Free ISACA IT Risk Fundamentals practice questions

10 free ISACA IT Risk Fundamentals practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 72 questions. Work through them, then open each answer to check your reasoning.

Question 1

Which of the following is considered an exploit event?

  1. Any event that is verified as a security breach
  2. The actual occurrence of an adverse event
  3. An attacker takes advantage of a vulnerability
Show answer and explanation

Correct answer: C. An attacker takes advantage of a vulnerability

An exploit event occurs when an attacker actively takes advantage of a vulnerability to cause harm or gain unauthorized access. Option A is incorrect because an exploit is an action, not merely a verified breach; a breach could result from an exploit but the exploit itself is the act of leveraging the vulnerability. Option B is too broad and vague; it could describe any adverse event rather than specifically an exploit.

Why the other options are wrong

  • A. This describes verification of a breach outcome, not the act of exploiting a vulnerability.
  • B. This is too general and does not specifically describe the action of leveraging a vulnerability.

Question 2

Of the following, which stakeholder group is MOST often responsible for risk governance?

  1. Board of directors
  2. Enterprise risk management (ERM)
  3. Business units
Show answer and explanation

Correct answer: A. Board of directors

The board of directors holds the highest governance responsibility within an organization and is most often accountable for overall risk governance, including setting the risk appetite and ensuring risk management frameworks are in place. Option B, ERM, typically implements and manages risk processes but reports to the board. Option C, business units, are responsible for managing risks within their own operations but do not govern risk at the enterprise level.

Why the other options are wrong

  • B. ERM implements risk management but does not hold the ultimate governance authority; they report to the board.
  • C. Business units manage operational risks within their domains but do not exercise enterprise-wide risk governance.

Question 3

Which of the following is MOST likely to promote ethical and open communication of risk management activities at the executive level?

  1. Increasing the frequency of risk status reports
  2. Recommending risk tolerance levels to the business
  3. Expressing risk results in financial terms
Show answer and explanation

Correct answer: C. Expressing risk results in financial terms

Expressing risk results in financial terms translates risk metrics into the language executives understand best, business impact and monetary value. This creates a common framework for discussion that promotes ethical and open communication because stakeholders can directly relate risk to business objectives and financial outcomes. Option A increases frequency without necessarily improving quality or understanding. Option B recommends tolerance levels but does not directly address communication promotion.

Why the other options are wrong

  • A. Increasing report frequency alone does not ensure the communication is more ethical, open, or better understood without improving the substance or language of those reports.
  • B. Recommending tolerance levels is part of governance but does not directly promote ethical and open communication at the executive level.

Question 4

Which of the following presents the GREATEST risk for the continued existence of an enterprise?

  1. When its risk appetite and tolerance are reviewed annually
  2. When its actual risk eventually exceeds organizational risk appetite
  3. When its risk appetite and actual risk exceed its risk capacity
Show answer and explanation

Correct answer: C. When its risk appetite and actual risk exceed its risk capacity

capacity The greatest existential risk to an enterprise occurs when both actual risk and risk appetite exceed the organization's risk capacity, the maximum risk it can absorb without compromising survival. This represents a breakdown at the foundational level of risk management. Option A indicates a normal governance review cycle. Option B describes a situation where appetite is exceeded but capacity may still accommodate it, which is serious but not the ultimate threshold.

Why the other options are wrong

  • A. Annual reviews of risk appetite and tolerance are standard governance practices, not indicative of enterprise peril.
  • B. When actual risk exceeds appetite, it signals a problem requiring correction, but the enterprise may still operate within its capacity to absorb losses.

Question 5

How does an enterprise decide how much risk it is willing to take to meet its business objectives?

  1. By conducting research on industry standards for acceptable risk based on similar businesses
  2. By identifying the risk conditions of the business and the impact of the loss if these risks materialize
  3. By surveying business initiatives to determine what risks would cease their operations
Show answer and explanation

Correct answer: B. By identifying the risk conditions of the business and the impact of the loss if these risks materialize

the impact of the loss if these risks materialize An enterprise determines its risk appetite by identifying the specific risk conditions present in its business environment and analyzing the potential financial and operational impacts if those risks materialize. This analysis directly informs how much risk the organization can and should accept to achieve objectives. Option A relies on external benchmarks that may not reflect this specific enterprise's unique situation and risk profile. Option C focuses on what risks would stop operations rather than what the enterprise is willing to accept.

Why the other options are wrong

  • A. Industry standards provide context but do not account for the unique risk conditions, capacity, and strategic objectives of this specific enterprise.
  • C. Identifying risks that would cease operations is about risk capacity, not about deciding how much risk the enterprise is willing to take to meet objectives.

Question 6

In the context of enterprise risk management (ERM), what is the overall role of I&T risk management stakeholders?

