Skip to content

CRISC Practice Questions

Prepare for CRISC with more than an answer.

1,093 questions in the full set20 sample questionsUpdated Feb 3, 2026
Level
Professional
Valid for
3 years
Domains covered on the exam 4
  1. Governance26%
  2. IT Risk Assessment20%
  3. Risk Response and Reporting32%
  4. Information Technology and Security22%
  1. 1

    What is the value of exposure factor if the asset is lost completely?

    Show answer details

    Correct answer: D

    D--Explanation:
    Exposure Factor represents the impact of the risk over the asset, or percentage of asset lost. For example, if the Asset Value is reduced to two third, the exposure factor value is 0.66.
    Therefore, when the asset is completely lost, the Exposure Factor is 1.0.

  2. 2

    Which of the following is the MOST effective key performance indicator (KPI) for change management?

    Show answer details

    Correct answer: B

    B

  3. 3

    Which of the following should be management’s PRIMARY consideration when approving risk response action plans?

    Show answer details

    Correct answer: B

    B

  4. 4

    Establishing an organizational code of conduct is an example of which type of control?

    Show answer details

    Correct answer: B

    B

  5. 5

    A risk practitioner is creating a report for the board of directors on the effectiveness of the control environment. The goal is to provide a high-level, aggregated view of risk that is easy to understand. Which reporting technique would be MOST effective for this purpose?

    quadrantChart title IT Risk Posture x-axis Low Impact --> High Impact y-axis Low Likelihood --> High Likelihood quadrant-1 "Monitor (Low)" quadrant-2 "Control (Medium)" quadrant-3 "Accept (Low)" quadrant-4 "Mitigate (High)" "Data Center Outage": [0.8, 0.9] "Insider Threat": [0.6, 0.7] "Phishing Attack": [0.9, 0.5] "Vendor Failure": [0.4, 0.8] "Minor Bug Exploit": [0.3, 0.2]
    Show answer details

    Correct answer: B

    A risk heat map (like the quadrant chart shown) is an ideal tool for communicating complex risk information to a senior, non-technical audience like a board of directors. It provides a quick, visual summary of the most significant risks based on their likelihood and impact, allowing for easy prioritization and discussion. A detailed list of deficiencies, KRI data, or the full risk register would be too granular and less effective for a strategic overview.

  6. 6

    Which of the following is the way to verify control effectiveness?

    Show answer details

    Correct answer: A

    A--Explanation:
    Control effectiveness requires a process to verify that the control process worked as intended and meets the intended control objectives.
    Hence the test result of intended objective helps in verifying effectiveness of control.

  7. 7

    Which of the following should be done FIRST when a new risk scenario has been identified?

    Show answer details

    Correct answer: D

    D

  8. 8

    Which of the following is MOST important to update when an organization’s risk appetite changes?

    Show answer details

    Correct answer: C

    C

  9. 9

    You are the risk professional of your enterprise. You need to calculate potential revenue loss if a certain risks occurs.

    Your enterprise has an electronic (e-commerce) web site that is producing US $1 million of revenue each day, then if a denial of service (DoS) attack occurs that lasts half a day creates how much loss?

    Show answer details

    Correct answer: C

    C--Explanation:
    Denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a computer resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the concerted efforts of person or persons to prevent an Internet site or service from functioning efficiently or at all, temporarily or indefinitely. Perpetrators of DoS attacks typically target sites or services hosted on high-profile web servers such as banks, credit card payment gateways, and even root name-servers. The term is generally used with regards to computer networks, but is not limited to this field; for example, it is also used in reference to CPU resource management. As the total revenue of the website for the day is $1 million, and due to denial of service attack it is unavailable for half day.
    Therefore, Revenue loss = $1,000,000/2 = $500,000

  10. 10

    You work as a Project Manager for Company Inc. You have to conduct the risk management activities for a project. Which of the following inputs will you use in the plan risk management process?
    Each correct answer represents a complete solution. (Choose three.)

    Show answer details

    Correct answer: A, C, D

    A,C,D

    A,C,D

    A,C,D

Create an account to continue.