Questions for the CRISC were updated on : Nov 30 ,2025
Which of the following is the FIRST step when identifying risk items related to a new IT project?
C
Which of the following is MOST important when creating a program to reduce ethical risk?
P-
D
An organization has implemented immutable backups to prevent successful ransomware attacks.
Which of the following is the MOST effective control for the risk practitioner to review?
C
Which of the following is the GREATEST benefit of involving business owners in risk scenario
development?
D
Which of the following is the PRIMARY objective of risk management?
A
During a data loss incident, which role in the RACI chart would be aligned to the risk practitioner?
D
Which of the following situations would cause the GREATEST concern around the integrity of
application logs?
A
Before selecting a final risk response option for a given risk scenario, management should FIRST:
C
Explanation:
P-
Which of the following is the MOST effective way to identify changes in the performance of the
control environment?
C
Which of the following is the PRIMARY role of the first line of defense with respect to information
security policies?
P-
D
An online retailer has decided to store its customer database with a cloud provider in an
Infrastructure as a Service (laaS) configuration. During an initial review of preliminary risk scenarios,
a risk practitioner identifies instances where sensitive customer information is stored unencrypted.
Who is accountable for ensuring this encryption?
B
Which of the following BEST enables senior management to make risk treatment decisions in line
with the organization's risk appetite?
A
Which of the following is the MOST important risk management activity during project initiation?
A. Defining key risk indicators (KRIs)
B. Classifying project data
C. Identifying key risk stakeholders
D. Establishing a risk mitigation plan
C
P-
A risk practitioner is asked to present the results of the most recent technology risk assessment to
executive management in a concise manner. Which of the following is MOST important to include in
the presentation?
A
Which of the following should be given the HIGHEST priority when developing a response plan for
risk assessment results?
P-
B