Risk-focused ISACA certification covering governance, IT risk assessment, risk response and reporting, and the technology and security knowledge a risk practitioner needs.
Free sample questions
No account needed. Every question has a worked explanation, just like the full bank.
lock_openFree sampleGovernancemedium
A risk practitioner is asked to demonstrate that the IT risk management approach supports the organisation's strategy. Which action provides the strongest evidence of strategic alignment?
- ADeriving risk appetite, tolerance and treatment priorities directly from the approved strategic objectivescheck_circle Correct
- BMapping each identified IT risk scenario to the specific business objectives it could impair
- CCounting how many IT risk scenarios were closed within the agreed remediation window
- DPublishing the IT risk register to every department head on a fixed monthly schedule
Strategic alignment is proven when risk appetite, tolerance and treatment priorities are derived from approved strategic objectives. Alignment means the strategy drives the risk decisions, so deriving appetite, tolerance and treatment priorities from the approved objectives makes business intent the controlling input rather than an afterthought layered onto technical activity.
Why A is correct: When appetite, tolerance and priorities flow from the approved strategic objectives, the risk approach is demonstrably governed by strategy rather than run as an isolated technical exercise.
Why B is wrong: Mapping risks to objectives is useful and tempting because it shows traceability, but it documents exposure rather than proving the overall approach is steered by strategy.
Why C is wrong: Closure rates measure operational efficiency of treatment, so they look like progress, yet they say nothing about whether the work served the organisation's strategic goals.
Why D is wrong: Wide distribution improves transparency and feels like good governance, but circulating a register does not show that risk decisions are anchored to business strategy.
lock_openFree sampleGovernancemedium
The board has approved a new strategy to expand into regulated overseas markets within two years. How should the risk practitioner adjust the IT risk management approach to stay aligned with this strategy?
- AFreeze the existing risk register until the overseas expansion has been fully completed and reviewed
- BReassess risk appetite and tolerance so they reflect the new regulatory and market exposures created by the expansioncheck_circle Correct
- CIncrease the frequency of vulnerability scans across all current production systems
- DDelegate all new market risk decisions to the local teams once each overseas office opens
When strategy changes, realign the risk approach by reassessing appetite and tolerance against the new objectives and exposures. Strategic objectives define the boundaries of acceptable risk, so a major shift such as regulated overseas expansion requires appetite and tolerance to be reassessed; otherwise the approach stays calibrated to a strategy the organisation has abandoned.
Why A is wrong: Freezing the register feels cautious during change, but it lets the approach drift out of step with a strategy whose risk profile is shifting right now.
Why B is correct: A new strategic direction changes what the organisation is willing to accept, so revisiting appetite and tolerance keeps the risk approach matched to the objectives the board has just set.
Why C is wrong: More frequent scanning is a sound technical control and sounds proactive, yet it addresses operational hygiene rather than realigning the approach with the new strategy.
Why D is wrong: Local delegation can speed decisions and seems pragmatic, but handing off without realigned appetite breaks the link between enterprise strategy and risk choices.
lock_openFree sampleRisk Response and Reportingmedium
A residual risk sits just above the organisation's stated risk appetite, and the cost of further controls would clearly exceed the potential loss. The business owner is willing to live with the exposure. Which risk treatment should the practitioner recommend?
- AAccept the residual risk with documented, informed sign-off from the business owner.check_circle Correct
- BTransfer the exposure to an insurer so the financial impact falls on a third party.
- CAvoid the risk by retiring the underlying activity that generates the exposure.
- DMitigate further by adding controls until the residual sits below appetite.
Recognise that informed risk acceptance is appropriate when the cost of further treatment exceeds the potential loss and the owner accepts the exposure. Risk acceptance is justified when the marginal cost of additional controls would exceed the value at risk; the practitioner records the decision with informed business-owner sign-off so the residual exposure is owned and accountable rather than ignored.
Why A is correct: When treatment cost exceeds the potential loss and the owner accepts the exposure, formal informed acceptance is the economically rational and accountable choice.
Why B is wrong: Transfer through insurance shifts financial impact but adds premium cost, which is hard to justify when the residual loss is already smaller than further treatment spend.
Why C is wrong: Avoidance removes the activity entirely, an extreme response that sacrifices business value when the exposure is only marginally above appetite.
Why D is wrong: Adding controls feels safe, but spending more than the loss is worth destroys value and is not warranted for a marginal breach of appetite.
More free CRISC practice questions with worked answersFrequently asked questions
- How many questions are on the CRISC exam?
- The Certified in Risk and Information Systems Control (CRISC) exam has 150 questions and runs for 240 minutes. The format is multiple choice, computer-based at psi testing centres or remote proctored.
- What score do I need to pass CRISC?
- The pass mark is 450 / 800. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
- How much does the CRISC exam cost?
- The exam costs 760 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
- Is there a CRISC practice exam?
- Yes. Examworthy's exam mode runs a timed CRISC practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand against the blueprint. Timed mocks are free with an account.
- How does Examworthy help me prepare for CRISC?
- Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
- Is Examworthy affiliated with ISACA?
- No. Examworthy is not affiliated with or endorsed by ISACA. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.
Examworthy is not affiliated with or endorsed by ISACA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CRISC and related marks belong to their respective owners.