ISACA · IT Risk Fundamentals

ISACA IT Risk Fundamentals Exam Practice Questions

72 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 72 questions in this pack

Question 1

Which of the following is considered an exploit event?

  1. Any event that is verified as a security breach
  2. The actual occurrence of an adverse event
  3. An attacker takes advantage of a vulnerability
Show answer and explanation

Correct answer: C. An attacker takes advantage of a vulnerability

An exploit event occurs when an attacker actively takes advantage of a vulnerability to cause harm or gain unauthorized access. Option A is incorrect because an exploit is an action, not merely a verified breach; a breach could result from an exploit but the exploit itself is the act of leveraging the vulnerability. Option B is too broad and vague; it could describe any adverse event rather than specifically an exploit.

Why the other options are wrong

  • A. This describes verification of a breach outcome, not the act of exploiting a vulnerability.
  • B. This is too general and does not specifically describe the action of leveraging a vulnerability.

Question 2

Of the following, which stakeholder group is MOST often responsible for risk governance?

  1. Board of directors
  2. Enterprise risk management (ERM)
  3. Business units
Show answer and explanation

Correct answer: A. Board of directors

The board of directors holds the highest governance responsibility within an organization and is most often accountable for overall risk governance, including setting the risk appetite and ensuring risk management frameworks are in place. Option B, ERM, typically implements and manages risk processes but reports to the board. Option C, business units, are responsible for managing risks within their own operations but do not govern risk at the enterprise level.

Why the other options are wrong

  • B. ERM implements risk management but does not hold the ultimate governance authority; they report to the board.
  • C. Business units manage operational risks within their domains but do not exercise enterprise-wide risk governance.

Question 3

Which of the following is MOST likely to promote ethical and open communication of risk management activities at the executive level?

  1. Increasing the frequency of risk status reports
  2. Recommending risk tolerance levels to the business
  3. Expressing risk results in financial terms
Show answer and explanation

Correct answer: C. Expressing risk results in financial terms

Expressing risk results in financial terms translates risk metrics into the language executives understand best, business impact and monetary value. This creates a common framework for discussion that promotes ethical and open communication because stakeholders can directly relate risk to business objectives and financial outcomes. Option A increases frequency without necessarily improving quality or understanding. Option B recommends tolerance levels but does not directly address communication promotion.

Why the other options are wrong

  • A. Increasing report frequency alone does not ensure the communication is more ethical, open, or better understood without improving the substance or language of those reports.
  • B. Recommending tolerance levels is part of governance but does not directly promote ethical and open communication at the executive level.

See all 10 free questions Get the full pack, US$39

72 practice questions for ISACA IT Risk Fundamentals Certificate, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 72 questions mapped to the IT Risk Fundamentals exam domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

An IT Risk Fundamentals attempt costs US$175 for ISACA members and US$225 for non-members. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 72 questions

What makes the IT Risk Fundamentals hard

IT Risk Fundamentals is ISACA’s entry point to the risk track and a natural warm up for CRISC. The exam is 75 questions in two hours with a fixed 65% pass mark, taken online with a remote proctor. Because it is a certificate rather than a certification, the questions stay at the level of concepts and vocabulary, but ISACA’s vocabulary is specific and the wrong-answer options are built from it.

Risk assessment and analysis is the biggest domain at 25%: the assessment process, likelihood and impact, qualitative and quantitative analysis, risk ranking and documenting results in a risk register. Risk identification, at 20%, covers assets, threats and vulnerabilities, and building risk scenarios. Risk monitoring, reporting and communication, also 20%, covers key risk indicators and continuous monitoring.

Knowing the CRISC vocabulary in advance covers most of what this exam asks; for candidates who do not, this exam teaches it.

About the exam

The ISACA IT Risk Fundamentals Certificate exam covers risk foundations and terminology, risk governance and management, risk identification, risk assessment and analysis, risk response, and risk monitoring, reporting and communication. There are no prerequisites, no experience requirement, and the certificate does not require continuing education.

Exam domains

  • Risk Intro and Overview: 5%
  • Risk Governance and Management: 15%
  • Risk Identification: 20%
  • Risk Assessment and Analysis: 25%
  • Risk Response: 15%
  • Risk Monitoring, Reporting and Communication: 20%

75 multiple-choice questions, 120 minutes, pass mark 65%, US$175 for ISACA members and US$225 for non-members, online remote proctored through PSI, exam must be taken within six months of purchase, certificate does not expire.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the ISACA IT Risk Fundamentals pack?

72 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.