Free sampler

Try 12 free ISACA CRISC practice questions

Real exam-style questions taken word for word from the ISACA CRISC study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.

Unlock the full sampler
ISACA CRISC cover
12 questions in the PDF Taken verbatim from the book One email, no spam, unsubscribe any time

Three questions to try right now

Work each one before you open the answer. These are the same style and depth as the Certified in Risk and Information Systems Control (CRISC) exam expects.

Question 1. A key performance indicator (KPI) shows that a business process is operating below efficiency targets, yet no control deficiencies were noted during the most recent risk assessment. What should be done FIRST?

  • A. Implement new controls to close the performance gap.
  • B. Recalibrate the KPI to verify it accurately reflects the process.
  • C. Redesign the process to eliminate the inefficiency.
  • D. Re-examine the design of existing controls.
Show the answer

Answer: B. When a KPI signals a problem that is not corroborated by any observed control issues, the FIRST action is to question the indicator itself. A misconfigured threshold, incorrect baseline, or misaligned metric definition will produce false negatives or positives, leading to wasted effort. Recalibrating the KPI validates whether the signal reflects reality before any remediation is undertaken.

  • A: Adding new controls is premature when the root cause has not been confirmed. If the KPI is miscalibrated, new controls solve nothing.
  • C: Process redesign is a significant undertaking and is unjustified until the accuracy of the KPI is verified.
  • D: Re-examining control design is secondary; the assessment just found no control issues, so control design is not the logical first focus.

Question 2. Days before an acquisition closes, a significant data breach is discovered at the target company. For the acquiring organization, this situation is BEST described as which of the following?

  • A. A threat event originating in the external environment
  • B. An inherent risk tied to the target company's existing control environment
  • C. A risk event with direct implications for the acquiring organization's objectives
  • D. A security incident requiring the acquiring organization to invoke its response plan
Show the answer

Answer: C. A risk event is an occurrence that has, or could have, a negative impact on the enterprise's objectives. The data breach at the acquisition target directly threatens the value, financial terms, reputational consequences, and legal exposure of the acquisition itself, making it a risk event for the acquiring organization. The acquiring organization has not yet experienced a breach itself, but the event materially affects its objectives.

  • A: A threat event describes an action or occurrence that exploits a vulnerability to cause harm. The breach has already materialized; it is no longer merely a threat.
  • B: Inherent risk describes the level of risk before controls are applied. The breach is an actual occurrence, not a pre-control risk estimate.
  • D: A security incident classification applies within the organization that experienced the breach. The acquiring organization does not yet own the target, so invoking its own incident response plan would be premature and procedurally incorrect.

Question 3. Which of the following BEST provides an early warning that network access is not being revoked for terminated employees within the timeframe specified in the service level agreement?

  • A. Requiring multi-factor authentication for all remote access accounts
  • B. Monitoring key performance indicators for the access revocation process
  • C. Analyzing access logs for anomalous activity patterns
  • D. Revising the service level agreement to extend the revocation window
Show the answer

Answer: B. A key performance indicator (KPI) tied to the access revocation process, such as the percentage of accounts deprovisioned within the SLA window, directly measures whether the process is meeting its targets. When the KPI trends toward the threshold, it acts as an early warning that the process is failing before a terminated employee's account is identified in an audit.

  • A: MFA strengthens authentication for active accounts but does nothing to detect or prevent accounts that should have been removed from still being active.
  • C: Analyzing logs for anomalous activity identifies potential misuse after the fact. It may reveal a problem but does not provide the early, proactive warning that a performance metric provides.
  • D: Extending the SLA window lowers the standard rather than solving the performance shortfall. It does not provide any warning capability.

Unlock the full 12-question sampler

All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.

One email with the PDF. Unsubscribe any time.

What you get

The sampler is free. Here is exactly what lands in your inbox.

The 12-question PDF

Print it or work it on screen, then score yourself against the answer key.

Questions from the real book

Nothing is written for marketing. Every question is lifted from the study guide itself.

A one-time discount

A few days later we send one email with a code for the full study guide. That is the entire sequence.

ISACA CRISC cover

The full ISACA CRISC study guide

The complete guide covers the Certified in Risk and Information Systems Control (CRISC) exam objective by objective in plain English, with the full practice question bank behind these samples.

From $20.99

See the study guide   All ISACA guides