ISACA CRISC — Certified in Risk and Information Systems Control · Domain 3 · 32% of exam

Risk Response and Reporting

Drill 20 practice questions focused entirely on Risk Response and Reporting for the ISACA CRISC exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A risk practitioner is reviewing a proposed control to mitigate a data-integrity risk. The annual cost of implementing and operating the control is estimated at $250,000, while the control is expected to reduce annualized loss expectancy from $180,000 to $40,000. Management is eager to proceed because the risk relates to a high-visibility system. What should the risk practitioner recommend?

Reviewed for accuracy · Report an issue
Question 2 of 20

During a review of a newly implemented access-recertification control, a risk analyst confirms that the control was thoughtfully designed to require quarterly manager sign-off on user entitlements. However, over the past two quarters, managers approved recertifications in bulk without reviewing individual entitlements, and several terminated employees retained active access. Which conclusion best describes the state of this control?

Reviewed for accuracy · Report an issue
Question 3 of 20

A risk practitioner is reviewing a remediation action where the IT team reports that a new privileged-access monitoring control has been fully deployed to close a high-rated finding. The finding owner has requested that the corresponding risk register entry be updated to 'closed.' Before agreeing to close the entry, what is the MOST important action the practitioner should take?

Reviewed for accuracy · Report an issue
Question 4 of 20

A financial services firm processes thousands of high-value wire transfers daily. Management is concerned that a manual quarterly review of transactions exceeding approval thresholds is failing to catch unauthorized transfers before funds leave the organization. The risk practitioner is asked to recommend an improvement to the monitoring approach. Which recommendation BEST addresses management's concern?

Reviewed for accuracy · Report an issue
Question 5 of 20

A financial institution processes thousands of high-value wire transfers daily. The risk practitioner is designing a monitoring approach for the fraud-detection control governing these transfers. Given the transaction volume and the potential for large, rapid financial loss from a single fraudulent transfer, which monitoring approach should the practitioner recommend?

Reviewed for accuracy · Report an issue
Question 6 of 20

During quarterly control monitoring, a risk analyst notices that the same access-provisioning control has generated approved exceptions in each of the last four quarters, always for the same business unit citing 'urgent operational need.' Each exception was individually approved within policy and expired on schedule. What should the analyst do FIRST?

Reviewed for accuracy · Report an issue
Question 7 of 20

A risk manager is designing a monitoring program for a payment processing system that has more than 40 documented controls. Resource constraints prevent continuous monitoring of every control. To provide the most meaningful assurance to management with limited resources, which approach should the risk manager prioritize?

Reviewed for accuracy · Report an issue
Question 8 of 20

During a risk response review, a newly appointed control owner for a data-loss-prevention (DLP) system tells the risk committee that because the control is operating effectively, the associated data-leakage risk is now fully 'owned and closed' by their team. The risk manager wants to correct the misunderstanding before it is documented in the risk register. Which statement best clarifies the accountability relationship the risk manager should communicate?

Reviewed for accuracy · Report an issue
Question 9 of 20

A newly implemented data loss prevention (DLP) control was deployed by the security engineering team to reduce the risk of confidential customer data leaving the organization. During a post-implementation review, the risk practitioner notes that no one has been formally designated as responsible for the ongoing operation, tuning, and monitoring of the DLP control. Which action should the risk practitioner recommend FIRST?

Reviewed for accuracy · Report an issue
Question 10 of 20

A financial services firm has identified a risk that employees may fraudulently alter payment amounts in the accounts payable system. Management wants to select a control response. The organization already has manual monthly reconciliations that catch discrepancies after payments are made, but losses have already occurred by that point. Which control approach should the risk practitioner recommend to most effectively reduce the likelihood of this risk materializing?

Reviewed for accuracy · Report an issue
Question 11 of 20

A risk manager wants to increase business unit engagement in control monitoring while reducing reliance on periodic internal audit reviews. Operational managers currently view control assessment as a compliance burden imposed by others. Which approach would BEST address this situation?

Reviewed for accuracy · Report an issue
Question 12 of 20

A risk practitioner is designing the ongoing monitoring plan for a portfolio of internal controls. Management wants an efficient approach that focuses testing effort where it matters most. Which factor should PRIMARILY determine how frequently each control is tested?

Reviewed for accuracy · Report an issue
Question 13 of 20

A risk manager is preparing a consolidated enterprise risk report for the board by combining risk data submitted independently by five business units. Each unit uses its own 1-to-5 scoring scale, but the definitions of what constitutes a '4' or '5' differ significantly between units (e.g., one unit defines '5' as a $1M loss while another defines it as a $10M loss). What should the risk manager do FIRST before aggregating the data?

Reviewed for accuracy · Report an issue
Question 14 of 20

A risk practitioner learns of an emerging technology risk related to generative AI tools being adopted informally across several business units. The threat is not yet well understood, no loss events have occurred, and the potential impact is highly uncertain. Senior management is pressing for an immediate decision on how to respond. What should the practitioner recommend FIRST?

Reviewed for accuracy · Report an issue
Question 15 of 20

A business unit cannot meet a corporate password-complexity standard because a legacy application does not support it. Management requests that the risk practitioner grant a formal exception so the application can remain in production. What is the MOST important element to include when documenting this exception?

Reviewed for accuracy · Report an issue
Question 16 of 20

During a quarterly review, a risk analyst finds that several audit findings from the previous year remain open. The findings were logged in the issue-tracking system, but no remediation progress has been recorded, and the target dates have all passed without any updates or escalation. Which weakness in the organization's issues and findings management process does this MOST directly indicate?

Reviewed for accuracy · Report an issue
Question 17 of 20

A KRI monitoring failed privileged-access login attempts has just crossed its established threshold for the third consecutive week. The metric is owned by the IT security manager, and reporting is automated and accurate. What should the risk practitioner ensure happens FIRST in response to this sustained breach?

Reviewed for accuracy · Report an issue
Question 18 of 20

A risk analyst notices that one of the organization's key risk indicators (KRIs) for failed login attempts has been reporting flat, unchanging values for three consecutive months, even though the security operations team has confirmed multiple brute-force incidents during that period. Before presenting the risk dashboard to the risk committee, what should the analyst do FIRST?

Reviewed for accuracy · Report an issue
Question 19 of 20

A risk manager is preparing a monthly dashboard for the operations leadership team. The team wants to understand both whether a critical patch-management control is operating as designed and whether the exposure it addresses is increasing. Which pairing of metrics BEST satisfies both needs on the same dashboard?

Reviewed for accuracy · Report an issue
Question 20 of 20

A risk manager is designing key risk indicators (KRIs) for the organization's patch management process. The goal is to give management advance warning so they can act before an incident occurs. Which of the following candidate metrics would be the MOST effective KRI for this purpose?

Reviewed for accuracy · Report an issue

More CRISC practice

Keep going with the other ISACA CRISC — Certified in Risk and Information Systems Control domains, or take a full timed mock exam.

← Back to CRISC overview