Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: A multinational corporation is assessing the risk…

A multinational corporation is assessing the risk of non-compliance with GDPR. Which of the following is the BEST approach to quantify the potential fine?

⚠ Common exam trap

ISACA often tests the distinction between regulatory fines (which follow a fixed statutory formula) and broader breach costs (which include operational, reputational, and legal expenses), leading candidates to mistakenly select a comprehensive cost model like Ponemon instead of the turnover-based regulatory calculation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Base the estimate on the organization's annual global turnover

Under GDPR, the maximum fine for non-compliance is the greater of €20 million or 4% of the organization's annual global turnover. Therefore, basing the estimate on annual global turnover directly aligns with the regulatory formula used by supervisory authorities, making it the most accurate and defensible quantification approach for potential fines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Base the estimate on the organization's annual global turnover

    Why this is correct

    GDPR fines are up to 4% of annual turnover.

  • Estimate based on the cost of cyber insurance premiums

    Why it's wrong here

    Insurance is not a fine.

  • Calculate the cost of data breach using the Ponemon Institute model

    Why it's wrong here

    This includes many costs beyond fines.

  • Use industry benchmarks for data breach costs

    Why it's wrong here

    Benchmarks may not reflect regulatory fines.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.