Reader small image

You're reading from  ISACA Certified in Risk and Information Systems Control (CRISC®) Exam Guide

Product typeBook
Published inSep 2023
PublisherPackt
ISBN-139781803236902
Edition1st Edition
Right arrow
Author (1)
Shobhit Mehta
Shobhit Mehta
author image
Shobhit Mehta

Shobhit Mehta is the Security and Compliance Director at Headspace, an on-demand mental health company in San Francisco, CA. Previously, he worked in different facets of security and assurance with HSBC, Deutsche Bank, Credit Suisse, PayPal, and Fidelity Investments. He also works with ISACA to develop exam questions for CISA, CISM, and CGEIT, served as the technical reviewer for the CGEIT and CISA review manuals, and is a published author for the COBIT 5 journal. He completed his MS in cybersecurity at Northeastern University, Boston, and holds CRISC, CISM, CISA, CGEIT, CISSP, and CCSP certifications. In his spare time, he likes to explore the inclined trails of the Bay Area, complete ultramarathons, and blog on GRCMusings.
Read more about Shobhit Mehta

Right arrow

Review questions

  1. Which of the following frameworks is primarily used for quantitative risk management?
    1. NIST 800-30
    2. FAIR
    3. ISO 27001
    4. ISO 27005
  2. A top-down risk assessment starts from the __.
    1. Team
    2. Individual
    3. Organization
    4. Department
  3. A bottom-up risk assessment starts from the __.
    1. Team
    2. Individual
    3. Organization
    4. Department
  4. Which of the following is NOT true about qualitative risk management?
    1. Less expensive
    2. Subjective
    3. Requires complex computation
    4. Focused on severity
  5. Which of the following NIST frameworks provides guidance for supply chain management?
    1. 800-161
    2. 800-30
    3. 800-57
    4. 27001
  6. Which of the following risk assessment techniques provides the results of a risk assessment by displaying links between possible causes, controls, and consequences in terms of a diagram?
    1. FAIR
    2. BTA
    3. Markov analysis
    4. Monte Carlo analysis
  7. The results of a risk assessment should be summarized as a(n) __.
    1. CAP
    2. Business continuity plan
    3. Organizational chart
    4. Risk register
lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
ISACA Certified in Risk and Information Systems Control (CRISC®) Exam Guide
Published in: Sep 2023Publisher: PacktISBN-13: 9781803236902

Author (1)

author image
Shobhit Mehta

Shobhit Mehta is the Security and Compliance Director at Headspace, an on-demand mental health company in San Francisco, CA. Previously, he worked in different facets of security and assurance with HSBC, Deutsche Bank, Credit Suisse, PayPal, and Fidelity Investments. He also works with ISACA to develop exam questions for CISA, CISM, and CGEIT, served as the technical reviewer for the CGEIT and CISA review manuals, and is a published author for the COBIT 5 journal. He completed his MS in cybersecurity at Northeastern University, Boston, and holds CRISC, CISM, CISA, CGEIT, CISSP, and CCSP certifications. In his spare time, he likes to explore the inclined trails of the Bay Area, complete ultramarathons, and blog on GRCMusings.
Read more about Shobhit Mehta