CRISC Information Systems Control Design 2 — Questions and Answers
Question 1: Which IS control framework is MOST widely used for evaluating and designing controls in IT environments?
- COBIT (Correct answer)
- TOGAF
- PMBOK
- SAFe
Correct answer: COBIT
COBIT is the leading framework for IT governance and control design, providing a comprehensive set of processes and control objectives.
Question 2: A key logger installed on workstations by an attacker would BEST be detected by which control?
- Endpoint detection and response (EDR) software (Correct answer)
- Network perimeter firewall rules
- Segregation of duties policy
- Data loss prevention (DLP) system
Correct answer: Endpoint detection and response (EDR) software
EDR solutions monitor endpoint behavior and can detect unauthorized software such as keyloggers through behavioral analysis.
Question 3: Which control design consideration is MOST important for systems handling Personally Identifiable Information (PII)?
- Data minimization and access controls aligned with privacy regulations (Correct answer)
- Maximum system uptime and availability
- Lowest possible latency for data retrieval
- Automated backup to geographically dispersed locations
Correct answer: Data minimization and access controls aligned with privacy regulations
PII systems must implement data minimization (collect only what's needed) and strong access controls to comply with privacy regulations like GDPR and CCPA.
Question 4: An application that generates an audit log of all privileged user actions is implementing which type of control?
- Detective control (Correct answer)
- Preventive control
- Corrective control
- Directive control
Correct answer: Detective control
Audit logging is a detective control that creates a record of activities, enabling identification and investigation of unauthorized or suspicious actions.
Question 5: When designing controls for a third-party vendor relationship, which document BEST defines required security controls?
- Service level agreement with security annexure (Correct answer)
- Vendor's published ISO 27001 certificate
- Vendor's internal security policy
- Annual vendor financial audit report
Correct answer: Service level agreement with security annexure
An SLA with a security annexure contractually requires the vendor to meet specific security control standards and allows for enforcement.
Question 6: Which control is MOST effective at preventing unauthorized changes to production systems?
- Change management process with formal approval workflow (Correct answer)
- Continuous monitoring of system logs
- Quarterly vulnerability assessment
- Automated patch deployment system
Correct answer: Change management process with formal approval workflow
A formal change management process requiring approvals before changes reach production prevents unauthorized modifications through procedural controls.
Which IS control framework is MOST widely used for evaluating and designing controls in IT environments?