Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 1–75

1062 questions total · 15pages · All types, answers revealed

Page 1 of 15

Page 2
1
MCQmedium

A risk practitioner is updating the risk register after a third-party security incident. Which of the following is the MOST important information to include in the risk register entry for this third-party risk?

A.The remediation plan and the risk owner's signature
B.The date of the incident and the amount of data compromised
C.A description of the risk event, its impact, and the response taken
D.The name and contact details of the third party
AnswerC

Recording the risk event, its impact and the response taken captures what occurred, the consequence and the mitigation, enabling accurate risk register updates and future comparison. This satisfies the stem's need for the most important entry content after a third-party incident.

Why this answer

A risk register entry must capture the essential elements of the risk: a description of the risk event, its potential or realized impact, and the response taken (or planned). For a third-party security incident, documenting what happened, how it affects the organization, and what was done provides the basis for risk tracking, reporting, and future decision-making. This is the core content that makes the register actionable.

Exam trap

CRISC often tests the distinction between incident details (dates, data volumes, contacts) and the structured risk information (description, impact, response) that belongs in a risk register — candidates may pick incident specifics over the risk-centric content.

How to eliminate wrong answers

Option A is wrong because a remediation plan and signature are important governance artifacts but secondary to the fundamental risk description, impact, and response — without those, the plan lacks context. Option B is wrong because incident date and data volume are incident-specific details, not the structured risk information needed for ongoing risk management and prioritization. Option D is wrong because third-party contact details are vendor management data, not risk register content — they belong in a vendor inventory or contract repository.

2
MCQhard

A board member asks for a summary of the top five risks. The risk practitioner has 10 risks with current residual risk levels. Which approach BEST supports board-level reporting?

A.Present the top five by residual risk level, including a trend indicator
B.Only highlight risks that have increased since last quarter
C.List risks alphabetically with current control status
D.Provide a detailed risk register with all 10 risks and full risk analysis
AnswerA

Ranking by residual risk reflects exposure after existing controls, which is what the board governs. Adding a trend indicator shows whether each risk is worsening or improving, supporting informed direction rather than a static snapshot.

Why this answer

Board-level reporting requires concise, actionable insights. Presenting the top five risks by residual risk level, with a trend indicator (e.g., increasing, stable, decreasing), allows the board to quickly understand the most critical exposures and whether risk posture is improving or deteriorating. This aligns with the CRISC focus on risk communication that supports strategic decision-making, not operational detail.

Exam trap

The trap here is that candidates may think the board needs full transparency (Option D) or only changes (Option B), but CRISC emphasizes that board reporting must be concise, prioritized, and decision-focused, not exhaustive or change-only.

How to eliminate wrong answers

Option B is wrong because highlighting only risks that have increased since last quarter omits the highest residual risks that may be stable or decreasing but still exceed the risk appetite, leading to an incomplete picture. Option C is wrong because listing risks alphabetically with current control status ignores risk prioritization, making it impossible for the board to focus on the most critical exposures. Option D is wrong because providing a detailed risk register with all 10 risks and full risk analysis overwhelms the board with operational granularity, violating the principle of tailoring risk reporting to the audience's need for summary-level, decision-oriented information.

3
Drag & Dropmedium

Arrange the steps for performing a risk assessment in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk assessment begins with asset identification, then threats/vulnerabilities, followed by likelihood and impact analysis, risk calculation, and documentation.

4
MCQmedium

A manufacturing company uses Internet of Things (IoT) sensors to monitor equipment temperature and vibration on the production floor. The sensor data is automatically sent to a central system, but there is a manual log maintained by operators that records their visual inspections. Recently, there have been instances where the sensor data indicated abnormal readings, but the operator logs showed normal conditions, leading to delayed maintenance actions and two equipment breakdowns. The risk manager investigates and finds that operators sometimes forget to update logs or misinterpret sensor alerts. The company wants to improve the reliability of the monitoring process. What should be the primary action?

A.Reduce reliance on IoT sensors and increase manual inspections.
B.Replace all IoT sensors with newer models that have better accuracy.
C.Provide additional training to operators on how to accurately fill in logs and respond to sensor alerts.
D.Implement automated reconciliation between sensor data and operator logs, flagging discrepancies in real time.
AnswerD

Automated reconciliation directly addresses the divergence between sensor readings and manual logs by continuously comparing both sources and flagging mismatches as they occur. This satisfies the stem's constraint of delayed detection caused by forgotten entries and misinterpreted alerts, enabling prompt maintenance escalation rather than relying on retrospective review.

Why this answer

The root cause is a disconnect between two data sources — automated sensor telemetry and manual operator logs — with no mechanism to detect when they disagree. Implementing automated reconciliation that flags discrepancies in real time closes the feedback loop, surfaces forgotten or mis-entered logs immediately, and prevents the delayed maintenance that caused the breakdowns. It addresses the process reliability gap rather than blaming a single human or technology component.

Exam trap

CRISC often tests the temptation to choose 'more training' as the fix for a human-error symptom — candidates miss that the risk manager's job is to design a detective control that compensates for inevitable human fallibility.

How to eliminate wrong answers

Option A is wrong because reducing sensor reliance and increasing manual inspections moves the process backward — manual inspection is the less reliable, more error-prone source in this scenario. Option B is wrong because the sensors were reporting abnormal readings correctly; the failure was in the human/log side, so replacing sensors does not fix the reconciliation gap. Option C is wrong because training alone does not create a control — operators already forget or misinterpret, and without a detection mechanism the same failures recur; training is a supporting action, not the primary fix.

5
MCQmedium

A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?

A.No change in risk level
B.Improved security posture
C.Increased vulnerability risk
D.Decreased vulnerability risk
AnswerC

Patch lag measures elapsed time between patch release and deployment. Rising from 15 to 45 days means exposure windows widen, so unpatched vulnerabilities persist longer and the likelihood of exploitation grows. The KRI trend therefore signals increased vulnerability risk, the exposure the metric tracks.

Why this answer

The patch lag KRI measures the time between a patch's release and its deployment. An increase from 15 to 45 days means systems are exposed to known vulnerabilities for a longer period, directly increasing the window of opportunity for exploitation. This trend indicates a worsening security posture and higher vulnerability risk.

Exam trap

The trap here is that candidates may confuse a KRI trend with a risk level itself, thinking a change in the indicator does not necessarily mean a change in risk, but in CRISC, a worsening KRI like patch lag directly signals increased vulnerability risk.

How to eliminate wrong answers

Option A is wrong because a significant increase in patch lag from 15 to 45 days represents a clear change in risk level, not no change. Option B is wrong because an increased patch lag means patches are applied more slowly, which degrades rather than improves the security posture. Option D is wrong because a longer delay in applying patches increases the attack surface and vulnerability risk, rather than decreasing it.

6
MCQmedium

A risk practitioner is preparing an IT risk report for the board risk committee. The committee has limited technical background and meets quarterly. Which of the following is the MOST appropriate way to present the aggregated IT risk exposure?

A.A raw export of the vulnerability scanner console showing every open finding with its CVSS score
B.The mean time to remediate critical incidents compared with the prior four quarters
C.A list of every control test performed during the quarter with pass or fail results
D.A heat map showing inherent and residual risk ratings mapped to the enterprise risk taxonomy
AnswerD

A heat map aligned to the enterprise risk taxonomy lets a non-technical board compare IT risk against other risk domains at a glance, showing both inherent exposure and the effect of controls through residual ratings. It supports aggregation and trend comparison across quarters, which is precisely what a quarterly governance committee needs to prioritize and challenge management decisions.

Why this answer

Board-level risk reporting must translate technical detail into business-relevant exposure that can be compared, aggregated, and tracked over time. Mapping inherent and residual ratings to the enterprise risk taxonomy lets the committee see IT risk alongside other risk categories and judge whether responses are proportionate. Raw findings, individual control tests, and single operational metrics all require interpretation the committee should not have to perform.

Exam trap

The trap here is assuming that more granular technical data automatically makes a report more useful, when governance audiences actually need aggregated, business-contextualized exposure.

7
MCQeasy

An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?

A.Operational risk
B.Compliance risk
C.Financial risk
D.Strategic risk
AnswerB

Regulatory fines for breaching data protection laws arise from failing to meet legal and regulatory obligations, which is precisely the scope of compliance risk. Other categories such as operational or strategic risk do not centre on statutory penalties for non-compliance.

Why this answer

Regulatory fines for non-compliance with data protection laws fall squarely under compliance risk, which encompasses the risk of violating laws, regulations, contracts, or standards and the resulting penalties, sanctions, or legal exposure. Data protection regulations such as GDPR or CCPA are compliance obligations, so the associated fine risk is classified as compliance risk.

Exam trap

CRISC often tests whether candidates can separate the cause of a risk from its consequence — the trap is choosing operational risk because a data breach is operational, when the question asks about the risk of regulatory fines, which is compliance risk.

How to eliminate wrong answers

Option A is wrong because operational risk covers failures in people, processes, and systems (for example, outages, errors, fraud) rather than legal or regulatory violations. Option C is wrong because financial risk concerns monetary losses from market movements, credit defaults, or liquidity issues, not regulatory penalties. Option D is wrong because strategic risk relates to decisions that affect the organization's ability to achieve its long-term objectives, not to legal non-compliance.

8
MCQmedium

A risk practitioner is reviewing the risk register of an e-commerce company and finds that several risks were identified only through past incident reports. The chief risk officer asks how to broaden risk identification to surface risks that have not yet materialized. Which of the following approaches is MOST effective for identifying emerging and previously unconsidered risks?

A.Increase the frequency of reviewing historical incident tickets to capture patterns in past outages.
B.Track the number of open vulnerabilities in the vulnerability management system and escalate when thresholds are exceeded.
C.Rely on the annual external audit findings to identify control weaknesses that could become risks.
D.Conduct scenario analysis workshops with business, technology, and external stakeholders to explore plausible future events.
AnswerD

Scenario analysis workshops bring together diverse perspectives to construct plausible future events that may not appear in incident history. For an e-commerce company, this could surface risks such as payment provider outages, new privacy regulations, or generative AI abuse in customer service. The technique is forward-looking and structured, making it effective for emerging risk identification. Outputs can be added to the risk register with likelihood and impact estimates for treatment decisions.

Why this answer

Scenario analysis workshops are forward-looking and draw on cross-functional and external perspectives to imagine plausible events that have no internal incident history. They are well suited to surfacing emerging risks such as regulatory shifts, technology changes, and third-party dependencies. Historical incident reviews, audit findings, and vulnerability counts are valuable but backward-looking or narrow in scope, so they cannot fulfill the goal of identifying risks that have not yet materialized.

Exam trap

The trap here is choosing a familiar internal data source like incident tickets or audit findings, which only reflects risks already experienced or in scope, rather than a forward-looking technique for unknown risks.

9
Multi-Selectmedium

A risk practitioner is performing an external threat environment analysis for a retail chain that accepts card payments. The practitioner wants to identify which external factors should be treated as inputs to the likelihood of payment card data compromise. Which TWO of the following are the MOST appropriate inputs? (Choose two.)

Select 2 answers
A.The percentage of the chain's stores that have completed a recent internal audit.
B.The prevalence and activity level of organized criminal groups that monetize stolen card data.
C.The turnover rate among store cashiers and the adequacy of their security awareness training.
D.Published reports of new skimming and shimming techniques observed at comparable retailers.
E.The number of point-of-sale terminals the chain operates across all stores.
AnswersB, D

Organized criminal activity that monetizes stolen card data is a direct external driver of the probability that the retail chain will be attacked. It reflects adversary capability and intent in the specific ecosystem where card data has resale value, so it belongs in the likelihood assessment for payment card compromise. Excluding it would leave the analysis anchored only in internal conditions and blind to the demand side of the threat.

Why this answer

External threat inputs describe conditions outside the organization's control that shape how likely an attack is. Organized criminal activity that monetizes card data, and published reports of skimming and shimming techniques used against comparable retailers, both reflect adversary capability and intent in the card payment ecosystem. Terminal counts, cashier turnover, and audit completion are internal attributes better suited to vulnerability, impact, or assurance analysis.

Exam trap

The trap here is treating internal scale and control metrics as threat environment factors simply because they are easy to measure.

10
MCQeasy

A small online retailer with 15 employees sells handmade crafts through its e-commerce website. The company processes payments via a third-party gateway. The owner manually reviews transaction logs once a week for fraud indicators, but recently discovered three chargebacks due to unauthorized transactions. The retailer has limited IT budget and no dedicated security staff. The owner wants to improve detection of fraudulent transactions without significant investment. The current manual process takes about two hours per week and often results in delayed detection. The payment gateway offers basic fraud detection features such as IP geolocation and velocity checks, but these are not enabled. What is the most practical first step?

A.Enable the built-in fraud detection features offered by the payment gateway.
B.Hire a part-time fraud analyst to review logs daily.
C.Purchase an automated fraud detection system from a third-party vendor.
D.Accept the current risk and set aside a reserve fund for chargebacks.
AnswerA

Enabling the gateway's existing IP geolocation and velocity checks adds automated fraud screening at zero additional cost, replacing the weekly manual log review that delayed detection. It directly addresses the limited-budget and no-security-staff constraints while reducing chargeback exposure.

