CRISC Risk Response and Reporting Practice Question
A Key Risk Indicator (KRI) for a critical system is the number of unpatched vulnerabilities older than 30 days. The threshold is set at 5. This KRI is best described as:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A leading indicator of vulnerability risk
This KRI measures the time lag in patching, which is a leading indicator of increasing vulnerability risk. It signals that the risk level is changing before an actual exploit occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Key Control Indicator (KCI)
Why it's wrong here
KCIs measure control performance, not risk level directly.
- ✓
A leading indicator of vulnerability risk
Why this is correct
It indicates that patch management is behind schedule, increasing risk.
- ✗
A measure of residual risk
Why it's wrong here
Residual risk is the risk remaining after controls; this KRI tracks a risk driver.
- ✗
A lagging indicator of control effectiveness
Why it's wrong here
It is a leading indicator because it predicts future risk.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.