Free ISACA CRISC practice questions

10 free ISACA CRISC practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 1,896 questions. Work through them, then open each answer to check your reasoning.

Question 1

Which of the following is the MOST important reason to maintain key risk indicators (KRIs)?

  1. In order to avoid risk
  2. Complex metrics require fine-tuning
  3. Risk reports need to be timely
  4. Threats and vulnerabilities change over time
Show answer and explanation

Correct answer: D. Threats and vulnerabilities change over time

Key Risk Indicators must be maintained because the risk landscape is dynamic, threats and vulnerabilities continuously evolve due to changing business environments, technological advancements, regulatory shifts, and emerging attack vectors. Static KRIs become obsolete and fail to provide meaningful early warning signals. While timeliness and metrics refinement are important, the fundamental reason for ongoing maintenance is that risks themselves change over time, necessitating updated indicators to remain effective.

Why the other options are wrong

  • A. Avoiding risk entirely is unrealistic; KRIs are designed to monitor and manage risk, not eliminate it.
  • B. Fine-tuning metrics is a process detail, not the primary reason for KRI maintenance.
  • C. Timeliness of reports is important but is a consequence of good KRI maintenance, not the main reason for it.

Question 2

You are the project manager of a HGT project that has recently finished the final compilation process. The project customer has signed off on the project completion and you have to do few administrative closure activities. In the project, there were several large risks that could have wrecked the project but you and your project team found some new methods to resolve the risks without affecting the project costs or project completion date.

What should you do with the risk responses that you have identified during the project's monitoring and controlling process?

  1. Include the responses in the project management plan.
  2. Include the risk responses in the risk management plan.
  3. Include the risk responses in the organization's lessons learned database.
  4. Nothing. The risk responses are included in the project's risk register already. ✅Correct Answer: C, Include the risk responses in the organization's lessons learned database. During project closure and administrative activities, successful risk responses that were identified and implemented during monitoring and controlling should be captured in the organization's lessons learned database. This preserves institutional knowledge for future projects and allows the organization to benefit from the innovative methods developed to handle similar risks. While the risk register documents what happened, lessons learned capture the insights and effective practices that should inform future project management. This is a best practice for organizational learning and continuous improvement.
Show answer and explanation

Answer and explanation for question 2

Question 3

You are the project manager of GHT project. You have identified a risk event on your project that could save $100,000 in project costs if it occurs.

Which of the following statements BEST describes this risk event?

  1. This risk event should be mitigated to take advantage of the savings.
  2. This is a risk event that should be accepted because the rewards outweigh the threat to the project.
  3. This risk event should be avoided to take full advantage of the potential savings.
  4. This risk event is an opportunity to the project and should be exploited.
Show answer and explanation

Correct answer: D. This risk event is an opportunity to the project and should be exploited.

A risk event that could save $100,000 is not a threat but an opportunity, a positive risk event. Opportunities are addressed with strategies such as exploit, enhance, share, accept, and escalate. Exploiting means taking action to make the opportunity certain so its benefit is realized, which is exactly what captures the $100,000 savings. Mitigation and avoidance are defensive strategies meant for threats, and acceptance is passive, so exploitation is the proactive strategy that best describes how to treat this event.

Why the other options are wrong

  • A. Mitigation is a threat response strategy used to reduce negative impact, not to capture positive benefits.
  • B. Acceptance is passive; it means tolerating the risk without action, which fails to actively pursue the opportunity.
  • C. Avoidance eliminates risk but would prevent the opportunity from being realized, negating the potential $100,000 savings.

Question 4

You are the project manager of a large construction project. This project will last for 18 months and will cost $750,000 to complete. You are working with your project team, experts, and stakeholders to identify risks within the project before the project work begins. Management wants to know why you have scheduled so many risk identification meetings throughout the project rather than just initially during the project planning.

What is the best reason for the duplicate risk identification sessions?

  1. The iterative meetings allow all stakeholders to participate in the risk identification processes throughout the project phases.
  2. The iterative meetings allow the project manager to discuss the risk events which have passed the project and which did not happen.
  3. The iterative meetings allow the project manager and the risk identification participants to identify newly discovered risk events throughout the project.
  4. The iterative meetings allow the project manager to communicate pending risks events during project execution.
Show answer and explanation

Correct answer: C. The iterative meetings allow the project manager and the risk identification participants to identify newly discovered risk events throughout the project.

Risk identification is not a one-time activity; it must be conducted iteratively throughout the project lifecycle because new risks emerge as the project progresses. Changes in project scope, environment, resources, stakeholder composition, and external factors continuously introduce previously unknown risks. Scheduling multiple risk identification sessions allows the project team to discover and address these newly identified risks before they materialize into problems. This proactive approach is essential for comprehensive risk management across all project phases.

Why the other options are wrong

  • A. While stakeholder participation is valuable, increased meetings do not primarily serve this purpose, proper planning can achieve participation without repetition.
  • B. Discussing risks that have already passed is retrospective analysis, not the primary reason for scheduling future risk sessions.
  • D. Communicating pending risks is important but is a secondary purpose; the primary reason is identifying new risks as conditions change.

Question 5

You are the risk official in Bluewell Inc. You are supposed to prioritize several risks. A risk has a rating for occurrence, severity, and detection as 4, 5, and 6, respectively.

What Risk Priority Number (RPN) you would give to it?

  1. 120
  2. 100
  3. 15
  4. 30
Show answer and explanation

Correct answer: A. 120

The Risk Priority Number (RPN) is calculated by multiplying occurrence, severity, and detection ratings: RPN = Occurrence × Severity × Detection = 4 × 5 × 6 = 120. This multiplicative approach prioritizes risks that are likely to occur, have high impact, and are difficult to detect, all factors that elevate overall risk criticality. The RPN provides a numerical ranking tool to prioritize which risks deserve the most attention and resources in the risk management plan.

Why the other options are wrong

  • B. 100 does not result from multiplying the three ratings given for this risk.
  • C. 15 is simply the sum of 4, 5 and 6; the RPN formula multiplies the ratings rather than adding them.
  • D. 30 is far too low and does not result from the correct multiplication of 4 × 5 × 6.

Question 6

Which of the following is the MOST important use of KRIs?

  1. Providing a backward-looking view on risk events that have occurred
  2. Providing an early warning signal
  3. Providing an indication of the enterprise's risk appetite and tolerance
  4. Enabling the documentation and analysis of trends
Show answer and explanation

Correct answer: B. Providing an early warning signal

The most important use of Key Risk Indicators is providing early warning signals of emerging or escalating risks before they materialize into actual problems. KRIs are forward-looking metrics designed to detect risk triggers and adverse trends in real-time, enabling management to take proactive corrective actions. This early warning capability is the fundamental value proposition of KRIs, they allow organizations to intervene before risks crystallize into incidents that impact operations, strategy, or stakeholders.

Why the other options are wrong

  • A. Providing a backward-looking view describes risk reporting and incident analysis, not the forward-looking nature of KRIs.
  • C. Indicating risk appetite and tolerance is a governance function, not the primary operational use of KRIs.
  • D. While documentation and trend analysis are important, they are secondary uses; the primary purpose is enabling proactive early intervention.

Question 7

Which of the following role carriers will decide the Key Risk Indicator of the enterprise?

Each correct answer represents a part of the solution.

Choose two.

  1. Business leaders
  2. Senior management
  3. Human resource
  4. Chief financial officer
Show answer and explanation

Correct answer: A, B

A. Business leaders B. Senior management Key Risk Indicators are set by Business Leaders and Senior Management, who understand the strategic objectives, risk appetite, and tolerance levels of the enterprise. Business leaders define what matters most to organizational strategy, while senior management ensures alignment with enterprise governance and risk policies. These two groups work together to establish which indicators should be monitored and what thresholds constitute acceptable or unacceptable risk levels, making them the appropriate decision-makers for KRI determination.

Why the other options are wrong

  • C. Human Resource departments manage personnel and organizational development, not enterprise risk indicator strategy.
  • D. While the Chief Financial Officer is important for financial risk oversight, they are typically part of senior management; the question seeks the two primary role categories rather than a specific executive function.

Question 8

What are the requirements for creating risk scenarios? Each correct answer represents a part of the solution. (Choose three.)

  1. Determination of cause and effect
  2. Determination of the value of business process at risk
  3. Potential threats and vulnerabilities that could cause loss
  4. Determination of the value of an asset
Show answer and explanation

Correct answer: B, C, D

B. Determination of the value of business process at risk C. Potential threats and vulnerabilities that could cause loss D. Determination of the value of an asset Risk scenarios are built around what is at risk and what could harm it. Creating them requires determining the value of the business process at risk, identifying the potential threats and vulnerabilities that could cause loss, and determining the value of the assets involved. Together these elements establish the exposure to be protected and the credible events that could trigger a loss, which is what makes a scenario realistic and measurable for analysis and response planning.

Why the other options are wrong

  • A. Cause and effect relationships are worked out when the scenario is analyzed and its impact assessed; they are not a required input for constructing the scenario itself.

Question 9

You work as the project manager for Bluewell Inc. Your project has several risks that will affect several stakeholder requirements.

Which project management plan will define who will be available to share information on the project risks?

  1. Resource Management Plan
  2. Risk Management Plan
  3. Stakeholder management strategy
  4. Communications Management Plan
Show answer and explanation

Correct answer: D. Communications Management Plan

The communications management plan documents stakeholder information needs and requirements: who needs what information, when they need it, in what format, and who is responsible for providing and receiving it. When several risks will affect multiple stakeholder requirements, this plan is the document that identifies which people are available and designated to share risk information with each stakeholder group.

Why the other options are wrong

  • A. The resource management plan covers acquiring, developing and releasing team and physical resources, not who shares project information.
  • B. The risk management plan describes how risk management will be conducted (methodology, roles for risk activities, categories, thresholds), not the detailed communication channels and who shares information with stakeholders.
  • C. The stakeholder management strategy analyzes stakeholder interest, influence and engagement approaches, but the specific communication assignments come from the communications plan.

Question 10

Which of the following controls is an example of non-technical controls?

  1. Access control
  2. Physical security
  3. Intrusion detection system
  4. Encryption
Show answer and explanation

Correct answer: B. Physical security

Physical security is a non-technical control that involves physical measures like locks, surveillance cameras, access cards, and facility design to protect assets and information. Access control, intrusion detection systems, and encryption are all technical controls that rely on technology and systems to implement security measures.

Why the other options are wrong

  • A. Access control is a technical control implemented through systems, permissions, and authentication mechanisms.
  • C. Intrusion detection system is a technical control that uses technology to monitor and detect unauthorized access.
  • D. Encryption is a technical control that uses algorithms and cryptographic methods to protect data.

That was 10 of 1,896.

The full ISACA CRISC pack has all 1,896 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack