ISACA
Free CRISC - Certified in Risk and Information Systems Control Practice Questions
The CRISC - Certified in Risk and Information Systems Control exam is up to 150 questions in 240 minutes, and the voucher costs $575. CertCrush provides 400 syllabus-aligned practice questions across all 4 exam domains, each with a full explanation. Free to try, no account required.
The Certified in Risk and Information Systems Control (CRISC) certification validates a professional's ability to identify, assess, respond to and report on enterprise IT risk, and to design and monitor the controls that keep that risk inside appetite. It is ISACA's flagship credential for risk practitioners who sit between the technology estate and the people who own the business consequences.
Practice content last updated · Independently written and aligned to ISACA’s published exam objectives.
10
Sample questions
240 min
Exam time limit
70%
Practice pass mark
$575
Exam voucher
About the CRISC - Certified in Risk and Information Systems Control Exam
CRISC is the certification for the person in the room who has to say how bad it would actually be. Where CISM is about running a security programme and CISA is about auditing controls after the fact, CRISC sits earlier in the chain: identifying IT risk, sizing it in terms a business owner recognises, choosing a response, and then proving the controls behind that response still work. ISACA aims it at risk practitioners, control owners, compliance leads and the security managers who keep being asked to quantify things. The exam is 150 multiple-choice questions in four hours, and its difficulty is not vocabulary — it is judgement. CRISC questions are overwhelmingly scenario-based and frequently ask for the BEST or FIRST action among four defensible options. Candidates who know the material still fail because they answer as a technologist rather than as a risk advisor: recommending a fix when the correct answer is to assess impact, or accepting a risk that was never theirs to accept. Domain 3, Risk Response and Reporting, carries 32% of the exam on its own, and Governance adds another 26%, so more than half the paper turns on ownership, appetite, escalation and reporting rather than on technology. The current exam content outline took effect on 3 November 2025, shifting weight toward Risk Assessment and away from Technology and Security. This course is built to that outline, with every practice question mapped to one of the four live domains so you can see exactly where your judgement is holding up and where it is not.
Exam Domains Covered
Exam Format & Details
The CRISC exam consists of 150 multiple-choice questions over a 4-hour (240-minute) time limit. There are no performance-based or simulation items — every question is multiple choice, and most are scenario-based. The passing score is 450 on a scaled range of 200-800. The exam covers four domains: Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%) and Technology and Security (20%), under the exam content outline that took effect on 3 November 2025. The exam is delivered at PSI test centres and by remote online proctoring. Registration costs $575 USD for ISACA members and $760 USD for non-members. Passing the exam is only part of certification: candidates must also submit evidence of at least three years of relevant IT risk management and IS control experience before the CRISC designation is awarded.
Why Practice Questions Matter
CRISC is not a recall exam, so re-reading a guide does a poor job of preparing you for it. Almost every question is a scenario with four plausible answers, one of which is best because of who owns the risk, what stage of the risk lifecycle you are in, or what the risk appetite already says. That instinct is built by repetition and by reading explanations of why the near-miss answer is wrong. Practising by domain also exposes the specific gap most candidates have: comfort in Technology and Security, and hesitation in Governance and in Risk Response and Reporting, which together carry 58% of the exam.
Try CRISC - Certified in Risk and Information Systems Control
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to CRISC - Certified in Risk and Information Systems Control
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CRISC - Certified in Risk and Information Systems Control exam — not actual exam content.
Q1.Which of the following BEST describes risk?
- A.Any technical weakness present in a system or process
- B.The possibility of an event that affects the achievement of an objective
- C.A problem currently affecting operations and requiring remediation
- D.The presence of a threat actor with the capability to attack the enterprise
Domain: Governance
Q2.A new customer-facing portal has been placed into production with no documented risk assessment. Which of the following should the risk practitioner do FIRST?
- A.Perform a vulnerability scan against the portal
- B.Recommend that multi-factor authentication be enabled for all portal users
- C.Report the missing assessment to the audit committee
- D.Identify the business objectives the portal is intended to support
Domain: Governance
Q3.A production database is administered using a single shared administrator password known to eight people. In ISACA terminology, the shared password is BEST described as which of the following?
- A.A threat
- B.A risk
- C.A vulnerability
- D.An event
Domain: Governance
Q4.A monitoring alert confirms that a file containing customer account details was downloaded by an unauthorised external party last week. Which of the following should the risk practitioner do FIRST?
- A.Escalate the confirmed exposure to management for remediation and tracking as an issue
- B.Perform a risk assessment to determine the likelihood of unauthorised data download
- C.Add the scenario to the risk register with a likelihood and impact rating
- D.Recommend deployment of data loss prevention tooling on the affected platform
Domain: Governance
Q5.A retailer wants to launch a mobile ordering app in twelve weeks rather than the usual nine months in order to reach the trading season. Which of the following is the BEST contribution from the risk practitioner?
- A.Recommend that the original nine-month timeline be retained to protect testing quality
- B.Escalate to the steering committee with a recommendation to halt the initiative
- C.Decline to advise until full security testing of the app has been completed
- D.Present the exposures created by the compressed timeline together with the business value at stake, so the decision is informed
Domain: Governance
CRISC - Certified in Risk and Information Systems Control guides & exam news
ISACA CRISC Explained: Domains, Cost and Is It Worth It in 2026?
A full breakdown of the ISACA CRISC certification for 2026: the four updated exam domains, cost, pass mark, experience rules, salary data and an honest verdict on whether it is worth your time and money.
ISACA CCS (Certified Cybersecurity Specialist) Explained: Domains, Cost and Is It Worth It in 2026?
ISACA has launched the Certified Cybersecurity Specialist (CCS), a new vendor-neutral entry-level cyber certification. Here are the three domains, the US$199 beta price, the 26 August application deadline, and an honest verdict on whether it beats ISC2 CC or Security+.
ISACA CGEIT Explained: Domains, Cost and Is It Worth It in 2026?
CGEIT is ISACA's IT governance certification: 150 questions, four domains and a five-year experience rule that blocks most applicants. Here is the full breakdown of the domains, the 2026 cost, the salary data and an honest verdict on whether it is worth it.
Frequently Asked Questions
What is included in the free CRISC - Certified in Risk and Information Systems Control sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CRISC - Certified in Risk and Information Systems Control course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CRISC - Certified in Risk and Information Systems Control course page.
Are these official ISACA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.
Which domains does the CRISC - Certified in Risk and Information Systems Control course cover?
The course covers 4 exam domains: Governance, Risk Assessment, Risk Response and Reporting, Technology and Security.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.