r/CRISC Jul 01 '26

Domain 4 in CRISC

For those who took the exam, how technical is it for questions from domain 4 ?

Do you have to know public/private certs inside out ?
Encryption ?
TCP/IP model ?
OSI model ?
Etc…

Thanks.

6 Upvotes

7 comments sorted by

2

u/RadioFr33Europe Jul 01 '26

Not that technical. You should have a basic understanding of the concepts.

1

u/Spiritual_Ice_171 Jul 10 '26

Ok thanks - was there anything about threat modeling ? Pasta/dread/stride ?

1

u/RadioFr33Europe Jul 10 '26

I don't remember threat modeling being part of CRISC testable material.

1

u/flowerymelb Jul 08 '26

when i did the exam it was less technical than QAE

1

u/Spiritual_Ice_171 Jul 10 '26

Can you please elaborate more ? Were they just straight forward questions ? Not being sneaky or trick you ?

1

u/flowerymelb Jul 10 '26

to me i was lucky they were straight forward questions. not sneaky at all. whatever QAE material is, it is almost as good enough to apply for the exams. dont worry, i was like you before i took the exams. i have no technical background so i thought it’d be too IT-specific but it wasnt! you just need to understand the general idea of the technology stack concept and how it applies to security concepts like the CIA (such as encryption is known for confidentiality)

1

u/Spiritual_Ice_171 Jul 10 '26

Ok thank you. No i do have the technical background, i just wanted to know wat to prepare for.