Courseiva
easyMultiple ChoiceObjective-mapped

Immediate Action When KRI Exceeds Threshold

A risk manager notices that a key risk indicator (KRI) for network downtime has been steadily increasing over the past three months. The current value is 15% above the risk tolerance threshold. Which of the following is the BEST immediate action?

Quick Answer

The correct immediate action is to alert the risk owner and initiate a root cause analysis. When a key risk indicator (KRI) exceeds the risk tolerance threshold, it signals that the current risk level has moved beyond the organization’s appetite, often due to a control failure or an emerging threat. Alerting the risk owner—the person accountable for managing that risk—ensures escalation to the proper decision-maker, while launching a root cause analysis addresses the underlying cause of the increasing network downtime rather than just treating the symptom. On the CRISC exam, this scenario tests your understanding of the risk monitoring and reporting process, specifically that KRIs are leading indicators requiring immediate escalation, not just documentation. A common trap is choosing to adjust the threshold or wait for more data, but the correct response is always to notify the accountable party and investigate. Memory tip: “Threshold breached? Alert and dig—don’t adjust the peg.”

⚠ Common exam trap

Candidates often confuse adjusting the threshold (a control metric) with managing the risk itself, but CRISC emphasizes that thresholds are set to trigger action, not to be moved to avoid action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Alert the risk owner and initiate a root cause analysis

The KRI has exceeded the risk tolerance threshold, indicating a potential control failure or emerging threat. The immediate action is to alert the risk owner, who has accountability for the risk, and initiate a root cause analysis to identify why network downtime is increasing. This aligns with the CRISC process of monitoring KRIs and escalating when thresholds are breached.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Lower the risk tolerance threshold to trigger more frequent alerts

    Why it's wrong here

    Lowering thresholds would increase false positives and not solve the underlying issue.

  • Accept the increased risk without further analysis because the trend is gradual

    Why it's wrong here

    Gradual increase still requires investigation to prevent further escalation.

  • Alert the risk owner and initiate a root cause analysis

    Why this is correct

    This follows the standard escalation process for KRI breaches.

  • Increase the risk tolerance threshold to match the current level

    Why it's wrong here

    Changing thresholds to avoid breach is not a proper risk management practice.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A risk manager notices that a key risk indicator (KRI) for system downtime has exceeded the threshold for two consecutive months. What is the MOST appropriate immediate action?

easy
  • A.Revise the KRI threshold to a higher value.
  • B.Archive the current KRI and define a new one.
  • C.Update the risk register with the new KRI value.
  • D.Escalate to the risk owner for investigation.

Why D: When a KRI exceeds its threshold for two consecutive months, the immediate priority is to investigate the root cause and assess whether the risk is materializing. Escalating to the risk owner ensures that the appropriate subject matter expert analyzes the situation, determines if controls are failing, and decides on corrective actions. Revising the threshold or replacing the KRI without investigation would bypass the monitoring and response process, potentially masking a real risk event.

Variation 2. A risk manager notices that a key risk indicator (KRI) for failed login attempts has exceeded the threshold for three consecutive weeks. Which of the following should be the FIRST action?

easy
  • A.Investigate the root cause of the increase.
  • B.Adjust the threshold to reduce false positives.
  • C.Report the breach to the senior management immediately.
  • D.Ignore the trend as a statistical anomaly.

Why A: When a KRI exceeds its threshold for multiple consecutive periods, the first action is to investigate the root cause to determine whether the increase indicates a genuine security issue (e.g., brute-force attack, credential stuffing) or a false positive. Jumping to reporting or threshold adjustment without understanding the underlying cause could lead to misallocation of resources or missed detection of an actual threat. This aligns with the CRISC principle that risk indicators must be validated before escalation or remediation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.