  1. Stakeholders are accountable for all risk management activities within an enterprise.
  2. Stakeholders set direction and provide support for risk management practices.
  3. Stakeholders are responsible for protecting enterprise assets to achieve business objectives.
Show answer and explanation

Correct answer: B. Stakeholders set direction and provide support for risk management practices.

risk management practices. I&T risk management stakeholders set the direction for risk management practices within their domain and provide the necessary support, resources, and accountability structures for those practices to succeed. This is their primary role in the broader ERM context. Option A overstates accountability by claiming stakeholders manage all enterprise risk activities. Option C describes the collective objective of protecting assets but does not capture the specific role stakeholders play in governance and support.

Why the other options are wrong

  • A. Stakeholders do not manage all risk activities; they provide governance and support for risk management within their accountability areas.
  • C. While protecting assets is an outcome, the role of stakeholders is more specifically about setting direction and providing support for risk management practices.

Question 7

Which of the following BEST supports a risk-aware culture within an enterprise?

  1. Risk issues and negative outcomes are only shared within a department.
  2. The enterprise risk management (ERM) function manages all risk-related activities.
  3. Risk is identified, documented, and discussed to make business decisions.
Show answer and explanation

Correct answer: C. Risk is identified, documented, and discussed to make business decisions.

make business decisions. A risk-aware culture is built on the identification, documentation, and open discussion of risks across the organization to inform better business decisions. This transparency and integration of risk into decision-making processes is the hallmark of a mature risk culture. Option A restricts information sharing within departments, which contradicts an enterprise- wide risk-aware culture. Option B concentrates all activities in one function rather than distributing risk awareness across the organization.

Why the other options are wrong

  • A. Limiting risk discussion to single departments prevents the organizational awareness and cross-functional understanding necessary for a risk-aware culture.
  • B. Concentrating risk activities in one function does not support a culture where risk awareness is distributed and integrated into all business decisions.

Question 8

Which of the following is the BEST indication of a good risk culture?

  1. The enterprise places a strong emphasis on the positive and negative elements of risk.
  2. The enterprise enables discussions of risk and facts within the risk management functions.
  3. The enterprise learns from negative outcomes and treats the root cause.
Show answer and explanation

Correct answer: C. The enterprise learns from negative outcomes and treats the root cause.

treats the root cause. The best indication of a good risk culture is when an organization learns from negative outcomes and systematically addresses root causes rather than just treating symptoms. This demonstrates that the organization uses risk experiences as learning opportunities to continuously improve. Option A focuses on acknowledging both positive and negative elements but does not demonstrate learning or improvement. Option B describes discussions within risk management functions but does not necessarily indicate the broader cultural practice of learning and treating root causes.

Why the other options are wrong

  • A. Emphasizing both positive and negative elements is important but does not demonstrate the learning and corrective action that characterizes a mature risk culture.
  • B. Enabling discussions within risk functions is a component of good risk culture, but it does not indicate whether the organization actually learns and treats root causes of negative outcomes.

Question 9

Publishing I&T risk-related policies and procedures BEST enables an enterprise to:

  1. ensure regulatory compliance and adherence to risk standards.
  2. hold management accountable for risk loss events.
  3. set the overall expectations for risk management.
Show answer and explanation

Correct answer: C. set the overall expectations for risk management.

Publishing I&T risk-related policies and procedures establishes the foundational expectations and standards that govern how the organization approaches risk management across all levels. This sets the tone, defines roles and responsibilities, and communicates the organization's risk management philosophy to all stakeholders. While compliance and accountability are important outcomes, the primary benefit of publishing policies is establishing organizational expectations that guide all risk management activities.

Why the other options are wrong

  • A. Ensuring compliance is a result of following published policies, not the primary purpose of publishing them.
  • B. Accountability for loss events depends on enforcement and governance structures, not merely on publishing policies.

Question 10

Which of the following is MOST important when defining an organization’s risk scope?

  1. Understanding the impacts of the risk environment to the organization
  2. Developing a top-down approach to risk management
  3. Developing requirements for risk reporting to executive management
Show answer and explanation

Correct answer: A. Understanding the impacts of the risk environment to the organization

the organization Defining an organization's risk scope requires first understanding how the risk environment impacts the organization's ability to achieve its objectives and protect its assets. Understanding the impacts ensures that the scope is tailored to what matters most to the business rather than adopting a generic approach. This impact-based understanding drives all subsequent risk management decisions.

Why the other options are wrong

  • B. A top-down approach is a methodology for implementing risk management, not the most important aspect of defining scope.
  • C. Risk reporting requirements are a downstream output of risk scoping, not a primary input to defining scope.

That was 10 of 72.

The full ISACA IT Risk Fundamentals pack has all 72 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack