CRISC Risk Response and Reporting Practice Question
A software company is defining key risk indicators (KRIs) for its cloud service availability risk. The risk owner wants indicators that provide early warning of deteriorating conditions rather than after-the-fact outcomes. Which TWO of the following are the most appropriate leading KRIs for this risk? (Choose two.)
⚠ Common exam trap
The trap here is selecting familiar operational metrics like outage counts or restore times, which are lagging indicators, when the scenario explicitly requires early warning of deteriorating conditions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of critical cloud components operating above 80% capacity utilization.
Leading KRIs detect conditions that precede an adverse event, giving the risk owner time to act. Capacity utilization thresholds and single points of failure both signal latent availability weaknesses before an outage occurs. Outage counts, mean time to restore, and patch currency either describe past events or relate to a different risk category, so they do not satisfy the requirement for early warning indicators specific to cloud service availability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Average time to restore service after a cloud availability incident.
Why it's wrong here
Mean time to restore measures recovery performance after an incident has occurred, making it a lagging indicator of response capability. It does not signal deteriorating conditions before an outage and therefore cannot serve as early warning. Although useful for resilience reporting, it fails the scenario's requirement for indicators that precede the adverse event and enable preventive action.
- ✗
Percentage of virtual machines running without current security patches.
Why it's wrong here
Patch currency is a leading indicator of vulnerability and compromise risk, not of service availability risk. While unpatched systems can contribute to outages, the indicator primarily measures exposure to exploitation and does not directly warn of capacity, redundancy, or dependency failures that drive availability loss. It is relevant to a different risk register entry and misaligns with the availability KRI objective.
- ✓
Percentage of critical cloud components operating above 80% capacity utilization.
Why this is correct
Capacity utilization above a defined threshold is a leading indicator because it signals approaching resource exhaustion before an outage occurs. It is measurable, tied directly to the availability risk, and provides time to scale infrastructure or rebalance workloads. Leading KRIs such as this give the risk owner an actionable warning window, unlike lagging indicators that only confirm an event after service has already degraded.
- ✗
Number of unplanned availability outages experienced in the past quarter.
Why it's wrong here
Outage counts are lagging indicators: they report events that have already happened and cannot provide advance warning. While valuable for trend analysis and post-incident review, they do not help the risk owner intervene before an outage. The scenario specifically asks for early warning indicators, so a historical outage count does not meet the stated requirement.
- ✓
Count of single points of failure identified in the cloud architecture during the last review.
Why this is correct
Single points of failure directly threaten availability, and tracking their count shows whether architectural resilience is improving or deteriorating. As a leading indicator, it highlights latent conditions that could cause an outage before one occurs, giving the risk owner a basis for remediation prioritization. It is measurable, tied to the specific risk, and supports early intervention.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.