Question 1
Which term describes the potential for losses caused by inadequate systems or controls, human error or mismanagement and natural disasters?
Correct Answer:
Operational risk
Explanation:
Operational risk is the potential for losses that arise from weaknesses in how an organization operates: inadequate systems or controls, human error or mismanagement, and external events like natural disasters. These factors all point to failures in processes, people, or technology that can disrupt daily operations and lead to financial or other losses. A policy is simply a formal rule or guideline, not a description of loss potential. Probability is a measure of how likely an event is, not the type of risk itself. Risk is the broad umbrella term for exposure to loss, but the description specifically targets losses from process and control failures, which is what operational risk captures. For example, a data center outage caused by outdated hardware and missing controls is a classic operational risk scenario.
Question 2
Which term refers to the coordinated activities to direct and control an enterprise with regard to risk?
Correct Answer:
Risk governance
Explanation:
The concept being tested is risk governance—the coordinated activities that establish how an organization directs and controls its approach to risk. Risk governance provides the framework, accountability, and oversight—the policies, risk appetite, roles, and decision-making processes—that guide how risk is identified, assessed, managed, and monitored across the enterprise. It sits above day-to-day risk management activities, ensuring those activities align with objectives, regulatory requirements, and stakeholder expectations. An asset is a resource of value the organization uses or holds, not a governance framework. A stakeholder is anyone with an interest in the organization, which is about who is affected or involved, not the control structure for risk. Access risk refers to a type of risk related to unauthorized or inappropriate access, not to the overarching governance mechanism that directs risk across the enterprise.
Question 3
What is the process for determining and documenting the risk an enterprise faces?
Correct Answer:
Risk identification
Explanation:
The process of determining and documenting the risk an enterprise faces is risk identification. This first step in risk management involves discovering potential events or conditions—from both inside and outside the organization—that could affect objectives, and describing them in a structured way. It captures details such as what could happen, why it might occur, the potential impact, and who would own the risk, typically resulting in a risk register or inventory. This foundation enables later steps like evaluating and prioritizing risks and deciding on responses. A risk scenario is a narrative example used to illustrate how a risk could unfold, not the overall process. A risk awareness program is about educating stakeholders on risk concepts, not identifying specific risks. A threat event is a specific incident that could cause harm, rather than the process of identifying and documenting risks.
Question 4
Which term describes a live test of the effectiveness of security defenses by mimicking the actions of real-life attackers?
Correct Answer:
Penetration test
Explanation:
A penetration test is a live examination where authorized testers simulate real-world attacker behavior to test how well security controls stand up to actual breach attempts. By attempting to exploit weaknesses, escalate privileges, and access sensitive data in a controlled setting, this type of testing reveals how effective defenses are in practice and whether detection and response processes work as intended. It goes beyond mere vulnerability scanning by proving what an attacker could achieve in the real world, helping prioritize fixes and validate security improvements. The other terms describe metrics or indicators rather than the active, attacker-simulated testing itself, so they don’t capture the practical assessment of defenses that a penetration test provides.
Question 5
Which term describes the statement of the desired result or purpose to be achieved by implementing control procedures in a particular process?
Correct Answer:
Control objective
Explanation:
Control objectives describe the intended result of applying controls to a process—the purpose or outcome the control procedures are meant to achieve. They set the target for what the controls are designed to ensure, such as preventing errors, ensuring compliance, or safeguarding assets. By defining this desired outcome, you know what success looks like and can design and test controls accordingly. This is different from governance, which is the broad framework for directing and controlling an organization; a RACI chart, which maps who is responsible, accountable, consulted, and informed; and a vulnerability, which is a weakness that could be exploited. For example, in a purchasing process the control objective might be to ensure all purchases are properly authorized and supported, guiding controls like required manager approval and documentation matching.
Question 1
Exam overview

About this Exam

Prepare with the ISACA IT Risk Fundamentals Practice Test practice quiz. This question bank includes 10 questions covering risk, term, describes, potential, and human. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

ISACA IT Risk Fundamentals Practice Test

This practice set contains 10 questions from the matching question bank and focuses on risk, term, describes, potential, and human. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions