What the ISACA CRISC (Certified in Risk and Information Systems Control) exam covers
- Governance213 questions
- IT Risk Assessment181 questions
- Risk Response and Reporting263 questions
- Information Technology and Security164 questions
Free ISACA CRISC (Certified in Risk and Information Systems Control) sample questions
A sample of 10 questions with answers and explanations. Sign up free to practice all 821.
-
A bank has outsourced its data center operations to a third party service provider. The risk practitioner is asked who remains accountable for risks arising from those outsourced operations. What is the BEST answer?
- AThe bank remains accountable, since outsourcing does not transfer accountability for the riskCorrect
- BThe service provider becomes accountable, since it now performs the day to day operational tasks
- CAccountability is shared equally and no single party can be identified as accountable
- DAccountability shifts to the regulator once a third party is engaged to perform the function
✓ Correct answer: AOutsourcing transfers the operational execution of a task to a service provider, but the bank retains accountability for outcomes because it made the decision to outsource and remains responsible to its stakeholders and regulators. The provider may take on certain contractual responsibilities, but this does not relieve the bank of ultimate accountability, and accountability does not shift to a regulator or become unassignable simply because a third party is involved.
Why the other options are wrong- BThe service provider takes on operational responsibility for the task, but this does not transfer the bank's underlying accountability for the risk.
- CTreating accountability as shared equally with no identifiable owner would leave a gap in governance that outsourcing arrangements are meant to avoid.
- DRegulators oversee the bank's management of outsourced risk, but accountability does not shift to the regulator itself.
-
Following the data owner's decision to classify a dataset as highly sensitive, the IT operations team configures encryption, backup, and access logging for the system storing it. Which role are they performing?
- ARisk owner, since they accept the residual risk associated with the data
- BData owner, since they are making the final decision on data sensitivity
- CData custodian, since they implement required controlsCorrect
- DData subject, since their personal information is contained in the dataset
✓ Correct answer: CCustodians, often within IT operations, are responsible for the day to day safeguarding of data through activities such as encryption, backups, and access logging, acting on requirements set by the data owner. The owner decides classification and acceptable use, while the custodian executes the technical safeguards. This division of duties keeps accountability with the owner and implementation with the custodian.
Why the other options are wrong- AA risk owner is accountable for treatment decisions regarding a given risk, not for daily technical control implementation.
- BThe data owner sets the classification and acceptable use of data, rather than performing the technical implementation described here.
- DA data subject is the individual to whom personal data relates and is not the party implementing protective controls.
-
When formally assigning ownership for a newly identified enterprise risk, which two elements should be confirmed to make the assignment effective? (Choose two)
- AThe owner has the authority to make decisions about the riskCorrect
- BThe owner has access to resources needed to treat the riskCorrect
- CThe owner is a member of the internal audit function
- DThe owner is the most senior executive in the organization
- EThe owner is located within the information technology department
✓ Correct answer: A, BAuthority without resources leaves an owner unable to implement decisions, while resources without authority leave decisions stuck awaiting someone else's approval. Neither internal audit membership, seniority alone, nor department location determines whether an assignment will be effective. What matters is whether the specific individual can actually direct and fund the treatment of that specific risk.
Why the other options are wrong- CInternal audit provides independent assurance and is not typically an appropriate risk owner for operational risks.
- DSeniority alone does not guarantee the specific authority and resource access needed for a particular risk.
- EDepartment location, such as being in information technology, does not by itself confirm authority or resource access for a given risk.
-
Which THREE of the following events should typically prompt an update to the risk register outside of the regular review cycle? (Choose three.)
- AIdentification of a new risk scenario not previously capturedCorrect
- BA routine, unremarkable day with no notable operational activity
- CThe scheduled annual budget meeting for an unrelated department
- DA significant change in business processes or the threat environmentCorrect
- EFailure of a control that an existing treatment plan depends onCorrect
✓ Correct answer: A, D, EThe risk register is meant to reflect current exposure, so events that materially change that picture, such as a newly identified scenario, a failed control, or a significant shift in the business or threat environment, warrant an update as soon as they are known rather than waiting for the next scheduled review. A routine day with no notable activity or an unrelated department's budget meeting does not introduce new information that would change any entry's rating. Responding promptly to genuine triggers keeps the register from becoming outdated between formal review cycles.
