Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 175

983 questions total · 14pages · All types, answers revealed

Page 1 of 14

Page 2
1
MCQmedium

A risk practitioner is updating the risk register after a third-party security incident. Which of the following is the MOST important information to include in the risk register entry for this third-party risk?

A.The remediation plan and the risk owner's signature
B.The date of the incident and the amount of data compromised
C.A description of the risk event, its impact, and the response taken
D.The name and contact details of the third party
AnswerC

Why this answer

The risk register should include a description of the risk event, its impact, and the response. While other details are relevant, the core of the entry is the event and its consequences.

2
MCQhard

A board member asks for a summary of the top five risks. The risk practitioner has 10 risks with current residual risk levels. Which approach BEST supports board-level reporting?

A.Present the top five by residual risk level, including a trend indicator
B.Only highlight risks that have increased since last quarter
C.List risks alphabetically with current control status
D.Provide a detailed risk register with all 10 risks and full risk analysis
AnswerA

Trend shows direction and urgency.

Why this answer

Board-level reporting requires concise, actionable insights. Presenting the top five risks by residual risk level, with a trend indicator (e.g., increasing, stable, decreasing), allows the board to quickly understand the most critical exposures and whether risk posture is improving or deteriorating. This aligns with the CRISC focus on risk communication that supports strategic decision-making, not operational detail.

Exam trap

The trap here is that candidates may think the board needs full transparency (Option D) or only changes (Option B), but CRISC emphasizes that board reporting must be concise, prioritized, and decision-focused, not exhaustive or change-only.

How to eliminate wrong answers

Option B is wrong because highlighting only risks that have increased since last quarter omits the highest residual risks that may be stable or decreasing but still exceed the risk appetite, leading to an incomplete picture. Option C is wrong because listing risks alphabetically with current control status ignores risk prioritization, making it impossible for the board to focus on the most critical exposures. Option D is wrong because providing a detailed risk register with all 10 risks and full risk analysis overwhelms the board with operational granularity, violating the principle of tailoring risk reporting to the audience's need for summary-level, decision-oriented information.

3
Drag & Dropmedium

Arrange the steps for performing a risk assessment in the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk assessment begins with asset identification, then threats/vulnerabilities, followed by likelihood and impact analysis, risk calculation, and documentation.

4
MCQmedium

A manufacturing company uses Internet of Things (IoT) sensors to monitor equipment temperature and vibration on the production floor. The sensor data is automatically sent to a central system, but there is a manual log maintained by operators that records their visual inspections. Recently, there have been instances where the sensor data indicated abnormal readings, but the operator logs showed normal conditions, leading to delayed maintenance actions and two equipment breakdowns. The risk manager investigates and finds that operators sometimes forget to update logs or misinterpret sensor alerts. The company wants to improve the reliability of the monitoring process. What should be the primary action?

A.Reduce reliance on IoT sensors and increase manual inspections.
B.Replace all IoT sensors with newer models that have better accuracy.
C.Provide additional training to operators on how to accurately fill in logs and respond to sensor alerts.
D.Implement automated reconciliation between sensor data and operator logs, flagging discrepancies in real time.
AnswerD

Directly addresses the inconsistency and enables timely corrective action.

Why this answer

Automated reconciliation between sensor data and operator logs would highlight discrepancies immediately, allowing quick investigation. Reducing reliance on IoT sensors (A) would eliminate the benefits of automated alerts and is a step backward. Replacing all sensors (B) is costly and does not address the human error in log keeping.

Training operators (C) may help but alone it does not guarantee consistent compliance and still leaves room for human error.

5
MCQmedium

A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?

A.No change in risk level
B.Improved security posture
C.Increased vulnerability risk
D.Decreased vulnerability risk
AnswerC

Correct. Higher patch lag means systems are exposed longer.

Why this answer

The patch lag KRI measures the time between a patch's release and its deployment. An increase from 15 to 45 days means systems are exposed to known vulnerabilities for a longer period, directly increasing the window of opportunity for exploitation. This trend indicates a worsening security posture and higher vulnerability risk.

Exam trap

The trap here is that candidates may confuse a KRI trend with a risk level itself, thinking a change in the indicator does not necessarily mean a change in risk, but in CRISC, a worsening KRI like patch lag directly signals increased vulnerability risk.

How to eliminate wrong answers

Option A is wrong because a significant increase in patch lag from 15 to 45 days represents a clear change in risk level, not no change. Option B is wrong because an increased patch lag means patches are applied more slowly, which degrades rather than improves the security posture. Option D is wrong because a longer delay in applying patches increases the attack surface and vulnerability risk, rather than decreasing it.

6
MCQeasy

An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?

A.Operational risk
B.Compliance risk
C.Financial risk
D.Strategic risk
AnswerB

Compliance risk directly addresses regulatory and legal violations.

Why this answer

Compliance risks involve violations of laws, regulations, or contractual obligations. Regulatory fines for data protection non-compliance fall under the compliance category.

7
MCQeasy

A small online retailer with 15 employees sells handmade crafts through its e-commerce website. The company processes payments via a third-party gateway. The owner manually reviews transaction logs once a week for fraud indicators, but recently discovered three chargebacks due to unauthorized transactions. The retailer has limited IT budget and no dedicated security staff. The owner wants to improve detection of fraudulent transactions without significant investment. The current manual process takes about two hours per week and often results in delayed detection. The payment gateway offers basic fraud detection features such as IP geolocation and velocity checks, but these are not enabled. What is the most practical first step?

A.Enable the built-in fraud detection features offered by the payment gateway.
B.Hire a part-time fraud analyst to review logs daily.
C.Purchase an automated fraud detection system from a third-party vendor.
D.Accept the current risk and set aside a reserve fund for chargebacks.
AnswerA

This is the correct answer because the payment gateway already offers fraud detection features that are not enabled; enabling them is a low-cost, immediate improvement.

Why this answer

Enabling the built-in fraud detection features offered by the payment gateway is the most practical first step because it is low-cost, quick to implement, and leverages existing capabilities without additional expense. Option B (hiring a part-time analyst) would increase costs and may not be sustainable for a small retailer. Option C (purchasing a third-party system) requires significant investment and implementation time.

Option D (accepting the risk) is not acceptable given the recent chargebacks.

8
MCQmedium

During the risk identification process, an IT risk universe is defined. Which of the following BEST describes the purpose of an IT risk universe?

A.A list of all known vulnerabilities in the organization's IT systems
B.A database of past security incidents and their root causes
C.A framework for categorizing risks into strategic, operational, financial, and compliance
D.A comprehensive inventory of all potential IT risks facing the organization
AnswerD

Correct. The IT risk universe includes all potential risks, covering threats, vulnerabilities, and impacts.

Why this answer

The IT risk universe is a comprehensive inventory of all potential IT risks that could affect the organization, serving as the foundation for further risk assessment and treatment.

9
MCQmedium

A risk assessment reveals that the cost of implementing a control ($500k) exceeds the annualized loss expectancy (ALE) of $300k. The risk is currently within the organization's risk appetite. What is the appropriate risk response?

A.Accept the risk
B.Implement the control
C.Avoid the risk
D.Transfer the risk
AnswerA

Acceptance is justified when mitigation is not cost-effective.

Why this answer

When the cost of the control ($500k) exceeds the annualized loss expectancy (ALE) of $300k and the risk is within the organization's risk appetite, it is more cost-effective to accept the risk rather than implement a costly control.

10
MCQmedium

Based on the exhibit, which of the following risks is MOST indicated by the policy configuration?

A.Exposure of web server to untrusted networks without encryption
B.Data exfiltration via MySQL from the internet
C.Unauthorized SSH access to the internal network
D.Policy misconfiguration causing low hits on rule 3
AnswerA

HTTP traffic is unencrypted and allowed from any source.

Why this answer

The policy configuration shows a rule allowing inbound HTTP/HTTPS traffic from the internet to a web server without any associated encryption requirement (e.g., no TLS enforcement or VPN). This directly exposes the web server to untrusted networks, making it vulnerable to man-in-the-middle attacks and data interception, which is the most significant risk indicated.

Exam trap

The trap here is that candidates focus on the specific service (HTTP/HTTPS) and overlook the lack of encryption as the primary risk, instead considering data exfiltration or unauthorized access as more obvious threats, but the policy explicitly permits unencrypted traffic from untrusted networks.

How to eliminate wrong answers

Option B is wrong because data exfiltration via MySQL from the internet would require a specific rule allowing MySQL traffic (port 3306) from the internet, which is not shown in the exhibit; the policy only permits HTTP/HTTPS. Option C is wrong because unauthorized SSH access to the internal network would require a rule allowing SSH traffic (port 22) from the internet, which is absent; SSH is typically blocked or restricted. Option D is wrong because policy misconfiguration causing low hits on rule 3 is a performance or tuning issue, not a risk; the question asks for the most indicated risk, and low hits do not represent a security exposure.

11
MCQmedium

A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?

A.Compensating control such as additional monitoring
B.Preventive control such as patching the vulnerability
C.Corrective control such as backup restoration
D.Detective control such as log monitoring
AnswerB

Patching removes the vulnerability, preventing exploitation.

Why this answer

Preventive controls aim to stop the risk event from occurring; patching is a classic preventive control.

12
MCQhard

An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?

A.User training
B.Change management
C.Vulnerability scanning
D.Access review
AnswerB

Change management is critical to control the implementation and avoid negative impacts.

Why this answer

Change management ensures that changes to systems are controlled, tested, and approved to prevent unintended disruptions or security gaps. It is essential during control implementation.

13
MCQhard

An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?

A.The residual risk is still critical
B.Controls are effective in reducing risk to a lower level
C.The inherent risk was overestimated
D.Controls are ineffective because residual risk is still above zero
AnswerB

Significant reduction shows effectiveness.

Why this answer

The reduction from 20 to 8 indicates the controls are effective in reducing risk.

14
MCQmedium

During a cost-benefit analysis for a new control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce risk by 80% and will cost $150,000 annually to operate. What is the net benefit of implementing the control?

A.$400,000
B.$100,000
C.$350,000
D.$250,000
AnswerD

Net benefit = $400,000 - $150,000 = $250,000.

Why this answer

ALE reduction is 80% of $500,000 = $400,000. Net benefit = ALE reduction - annual control cost = $400,000 - $150,000 = $250,000.

15
MCQmedium

A risk practitioner is categorizing IT risks for a manufacturing company. Which of the following risks would be classified as an 'operational' IT risk?

A.Risk of financial loss from a ransomware payment
B.Risk of non-compliance with GDPR for customer data stored in the EU
C.Risk of production line downtime due to a server failure
D.Risk of reputational damage from a data breach
AnswerC

Correct. This directly affects operational processes.

Why this answer

Operational IT risks relate to the day-to-day functioning of IT systems and processes. Production line downtime due to a system failure directly impacts operations.

16
MCQeasy

Which of the following is a detective control?

A.Data encryption
B.Intrusion detection system
C.Backup and restore
D.Firewall
AnswerB

Correct; IDS detects intrusions after they occur.

Why this answer

Detective controls identify risk events that have occurred. Intrusion detection systems (IDS) monitor network traffic for malicious activity and alert administrators.

17
MCQeasy

Which of the following is the most appropriate frequency for operational IT risk reporting to IT management?

A.Annually
B.Quarterly
C.Weekly or monthly
D.Semi-annually
AnswerC

Operational risk reporting is frequent to support timely decisions.

Why this answer

Operational risk reporting is typically provided on a weekly or monthly basis to IT management to support day-to-day decision-making.

18
MCQmedium

In third-party risk management, which of the following is MOST indicative of a vendor's control effectiveness for a critical vendor?

A.SOC 2 Type II report
B.Contractual security requirements
C.Vendor's self-assessment questionnaire
D.Vendor's marketing materials
AnswerA

This is an independent audit that tests controls over time, providing strong evidence.

Why this answer

A SOC 2 Type II report is the most indicative of a vendor's control effectiveness because it provides an independent auditor's opinion on the design and operating effectiveness of controls over a specified period (typically 6–12 months). For a critical vendor, this third-party attestation offers objective evidence that security and privacy controls are actually working, not just promised.

Exam trap

The trap here is that candidates often confuse contractual requirements or self-assessments as sufficient evidence of control effectiveness, but the exam tests that only an independent, audited report like SOC 2 Type II provides the objective assurance needed for critical vendors.

How to eliminate wrong answers

Option B is wrong because contractual security requirements are only promises and obligations, not evidence that controls are actually implemented or effective; they lack independent verification. Option C is wrong because a vendor's self-assessment questionnaire is subjective, unaudited, and prone to bias or incomplete responses, providing no assurance of actual control operation. Option D is wrong because marketing materials are promotional content designed to sell services, not factual evidence of control effectiveness, and they contain no technical or operational details.

19
Multi-Selectmedium

Which THREE of the following are effective techniques for identifying IT risks?

Select 3 answers
A.Root cause analysis
B.Cost-benefit analysis
C.Brainstorming
D.Vulnerability scanning
E.SWOT analysis
AnswersC, D, E

Brainstorming is a common technique for risk identification.

Why this answer

Brainstorming is a structured group technique that leverages the collective expertise of stakeholders to identify a wide range of IT risks, including emerging threats and vulnerabilities that may not be captured by automated tools. It is effective because it encourages creative thinking and surfaces risks related to business processes, third-party dependencies, and human factors that are often missed by purely technical assessments.

Exam trap

The trap here is confusing risk identification techniques with risk analysis or risk treatment techniques, leading candidates to select root cause analysis (a post-incident technique) or cost-benefit analysis (a decision-making tool) instead of recognizing that brainstorming, vulnerability scanning, and SWOT analysis are all valid methods for initially identifying risks.

20
Multi-Selectmedium

A financial institution is identifying IT risks associated with a new mobile banking application. Which TWO threat modeling techniques are best suited for this scenario? (Select two.)

Select 2 answers
A.STRIDE
B.PASTA
C.VAST
D.TRIKE
E.OWASP Top 10
AnswersA, B

STRIDE is a classic threat modeling technique that categorizes threats for applications.

Why this answer

STRIDE is ideal for application threat modeling, and PASTA provides a risk-centric approach for critical applications.

21
MCQhard

An organization is implementing a data classification scheme. Which of the following classification categories would be MOST effective for identifying risks related to intellectual property theft?

A.Restricted
B.Internal
C.Confidential
D.Public
AnswerC

Confidential is the standard category for sensitive business information.

Why this answer

Confidential data is the classification category specifically designed to protect sensitive information that, if disclosed, could cause significant harm to the organization, including intellectual property theft. In a data classification scheme, 'Confidential' typically applies to trade secrets, source code, and proprietary designs, making it the most effective category for identifying and mitigating risks related to IP theft.

Exam trap

The trap here is that candidates often confuse 'Restricted' with 'Confidential' due to military/government classification hierarchies, but in a corporate context, 'Confidential' is the standard category for intellectual property, while 'Restricted' is typically reserved for highly sensitive data like PII or PHI under GDPR or HIPAA.

How to eliminate wrong answers

Option A is wrong because 'Restricted' is often a higher classification than Confidential (e.g., in government or military contexts) and may be too narrow or not aligned with standard corporate IP protection tiers, potentially causing overclassification and operational friction. Option B is wrong because 'Internal' data is intended for internal use but does not imply the high level of sensitivity required for intellectual property; it typically covers general business communications and policies, not trade secrets. Option D is wrong because 'Public' data is explicitly intended for unrestricted disclosure and poses no risk of IP theft, as it is already in the public domain.

22
Multi-Selecthard

Which THREE of the following are common challenges when implementing a risk monitoring dashboard? (Select exactly three.)

Select 3 answers
A.Data quality and consistency issues
B.Lack of clear ownership for monitoring
C.Reduced need for manual controls
D.Overwhelming amount of information displayed
E.Improved decision-making
AnswersA, B, D

Common due to multiple sources.

Why this answer

Data quality and consistency issues (A) are a common challenge because risk monitoring dashboards aggregate data from multiple sources, each with its own format, timeliness, and accuracy. Inconsistent data leads to unreliable metrics and false alarms, undermining the dashboard's purpose of providing a single source of truth for risk posture.

Exam trap

The trap here is confusing the challenges of implementation with the benefits or outcomes of the dashboard, leading candidates to select 'reduced need for manual controls' or 'improved decision-making' as challenges instead of recognizing them as positive results.

23
MCQeasy

An organization is implementing a new access control system. Which of the following should be included in the control implementation plan?

A.Annual cost of the control only
B.Key Risk Indicators (KRIs) for the control
C.Project milestones, training schedule, and documentation updates
D.Risk assessment results
AnswerC

These are essential components of an implementation plan.

Why this answer

A control implementation plan should cover all aspects of deployment, including project management, change management, user training, and documentation updates.

