About the Exam

ISACA's IT Risk Fundamentals Certificate is intended for professionals who are new to risk, work with risk professionals, or want to build foundational knowledge of information and technology-related risk. The exam covers IT risk management principles, risk governance and management, risk identification, risk assessment and analysis, risk response, and risk monitoring, reporting, and communication. It is a 2-hour remotely proctored exam with multiple-choice and performance-based questions, and passing requires a score of 65% or higher. Passing demonstrates foundational knowledge of IT risk terminology, concepts, general practices, and I&T-related risk.

Exam Topics

  • Risk Assessment and Analysis25%
  • Risk Monitoring, Reporting and Communication20%
  • Risk Identification20%
  • Risk Response15%
  • Risk Governance and Management15%
  • Risk Intro and Overview5%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated December 3, 2025 at 6:20 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Risk Identification

Which of the following is an example of an inductive approach to gathering information?

Explanation

Vulnerability analysis collects evidence about specific weaknesses and exposures, then uses those findings to infer potential security risks. This is an inductive approach because it moves from individual observations to broader conclusions.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Risk Assessment and Analysis

Which of these risk-analysis methods collects various potential risk ideas for validation and ranking by an individual or small groups during interviews?

Explanation

The Delphi technique systematically elicits expert opinions on possible risks and uses structured, often iterative feedback to validate and prioritize them. Monte Carlo analysis models uncertainty quantitatively, whereas brainstorming generates ideas in a group without the same structured expert-ranking process.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Risk Assessment and Analysis

Which of the following is the MOST important input for analyzing I&T-related risk?

Explanation

Historical information about incidents, their frequency, and resulting organizational losses provides evidence for estimating risk likelihood and impact. These estimates are central to I&T-related risk analysis.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Risk Assessment and Analysis

A risk practitioner has been assigned to analyze newly added risk events in the risk register. Which of the following analysis methods would BEST allow the practitioner to minimize ambiguity and subjectivity?

Explanation

Annual loss expectancy (ALE) applies quantitative monetary values to expected loss frequency and impact, providing an objective, consistently interpretable basis for risk analysis. Delphi and brainstorming rely on expert judgment, so they retain greater subjectivity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Risk Assessment and Analysis

Which of the following is a KEY contributing factor in determining risk rankings to guide risk response?

Explanation

Vulnerability severity is a direct contributor to risk assessment and prioritization because it indicates the seriousness of a weakness and supports risk-response decisions. The cost of controls is considered when choosing a treatment, whereas risk-management-process maturity is an organizational capability measure rather than a risk-ranking input.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home