13 of 20

A risk practitioner is reviewing the organization's qualitative risk analysis results. Several business units rated similar risks very differently — one unit labeled a data-entry error risk as 'High' while another rated an almost identical risk as 'Low.' The differences appear to stem from how each assessor interpreted the rating scale. Which of the following BEST addresses the underlying weakness in the current approach?

Reviewed for accuracy · Report an issue
Question 14 of 20

A risk analyst is quantifying the exposure of a customer database to ransomware. Historical data indicates a successful ransomware incident occurs approximately once every four years, and each incident is estimated to cause $800,000 in recovery, downtime, and notification costs. Management asks the analyst to express the risk in a form that supports a cost-benefit comparison against a proposed $150,000-per-year backup and detection solution. Which figure should the analyst present?

Reviewed for accuracy · Report an issue
Question 15 of 20

A risk practitioner is assessing risks for a newly launched digital payments platform. Historical loss data for fraud events is scarce because the platform is new, but subject matter experts have strong opinions about the relative likelihood and impact of various threat scenarios. Management wants an assessment delivered quickly to prioritize the top risks for remediation. Which risk analysis approach is MOST appropriate given these constraints?

Reviewed for accuracy · Report an issue
Question 16 of 20

After implementing a new data loss prevention (DLP) solution, a risk analyst reassesses a data exfiltration scenario. The inherent risk was rated High. Following control implementation, the residual risk is rated Medium, but the organization's documented risk appetite for data exfiltration is Low. What should the risk analyst recommend as the MOST appropriate next step?

Reviewed for accuracy · Report an issue
Question 17 of 20

After implementing a new set of controls on a customer-facing payment application, a risk analyst measures the residual risk and finds it is still slightly above the organization's stated risk appetite. The cost of implementing additional controls to close the remaining gap would exceed the projected annualized loss from the residual exposure by a wide margin. What should the risk analyst recommend to management?

Reviewed for accuracy · Report an issue
Question 18 of 20

A retailer's risk analyst is evaluating two data-related risks for the risk register. Risk A involves a rare but catastrophic breach of the entire customer database, estimated once every 20 years, with a loss of $10 million per occurrence. Risk B involves frequent minor payment-processing errors occurring about 40 times per year, each costing roughly $8,000. Management wants to know which risk should receive higher priority for treatment based on expected annual loss. Which conclusion should the analyst present?

Reviewed for accuracy · Report an issue
Question 19 of 20

A risk analyst is comparing two quantitative risk scenarios for a board presentation. Both scenarios have an identical annualized loss expectancy (ALE) of $500,000. However, Scenario A involves frequent, small, predictable losses, while Scenario B involves a rare but catastrophic single loss event. The board asks the analyst which measure best captures the difference in risk between the two scenarios that a single ALE figure hides. Which additional analysis output should the analyst emphasize?

Reviewed for accuracy · Report an issue
Question 20 of 20

A financial services firm currently performs enterprise risk assessments on a fixed annual cycle. Over the past year, the organization migrated several core services to a cloud provider, acquired a fintech startup, and faced a surge in targeted phishing campaigns. During the most recent annual assessment, several risks were found to have materialized months earlier without detection. What should the risk practitioner recommend to best address this gap?

Reviewed for accuracy · Report an issue

More CRISC practice

Keep going with the other ISACA CRISC — Certified in Risk and Information Systems Control domains, or take a full timed mock exam.

← Back to CRISC overview