24
MCQmedium

A financial institution has implemented a continuous monitoring solution for its core banking application. The monitoring team receives an alert indicating that the average response time for a critical transaction has exceeded the threshold for the past 15 minutes. The transaction volume during this period is within normal range. What should be the FIRST step in the incident response process?

A.Contact the application vendor to report a potential performance issue.
B.Verify the alert by reviewing real-time logs and metrics, then assess the potential impact on business operations.
C.Compare current response time with historical baselines to determine if this is an anomaly.
D.Escalate the alert to the IT operations manager and the application owner immediately.
AnswerB

Verification and impact assessment are the correct first steps.

Why this answer

The first step in incident response is to validate the alert by reviewing real-time logs and metrics to confirm it is not a false positive, and then assess the potential impact on business operations. This aligns with the NIST SP 800-61 incident response lifecycle, where detection and analysis precede containment or escalation. Without verification, subsequent actions like vendor contact or escalation may be premature and waste resources.

Exam trap

The trap here is that candidates may confuse 'analysis' (comparing to baselines) or 'escalation' as the first step, but CRISC emphasizes that verification and impact assessment must precede any further action to avoid wasted effort on false alarms.

How to eliminate wrong answers

Option A is wrong because contacting the application vendor should occur only after the alert is verified and the issue is confirmed to be a software defect, not as a first step. Option C is wrong because comparing with historical baselines is part of analysis but should follow verification of the current alert data; it is not the immediate first action. Option D is wrong because immediate escalation without verification risks unnecessary alarm and misdirected effort; escalation is appropriate only after confirming a genuine incident and assessing its severity.

25
MCQeasy

Which of the following is the PRIMARY benefit of using a risk register for monitoring?

A.Provides real-time alerts.
B.Centralized repository of all risks.
C.Eliminates the need for KRIs.
D.Automates control testing.
AnswerB

A risk register provides a single source of truth for risk information.

Why this answer

The primary benefit of a risk register for monitoring is that it serves as a centralized repository for all identified risks, enabling consistent tracking, prioritization, and reporting. Option B is correct. Option A is incorrect because risk registers are typically static documents that do not provide real-time alerts; real-time monitoring is achieved through other tools like dashboards or automated alerts.

Option C is incorrect because risk registers and Key Risk Indicators (KRIs) are complementary; KRIs provide leading indicators, while the register documents risks and controls. Option D is incorrect because a risk register does not automate control testing; it records control information but testing is a separate process.

26
MCQmedium

A healthcare organization operates a legacy electronic health record (EHR) system that is manually monitored for access anomalies by a small IT team. The organization is planning to migrate to a new cloud-based EHR with integrated logging and monitoring. However, due to budget constraints, the migration will take two years. In the interim, the risk manager wants to improve monitoring for unauthorized access to patient data. The current manual process involves weekly log reviews, but recent audits have identified instances of delayed detection (up to two weeks) and missed incidents. The IT team can dedicate only 10 additional hours per week for monitoring. What is the best approach to enhance monitoring during the transition period?

A.Outsource the monitoring to a third-party managed security service provider.
B.Implement a full automation suite for access monitoring immediately.
C.Use a phased risk-based approach, prioritizing monitoring of high-risk areas such as privileged accounts and sensitive patient data.
D.Accept the current monitoring state as adequate given the upcoming migration.
AnswerC

Targets the highest risks with limited resources; feasible and effective.

Why this answer

A phased approach focusing on high-risk areas (e.g., privileged accounts, sensitive data) optimizes limited resources. Full automation (Option B) is too costly; outsourcing (Option A) may have data privacy issues; accepting the state (Option D) is irresponsible given audit findings.

27
MCQmedium

In third-party risk management, which of the following is typically used for initial onboarding assessment of a vendor?

A.Contract compliance review
B.Security questionnaire
C.SOC 2 Type II report
D.Shared intelligence platform feed
AnswerB

A security questionnaire is a standard initial assessment tool.

Why this answer

Security questionnaires are commonly used during initial vendor assessment to gather information about the vendor's security posture.

28
Multi-Selectmedium

Which TWO of the following are valid risk scenarios that should be documented during IT risk identification?

Select 2 answers
A.An employee may inadvertently share confidential data via email due to lack of data classification training.
B.The organization must comply with GDPR requirements for data protection.
C.An external attacker may exploit weak password policies to gain access to the email system and exfiltrate sensitive data.
D.The database server has not been patched for critical vulnerabilities.
E.The IT department will implement multi-factor authentication to reduce the risk of unauthorized access.
AnswersA, C

This is a risk scenario with threat, vulnerability, and impact.

Why this answer

It describes a specific risk scenario: an employee inadvertently sharing confidential data via email due to lack of data classification training. This is a valid risk scenario as it identifies a threat (human error), a vulnerability (insufficient training), and a potential impact (data leakage). In IT risk identification, scenarios must be concrete and actionable, not just statements of compliance or controls.

Exam trap

The trap here is that candidates often mistake compliance requirements (option B) or control implementations (option E) for risk scenarios, but CRISC requires scenarios to describe specific threat events with a clear cause-effect chain, not static states or planned actions.

29
MCQmedium

A financial services company uses a legacy mainframe system for core banking transactions. The risk assessment identifies that the system does not support modern encryption standards, and data is transmitted in clear text over internal networks. The IT department has proposed implementing network segmentation and encryption at the application layer using a middleware solution. However, the cost is high and the project would take 18 months. Meanwhile, the company is planning to migrate to a new core system in two years. The risk appetite for data confidentiality is low. As the risk practitioner, what is the MOST appropriate risk response?

A.Implement compensating controls such as strict network access controls and monitoring.
B.Transfer the risk by purchasing cyber insurance covering data breach incidents.
C.Accept the risk because the system will be replaced in two years.
D.Avoid the risk by accelerating the migration to the new system within 18 months.
AnswerA

Compensating controls reduce risk immediately.

Why this answer

The correct response is to implement compensating controls such as strict network access controls and monitoring. Given the low risk appetite for data confidentiality, the 18-month delay for the middleware solution is unacceptable, and the two-year migration timeline leaves a significant exposure window. Compensating controls like VLAN segmentation, ACLs, and continuous traffic monitoring can reduce the likelihood of exploitation of the clear-text transmission without requiring changes to the legacy mainframe itself.

Exam trap

The trap here is that candidates may confuse 'accepting the risk' with a valid response when a migration is planned, but the low risk appetite for data confidentiality makes acceptance inappropriate, and they may overlook that compensating controls can be implemented quickly and cost-effectively to reduce exposure.

How to eliminate wrong answers

Option B is wrong because cyber insurance transfers financial risk but does not reduce the likelihood or impact of a data breach; the low risk appetite for confidentiality requires a control that protects the data, not just compensates for losses. Option C is wrong because accepting the risk for two years violates the stated low risk appetite for data confidentiality, as clear-text transmission over internal networks is a direct exposure that could lead to a breach. Option D is wrong because accelerating the migration to 18 months is not feasible without a detailed project plan and budget, and it still leaves a gap; moreover, 'avoiding' risk by accelerating does not address the immediate exposure during the migration period.

30
MCQeasy

Which threat modeling technique is specifically designed to be integrated into Agile and DevSecOps processes, providing a visual and simple approach?

A.VAST
B.TRIKE
C.PASTA
D.STRIDE
AnswerA

Correct. VAST (Visual Agile and Simple Threat) is built for DevSecOps and Agile workflows.

Why this answer

VAST (Visual Agile and Simple Threat) is tailored for Agile and DevSecOps environments, emphasizing simplicity and visual representation.

31
MCQmedium

An IT risk manager is preparing a report for the board of directors. Which of the following content elements is most important for strategic risk reporting?

A.Weekly vulnerability scan results
B.IT risk integration with enterprise risk management
C.List of all vendor risk assessments
D.Detailed control performance metrics
AnswerB

The board needs to understand how IT risk fits into the overall enterprise risk profile.

Why this answer

Strategic risk reporting to the board requires a high-level view that aligns IT risk with enterprise objectives. Option B is correct because it demonstrates how IT risk is integrated into the broader enterprise risk management (ERM) framework, enabling the board to understand the business impact of IT risks. This integration is essential for strategic decision-making, as it connects technical risk data to organizational goals and risk appetite.

Exam trap

The trap here is that candidates often confuse operational reporting (e.g., vulnerability scans, control metrics) with strategic reporting, failing to recognize that the board requires a consolidated, business-aligned view of risk rather than detailed technical data.

How to eliminate wrong answers

Option A is wrong because weekly vulnerability scan results are operational, tactical data that is too granular and frequent for board-level strategic reporting; the board needs aggregated risk trends, not raw scan outputs. Option C is wrong because listing all vendor risk assessments is an operational detail that does not convey strategic risk posture or business impact; the board requires a summary of key vendor risks and their effect on enterprise objectives. Option D is wrong because detailed control performance metrics, such as specific control failure rates, are more appropriate for management and audit reporting, not for the board's strategic view, which focuses on risk exposure and mitigation effectiveness at a macro level.

32
MCQmedium

A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time production monitoring. Which risk is most directly introduced by this convergence?

A.Higher licensing costs for industrial software
B.Expanded attack path from IT to OT systems
C.Increased complexity of data analytics
D.Reduced operational efficiency due to network latency
AnswerB

Correct. IT/OT convergence creates new attack vectors that can compromise safety-critical systems.

Why this answer

Connecting OT networks to IT networks expands the attack surface, allowing threats from the corporate network to reach ICS/SCADA systems, which were previously isolated.

33
MCQhard

An organization's IT risk team is promoting a risk-aware culture. Which initiative is most likely to encourage employees to report security incidents without fear?

A.Establishing a no-blame incident reporting policy
B.Publishing quarterly incident statistics
C.Increasing the frequency of security awareness training
D.Implementing automated incident detection
AnswerA

A no-blame policy fosters a culture of reporting.

Why this answer

A no-blame incident reporting policy directly addresses the psychological barrier of fear of reprisal, which is the primary reason employees hesitate to report security incidents. By explicitly stating that reporters will not face disciplinary action for unintentional errors or omissions, the organization fosters psychological safety and encourages timely reporting, which is critical for effective risk response.

Exam trap

The trap here is that candidates may confuse 'increasing awareness training' (Option C) with addressing fear, when in fact training alone does not remove the organizational culture of blame that discourages reporting.

How to eliminate wrong answers

Option B is wrong because publishing quarterly incident statistics provides transparency and awareness but does not address the fear of personal consequences that prevents employees from reporting incidents. Option C is wrong because increasing the frequency of security awareness training improves knowledge and vigilance but does not remove the fear of blame or punishment for reporting an incident. Option D is wrong because implementing automated incident detection improves technical detection capabilities but does not influence human behavior or the cultural willingness to report incidents voluntarily.

34
MCQmedium

An organization is planning to deploy an IoT solution in a manufacturing plant. The risk manager is asked to identify risks associated with the integration of IoT devices into the plant network. Which of the following techniques would be MOST effective for identifying both technical and operational risks?

A.Conduct a SWOT analysis of the IoT project
B.Facilitate a brainstorming session with IT, operational technology (OT), and safety teams
C.Interview the plant manager about operational challenges
D.Send a risk questionnaire to employees
AnswerB

Brainstorming with diverse teams identifies both technical and operational risks.

Why this answer

A brainstorming session that includes IT, operational technology (OT), and safety teams is the most effective technique because IoT integration creates a convergence of traditional IT risks (e.g., network segmentation, patch management) with OT-specific risks (e.g., real-time control system integrity, safety interlocks) and physical safety hazards. This cross-functional approach surfaces technical risks like unpatched firmware vulnerabilities in programmable logic controllers (PLCs) and operational risks such as unplanned downtime due to misconfigured device-to-controller communication protocols (e.g., Modbus/TCP without authentication).

Exam trap

ISACA often tests the misconception that a single-stakeholder interview or a generic analysis tool is sufficient for risk identification in converged IT/OT environments, when in reality the most effective technique requires collaborative input from all relevant technical and operational domains to capture the full spectrum of risks.

How to eliminate wrong answers

Option A is wrong because a SWOT analysis is a high-level strategic tool that identifies strengths, weaknesses, opportunities, and threats but lacks the granularity to uncover specific technical risks like insecure MQTT broker configurations or operational risks like loss of safety-critical sensor data. Option C is wrong because interviewing only the plant manager provides a narrow, managerial perspective that misses deep technical risks from OT engineers (e.g., legacy fieldbus vulnerabilities) and safety risks from safety engineers (e.g., failure modes of IoT-triggered emergency stops). Option D is wrong because a risk questionnaire sent to employees is a passive, one-way data collection method that cannot dynamically probe or clarify complex IoT-specific risks such as latency-induced control loop instability or interference between Wi-Fi and industrial wireless protocols like WirelessHART.

35
MCQeasy

An organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?

A.Eliminates subjectivity in risk assessment
B.Provides comparable results across organizations
C.Quick and easy to communicate
D.Produces financially meaningful results
AnswerC

Heat maps are simple to create and understand, facilitating communication.

Why this answer

Qualitative risk analysis using heat maps is quick to perform and easy to communicate to stakeholders, making it the primary advantage. The other options are not primary advantages of this method.

36
Multi-Selectmedium

When developing realistic risk scenarios, which THREE components are essential according to the ISACA risk scenario template?

Select 3 answers
A.Threat actor
B.Asset/resource
C.Mitigation cost
D.Threat event
E.Detection speed
AnswersA, B, D

The threat actor is the entity that initiates the threat.

Why this answer

The ISACA risk scenario template includes threat actor, threat event, and asset/resource as essential components. Timing, detection, and response are also included but are not always considered essential for the basic scenario.

37
MCQeasy

A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?

A.Avoidance
B.Transfer
C.Acceptance
D.Mitigation
AnswerC

Acceptance is appropriate when risk is low impact and cannot be mitigated or transferred easily.

Why this answer

Acceptance is the most appropriate response because the vulnerability exists in a legacy application that supports a non-critical business process and is used by a small number of users. The cost and operational impact of patching or replacing the application outweigh the risk, making it acceptable to operate with the known vulnerability under formal risk acceptance.

Exam trap

The trap here is that candidates often choose mitigation by default, failing to recognize that when a vulnerability cannot be patched and the asset is low-impact, formal acceptance is the correct risk response per the CRISC framework.

How to eliminate wrong answers

Option A is wrong because avoidance would require removing the application or the process entirely, which is unnecessary for a non-critical process with limited user exposure. Option B is wrong because transfer (e.g., via cyber insurance or outsourcing) does not eliminate the technical vulnerability; it only shifts financial liability, and the underlying risk remains in the application. Option D is wrong because mitigation (e.g., applying a vendor patch, implementing a WAF rule, or hardening the host) is not immediately feasible for a legacy application that cannot be patched, and the low business impact does not justify the effort.

38
Multi-Selectmedium

Which TWO of the following are primary purposes of risk and control monitoring? (Choose two.)

Select 2 answers
A.To identify opportunities for implementing new controls.
B.To ensure compliance with all regulatory requirements.
C.To verify that controls are operating as intended.
D.To provide assurance to stakeholders on risk management.
E.To eliminate all residual risk.
AnswersC, D

Verification of control effectiveness is a core monitoring objective.

Why this answer

The primary purpose of risk and control monitoring is to verify that controls are operating as intended. This involves ongoing testing and observation to ensure that control activities are effectively mitigating risks to the desired level. Without this verification, an organization cannot confirm that its risk responses are actually working.

Exam trap

The trap here is that candidates often confuse the primary purpose of monitoring (verifying control effectiveness) with secondary or broader objectives like identifying new controls or ensuring full compliance, leading them to select options that are not the core focus of risk and control monitoring.

39
MCQmedium

A company is implementing a new access control system. According to the project plan, user training will be delivered after the system goes live. What change management issue does this present?

A.Training after go-live ensures the system is fully operational
B.Training after go-live is more effective because users have context
C.Training after go-live reduces the project budget
D.Training after go-live may lead to user errors and security incidents
AnswerD

Without prior training, users may misuse the system, increasing risk.

Why this answer

Training should ideally be delivered before go-live to ensure users can operate the system securely. Delaying training increases the risk of errors and security incidents.

40
Multi-Selectmedium

An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?

Select 3 answers
A.Using consistent risk metrics and terminology across IT and enterprise levels
B.Aligning IT risk appetite with enterprise risk appetite
C.Reporting IT risk as a component of broader operational risk
D.Maintaining a separate IT risk register not shared with ERM
E.Reporting IT risks only to the CIO without board visibility
AnswersA, B, C

Consistency enables aggregation and comparison.

Why this answer

Using consistent risk metrics and terminology across IT and enterprise levels ensures that IT risks are communicated in a language that the broader ERM framework understands, enabling aggregation and comparison. This alignment prevents siloed risk assessments and supports a unified view of risk exposure across the organization, which is a foundational requirement for integrating IT risk into ERM.

Exam trap

The trap here is that candidates may think maintaining a separate IT risk register is acceptable for specialized IT risks, but CRISC emphasizes that integration requires sharing and aligning risk information across all levels, not isolating it.

41
Matchingmedium

Match each risk assessment method to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses numerical values like ALE and SLE

Uses ordinal scales like high/medium/low

Combines numeric values with qualitative scales

Evaluates risks based on hypothetical events

Why these pairings

Correct matches: Quantitative → numerical values/formulas; Qualitative → subjective categories; Semi-quantitative → hybrid numeric/qualitative. Common confusions include swapping these definitions.

42
MCQhard

During a quarterly risk review, it is discovered that a previously accepted risk has materialized due to a change in the external environment. What is the MOST appropriate response?

A.Report to regulators.
B.Increase insurance coverage.
C.Accept the impact.
D.Re-evaluate the risk treatment plan.
AnswerD

A materialized risk indicates the original plan is no longer adequate, requiring reassessment.

Why this answer

When a previously accepted risk materializes due to a change in the external environment, the risk treatment plan is no longer valid. The most appropriate response is to re-evaluate the risk treatment plan (Option D) because the original acceptance decision was based on assumptions that have now changed. This ensures that new controls or alternative treatments are considered to address the realized risk effectively.

Exam trap

The trap here is that candidates may confuse 'accept the impact' (Option C) with the original acceptance decision, failing to recognize that a materialized risk due to environmental change invalidates the prior acceptance and requires a new treatment evaluation.

How to eliminate wrong answers

Option A is wrong because reporting to regulators is not the immediate or most appropriate response; regulatory reporting is typically required only when specific compliance obligations are triggered, not for every materialized risk. Option B is wrong because increasing insurance coverage is a risk transfer mechanism that may be considered after re-evaluation, but it does not address the root cause or immediate impact of the realized risk. Option C is wrong because accepting the impact implies no further action, which ignores the need to reassess the risk treatment in light of the changed environment and potentially prevent future occurrences.

43
MCQeasy

A company is migrating its customer database to a public cloud provider. During the planning phase, which of the following is the MOST effective approach to identify risks specific to this migration?

A.Review industry risk reports for similar migrations
B.Rely on the cloud provider's published risk documentation
C.Perform a compliance checklist review
D.Conduct a threat modeling exercise focusing on the cloud architecture
AnswerD

Threat modeling identifies environment-specific threats like data exposure and misconfigurations.

Why this answer

Conducting a threat modeling exercise (D) is the most effective approach because it systematically identifies threats, vulnerabilities, and attack vectors specific to the cloud architecture, data flow, and trust boundaries of the migration. Unlike generic reviews, threat modeling (e.g., using STRIDE or PASTA) directly addresses the unique risks of moving a customer database to a public cloud, such as misconfigured access controls, insecure APIs, or data exposure during transit.

Exam trap

The trap here is that candidates often choose a compliance checklist (C) or industry reports (A) because they seem thorough and authoritative, but the CRISC exam emphasizes that risk identification must be proactive and architecture-specific, not reactive or generic.

How to eliminate wrong answers

Option A is wrong because industry risk reports provide aggregated, historical data that may not reflect the specific architecture, provider, or configuration of this migration, leading to missed context-sensitive risks. Option B is wrong because relying solely on the cloud provider's published risk documentation shifts responsibility and fails to account for the customer's own configuration errors, shared responsibility model gaps, or application-layer vulnerabilities. Option C is wrong because a compliance checklist review only verifies adherence to regulatory standards (e.g., GDPR, PCI DSS) but does not identify technical threats like privilege escalation, data leakage, or denial-of-service risks unique to the cloud deployment.

44
Multi-Selectmedium

An organization is designing a vendor risk management program. Which TWO of the following are essential components of ongoing vendor monitoring? (Select TWO)

Select 2 answers
A.Review of contract terms
B.Penetration testing by the vendor
C.Initial onboarding security questionnaire
D.Continuous monitoring via shared threat intelligence platforms
E.Annual reassessment of vendor risk
AnswersD, E

Continuous monitoring using external intel is an ongoing practice.

Why this answer

Continuous monitoring via shared threat intelligence platforms (Option D) is essential because it provides real-time visibility into emerging threats and vulnerabilities that may affect the vendor's environment. This allows the organization to proactively adjust risk posture without waiting for periodic reviews, aligning with the CRISC principle of ongoing risk response.

Exam trap

The trap here is that candidates often mistake periodic activities like annual reassessment (Option E) as the only ongoing monitoring component, but CRISC emphasizes that continuous monitoring includes real-time threat intelligence, while annual reassessment is a scheduled review, not continuous.

45
MCQmedium

During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control will cost $100,000 annually and is expected to reduce the ALE by 80%. What is the net benefit of implementing this control?

A.$100,000
B.$300,000
C.$400,000
D.$500,000
AnswerB

Reduction of $400,000 minus cost of $100,000 equals $300,000 net benefit.

Why this answer

The current annual loss expectancy (ALE) is $500,000. An 80% reduction lowers the ALE by $400,000, resulting in a new ALE of $100,000. The annual control cost is $100,000, so the net benefit is the reduction in ALE ($400,000) minus the control cost ($100,000), which equals $300,000.

Exam trap

CRISC often tests the distinction between gross reduction in ALE and net benefit, tricking candidates into forgetting to subtract the annual control cost from the ALE reduction.

How to eliminate wrong answers

Option A is wrong because $100,000 represents only the annual control cost, not the net benefit after accounting for the ALE reduction. Option C is wrong because $400,000 is the gross reduction in ALE (80% of $500,000) but fails to subtract the $100,000 control cost. Option D is wrong because $500,000 is the original ALE before any control is applied, ignoring both the reduction and the cost of the control.

46
Multi-Selecthard

An organization assesses a risk of intellectual property theft through email exfiltration. They decide to enforce DLP controls, purchase a cyber liability policy, and officially accept the residual risk after controls. Which THREE risk response options are demonstrated?

Select 3 answers
A.Avoid
B.Reduce
C.Mitigate
D.Accept
E.Transfer
AnswersC, D, E

DLP controls mitigate the risk.

Why this answer

Enforcing DLP controls directly reduces the likelihood of intellectual property theft by monitoring and blocking unauthorized email exfiltration, which is a classic risk mitigation (reduce) action. Purchasing a cyber liability policy transfers the financial impact of a breach to an insurer, demonstrating risk transfer. Formally accepting the residual risk after controls acknowledges that some risk remains, which is risk acceptance.

Exam trap

ISACA CRISC exams often test the distinction between 'mitigate' and 'reduce' as synonyms, but the CRISC framework uses 'mitigate' as the official term, so candidates may incorrectly select 'reduce' as a separate valid option when it is actually a distractor.

47
MCQmedium

Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?

A.Failed authentication spike
B.Increased number of successful logins
C.Low patch compliance
D.High mean time to resolve incidents
AnswerA

A sudden increase in failures is a common KRI for credential attacks.

Why this answer

A failed authentication spike is a leading indicator because it directly signals an increase in attempted unauthorized access, often from credential stuffing or brute-force attacks. Unlike lagging indicators that measure past incidents, this metric provides early warning that the risk of a credential-based attack is rising, allowing proactive controls like account lockout policies or CAPTCHA challenges to be implemented before a breach occurs.

Exam trap

The trap here is that candidates confuse leading indicators (which predict future risk) with lagging indicators (which measure past events), leading them to choose options like high mean time to resolve incidents or low patch compliance, which are not directly tied to credential-based attack risk.

How to eliminate wrong answers

Option B is wrong because an increased number of successful logins is not a leading indicator of credential-based attack risk; it could indicate legitimate user activity or a successful compromise, but it does not signal an impending attack. Option C is wrong because low patch compliance is a general security risk indicator, not specific to credential-based attacks; it relates to vulnerability management rather than authentication attempts. Option D is wrong because high mean time to resolve incidents is a lagging indicator of incident response effectiveness, not a leading indicator of attack risk; it measures post-incident performance, not pre-attack conditions.

48
MCQmedium

After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?

A.Formally accept the residual risk
B.Re-assess the inherent risk
C.Reduce current controls to lower costs
D.Implement additional controls despite the cost
AnswerA

Acceptance with sign-off is appropriate when mitigation is too costly.

Why this answer

When the residual risk remains above the risk tolerance but the cost of further mitigation exceeds the potential loss, the most appropriate step is to formally accept the residual risk. This decision is based on a cost-benefit analysis showing that additional controls are not economically justified. The risk owner documents the acceptance, acknowledging the remaining exposure within the organization's risk appetite framework.

