CRISC Information Technology and Security Practice Question
A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?
⚠ Common exam trap
CRISC often tests risk response timing; candidates may choose extreme actions (ignore or immediate replacement) instead of a balanced, proactive approach like planning and agility assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Begin post-quantum cryptography migration planning and crypto-agility assessment
Beginning post-quantum cryptography (PQC) migration planning and crypto-agility assessment is the most appropriate immediate action because it addresses the long-term risk without premature disruption. Crypto-agility ensures systems can quickly switch algorithms, and planning allows for a smooth transition as standards mature. This proactive approach aligns with risk management principles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase key lengths for all symmetric encryption to 256 bits
Why it's wrong here
Increasing symmetric key lengths does not address the asymmetric algorithms (RSA, ECC) that Shor's algorithm breaks, and AES-256 already resists Grover's search. It is tempting because longer keys harden encryption generally, and it would be correct if the assessed threat were classical brute-force cryptanalysis rather than quantum factoring.
- ✗
Ignore the risk until quantum computers are commercially available
Why it's wrong here
Deferring action leaves long-lived data exposed to harvest-now-decrypt-later attacks, and migration lead times exceed the ten-year estimate. It is tempting because quantum advantage is not yet realised, and ignoring the risk would be defensible if all cryptography protected only short-lived, low-sensitivity data with no retrospective confidentiality requirement.
- ✓
Begin post-quantum cryptography migration planning and crypto-agility assessment
Why this is correct
Harvest-now-decrypt-later exposure means encrypted data captured today is at risk once quantum advantage arrives, so migration planning and crypto-agility assessment must start immediately. This satisfies the stem's immediate-action constraint, since inventorying algorithms and enabling rapid substitution takes years.
- ✗
Replace all existing cryptographic algorithms with post-quantum algorithms immediately
Why it's wrong here
Immediate wholesale replacement disrupts interoperability with existing systems and standards, and mature post-quantum algorithms are still being standardised. It is tempting because it eliminates the exposure outright, and it would be correct once NIST standards are finalised and vendor support exists across the entire cryptographic estate.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.