hardMultiple ChoiceObjective-mapped
CRISC Practice Question: A global financial services firm has implemented…
A global financial services firm has implemented a risk monitoring system that aggregates data from 50+ systems across three regions (Americas, EMEA, APAC). The system uses a centralized data lake and provides dashboards to regional risk committees. Recently, the APAC committee reported that their dashboard shows a spike in cyber risk indicators, but the Americas and EMEA dashboards show no change. The data source for the spike is a single system in APAC that tracks failed VPN logins. The risk owner for that system believes the spike is due to a misconfiguration during a recent patch. However, the APAC risk committee is concerned that this indicates a coordinated attack. The Chief Risk Officer (CRO) wants a clear assessment. Which course of action is most appropriate?
⚠ Common exam trap
The trap here is that candidates may overreact to a spike in risk indicators and choose escalation (Option D) or broad control additions (Option A), failing to recognize that a single-system anomaly with a plausible technical explanation (patch misconfiguration) should first be investigated and confirmed before any further action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advise the CRO that the spike is likely a false positive due to the recent patch and recommend the system owner confirm and fix the misconfiguration.
The spike originates from a single system in APAC tracking failed VPN logins, and the risk owner has identified a misconfiguration from a recent patch as the cause. This is a classic false positive scenario where a technical anomaly (e.g., a patch altering authentication timeout or lockout thresholds) generates an alert spike without evidence of lateral movement or other indicators. The CRO needs a clear assessment, and the most appropriate action is to confirm the misconfiguration and fix it, rather than escalating or adding controls prematurely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Recommend implementing additional monitoring controls across all regions to detect similar spikes.
Why it's wrong here
Reactive and may not address root cause.
- ✓
Advise the CRO that the spike is likely a false positive due to the recent patch and recommend the system owner confirm and fix the misconfiguration.
Why this is correct
Addresses the likely cause directly.
- ✗
Suggest the APAC committee accept the risk based on the system owner's opinion.
Why it's wrong here
Should verify before simply accepting.
- ✗
Immediately escalate to the board and activate the incident response team.
Why it's wrong here
Premature without confirmation of an attack.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.