Why this answer

Enabling the built-in fraud detection features offered by the payment gateway is the most practical first step because it is low-cost, quick to implement, and leverages existing capabilities without additional expense. Option B (hiring a part-time analyst) would increase costs and may not be sustainable for a small retailer. Option C (purchasing a third-party system) requires significant investment and implementation time.

Option D (accepting the risk) is not acceptable given the recent chargebacks.

11
MCQmedium

During the risk identification process, an IT risk universe is defined. Which of the following BEST describes the purpose of an IT risk universe?

A.A list of all known vulnerabilities in the organization's IT systems
B.A database of past security incidents and their root causes
C.A framework for categorizing risks into strategic, operational, financial, and compliance
D.A comprehensive inventory of all potential IT risks facing the organization
AnswerD

The IT risk universe is the structured catalogue of every plausible IT risk that could affect the organisation, forming the scope from which individual risks are later identified, assessed and prioritised. It ensures risk identification is comprehensive rather than ad hoc.

Why this answer

An IT risk universe is a comprehensive inventory of all potential IT risks facing the organization — it is the master list from which risk assessments, prioritization, and treatment decisions are drawn. It defines the scope of what the organization considers 'in scope' for IT risk management, ensuring no material risk category is overlooked. It is not limited to vulnerabilities, incidents, or a single categorization scheme.

Exam trap

CRISC often tests the distinction between the risk universe and its inputs — candidates confuse it with a vulnerability list or incident database, but the universe is the comprehensive forward-looking inventory of all potential IT risks.

How to eliminate wrong answers

Option A is wrong because a list of known vulnerabilities is a vulnerability register or scan output, which is a subset of the risk universe — vulnerabilities are one input, not the universe itself. Option B is wrong because a database of past incidents is an incident register or historical log; the risk universe is forward-looking and includes risks that have not yet materialized. Option C is wrong because categorizing risks into strategic, operational, financial, and compliance is a taxonomy or framework applied to risks, not the universe itself — the universe is the inventory, and categorization is one way to organize it.

12
MCQmedium

A risk assessment reveals that the cost of implementing a control ($500k) exceeds the annualized loss expectancy (ALE) of $300k. The risk is currently within the organization's risk appetite. What is the appropriate risk response?

A.Accept the risk
B.Implement the control
C.Avoid the risk
D.Transfer the risk
AnswerA

Acceptance is appropriate because the control's cost exceeds the ALE it would reduce, so the expenditure is not justified, and the residual risk already sits within the organisation's stated risk appetite. No further treatment is warranted beyond monitoring.

Why this answer

When the cost of a control exceeds the ALE and the risk is already within the organization's risk appetite, accepting the risk is the economically justified response. Spending $500k to mitigate a $300k annualized loss is not cost-effective, and the risk is tolerable by definition.

Exam trap

CRISC often tests whether candidates reflexively choose 'implement the control' without checking cost-benefit, ignoring that acceptance is valid when the risk is within appetite.

How to eliminate wrong answers

Option B is wrong because implementing a control that costs more than the expected loss destroys value and is not justified when the risk is already within appetite. Option C is wrong because risk avoidance means eliminating the activity entirely, which is disproportionate here and not indicated by the cost-benefit analysis. Option D is wrong because risk transfer (e.g., insurance) is not warranted when the risk is acceptable and the control cost already exceeds the ALE.

13
MCQmedium

A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?

A.Compensating control such as additional monitoring
B.Preventive control such as patching the vulnerability
C.Corrective control such as backup restoration
D.Detective control such as log monitoring
AnswerB

Patching removes the vulnerable code path entirely, stopping exploitation before it can occur, which is the defining mechanism of a preventive control. This directly satisfies the stem's requirement for the control type most effective at preventing exploitation of the identified web application vulnerability.

Why this answer

A preventive control stops an incident before it occurs, and patching the vulnerability removes the exploitable condition entirely, which is the most effective way to prevent exploitation. Since the vulnerability is identified as critical, remediation via patching directly addresses the root cause rather than merely detecting or recovering from an exploit.

Exam trap

CRISC often tests the distinction between control types; candidates must recognize that 'prevent' questions require a preventive control, not a detective or corrective one, even if those are also valuable.

How to eliminate wrong answers

Option A is wrong because a compensating control (e.g., additional monitoring) only mitigates risk when the primary control cannot be applied; it does not prevent exploitation and is a secondary measure. Option C is wrong because a corrective control (backup restoration) operates after an incident has occurred and does not prevent the vulnerability from being exploited. Option D is wrong because a detective control (log monitoring) identifies an attack in progress or after the fact but does not stop it from succeeding.

14
MCQhard

An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?

A.User training
B.Change management
C.Vulnerability scanning
D.Access review
AnswerB

Change management governs how modifications to existing systems are assessed, approved and recorded, directly satisfying the project manager's need to control alterations during implementation. It prevents unauthorised or untested changes disrupting production, aligning the security control rollout with established baselines and audit trails required under CRISC's change control domain.

Why this answer

Change management ensures that changes to systems are controlled, tested, and approved to prevent unintended disruptions or security gaps. It is essential during control implementation.

15
MCQhard

An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?

A.The residual risk is still critical
B.Controls are effective in reducing risk to a lower level
C.The inherent risk was overestimated
D.Controls are ineffective because residual risk is still above zero
AnswerB

The controls demonstrably lower risk from critical to medium, satisfying the stem's inherent-to-residual reduction. Residual risk of 8 reflects the remaining exposure after control operation, confirming effectiveness rather than mere existence. This axis—measured risk reduction—distinguishes effective controls from implemented-but-ineffective ones.

Why this answer

The reduction from 20 to 8 indicates the controls are effective in reducing risk.

16
MCQmedium

During a cost-benefit analysis for a new control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce risk by 80% and will cost $150,000 annually to operate. What is the net benefit of implementing the control?

A.$400,000
B.$100,000
C.$350,000
D.$250,000
AnswerD

Risk reduction equals 80% of the $500,000 ALE, or $400,000. Subtracting the $150,000 annual control operating cost gives a net benefit of $250,000, the figure that justifies the control against the cost-benefit constraint in the stem.

Why this answer

ALE reduction is 80% of $500,000 = $400,000. Net benefit = ALE reduction - annual control cost = $400,000 - $150,000 = $250,000.

17
MCQmedium

A risk practitioner is categorizing IT risks for a manufacturing company. Which of the following risks would be classified as an 'operational' IT risk?

A.Risk of financial loss from a ransomware payment
B.Risk of non-compliance with GDPR for customer data stored in the EU
C.Risk of production line downtime due to a server failure
D.Risk of reputational damage from a data breach
AnswerC

Server failure causing production line downtime is an operational IT risk because it concerns the day-to-day reliability and availability of systems supporting business processes. This satisfies the stem's operational category, which covers disruptions to service delivery and processing, rather than strategic, compliance or external risk domains.

Why this answer

Operational IT risks relate to the day-to-day functioning of IT systems and processes. Production line downtime due to a system failure directly impacts operations.

18
MCQeasy

Which of the following is a detective control?

A.Data encryption
B.Intrusion detection system
C.Backup and restore
D.Firewall
AnswerB

An intrusion detection system monitors network traffic and raises alerts on suspicious activity, satisfying the detective control requirement of identifying events after they occur. Unlike preventive controls such as firewalls, which block traffic, it detects and reports intrusions without stopping them, providing the visibility CRISC expects for detection.

Why this answer

Detective controls identify risk events that have occurred. Intrusion detection systems (IDS) monitor network traffic for malicious activity and alert administrators.

19
MCQeasy

Which of the following is the most appropriate frequency for operational IT risk reporting to IT management?

A.Annually
B.Quarterly
C.Weekly or monthly
D.Semi-annually
AnswerC

Operational risk reporting feeds day-to-day IT management, so weekly or monthly cycles align with the pace of operational change and let management act on emerging issues before they escalate. Quarterly or annual intervals would leave operational exposures unaddressed for too long.

Why this answer

Operational risk reporting is typically provided on a weekly or monthly basis to IT management to support day-to-day decision-making.

20
MCQmedium

In third-party risk management, which of the following is MOST indicative of a vendor's control effectiveness for a critical vendor?

A.SOC 2 Type II report
B.Contractual security requirements
C.Vendor's self-assessment questionnaire
D.Vendor's marketing materials
AnswerA

A SOC 2 Type II report provides independent auditor testing of control design and operating effectiveness across a period, directly addressing whether the critical vendor's controls actually functioned. This period-based evidence distinguishes it from self-attestations or Type I point-in-time reports, satisfying the effectiveness criterion.

Why this answer

A SOC 2 Type II report is the most indicative of a vendor's control effectiveness because it provides an independent auditor's opinion on the design and operating effectiveness of controls over a specified period (typically 6–12 months). For a critical vendor, this third-party attestation offers objective evidence that security and privacy controls are actually working, not just promised.

Exam trap

The trap here is that candidates often confuse contractual requirements or self-assessments as sufficient evidence of control effectiveness, but the exam tests that only an independent, audited report like SOC 2 Type II provides the objective assurance needed for critical vendors.

How to eliminate wrong answers

Option B is wrong because contractual security requirements are only promises and obligations, not evidence that controls are actually implemented or effective; they lack independent verification. Option C is wrong because a vendor's self-assessment questionnaire is subjective, unaudited, and prone to bias or incomplete responses, providing no assurance of actual control operation. Option D is wrong because marketing materials are promotional content designed to sell services, not factual evidence of control effectiveness, and they contain no technical or operational details.

21
MCQeasy

A risk practitioner is evaluating the effectiveness of the organization's IT change management process. Which of the following metrics would BEST indicate that the process is effectively reducing risk?

A.Number of changes implemented per month.
B.Percentage of changes that are rolled back due to failures.
C.Percentage of changes that are tested in a non-production environment before deployment.
D.Average time to implement a change.
AnswerC

Testing changes in a non-production environment before deployment is a key preventive control in change management. A high percentage of changes tested indicates that the process is effectively identifying and mitigating potential issues before they affect production. This directly reduces the risk of service disruptions, data corruption, and security vulnerabilities introduced by changes.

Why this answer

The percentage of changes tested in a non-production environment is a leading indicator of effective change management. It shows that the organization is proactively identifying and mitigating risks before changes reach production. This directly reduces the likelihood of incidents caused by changes, making it the best metric for assessing risk reduction.

Exam trap

The trap here is focusing on efficiency metrics like speed or volume, which do not necessarily correlate with reduced risk, instead of a control adherence metric like testing coverage.

22
Multi-Selectmedium

Which THREE of the following are effective techniques for identifying IT risks?

Select 3 answers
A.Root cause analysis
B.Cost-benefit analysis
C.Brainstorming
D.Vulnerability scanning
E.SWOT analysis
AnswersC, D, E

Brainstorming is a common technique for risk identification.

Why this answer

Brainstorming is a structured group technique that leverages the collective expertise of stakeholders to identify a wide range of IT risks, including emerging threats and vulnerabilities that may not be captured by automated tools. It is effective because it encourages creative thinking and surfaces risks related to business processes, third-party dependencies, and human factors that are often missed by purely technical assessments.

Exam trap

The trap here is confusing risk identification techniques with risk analysis or risk treatment techniques, leading candidates to select root cause analysis (a post-incident technique) or cost-benefit analysis (a decision-making tool) instead of recognizing that brainstorming, vulnerability scanning, and SWOT analysis are all valid methods for initially identifying risks.

23
MCQmedium

A risk practitioner is reviewing the organization's identity and access management (IAM) processes. The organization wants to reduce the risk of excessive access rights for employees who change roles internally. Which of the following controls is MOST effective for this risk?

A.Enforcing least privilege at the database level only.
B.Implementing mandatory vacation policies for all employees.
C.Automating role-based access revocation and provisioning upon HR role changes.
D.Conducting periodic user access reviews by managers.
AnswerC

Automating access revocation and provisioning based on HR role changes ensures that when an employee moves to a new role, their old access is immediately removed and new access is granted according to the new role. This event-driven approach directly mitigates the risk of excessive access rights, providing timely and consistent enforcement without relying on manual reviews.

Why this answer

The most effective control to reduce excessive access rights from internal role changes is automated role-based access revocation and provisioning triggered by HR events. This ensures immediate removal of old access and assignment of new access, directly addressing the risk. Other controls like vacation policies, periodic reviews, or database-level least privilege are either indirect or incomplete.

Exam trap

The trap here is assuming that periodic access reviews or least privilege at a single layer are sufficient, when timely, automated revocation upon role change is the most direct mitigation.

24
MCQmedium

A risk practitioner is estimating the likelihood of a ransomware event for a manufacturing firm. The firm has endpoint protection, network segmentation, and offline backups, but the practitioner learns that a third-party maintenance vendor has persistent remote access with shared credentials and no multi-factor authentication. Which of the following BEST explains how this finding should affect the likelihood estimate?

A.Likelihood should be set to the industry average for manufacturing ransomware incidents.
B.Likelihood should decrease because the firm's existing controls are strong.
C.Likelihood should increase because the vendor access path provides an unmitigated entry point.
D.Likelihood should remain unchanged because backup availability determines ransomware outcomes.
AnswerC

Shared credentials without multi-factor authentication create a low-effort, persistent entry point that attackers commonly exploit in supply chain ransomware incidents. Because this path bypasses the firm's endpoint and segmentation controls, it materially raises the probability that an attacker can establish a foothold and escalate. The finding is a direct likelihood driver, so the estimate should rise to reflect the expanded attack surface.

Why this answer

Likelihood reflects how probable an event is given the threat environment and existing controls. The vendor's shared credentials and lack of multi-factor authentication create a persistent, low-effort entry point that bypasses internal defenses, so it raises the probability of a successful ransomware intrusion. Backup availability and industry averages address recovery and context, not this specific exposure.

Exam trap

The trap here is letting strong internal controls or backup availability dominate the likelihood judgment while overlooking a third-party access path that sidesteps those controls.

25
MCQmedium

A risk practitioner is reviewing the risk register and notices that several risks have not been reassessed in over a year. The business environment has changed significantly due to a new regulation. What is the PRIMARY reason the practitioner should escalate this issue to the risk committee?

A.The risk owners have failed to perform their assigned duties, which is a performance management issue.
B.The risk register may no longer reflect the current risk landscape, leading to ineffective risk treatment decisions.
C.The risk committee is required by regulation to meet at least quarterly to review all risks.
D.The risk assessment methodology itself is flawed and must be replaced with a quantitative approach.
AnswerB

Risk registers must be updated to reflect changes in the internal and external environment. A new regulation can alter likelihood, impact, or risk appetite, making prior assessments obsolete. If the register is stale, treatment plans and resource allocations may be misdirected. Escalation ensures the committee can direct reassessment and realign risk responses with current conditions.

Why this answer

The core issue is that unreviewed risks may no longer be valid after a significant regulatory change. A stale risk register can lead to incorrect treatment priorities and resource allocation. Escalating to the risk committee ensures that reassessment is prioritized and that risk responses are realigned with the new environment, maintaining the effectiveness of risk management.

Exam trap

The trap here is focusing on procedural compliance or individual accountability instead of the substantive risk that outdated assessments may misinform decision-making.

26
MCQeasy

A small retail company has determined that the risk of a point-of-sale (POS) system malware infection is high. The company decides to implement a whitelisting solution that only allows approved applications to run on POS terminals. This is an example of which risk response?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerB

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. The whitelisting solution prevents unauthorized applications from running, thereby reducing the likelihood of malware infection on POS terminals. This is a classic example of a preventive control that mitigates risk. The company is actively reducing the risk to an acceptable level, which aligns with the risk mitigation strategy.

Why this answer

The company is implementing a whitelisting solution to prevent malware on POS terminals. This is a preventive control that reduces the likelihood of the risk occurring. Risk mitigation is the correct response because it involves taking action to reduce the probability or impact of a risk.

Risk acceptance would mean doing nothing, risk transfer would involve shifting the financial impact, and risk avoidance would mean eliminating the activity. Since the company is actively reducing the risk while continuing the activity, it is mitigation.

Exam trap

The trap here is confusing mitigation with avoidance; avoidance would require stopping the use of POS systems, while mitigation reduces risk while continuing the activity.

27
Multi-Selecthard

Which THREE of the following are common challenges when implementing a risk monitoring dashboard? (Select exactly three.)

Select 3 answers
A.Data quality and consistency issues
B.Lack of clear ownership for monitoring
C.Reduced need for manual controls
D.Overwhelming amount of information displayed
E.Improved decision-making
AnswersA, B, D

Common due to multiple sources.

Why this answer

Data quality and consistency issues (A) are a common challenge because risk monitoring dashboards aggregate data from multiple sources, each with its own format, timeliness, and accuracy. Inconsistent data leads to unreliable metrics and false alarms, undermining the dashboard's purpose of providing a single source of truth for risk posture.

Exam trap

The trap here is confusing the challenges of implementation with the benefits or outcomes of the dashboard, leading candidates to select 'reduced need for manual controls' or 'improved decision-making' as challenges instead of recognizing them as positive results.

28
MCQeasy

An organization is implementing a new access control system. Which of the following should be included in the control implementation plan?

A.Annual cost of the control only
B.Key Risk Indicators (KRIs) for the control
C.Project milestones, training schedule, and documentation updates
D.Risk assessment results
AnswerC

Project milestones, training schedule, and documentation updates constitute the implementation plan's core components, ensuring the control is deployed on time, users are trained, and records reflect the change. This satisfies the stem's requirement for what belongs in a control implementation plan, covering delivery, competence, and audit evidence.

Why this answer

The control implementation plan must be actionable and comprehensive, covering the practical steps needed to deploy the new access control system. Option C includes project milestones (timeline), training schedule (ensuring users and administrators know how to use the system), and documentation updates (keeping policies, procedures, and system documentation current). These elements are essential for a successful implementation and align with CRISC's focus on integrating risk management into business processes.

The other options are either too narrow (cost only) or are inputs to the plan rather than components of the plan itself.

Exam trap

CRISC often tests the distinction between inputs to risk management processes and the components of implementation plans, causing candidates to confuse risk assessment results or KRIs as part of the plan rather than as separate elements.

How to eliminate wrong answers

Option A is wrong because focusing solely on the annual cost of the control ignores other critical aspects of implementation such as timeline, training, and documentation, which are necessary for effective deployment and ongoing operation. Option B is wrong because Key Risk Indicators (KRIs) are metrics used to monitor risk levels after controls are in place; they are not typically part of the implementation plan itself, which focuses on the steps to deploy the control. Option D is wrong because risk assessment results are an input to the decision to implement a control and help define requirements, but they are not components of the implementation plan; the plan should detail how the control will be implemented, not restate the risk assessment.

29
MCQeasy

Which of the following is the PRIMARY benefit of using a risk register for monitoring?

A.Provides real-time alerts.
B.Centralized repository of all risks.
C.Eliminates the need for KRIs.
D.Automates control testing.
AnswerB

A risk register consolidates identified risks, owners, ratings, and treatment status into one repository, giving consistent visibility for monitoring and reporting. This centralisation enables trend analysis and accountability, which scattered spreadsheets or departmental logs cannot deliver reliably.

Why this answer

A risk register serves as the centralized repository where all identified risks, their attributes (likelihood, impact, owner, response), and status are documented and tracked over time. This single source of truth is the PRIMARY benefit for monitoring because it enables consistent tracking, reporting, and escalation of risk status across the enterprise. Real-time alerting and automation are features of GRC tooling layered on top, not the register's core value.

Exam trap

CRISC often tests the distinction between the risk register's role as a centralized tracking repository versus the functions of monitoring tools (SIEM, KRI dashboards) — candidates confuse 'monitoring' with 'real-time alerting' and pick Option A.