Exam trap

The CRISC exam often tests the misconception that residual risk must always be reduced to zero or below tolerance regardless of cost, but the correct approach is to accept risk when further mitigation is economically unjustified.

How to eliminate wrong answers

Option B is wrong because re-assessing inherent risk does not address the fact that residual risk is already calculated and above tolerance; inherent risk is the starting point, not the solution to an economic decision. Option C is wrong because reducing current controls would likely increase residual risk further, moving it even farther from tolerance and potentially violating compliance or security baselines. Option D is wrong because implementing additional controls despite the cost violates the fundamental principle of cost-benefit analysis in risk management; it would waste resources without proportional risk reduction.

49
Multi-Selecteasy

Which TWO of the following are examples of inherent risk?

Select 2 answers
A.Risk of unauthorized access due to weak password policy
B.Risk of data breach due to unencrypted sensitive data
C.Residual risk after implementing firewalls
D.Risk appetite defined by the board
E.Risk reduction achieved by multifactor authentication
AnswersA, B

This is a risk that exists without controls.

Why this answer

Inherent risk is the risk that exists in the absence of any controls or mitigations. Option A describes the risk of unauthorized access due to a weak password policy, which is a vulnerability present before any compensating controls (like multifactor authentication) are applied. Option B describes the risk of a data breach due to unencrypted sensitive data, which is a direct exposure that exists before encryption controls are implemented.

Both represent the raw, uncontrolled risk level.

Exam trap

The trap here is confusing inherent risk with residual risk or control effectiveness; candidates often pick options that describe the result of controls (like risk reduction) or the state after controls (residual risk) instead of the raw, uncontrolled exposure.

50
Multi-Selectmedium

Which TWO of the following are key risk identification techniques used to identify threats and vulnerabilities in IT systems? (Select exactly 2.)

Select 2 answers
A.Risk mitigation
B.Vulnerability scanning
C.Risk transfer
D.Threat modeling
E.Access control implementation
AnswersB, D

Vulnerability scanning identifies known vulnerabilities.

Why this answer

Vulnerability scanning is a key risk identification technique that systematically probes IT systems for known vulnerabilities, such as unpatched software or misconfigurations, using tools like Nessus or OpenVAS. It directly identifies weaknesses that could be exploited by threats, making it essential for the risk identification phase.

Exam trap

The trap here is confusing risk identification techniques (like scanning and modeling) with risk response strategies (like mitigation, transfer, or control implementation), leading candidates to select options that are actually post-identification actions.

51
MCQhard

A risk assessment for a healthcare organization reveals a high likelihood of data breaches due to weak encryption on portable devices. The organization decides to deploy full-disk encryption and enforce multi-factor authentication. Which risk response strategy is being applied?

A.Transfer
B.Acceptance
C.Avoidance
D.Mitigation
AnswerD

Controls reduce risk.

Why this answer

Deploying full-disk encryption and multi-factor authentication directly reduces the likelihood and/or impact of data breaches from weak encryption on portable devices. This is the definition of risk mitigation — applying controls to lower risk to an acceptable level. The organization is actively reducing the vulnerability, not transferring, accepting, or avoiding the risk.

Exam trap

The trap here is that candidates often confuse 'avoidance' with 'mitigation' — avoidance eliminates the risk by discontinuing the activity (e.g., banning portable devices), while mitigation reduces the risk through controls like encryption and MFA.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial burden of a loss to a third party (e.g., cyber insurance), not implementing technical controls like encryption or MFA. Option B is wrong because risk acceptance means acknowledging the risk and taking no proactive action to reduce it, which contradicts the decision to deploy new security measures. Option C is wrong because risk avoidance would mean ceasing the use of portable devices entirely or eliminating the process that creates the risk, not strengthening the protection on those devices.

52
MCQmedium

An organization is assessing risks related to a third-party cloud provider. Which of the following is the BEST source of threat intelligence for identifying threats targeting the cloud infrastructure?

A.Government advisories
B.OSINT
C.Commercial feeds
D.ISACs
AnswerD

ISACs provide relevant, timely threat intelligence shared within the industry.

Why this answer

ISACs (Information Sharing and Analysis Centers) provide sector-specific threat intelligence and can share information about threats targeting cloud infrastructure relevant to the organization's industry.

53
Multi-Selecthard

A financial services firm is migrating critical applications to a public cloud. The architecture review board (ARB) is evaluating the solution architecture. Which THREE risks should the ARB prioritize for review?

Select 3 answers
A.Vendor lock-in due to proprietary services
B.Energy consumption of cloud data centers
C.Network bandwidth limitations
D.Shared responsibility model gaps
E.Data sovereignty compliance
AnswersA, D, E

Strategic risk affecting future flexibility and costs.

Why this answer

Data sovereignty (regulatory), shared responsibility model (security gaps), and vendor lock-in (strategic) are key cloud risks that the ARB should assess before implementation.

54
MCQeasy

Which of the following is the BEST practice for determining the frequency of control monitoring activities?

A.Standardize all controls to quarterly monitoring
B.Monitor only after a control failure is detected
C.Set frequency based solely on regulatory minimum requirements
D.Align monitoring frequency with risk level and control effectiveness assessment
AnswerD

Risk-based monitoring ensures resources are focused on higher risks.

Why this answer

Control monitoring frequency should be driven by the assessed risk level and the effectiveness of existing controls. High-risk areas or controls with lower effectiveness require more frequent monitoring to ensure timely detection of failures, while low-risk or highly effective controls can be monitored less often, optimizing resource allocation.

Exam trap

The trap here is that candidates often choose Option C (regulatory minimums) because they confuse compliance-driven minimums with best practice, failing to recognize that risk-based monitoring is more adaptive and effective for real-world risk management.

How to eliminate wrong answers

Option A is wrong because standardizing all controls to quarterly monitoring ignores the varying risk profiles and control effectiveness across different assets and processes, leading to either over-monitoring low-risk areas or under-monitoring high-risk ones. Option B is wrong because monitoring only after a control failure is detected is reactive and violates the principle of continuous monitoring; it allows failures to persist undetected until a breach occurs, increasing exposure. Option C is wrong because setting frequency based solely on regulatory minimum requirements ignores the organization's specific risk appetite and control performance, potentially leaving critical risks unmonitored between compliance cycles.

55
MCQhard

A company calculates the annualized loss expectancy (ALE) for a server failure as $150,000. After implementing a backup solution costing $20,000 per year, the ALE drops to $30,000. What is the annualized benefit of the control?

A.$100,000
B.$130,000
C.$120,000
D.$20,000
AnswerA

Correct; $120k reduction minus $20k cost = $100k.

Why this answer

Annualized benefit = reduction in ALE - annual control cost. Reduction in ALE = $150k - $30k = $120k. Benefit = $120k - $20k = $100k.

56
MCQeasy

Which of the following is an example of a 'configuration vulnerability' that should be identified during vulnerability assessment?

A.A buffer overflow in a custom application
B.An SQL injection flaw in a web form
C.Default administrative passwords left unchanged on a network device
D.Missing security patches on a server
AnswerC

Correct. This is a configuration issue.

Why this answer

A configuration vulnerability arises from improper system settings. Leaving default passwords unchanged is a classic configuration weakness.

57
MCQeasy

A risk manager notices that a key risk indicator (KRI) for failed login attempts has exceeded the threshold for three consecutive weeks. Which of the following should be the FIRST action?

A.Investigate the root cause of the increase.
B.Adjust the threshold to reduce false positives.
C.Report the breach to the senior management immediately.
D.Ignore the trend as a statistical anomaly.
AnswerA

First step is to investigate root cause.

Why this answer

When a KRI exceeds its threshold for multiple consecutive periods, the first action is to investigate the root cause to determine whether the increase indicates a genuine security issue (e.g., brute-force attack, credential stuffing) or a false positive. Jumping to reporting or threshold adjustment without understanding the underlying cause could lead to misallocation of resources or missed detection of an actual threat. This aligns with the CRISC principle that risk indicators must be validated before escalation or remediation.

Exam trap

The trap here is that candidates often choose immediate escalation (Option C) because they assume any threshold breach must be reported, but CRISC emphasizes that the first step is always to investigate and validate the indicator before escalating.

How to eliminate wrong answers

Option B is wrong because adjusting the threshold without first investigating the root cause may mask a real security incident, such as an ongoing brute-force attack, and violates the principle of maintaining KRI integrity. Option C is wrong because immediate reporting to senior management should occur only after the root cause is understood and the risk impact is assessed; premature reporting can cause unnecessary alarm or misinformed decisions. Option D is wrong because ignoring a three-week consistent trend as a statistical anomaly dismisses a potential pattern of malicious activity, such as a distributed password-spraying attack, which is a common oversight in risk monitoring.

