ISACA CRISC — Certified in Risk and Information Systems Control · Domain 4 · 20% of exam

Technology and Security

Drill 20 practice questions focused entirely on Technology and Security for the ISACA CRISC exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A financial services firm is deploying a smart contract on a public blockchain to automate loan disbursements. During a pre-deployment risk review, a risk practitioner notes that once deployed, the contract code cannot be modified. Which risk implication should the practitioner prioritize when advising the project team?

Reviewed for accuracy · Report an issue
Question 2 of 20

An organization is migrating a customer-facing application to a public cloud provider using an Infrastructure-as-a-Service (IaaS) model. During the risk assessment, the risk practitioner notices that the project team assumes the cloud provider will handle all security patching, including the guest operating systems and application layers. Which action should the risk practitioner recommend FIRST to address this concern?

Reviewed for accuracy · Report an issue
Question 3 of 20

A financial services firm is rolling out a new data protection program. The security team wants to apply encryption, access restrictions, and retention rules across all repositories. However, they find that data across shared drives, databases, and cloud storage is treated uniformly, making it unclear which datasets warrant the strongest safeguards. What should the risk practitioner recommend the organization establish FIRST to guide the assignment of protection controls?

Reviewed for accuracy · Report an issue
Question 4 of 20

A financial services firm retains seven years of transaction data to satisfy regulatory obligations. Most queries touch only the last 90 days, but the entire dataset currently resides on high-performance production storage that is nearing capacity. The risk practitioner is asked to advise on managing this data through its lifecycle. Which recommendation BEST balances cost, performance, and risk?

Reviewed for accuracy · Report an issue
Question 5 of 20

A financial services firm is decommissioning several storage arrays that held customer account records subject to retention regulations. The records have exceeded their mandatory retention period and are no longer needed. The IT operations team plans to reformat the drives before sending the equipment to a third-party recycler. As the risk practitioner reviewing the data lifecycle disposal stage, what is your PRIMARY concern with this plan?

Reviewed for accuracy · Report an issue
Question 6 of 20

A development team is building a new customer-facing mobile application that will collect location, contact, and payment data. To align with data protection principles, the privacy officer insists that privacy safeguards be embedded from the earliest design phases rather than added after the product is functional. Which principle is the privacy officer primarily applying?

Reviewed for accuracy · Report an issue
Question 7 of 20

A multinational retailer plans to transfer customer personal data from its European subsidiary to a cloud analytics platform hosted in a country that the European Commission has NOT deemed to provide an adequate level of data protection. The privacy officer must ensure the transfer is lawful before it begins. Which action should the privacy officer take FIRST to enable this cross-border transfer?

Reviewed for accuracy · Report an issue
Question 8 of 20

A retail company receives an email from an individual demanding a copy of all personal data the company holds about them, citing their right of access under applicable privacy law. The requester provides only a name and email address. The data protection officer must decide how to proceed before releasing any records. What is the MOST important action to take first?

Reviewed for accuracy · Report an issue
Question 9 of 20

A marketing team wants to launch a new customer loyalty app. During the design review, the privacy officer notes that the app's registration form requests the customer's date of birth, home address, income bracket, and social media handles, even though the loyalty program only requires an email address and purchase history to function. Which data privacy principle should the privacy officer cite to challenge the current design?

Reviewed for accuracy · Report an issue
Question 10 of 20

An organization's data retention schedule mandates that customer transaction records be automatically purged after seven years. Litigation has just commenced involving one customer segment, and outside counsel has issued a legal hold notice covering those records. The automated purge routine is scheduled to run next week. What should the risk practitioner recommend FIRST?

Reviewed for accuracy · Report an issue
Question 11 of 20

A financial services organization maintains nightly encrypted backups of its core banking database, replicated to an off-site facility. During an annual audit, the risk manager notes that the backups have never actually been restored to verify usability; the team relies solely on the backup software's success logs. Which action should the risk manager recommend FIRST to address this concern?

Reviewed for accuracy · Report an issue
Question 12 of 20

A financial services firm's business impact analysis established a two-hour recovery time objective (RTO) for its core transaction processing platform. The firm is designing its disaster recovery strategy and comparing recovery site options against cost. Which recovery site option is MOST appropriate to meet the stated RTO?

Reviewed for accuracy · Report an issue
Question 13 of 20

A financial services firm completes a business impact analysis for its transaction processing system. Business owners state that, following a disruption, the firm can tolerate losing no more than 15 minutes of transaction data before regulatory and reconciliation problems become unacceptable. The current backup schedule captures full snapshots every 4 hours. Which action should the risk practitioner recommend to align the recovery strategy with this requirement?

Reviewed for accuracy · Report an issue
Question 14 of 20

During a regional disaster, a financial services firm activates its disaster recovery plan. The IT operations team is overwhelmed by simultaneous requests to restore dozens of systems. To restore services in a way that minimizes overall business impact, what should MOST guide the sequence in which systems are recovered?

Reviewed for accuracy · Report an issue
Question 15 of 20

A financial services firm has documented a disaster recovery plan for its core transaction platform but has never validated it beyond reviewing the written procedures. The risk practitioner wants to recommend a test that provides meaningful assurance that recovery procedures actually work while minimizing the risk of disrupting live production operations. Which testing approach should the practitioner recommend as the next step?

Reviewed for accuracy · Report an issue
Question 16 of 20

An enterprise has deployed a machine-learning model into production to approve consumer credit applications. Six months later, a risk practitioner notices that the model's approval patterns have shifted noticeably compared to its validation baseline, though no code changes were made. Which emerging-technology risk consideration should the practitioner MOST emphasize to management?

Reviewed for accuracy · Report an issue
Question 17 of 20

A risk practitioner reviews an organization where individual business units independently procure and deploy cloud services and applications without central coordination. This has resulted in duplicated tools, inconsistent security configurations, and integration gaps between systems. Which enterprise architecture practice would MOST effectively reduce the underlying risk exposure?

Reviewed for accuracy · Report an issue
Question 18 of 20

A risk practitioner reviews an enterprise's IT estate and finds that several core business applications still run on an unsupported operating system for which the vendor no longer issues security patches. IT operations continues to keep the systems running because migrating them would disrupt production. From a risk management perspective, what is the MOST significant concern the practitioner should raise to leadership?

Reviewed for accuracy · Report an issue
Question 19 of 20

A large manufacturing enterprise has grown through several acquisitions, and each business unit selected its own middleware, database platforms, and integration tools. Executives now report that inter-unit data exchange requires costly custom connectors, upgrades are unpredictable, and integrating a newly acquired firm takes over a year. The CIO asks the risk practitioner what enterprise architecture (EA) practice would most directly reduce these recurring integration risks and costs going forward. Which recommendation should the risk practitioner make?

Reviewed for accuracy · Report an issue
Question 20 of 20

A manufacturing enterprise is deploying thousands of Internet-connected sensors (IoT devices) across its production floor to enable real-time monitoring. Many of these devices ship with limited processing power, cannot run endpoint agents, and receive infrequent firmware updates from the vendor. The risk practitioner is asked to recommend the control that best limits the enterprise's exposure to the compromise of these devices. Which recommendation should the risk practitioner make FIRST?

Reviewed for accuracy · Report an issue

More CRISC practice

Keep going with the other ISACA CRISC — Certified in Risk and Information Systems Control domains, or take a full timed mock exam.

← Back to CRISC overview