ISACA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
26% of exam · 6 sample questions below
An organization is developing its IT risk universe. Which of the following is the BEST source of information for identifying potential IT risks?
Threat intelligence feeds from ISACs
ISACs provide timely, relevant threat intelligence for the organization's sector.
Industry benchmarking reports
Results from the latest internal audit
Historical loss data from the finance department
A company is adopting a DevSecOps approach and wants to conduct threat modeling early in the development lifecycle. Which threat modeling methodology is BEST suited for this environment due to its focus on agile and continuous integration?
TRIKE
VAST
VAST is Visual, Agile, and Simple, tailored for DevSecOps.
STRIDE
PASTA
During a risk identification workshop, a risk owner proposes a scenario: 'A disgruntled employee with privileged access exfiltrates customer data to a competitor.' In the context of the ISACA risk scenario template, which element is missing if the scenario only includes the actor, threat type, event, and asset?
Timing and detection
Timing and detection are required by the ISACA template.
Business impact
Consequence
Vulnerability
An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?
Operational risk
Compliance risk
Compliance risk directly addresses regulatory and legal violations.
Financial risk
Strategic risk
A risk analyst is building a risk register. After identifying a list of risks, what is the NEXT step in the risk identification process according to ISACA best practices?
Assign risk owners
Categorize the risks
Categorization is the next logical step to organize risks.
Determine risk response
Assess the inherent risk level
A multinational corporation uses commercial threat intelligence feeds and participates in an ISAC. However, they recently missed a critical vulnerability exploited in the wild that was not in their feeds. Which additional source should they incorporate to improve vulnerability identification?
CISA KEV catalog
CISA KEV is a focused, authoritative source for known exploited vulnerabilities.
NVD database
OSINT from social media
Vendor advisories only
Want more IT Risk Identification practice?
Practice this domainAn organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?
Eliminates subjectivity in risk assessment
Provides comparable results across organizations
Quick and easy to communicate
Heat maps are simple to create and understand, facilitating communication.
Produces financially meaningful results
A company is evaluating the risk of a data breach using the FAIR framework. The threat event frequency is estimated at 10 per year, and the vulnerability is 0.2. The primary loss per event is $50,000 and secondary loss is $20,000. What is the annualized loss expectancy (ALE)?
$100,000
$140,000
Correctly computed as described.
$70,000
$1,400,000
An organization has identified a high-risk IT process that, if continued, could result in significant regulatory fines. The risk owner recommends implementing additional controls. However, the cost of controls exceeds the potential financial loss. Which risk treatment option is MOST appropriate?
Avoid the risk by discontinuing the process
Accept the risk with formal sign-off
Mitigate the risk by implementing controls
Transfer the risk through cyber insurance
Transfer is cost-effective when control costs exceed potential loss.
During an IT risk assessment, the risk practitioner calculates the inherent risk score for a critical application as 25 (on a 5×5 matrix). After evaluating control effectiveness, the residual risk score is 9. What can be inferred about the controls?
Controls are effective in reducing the risk level
Significant reduction from 25 to 9 indicates effective controls.
Additional controls are unnecessary
Controls are not effective because residual risk remains
The inherent risk was overestimated
Which of the following is a detective control for an information system?
Data backup
Encryption
Firewall
Intrusion detection system
IDS detects attacks or policy violations.
A quantitative risk assessment for a server shows an ARO of 0.5 and SLE of $200,000. What is the ALE, and what does it imply?
ALE = $400,000; maximum possible loss
ALE = $100,000; single loss expectancy
ALE = $100,000; expected annual loss
Correct calculation and interpretation.
ALE = $200,000; annual cost of controls
Want more IT Risk Assessment practice?
Practice this domain16% of exam · 6 sample questions below
A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?
Corrective control
Preventive control
Preventive controls are designed to stop an incident from occurring.
Detective control
Directive control
The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?
$400,000
$250,000
Correct: $400,000 reduction minus $150,000 cost equals $250,000 net benefit.
$150,000
$350,000
A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?
Investigate the root cause of the high exception rate
Root cause analysis is the first step to address the issue.
Increase the acceptable threshold to 20%
Replace the control with a different one
Escalate to the board immediately
An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?
The patching process is effective because the KRI is still below 60 days
The KRI should be replaced with a lagging indicator
The vulnerability risk is increasing and requires management attention
The KRI breach and trend indicate rising risk.
The risk is within appetite because the increase is gradual
When implementing a new access control system, which activity is essential during the change management process?
Updating the system documentation and user manuals
Documentation updates are a key step in change management.
Removing all legacy controls
Assigning control ownership to external vendors
Disabling audit logs to save storage
An IT risk manager is preparing a quarterly risk report for the CISO. Which type of reporting structure does this represent?
Tactical risk reporting
Quarterly to CISO/CIO is tactical.
Executive risk reporting
Operational risk reporting
Strategic risk reporting
Want more Risk Response and Reporting practice?
Practice this domain22% of exam · 6 sample questions below
A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?
Vendor lock-in
Multi-tenancy isolation
Misconfiguration of access controls
Access control misconfiguration is a leading cause of cloud data breaches and is often underestimated in the shared responsibility model.
Data sovereignty compliance
An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?
Increased number of malware infections
Unauthorized access to corporate financial systems
Manipulation of operational parameters leading to equipment damage
This can result in physical damage, safety incidents, and environmental harm, making it the highest priority.
Denial of service affecting IT services
A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?
Risk treatment plan
Risk register
Risk management policy
The policy sets the direction and framework for risk management.
Risk assessment methodology
A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?
Model bias
Adversarial attacks
Lack of explainability
Explainability is required by regulations for credit decisions; lack thereof can lead to non-compliance.
Data privacy in training
During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?
Require encryption (e.g., TLS) for the communication
Encryption mitigates the risk of data exposure effectively.
Transfer the risk to a third-party vendor
Accept the risk because the legacy system cannot be changed
Decommission the legacy system immediately
Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?
EDM01 — Ensure Governance Framework Setting and Maintenance
EDM02 — Ensure Benefits Delivery
EDM04 — Ensure Resource Optimization
EDM03 — Ensure Risk Optimization
This is the correct objective for risk optimization.
Want more Information Technology and Security practice?
Practice this domain16% of exam · 6 sample questions below
After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?
Re-evaluate risk treatment options with the risk owner
The practitioner should collaborate with the risk owner to identify additional controls or modify existing ones.
Escalate directly to the board
Update the risk register to reflect the residual risk
Accept the residual risk
A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?
Risk avoidance by decommissioning the system
Risk transfer through cyber insurance
Risk reduction by implementing redundant systems
Redundancy reduces both likelihood and impact of downtime.
Risk acceptance because mitigation is too costly
An organization decides to outsource its data center operations to a third party. This is an example of which risk response?
Risk reduction
Risk transfer
Outsourcing transfers operational risk to the third party.
Risk acceptance
Risk avoidance
During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?
Accept the risk owner's decision
Document the deficiency and move on
Communicate the risk exposure to senior management
Senior management needs to be aware of the risk and decide on additional funding.
Escalate directly to the board
A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?
Perform a new risk assessment
Interview control owners
Review risk register updates
Conduct a control testing and audit review
Testing provides direct evidence of control operation.
Which TWO of the following are effective risk mitigation strategies for reducing the likelihood of a ransomware attack?
Installing intrusion detection systems
Conducting periodic vulnerability scans
Regularly backing up critical data
Deploying network segmentation
Segmentation limits the spread of ransomware, reducing likelihood of widespread infection.
Implementing user awareness training
Training reduces the chance of users falling for phishing attacks.
Want more Risk Response and Mitigation practice?
Practice this domainThe CRISC exam has 150 questions and must be completed in 240 minutes. The passing score is 450/1000.
Scenario questions on IT risk identification, assessment, response, and reporting.
The exam covers 5 domains: IT Risk Identification, IT Risk Assessment, Risk Response and Reporting, Information Technology and Security, Risk Response and Mitigation. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA CRISC exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.