CRISC Information Technology and Security Practice Question
Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?
⚠ Common exam trap
CRISC often tests common cyber insurance exclusions, and candidates commonly pick 'ransomware attacks' or 'social engineering fraud' because they are frequently discussed in the news — the trap is that these are typically covered (with sublimits), while acts of war is the classic uninsurable exclusion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acts of war
Acts of war (and sometimes terrorism, nation-state cyber operations, or hostile acts) are a common exclusion in cyber insurance policies. Insurers exclude them because the potential for catastrophic, correlated losses across many policyholders is uninsurable. A risk manager must be aware of this exclusion because it can leave the organization without coverage for state-sponsored cyberattacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Business interruption
Why it's wrong here
Business interruption is a core covered loss in cyber policies, not a standard exclusion; insurers expect to pay for downtime caused by covered incidents. It is tempting because BI is the largest cost driver in cyber claims, so a risk manager might assume it is restricted, but that would be the case only under specific sub-limits or waiting periods.
- ✗
Ransomware attacks
Why it's wrong here
Ransomware attacks are typically covered under cyber insurance, often with sub-limits, and are not a standard exclusion; insurers instead impose conditions such as backups and MFA. It is tempting to assume exclusion because ransomware is high-severity, but that would be correct only for policies with specific ransomware exclusions or warranties.
- ✗
Social engineering fraud
Why it's wrong here
Social engineering fraud, where an employee is tricked into transferring funds or credentials, is a standard cyber insurance exclusion. It is tempting because it feels like a covered cyber loss, and it would be correct if the policy explicitly bought back that cover via endorsement.
- ✓
Acts of war
Why this is correct
Cyber insurance policies commonly exclude loss from acts of war, since such catastrophic, state-driven events are deemed uninsurable. A risk manager must recognise this exclusion because it leaves the organisation retaining that risk, requiring separate treatment within the risk register rather than assuming cover.
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.