Inspirational journeys

Follow the stories of academics and their research expeditions

CRISC—Certified in Risk and Information Systems Control Certification Questions and answer - Part 58

Mary Smith

Sat, 21 Feb 2026

CRISC—Certified in Risk and Information Systems Control Certification Questions and answer - Part 58

1. You are the project manager of a large networking project. During the execution phase the customer requests for a change in the existing project plan. What will be your immediate action?

A) Update the risk register.
B) Ask for a formal change request.
C) Ignore the request as the project is in the execution phase.
D) Refuse the change request.



2. Which of the following is described by the definition given below?'It is the expected guaranteed value of taking a risk.'

A) Certainty equivalent value
B) Risk premium
C) Risk value guarantee
D) Certain value assurance



3. You are the project manager of GHT project. Your hardware vendor left you a voicemail saying that the delivery of the equipment you have ordered would not arrive on time. She wanted to give you a heads-up and asked that you return the call. Which of the following statements is TRUE?

A) This is a residual risk.
B) This is a trigger.
C) This is a contingency plan.
D) This is a secondary risk.



4. There are five inputs to the quantitative risk analysis process. Which one of the following is NOT an input to quantitative risk analysis process?

A) Risk management plan
B) Enterprise environmental factors
C) Cost management plan
D) Risk register



5. Stephen is the project manager of the GBB project. He has worked with two subject matter experts and his project team to complete the risk assessment technique. There are approximately 47 risks that have a low probability and a low impact on the project. Which of the following answers best describes whatStephen should do with these risk events?

A) Because they are low probability and low impact, Stephen should accept the risks.
B) The low probability and low impact risks should be added to a watchlist for future monitoring.
C) Because they are low probability and low impact, the risks can be dismissed.
D) The low probability and low impact risks should be added to the risk register.



1. Right Answer: B
Explanation: Whenever the customer or key stakeholder asks for a change in the existing plan, you should ask him/her to submit a formal change request. Change requests may modify project policies or procedures, project scope, project cost or budget, project schedule, or project quality.Incorrect Answers:A, C, D: The first action required is to create a formal change request, if a change is requested in the project.

2. Right Answer: A
Explanation: The Certainty equivalent value is the expected guaranteed value of taking a risk. It is derived by the uncertainty of the situation and the potential value of the situation's outcome.Incorrect Answers:B: The risk premium is the difference between the larger expected value of the risk and the smaller certainty equivalent value.C, D: These are not valid answers.

3. Right Answer: B
Explanation: Triggers are warning signs of an upcoming risk event. Here delay in delivery signifies that there may be a risk event like delay in completion of project. Hence it is referred to as a trigger.Incorrect Answers:A: Residual risk is the risk that remains after applying controls. But here in this scenario, risk event has not occurred yet.C: A contingency plan is a plan devised for a specific situation when things go wrong. Contingency plans are often devised by governments or businesses who want to be prepared for anything that could happen. Here there are no such plans.D: Secondary risks are risks that come about as a result of implementing a risk response. But here in this scenario, risk event has not occurred yet.

4. Right Answer: B
Explanation: Enterprise environmental factor is not an input to the quantitative risk analysis process. The five inputs to the perform quantitative risk analysis process are: risk register, risk management plan, cost management plan, schedule management plan, and organizational process assets.Incorrect Answers:A, C, D: These are the valid inputs to the perform quantitative risk analysis process.

5. Right Answer: B
Explanation: The low probability and low impact risks should be added to a watchlist for future monitoring.Incorrect Answers:A: The risk response for these events may be to accept them, but the best answer is to first add them to a watchlist.C: Risks are not dismissed; they are at least added to a watchlist for monitoring.D: While the risks may eventually be added to the register, the best answer is to first add them to the watchlist for monitoring.

0 Comments

Leave a comment