mediumMultiple Choice
CRISC Practice Question: A company's risk monitoring report shows that a…
A company's risk monitoring report shows that a key risk indicator (KRI) has exceeded the threshold for three consecutive months. What is the MOST appropriate action?
⚠ Common exam trap
Many exam-takers confuse a persistent KRI breach with a temporary spike and choose to wait (Option B) or adjust the threshold (Option C), failing to recognize that the CRISC framework mandates investigation and corrective action for sustained deviations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a root cause analysis and implement corrective actions.
A KRI that has exceeded its threshold for three consecutive months indicates a persistent risk condition, not a transient anomaly. The most appropriate action is to conduct a root cause analysis to identify the underlying issue and implement corrective actions to bring the risk back within acceptable levels. This aligns with the CRISC domain of Risk and Control Monitoring and Reporting, which emphasizes proactive remediation over passive observation or threshold manipulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a root cause analysis and implement corrective actions.
Why this is correct
Three consecutive breaches indicate the KRI is not transient, so root cause analysis identifies why the threshold is persistently exceeded and corrective actions restore the control. This addresses the underlying driver rather than merely re-reporting or adjusting the threshold.
- ✗
Wait for the KRI to return to normal on its own.
Why it's wrong here
Waiting for the KRI to self-correct ignores the three-month breach, which signals the risk response is failing and demands escalation or treatment, not passive observation. It is tempting because KRIs are monitoring metrics, and tolerating brief single-period variance is reasonable; however, sustained threshold breaches require action, making this appropriate only when a KRI spikes once and recovers.
- ✗
Raise the threshold to avoid future breaches.
Why it's wrong here
Raising the threshold suppresses the signal rather than addressing the underlying risk exposure, defeating the KRI's purpose as a monitoring control. Thresholds are tuned during risk appetite calibration, when baselines are set or indicators prove noisy. Here, three consecutive breaches indicate the risk is materialising, demanding escalation or treatment, not recalibration.
- ✗
Implement temporary manual controls.
Why it's wrong here
Manual controls are a compensating measure for a control gap, not a response to a KRI breaching its threshold for three months, which signals the underlying risk is materialising and needs escalation or treatment. They are tempting because temporary workarounds do restore oversight when automated controls fail, but here the trend itself demands reassessment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.