Courseiva

CRISC · topic practice

Information Technology and Security practice questions

This domain covers IT governance and risk management frameworks, including COBIT 2019, NIST CSF, and IEC 62443. It tests your ability to apply these models to real-world scenarios, such as OT security and IoT risks, ensuring you can identify controls and optimize risk in complex environments.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Information Technology and Security

What the exam tests

What to know about Information Technology and Security

You must apply governance and risk frameworks to scenarios. The most important thing is to correctly map controls to the right framework component, like using COBIT APO12 for risk optimization or IEC 62443 for OT security.

COBIT 2019 process APO12 for risk optimization

IEC 62443 security requirements for OT environments

NIST CSF Identify function components like asset management

IoT security risks in manufacturing like weak authentication

Watch out for

Common Information Technology and Security exam traps

  • ▸Confusing COBIT 2019 governance and management objectives, such as mixing APO12 with APO13.
  • ▸Assuming all IEC 62443 requirements apply equally to every OT zone, ignoring zone/conduit modeling.
  • ▸Overlooking that NIST CSF Identify includes risk assessment, not just asset inventory.

Practice set

Information Technology and Security questions

20 questions · select your answer, then reveal the explanation

A risk manager is calculating the probable financial impact of a ransomware attack using the FAIR model. Which factor is MOST critical to estimate the annual loss exposure?

A risk manager is integrating the NIST Cybersecurity Framework with the organization's risk management processes. Which TWO functions of the NIST CSF directly support risk assessment?

An organization is adopting machine learning for credit scoring decisions. Which of the following risks is MOST critical from a regulatory compliance perspective?

A risk manager is evaluating the risks associated with using a public cloud provider. Which TWO of the following are key considerations for multi-tenancy isolation? (Select TWO.)

An organization's architecture review board (ARB) is evaluating a new solution architecture. What is the PRIMARY risk management role of the ARB in this context?

An organization is evaluating cyber insurance to cover potential losses from ransomware attacks. The insurer requires that the organization have multi-factor authentication (MFA) on all remote access systems. This requirement is an example of which factor influencing insurance premiums?

A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?

An organization is reviewing its IT risk management program and identifies that the risk register is not being updated after project changes. Which TWO components of the risk management program are most likely deficient?

A financial services firm is migrating critical applications to a public cloud. The architecture review board (ARB) is evaluating the solution architecture. Which THREE risks should the ARB prioritize for review?

The risk committee is reviewing a cyber risk quantification report that uses the FAIR model. The report estimates the annualized loss expectancy (ALE) for a ransomware attack as $2.5 million. The committee asks the risk manager to explain the key components used to derive this figure. Which of the following is the MOST important factor in the FAIR model for calculating ALE?

A risk manager is assessing the risks of an IT/OT convergence project in a chemical plant. Which TWO of the following are the most significant security risks? (Select two.)

A financial institution is evaluating cyber insurance to cover potential losses from a ransomware attack. Which factor is most likely to increase the insurance premium?

An organization uses AI/ML for credit scoring decisions. The risk manager is concerned about regulatory compliance if the model cannot explain its decisions. Which AI risk is most directly addressed by requiring explainability?

Which of the following is a key component of the NIST Cybersecurity Framework's Identify function?

According to the FAIR model, which TWO of the following are primary components used to calculate probable financial impact of a cyber incident?

A risk manager is evaluating the security of a new API gateway that will expose internal microservices to external partners. The gateway will use OAuth 2.0 for authorization. Which of the following is the MOST critical risk to assess regarding the OAuth 2.0 implementation?

A risk practitioner is evaluating the security of an organization's software development lifecycle. The organization uses a CI/CD pipeline with automated deployments. Which of the following is the MOST effective control to reduce the risk of vulnerable code reaching production?

A risk manager is reviewing the organization's backup strategy for a critical database. The current strategy performs full backups weekly and differential backups daily, with no transaction log backups. The recovery point objective (RPO) is 4 hours. Which of the following is the MOST likely risk if a failure occurs 3 hours after the last differential backup?

A risk practitioner is assessing the security of a new web application that will process credit card payments. The organization must comply with PCI DSS. Which TWO of the following are core requirements of PCI DSS that directly apply to this scenario? (Choose two.)

Question 20mediummulti select
Study the full SD-WAN breakdown →

A risk practitioner is assessing the security of a new software-defined wide area network (SD-WAN) deployment that connects branch offices directly to cloud services. Which TWO of the following are the MOST significant risks introduced by this architecture? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Information Technology and Security sessions

Start a Information Technology and Security only practice session

Every question in these sessions is drawn from the Information Technology and Security domain — nothing else.

Related practice questions

Related CRISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CRISC exam test about Information Technology and Security?
You must apply governance and risk frameworks to scenarios. The most important thing is to correctly map controls to the right framework component, like using COBIT APO12 for risk optimization or IEC 62443 for OT security.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Information Technology and Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Information Technology and Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CRISC topics?
Use the topic links above to move to related areas, or go back to the CRISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CRISC exam covers. They are not copied from any real exam or dump site.