Certified in Risk and Information Systems Control

ISACA_CRISC
ProfessionalVersion 2024.1Official exam guide โ†—

Ready to test yourself?

A timed, blueprint-proportional exam drawn fresh from this bank โ€” with a per-domain score report.

๐Ÿ”’ Unlock the simulation โ†’

๐Ÿ”“ Free preview: showing 10 of 150 questions. Unlock the full bank โ€” every question, explanation, and reference.

Unlock all 150 questions โ†’

10 questions across 4 topics. Choose an answer for each question, then check it to see the correct answer and explanation.

Filter by topic

10 questions in Governance

D1_GOVERNANCE

Governance

10 questions in topic

Organizational and risk governance, appetite and tolerance, three lines of defense, frameworks, culture, policies, and professional ethics.

1
Single choice~110s

An enterprise's board approves an appetite statement but management continues approving initiatives that exceed it. Which conclusion is MOST accurate?

2
Single choice~110s

A risk practitioner is asked to define tolerance thresholds for an appetite statement that says the enterprise is 'moderately risk-averse for operational disruption'. What is the essential next step?

3
Single choice~110s

Which arrangement MOST compromises the second line of defense?

4
Single choice~110s

An enterprise assigns risk ownership for a cross-cutting technology risk to four divisional heads jointly. What is the MOST likely consequence?

5
Single choice~110s

Which distinguishes risk capacity from risk appetite in a practical decision?

6
Single choice~110s

A risk practitioner finds that a business unit consistently rates its own risks lower than comparable units rate equivalent exposures. What should be examined FIRST?

7
Single choice~110s

Which evidence BEST demonstrates that an enterprise's risk culture supports effective risk management?

8
Single choice~110s

An enterprise adopts COBIT governance and management objectives verbatim without tailoring. Which risk is MOST significant?

9
Single choice~110s

Which is the correct governance treatment when a risk is accepted at divisional level but its aggregate effect threatens enterprise objectives?

10
Single choice~110s

A newly appointed executive inherits several risks accepted by their predecessor. What is the correct treatment?