hardMultiple ChoiceObjective-mapped
CRISC Practice Question: A multinational corporation is assessing the risk…
A multinational corporation is assessing the risk of non-compliance with GDPR. Which of the following is the BEST approach to quantify the potential fine?
⚠ Common exam trap
ISACA often tests the distinction between regulatory fines (which follow a fixed statutory formula) and broader breach costs (which include operational, reputational, and legal expenses), leading candidates to mistakenly select a comprehensive cost model like Ponemon instead of the turnover-based regulatory calculation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Base the estimate on the organization's annual global turnover
Under GDPR, the maximum fine for non-compliance is the greater of €20 million or 4% of the organization's annual global turnover. Therefore, basing the estimate on annual global turnover directly aligns with the regulatory formula used by supervisory authorities, making it the most accurate and defensible quantification approach for potential fines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Base the estimate on the organization's annual global turnover
Why this is correct
GDPR fines are up to 4% of annual turnover.
- ✗
Estimate based on the cost of cyber insurance premiums
Why it's wrong here
Insurance is not a fine.
- ✗
Calculate the cost of data breach using the Ponemon Institute model
Why it's wrong here
This includes many costs beyond fines.
- ✗
Use industry benchmarks for data breach costs
Why it's wrong here
Benchmarks may not reflect regulatory fines.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.