Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?

⚠ Common exam trap

Many candidates confuse a KRI trend with a risk level itself, thinking a change in the indicator does not necessarily mean a change in risk, but in CRISC, a worsening KRI like patch lag directly signals increased vulnerability risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increased vulnerability risk

The patch lag KRI measures the time between a patch's release and its deployment. An increase from 15 to 45 days means systems are exposed to known vulnerabilities for a longer period, directly increasing the window of opportunity for exploitation. This trend indicates a worsening security posture and higher vulnerability risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    No change in risk level

    Why it's wrong here

    Patch lag tripling from 15 to 45 days is a material deterioration, so the risk level has not stayed static. The KRI tracks remediation latency; longer windows let known exploits be used against unpatched systems. Unchanged risk would require the indicator to hold steady, which the reported trend explicitly contradicts.

  • ✗

    Improved security posture

    Why it's wrong here

    A higher patch lag indicates slower patching, worsening security.

  • ✓

    Increased vulnerability risk

    Why this is correct

    Patch lag measures elapsed time between patch release and deployment. Rising from 15 to 45 days means exposure windows widen, so unpatched vulnerabilities persist longer and the likelihood of exploitation grows. The KRI trend therefore signals increased vulnerability risk, the exposure the metric tracks.

  • ✗

    Decreased vulnerability risk

    Why it's wrong here

    Rising patch lag means vulnerabilities remain unpatched longer, so exposure grows rather than shrinks. The KRI measures elapsed time between patch release and deployment; a jump from 15 to 45 days signals a widening remediation gap. Decreased vulnerability risk would follow faster patching, not slower, so the trend contradicts this reading.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.