10 free, exam-style Certified in Risk and Information Systems Control (CRISC) practice questions with answers and
explanations. No signup required. Work through them below, then take the
full free CRISC practice test to study every exam domain.
These 10 free CRISC questions are organized by exam domain, so you can see how each part of the Certified in Risk and Information Systems Control blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Governance
Question 1
An organization's board sets risk appetite, management establishes risk tolerance for specific objectives, and financial analysis determines the organization cannot survive losses exceeding $50 million. Which statement CORRECTLY describes the relationship between these concepts?
- Risk tolerance > Risk appetite > Risk capacity
- Risk appetite > Risk capacity > Risk tolerance
- Risk capacity > Risk appetite > Risk tolerance
- All three concepts are equivalent and interchangeable
Show answer & explanation
Correct answer: C - Risk capacity > Risk appetite > Risk tolerance
Question 2
To maintain independence and provide objective assurance to the organization, Internal Audit (the Third Line of Defense) should report functionally to:
- The Chief Executive Officer (CEO)
- The Chief Risk Officer (CRO)
- The Board of Directors or Audit Committee
- The Chief Information Officer (CIO)
Show answer & explanation
Correct answer: C - The Board of Directors or Audit Committee
Domain 2: IT Risk Assessment
Question 3
A data center power failure would result in losses of $80,000 per incident. Historical data indicates this type of failure occurs approximately once every four years. What is the Annualized Loss Expectancy (ALE)?
- $320,000
- $80,000
- $20,000
- $40,000
Show answer & explanation
Correct answer: C - $20,000
Question 4
After implementing security controls, the residual risk for a critical system remains. To determine whether the residual risk is acceptable or requires additional treatment, it should be compared against:
- The original inherent risk level
- Industry benchmark averages
- The organization's defined risk tolerance
- The total cost of implemented controls
Show answer & explanation
Correct answer: C - The organization's defined risk tolerance
Domain 3: Risk Response and Reporting
Question 5
An organization purchases comprehensive cyber insurance and outsources its IT operations to a managed service provider with contractual SLAs. The risk manager states that operational IT risk has been fully transferred. What is the PRIMARY limitation of this assessment?
- The organization has effectively eliminated its IT operational risk
- Reputational risk and counterparty risk remain with the organization regardless of transfer mechanisms
- Risk transfer is only valid when approved by external auditors
- Insurance and outsourcing cannot be used together for risk transfer
Show answer & explanation
Correct answer: B - Reputational risk and counterparty risk remain with the organization regardless of transfer mechanisms
Question 6
The risk management team is establishing a monitoring program and must select appropriate indicators. Which statement BEST describes the fundamental difference between Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)?
- KRIs are always quantitative while KPIs can be qualitative
- KRIs provide early warning of increasing risk exposure; KPIs measure achievement of objectives after the fact
- KPIs are leading indicators while KRIs are lagging indicators
- KRIs are owned by IT while KPIs are owned by business units
Show answer & explanation
Correct answer: B - KRIs provide early warning of increasing risk exposure; KPIs measure achievement of objectives after the fact
Question 7
An organization implements Security Information and Event Management (SIEM), intrusion detection systems (IDS), and comprehensive audit logging across its environment. These controls are PRIMARILY classified as:
- Preventive controls - stopping incidents before they occur
- Detective controls - identifying incidents during or after occurrence
- Corrective controls - remediating issues after detection
- Deterrent controls - discouraging potential attackers
Show answer & explanation
Correct answer: B - Detective controls - identifying incidents during or after occurrence
Question 8
A healthcare organization stores patient records with a cloud provider that holds SOC 2 Type II certification and has signed a Business Associate Agreement. A breach at the cloud provider exposes patient data. Who is ultimately ACCOUNTABLE for the protection of the patient data under regulatory requirements?
- The cloud provider, since they had physical custody of the data
- The healthcare organization, as the data controller and owner of the patient relationship
- The external auditors who certified the cloud provider's controls
- Accountability is shared equally and cannot be assigned to one party
Show answer & explanation
Correct answer: B - The healthcare organization, as the data controller and owner of the patient relationship
Domain 4: Information Technology and Security
Question 9
The NIST Cybersecurity Framework organizes security activities into five core functions. What is the CORRECT sequence of these functions?
- Protect, Identify, Detect, Respond, Recover
- Identify, Protect, Detect, Respond, Recover
- Detect, Protect, Respond, Recover, Identify
- Respond, Recover, Identify, Protect, Detect
Show answer & explanation
Correct answer: B - Identify, Protect, Detect, Respond, Recover
Question 10
An organization is deploying a Large Language Model (LLM) to assist with customer inquiries. During risk assessment, the team identifies a risk that is UNIQUE to this type of AI technology. Which risk is MOST specific to LLM implementations?
- Distributed denial of service attacks
- SQL injection vulnerabilities in the database layer
- Hallucinations - generating plausible but incorrect or fabricated information
- Cross-site scripting in web interfaces
Show answer & explanation
Correct answer: C - Hallucinations - generating plausible but incorrect or fabricated information