CRISC Risk Response and Reporting Practice Question
A Key Risk Indicator (KRI) that shows a rising trend in the average time to apply critical security patches suggests:
⚠ Common exam trap
Candidates may confuse KRIs with KPIs and think a rising trend in a security metric means improved performance, but here it's a risk indicator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increasing risk of exploitation
A rising trend in the average time to apply critical security patches indicates that systems remain vulnerable for longer periods, increasing the likelihood of exploitation. This is a lagging indicator of control effectiveness and directly points to increased risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Decreasing risk of exploitation
Why it's wrong here
A rising patch time lengthens exposure windows, so exploitation risk increases rather than decreases. It is tempting because falling patch times do indicate decreasing risk, but the KRI trend here moves the wrong way; the metric measures latency, not residual vulnerability.
- ✗
Stable risk level
Why it's wrong here
A rising patch-latency trend is a change indicator, so risk is increasing, not stable. Stability would require the KRI to remain flat over the reporting period. The metric tracks exposure duration, and lengthening it widens the exploitation window.
- ✓
Increasing risk of exploitation
Why this is correct
A rising average patch time means critical vulnerabilities remain exploitable for longer, widening the window attackers can leverage. The KRI measures exposure duration, so the upward trend directly signals growing likelihood of successful exploitation rather than improved remediation.
- ✗
Improved control effectiveness
Why it's wrong here
Longer patch latency reflects deteriorating, not improved, control effectiveness, since the patching process is the control being measured. Improved effectiveness would appear as a falling average time; the rising trend signals the control is weakening, leaving critical vulnerabilities unpatched longer.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.