ISACA IT Risk Fundamentals Certificate Free Sample Questions

20 free sample questions208 in the full practice test

Try simulator

IT-Risk-Fundamentals Sample Questions

  1. Question 1

    A global logistics company is analyzing the financial impact of a potential data breach in its primary shipping database. The asset value (AV) of the database is estimated at $5,000,000. Historical data from similar incidents suggest a 20% loss of asset value if a breach occurs (Exposure Factor). Based on threat intelligence, an attack of this nature is expected to succeed once every four years. What is the Annualized Loss Expectancy (ALE) for this scenario?

    Answer and explanation

    Correct answer: B

    The calculation is as follows: First, find the Single Loss Expectancy (SLE) = Asset Value (AV) * Exposure Factor (EF), which is $5,000,000 * 0.20 = $1,000,000. Next, determine the Annualized Rate of Occurrence (ARO), which is 1 incident / 4 years = 0.25. Finally, calculate the Annualized Loss Expectancy (ALE) = SLE * ARO, which is $1,000,000 * 0.25 = $250,000.

  2. Question 2

    A risk analyst at a manufacturing firm is preparing a report for senior management. The analyst has identified that a critical control system for the assembly line has no failover capability, making it a single point of failure. Which of the following is the MOST appropriate way to document this in the risk register?

    Answer and explanation

    Correct answer: C

    This is the most comprehensive and appropriate risk statement. It clearly links the threat (system failure) and the vulnerability (lack of failover) to the specific business impact (production stoppage, financial loss, delays). This format provides the necessary context for risk assessment and response planning.

  3. Question 3

    Multiple answers

    A financial services firm is implementing a continuous monitoring program for its IT risks. The CISO wants to create Key Risk Indicators (KRIs) to provide early warnings of increasing risk levels. Which TWO of the following would be the MOST effective KRIs for monitoring the risk of unauthorized access to sensitive client data? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    This is an excellent KRI. A rising percentage indicates a breakdown in access control processes, which directly increases the risk of unauthorized access through stale or inappropriate privileged accounts. It is a leading indicator of potential future incidents.

    This is a strong KRI because a spike in this metric provides an early warning of a potential brute-force or credential stuffing attack in progress. It allows the security team to react before a successful breach occurs, making it a leading indicator.

  4. Question 4

    A non-profit organization relies on a third-party cloud provider for all its donor management and financial systems. A risk assessment identifies a significant risk of service unavailability due to a potential provider outage. The organization has a very limited budget and cannot afford to switch providers or implement a multi-cloud strategy. What is the MOST appropriate risk response strategy in this situation?

    Answer and explanation

    Correct answer: B

    Risk mitigation involves taking action to reduce the likelihood or impact of the risk. Even with a limited budget, the organization can implement mitigating controls such as developing a robust incident response plan, performing regular data backups to a separate, low-cost location, and negotiating stronger Service Level Agreements (SLAs) with the provider. This is the most proactive and appropriate response.

  5. Question 5

    True or False: In a qualitative risk assessment, a risk with a 'High' impact and a 'Low' probability should always be prioritized for treatment over a risk with a 'Medium' impact and a 'High' probability.

    Answer and explanation

    Correct answer: B

    This statement is false. Risk prioritization is determined by the overall risk rating, which is a combination of impact and probability. An organization's risk matrix might rate a 'Medium Impact / High Probability' risk as 'High' overall, while rating a 'High Impact / Low Probability' risk as 'Medium' overall. The prioritization depends entirely on the specific risk matrix and risk appetite defined by the organization.

  6. Question 6

    An internal audit of a regional bank reveals that business unit managers are frequently accepting high-level IT risks without consulting the central risk management function or senior leadership. This has led to several operational issues. This situation indicates a primary failure in which of the following?

    Answer and explanation

    Correct answer: C

    This is a classic failure of risk governance. A proper governance framework would establish clear lines of authority, define risk appetite and tolerance levels, and specify the escalation process for accepting risks that exceed a certain threshold. The managers are operating outside of a well-defined structure, indicating a weakness in governance.

  7. Question 7

    The 'three lines of defense' model is a fundamental concept in risk governance. Which of the following correctly maps the roles to their respective lines of defense?

    graph TD subgraph First_Line [First Line] A[Business Operations] B[Front-line Staff] end subgraph Second_Line [Second Line] C[Risk Management Function] D[Compliance Department] end subgraph Third_Line [Third Line] E[Internal Audit] end First_Line --> Second_Line Second_Line --> Third_Line

    Answer and explanation

    Correct answer: B

    This is the correct mapping. The first line consists of front-line staff and business operations who own and manage risks directly. The second line, including Risk Management and Compliance, provides oversight and sets policies. The third line, Internal Audit, provides independent assurance to the board and senior management that the first two lines are effective.

  8. Question 8

    Case Study

    A mid-sized e-commerce company, 'Urban Threads', is planning a major migration of its customer relationship management (CRM) and inventory systems from an on-premises data center to a public cloud provider. The company's risk management team has been tasked with identifying and assessing the risks associated with this migration. The primary business objective is to enhance scalability and reduce operational overhead, but the board is highly concerned about data security and potential business disruption during the transition.

    The project team is composed of internal IT staff with limited cloud experience and an external consulting firm specializing in cloud migrations. The timeline for the migration is aggressive, set at three months to align with the launch of a new product line. Early analysis shows that the current on-premises systems have several undocumented dependencies and custom configurations.

    Which risk assessment finding should be of the HIGHEST priority to the board of directors?

    Answer and explanation

    Correct answer: C

    This represents the highest priority risk. A prolonged outage directly impacts the company's ability to conduct business, leading to immediate revenue loss, reputational damage, and failure to meet the product launch deadline. It combines a high likelihood (due to undocumented dependencies and an aggressive timeline) with a catastrophic business impact, directly addressing the board's concern about business disruption.

  9. Question 9

    A risk manager is using a 5x5 risk matrix (with axes for Likelihood and Impact) to assess risks. Risk A is rated as Likelihood=2, Impact=5. Risk B is rated as Likelihood=4, Impact=3. Assuming the risk score is calculated by multiplying the ratings (Score = Likelihood x Impact), which statement is correct?

    Answer and explanation

    Correct answer: C

    This is correct. The risk score for Risk A is 2 * 5 = 10. The risk score for Risk B is 4 * 3 = 12. Since Risk B has a higher overall score (12 vs. 10), it should be prioritized for treatment over Risk A, despite having a lower individual impact rating.

  10. Question 10

    A telecom company has decided it will no longer offer services in a high-risk geopolitical region to eliminate all associated cybersecurity and compliance risks. This is an example of which risk response strategy?

    Answer and explanation

    Correct answer: D

    Risk avoidance is the strategy of deciding not to become involved in, or to withdraw from, a risk situation. By ceasing operations in the high-risk region, the company is eliminating the activities that give rise to the associated risks.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 208 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon