CertGrid
Security Certification

ISACA CRISC (Certified in Risk and Information Systems Control) Practice Exam

Validates expertise in enterprise IT risk management and information systems control - governance, IT risk assessment, risk response and reporting, and information technology and security.

Start with a free ISACA CRISC (Certified in Risk and Information Systems Control) practice test, then work through 842 exam-style questions with full answer explanations, and take timed mock exams to track your readiness against the exam objectives.

842
Practice pool
150 qs
Real exam
240 min
Real exam time
450 / 800
Passing score

CertGrid runs a fixed 75-question timed mock, separate from the real exam format above.

Objective-mapped practice, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

What the ISACA CRISC (Certified in Risk and Information Systems Control) exam covers

Free ISACA CRISC (Certified in Risk and Information Systems Control) practice test questions

A sample of 10 questions with answers and explanations. Sign up free to practice all 842.

  1. Question 1Governance

    A bank has outsourced its data center operations to a third party service provider. The risk practitioner is asked who remains accountable for risks arising from those outsourced operations. What is the BEST answer?

    • AThe bank remains accountable, since outsourcing does not transfer accountability for the riskCorrect
    • BThe service provider becomes accountable, since it now performs the day to day operational tasks
    • CAccountability is shared equally and no single party can be identified as accountable
    • DAccountability shifts to the regulator once a third party is engaged to perform the function
    ✓ Correct answer: A

    Outsourcing transfers the operational execution of a task to a service provider, but the bank retains accountability for outcomes because it made the decision to outsource and remains responsible to its stakeholders and regulators. The provider may take on certain contractual responsibilities, but this does not relieve the bank of ultimate accountability, and accountability does not shift to a regulator or become unassignable simply because a third party is involved.

    Why the other options are wrong
    • BThe service provider takes on operational responsibility for the task, but this does not transfer the bank's underlying accountability for the risk.
    • CTreating accountability as shared equally with no identifiable owner would leave a gap in governance that outsourcing arrangements are meant to avoid.
    • DRegulators oversee the bank's management of outsourced risk, but accountability does not shift to the regulator itself.
  2. Question 2GovernanceSelect all that apply

    Which two principles are most directly reflected in the ISACA Code of Professional Ethics as it applies to a risk practitioner's daily work? Choose two.

    • APrioritizing personal relationships with business unit leaders over independent risk judgment
    • BEnsuring that the enterprise reports zero compliance findings during an external audit
    • CPerforming professional duties with due diligence and care in accordance with standardsCorrect
    • DMaintaining confidentiality of information from professional work unless legally requiredCorrect
    • EGuaranteeing that every identified risk will be fully eliminated before a project proceeds
    ✓ Correct answer: C, D

    Core ethical expectations for risk practitioners include performing work with due diligence and care consistent with professional standards, and safeguarding the confidentiality of information learned during engagements unless disclosure is legally required. Guaranteeing complete risk elimination or a finding free audit are unrealistic and not part of the ethical code, and prioritizing personal relationships over independent judgment directly conflicts with the expectation of objectivity.

    Why the other options are wrong
    • APrioritizing personal relationships over independent judgment directly conflicts with the expectation of objectivity in professional conduct.
    • BGuaranteeing a finding free external audit is not a realistic professional commitment and is not part of the ethical code.
    • EGuaranteeing complete elimination of risk is not a realistic or achievable professional expectation and is not part of the ethical code.
  3. Question 3Governance

    During an internal audit, the access control restricting changes to the payroll system is confirmed to be operating effectively, yet the residual risk of unauthorized payroll changes remains above the organization's risk appetite because compensating controls elsewhere are weak. Who is accountable for deciding whether additional risk treatment is required?

    • AThe IT operations manager who administers the system
    • BThe control owner who designed and operates the specific payroll access control
    • CThe internal audit team that tested the control
    • DThe risk owner accountable for the payroll riskCorrect
    ✓ Correct answer: D

    The control owner is accountable for ensuring a specific control operates as designed, but that role does not extend to deciding whether overall residual risk is acceptable. The risk owner weighs the aggregate effect of all controls against the organization's risk appetite and determines whether further treatment is warranted. Audit and IT operations support this decision with evidence but do not make it.

    Why the other options are wrong
    • AThe IT operations manager administers the underlying system but is not accountable for accepting or treating the residual risk.
    • BThe control owner confirms the control itself works but is not accountable for the broader residual risk decision.
    • CInternal audit provides independent assurance on control effectiveness but does not make risk treatment decisions.
  4. Question 4IT Risk Assessment

    A risk practitioner at a regional bank is building a heat map to present risk scenarios to the risk committee. Likelihood and impact for each scenario are rated on ordinal scales of low, medium, and high based on facilitated workshop discussion. What type of risk analysis is being performed?

    • AMonte Carlo simulation using randomized numeric iterations
    • BValue at risk modeling using statistical confidence intervals
    • CQualitative analysis using descriptive ordinal rating scalesCorrect
    • DQuantitative analysis using calculated monetary loss figures
    ✓ Correct answer: C

    Qualitative analysis relies on descriptive categories and expert judgment rather than numeric loss figures, making it fast to perform and easy for stakeholders to interpret on a heat map. Quantitative and simulation based methods instead express likelihood and impact in numeric or monetary terms derived from data. Since the scenario uses low, medium, and high labels from workshop discussion, it is squarely qualitative.

    Why the other options are wrong
    • AMonte Carlo simulation runs many numeric iterations to model outcome distributions, which is not what an ordinal rating reflects.
    • BValue at risk is a numeric statistical measure of potential loss over a time horizon, not a descriptive ordinal rating.
    • DQuantitative analysis expresses likelihood and impact as calculated monetary amounts, not ordinal labels like low or medium.
  5. Question 5IT Risk Assessment

    A backup strategy is being designed for a financial reporting database. The BIA specified that no more than two hours of transaction data can be lost in a disruption. Which metric does this two hour figure represent?

    • AWork recovery time, the post restoration validation timeframe
    • BRecovery point objective, the maximum acceptable data lossCorrect
    • CRecovery time objective, the target restoration duration
    • DMaximum tolerable downtime, the outage limit before harm
    ✓ Correct answer: B

    RPO defines how much data, expressed as a time interval, the enterprise can afford to lose and directly drives backup and replication frequency. A two hour RPO means backups or replication must occur at least every two hours. RTO addresses how long restoration takes, MTD is the total outage the process can survive, and work recovery time covers post restoration validation activity.

    Why the other options are wrong
    • AWork recovery time covers the validation and catch up work after systems are restored, not acceptable data loss.
    • CRecovery time objective addresses how long it takes to restore the process, not how much data can be lost.
    • DMaximum tolerable downtime is the total outage duration the process can survive, not a data loss measurement.
  6. Question 6Risk Response and Reporting

    A national insurer's chief risk officer wants a single tool to visualize which key risks are covered by internal audit, compliance monitoring, and external audit, and to identify any risks with no assurance coverage at all. Which tool is MOST suited to this purpose?

    • AA risk and control matrix documenting the design of each individual control in the environment.
    • BA key risk indicator dashboard tracking threshold breaches for the insurer's top risks.
    • CA control self-assessment questionnaire completed independently by each business unit annually.
    • DAn assurance map showing which providers cover each key risk and where coverage gaps exist.Correct
    ✓ Correct answer: D

    An assurance map plots each key risk against the assurance providers, such as internal audit, compliance, and external audit, that cover it, making it possible to see both areas of overlapping coverage and risks with no coverage at all, which supports a combined assurance approach. A risk and control matrix documents control design rather than assurance provider coverage, a CSA questionnaire is one input to assurance rather than a coverage map, and a KRI dashboard tracks risk indicator thresholds rather than assurance coverage.

    Why the other options are wrong
    • AA risk and control matrix documents control design details rather than mapping assurance provider coverage across risks.
    • BA KRI dashboard tracks indicator thresholds for risks, not which assurance providers cover each risk.
    • CA CSA questionnaire is one source of assurance input, not a tool for mapping coverage across multiple assurance providers.
  7. Question 7Risk Response and Reporting

    A manufacturer calculates that installing redundant sensors on an aging production line would cost more over five years than the maximum expected loss from a sensor failure. No regulatory requirement mandates the upgrade. What should guide the response decision in this case?

    • AA transfer arrangement to shift the cost to a supplier
    • BAn avoidance decision to shut down the production line
    • CA cost-benefit analysis supporting acceptance of the riskCorrect
    • DA feasibility study to justify mitigation regardless of cost
    ✓ Correct answer: C

    Cost-benefit analysis is one of the primary criteria for choosing among response options. Since the redundant sensors cost more than the expected loss and no regulation compels the upgrade, the economically sound response is to formally accept the risk rather than spend disproportionately on mitigation.

    Why the other options are wrong
    • AShifting the cost to a supplier does not reflect an established transfer mechanism for this internal equipment risk.
    • BShutting down the production line sacrifices ongoing output disproportionate to the modest expected loss.
    • DPursuing mitigation despite the cost-benefit analysis showing a net loss ignores the economic criterion central to response selection.
  8. Question 8Risk Response and Reporting

    A managed services contract states that the vendor must inform the organization of a confirmed security incident affecting shared data within 48 hours of discovery. Which type of clause does this represent?