58
MCQmedium

An organization deployed a new intrusion detection system (IDS) that generates many alerts. The security team is overwhelmed and has started ignoring some alerts. What is the BEST way to address this issue?

A.Implement a SIEM to filter and prioritize alerts.
B.Deactivate the IDS until it can be properly configured.
C.Tune the IDS to reduce false positive alerts.
D.Hire additional security analysts to handle the alert volume.
AnswerC

Reducing false positives improves efficiency.

Why this answer

Tuning the IDS to reduce false positive alerts directly addresses the root cause of alert fatigue: excessive noise from misconfigured or overly sensitive detection rules. By adjusting thresholds, signatures, and exclusion lists, the security team can focus on genuine threats without being overwhelmed, which is a core risk monitoring and reporting practice.

Exam trap

The trap here is that candidates often choose 'Implement a SIEM' (Option A) thinking it solves alert overload, but CRISC emphasizes that monitoring tools must first be properly configured before layering additional technology, and tuning the source system is the most direct and cost-effective control.

How to eliminate wrong answers

Option A is wrong because implementing a SIEM to filter and prioritize alerts does not fix the underlying issue of poorly tuned IDS rules; it merely adds another layer that may still pass through excessive false positives, delaying true threat detection. Option B is wrong because deactivating the IDS removes all monitoring capability, creating a security gap that exposes the organization to undetected attacks, which is not a risk-acceptable approach. Option D is wrong because hiring additional analysts only treats the symptom of high alert volume without reducing the noise; it increases operational cost without addressing the root cause of misconfigured detection logic.

59
MCQmedium

A retail company uses a manual control to verify that all credit card transactions are processed by authorized payment terminals. The control requires a store manager to compare a daily transaction log against a list of approved terminal IDs. The company processes an average of 10,000 transactions per day across 200 stores. During a recent internal audit, it was found that 15% of stores had not completed the reconciliation for the past month. The audit also revealed that several unauthorized terminals had been used to process transactions, resulting in a data breach of customer payment information. The company's risk appetite for payment card data security is very low. The current monitoring approach includes a quarterly review of control performance by the internal audit team. The risk manager needs to recommend improvements to the monitoring of this control. Which of the following is the BEST recommendation?

A.Increase internal audit reviews of the control to monthly.
B.Implement disciplinary actions for store managers who skip reconciliations.
C.Automate the reconciliation by integrating the transaction log with the approved terminal list.
D.Provide refresher training to all store managers on the procedure.
AnswerC

Automation enforces the control, reduces manual effort, and provides real-time monitoring.

Why this answer

Automating the reconciliation process ensures it is performed consistently and promptly, eliminating the manual gaps. Option A is wrong because increasing audit frequency does not prevent the control from being skipped. Option B is wrong because disciplinary actions may motivate compliance but do not address the process inefficiency.

Option D is wrong because additional training may help but does not guarantee consistent performance.

60
MCQmedium

An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?

A.Risk assessment methodology
B.Risk treatment process
C.Risk management policy
D.Risk register
AnswerA

A methodology provides a repeatable process for consistent risk identification and assessment.

Why this answer

A standardized risk assessment methodology is essential for consistent identification and assessment of risks across the enterprise.

61
MCQmedium

An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?

A.Accept
B.Avoid
C.Mitigate
D.Transfer
AnswerD

Outsourcing with contractual liability is a common risk transfer mechanism.

Why this answer

Transferring risk shifts the financial consequences to a third party, such as through outsourcing or insurance.

62
MCQmedium

An organization uses a qualitative risk assessment methodology. During a recent assessment, several risks were rated as 'high' due to vague definitions. What is the BEST way to improve the accuracy of the assessment?

A.Switch to a quantitative methodology
B.Assign a single expert to rate all risks
C.Use historical loss data as the primary input
D.Define clear and objective rating criteria for likelihood and impact
AnswerD

Clear criteria reduce subjectivity and improve consistency across assessors.

Why this answer

Vague rating criteria lead to inconsistent and subjective risk scores. By defining clear and objective rating criteria for likelihood and impact, the organization ensures that all assessors apply the same standards, reducing ambiguity and improving the accuracy of the qualitative assessment.

Exam trap

The trap here is that candidates often assume quantitative methods are always more accurate, but the question specifically highlights vague definitions as the root cause, which is best addressed by refining the qualitative criteria rather than changing the methodology.

How to eliminate wrong answers

Option A is wrong because switching to a quantitative methodology does not address the root cause of vague definitions; it introduces new requirements for numerical data that may not be available or reliable, and does not inherently improve the consistency of risk ratings. Option B is wrong because assigning a single expert to rate all risks introduces personal bias and does not eliminate the underlying problem of vague criteria; it merely centralizes the subjectivity. Option C is wrong because historical loss data is often incomplete, not directly applicable to emerging threats, and may not reflect current control effectiveness; using it as the primary input does not resolve the ambiguity in rating definitions.

63
Multi-Selecteasy

Which TWO of the following are examples of continuous monitoring techniques?

Select 2 answers
A.Ad-hoc access reviews requested by management.
B.Automated SIEM rules for intrusion detection.
C.Annual risk assessment.
D.Quarterly control testing by internal audit.
E.Vulnerability scanning performed weekly.
AnswersB, E

SIEM rules run continuously to detect threats.

Why this answer

Automated SIEM rules for intrusion detection (B) are a continuous monitoring technique because they operate in real-time, analyzing logs and events as they occur to detect and alert on security incidents without manual intervention. This aligns with the CRISC principle of ongoing, automated oversight rather than periodic or ad-hoc reviews.

Exam trap

The trap here is that candidates confuse periodic activities (like quarterly testing or annual assessments) with continuous monitoring, failing to recognize that continuous monitoring requires automated, real-time or near-real-time data collection and analysis, not scheduled human-driven reviews.

64
MCQhard

A risk manager is evaluating the potential impact of quantum computing on the organization's encryption infrastructure. The organization uses RSA-2048 for key exchanges and digital signatures. According to current quantum computing projections, what is the MOST urgent risk management action to take?

A.Immediately replace all RSA-2048 keys with symmetric encryption
B.Begin a cryptographic inventory and develop a migration plan to post-quantum cryptography
C.Purchase cyber insurance to cover potential losses from quantum attacks
D.Increase the RSA key length to 4096 bits
AnswerB

Starting the inventory and planning is essential to prepare for the transition before quantum advantage is achieved.

Why this answer

Quantum computers capable of breaking RSA-2048 are not imminent but expected within 10-20 years. The most urgent action is to start planning for post-quantum cryptography migration, as it requires long lead times for assessment and implementation.

65
MCQmedium

An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:

A.Residual risk calculation
B.Inherent risk assessment
C.Cost-benefit analysis
D.Risk acceptance
AnswerC

Comparing cost of control to expected loss is cost-benefit analysis.

Why this answer

The risk manager is comparing the cost of implementing the WAF against the likelihood and potential impact of a SQL injection attack. This direct comparison of mitigation cost to risk reduction benefit is the essence of a cost-benefit analysis, which determines whether the control is economically justified. It is not a calculation of residual or inherent risk, nor is it an acceptance decision.

Exam trap

The trap here is that candidates confuse the evaluation of a control's cost against risk reduction with inherent risk assessment, but inherent risk is calculated without any controls in place, whereas this scenario explicitly involves weighing the cost of a specific control against the risk it mitigates.

How to eliminate wrong answers

Option A is wrong because residual risk calculation determines the risk remaining after controls are implemented, not the evaluation of whether to implement a control in the first place. Option B is wrong because inherent risk assessment evaluates the risk level before any controls are applied, without considering the cost of mitigation. Option D is wrong because risk acceptance is a formal decision to tolerate a risk without implementing additional controls, which is not what is happening when the manager evaluates the cost of a proposed control.

66
MCQmedium

A Key Risk Indicator (KRI) that shows a rising trend in the average time to apply critical security patches suggests:

A.Decreasing risk of exploitation
B.Stable risk level
C.Increasing risk of exploitation
D.Improved control effectiveness
AnswerC

Longer patch times mean vulnerabilities remain unpatched longer, increasing risk.

Why this answer

Patch lag is a leading indicator that vulnerability risk is increasing because unpatched systems are more exposed to exploits.

