100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CRISC Exam with correct answers.

Rating
-
Sold
-
Pages
16
Grade
A+
Uploaded on
12-10-2025
Written in
2025/2026

CRISC Exam with correct answers.

Institution
CRISC
Course
CRISC










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CRISC
Course
CRISC

Document information

Uploaded on
October 12, 2025
Number of pages
16
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CRISC Exam with correct answers
| | | |




What |is |the |difference |between |a |standard |and |a |policy? |- |correct |answer |Standard |= |A |
mandatory |action, |explicit |rules, |controls |or |configuration |settings |that |are |designed |to |
support |and |conform |to |a |policy. |A |standard |should |make |a |policy |more |meaningful |and |
effective |by |including |accepted |specifications |for |hardware, |software |or |behavior. |Standards |
should |always |point |to |the |policy |to |which |they |relate.

Policy |= |IT |policies |help |organizations |to |properly |articulate |the |organization's |desired |
behavior, |mitigate |risk |and |contribute |to |achieving |the |organization's |goals.



What |are |the |4 |risk |elements? |- |correct |answer |Threats, |Vulnerabilities, |Likelihood, |and |
Impact. |Threats |exploit |vulnerabilities |and |the |level |of |risk |is |based |on |likelihood |and |the |
impact |to |the |system.



Describe |risk |appetite |vs. |risk |tollerance |- |correct |answer |Risk |appetite |is |how |much |risk |an |
organization |is |willing |to |endure; |Risk |Tolerance |is |how |much |variation |from |that |amount |is |
acceptable.



Name |the |6 |steps |of |the |NIST |Risk |Management |Framework |(RMF) |- |correct |answer |1. |
Categorize |Information |Systems

2. |Select |Security |Controls

3. |Implement |Security |Controls

4. |Assess |Security |Controls

5. |Authorize |Information |Systems

6. |Monitor |Security |Controls



Which |framework |is |developed |by |ISACA |and |integrates |other |frameworks?

a) |(Val) |IT

,b) |IT |Assurance |Framework |(ITAF)

c) |COBIT |5

d) |Risk |IT |- |correct |answer |c. |COBIT |5



What |are |the |3 |domains |of |ISACA's |Risk |IT |Framework? |- |correct |answer |Risk |Governance |
(RG), |Risk |Evaluation |(RE), |Risk |Response |(RR)



What |are |the |tenets |of |risk |management? |- |correct |answer |confidentiality, |integrity, |and |
availability



Which |legal |act |requires |U.S. |Federal |Govt |agencies |to |establish |an |information |security |
program? |- |correct |answer |Federal |Information |Security |Management |Act |(FISMA)



What |is |the |Gramm-Leach-Bliley |Act |(GLBA) |- |correct |answer |GLBA |requires |periodic |risk |
analysis |performed |on |processes |that |deal |with |nonpublic |financial |information |and |personal |
financial |data.



The |Risk |Governance |(RG) |domain |of |the |Risk |IT |framework |is |comprised |of |what |3 |processes?
|- |correct |answer |RG1: |Establish |and |maintain |a |common |risk |view



RG2: |Integrate |with |ERM

RG3: |Make |risk-aware |business |decisions



The |Risk |Evaluation |(RE) |domain |of |the |Risk |IT |framework |is |comprised |of |what |3 |processes? |- |
correct |answer |RE1: |Collect |Data

RE2: |Analyze |Risk

RE3: |Maintain |risk |profile



The |Risk |Response |(RR) |domain |of |the |Risk |IT |framework |is |comprised |of |what |3 |processes? |- |
correct |answer |RR1: |Articulate |risk

, RR2: |Manage |risk

RR3: |React |to |events



What |is |a |threat |agent? |- |correct |answer |The |entity |causing |or |enacting |a |threat |against |a |
vulnerability.



What |is |the |simple |risk |formula? |- |correct |answer |threats |x |vulnerabilities |= |risk



What |are |the |key |areas |of |concern |for |emerging |technologies? |- |correct |answer |
Interoperability |and |Compatibility



What |are |the |5 |components |of |a |risk |scenario? |- |correct |answer |1) |Threat |agent

2) |Threat

3) |Asset

4) |Vulnerability

5) |Time/location



Describe |the |bottom-up |approach |to |risk |scenario |generation |- |correct |answer |Look |at |all |
potential |scenarios |beginning |with |what |asset, |process, |or |area |of |concern |the |risk |scenarios |
might |affect.



Describe |the |top-down |approach |to |risk |scenario |generation |- |correct |answer |Develop |risk |
scenarios |from |a |specific |business |objective |perspective



What |document |would |list |the |different |risk |scenarios? |- |correct |answer |The |risk |register |
could |include:

Risk |factors

Threats |& |vulnerabilities
$14.49
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
Lectpolly

Get to know the seller

Seller avatar
Lectpolly Chamberlain College Of Nursing
View profile
Follow You need to be logged in order to follow users or courses
Sold
0
Member since
4 months
Number of followers
0
Documents
36
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions