ISACA free practice

Free CRISC practice questions

12 real CRISC sample questions, each with a worked explanation and a rationale for every option, right and wrong. No account, no card. This is the reasoning the CRISC tests: knowing why the tempting answer is wrong, not just spotting the right one.

The real CRISC is 150 questions in 240 minutes, pass mark 450 / 800. For a domain-by-domain breakdown and a study plan, read the CRISC study guide. The full bank has 290 questions.

Risk Response and Reporting (32% of the exam)

Free sampleRisk Response and Reportingmedium

A residual risk sits just above the organisation's stated risk appetite, and the cost of further controls would clearly exceed the potential loss. The business owner is willing to live with the exposure. Which risk treatment should the practitioner recommend?

  • AAccept the residual risk with documented, informed sign-off from the business owner. Correct
  • BTransfer the exposure to an insurer so the financial impact falls on a third party.
  • CAvoid the risk by retiring the underlying activity that generates the exposure.
  • DMitigate further by adding controls until the residual sits below appetite.
Recognise that informed risk acceptance is appropriate when the cost of further treatment exceeds the potential loss and the owner accepts the exposure. Risk acceptance is justified when the marginal cost of additional controls would exceed the value at risk; the practitioner records the decision with informed business-owner sign-off so the residual exposure is owned and accountable rather than ignored.

Why A is correct: When treatment cost exceeds the potential loss and the owner accepts the exposure, formal informed acceptance is the economically rational and accountable choice.

Why B is wrong: Transfer through insurance shifts financial impact but adds premium cost, which is hard to justify when the residual loss is already smaller than further treatment spend.

Why C is wrong: Avoidance removes the activity entirely, an extreme response that sacrifices business value when the exposure is only marginally above appetite.

Why D is wrong: Adding controls feels safe, but spending more than the loss is worth destroys value and is not warranted for a marginal breach of appetite.

Free sampleRisk Response and Reportingmedium

An online retailer faces a low-probability but financially catastrophic risk: a major data breach could trigger losses far beyond its capacity to absorb. Internal controls reduce likelihood but cannot eliminate the severe impact. Which treatment option best addresses the residual exposure?

  • AAccept the residual exposure because the probability of a breach is judged to be low.
  • BTransfer the residual financial impact through a cyber-insurance policy covering breach losses. Correct
  • CAvoid the risk by withdrawing entirely from holding any customer payment data online.
  • DMitigate alone by layering further preventive controls until the breach risk is zero.
Identify risk transfer through insurance as the fitting treatment for low-likelihood, high-impact risks that exceed the organisation's capacity to absorb. Transfer is the rational response when a residual risk has an impact larger than the organisation can withstand and likelihood is already low; insurance funds the rare but catastrophic loss while controls continue to limit how often it could occur.

Why A is wrong: Low probability tempts acceptance, but an impact beyond the firm's capacity to absorb makes pure acceptance reckless for a potentially ruinous loss.

Why B is correct: Insurance suits low-likelihood, high-impact risks the firm cannot absorb, moving the catastrophic financial impact to an insurer while internal controls still lower likelihood.

Why C is wrong: Avoidance removes the threat but also guts the core retail business, an overreaction when the impact can be transferred instead.

Why D is wrong: More controls reduce likelihood but cannot drive a breach risk to zero, so relying on mitigation alone leaves the catastrophic impact unfunded.

Free sampleRisk Response and Reportingmedium

A practitioner is selecting a treatment for a risk whose residual level is well above appetite. Which factor should most influence the choice between mitigating, transferring, accepting, or avoiding the risk?

  • AThe option that delivers the greatest reduction in gross risk before any control cost is considered.
  • BThe response category that shifts the largest share of the exposure onto an external third party.
  • CThe cost and benefit of each option weighed against the organisation's risk appetite. Correct
  • DThe option that moves the organisation's control maturity closest to its target maturity rating.
Understand that treatment selection is driven by cost-benefit analysis against risk appetite, not gross-risk reduction alone, a preferred response category, or a maturity target. Selecting a response means comparing the cost and effectiveness of each option against the organisation's appetite and tolerance, so the practitioner chooses the treatment that reduces residual risk to an acceptable level for a defensible cost rather than optimising for gross reduction, a favoured category, or a maturity score.

Why A is wrong: Maximising gross-risk reduction looks rigorous, but judging options on inherent exposure while ignoring cost can fund treatment that overshoots appetite at indefensible expense.

Why B is wrong: Favouring transfer feels prudent for a high residual risk, yet defaulting to one category ignores cost-benefit and leaves retained residual risk and counterparty risk unaddressed.

Why C is correct: Treatment selection should compare each option's cost and benefit against appetite, choosing the response that brings residual risk within tolerance at justifiable cost.

Why D is wrong: Closing a maturity gap is a valid programme goal, but a maturity target is not the appetite threshold and may not reduce this residual risk to a tolerable level at justifiable cost.

Governance (26% of the exam)

Free sampleGovernancemedium

A risk practitioner is asked to demonstrate that the IT risk management approach supports the organisation's strategy. Which action provides the strongest evidence of strategic alignment?

  • ADeriving risk appetite, tolerance and treatment priorities directly from the approved strategic objectives Correct
  • BMapping each identified IT risk scenario to the specific business objectives it could impair
  • CCounting how many IT risk scenarios were closed within the agreed remediation window
  • DPublishing the IT risk register to every department head on a fixed monthly schedule
Strategic alignment is proven when risk appetite, tolerance and treatment priorities are derived from approved strategic objectives. Alignment means the strategy drives the risk decisions, so deriving appetite, tolerance and treatment priorities from the approved objectives makes business intent the controlling input rather than an afterthought layered onto technical activity.

Why A is correct: When appetite, tolerance and priorities flow from the approved strategic objectives, the risk approach is demonstrably governed by strategy rather than run as an isolated technical exercise.

Why B is wrong: Mapping risks to objectives is useful and tempting because it shows traceability, but it documents exposure rather than proving the overall approach is steered by strategy.

Why C is wrong: Closure rates measure operational efficiency of treatment, so they look like progress, yet they say nothing about whether the work served the organisation's strategic goals.

Why D is wrong: Wide distribution improves transparency and feels like good governance, but circulating a register does not show that risk decisions are anchored to business strategy.

Free sampleGovernancemedium

The board has approved a new strategy to expand into regulated overseas markets within two years. How should the risk practitioner adjust the IT risk management approach to stay aligned with this strategy?

  • AFreeze the existing risk register until the overseas expansion has been fully completed and reviewed
  • BReassess risk appetite and tolerance so they reflect the new regulatory and market exposures created by the expansion Correct
  • CIncrease the frequency of vulnerability scans across all current production systems
  • DDelegate all new market risk decisions to the local teams once each overseas office opens
When strategy changes, realign the risk approach by reassessing appetite and tolerance against the new objectives and exposures. Strategic objectives define the boundaries of acceptable risk, so a major shift such as regulated overseas expansion requires appetite and tolerance to be reassessed; otherwise the approach stays calibrated to a strategy the organisation has abandoned.

Why A is wrong: Freezing the register feels cautious during change, but it lets the approach drift out of step with a strategy whose risk profile is shifting right now.

Why B is correct: A new strategic direction changes what the organisation is willing to accept, so revisiting appetite and tolerance keeps the risk approach matched to the objectives the board has just set.

Why C is wrong: More frequent scanning is a sound technical control and sounds proactive, yet it addresses operational hygiene rather than realigning the approach with the new strategy.

Why D is wrong: Local delegation can speed decisions and seems pragmatic, but handing off without realigned appetite breaks the link between enterprise strategy and risk choices.

Free sampleGovernancemedium

Senior management complains that the IT risk function operates in isolation and rarely informs strategic planning. Which change would best embed the risk management approach within the organisation's strategy and objectives?

  • ASchedule additional technical risk workshops for the IT operations team each quarter
  • BRequire the risk team to produce a longer, more detailed monthly risk report
  • CEmbed the risk practitioner in the strategic planning cycle so risk input shapes objectives as they are set Correct
  • DMove the risk function to report directly to the chief information officer instead
Integration with strategy is achieved by placing risk input inside the planning cycle so it shapes objectives as they form. Alignment is structural, not cosmetic, so embedding risk input where objectives are actually decided ensures strategy and risk are weighed together rather than risk being bolted on once the plan is fixed.

Why A is wrong: More technical workshops build operational skill and look constructive, but they deepen the silo rather than connecting risk activity to strategic planning.

Why B is wrong: A richer report seems like better communication, yet adding length without a seat at the planning table still leaves risk reacting after strategy is set.

Why C is correct: Bringing the risk practitioner into the planning cycle lets risk considerations inform objectives while they are being formed, which integrates the approach with strategy at source.

Why D is wrong: Changing the reporting line may raise the function's profile and feels decisive, but it does not by itself bring risk insight into strategic decision making.

Risk Assessment (22% of the exam)

Free sampleRisk Assessmentmedium

A risk practitioner is documenting an IT risk scenario for a customer-facing payment service. Which combination of components makes the scenario most useful for analysis and response?

  • AA list of every control currently operating on the payment platform and its last test date
  • BA detailed network diagram of the payment platform and the data flows between each hosted component
  • CA summary of past audit findings raised against the payment service over the previous three years
  • DA threat actor, the event, the affected asset and the resulting business loss consequence Correct
A usable IT risk scenario binds a threat actor, an event, an affected asset and a loss consequence together. Risk scenarios become analysable only when they connect who or what triggers the event, the asset affected and the business consequence, because likelihood and impact estimates depend on all four elements being present.

Why A is wrong: Cataloguing existing controls describes the current state but omits the threat, event and consequence, so it cannot frame what could go wrong or how badly.

Why B is wrong: An architecture diagram supports analysis but is an input, not a scenario, because on its own it states no event, no actor and no loss outcome.

Why C is wrong: Prior findings are useful history but describe known weaknesses, not a forward-looking event with an actor and a quantifiable loss consequence.

Why D is correct: A complete scenario links actor, event, asset and consequence, giving analysts enough context to estimate likelihood and impact and to design a proportionate response.

Free sampleRisk Assessmentmedium

When pairing threats and vulnerabilities to build a credible risk scenario, which condition must hold for the scenario to represent a genuine exposure rather than a theoretical one?

  • AA capable threat must be able to act on a vulnerability that exposes an asset of value Correct
  • BThe vulnerability must have been formally accepted by the asset owner during the last review cycle
  • CThe threat must already have caused a recorded incident somewhere within the same industry sector
  • DThe vulnerability must be tied to an asset that the organisation has classified as critical to operations
Genuine exposure requires a capable threat able to exploit a real vulnerability affecting an asset of value. Threat-vulnerability pairing produces real risk only when a threat with capability meets an exploitable weakness on a valued asset, because absence of any of these three breaks the chain from cause to consequence.

Why A is correct: Exposure is genuine only when a capable threat can exploit an actual vulnerability affecting something of value; remove any element and the scenario is theoretical.

Why B is wrong: Formal acceptance is a treatment decision recorded after assessment; it does not determine whether the threat-vulnerability pair creates a real exposure in the first place.

Why C is wrong: A prior sector incident raises plausibility but is not required, because credible exposure can exist for a threat that has not yet materialised in the sector.

Why D is wrong: Criticality affects impact and prioritisation, yet a non-critical asset can still face a real exposure, so this is not the defining condition for a genuine pairing.

Free sampleRisk Assessmentmedium

An organisation wants its IT risk scenarios to reflect what matters most to the business and to stay aligned with strategic objectives. Which scenario development approach best supports this aim?

  • AA bottom-up approach that builds scenarios solely from the current technical vulnerability register
  • BA top-down approach that derives scenarios from business objectives and the impact on them Correct
  • CAn external approach that adopts the published scenario catalogue of a peer organisation wholesale
  • DA historical approach that reuses last year's scenarios without revisiting the strategic objectives
A top-down approach derives risk scenarios from business objectives so the assessment stays aligned with strategy. Top-down scenario development anchors each scenario in a business objective and the impact on it, which keeps the resulting risk picture relevant to leadership priorities and aids consistent prioritisation.

Why A is wrong: A purely bottom-up technical view surfaces weaknesses but can miss strategic exposures and risks flooding the register with low-relevance scenarios.

Why B is correct: Starting from business objectives ensures scenarios trace to outcomes leadership cares about, keeping the assessment aligned with strategy and supporting prioritisation.

Why C is wrong: Reusing a peer catalogue is a tempting shortcut but ignores the organisation's own objectives and context, so the scenarios may not reflect what truly matters.

Why D is wrong: Reusing prior scenarios is efficient yet leaves them stale when objectives shift, so alignment with current strategy is not preserved over time.

Information Technology and Security (20% of the exam)

Free sampleInformation Technology and Securitymedium

A business unit at a retail bank wants to procure a specialist analytics platform that duplicates capabilities already provided by an existing enterprise data warehouse. A risk practitioner is asked how the enterprise architecture function should be used to manage the IT risk this decision creates. What is the most appropriate role for enterprise architecture here?

  • AUse the architecture review to assess the proposed platform against the target-state architecture and surface the redundancy and integration risk before approval. Correct
  • BLet the business unit procure the platform first and ask the architecture function to document it in the repository once it has been deployed into production.
  • CDefer entirely to the business unit because tool selection is a local operational matter that sits outside the remit of the enterprise architecture function.
  • DEscalate the request straight to the audit committee so an independent review can decide whether the analytics platform should be purchased at all.
Enterprise architecture review evaluates proposals against the target-state architecture to surface duplication and integration risk before approval. Enterprise architecture manages technology risk by comparing each proposed change to the agreed target state. Reviewing the analytics platform against that target reveals redundancy with the warehouse and the integration burden, allowing the risk to be addressed before the purchase rather than after deployment.

Why A is correct: Architecture review checks a proposal against the agreed target state, which is exactly where duplication and integration risk are caught before money is committed and the estate fragments.

Why B is wrong: Recording a tool after deployment keeps the repository current, but it does nothing to manage the risk of the purchase itself and locks in the redundancy the practitioner was asked about.

Why C is wrong: Treating selection as purely local is tempting for autonomy, but it ignores that overlapping platforms raise enterprise integration and cost risk that architecture exists to govern.

Why D is wrong: Audit-committee escalation sounds rigorous, but it bypasses the architecture review that is the correct first-line mechanism and is disproportionate to a routine procurement decision.

Free sampleInformation Technology and Securitymedium

A manufacturer's current technology stack relies on a database engine whose vendor has announced an end-of-support date eighteen months away. A risk practitioner is mapping how this single architectural fact affects IT risk across the estate. Which consequence of the impending end of support most directly increases risk for the enterprise?

  • AThe vendor will stop answering operational support tickets, so the team must resolve routine configuration and tuning issues without the supplier's help desk after the cut-off.
  • BSecurity patches will cease after the end-of-support date, leaving any newly discovered vulnerabilities in the engine permanently unremediated across every dependent system. Correct
  • CThe licensing cost of the database engine is likely to fall once the vendor stops actively marketing the now-superseded product to new and existing enterprise customers.
  • DThe vendor will probably extend support indefinitely because too many large customers still depend on the engine for critical regulated and revenue-generating workloads.
An end-of-support technology stack component stops receiving patches, leaving future vulnerabilities permanently unremediated and raising IT risk. The defining risk of an unsupported component is that the vendor no longer releases security patches. After the end-of-support date, any vulnerability discovered in the database engine stays open indefinitely, so the architectural fact translates directly into growing exposure across every system that depends on it.