    • AA service level agreement with a clearly defined resolution deadline
    • BA right to audit clause with a clearly defined inspection window
    • CA breach notification clause with a defined disclosure timeframeCorrect
    • DA limitation of liability clause with a clearly defined damages cap
    ✓ Correct answer: C

    Specifying an exact window, such as 48 hours, removes ambiguity about when the organization can expect to be informed, enabling it to meet its own downstream regulatory or contractual notification duties. Audit windows, SLA resolution deadlines, and liability caps address verification rights, performance timing, and financial exposure respectively, not the disclosure of an incident itself.

    Why the other options are wrong
    • AAn SLA resolution deadline addresses how quickly an issue is fixed, not how quickly it must be reported.
    • BAn audit clause window governs when inspections may occur, not when an incident must be disclosed.
    • DA liability cap defines the maximum recoverable damages, not the timing of incident disclosure.
  9. Question 9Information Technology and Security

    A risk practitioner is reviewing an organization's incident response capability and finds that runbooks, contact lists, and forensic tools exist but staff have never been trained on them and roles are unassigned. Which IR lifecycle phase is deficient?

    • AEradication
    • BPreparationCorrect
    • CDetection
    • DContainment
    ✓ Correct answer: B

    Preparation includes developing plans, assigning responsibilities, training staff, and staging tools before an incident occurs. Having documentation without trained personnel or clear ownership means the organization is not actually ready to respond effectively when an incident is detected.

    Why the other options are wrong
    • AEradication concerns removing the root cause of an incident, which presumes detection and containment already occurred.
    • CDetection concerns identifying that an incident has occurred, which is a separate capability from the readiness gaps described.
    • DContainment concerns limiting an incident already underway, not pre incident readiness.
  10. Question 10Information Technology and Security

    A risk assessment identifies that all application logins depend on a single on premises authentication server with no failover instance. Which risk is MOST significant from an availability perspective?

    • ALog data from the authentication server may not be retained long enough for investigations
    • BUsers may reuse weak passwords across the authentication server and other systems
    • CA single point of failure could prevent all users from authenticating during an outageCorrect
    • DThe authentication server could be targeted by unauthorized privileged access attempts
    ✓ Correct answer: C

    Availability risk focuses on whether a critical service can continue operating when a component fails. Without redundancy, an outage of the sole authentication server would prevent every dependent application from validating logins, a broader business impact than the credential, access, or logging concerns in the other options.

    Why the other options are wrong
    • ALog retention supports investigation and monitoring but is not the primary availability concern raised by the lack of redundancy.
    • BPassword reuse is a credential risk affecting confidentiality rather than the availability impact described in the scenario.
    • DUnauthorized privileged access attempts relate to access control risk rather than the server acting as a single point of failure.

Who this ISACA CRISC (Certified in Risk and Information Systems Control) practice exam is for

This practice set is for anyone preparing for the ISACA CRISC (Certified in Risk and Information Systems Control) exam - from first-time candidates building a foundation to experienced professionals doing a final review before test day. If you learn best by working through realistic questions and reading why each answer is right or wrong, it is built for you.

How to use this ISACA CRISC (Certified in Risk and Information Systems Control) practice exam

  1. Start with the free sample questions above to gauge your current baseline.
  2. Read the full explanation on every question, including why each wrong option is wrong.
  3. Track your weak domains and focus your study where you are losing the most marks.
  4. Once you are scoring consistently well, take a timed, full-length mock exam.
  5. Use your readiness score to decide when you are ready to book the real ISACA CRISC (Certified in Risk and Information Systems Control) exam.

Related Security resources

ISACA CRISC (Certified in Risk and Information Systems Control) practice exam FAQ

How many questions are in the ISACA CRISC (Certified in Risk and Information Systems Control) practice exam on CertGrid?

CertGrid has 842 practice questions for ISACA CRISC (Certified in Risk and Information Systems Control), covering 4 exam domains. The real ISACA CRISC (Certified in Risk and Information Systems Control) exam is 150 qs in 240 min. CertGrid's timed mock is a fixed 75 questions.

What is the passing score for ISACA CRISC (Certified in Risk and Information Systems Control)?

ISACA grades the CRISC on a 200-800 scaled score with 450 required to pass; a scaled score is not a raw percentage. CertGrid reports your percent-correct on this mock separately as a readiness indicator. You have about 240 min to complete it. CertGrid tracks your readiness against the exam objectives so you know where to focus.

Are these official ISACA CRISC (Certified in Risk and Information Systems Control) exam questions?

No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the ISACA CRISC (Certified in Risk and Information Systems Control) exam.

Is there a free ISACA CRISC (Certified in Risk and Information Systems Control) practice test?

Yes. You can take a free ISACA CRISC (Certified in Risk and Information Systems Control) practice test straight away: a fixed set of 20 practice questions for this exam, retryable as often as you like, with no credit card required. You get readiness scoring and a weak-domain breakdown on those questions. Paid plans unlock the full 842-question bank, timed mock exams and full-bank domain analytics.

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by ISACA. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.