67
MCQhard

In the FAIR framework, loss magnitude (LM) is composed of primary loss and secondary loss. Which of the following is an example of secondary loss?

A.Incident response costs
B.Lost business due to reputation damage
C.Legal notification costs
D.System restoration expenses
AnswerB

Lost business from reputation damage is an indirect secondary loss.

Why this answer

Secondary loss includes indirect costs like reputational damage, loss of customer trust, and share price impact.

68
MCQhard

An organization has identified a high-risk IT process that, if continued, could result in significant regulatory fines. The risk owner recommends implementing additional controls. However, the cost of controls exceeds the potential financial loss. Which risk treatment option is MOST appropriate?

A.Avoid the risk by discontinuing the process
B.Accept the risk with formal sign-off
C.Mitigate the risk by implementing controls
D.Transfer the risk through cyber insurance
AnswerD

Transfer is cost-effective when control costs exceed potential loss.

Why this answer

The cost of implementing additional controls exceeds the potential financial loss from regulatory fines, making mitigation economically inefficient. Transferring the risk through cyber insurance is the most appropriate option because it shifts the financial impact of the fines to an insurer, aligning with cost-benefit analysis principles in risk management.

Exam trap

The trap here is that candidates often choose 'mitigate' (Option C) without performing a cost-benefit analysis, forgetting that risk management requires controls to be cost-justified relative to the potential loss.

How to eliminate wrong answers

Option A is wrong because discontinuing the process (avoidance) would eliminate the business value it provides, which is an extreme measure not justified when a less disruptive option like insurance exists. Option B is wrong because accepting the risk with formal sign-off would leave the organization exposed to fines that exceed the cost of controls, violating the principle that acceptance is only appropriate when residual risk is within tolerance and cost-justified. Option C is wrong because mitigating the risk by implementing controls would cost more than the potential loss, violating the fundamental risk management principle that control costs should not exceed the expected benefit.

69
Multi-Selectmedium

A financial services firm is assessing vulnerabilities in its web application. The team wants to identify application-level vulnerabilities that could be exploited. Which TWO vulnerability identification techniques should be prioritized for this purpose?

Select 2 answers
A.IAST (Interactive Application Security Testing)
B.CVE database review
C.CIS Benchmarks comparison
D.SAST (Static Application Security Testing)
E.DAST (Dynamic Application Security Testing)
AnswersD, E

SAST analyzes source code for vulnerabilities early in the development lifecycle, making it effective for application vulnerability identification.

Why this answer

SAST (Static Application Security Testing) analyzes source code for vulnerabilities, and DAST (Dynamic Application Security Testing) tests running applications. IAST combines both but is less common. CVE database and CIS Benchmarks are asset- and configuration-focused, not application-specific.

70
MCQhard

A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?

A.Perform a new risk assessment
B.Interview control owners
C.Review risk register updates
D.Conduct a control testing and audit review
AnswerD

Testing provides direct evidence of control operation.

Why this answer

Conducting a control testing and audit review directly assesses whether controls are operating as intended, providing evidence of compliance or non-compliance. This is the most effective way to verify if controls are being followed. Option A (perform a new risk assessment) is indirect and does not focus on control effectiveness.

Option B (interview control owners) relies on self-reporting and may not be objective. Option C (review risk register updates) does not provide evidence of actual control operation.

71
MCQhard

A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?

A.A planned system upgrade may cause two hours of downtime during maintenance window
B.A vendor is late in delivering a software patch for a low-severity bug
C.A new cloud service may inadvertently expose customer PII due to misconfiguration
D.An employee mistakenly deletes a non-critical test database
AnswerC

Correct. This involves compliance risk (data protection) and low tolerance.

Why this answer

Given the low tolerance for compliance risk, any potential compliance violation (like PII exposure) must be escalated immediately, even if operational risk is moderate.

72
MCQhard

A risk practitioner notices that the number of failed authentication attempts has spiked by 300% over the past week. Which of the following actions should be taken FIRST?

A.Report the spike to the board
B.Implement multi-factor authentication
C.Increase the frequency of password changes
D.Analyze the logs to identify the source and nature of the attempts
AnswerD

Investigation is the first step to determine if it's an attack or a system issue.

Why this answer

The first step in responding to a security incident, such as a 300% spike in failed authentication attempts, is to analyze the logs to determine the source and nature of the activity. This aligns with the NIST incident response lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery) where analysis precedes any containment or reporting action. Without understanding whether the spike is due to a brute-force attack, a misconfigured application, or a credential-stuffing campaign, any subsequent action could be premature or ineffective.

Exam trap

The trap here is that candidates often jump to implementing a security control (like MFA or password changes) as a first response, but CRISC emphasizes that analysis and understanding of the risk must precede any response action.

How to eliminate wrong answers

Option A is wrong because reporting a spike to the board without first analyzing the logs is premature; the board requires actionable, analyzed information, not raw alerts. Option B is wrong because implementing multi-factor authentication (MFA) is a long-term control that should be designed and deployed after understanding the attack vector, not as an immediate response to a log spike. Option C is wrong because increasing the frequency of password changes does not address the root cause of failed authentication attempts (e.g., brute force or credential stuffing) and can actually weaken security by encouraging weak passwords; it is not a first-response action.

73
MCQmedium

During an IT risk assessment, a risk owner identifies a risk that is within the organization's risk appetite. The recommended risk treatment option is to:

A.Accept the risk with formal sign-off.
B.Avoid the risk by eliminating the activity.
C.Transfer the risk through cyber insurance.
D.Mitigate the risk by implementing additional controls.
AnswerA

Acceptance is appropriate for risks within appetite.

Why this answer

When a risk is within appetite, the appropriate response is to accept it, with formal documentation and sign-off by the risk owner.

74
MCQhard

A company's internal audit function reports that a detective control (manual review of transactions) is operating effectively based on a sample of 50 transactions showing no issues. However, the continuous monitoring system shows that 100 suspicious transactions were not reviewed during the same period. The control owner argues the control is effective. What is the BEST conclusion?

A.The control is effective because the monitoring system is too sensitive.
B.The control is ineffective because the monitoring system is unreliable.
C.The control is ineffective because the audit sample size is too small to detect the actual failure rate.
D.The control is effective because the sample showed no issues.
AnswerC

The large number of unreviewed suspicious transactions indicates a control weakness that the sample missed.

Why this answer

The detective control (manual review) is ineffective because the audit sample of 50 transactions is statistically insufficient to detect a failure rate of 100 suspicious transactions out of the total population. The continuous monitoring system provides near-real-time visibility into all transactions, revealing a significant gap that the small sample missed. A control cannot be deemed effective when a larger, more comprehensive monitoring system shows a high volume of unaddressed suspicious activity.

Exam trap

The trap here is that candidates may assume a clean sample proves control effectiveness, but CRISC tests the understanding that sample size and population coverage are critical—a small sample can miss a high failure rate, especially when continuous monitoring reveals a significant gap.

How to eliminate wrong answers

Option A is wrong because assuming the monitoring system is 'too sensitive' ignores the objective evidence of 100 unreviewed suspicious transactions; sensitivity is a design parameter, not a flaw when it correctly identifies anomalies. Option B is wrong because the monitoring system's reliability is not questioned—it flagged actual suspicious transactions that were not reviewed, making the control ineffective regardless of the system's precision. Option D is wrong because a sample showing no issues does not prove effectiveness when the sample size is too small to represent the population, especially when a larger dataset contradicts the sample result.

75
Multi-Selecthard

A multinational corporation is implementing continuous monitoring of its compliance with data privacy regulations across multiple jurisdictions. Which TWO of the following are significant challenges to this approach?

Select 2 answers
A.Inconsistent regulatory requirements across jurisdictions.
B.The need for manual data collection.
C.High cost of automation tools.
D.Difficulty in establishing a single data repository.
E.Lack of skilled personnel.
AnswersA, D

Different laws require tailored monitoring criteria, complicating a unified system.

Why this answer

A is correct because data privacy regulations (e.g., GDPR, CCPA, LGPD) have conflicting requirements for data retention, consent, breach notification, and cross-border transfer. Continuous monitoring must reconcile these differences, often requiring jurisdiction-specific rule sets and mapping controls to multiple legal frameworks, which introduces significant complexity and risk of non-compliance.

Exam trap

The trap here is that candidates often select 'Lack of skilled personnel' (E) as a generic challenge, but the CRISC exam focuses on the technical and process-oriented obstacles specific to continuous monitoring across jurisdictions, such as inconsistent requirements (A) and data repository conflicts (D).

Page 1 of 14

Page 2