200+ Free CRISC Practice Questions
Prepare for the Certified in Risk and Information Systems Control exam with instant access — no signup required.
Loading practice questions...
Explore More ISACA Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
Key Facts: CRISC Exam
150
Exam Questions
ISACA
450/800
Passing Score
ISACA
US$151K+
Avg Salary
ISACA
30K+
CRISC Holders
ISACA
$575
Exam Fee (Member)
ISACA
3 years
Experience Required
ISACA
The CRISC (Certified in Risk and Information Systems Control) is ISACA's risk-focused certification for IT risk professionals, held by more than 30,000 practitioners worldwide. The exam covers 4 domains, with Risk Response and Reporting (32%) and Governance (26%) the largest. Candidates need 450/800 to pass with 150 questions in 4 hours. ISACA reports an average annual salary of US$151K+ for CRISC holders.
Sample CRISC Practice Questions
Try these sample questions to test your CRISC exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 200+ question experience with AI tutoring.
1What is the primary purpose of an enterprise risk management (ERM) framework in an organization?
2Which of the following BEST describes risk appetite?
3Who is ultimately responsible for risk governance in an organization?
4What is the primary objective of the Three Lines of Defense model?
5Which component of the COSO ERM framework focuses on the integrity and ethical values of the organization?
6What is risk tolerance?
7Which of the following is a responsibility of the Chief Risk Officer (CRO)?
8What is the primary purpose of risk policies and standards?
9In the context of risk culture, what does "tone at the top" refer to?
10Which compliance obligation is typically associated with SOX (Sarbanes-Oxley Act)?
About the CRISC Exam
The CRISC (Certified in Risk and Information Systems Control) is ISACA's risk-focused certification for IT and business professionals. It validates expertise in identifying, assessing, and managing IT risk, and implementing appropriate risk-based controls. CRISC is the only certification that prepares IT professionals for the unique challenges of IT and enterprise risk management.
Questions
150 scored questions
Time Limit
4 hours
Passing Score
450/800
Exam Fee
$575 (members) / $760 (non-members) (ISACA)
CRISC Exam Content Outline
Governance
Risk governance frameworks, organizational structure, risk culture, and policy standards
Risk Assessment
Risk identification, analysis, evaluation, and assessment methodologies
Risk Response and Reporting
Risk treatment, control selection, KRI development, and risk reporting
Technology and Security
IT controls, security operations, business continuity, and emerging technologies
How to Pass the CRISC Exam
What You Need to Know
- Passing score: 450/800
- Exam length: 150 questions
- Time limit: 4 hours
- Exam fee: $575 (members) / $760 (non-members)
Keys to Passing
- Work through all 200 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CRISC Study Tips from Top Performers
Frequently Asked Questions
What is the CRISC exam format?
The CRISC exam consists of 150 multiple-choice questions with a 4-hour time limit. The exam is non-adaptive (linear format). You need a scaled score of 450 out of 800 to pass. Questions are distributed across 4 domains, with Domain 3 (Risk Response and Reporting) at 32% and Domain 1 (Governance) at 26% being the largest.
What are the CRISC experience requirements?
CRISC requires three years of cumulative work experience performing the tasks of a CRISC professional across at least two of the four CRISC domains, and at least one of those years must fall in Domain 1 (Governance) or Domain 2 (Risk Assessment). There are no substitutions or waivers for education or other certifications. You can sit the exam before meeting the experience requirement and have five years from the date of passing to apply for certification, plus a one-time US$50 application processing fee.
How hard is the CRISC exam?
CRISC is an advanced credential that tests risk-based judgment rather than recall. ISACA does not publish CRISC pass-rate statistics, so any percentage you see quoted is an unofficial estimate. The exam tests both risk management concepts and IT knowledge, and most successful candidates study 100-150 hours over 2-3 months. The risk response domain is the largest at 32% and requires understanding control frameworks and risk treatment strategies.
What salary do CRISC holders earn?
ISACA reports an average annual salary of US$151,000 or more for CRISC holders on its official CRISC credential page. The certification is consistently ranked among the top-paying IT certifications and is valued for risk management, compliance, and IT governance positions. Actual pay varies substantially by region, industry, and years of experience.
How should I study for the CRISC?
Study domains proportional to their exam weights — focus heavily on Domain 3 (32%) and Domain 1 (26%). Understand risk frameworks (COSO, ISO 31000), risk assessment methodologies, and control selection. Practice scenario-based questions that require risk-based decision making. Complete 500+ practice questions and score 75%+ consistently.
CRISC vs CISA — which should I get?
CRISC is risk-focused for those managing IT and enterprise risk. CISA is audit-focused for IT auditors and assurance professionals. CRISC is ideal for risk managers, compliance officers, and IT professionals responsible for risk management. Many professionals get both to demonstrate comprehensive risk and audit expertise.