ISACA · Advanced

ISACA CRISC — Certified in Risk and Information Systems Control (CRISC) practice exam & study guide

ISACA CRISC (Certified in Risk and Information Systems Control) is a certification for professionals who identify and manage IT risk and implement information systems controls. It validates expertise across four domains — governance, risk assessment, risk response and reporting, and information technology and security.

CRISC is a risk practitioner’s credential. Questions favor risk-based judgment and aligning IT risk to business objectives over deep technical implementation.

This free hub gives you everything you need to prepare: a syllabus breakdown by exam domain, realistic practice questions with teacher-style explanations, a glossary of the risk-management concepts the exam relies on, and full-length timed mock exams that mirror the real testing experience.

100
Questions
180 min
Time limit
70%
Mock pass %
4
Domains

Start studying CRISC

New here? Follow the three steps below in order. Everything is free and needs no account.

  1. 1
    Learn the plan

    See all 4 domains in exam-weight order.

    Open study path
  2. 2
    Drill by domain

    Practice one topic at a time with explained answers.

    Start with the first domain
  3. 3
    Sit a timed mock

    100 questions · 180 min · 70% to pass our mock.

    Take the mock exam

All CRISC study resources

CRISC exam domains

The CRISC exam is weighted across 4 domains. Pick any domain below to drill it — or read the full breakdown in the FAQ.

Exam domainExam weightPractice
Governance26%Practice this topic
Risk Assessment22%Practice this topic
Risk Response and Reporting32%Practice this topic
Technology and Security20%Practice this topic

Sample CRISC questions

A sample of the CRISC questions on this hub. Each links through to the full question, the correct answer, and an explanation of why every other option is wrong.

Key CRISC terms

Start with these terms, then explore the full glossary. Each links to a plain-English definition written for the CRISC exam.

CRISC frequently asked questions

What is the CRISC certification?+

CRISC is widely regarded as a leading certification for IT risk management and is common in job listings for risk and control professionals.

It emphasizes the full risk lifecycle — identification, assessment, response, and monitoring — so success rewards risk judgment rather than tool-specific skills.

What topics are on the CRISC exam?+

The CRISC exam is organised into four weighted domains. The percentages below are ISACA’s official weightings for the current exam content outline, so bias your study toward the heaviest domain — Risk Response and Reporting is the largest, followed by Governance.

Governance (26%)

Covers organizational strategy and structure, culture, policies and standards, and risk governance — enterprise risk management, the risk management framework, three lines of defense, risk appetite/tolerance/capacity, and legal, regulatory, and ethical requirements.

Risk Assessment (22%)

Covers risk events and threat modeling, the threat landscape, vulnerability and control-deficiency analysis, assessment concepts and frameworks, the risk register, quantitative and qualitative analysis, business impact analysis, and inherent versus residual risk.

Risk Response and Reporting (32%)

The largest domain. Covers risk response options (accept, mitigate, transfer, avoid) and their selection, control design and ownership, third-party risk, control monitoring, issues and exceptions management, emerging risk, KRIs and KPIs, and risk reporting to stakeholders.

Technology and Security (20%)

Covers enterprise architecture, IT operations and project management, disaster recovery and data lifecycle management, the SDLC, emerging technologies and their risk, information security concepts and frameworks, awareness programs, and data privacy principles.

Is the CRISC hard?+

CRISC is challenging because it demands risk-based judgment: you must choose the best response for a given risk relative to the organization’s appetite, not the most technical control.

The four domains span the whole IT risk lifecycle, and the heavy weighting on risk response and reporting rewards practical risk-management experience.

How many questions are on the CRISC exam and how long is it?+

The CRISC exam consists of 150 multiple-choice questions to be completed in 4 hours (240 minutes).

Our full-length practice mock uses a 100-question, 180-minute session so you can rehearse pacing and risk-based reasoning across all four domains before test day.

What score do you need to pass the CRISC?+

ISACA scores CRISC on a scaled range of 200 to 800, and you need a scaled score of 450 to pass. Your raw performance is converted to this scaled score, and there is no penalty for guessing, so answer everything. Our practice mock uses a 70% threshold as a study checkpoint; aim comfortably beyond it before test day.

How much does the CRISC exam cost?+

The CRISC exam fee is set by ISACA and differs for members and non-members — check the ISACA site for current pricing. Certification also requires meeting the work-experience requirement and paying annual maintenance fees with continuing professional education (CPE). Everything on this hub is free.

Who should take the CRISC?+

CRISC is aimed at risk professionals, control practitioners, and IT and business managers who manage IT risk.

ISACA requires three years of experience in IT risk management and information systems control to certify, with no experience waivers. You can pass the exam first and claim the experience within five years.

What jobs and salaries can the CRISC lead to?+

CRISC maps to roles such as IT risk manager, risk and control analyst, compliance manager, and information security risk officer.

How much any certification affects pay depends heavily on geography, seniority, and experience, so treat any single salary figure with caution. CRISC is best viewed as validation of IT risk-management competence.

How long does it take to study for the CRISC?+

Experienced candidates often need two to three months of steady study, focused on the risk-based mindset the exam rewards.

Review every explanation, including for questions you answered correctly, because CRISC distractors are built from plausible but sub-optimal risk choices. Use the per-domain results here to find your weakest area, then finish with full-length timed mocks.

How should you prepare for the CRISC?+

Study the four domains above, giving the heaviest weight to Risk Response and Reporting, then drill scenario questions domain by domain. Every MockAPI question reveals a full explanation and tells you why each wrong answer is wrong.

When you can reason to the best risk response comfortably, move to full-length timed mocks. Use the glossary to keep concepts like risk appetite, inherent versus residual risk, KRIs, and the three lines of defense straight, and aim to score consistently above the checkpoint before you book.

Can you take the CRISC exam online?+

Yes. ISACA offers CRISC through remote online proctoring as well as at in-person test centers, so you can choose the option that suits you. The online exam requires a private, quiet room, a clear workspace, a webcam and microphone, a stable connection, and government-issued photo ID, with a proctor monitoring you and a room scan before you start.

If you do not pass, ISACA lets you retake the exam, with a limited number of attempts allowed per rolling twelve-month period — check the current policy before rebooking.

What certification should you take after the CRISC?+

After CRISC, common next steps include ISACA’s CISM for security management or CISA for audit, depending on your focus.

For many, the real next step is owning an enterprise IT risk program. Pairing CRISC with hands-on risk management is what turns the certificate into a career.