How to eliminate wrong answers

Option A is wrong because a risk register is a static or periodically updated record, not a real-time monitoring/alerting system — real-time alerts come from SIEM, IDS, or monitoring tools. Option C is wrong because KRIs (Key Risk Indicators) are metrics that feed INTO the risk register; the register does not replace them — they are complementary. Option D is wrong because control testing is performed by control owners and audit functions; the register only records the results, it does not automate the testing itself.

30
MCQmedium

A healthcare organization operates a legacy electronic health record (EHR) system that is manually monitored for access anomalies by a small IT team. The organization is planning to migrate to a new cloud-based EHR with integrated logging and monitoring. However, due to budget constraints, the migration will take two years. In the interim, the risk manager wants to improve monitoring for unauthorized access to patient data. The current manual process involves weekly log reviews, but recent audits have identified instances of delayed detection (up to two weeks) and missed incidents. The IT team can dedicate only 10 additional hours per week for monitoring. What is the best approach to enhance monitoring during the transition period?

A.Outsource the monitoring to a third-party managed security service provider.
B.Implement a full automation suite for access monitoring immediately.
C.Use a phased risk-based approach, prioritizing monitoring of high-risk areas such as privileged accounts and sensitive patient data.
D.Accept the current monitoring state as adequate given the upcoming migration.
AnswerC

A phased risk-based approach directs the team's limited ten hours weekly toward privileged accounts and sensitive patient data, where unauthorised access carries the greatest impact. This targets the constraint of scarce analyst capacity while reducing the delayed detection and missed incidents that audits identified, without awaiting the two-year cloud migration.

Why this answer

Given budget and staffing constraints, a phased risk-based approach that prioritizes high-risk areas (privileged accounts, sensitive patient data) is the most practical way to improve monitoring during the two-year transition. It focuses limited resources where risk is highest and can be implemented incrementally without a large upfront investment.

Exam trap

CRISC often tests the tendency to choose the most comprehensive or outsourced solution — candidates overlook that risk-based prioritization is preferred when resources are constrained, even if it is not the 'perfect' long-term fix.

How to eliminate wrong answers

Option A is wrong because outsourcing may exceed budget constraints and does not guarantee better prioritization; it also adds third-party risk and may not be feasible within the stated 10-hour weekly limit. Option B is wrong because implementing a full automation suite immediately is unrealistic given budget constraints and the two-year migration timeline. Option D is wrong because accepting the current state ignores the audit findings of delayed detection and missed incidents, which is not acceptable for patient data.

31
MCQmedium

In third-party risk management, which of the following is typically used for initial onboarding assessment of a vendor?

A.Contract compliance review
B.Security questionnaire
C.SOC 2 Type II report
D.Shared intelligence platform feed
AnswerB

A security questionnaire collects the vendor's control, compliance and data-handling details before any contract or data sharing, making it the standard initial onboarding assessment. It is proportionate and repeatable at scale, unlike audits or penetration tests reserved for higher-risk vendors.

Why this answer

Security questionnaires are commonly used during initial vendor assessment to gather information about the vendor's security posture.

32
Multi-Selectmedium

Which TWO of the following are valid risk scenarios that should be documented during IT risk identification?

Select 2 answers
A.An employee may inadvertently share confidential data via email due to lack of data classification training.
B.The organization must comply with GDPR requirements for data protection.
C.An external attacker may exploit weak password policies to gain access to the email system and exfiltrate sensitive data.
D.The database server has not been patched for critical vulnerabilities.
E.The IT department will implement multi-factor authentication to reduce the risk of unauthorized access.
AnswersA, C

This is a risk scenario with threat, vulnerability, and impact.

Why this answer

It describes a specific risk scenario: an employee inadvertently sharing confidential data via email due to lack of data classification training. This is a valid risk scenario as it identifies a threat (human error), a vulnerability (insufficient training), and a potential impact (data leakage). In IT risk identification, scenarios must be concrete and actionable, not just statements of compliance or controls.

Exam trap

The trap here is that candidates often mistake compliance requirements (option B) or control implementations (option E) for risk scenarios, but CRISC requires scenarios to describe specific threat events with a clear cause-effect chain, not static states or planned actions.

33
MCQmedium

An IT risk manager is preparing a report for the board of directors. Which of the following content elements is most important for strategic risk reporting?

A.Weekly vulnerability scan results
B.IT risk integration with enterprise risk management
C.List of all vendor risk assessments
D.Detailed control performance metrics
AnswerB

Board-level reporting demands a strategic, aggregated view, so integrating IT risk into enterprise risk management lets the board see IT exposure alongside other business risks and prioritise investment accordingly. Standalone IT risk registers lack that enterprise context.

Why this answer

Strategic risk reporting to the board requires a high-level view that aligns IT risk with enterprise objectives. Option B is correct because it demonstrates how IT risk is integrated into the broader enterprise risk management (ERM) framework, enabling the board to understand the business impact of IT risks. This integration is essential for strategic decision-making, as it connects technical risk data to organizational goals and risk appetite.

Exam trap

The trap here is that candidates often confuse operational reporting (e.g., vulnerability scans, control metrics) with strategic reporting, failing to recognize that the board requires a consolidated, business-aligned view of risk rather than detailed technical data.

How to eliminate wrong answers

Option A is wrong because weekly vulnerability scan results are operational, tactical data that is too granular and frequent for board-level strategic reporting; the board needs aggregated risk trends, not raw scan outputs. Option C is wrong because listing all vendor risk assessments is an operational detail that does not convey strategic risk posture or business impact; the board requires a summary of key vendor risks and their effect on enterprise objectives. Option D is wrong because detailed control performance metrics, such as specific control failure rates, are more appropriate for management and audit reporting, not for the board's strategic view, which focuses on risk exposure and mitigation effectiveness at a macro level.

34
MCQmedium

A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time production monitoring. Which risk is most directly introduced by this convergence?

A.Higher licensing costs for industrial software
B.Expanded attack path from IT to OT systems
C.Increased complexity of data analytics
D.Reduced operational efficiency due to network latency
AnswerB

Converging ICS with corporate IT dissolves the air gap, letting compromised enterprise credentials or lateral movement reach operational technology. This expanded attack path directly satisfies the stem's convergence scenario, where IT-borne threats can now pivot into production systems, escalating impact from data loss to physical process disruption.

Why this answer

The convergence of IT and OT networks creates a bridge between two environments that were traditionally air-gapped. This bridge allows threats that compromise the corporate IT network to pivot into the industrial control systems (ICS), expanding the attack surface and providing adversaries with a direct path to operational technology (OT). Unlike licensing costs or analytics complexity, this is a direct security risk that can lead to physical consequences, making it the most critical risk introduced by such integration.

