Skip to main content
Course

CRISC Exam Prep

Master IT risk management and pass ISACA's CRISC exam by thinking in terms of risk, not controls.

Intermediate

Level

5

Modules

10

Lessons

5

Graded quizzes

6 hours

Estimated time

What you will be able to do

  • You will be able to apply the CRISC risk-practitioner mindset to choose the BEST answer when several options look technically correct.
  • You will be able to explain how IT risk management aligns with enterprise risk management, governance, and the organization's risk appetite and tolerance.
  • You will be able to identify and assess IT risk using threats, vulnerabilities, likelihood, and impact, and express results as inherent and residual risk.
  • You will be able to select and recommend appropriate risk responses (mitigate, transfer, avoid, accept) and justify them against risk appetite.
  • You will be able to design, monitor, and report on Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and a risk register to support decisions.
  • You will be able to relate information systems controls, the CIA triad, and emerging technologies to the risk they are intended to manage.
  • You will be able to navigate ISACA's scenario-based 'MOST / BEST / FIRST / GREATEST' question phrasing with a repeatable answering strategy.

What is inside

5 modules, 10 lessons. Each module ends in a graded quiz.

  1. 01

    Governance

    Covers the ISACA CRISC, Certified in Risk and Information Systems Control Governance domain (about 26% of the exam), spanning 1.1, 1.2. Each objective is taught as its own lesson with worked examples and exam-style checks.

    2 lessons · 15 quiz questions

  2. 02

    IT Risk Assessment

    Covers the ISACA CRISC, Certified in Risk and Information Systems Control IT Risk Assessment domain (about 22% of the exam), spanning 2.1, 2.2. Each objective is taught as its own lesson with worked examples and exam-style checks.

    2 lessons · 15 quiz questions

  3. 03

    Risk Response & Reporting

    Covers the ISACA CRISC, Certified in Risk and Information Systems Control Risk Response & Reporting domain (about 32% of the exam), spanning 3.1, 3.2, 3.3. Each objective is taught as its own lesson with worked examples and exam-style checks.

    3 lessons · 15 quiz questions

  4. 04

    Information Technology & Security

    Covers the ISACA CRISC, Certified in Risk and Information Systems Control Information Technology & Security domain (about 20% of the exam), spanning 4.1, 4.2. Each objective is taught as its own lesson with worked examples and exam-style checks.

    2 lessons · 15 quiz questions

  5. 05

    Exam Readiness & Practice Exam

    Pulls the whole exam together: an exam-day strategy and key-term glossary, then a timed, domain-weighted practice exam written in the real exam style.

    1 lessons · 50 quiz questions