8 real CRISC flashcards, sampled across every domain the exam tests. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.
The full deck has 1159 flashcards. For a domain-by-domain breakdown and a study plan, read the CRISC study guide.
schoolConceptRisk Response and Reporting
When residual risk sits just above appetite but further controls would cost more than the potential loss, what treatment is appropriate?
arrow_downward
Informed risk acceptance with documented business-owner sign-off. When the marginal cost of more controls exceeds the value at risk, accepting is the economically rational choice, and formal sign-off keeps the residual exposure owned and accountable rather than ignored.
errorMisconceptionRisk Response and Reporting
Transferring a marginal over-appetite exposure to an insurer is the right call when controls would cost more than the loss.
arrow_downward
Transfer adds premium cost on top of an exposure already smaller than further treatment spend, so it is hard to justify. When treatment cost exceeds the potential loss, documented acceptance is the rational response.
schoolConceptGovernance
What provides the strongest evidence that an IT risk management approach is aligned with organisational strategy?
arrow_downward
Deriving risk appetite, tolerance and treatment priorities directly from the approved strategic objectives. When these flow from strategy, business intent becomes the controlling input and the risk approach is demonstrably governed by strategy rather than run as an isolated technical exercise.
errorMisconceptionGovernance
Mapping each IT risk scenario to the business objectives it could impair proves the risk approach is steered by strategy.
arrow_downward
Mapping risks to objectives shows useful traceability and documents exposure, but it does not prove the overall approach is steered by strategy. Strategic alignment is shown by deriving appetite, tolerance and treatment priorities from the approved objectives.
schoolConceptRisk Assessment
What four components must an IT risk scenario bind together to be useful for analysis and response?
arrow_downward
A usable scenario links a threat actor, the triggering event, the affected asset, and the resulting business loss consequence. Likelihood and impact estimates depend on all four being present, so a complete scenario gives analysts enough context to size the risk and design a proportionate response.
errorMisconceptionRisk Assessment
A list of every operating control and its last test date is enough to form a risk scenario.
arrow_downward
A control catalogue describes the current state but states no threat, event, or consequence, so it cannot frame what could go wrong or how badly. A scenario needs an actor, an event, an affected asset, and a loss outcome.
schoolConceptInformation Technology and Security
How should the enterprise architecture function manage IT risk when a business unit wants to buy a platform that duplicates an existing capability?
arrow_downward
Architecture review compares each proposed change against the agreed target-state architecture. Running the proposed platform through that review surfaces redundancy with the existing capability and the integration burden before money is committed, so the risk is addressed pre-approval rather than after deployment fragments the estate.
errorMisconceptionInformation Technology and Security
Architecture's job for a duplicate tool purchase is just to document it in the repository after it goes into production.
arrow_downward
Recording a tool after deployment keeps the repository current but does nothing to manage the risk of the purchase itself. By then the redundancy and integration cost are locked in. The architecture review must happen before approval, while the decision can still be changed.
Examworthy is not affiliated with or endorsed by ISACA. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CRISC and related marks belong to their respective owners.