Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 63 páginas
Examen

ISACA CERTIFIED IN RISK AND INFORMATION SYSTEMS CONTROL (CRISC) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Vista previa 4 fuera de 63 páginas

ISACA CERTIFIED IN RISK AND INFORMATION SYSTEMS CONTROL (CRISC) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF ISACA CERTIFIED IN RISK AND INFORMATION SYSTEMS CONTROL (CRISC) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Vista previa del contenido

ISACA CERTIFIED IN RISK AND
INFORMATION SYSTEMS CONTROL (CRISC)
EXAM WITH QUESTIONS AND VERIFIED
ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
A multinational organization is implementing a new cloud-based
customer relationship management platform. During the risk assessment,
the risk team identifies that a compromise of customer information could
result in regulatory penalties, litigation, reputational damage, and loss of
customer trust. The business owner estimates that the organization could
tolerate a temporary degradation of CRM availability but has almost no
tolerance for unauthorized disclosure of customer information. Which
action would BEST demonstrate that the risk assessment is aligned with
the organization's risk appetite?
A. Assign the same risk rating to confidentiality and availability because
both are security objectives
B. Prioritize confidentiality-related risks according to the organization's
stated tolerance and business impact
C. Treat all cloud risks as high because cloud services are outside the
organization's physical infrastructure
D. Transfer all identified risks to the cloud provider through contractual
agreements
Answer: B. Prioritize confidentiality-related risks according to the
organization's stated tolerance and business impact



1

,Rationale: The organization's risk appetite and tolerance determine
how identified risks should be evaluated and prioritized. Because
management has very low tolerance for confidentiality failures but
greater tolerance for temporary availability degradation,
confidentiality risks should receive greater attention and stronger
controls. Risk cannot be evaluated solely by technical severity; it must
be considered in the context of business objectives, impact, and
management's willingness to accept exposure.


2.
A risk practitioner is conducting an enterprise risk assessment for an
organization preparing to launch an online payment service. The
organization has identified several threats, including credential theft,
distributed denial-of-service attacks, insider fraud, and third-party
service outages. Which activity should occur FIRST after identifying the
relevant threats?
A. Purchase additional security technologies
B. Determine the likelihood and potential business impact associated
with the risks
C. Develop detailed incident response procedures
D. Transfer all risks to insurance providers
Answer: B. Determine the likelihood and potential business impact
associated with the risks
Rationale: Risk analysis requires evaluating the likelihood that a
threat will exploit a vulnerability or weakness and the resulting
business impact. Controls should not be selected merely because a
threat exists. Understanding likelihood and impact enables
management to prioritize risks and determine appropriate treatment.
Technology purchases, response procedures, and insurance decisions
should follow risk analysis rather than precede it.
2

,3.
An organization has classified a critical database as having a maximum
tolerable downtime of four hours. During a business continuity
assessment, the recovery team determines that the current recovery
solution requires approximately eight hours to restore the database.
What does this MOST directly indicate?
A. The recovery solution creates a residual risk exceeding the
organization's tolerance
B. The database has been incorrectly classified as a critical asset
C. The recovery solution has completely eliminated availability risk
D. The maximum tolerable downtime should automatically be increased
to eight hours
Answer: A. The recovery solution creates a residual risk exceeding
the organization's tolerance
Rationale: The organization requires recovery within four hours, but
the current capability requires eight hours. This creates a gap between
the required recovery objective and the implemented capability. Unless
management explicitly changes the business requirement, the gap
represents unacceptable residual risk that should be addressed
through risk treatment or improved recovery capabilities.


4.
A chief information security officer asks the CRISC practitioner to
recommend a risk treatment strategy for a vulnerability in an internal
application. Exploitation is possible, but the application is scheduled to
be decommissioned in two weeks. The cost of remediation would be
substantial. Which approach is MOST appropriate?


3

, A. Immediately replace the application
B. Accept the risk without management involvement
C. Consider risk acceptance or temporary mitigation based on
documented business risk and remaining exposure
D. Transfer the risk entirely to the application vendor
Answer: C. Consider risk acceptance or temporary mitigation based
on documented business risk and remaining exposure
Rationale: Risk treatment should consider exposure, business context,
remaining asset life, cost, and risk tolerance. Since the application will
soon be decommissioned, a major remediation effort may not be cost-
effective. However, the risk should not simply be ignored.
Management should evaluate temporary controls or formally accept
the remaining risk if it falls within approved tolerance.


5.
During a risk assessment, a business manager insists that a particular
application is "low risk" because it has never experienced a security
incident. Which response by the CRISC practitioner is BEST?
A. Agree because historical incidents are the strongest indicator of future
risk
B. Explain that absence of previous incidents does not establish absence
of risk
C. Immediately classify the application as high risk
D. Recommend shutting down the application until an incident occurs
Answer: B. Explain that absence of previous incidents does not
establish absence of risk
Rationale: Risk is forward-looking. Historical incidents can provide
useful evidence but do not prove that an asset is secure. A threat may
exist even if exploitation has not yet occurred. Effective risk

4

Información del documento

Subido en
28 de agosto de 2026
Número de páginas
63
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$24.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
profwhite
4.3
(20)
Vendido
120
Seguidores
76
Artículos
4660
Última venta
1 día hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes