Certified in Risk and Information Systems
Control (CRISC) Practice Test Exam
1. Which statement best describes the primary purpose of the
CRISC certification?
A) To certify proficiency in penetration testing and vulnerability
assessment
B) To validate expertise in identifying, evaluating, and managing
information systems and technology risk
C) To demonstrate mastery of database administration and SQL
optimization
D) To certify network engineering skills for enterprise routing
and switching
Correct Answer: B
Rationale: The CRISC certification demonstrates to employers
that the holder is able to identify, evaluate, and manage
information systems and technology risk, and help enterprises
achieve their business objectives .
,2. What is the approximate percentage weighting of Domain 3,
Risk Response and Reporting, on the current CRISC exam?
A) 20 percent
B) 22 percent
C) 26 percent
D) 32 percent
Correct Answer: D
Rationale: According to the ISACA exam content outline,
Domain 3, Risk Response and Reporting, carries the highest
weighting at 32 percent, followed by Governance at 26 percent,
Risk Assessment at 22 percent, and Technology and Security at
20 percent .
3. In CRISC terminology, what does risk appetite represent?
A) The maximum loss an organization can absorb without failing
B) The amount and type of risk an organization is willing to
pursue or retain
C) The level of risk remaining after controls are applied
,D) The total number of identified risks in the risk register
Correct Answer: B
Rationale: Risk appetite is the amount and type of risk an
organization is willing to pursue or retain. Risk tolerance refers
to the acceptable variation around that appetite .
4. A risk practitioner is analyzing the difference between
inherent risk and residual risk. Which statement correctly
describes residual risk?
A) Residual risk is the risk that exists before any controls are
implemented
B) Residual risk is the risk that remains after controls have been
applied
C) Residual risk is always greater than inherent risk
D) Residual risk is the same as control risk
Correct Answer: B
, Rationale: Inherent risk is the risk level before controls, while
residual risk is the risk that remains after controls have been
applied to mitigate the threat .
5. An organization discovers a vulnerability in a public-facing
web server. The security team decides to apply a vendor patch
immediately. Which risk response option does this represent?
A) Risk avoidance
B) Risk acceptance
C) Risk mitigation
D) Risk transfer
Correct Answer: C
Rationale: Risk mitigation involves taking actions to reduce the
likelihood or impact of a risk. Applying a patch reduces the
vulnerability, which is a mitigation strategy. Avoidance would
mean discontinuing the activity entirely, and transfer would
involve shifting the risk to a third party .
Control (CRISC) Practice Test Exam
1. Which statement best describes the primary purpose of the
CRISC certification?
A) To certify proficiency in penetration testing and vulnerability
assessment
B) To validate expertise in identifying, evaluating, and managing
information systems and technology risk
C) To demonstrate mastery of database administration and SQL
optimization
D) To certify network engineering skills for enterprise routing
and switching
Correct Answer: B
Rationale: The CRISC certification demonstrates to employers
that the holder is able to identify, evaluate, and manage
information systems and technology risk, and help enterprises
achieve their business objectives .
,2. What is the approximate percentage weighting of Domain 3,
Risk Response and Reporting, on the current CRISC exam?
A) 20 percent
B) 22 percent
C) 26 percent
D) 32 percent
Correct Answer: D
Rationale: According to the ISACA exam content outline,
Domain 3, Risk Response and Reporting, carries the highest
weighting at 32 percent, followed by Governance at 26 percent,
Risk Assessment at 22 percent, and Technology and Security at
20 percent .
3. In CRISC terminology, what does risk appetite represent?
A) The maximum loss an organization can absorb without failing
B) The amount and type of risk an organization is willing to
pursue or retain
C) The level of risk remaining after controls are applied
,D) The total number of identified risks in the risk register
Correct Answer: B
Rationale: Risk appetite is the amount and type of risk an
organization is willing to pursue or retain. Risk tolerance refers
to the acceptable variation around that appetite .
4. A risk practitioner is analyzing the difference between
inherent risk and residual risk. Which statement correctly
describes residual risk?
A) Residual risk is the risk that exists before any controls are
implemented
B) Residual risk is the risk that remains after controls have been
applied
C) Residual risk is always greater than inherent risk
D) Residual risk is the same as control risk
Correct Answer: B
, Rationale: Inherent risk is the risk level before controls, while
residual risk is the risk that remains after controls have been
applied to mitigate the threat .
5. An organization discovers a vulnerability in a public-facing
web server. The security team decides to apply a vendor patch
immediately. Which risk response option does this represent?
A) Risk avoidance
B) Risk acceptance
C) Risk mitigation
D) Risk transfer
Correct Answer: C
Rationale: Risk mitigation involves taking actions to reduce the
likelihood or impact of a risk. Applying a patch reduces the
vulnerability, which is a mitigation strategy. Avoidance would
mean discontinuing the activity entirely, and transfer would
involve shifting the risk to a third party .