Exam trap

CRISC often tests the ability to distinguish between direct security risks and secondary business impacts; candidates may incorrectly focus on operational or financial outcomes rather than the immediate security risk of expanded attack paths.

How to eliminate wrong answers

Option A is wrong because licensing costs are a financial consideration, not a direct risk introduced by network convergence; they may change but are not the primary risk. Option C is wrong because increased complexity of data analytics is an operational challenge, not a security risk, and may even be mitigated by integration. Option D is wrong because reduced operational efficiency due to network latency is a performance concern, not a risk; in fact, integration often aims to improve efficiency, and latency can be managed with proper design.

35
MCQhard

An organization's IT risk team is promoting a risk-aware culture. Which initiative is most likely to encourage employees to report security incidents without fear?

A.Establishing a no-blame incident reporting policy
B.Publishing quarterly incident statistics
C.Increasing the frequency of security awareness training
D.Implementing automated incident detection
AnswerA

A no-blame policy removes the fear of punitive consequences, directly addressing the stem's constraint that staff withhold incident reports due to blame. By decoupling reporting from disciplinary action, it increases the volume and speed of disclosures, giving risk management earlier visibility of actual losses and control failures.

Why this answer

A no-blame incident reporting policy directly addresses the psychological barrier of fear of reprisal, which is the primary reason employees hesitate to report security incidents. By explicitly stating that reporters will not face disciplinary action for unintentional errors or omissions, the organization fosters psychological safety and encourages timely reporting, which is critical for effective risk response.

Exam trap

The trap here is that candidates may confuse 'increasing awareness training' (Option C) with addressing fear, when in fact training alone does not remove the organizational culture of blame that discourages reporting.

How to eliminate wrong answers

Option B is wrong because publishing quarterly incident statistics provides transparency and awareness but does not address the fear of personal consequences that prevents employees from reporting incidents. Option C is wrong because increasing the frequency of security awareness training improves knowledge and vigilance but does not remove the fear of blame or punishment for reporting an incident. Option D is wrong because implementing automated incident detection improves technical detection capabilities but does not influence human behavior or the cultural willingness to report incidents voluntarily.

36
MCQmedium

An organization is planning to deploy an IoT solution in a manufacturing plant. The risk manager is asked to identify risks associated with the integration of IoT devices into the plant network. Which of the following techniques would be MOST effective for identifying both technical and operational risks?

A.Conduct a SWOT analysis of the IoT project
B.Facilitate a brainstorming session with IT, operational technology (OT), and safety teams
C.Interview the plant manager about operational challenges
D.Send a risk questionnaire to employees
AnswerB

A cross-functional brainstorming session draws on IT, OT and safety perspectives, surfacing both technical vulnerabilities and operational or physical safety risks that a single-discipline review would miss. This satisfies the stem's requirement to identify technical and operational risks together for the IoT deployment.

Why this answer

A brainstorming session that includes IT, operational technology (OT), and safety teams is the most effective technique because IoT integration creates a convergence of traditional IT risks (e.g., network segmentation, patch management) with OT-specific risks (e.g., real-time control system integrity, safety interlocks) and physical safety hazards. This cross-functional approach surfaces technical risks like unpatched firmware vulnerabilities in programmable logic controllers (PLCs) and operational risks such as unplanned downtime due to misconfigured device-to-controller communication protocols (e.g., Modbus/TCP without authentication).

Exam trap

ISACA often tests the misconception that a single-stakeholder interview or a generic analysis tool is sufficient for risk identification in converged IT/OT environments, when in reality the most effective technique requires collaborative input from all relevant technical and operational domains to capture the full spectrum of risks.

How to eliminate wrong answers

Option A is wrong because a SWOT analysis is a high-level strategic tool that identifies strengths, weaknesses, opportunities, and threats but lacks the granularity to uncover specific technical risks like insecure MQTT broker configurations or operational risks like loss of safety-critical sensor data. Option C is wrong because interviewing only the plant manager provides a narrow, managerial perspective that misses deep technical risks from OT engineers (e.g., legacy fieldbus vulnerabilities) and safety risks from safety engineers (e.g., failure modes of IoT-triggered emergency stops). Option D is wrong because a risk questionnaire sent to employees is a passive, one-way data collection method that cannot dynamically probe or clarify complex IoT-specific risks such as latency-induced control loop instability or interference between Wi-Fi and industrial wireless protocols like WirelessHART.

37
MCQeasy

An organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?

A.Eliminates subjectivity in risk assessment
B.Provides comparable results across organizations
C.Quick and easy to communicate
D.Produces financially meaningful results
AnswerC

A 5×5 heat map plots likelihood against impact using ordinal scales, so assessors assign ratings without quantitative data or modelling. This makes results fast to produce and readily understood by executives and business stakeholders, satisfying the need to communicate IT risk posture quickly across the organisation.

Why this answer

A 5×5 risk heat map is a qualitative tool that plots likelihood against impact using ordinal scales, making it fast to produce and easy for executives and non-technical stakeholders to interpret at a glance. Its primary advantage is communication and speed, not quantitative precision.

Exam trap

CRISC often tests the misconception that qualitative heat maps are objective or financially meaningful; candidates must remember that their primary advantage is speed and ease of communication, not precision or comparability.

How to eliminate wrong answers

Option A is wrong because qualitative heat maps are inherently subjective — they rely on expert judgment and ordinal scales, so they do not eliminate subjectivity. Option B is wrong because heat maps are organization-specific; different organizations define their 5×5 scales differently, so results are not directly comparable across organizations. Option D is wrong because qualitative heat maps produce ordinal rankings (e.g., high/medium/low), not financially meaningful monetary values; quantitative methods like FAIR or ALE produce financial results.

38
Multi-Selectmedium

When developing realistic risk scenarios, which THREE components are essential according to the ISACA risk scenario template?

Select 3 answers
A.Threat actor
B.Asset/resource
C.Mitigation cost
D.Threat event
E.Detection speed
AnswersA, B, D

The threat actor is the party who could exploit a vulnerability or trigger the event. Naming a specific actor — insider, criminal group, nation-state — grounds the scenario in a realistic capability and intent, which is essential for estimating likelihood within the ISACA risk scenario template.

Why this answer

According to the ISACA risk scenario template, a realistic risk scenario must combine a threat actor (option A), the asset/resource at risk (option B), and the threat event itself (option D). The threat actor identifies who or what could cause harm (e.g., an external attacker, insider, or natural force), the asset/resource specifies what is being targeted or affected (e.g., a database, service, or facility), and the threat event describes the specific action or occurrence that exploits a vulnerability (e.g., SQL injection, ransomware execution, or fire). Together these three elements form the core structure of an ISACA risk scenario, enabling consistent identification, analysis, and communication of risk.

