8 real CRISC flashcards, sampled from all 4 domains the exam tests, heaviest first. Where a tempting wrong answer encodes a belief people genuinely hold, the card corrects it too - the trap most decks skip. No account, no card.
The full deck has 554 flashcards, and a free account opens 40 of them across every domain. For a domain-by-domain breakdown and a study plan, read the CRISC study guide.
schoolConceptRisk Response and Reporting
When residual risk sits just above appetite but further controls would cost more than the potential loss, what treatment is appropriate?
arrow_downward
Informed risk acceptance with documented business-owner sign-off. When the marginal cost of more controls exceeds the value at risk, accepting is the economically rational choice, and formal sign-off keeps the residual exposure owned and accountable rather than ignored.
errorMisconceptionRisk Response and Reporting
Transferring a marginal over-appetite exposure to an insurer is the right call when controls would cost more than the loss.
arrow_downward
Transfer adds premium cost on top of an exposure already smaller than further treatment spend, so it is hard to justify. When treatment cost exceeds the potential loss, documented acceptance is the rational response.
schoolConceptGovernance
What provides the strongest evidence that an IT risk management approach is aligned with organisational strategy?
arrow_downward
Deriving risk appetite, tolerance and treatment priorities directly from the approved strategic objectives. When these flow from strategy, business intent becomes the controlling input and the risk approach is demonstrably governed by strategy rather than run as an isolated technical exercise.
errorMisconceptionGovernance
Mapping each IT risk scenario to the business objectives it could impair proves the risk approach is steered by strategy.
arrow_downward
Mapping risks to objectives shows useful traceability and documents exposure, but it does not prove the overall approach is steered by strategy. Strategic alignment is shown by deriving appetite, tolerance and treatment priorities from the approved objectives.
schoolConceptRisk Assessment
What four components must an IT risk scenario bind together to be useful for analysis and response?
arrow_downward
A usable scenario links a threat actor, the triggering event, the affected asset, and the resulting business loss consequence. Likelihood and impact estimates depend on all four being present, so a complete scenario gives analysts enough context to size the risk and design a proportionate response.
errorMisconceptionRisk Assessment
A detailed network and data-flow diagram of a platform constitutes a risk scenario.
arrow_downward
An architecture diagram is an input that supports analysis, not a scenario in itself, because it names no event, no actor, and no loss outcome. A scenario must connect actor, event, asset, and consequence.
schoolConceptInformation Technology and Security
How should the enterprise architecture function manage IT risk when a business unit wants to buy a platform that duplicates an existing capability?
arrow_downward
Architecture review compares each proposed change against the agreed target-state architecture. Running the proposed platform through that review surfaces redundancy with the existing capability and the integration burden before money is committed, so the risk is addressed pre-approval rather than after deployment fragments the estate.
errorMisconceptionInformation Technology and Security
A routine duplicate-platform purchase should be escalated straight to the audit committee for an independent buy or no-buy decision.
arrow_downward
Audit-committee escalation sounds rigorous but bypasses the architecture review, which is the correct first-line mechanism for catching duplication and integration risk. It is also disproportionate to a routine procurement decision.
Examworthy is not affiliated with or endorsed by ISACA. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CRISC and related marks belong to their respective owners.