ISACA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
16% of exam · 6 sample questions below
A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?
Corrective control
Preventive control
Preventive controls block unauthorised access attempts before they reach the critical database, matching the stem's objective to prevent rather than detect. Authentication, authorisation and network filtering deny intrusion at entry, whereas detective controls only identify breaches after they occur.
Detective control
Directive control
The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?
$400,000
$250,000
The control lowers annualised loss expectancy by $400,000 ($500,000 − $100,000), then deducts the $150,000 annual cost, giving a net benefit of $250,000. This directly satisfies the stem's cost-effectiveness constraint by quantifying residual risk reduction against control expenditure.
$150,000
$350,000
A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?
Investigate the root cause of the high exception rate
A 15% exception rate signals the control is failing beyond tolerance, so the control owner must first determine why exceptions occur before remediating. Root-cause investigation identifies whether the issue is rule design, process adherence or tooling, informing corrective action.
Increase the acceptable threshold to 20%
Replace the control with a different one
Escalate to the board immediately
An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?
The patching process is effective because the KRI is still below 60 days
The KRI should be replaced with a lagging indicator
The vulnerability risk is increasing and requires management attention
The KRI has breached the 20-day risk appetite threshold, rising from 15 to 30 days, so vulnerability exposure is worsening. This trend signals that patch management controls are degrading, requiring management attention to remediate the control weakness before the risk exceeds tolerance further.
The risk is within appetite because the increase is gradual
When implementing a new access control system, which activity is essential during the change management process?
Updating the system documentation and user manuals
Updating documentation and user manuals preserves the integrity of the change record, satisfying the change management requirement for controlled, auditable transitions. This ensures users and administrators understand altered access procedures, reducing operational risk from misconfiguration. Documentation updates also provide the evidence trail auditors need to verify that the access control change was authorised, tested and communicated before deployment.
Removing all legacy controls
Assigning control ownership to external vendors
Disabling audit logs to save storage
An organization is implementing a continuous monitoring solution for its network. Which of the following is an example of continuous monitoring?
Monthly control testing by internal audit
Annual penetration testing
Quarterly access reviews
Daily automated vulnerability scanning
Daily automated vulnerability scanning repeatedly and systematically inspects network assets on a scheduled basis, generating current findings without manual intervention. This satisfies continuous monitoring's defining characteristic of ongoing automated observation, unlike one-off assessments or periodic manual reviews that capture only point-in-time snapshots.
Want more Risk Response and Reporting practice?
Practice this domain16% of exam · 6 sample questions below
After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?
Re-evaluate risk treatment options with the risk owner
Residual risk exceeding appetite means the implemented treatment proved insufficient, so the practitioner must revisit treatment with the risk owner to identify additional or alternative controls. Re-evaluating options directly addresses the gap between current residual exposure and the defined appetite before escalation or acceptance is considered.
Escalate directly to the board
Update the risk register to reflect the residual risk
Accept the residual risk
A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?
Risk avoidance by decommissioning the system
Risk transfer through cyber insurance
Risk reduction by implementing redundant systems
Redundant systems directly address the extreme downtime cost identified in the business impact analysis by eliminating single points of failure. Failover to a standby component maintains availability during hardware or service faults, reducing the probability and duration of outages. This satisfies the mitigation objective where downtime losses outweigh the cost of duplicate infrastructure.
Risk acceptance because mitigation is too costly
An organization decides to outsource its data center operations to a third party. This is an example of which risk response?
Risk reduction
Risk transfer
Outsourcing shifts the financial impact of data centre failures to the third party, satisfying the stem's need to reallocate risk ownership. Unlike risk avoidance, which eliminates the activity, or mitigation, which reduces likelihood, transfer moves the consequence to another party via contract.
Risk acceptance
Risk avoidance
During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?
Accept the risk owner's decision
Document the deficiency and move on
Communicate the risk exposure to senior management
Escalating the exposure to senior management is the first step because the risk owner's budget refusal leaves the practitioner without authority to accept or fund the risk. Senior management owns risk acceptance at the organisational level, so they must decide whether to accept, mitigate or transfer the exposure.
Escalate directly to the board
A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?
