Certified Information Systems Risk Manager Exam Prep
Free practice questions

Free C)ISRM Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The C)ISRM exam has 100 questions and runs 2 hours.

These 10 free C)ISRM questions are organized by exam domain, so you can see how each part of the Certified Information Systems Risk Manager blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Risk Identification Assessment and Evaluation

Question 1

A risk assessment identifies a cloud outage scenario that could interrupt customer transactions. Which item represents the business impact?

Show answer & explanation

Correct answer: B - Potential revenue loss from disruption

Question 2

A company estimates downtime cost, recovery expense, and lost revenue in dollars after a cyber event. Which analysis method is being used?

Show answer & explanation

Correct answer: B - Quantitative analysis

Question 3

After controls are implemented, the remaining exposure to a database compromise is known as:

Show answer & explanation

Correct answer: B - Residual risk

Question 4

The primary purpose of a business impact analysis is to determine:

Show answer & explanation

Correct answer: B - Business consequences of disruption

Domain 2: Risk Response

Question 5

A risk exceeds tolerance but the activity cannot be stopped. Which response reduces likelihood or impact?

Show answer & explanation

Correct answer: B - Mitigate

Question 6

Cyber insurance purchased to reduce financial consequences of an incident is an example of:

Show answer & explanation

Correct answer: B - Transfer

Question 7

A control costs more than the expected reduction in risk and remaining exposure is within approved limits. The best action is to:

Show answer & explanation

Correct answer: B - Consider accepting the remaining risk

Domain 3: Risk Monitoring

Question 8

A measurable security metric used to identify increasing exposure and trigger decisions is a:

Show answer & explanation

Correct answer: A - Key risk indicator

Question 9

After risk monitoring data is validated, the next lifecycle activity is typically:

Show answer & explanation

Correct answer: A - Data analysis

Question 10

Evaluating whether risk processes are repeatable and improving over time assesses:

Show answer & explanation

Correct answer: A - Risk maturity

The rest of the C)ISRM blueprint

The C)ISRM exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)ISRM questions with explanations.

Continue in the free practice test →

View plans