Courseiva

CRISC Information Technology and Security Practice Question

Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?

⚠ Common exam trap

CRISC often tests common cyber insurance exclusions, and candidates commonly pick 'ransomware attacks' or 'social engineering fraud' because they are frequently discussed in the news — the trap is that these are typically covered (with sublimits), while acts of war is the classic uninsurable exclusion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Acts of war

Acts of war (and sometimes terrorism, nation-state cyber operations, or hostile acts) are a common exclusion in cyber insurance policies. Insurers exclude them because the potential for catastrophic, correlated losses across many policyholders is uninsurable. A risk manager must be aware of this exclusion because it can leave the organization without coverage for state-sponsored cyberattacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Business interruption

    Why it's wrong here

    Business interruption is a core covered loss in cyber policies, not a standard exclusion; insurers expect to pay for downtime caused by covered incidents. It is tempting because BI is the largest cost driver in cyber claims, so a risk manager might assume it is restricted, but that would be the case only under specific sub-limits or waiting periods.

  • ✗

    Ransomware attacks

    Why it's wrong here

    Ransomware attacks are typically covered under cyber insurance, often with sub-limits, and are not a standard exclusion; insurers instead impose conditions such as backups and MFA. It is tempting to assume exclusion because ransomware is high-severity, but that would be correct only for policies with specific ransomware exclusions or warranties.

  • ✗

    Social engineering fraud

    Why it's wrong here

    Social engineering fraud, where an employee is tricked into transferring funds or credentials, is a standard cyber insurance exclusion. It is tempting because it feels like a covered cyber loss, and it would be correct if the policy explicitly bought back that cover via endorsement.

  • ✓

    Acts of war

    Why this is correct

    Cyber insurance policies commonly exclude loss from acts of war, since such catastrophic, state-driven events are deemed uninsurable. A risk manager must recognise this exclusion because it leaves the organisation retaining that risk, requiring separate treatment within the risk register rather than assuming cover.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.