Perform a new risk assessment
Interview control owners
Review risk register updates
Conduct a control testing and audit review
Control testing and audit review examines whether the technical controls operate as designed and whether staff actually follow them, directly addressing the suspected compliance gap. It produces evidence of control effectiveness, confirming whether residual risk remains elevated because of non-adherence rather than poor control design.
Which THREE of the following are key components of an effective risk treatment plan?
Assigned responsibilities
Clear ownership ensures accountability.
Risk acceptance criteria
Defines what residual risk is acceptable.
A timeline for implementation
Deadlines drive action.
The risk owner's signature
A detailed budget
Want more Risk Response and Mitigation practice?
Practice this domainAn organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?
Eliminates subjectivity in risk assessment
Provides comparable results across organizations
Quick and easy to communicate
A 5×5 heat map plots likelihood against impact using ordinal scales, so assessors assign ratings without quantitative data or modelling. This makes results fast to produce and readily understood by executives and business stakeholders, satisfying the need to communicate IT risk posture quickly across the organisation.
Produces financially meaningful results
During an IT risk assessment, the risk practitioner calculates the inherent risk score for a critical application as 25 (on a 5×5 matrix). After evaluating control effectiveness, the residual risk score is 9. What can be inferred about the controls?
Controls are effective in reducing the risk level
Residual risk of 9 is substantially lower than the inherent risk of 25, showing the controls reduced exposure. This drop demonstrates the controls are effective, as residual risk reflects remaining risk after control effectiveness is applied to inherent risk.
Additional controls are unnecessary
Controls are not effective because residual risk remains
The inherent risk was overestimated
Which of the following is a detective control for an information system?
Data backup
Encryption
Firewall
Intrusion detection system
An intrusion detection system monitors network or host activity and raises alerts on suspicious patterns, identifying incidents after or during occurrence rather than blocking them. That monitoring-and-alerting function is detective by definition, distinguishing it from preventive controls such as firewalls or encryption.
A quantitative risk assessment for a server shows an ARO of 0.5 and SLE of $200,000. What is the ALE, and what does it imply?
ALE = $400,000; maximum possible loss
ALE = $100,000; single loss expectancy
ALE = $100,000; expected annual loss
Multiplying ARO 0.5 by SLE $200,000 yields an ALE of $100,000, representing the expected annual loss from this risk. This satisfies the stem's quantitative requirement, giving management a monetary figure to compare against control costs when prioritising remediation.
ALE = $200,000; annual cost of controls
Which risk treatment option involves eliminating the activity that creates the risk?
Accept
Transfer
Avoid
Avoidance eliminates the activity generating the risk entirely, satisfying the stem's requirement to remove the source rather than mitigate, transfer or accept it. Unlike mitigation, which reduces likelihood or impact, avoidance erases the exposure by discontinuing the underlying process, making it the only treatment that structurally removes risk at origin.
Mitigate
A risk practitioner is prioritizing IT risks for treatment. Which factor should be the PRIMARY basis for prioritization?
Ease of implementing controls
Risk level (inherent or residual)
Risk level drives prioritisation because it combines likelihood and impact into a single comparable value, whether inherent or residual. Treatment resources should target the highest-rated risks first, so this factor directly satisfies the stem's requirement to rank IT risks for remediation.
Cost of controls
Business unit manager's preference
Want more IT Risk Assessment practice?
Practice this domain26% of exam · 6 sample questions below
A company is adopting a DevSecOps approach and wants to conduct threat modeling early in the development lifecycle. Which threat modeling methodology is BEST suited for this environment due to its focus on agile and continuous integration?
TRIKE
VAST
VAST's Visual, Agile and Simple Threat modelling integrates into agile workflows and CI pipelines, producing scalable, automation-friendly outputs. This suits DevSecOps, where threat modelling must recur each sprint rather than as a one-off design-phase exercise.
STRIDE
PASTA
An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?
Operational risk
Compliance risk
Regulatory fines for breaching data protection laws arise from failing to meet legal and regulatory obligations, which is precisely the scope of compliance risk. Other categories such as operational or strategic risk do not centre on statutory penalties for non-compliance.
Financial risk
Strategic risk
A multinational corporation uses commercial threat intelligence feeds and participates in an ISAC. However, they recently missed a critical vulnerability exploited in the wild that was not in their feeds. Which additional source should they incorporate to improve vulnerability identification?
CISA KEV catalog
The CISA Known Exploited Vulnerabilities catalog lists vulnerabilities confirmed as exploited in the wild, including those absent from commercial feeds and ISAC sharing. Incorporating it closes the gap that let the exploited vulnerability go unidentified, directly addressing the missed in-the-wild exploitation described in the stem.
NVD database
OSINT from social media
Vendor advisories only
A company is developing risk scenarios for business impact analysis. Which of the following scenario components directly links the risk event to potential financial loss?
Vulnerability
Threat actor
Consequence
Consequence describes the resulting impact of a risk event materialising, quantified in financial, operational or regulatory terms. It satisfies the scenario component that directly links the event to potential financial loss, unlike cause, threat source or event description.
Asset
Which of the following is a key characteristic of a well-maintained risk register?
It is maintained solely by the IT department
It is static and reviewed annually
It is updated regularly to reflect changes
Risk registers are living documents; regular updates ensure risks, ratings and owners reflect current threats, controls and business changes. Without periodic refresh, the register becomes stale and misdirects risk treatment decisions, defeating its purpose as a decision-support tool.
It includes only high-impact risks
An organization's board has set a risk appetite statement that says: 'We accept moderate levels of operational risk but will not tolerate any compliance violations.' During risk identification, which type of risk should be given the HIGHEST priority?
Reputational risks
Compliance risks
The board's statement explicitly declares zero tolerance for compliance violations, making this the binding constraint. Unlike operational risk, where moderate exposure is accepted, any compliance breach exceeds the stated appetite, so compliance risks demand the highest prioritisation during identification.
Operational risks
Strategic risks
Want more IT Risk Identification practice?
Practice this domain22% of exam · 6 sample questions below
A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?
Vendor lock-in
Multi-tenancy isolation
Misconfiguration of access controls
In the shared responsibility model, the provider secures the cloud infrastructure while the customer configures identity and access controls. Misconfigured permissions, such as overly broad roles or public buckets, are the customer's responsibility and are frequently overlooked, exposing sensitive customer data.
Data sovereignty compliance
An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?
Increased number of malware infections
Unauthorized access to corporate financial systems
Manipulation of operational parameters leading to equipment damage
Manipulating operational parameters can drive actuators, valves or turbines beyond safe limits, producing physical destruction or safety incidents rather than mere data loss. That direct kinetic consequence outranks confidentiality or availability risks when integrating IT with OT for real-time monitoring.
Denial of service affecting IT services
A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?
Risk treatment plan
Risk register
Risk management policy
The risk management policy establishes the organisation's overall intent, scope, objectives and governance for risk, providing the mandate from which frameworks, processes and procedures are subsequently derived. Creating it first ensures all later risk activities align with approved direction.
Risk assessment methodology
A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?
Model bias
Adversarial attacks
Lack of explainability
Black-box credit scoring prevents the institution from justifying adverse decisions to regulators, breaching explainability obligations. Addressing this risk directly satisfies the compliance constraint, since undocumented model reasoning cannot be defended during supervisory review or customer appeals.
Data privacy in training
During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?
Require encryption (e.g., TLS) for the communication
TLS encrypts data in transit, directly removing the plain-text exposure over the public network that the ARB flagged. Encryption is a preventive control that reduces likelihood, which suits an architectural review where the risk is interception of credentials or sensitive payloads.
Transfer the risk to a third-party vendor
Accept the risk because the legacy system cannot be changed
Decommission the legacy system immediately
Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?
EDM01 — Ensure Governance Framework Setting and Maintenance
EDM02 — Ensure Benefits Delivery
EDM04 — Ensure Resource Optimization
EDM03 — Ensure Risk Optimization
EDM03 — Ensure Risk Optimization sits in the Evaluate, Direct and Monitor domain, covering evaluation of risk appetite, direction of risk responses and monitoring of risk optimisation, exactly matching the stem's description of optimising risk through evaluation, direction and monitoring.
Want more Information Technology and Security practice?
Practice this domainThe CRISC exam has 150 questions and must be completed in 240 minutes. The passing score is 450/1000.
Scenario questions on IT risk identification, assessment, response, and reporting.
The exam covers 5 domains: Risk Response and Reporting, Risk Response and Mitigation, IT Risk Assessment, IT Risk Identification, Information Technology and Security. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA CRISC exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.