Courseiva
Risk Response and ReportingmediumMultiple ChoiceObjective-mapped

CRISC Risk Response and Reporting Practice Question

A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?

⚠ Common exam trap

Many candidates confuse a KRI trend with a risk level itself, thinking a change in the indicator does not necessarily mean a change in risk, but in CRISC, a worsening KRI like patch lag directly signals increased vulnerability risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Increased vulnerability risk

The patch lag KRI measures the time between a patch's release and its deployment. An increase from 15 to 45 days means systems are exposed to known vulnerabilities for a longer period, directly increasing the window of opportunity for exploitation. This trend indicates a worsening security posture and higher vulnerability risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • No change in risk level

    Why it's wrong here

    The increase indicates a change.

  • Improved security posture

    Why it's wrong here

    A higher patch lag indicates slower patching, worsening security.

  • Increased vulnerability risk

    Why this is correct

    Correct. Higher patch lag means systems are exposed longer.

  • Decreased vulnerability risk

    Why it's wrong here

    It indicates increased risk.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.