Prepare for the Certified in Risk and Information Systems Control (CRISC) certification by ISACA with free exam-style practice questions on CyberCertPrep. The CRISC exam has 150 questions, a time limit of 4 hours, and a passing score of 65%.
Choose from Practice mode, Exam Simulation, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
Certified in Risk and Information Systems Control (CRISC) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 26% of your CRISC exam score.
The Governance domain is one of 4 exam domains on the Certified in Risk and Information Systems Control (CRISC) certification exam by ISACA. At 26% of the total exam, this is one of the most heavily weighted domains, mastering it is critical for passing.
The CRISC exam consists of 150 questions with a time limit of 4 hours and a passing score of 65%. That means approximately 39 questions on your exam will come from the Governance domain.
GDPR
The General Data Protection Regulation, an EU regulation enacted in 2018 that governs data protection and privacy for al...
IAM (Identity and Access Management)
A framework of policies, processes, and technologies for managing digital identities and controlling user access to crit...
Identity and Access Management (IAM)
A framework of policies and technologies that ensures the right individuals have appropriate access to resources at the ...
SOX (Sarbanes-Oxley Act)
U.S. federal law enacted in 2002 to enhance corporate financial reporting accuracy and prevent accounting fraud followin...
Prompt Injection
An attack against large language model (LLM) applications in which crafted input manipulates the model into ignoring its...
Model Inversion Attack
A privacy attack that reconstructs sensitive training data, or attributes of it, by repeatedly querying a model and anal...
Membership Inference Attack
A privacy attack that determines whether a specific data record was part of a model's training set, by exploiting differ...
AI Red Teaming
The structured practice of adversarially testing AI systems — probing for jailbreaks, prompt injection, harmful or biase...
These certifications also cover topics related to Governance:
Governance, Risk & Compliance, 20% of exam
Information Security Governance, 17% of exam
Governance and Management of IT, 18% of exam
Privacy Governance, 20% of exam
Security and Privacy Governance, Risk Management, and Compliance Program, 16% of exam
AI Governance, 25% of exam