Inspirational journeys

Follow the stories of academics and their research expeditions

CRISC—Certified in Risk and Information Systems Control Certification Questions and answer - Part 77

Mary Smith

Sat, 18 Apr 2026

CRISC—Certified in Risk and Information Systems Control Certification Questions and answer - Part 77

1. You are the project manager of the GHT project. This project will last for 18 months and has a project budget of $567,000. Robert, one of your stakeholders, has introduced a scope change request that will likely have an impact on the project costs and schedule. Robert assures you that he will pay for the extra time and costs associated with the risk event. You have identified that change request may also affect other areas of the project other than just time and cost. What project management component is responsible for evaluating a change request and its impact on all of the project management knowledge areas?

A) Configuration management
B) Integrated change control
C) Risk analysis
D) Project change control system



2. While developing obscure risk scenarios, what are the requirements of the enterprise?Each correct answer represents a part of the solution. Choose two.(Select 2answers)

A) Have capability to cure the risk events
B) Have capability to recognize an observed event as something wrong
C) Have sufficient number of analyst
D) Be in a position that it can observe anything going wrong



3. You are the project manager of GHT project. During the data extraction process you evaluated the total number of transactions per year by multiplying the monthly average by twelve. This process of evaluating total number of transactions is known as?

A) Duplicates test
B) Controls total
C) Simplistic and ineffective
D) Reasonableness test



4. You are the project manager of the KJH Project and are working with your project team to plan the risk responses. Consider that your project has a budget of$500,000 and is expected to last six months. Within the KJH Project you have identified a risk event that has a probability of .70 and has a cost impact of$350,000. When it comes to creating a risk response for this event what is the risk exposure of the event that must be considered for the cost of the risk response?

A) The risk exposure of the event is $350,000.
B) The risk exposure of the event is $500,000.
C) The risk exposure of the event is $850,000.
D) The risk exposure of the event is $245,000.



5. Jane, the Director of Sales, contacts you and demands that you add a new feature to the software your project team is creating for the organization. In the meeting she tells you how important the scope change would be. You explain to her that the software is almost finished and adding a change now could cause the deliverable to be late, cost additional funds, and would probably introduce new risks to the project. Jane stands up and says to you, 'I am the Director of Sales and this change will happen in the project.' And then she leaves the room. What should you do with this verbal demand for a change in the project?

A) Include the change in the project scope immediately.
B) Direct your project team to include the change if they have time.
C) Do not implement the verbal change request.
D) Report Jane to your project sponsor and then include the change.



1. Right Answer: B
Explanation: Integrated change control is responsible for evaluating a proposed change and determining its impact on all areas of the project: scope, time, cost, quality, human resources, communication, risk, and procurement.Incorrect Answers:A: Configuration management defines the management, control, and documentation of the features and functions of the project's product.C: Risk analysis is not responsible for reviewing the change aspects for the entire project.D: The project change control system defines the workflow and approval process for proposed changes to the project scope, time, cost, and contracts.

2. Right Answer: B,D
Explanation: The enterprise must consider risk that has not yet occurred and should develop scenarios around unlikely, obscure or non-historical events.Such scenarios can be developed by considering two things: Visibility Recognition For the fulfillment of this task enterprise must: Be in a position that it can observe anything going wrong Have the capability to recognize an observed event as something wrongIncorrect Answers:A, C: These are not the direct requirements for developing obscure risk scenarios, like curing risk events comes under process of risk management. Hence capability of curing risk event does not lay any impact on the process of development of risk scenarios.

3. Right Answer: D
Explanation: Reasonableness tests make certain assumptions about the information as the basis for more elaborate data validation tests.Incorrect Answers:A: The duplicate test does not identify duplicate transactions; rather it identifies and confirms the validity of duplicates.B: The control total test does not ensure that all transactions have been extracted, but only ensures that the data are complete.C: As compared to simplistic, the reasonableness test is a valid foundation for more elaborate data validation tests.

4. Right Answer: D
Explanation: The risk exposure for this event is found by multiplying the risk impact by the risk probability.Risk Exposure is a straightforward estimate that gives a numeric value to a risk, enabling different risks to be compared.Risk Exposure of any given risk = Probability of risk occurring x impact of risk event= 0.70 * 350,000= 245,000Incorrect Answers:A: $350,000 is the impact of the risk event.B: $500,000 is the project's budget.C: $850,000 is the project's budget and the risk's impact.

5. Right Answer: C
Explanation: This is a verbal change request, and verbal change requests are never implemented. They introduce risk and cannot be tracked in the project scope. Change requests are requests to expand or reduce the project scope, modify policies, processes, plans, or procedures, modify costs or budgets or revise schedules.These requests for a change can be direct or indirect, externally or internally initiated, and legally or contractually imposed or optional. A Project Manager needs to ensure that only formally documented requested changes are processed and only approved change requests are implemented.Incorrect Answers:A: Including the verbal change request circumvents the project's change control system.B: Directing the project team to include the change request if they have time is not a valid option. The project manager and the project team will have all of the project team already accounted for so there is no extra time for undocumented, unapproved change requests.D: You may want to report Jane to the project sponsor, but you are not obligated to include the verbal change request.

0 Comments

Leave a comment