Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 63 pages
Exam (elaborations)

ISACA CERTIFIED IN RISK AND INFORMATION SYSTEMS CONTROL (CRISC) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Preview 4 out of 63 pages

ISACA CERTIFIED IN RISK AND INFORMATION SYSTEMS CONTROL (CRISC) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF ISACA CERTIFIED IN RISK AND INFORMATION SYSTEMS CONTROL (CRISC) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Content preview

ISACA CERTIFIED IN RISK AND
INFORMATION SYSTEMS CONTROL (CRISC)
EXAM WITH QUESTIONS AND VERIFIED
ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
A multinational organization is implementing a new cloud-based
customer relationship management platform. During the risk assessment,
the risk team identifies that a compromise of customer information could
result in regulatory penalties, litigation, reputational damage, and loss of
customer trust. The business owner estimates that the organization could
tolerate a temporary degradation of CRM availability but has almost no
tolerance for unauthorized disclosure of customer information. Which
action would BEST demonstrate that the risk assessment is aligned with
the organization's risk appetite?
A. Assign the same risk rating to confidentiality and availability because
both are security objectives
B. Prioritize confidentiality-related risks according to the organization's
stated tolerance and business impact
C. Treat all cloud risks as high because cloud services are outside the
organization's physical infrastructure
D. Transfer all identified risks to the cloud provider through contractual
agreements
Answer: B. Prioritize confidentiality-related risks according to the
organization's stated tolerance and business impact



1

,Rationale: The organization's risk appetite and tolerance determine
how identified risks should be evaluated and prioritized. Because
management has very low tolerance for confidentiality failures but
greater tolerance for temporary availability degradation,
confidentiality risks should receive greater attention and stronger
controls. Risk cannot be evaluated solely by technical severity; it must
be considered in the context of business objectives, impact, and
management's willingness to accept exposure.


2.
A risk practitioner is conducting an enterprise risk assessment for an
organization preparing to launch an online payment service. The
organization has identified several threats, including credential theft,
distributed denial-of-service attacks, insider fraud, and third-party
service outages. Which activity should occur FIRST after identifying the
relevant threats?
A. Purchase additional security technologies
B. Determine the likelihood and potential business impact associated
with the risks
C. Develop detailed incident response procedures
D. Transfer all risks to insurance providers
Answer: B. Determine the likelihood and potential business impact
associated with the risks
Rationale: Risk analysis requires evaluating the likelihood that a
threat will exploit a vulnerability or weakness and the resulting
business impact. Controls should not be selected merely because a
threat exists. Understanding likelihood and impact enables
management to prioritize risks and determine appropriate treatment.
Technology purchases, response procedures, and insurance decisions
should follow risk analysis rather than precede it.
2

,3.
An organization has classified a critical database as having a maximum
tolerable downtime of four hours. During a business continuity
assessment, the recovery team determines that the current recovery
solution requires approximately eight hours to restore the database.
What does this MOST directly indicate?
A. The recovery solution creates a residual risk exceeding the
organization's tolerance
B. The database has been incorrectly classified as a critical asset
C. The recovery solution has completely eliminated availability risk
D. The maximum tolerable downtime should automatically be increased
to eight hours
Answer: A. The recovery solution creates a residual risk exceeding
the organization's tolerance
Rationale: The organization requires recovery within four hours, but
the current capability requires eight hours. This creates a gap between
the required recovery objective and the implemented capability. Unless
management explicitly changes the business requirement, the gap
represents unacceptable residual risk that should be addressed
through risk treatment or improved recovery capabilities.


4.
A chief information security officer asks the CRISC practitioner to
recommend a risk treatment strategy for a vulnerability in an internal
application. Exploitation is possible, but the application is scheduled to
be decommissioned in two weeks. The cost of remediation would be
substantial. Which approach is MOST appropriate?


3

, A. Immediately replace the application
B. Accept the risk without management involvement
C. Consider risk acceptance or temporary mitigation based on
documented business risk and remaining exposure
D. Transfer the risk entirely to the application vendor
Answer: C. Consider risk acceptance or temporary mitigation based
on documented business risk and remaining exposure
Rationale: Risk treatment should consider exposure, business context,
remaining asset life, cost, and risk tolerance. Since the application will
soon be decommissioned, a major remediation effort may not be cost-
effective. However, the risk should not simply be ignored.
Management should evaluate temporary controls or formally accept
the remaining risk if it falls within approved tolerance.


5.
During a risk assessment, a business manager insists that a particular
application is "low risk" because it has never experienced a security
incident. Which response by the CRISC practitioner is BEST?
A. Agree because historical incidents are the strongest indicator of future
risk
B. Explain that absence of previous incidents does not establish absence
of risk
C. Immediately classify the application as high risk
D. Recommend shutting down the application until an incident occurs
Answer: B. Explain that absence of previous incidents does not
establish absence of risk
Rationale: Risk is forward-looking. Historical incidents can provide
useful evidence but do not prove that an asset is secure. A threat may
exist even if exploitation has not yet occurred. Effective risk

4

Document information

Uploaded on
August 28, 2026
Number of pages
63
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$24.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
profwhite
4.3
(20)
Sold
120
Followers
76
Items
4660
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions