10 free ISACA CRISC practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 1,896 questions. Work through them, then open each answer to check your reasoning.
Get all 1,896 questions (US$39) · Download these 10 as a PDF
Question 1
Which of the following is the MOST important reason to maintain key risk indicators (KRIs)?
Show answer and explanation
Correct answer: D. Threats and vulnerabilities change over time
Key Risk Indicators must be maintained because the risk landscape is dynamic, threats and vulnerabilities continuously evolve due to changing business environments, technological advancements, regulatory shifts, and emerging attack vectors. Static KRIs become obsolete and fail to provide meaningful early warning signals. While timeliness and metrics refinement are important, the fundamental reason for ongoing maintenance is that risks themselves change over time, necessitating updated indicators to remain effective.
Why the other options are wrong
- A. Avoiding risk entirely is unrealistic; KRIs are designed to monitor and manage risk, not eliminate it.
- B. Fine-tuning metrics is a process detail, not the primary reason for KRI maintenance.
- C. Timeliness of reports is important but is a consequence of good KRI maintenance, not the main reason for it.
Question 2
You are the project manager of a HGT project that has recently finished the final compilation process. The project customer has signed off on the project completion and you have to do few administrative closure activities. In the project, there were several large risks that could have wrecked the project but you and your project team found some new methods to resolve the risks without affecting the project costs or project completion date.
What should you do with the risk responses that you have identified during the project's monitoring and controlling process?
Show answer and explanation

Question 3
You are the project manager of GHT project. You have identified a risk event on your project that could save $100,000 in project costs if it occurs.
Which of the following statements BEST describes this risk event?
Show answer and explanation
Correct answer: D. This risk event is an opportunity to the project and should be exploited.
A risk event that could save $100,000 is not a threat but an opportunity, a positive risk event. Opportunities are addressed with strategies such as exploit, enhance, share, accept, and escalate. Exploiting means taking action to make the opportunity certain so its benefit is realized, which is exactly what captures the $100,000 savings. Mitigation and avoidance are defensive strategies meant for threats, and acceptance is passive, so exploitation is the proactive strategy that best describes how to treat this event.
Why the other options are wrong
- A. Mitigation is a threat response strategy used to reduce negative impact, not to capture positive benefits.
- B. Acceptance is passive; it means tolerating the risk without action, which fails to actively pursue the opportunity.
- C. Avoidance eliminates risk but would prevent the opportunity from being realized, negating the potential $100,000 savings.
Question 4
You are the project manager of a large construction project. This project will last for 18 months and will cost $750,000 to complete. You are working with your project team, experts, and stakeholders to identify risks within the project before the project work begins. Management wants to know why you have scheduled so many risk identification meetings throughout the project rather than just initially during the project planning.
What is the best reason for the duplicate risk identification sessions?
Show answer and explanation
Correct answer: C. The iterative meetings allow the project manager and the risk identification participants to identify newly discovered risk events throughout the project.
Risk identification is not a one-time activity; it must be conducted iteratively throughout the project lifecycle because new risks emerge as the project progresses. Changes in project scope, environment, resources, stakeholder composition, and external factors continuously introduce previously unknown risks. Scheduling multiple risk identification sessions allows the project team to discover and address these newly identified risks before they materialize into problems. This proactive approach is essential for comprehensive risk management across all project phases.
Why the other options are wrong
- A. While stakeholder participation is valuable, increased meetings do not primarily serve this purpose, proper planning can achieve participation without repetition.
- B. Discussing risks that have already passed is retrospective analysis, not the primary reason for scheduling future risk sessions.
- D. Communicating pending risks is important but is a secondary purpose; the primary reason is identifying new risks as conditions change.
Question 5
You are the risk official in Bluewell Inc. You are supposed to prioritize several risks. A risk has a rating for occurrence, severity, and detection as 4, 5, and 6, respectively.
What Risk Priority Number (RPN) you would give to it?
Show answer and explanation
Correct answer: A. 120
The Risk Priority Number (RPN) is calculated by multiplying occurrence, severity, and detection ratings: RPN = Occurrence × Severity × Detection = 4 × 5 × 6 = 120. This multiplicative approach prioritizes risks that are likely to occur, have high impact, and are difficult to detect, all factors that elevate overall risk criticality. The RPN provides a numerical ranking tool to prioritize which risks deserve the most attention and resources in the risk management plan.
