In the full course
What you get
- 400 exam-style questions, each with a full explanation
- 200 flashcards, filtered by domain
- The full study guide, 24 chapters
- Timed mock exams matched to the real exam length
- A readiness score weighted by the official exam blueprint
Get full access to CRISC - Certified in Risk and Information Systems Control
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
Lifetime · all courses
$29.99
One payment · future courses included
30 seconds, then straight to checkout.
Pass, or your money back
Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.
More free samples
Marked, and passed
Real feedback from people who passed
“What I liked most was seeing my domain scores after each practice session. I knew exactly that I was weak on Access Control and could drill just that area. Passed CISA with a comfortable margin.”
“I failed my CISSP on the first attempt with another platform. Switched to CertCrush, focused on my weak domains using the tracking feature, and passed three months later. The explanations for wrong answers are genuinely useful, not just 'A is correct because A is correct'.”
“Honestly wasn't expecting much but this is probably the best ten bucks I've spent on exam prep. Did 20–30 questions every morning before work for 6 weeks. Passed with a comfortable margin. The timed exam mode is what really got me comfortable with the pressure.”
The Certified in Risk and Information Systems Control (CRISC) certification validates a professional's ability to identify, assess, respond to and report on enterprise IT risk, and to design and monitor the controls that keep that risk inside appetite. It is ISACA's flagship credential for risk practitioners who sit between the technology estate and the people who own the business consequences.
Practice content last updated · Independently written and aligned to ISACA’s published exam objectives.
About the CRISC - Certified in Risk and Information Systems Control Exam
CRISC is the certification for the person in the room who has to say how bad it would actually be. Where CISM is about running a security programme and CISA is about auditing controls after the fact, CRISC sits earlier in the chain: identifying IT risk, sizing it in terms a business owner recognises, choosing a response, and then proving the controls behind that response still work. ISACA aims it at risk practitioners, control owners, compliance leads and the security managers who keep being asked to quantify things. The exam is 150 multiple-choice questions in four hours, and its difficulty is not vocabulary — it is judgement. CRISC questions are overwhelmingly scenario-based and frequently ask for the BEST or FIRST action among four defensible options. Candidates who know the material still fail because they answer as a technologist rather than as a risk advisor: recommending a fix when the correct answer is to assess impact, or accepting a risk that was never theirs to accept. Domain 3, Risk Response and Reporting, carries 32% of the exam on its own, and Governance adds another 26%, so more than half the paper turns on ownership, appetite, escalation and reporting rather than on technology. The current exam content outline took effect on 3 November 2025, shifting weight toward Risk Assessment and away from Technology and Security. This course is built to that outline, with every practice question mapped to one of the four live domains so you can see exactly where your judgement is holding up and where it is not.
Exam Domains Covered
- Governance26%
- Risk Assessment22%
- Risk Response and Reporting32%
- Technology and Security20%
Exam Format & Details
The CRISC exam consists of 150 multiple-choice questions over a 4-hour (240-minute) time limit. There are no performance-based or simulation items — every question is multiple choice, and most are scenario-based. The passing score is 450 on a scaled range of 200-800. The exam covers four domains: Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%) and Technology and Security (20%), under the exam content outline that took effect on 3 November 2025. The exam is delivered at PSI test centres and by remote online proctoring. Registration costs $575 USD for ISACA members and $760 USD for non-members. Passing the exam is only part of certification: candidates must also submit evidence of at least three years of relevant IT risk management and IS control experience before the CRISC designation is awarded.
Why Practice Questions Matter
CRISC is not a recall exam, so re-reading a guide does a poor job of preparing you for it. Almost every question is a scenario with four plausible answers, one of which is best because of who owns the risk, what stage of the risk lifecycle you are in, or what the risk appetite already says. That instinct is built by repetition and by reading explanations of why the near-miss answer is wrong. Practising by domain also exposes the specific gap most candidates have: comfort in Technology and Security, and hesitation in Governance and in Risk Response and Reporting, which together carry 58% of the exam.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CRISC - Certified in Risk and Information Systems Control exam, not actual exam content.
Q1.A hospital is designing controls across the data lifecycle for a new patient records system. Which activity at the create stage has the GREATEST influence on the effectiveness of every later control?
- A.Assigning a classification and a named data owner
- B.Encrypting the underlying storage volumes
- C.Setting the backup frequency for the database
- D.Designing the database index structure for performance
Domain: Technology and Security
Q2.A key risk indicator for third-party access has crossed the defined tolerance threshold and now sits outside stated appetite. What is the MOST appropriate action?
- A.Adjust the threshold so the indicator returns inside the acceptable band
- B.Wait for the next reporting cycle to confirm the reading is not an anomaly
- C.Escalate the breach with the position and response options for decision
- D.Select and implement the most effective mitigating control immediately
Domain: Risk Response and Reporting
Q3.Residual risk for a business-critical process sits above appetite, no affordable control is available, and the activity is essential to strategy. What should the risk practitioner do FIRST?
- A.Recommend avoiding the risk by discontinuing the process
- B.Escalate for a formal senior-level acceptance decision with defined monitoring
- C.Implement the most effective control available and report the residual position as resolved
- D.Request that the board raise risk appetite so the exposure falls within it
Domain: Risk Response and Reporting
Q4.A risk assessment has already established the likelihood and impact of a prolonged data centre outage. Management now wants to know how quickly the absence of each affected process becomes intolerable and what each hour of downtime costs. Which activity BEST provides this?
- A.A business impact analysis
- B.A repeat quantitative risk analysis using updated annualised loss expectancy figures
- C.A threat assessment of the causes of data centre outages
- D.A control self-assessment of the data centre resilience controls
Domain: Risk Assessment
Q5.An organisation responds to an internal capacity risk by outsourcing the affected service to a specialist provider. What should the practitioner ensure is addressed as a result of this decision?
- A.The inherent risk rating of the original capacity issue is recalculated
- B.The secondary risk created by the outsourcing arrangement is identified and owned
- C.The original risk register entry is closed now that the service has moved
- D.Insurance is purchased to cover potential provider failure
Domain: Risk Response and Reporting
Q6.A newly identified risk relating to a customer data platform has been described clearly, but no business owner has been named. What should the risk practitioner do FIRST?
- A.Perform the impact assessment so the risk can be prioritised
- B.Identify and confirm the business risk owner
- C.Assign ownership to the IT platform team who operate the system
- D.Report the risk in the next monthly risk report and request an owner
Domain: Risk Assessment
Q7.A third-party supplier presents a current certificate against a recognised information security management standard and asks that the planned security assessment be waived. Which conclusion is MOST accurate?
- A.The certificate is sufficient, since the standard is more rigorous than an internal assessment
- B.The certificate carries no assurance value and should be disregarded
- C.The certificate confirms requirements were met in a defined scope at a point in time and does not confirm the relevant risk is managed
- D.The certificate demonstrates that residual risk in the supplied services has been reduced to zero
Domain: Governance
Q8.A company outsources payroll processing to a bureau, and the contract makes the bureau liable for processing errors. Which statement about this arrangement is MOST accurate?
- A.Accountability for payroll data protection remains with the organisation
- B.Contractual liability transfers accountability for the outcome to the bureau
- C.The payroll risk can be removed from the risk register once the contract is signed
- D.Outsourcing eliminates the organisation's exposure to payroll processing failure
Domain: Risk Response and Reporting
Q9.A register entry describes the scenario clearly, carries a current rating, lists existing controls and has a review date, but no named individual is recorded against it. What should the practitioner do FIRST?
- A.Validate the current rating with the assessment team
- B.Identify and assign a named business risk owner for the entry
- C.Escalate the entry to the risk committee for a decision
- D.Review the listed controls to confirm they are operating as designed
Domain: Risk Assessment
Q10.Testing of a correctly designed dual-approval control finds that 11 of 40 sampled payments were approved by the person who raised them, because a shared deputy login was used while the manager was on leave. What is the BEST remediation?
- A.Redesign the control by lowering the approval threshold
- B.Formally accept the residual risk pending the next system upgrade
- C.Implement individual credentials and a documented delegation of authority process, and enforce segregation in the system
- D.Remove the dual approval requirement because it is not being followed
Domain: Risk Response and Reporting
CRISC - Certified in Risk and Information Systems Control guides & exam news
How to Pass the ISACA CRISC Exam in 2026: A 12-Week Study Plan for the Updated Job Practice
The CRISC exam is 150 questions in four hours, scored 200 to 800, and you need 450 to pass. Here is a 12-week study plan built around the job practice that took effect on 3 November 2025, plus the answering technique that decides most results.
Best GRC Certifications in 2026: CGRC vs CRISC vs CISA vs CISM (And Which One to Take First)
Four credentials dominate governance, risk and compliance hiring, and three of them will block you at the application stage if you lack the years. Here is what each GRC certification actually costs, what it tests, and the order to take them in.
ISACA CRISC Explained: Domains, Cost and Is It Worth It in 2026?
A full breakdown of the ISACA CRISC certification for 2026: the four updated exam domains, cost, pass mark, experience rules, salary data and an honest verdict on whether it is worth your time and money.
ISACA CISA Practice Questions: 25 Exam-Style Examples With Answers and Explanations (2026)
Twenty-five CISA practice questions written to the real domain weightings, with the reasoning behind every answer. Covers all five job practice domains, plus the exam format, pass mark and the auditor mindset ISACA actually tests.
Frequently Asked Questions
What is included in the free CRISC - Certified in Risk and Information Systems Control sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CRISC - Certified in Risk and Information Systems Control course?
The full CRISC - Certified in Risk and Information Systems Control course includes 400 practice questions, covering all 4 exam domains. Every question carries a full explanation for the right answer and the wrong ones.
Are these official ISACA exam questions?
No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.
Which domains does the CRISC - Certified in Risk and Information Systems Control course cover?
The course covers 4 exam domains: Governance, Risk Assessment, Risk Response and Reporting, Technology and Security.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.
Start with 10 free questions
No account, no card. The full CRISC - Certified in Risk and Information Systems Control course is $9.99, once.