Courseiva

CRISC Information Technology and Security Practice Question

A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?

⚠ Common exam trap

CRISC often tests risk response timing; candidates may choose extreme actions (ignore or immediate replacement) instead of a balanced, proactive approach like planning and agility assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Begin post-quantum cryptography migration planning and crypto-agility assessment

Beginning post-quantum cryptography (PQC) migration planning and crypto-agility assessment is the most appropriate immediate action because it addresses the long-term risk without premature disruption. Crypto-agility ensures systems can quickly switch algorithms, and planning allows for a smooth transition as standards mature. This proactive approach aligns with risk management principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase key lengths for all symmetric encryption to 256 bits

    Why it's wrong here

    Increasing symmetric key lengths does not address the asymmetric algorithms (RSA, ECC) that Shor's algorithm breaks, and AES-256 already resists Grover's search. It is tempting because longer keys harden encryption generally, and it would be correct if the assessed threat were classical brute-force cryptanalysis rather than quantum factoring.

  • ✗

    Ignore the risk until quantum computers are commercially available

    Why it's wrong here

    Deferring action leaves long-lived data exposed to harvest-now-decrypt-later attacks, and migration lead times exceed the ten-year estimate. It is tempting because quantum advantage is not yet realised, and ignoring the risk would be defensible if all cryptography protected only short-lived, low-sensitivity data with no retrospective confidentiality requirement.

  • ✓

    Begin post-quantum cryptography migration planning and crypto-agility assessment

    Why this is correct

    Harvest-now-decrypt-later exposure means encrypted data captured today is at risk once quantum advantage arrives, so migration planning and crypto-agility assessment must start immediately. This satisfies the stem's immediate-action constraint, since inventorying algorithms and enabling rapid substitution takes years.

  • ✗

    Replace all existing cryptographic algorithms with post-quantum algorithms immediately

    Why it's wrong here

    Immediate wholesale replacement disrupts interoperability with existing systems and standards, and mature post-quantum algorithms are still being standardised. It is tempting because it eliminates the exposure outright, and it would be correct once NIST standards are finalised and vendor support exists across the entire cryptographic estate.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.