CRISC Information Technology and Security Practice Question
Which THREE of the following are typical exclusions in a cyber insurance policy?
⚠ Common exam trap
CRISC often tests the misconception that ransomware and social engineering are excluded, when in fact they are commonly covered (with sub-limits), while power outages, intentional acts, and war/terrorism are the standard exclusions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Losses due to power outages without malicious intent
Option A (losses due to power outages without malicious intent) is a typical exclusion because cyber policies generally cover malicious cyber events, not non-malicious infrastructure or utility failures that cause business interruption. Option B (intentional acts by the insured) is excluded because insurance cannot cover deliberate wrongdoing or fraudulent conduct by the policyholder, as this would violate the principle of indemnity and public policy. Option D (acts of war or terrorism) is a standard exclusion found in most cyber policies, often tied to war exclusions that remove coverage for state-sponsored or warlike attacks. Option C (ransomware payments) is not a standard exclusion — many cyber policies explicitly cover ransomware, including reimbursement of ransom payments, subject to conditions. Option E (social engineering fraud) is also not a typical blanket exclusion; it is frequently offered as a covered extension or sub-limit, though it may require specific endorsement rather than being excluded outright.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Losses due to power outages without malicious intent
Why this is correct
Cyber policies typically exclude physical perils such as power outages without a malicious element, since these are property or business-interruption losses rather than cyber incidents. This exclusion satisfies the stem's requirement by removing non-malicious, non-cyber causes of loss from cover.
- ✓
Intentional acts by the insured
Why this is correct
Policies exclude intentional or fraudulent acts by the insured because insurance cannot indemnify deliberate wrongdoing; such conduct breaches the insurable-interest and fortuity principles. This exclusion satisfies the stem by removing self-inflicted losses from the scope of cover.
- ✗
Ransomware payments
Why it's wrong here
Ransomware payments are typically covered, not excluded, because insurers treat them as a covered loss under cyber extortion cover. The exclusion list instead names state-backed attacks, war, and unpatched systems. It is tempting because paying ransoms is controversial, but the question asks what policies actually exclude, not what should be excluded.
- ✓
Acts of war or terrorism
Why this is correct
War and terrorism exclusions remove catastrophic, state-sponsored or politically motivated events from cover, as insurers cannot adequately price systemic risk. This satisfies the stem by excluding losses arising from armed conflict or terrorist acts rather than cyber operations themselves.
- ✗
Social engineering fraud
Why it's wrong here
Social engineering fraud is a standard cyber policy exclusion, so it is a correct answer rather than a wrong one. Insurers exclude it because losses stem from human deception rather than a network breach, and it is often covered separately under crime or fidelity policies. It is tempting to assume all fraud is covered.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.