TechNuggets Academy
CRISC

Free Certified in Risk and Information Systems Control Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$5754 exam domainsLevel Advanced2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Governance
An organization's second line risk management function has identified that a business unit is operating outside the board-approved risk appetite for credit risk, but the business unit's manager refuses to reduce exposure, citing revenue targets. Which of the following is the BEST course of action for the risk management function?
The second line of defense oversees and monitors risk but does not have direct operational authority; when a business unit breaches board-approved appetite, the correct action is to escalate to the parties who own the risk decision (senior management and the board) for resolution.
Question 2 of 12 · Domain 2: IT Risk Assessment
An organization has implemented multiple layers of security controls, including firewalls, encryption, and access reviews, to protect a critical database. Which of the following BEST describes the risk that remains after these controls have been applied?
Residual risk is the risk that remains after management has applied controls to reduce the inherent risk to an acceptable level.
Question 3 of 12 · Domain 3: Risk Response and Reporting
A retail company identified a risk of fraud in a legacy payment process used by a small, non-core business unit generating minimal revenue. The cost to implement compensating controls significantly exceeds the potential loss exposure, and the business unit head confirms operations could continue without this process entirely. Which risk response is MOST appropriate?
When an activity is not essential to the business, generates minimal value, and the cost of any control response exceeds the risk exposure, risk avoidance (eliminating the activity) is the most efficient response - the organization simply stops doing the thing that creates the risk.
Question 4 of 12 · Domain 4: Information Technology and Security
A bank's business impact analysis determines that its core transaction database can tolerate a maximum of 15 minutes of data loss but can remain unavailable for up to 4 hours before causing unacceptable harm to the business. Which combination of RPO, RTO, and backup/replication strategy BEST satisfies these requirements?
The BIA specifies RPO = 15 minutes (max tolerable data loss) and RTO = 4 hours (max tolerable downtime). Continuous/near-continuous replication meets the 15-minute RPO, while a 4-hour restoration window satisfies the RTO without over-engineering the solution.
Question 5 of 12 · Domain 1: Governance
According to the three lines model referenced in CRISC risk governance guidance, which function provides independent assurance to the board on the effectiveness of governance and risk management, without itself owning or managing risk?
Internal audit occupies the third line, providing independent and objective assurance to the board and senior management on the effectiveness of governance, risk management, and controls, without owning or managing risk itself.
Question 6 of 12 · Domain 2: IT Risk Assessment
A risk practitioner is developing risk scenarios for a new cloud migration initiative. To ensure the scenarios are both relevant to the organization's specific risk profile and comprehensive in covering generic risk events, which approach should the practitioner use?
ISACA guidance recommends combining a top-down approach (derived from business objectives and goals) with a bottom-up approach (derived from a generic list of risk scenarios/events), then validating the resulting scenarios with business process owners to ensure both relevance and comprehensiveness.
Question 7 of 12 · Domain 3: Risk Response and Reporting
During an IT risk assessment, an auditor notes that the control for reviewing privileged access logs is executed daily by the IT security team, but the ERP system to which the control applies is formally owned by the Finance department head. If the control is later found to be ineffective, who is ultimately accountable for the resulting risk exposure?
The risk owner is accountable for ensuring risk is managed to an acceptable level, even when execution of a specific control is delegated to a control owner/operator. Delegating performance of a task does not transfer accountability for the outcome.
Question 8 of 12 · Domain 4: Information Technology and Security
An organization is developing a new customer-facing loan origination application using a waterfall SDLC methodology. At which phase should the risk practitioner ensure security and risk requirements are FIRST formally incorporated into the project?
Security and risk requirements must be defined during requirements gathering and design so controls are built into the architecture from the start. This is the most cost-effective point to address risk and avoids expensive rework later in the SDLC.
Question 9 of 12 · Domain 1: Governance
The board of directors has approved a risk appetite statement indicating the organization will accept 'low' exposure to operational risk. The IT risk practitioner is defining risk tolerance levels for a new cloud migration initiative. Which statement BEST describes the relationship between risk appetite and risk tolerance in this context?
Risk tolerance defines the acceptable range of variation around the broader, board-approved risk appetite for specific objectives or initiatives, allowing operational-level flexibility while staying aligned with the enterprise-wide appetite.
Question 10 of 12 · Domain 2: IT Risk Assessment
During a business impact analysis, a risk practitioner determines that a core order-processing application can be unavailable for a maximum of 4 hours before the organization incurs unacceptable financial and reputational damage. Which term BEST describes this 4-hour value?
Maximum Tolerable Downtime (MTD) represents the maximum period a business function can be unavailable before the organization suffers unacceptable consequences; it is derived during the BIA and defines the outer boundary for recovery planning.
Question 11 of 12 · Domain 3: Risk Response and Reporting
A supply chain risk assessment reveals that a company depends on a single overseas supplier for a critical component, and geopolitical instability creates a significant risk of disruption. Switching suppliers immediately is not feasible due to lengthy product certification requirements. Which risk response is MOST appropriate?
Mitigation through supplier diversification (qualifying a second source while retaining the current supplier) reduces concentration risk over time without abruptly disrupting operations that depend on certification lead times - this is the standard treatment for single-source supply chain risk.
Question 12 of 12 · Domain 4: Information Technology and Security
A marketing department wants to collect and retain full customer purchase histories, browsing behavior, and demographic data indefinitely to support future, undefined analytics initiatives. From a data privacy risk perspective, which principle is being violated?
Data minimization requires that organizations collect and retain only the data necessary for a specific, defined purpose, and dispose of it when no longer needed. Retaining broad data indefinitely for undefined future use directly violates this principle and increases privacy and breach-impact risk.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

CRISC exam — quick answers

How much does the CRISC exam cost?

The exam fee is approximately $575 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 4 domains: Governance (26%), IT Risk Assessment (20%), Risk Response and Reporting (32%), Information Technology and Security (22%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Governance →IT Risk Assessment →Risk Response and Reporting →Information Technology and Security →