Why the other options are wrong
- B. 100 does not result from multiplying the three ratings given for this risk.
- C. 15 is simply the sum of 4, 5 and 6; the RPN formula multiplies the ratings rather than adding them.
- D. 30 is far too low and does not result from the correct multiplication of 4 × 5 × 6.
Question 6
Which of the following is the MOST important use of KRIs?
Show answer and explanation
Correct answer: B. Providing an early warning signal
The most important use of Key Risk Indicators is providing early warning signals of emerging or escalating risks before they materialize into actual problems. KRIs are forward-looking metrics designed to detect risk triggers and adverse trends in real-time, enabling management to take proactive corrective actions. This early warning capability is the fundamental value proposition of KRIs, they allow organizations to intervene before risks crystallize into incidents that impact operations, strategy, or stakeholders.
Why the other options are wrong
- A. Providing a backward-looking view describes risk reporting and incident analysis, not the forward-looking nature of KRIs.
- C. Indicating risk appetite and tolerance is a governance function, not the primary operational use of KRIs.
- D. While documentation and trend analysis are important, they are secondary uses; the primary purpose is enabling proactive early intervention.
Question 7
Which of the following role carriers will decide the Key Risk Indicator of the enterprise?
Each correct answer represents a part of the solution.
Choose two.
Show answer and explanation
Correct answer: A, B
A. Business leaders B. Senior management Key Risk Indicators are set by Business Leaders and Senior Management, who understand the strategic objectives, risk appetite, and tolerance levels of the enterprise. Business leaders define what matters most to organizational strategy, while senior management ensures alignment with enterprise governance and risk policies. These two groups work together to establish which indicators should be monitored and what thresholds constitute acceptable or unacceptable risk levels, making them the appropriate decision-makers for KRI determination.
Why the other options are wrong
- C. Human Resource departments manage personnel and organizational development, not enterprise risk indicator strategy.
- D. While the Chief Financial Officer is important for financial risk oversight, they are typically part of senior management; the question seeks the two primary role categories rather than a specific executive function.
Question 8
What are the requirements for creating risk scenarios? Each correct answer represents a part of the solution. (Choose three.)
Show answer and explanation
Correct answer: B, C, D
B. Determination of the value of business process at risk C. Potential threats and vulnerabilities that could cause loss D. Determination of the value of an asset Risk scenarios are built around what is at risk and what could harm it. Creating them requires determining the value of the business process at risk, identifying the potential threats and vulnerabilities that could cause loss, and determining the value of the assets involved. Together these elements establish the exposure to be protected and the credible events that could trigger a loss, which is what makes a scenario realistic and measurable for analysis and response planning.
Why the other options are wrong
- A. Cause and effect relationships are worked out when the scenario is analyzed and its impact assessed; they are not a required input for constructing the scenario itself.
Question 9
You work as the project manager for Bluewell Inc. Your project has several risks that will affect several stakeholder requirements.
Which project management plan will define who will be available to share information on the project risks?
Show answer and explanation
Correct answer: D. Communications Management Plan
The communications management plan documents stakeholder information needs and requirements: who needs what information, when they need it, in what format, and who is responsible for providing and receiving it. When several risks will affect multiple stakeholder requirements, this plan is the document that identifies which people are available and designated to share risk information with each stakeholder group.
Why the other options are wrong
- A. The resource management plan covers acquiring, developing and releasing team and physical resources, not who shares project information.
- B. The risk management plan describes how risk management will be conducted (methodology, roles for risk activities, categories, thresholds), not the detailed communication channels and who shares information with stakeholders.
- C. The stakeholder management strategy analyzes stakeholder interest, influence and engagement approaches, but the specific communication assignments come from the communications plan.
Question 10
Which of the following controls is an example of non-technical controls?
Show answer and explanation
Correct answer: B. Physical security
Physical security is a non-technical control that involves physical measures like locks, surveillance cameras, access cards, and facility design to protect assets and information. Access control, intrusion detection systems, and encryption are all technical controls that rely on technology and systems to implement security measures.
Why the other options are wrong
- A. Access control is a technical control implemented through systems, permissions, and authentication mechanisms.
- C. Intrusion detection system is a technical control that uses technology to monitor and detect unauthorized access.
- D. Encryption is a technical control that uses algorithms and cryptographic methods to protect data.
That was 10 of 1,896.
The full ISACA CRISC pack has all 1,896 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