Why the other options are wrong- BA routine, unremarkable day introduces no new information that would change the rating of any existing entry.
- CAn unrelated department's scheduled budget meeting has no bearing on the risk scenarios tracked in the register.
-
A risk team wants to combine the speed of workshop based ratings with more defensible numeric scoring, so they assign numbers such as 1 through 5 to likelihood and impact categories and multiply them to produce a risk score. This approach is BEST described as which type of analysis?
- APure quantitative analysis using historical loss data
- BBow-tie analysis using causal pathway and control diagrams
- CValue at risk analysis using confidence level thresholds
- DSemi-quantitative analysis using scaled numeric ratingsCorrect
✓ Correct answer: DSemi-quantitative analysis bridges qualitative and quantitative methods by converting descriptive ratings into numbers, such as a 1 to 5 scale, so scenarios can be ranked with slightly more rigor than pure qualitative labels while avoiding the data demands of full quantitative modeling. Pure quantitative analysis instead relies on actual monetary and frequency data. Value at risk and bow-tie analysis are distinct techniques not centered on multiplying scale numbers.
Why the other options are wrong- APure quantitative analysis uses actual monetary values and real frequency data rather than arbitrary numbers on ordinal categories.
- BBow-tie analysis visually maps causes and consequences with controls, rather than producing a multiplied numeric score.
- CValue at risk is a statistical measure of potential loss at a confidence level, not a scoring scale multiplication method.
-
During design of a KRI program for third party dependency risk, the team proposes tracking 'vendor relationship quality' as an indicator. A colleague objects to this proposal. What is the MOST valid basis for the objection?
- AThe indicator has not previously been adopted by any similar organization in the industry
- BThe indicator does not appear in the vendor's service level agreement
- CThe indicator would require input from the procurement department
- DThe indicator cannot be quantified in consistent, comparable termsCorrect
✓ Correct answer: DVendor relationship quality is a subjective concept that cannot be consistently quantified, so it fails the measurability criterion even if it may seem relevant to third party risk. Objective substitutes such as SLA breach counts or on time delivery rates would satisfy this criterion instead. Novelty in the industry, cross departmental data needs, and absence from a contract are secondary concerns that do not by themselves disqualify a metric.
Why the other options are wrong- ABeing untested elsewhere in the industry does not make a metric invalid; the real problem is that the concept cannot be objectively measured.
- BAbsence from the SLA is a contractual gap, not the fundamental reason this qualitative concept fails as a KRI.
- CNeeding data from another department is a sourcing challenge, not a reason the indicator itself is flawed.
-
A hospital's clinical systems team has one administrator who provisions and de-provisions all electronic health record accounts due to limited IT staffing. Which compensating control would BEST address the resulting segregation of duties gap?
- AA dashboard showing the administrator's total number of tickets closed each month
- BA policy requiring the administrator to document their own work in a personal notebook
- CA rule that the administrator must complete provisioning requests within twenty-four hours
- DA periodic access review performed by someone outside the clinical systems teamCorrect
✓ Correct answer: DHaving someone outside the clinical systems team periodically compare provisioned accounts to records of authorized personnel and role changes can catch inappropriate access the administrator created or failed to remove. A self-maintained personal notebook, a turnaround time requirement, or a productivity dashboard of closed tickets do not provide any independent verification of whether the access granted was appropriate.
Why the other options are wrong- AA count of closed tickets measures productivity, not the appropriateness of the access provisioned.
- BA self-maintained notebook is not independent and does not verify whether access granted was appropriate.
- CA turnaround time requirement addresses speed of service, not whether granted access is appropriate.
-
A risk response action plan for a newly identified vendor dependency risk lists only a general description of the risk and a note that controls will be improved. What is the plan MOST critically missing?
- AA named responsible owner and a target completion dateCorrect
- BAn extended list of every risk in the enterprise risk register
- CA summary of the vendor's marketing materials and history
- DA restatement of the risk description in more technical language
✓ Correct answer: ABeyond describing the risk, an action plan needs to specify who is accountable for executing the response and by when, along with the resources required. Without an owner and a deadline, the vague intent to improve controls cannot be tracked, measured, or held accountable to any outcome.
Why the other options are wrong- BListing unrelated enterprise risks does not address the specific gap in this action plan's accountability and timeline.
- CBackground information on the vendor's marketing history has no bearing on whether the response will actually be executed.
- DRephrasing the risk description in technical terms does not make the plan actionable or trackable.
-
A remediation action for a moderate risk finding is significantly overdue, and the process owner requests that the residual risk simply be accepted instead of completing the fix. Who should make the final decision to accept this risk?
- AA risk owner or governance body with authority to accept risk at that levelCorrect
- BThe process owner who originally requested this particular risk acceptance
- CThe project manager currently tracking the remediation action in the register
- DThe internal auditor who originally raised and documented this specific finding
✓ Correct answer: ARisk acceptance decisions should be made by a designated risk owner or governance body whose authority level matches the significance of the risk, ensuring the decision reflects organizational risk appetite rather than one individual's convenience. The process owner requesting acceptance has an interest in avoiding further remediation work, which is a conflict of interest for making the final call. The original auditor and the tracking project manager play monitoring roles rather than holding risk acceptance authority.
Why the other options are wrong- BThe process owner requesting acceptance has a conflict of interest in being the one to approve it.
- CThe project manager tracking the action in the register does not hold risk acceptance authority.
- DThe auditor's role is to assess and report on the finding, not to approve accepting the residual risk.
-
A finance department continues to store customer transaction records indefinitely, well beyond the period required by applicable regulation or ongoing business need. What risk does this practice MOST directly create?
- AThe finance department's service level agreement will be immediately breached
- BThe organization will automatically fail its next external financial audit
- CThe service desk will be required to reclassify all related incident tickets
- DSensitive data stays exposed to potential compromise longer than necessaryCorrect
✓ Correct answer: DEvery additional record kept beyond the period justified by regulation or genuine business need adds to the volume of sensitive data an attacker could potentially reach, and increases the scope and cost of activities like e-discovery or breach investigation if an incident occurs. This does not automatically cause an audit failure, since retention alone is only one factor considered, and it has no direct bearing on incident ticket classification or a specific SLA being breached.
Why the other options are wrong- ANo specific service level agreement breach is described as a direct result of extended data retention.
- BExcess retention is a risk factor an auditor may flag, but it does not automatically cause an audit to fail outright.
- CIncident ticket classification is unrelated to how long finance records are retained.
Related Security resources
- ISACA CRISC (Certified in Risk and Information Systems Control) study guideKey concepts
- Security practice examsAll Security
- Certification pathWhere this fits
- Certification exam guides & tipsBlog
- Plans & pricingFree & paid
- (ISC)² CISSP practice examRelated
- (ISC)² Certified in Cybersecurity (CC) practice examRelated
- CompTIA Security+ SY0-701 practice examRelated
ISACA CRISC (Certified in Risk and Information Systems Control) practice exam FAQ
How many questions are in the ISACA CRISC (Certified in Risk and Information Systems Control) practice exam on CertGrid?
CertGrid has 821 practice questions for ISACA CRISC (Certified in Risk and Information Systems Control), covering 4 exam domains. The real ISACA CRISC (Certified in Risk and Information Systems Control) exam is 150 qs in 240 min. CertGrid's timed mock is a fixed 75 questions.
What is the passing score for ISACA CRISC (Certified in Risk and Information Systems Control)?
The ISACA CRISC (Certified in Risk and Information Systems Control) exam passing score is 56.3%, and you have about 240 min to complete it. CertGrid scores your practice attempts the same way so you know when you are ready.
Are these official ISACA CRISC (Certified in Risk and Information Systems Control) exam questions?
No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the ISACA CRISC (Certified in Risk and Information Systems Control) exam.
Can I practice ISACA CRISC (Certified in Risk and Information Systems Control) for free?
Yes. You can start practicing ISACA CRISC (Certified in Risk and Information Systems Control) for free with daily practice and sample questions. Paid plans unlock full timed exams, complete explanations, and domain analytics.
What CertGrid is (and is not)
CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.
Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.