Why A is wrong: Losing operational help-desk support is a real consequence and tempting because it follows from the announcement, but it is an availability and supportability concern that does not match the direct security exposure the practitioner is mapping.

Why B is correct: End of support means the vendor stops issuing patches, so future vulnerabilities in the engine cannot be fixed, which is the direct and material increase in IT risk.

Why C is wrong: A possible price drop is a commercial detail that could even feel reassuring, but it does not describe a risk and ignores the security exposure that the end of support creates for the estate.

Why D is wrong: Assuming an indefinite extension is wishful and unsupported by the published announcement, so relying on it leaves the genuine end-of-support exposure unidentified and unmanaged.

Free sampleInformation Technology and Securitymedium

An insurer has grown by acquisition and now holds customer records in several independent systems, each with its own definition of a customer identifier and address format. A risk practitioner is assessing the IT risk arising from this data architecture. Which architectural weakness should the practitioner identify as the primary driver of risk?

  • AThe systems duplicate the same customer across separate databases, so storage costs rise and queries slow, which is the chief architectural risk the practitioner should record.
  • BThe independent systems each apply their own encryption and access controls, so confidentiality protection is uneven and this is the leading data-architecture risk to flag.
  • CThe absence of a consistent data model and authoritative source means the same customer can be represented inconsistently, undermining reporting and control reliability. Correct
  • DReconciling the systems demands point-to-point integration interfaces whose ongoing maintenance burden is the primary architectural risk the practitioner should highlight.
Fragmented data architecture without a common model and authoritative source produces inconsistent records that undermine reporting and control reliability. Sound data architecture relies on a shared data model and an authoritative system of record. When acquired systems define the customer differently and none is authoritative, the same person appears inconsistently, so reports and controls built on that data become unreliable, which is the primary source of risk.

Why A is wrong: Duplicated storage and slower queries are real consequences of redundant data, which makes this tempting, but they are cost and performance symptoms rather than the integrity flaw that drives unreliable reporting and controls.

Why B is wrong: Uneven encryption and access controls are a genuine post-acquisition security gap, so the option is plausible, but it concerns confidentiality of the data, not the inconsistent customer representation that undermines reporting accuracy here.

Why C is correct: Without a shared data model and a system of record, the same customer is described differently across systems, which corrupts reporting and weakens any control that depends on reliable data.

Why D is wrong: Brittle point-to-point integration is a real architectural burden that tempts candidates, yet the maintenance effort is a delivery and availability concern, not the underlying data-consistency weakness that corrupts customer records and controls.

Want the full bank?

290 CRISC questions, every one with a worked explanation and a per-option rationale. No sign-up to start.

Practise CRISC free

Frequently asked questions

Are these CRISC practice questions free?

Yes. Every CRISC question on this page is free to read with no sign-up, and each one carries a worked explanation and a rationale for every option. The full bank of 290 questions is on Examworthy.

Do the questions explain why the wrong answers are wrong?

Yes, and that is the point. Each option, correct or not, has its own rationale, so you learn to rule out the tempting wrong answer, not just recognise the right one. That is the reasoning the CRISC tests.

Are these real CRISC exam questions?

No. These are original, blueprint-aligned practice questions written to the public ISACA content outline. We never reproduce live exam items. They mirror the format and difficulty of the real exam.

How many questions are on the real CRISC?

The CRISC is 150 questions in 240 minutes, with a pass mark of 450 / 800. For the full domain-by-domain breakdown and a study plan, read the study guide.

Examworthy is not affiliated with or endorsed by ISACA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CRISC and related marks belong to their respective owners.