72 practice questions for ISACA IT Risk Fundamentals Certificate, with full explanations.
Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.
- 72 questions mapped to the IT Risk Fundamentals exam domains
- Answers and explanations for every question, including the wrong options
- A questions-only PDF for timed practice runs
- Instant delivery by email the moment you check out
- Free monthly updates for as long as the exam is live
- Pass or your money back
An IT Risk Fundamentals attempt costs US$175 for ISACA members and US$225 for non-members. This pack is US$39, paid once.
Try 10 questions free before you buy.
Last updated September 2026 · 72 questions
What makes the IT Risk Fundamentals hard
IT Risk Fundamentals is ISACA’s entry point to the risk track and a natural warm up for CRISC. The exam is 75 questions in two hours with a fixed 65% pass mark, taken online with a remote proctor. Because it is a certificate rather than a certification, the questions stay at the level of concepts and vocabulary, but ISACA’s vocabulary is specific and the wrong-answer options are built from it.
Risk assessment and analysis is the biggest domain at 25%: the assessment process, likelihood and impact, qualitative and quantitative analysis, risk ranking and documenting results in a risk register. Risk identification, at 20%, covers assets, threats and vulnerabilities, and building risk scenarios. Risk monitoring, reporting and communication, also 20%, covers key risk indicators and continuous monitoring.
Knowing the CRISC vocabulary in advance covers most of what this exam asks; for candidates who do not, this exam teaches it.
About the exam
The ISACA IT Risk Fundamentals Certificate exam covers risk foundations and terminology, risk governance and management, risk identification, risk assessment and analysis, risk response, and risk monitoring, reporting and communication. There are no prerequisites, no experience requirement, and the certificate does not require continuing education.
Exam domains
- Risk Intro and Overview: 5%
- Risk Governance and Management: 15%
- Risk Identification: 20%
- Risk Assessment and Analysis: 25%
- Risk Response: 15%
- Risk Monitoring, Reporting and Communication: 20%
75 multiple-choice questions, 120 minutes, pass mark 65%, US$175 for ISACA members and US$225 for non-members, online remote proctored through PSI, exam must be taken within six months of purchase, certificate does not expire.









Reviews
There are no reviews yet.