ISACA · CRISC
Validates expertise in IT risk management across governance, risk assessment, risk response and reporting, and technology and security domains.
Practice Questions
761
≈ 5 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Jan 2026
Use this CRISC practice exam to prepare for Certified in Risk and Information Systems Control (CRISC) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 761 questions for ISACA CRISC, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%). Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified in Risk and Information Systems Control (CRISC) is an ISACA credential that validates a professional's expertise in enterprise IT risk management and information systems control. It is the only professional certification specifically focused on IT risk management, making it uniquely positioned among risk and security credentials. The exam covers four core domains: Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security — spanning the full lifecycle of identifying, analyzing, evaluating, and responding to IT-related business risks. The certification was updated in November 2025 to reflect evolving enterprise risk landscapes and the growing intersection of governance, technology, and cybersecurity risk.
Since its inception in 2010, more than 46,000 professionals worldwide have earned the CRISC designation. It is consistently ranked among the top-paying IT certifications globally — ISACA data places it at #4 worldwide by average compensation. Holding the CRISC demonstrates the ability to apply risk governance best practices, design and implement information system controls, and communicate risk findings to senior stakeholders and boards.
CRISC is designed for mid-to-senior-level IT and business professionals who are directly involved in managing enterprise risk. Primary target roles include IT Risk Managers, Chief Information Security Officers (CISOs), IT Auditors, Compliance Officers, Security Consultants, and Information Systems Control professionals. It is particularly relevant for those who bridge technical IT functions and executive-level governance responsibilities.
The credential suits professionals with several years of hands-on experience in risk identification, assessment, and mitigation — not entry-level candidates. Those working in financial services, healthcare, technology, consulting, or government sectors will find the certification especially aligned with regulatory and operational demands in those industries. Professionals seeking to transition from purely technical roles into risk management leadership will also benefit significantly.
ISACA does not impose formal educational prerequisites for sitting the CRISC exam. However, to achieve full certification after passing the exam, candidates must demonstrate at least three years of cumulative work experience in IT risk management and information systems control, spanning at least two of the four CRISC job practice domains. This experience must have been gained within the 10-year period preceding the certification application date. The exam result is valid for five years, giving candidates time to accumulate the required experience after passing.
While not required to register, candidates are strongly advised to have a working knowledge of enterprise risk frameworks (such as COBIT, ISO 31000, or NIST), IT governance principles, and information security fundamentals before attempting the exam. Familiarity with risk assessment methodologies, control design concepts, and regulatory compliance environments will significantly ease preparation.
The CRISC exam consists of 150 scored multiple-choice questions administered over 240 minutes (4 hours). The exam is computer-based and can be taken at authorized PSI testing centers worldwide or via remote proctoring. All questions test practical, scenario-based judgment aligned with real-world job tasks performed by risk professionals, rather than pure memorization of definitions.
Scoring uses a scaled system ranging from 200 to 800, and the minimum passing score is 450. Exam registration is continuous — there are no fixed testing windows — and candidates can schedule their appointment as early as 48 hours after paying the registration fee. Once registered, candidates have a 12-month eligibility window to sit the exam. Registration costs US$575 for ISACA members and US$760 for non-members, plus a US$50 application processing fee upon certification.
CRISC-certified professionals command some of the highest compensation in the IT and security fields. ISACA reports an average annual salary exceeding US$151,000 for credential holders, and the certification consistently ranks in the top five globally for IT compensation. In high-demand markets such as financial services, healthcare, and government contracting — particularly in cities like New York, Washington D.C., and San Francisco — salaries can run 20–40% above average. Consulting and contract rates for CRISC holders typically range from US$50 to over US$100 per hour depending on experience.
Beyond compensation, CRISC opens doors to senior leadership roles including IT Risk Manager, CISO, Compliance Program Manager, and VP of Enterprise Risk. It is especially valued for enabling career transitions from technical IT or audit roles into governance and risk management leadership. As regulatory requirements intensify globally and organizations face growing operational, cyber, and third-party risks, demand for credentialed risk professionals continues to strengthen. CRISC differentiates candidates from those holding broader security credentials (such as CISSP or CISM) by demonstrating specialized depth in enterprise IT risk governance and control design.
5 sample questions with answers and explanations. The full bank has 761 questions, enough for 5 full-length practice exams.
Preview — answers shown1. A risk manager develops a comprehensive risk scenario for unauthorized database access. Which component is NOT required in a complete IT risk scenario? (Select one!)
Explanation
A complete IT risk scenario requires five essential components: threat actor (internal or external), threat type (malicious, accidental, failure, natural), event description, asset/resource affected, and timing considerations. Residual risk rating is calculated during risk analysis after the scenario is constructed and controls are evaluated, not during scenario development. Threat actor identification is essential to understand who might cause the event. Asset or resource affected identifies what is at risk. Timing of potential occurrence provides context about when and how long the risk might manifest.
2. A financial institution calculates the annual loss expectancy for credit card fraud. The asset value is $500,000, exposure factor is 30%, and fraud occurs twice annually on average. What is the Annual Loss Expectancy (ALE)? (Select one!)
Explanation
ALE is calculated using the formula: ALE = SLE × ARO. First calculate SLE (Single Loss Expectancy): SLE = Asset Value × Exposure Factor = $500,000 × 0.30 = $150,000. Then multiply by ARO (Annual Rate of Occurrence): ALE = $150,000 × 2 = $300,000. The $150,000 option represents only the SLE without considering annual frequency. The $500,000 option incorrectly uses the full asset value. The $1,000,000 option incorrectly multiplies the asset value by ARO without applying the exposure factor.
3. An enterprise calculates risk exposure for data center equipment loss. The server infrastructure has an asset value of $400,000, an exposure factor of 60%, and an annualized rate of occurrence of 0.1. What is the Annualized Loss Expectancy? (Select one!)
Explanation
The calculation follows the quantitative risk analysis formula. Single Loss Expectancy equals Asset Value multiplied by Exposure Factor: $400,000 times 0.60 equals $240,000. Annualized Loss Expectancy equals SLE multiplied by ARO: $240,000 times 0.1 equals $24,000 per year. This represents the expected annual monetary loss from this risk event.
4. A financial institution evaluates a new fraud detection control costing $80,000 annually. Current ALE without the control is $500,000. With the control, ALE reduces to $50,000. What is the Return on Security Investment? (Select one!)
Explanation
Return on Security Investment calculation uses the formula: (ALE before minus ALE after minus Control Cost) divided by Control Cost. This equals ($500,000 minus $50,000 minus $80,000) divided by $80,000, which equals $370,000 divided by $80,000, resulting in 4.625 or 462.5 percent. This positive ROSI indicates the control investment is financially justified, returning $4.62 for every dollar spent.
5. A manufacturing company evaluates threat severity using DREAD scoring. A vulnerability receives the following scores: Damage potential = 8, Reproducibility = 9, Exploitability = 7, Affected users = 6, Discoverability = 5. What is the overall DREAD risk rating? (Select one!)
Explanation
DREAD scoring calculates overall risk by averaging the five component scores. The calculation is: (8 + 9 + 7 + 6 + 5) divided by 5 equals 35 divided by 5 which equals 7.0. Each DREAD component is rated on a scale from 1 to 10, and the average provides the overall threat severity rating. This quantitative approach helps prioritize remediation efforts by ranking threats according to their calculated severity.
Blockchain Fundamentals Certificate
Blockchain-Fund · 599 questions
Certified Cybersecurity Operations Analyst (CCOA)
CCOA · 593 questions
Certified Data Privacy Solutions Engineer (CDPSE)
CDPSE · 749 questions
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
$17.99
One-time access to this exam