Mitigation cost (option C) is a response/treatment consideration, not a defining component of the scenario itself, and detection speed (option E) is a control effectiveness metric rather than an essential scenario element.

Exam trap

CRISC often tests whether candidates confuse the structural components of a risk scenario (actor, asset, event) with downstream risk-management activities such as mitigation cost or detection capability, which are not part of the template.

39
MCQeasy

A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?

A.Avoidance
B.Transfer
C.Acceptance
D.Mitigation
AnswerC

Acceptance suits this scenario because the residual risk falls within tolerance: the vulnerability affects a legacy application serving few users on a non-critical process, and patching is not immediately feasible. Formally documenting and monitoring that accepted exposure satisfies the stem's constraints, whereas mitigation, transfer or avoidance would demand disproportionate cost or effort.

Why this answer

Acceptance is the most appropriate response because the vulnerability exists in a legacy application that supports a non-critical business process and is used by a small number of users. The cost and operational impact of patching or replacing the application outweigh the risk, making it acceptable to operate with the known vulnerability under formal risk acceptance.

Exam trap

The trap here is that candidates often choose mitigation by default, failing to recognize that when a vulnerability cannot be patched and the asset is low-impact, formal acceptance is the correct risk response per the CRISC framework.

How to eliminate wrong answers

Option A is wrong because avoidance would require removing the application or the process entirely, which is unnecessary for a non-critical process with limited user exposure. Option B is wrong because transfer (e.g., via cyber insurance or outsourcing) does not eliminate the technical vulnerability; it only shifts financial liability, and the underlying risk remains in the application. Option D is wrong because mitigation (e.g., applying a vendor patch, implementing a WAF rule, or hardening the host) is not immediately feasible for a legacy application that cannot be patched, and the low business impact does not justify the effort.

40
Multi-Selectmedium

Which TWO of the following are primary purposes of risk and control monitoring? (Choose two.)

Select 2 answers
A.To identify opportunities for implementing new controls.
B.To ensure compliance with all regulatory requirements.
C.To verify that controls are operating as intended.
D.To provide assurance to stakeholders on risk management.
E.To eliminate all residual risk.
AnswersC, D

Verification of control effectiveness is a core monitoring objective.

Why this answer

The primary purpose of risk and control monitoring is to verify that controls are operating as intended. This involves ongoing testing and observation to ensure that control activities are effectively mitigating risks to the desired level. Without this verification, an organization cannot confirm that its risk responses are actually working.

Exam trap

The trap here is that candidates often confuse the primary purpose of monitoring (verifying control effectiveness) with secondary or broader objectives like identifying new controls or ensuring full compliance, leading them to select options that are not the core focus of risk and control monitoring.

41
MCQmedium

A company is implementing a new access control system. According to the project plan, user training will be delivered after the system goes live. What change management issue does this present?

A.Training after go-live ensures the system is fully operational
B.Training after go-live is more effective because users have context
C.Training after go-live reduces the project budget
D.Training after go-live may lead to user errors and security incidents
AnswerD

Delaying training until after go-live means users operate the new access control system without knowing correct procedures, producing misconfigurations and access errors that become security incidents, directly violating the change management requirement that users be prepared before implementation.

Why this answer

Training should ideally be delivered before go-live to ensure users can operate the system securely. Delaying training increases the risk of errors and security incidents.

42
Multi-Selectmedium

An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?

Select 3 answers
A.Using consistent risk metrics and terminology across IT and enterprise levels
B.Aligning IT risk appetite with enterprise risk appetite
C.Reporting IT risk as a component of broader operational risk
D.Maintaining a separate IT risk register not shared with ERM
E.Reporting IT risks only to the CIO without board visibility
AnswersA, B, C

Shared metrics and terminology let IT risk data roll up into enterprise reporting without translation loss, enabling aggregation and comparison across the ERM framework. This consistency is a foundational integration activity, aligning how risk is measured and described at both levels.

Why this answer

Option A is correct because using consistent risk metrics and terminology across IT and enterprise levels enables IT risk data to be aggregated, compared, and communicated within the ERM framework rather than being siloed in IT-specific language. Option B is correct because aligning IT risk appetite with enterprise risk appetite ensures IT risk tolerances and thresholds are derived from and consistent with the organization's overall risk appetite, which is a core requirement of ERM integration. Option C is correct because reporting IT risk as a component of broader operational risk allows IT risk to be consolidated into enterprise risk reporting, giving leadership a holistic view of risk exposure.

Option D does not belong because maintaining a separate IT risk register not shared with ERM perpetuates silos and prevents aggregation and enterprise-level visibility. Option E does not belong because reporting IT risks only to the CIO without board visibility excludes key governance stakeholders and contradicts the top-down, board-engaged nature of ERM integration.

Exam trap

The trap here is that candidates may think maintaining a separate IT risk register is acceptable for specialized IT risks, but CRISC emphasizes that integration requires sharing and aligning risk information across all levels, not isolating it.

43
MCQhard

During a quarterly risk review, it is discovered that a previously accepted risk has materialized due to a change in the external environment. What is the MOST appropriate response?

A.Report to regulators.
B.Increase insurance coverage.
C.Accept the impact.
D.Re-evaluate the risk treatment plan.
AnswerD

Re-evaluating the risk treatment plan addresses the changed external environment by reassessing likelihood and impact against the new conditions, then selecting revised controls or acceptance. Since the previously accepted risk has materialised, the original treatment decision is invalid; the plan must be updated before any further action.

Why this answer

When a previously accepted risk materializes due to a change in the external environment, the risk treatment plan is no longer valid. The most appropriate response is to re-evaluate the risk treatment plan (Option D) because the original acceptance decision was based on assumptions that have now changed. This ensures that new controls or alternative treatments are considered to address the realized risk effectively.

Exam trap

The trap here is that candidates may confuse 'accept the impact' (Option C) with the original acceptance decision, failing to recognize that a materialized risk due to environmental change invalidates the prior acceptance and requires a new treatment evaluation.

How to eliminate wrong answers

Option A is wrong because reporting to regulators is not the immediate or most appropriate response; regulatory reporting is typically required only when specific compliance obligations are triggered, not for every materialized risk. Option B is wrong because increasing insurance coverage is a risk transfer mechanism that may be considered after re-evaluation, but it does not address the root cause or immediate impact of the realized risk. Option C is wrong because accepting the impact implies no further action, which ignores the need to reassess the risk treatment in light of the changed environment and potentially prevent future occurrences.

44
MCQeasy

A company is migrating its customer database to a public cloud provider. During the planning phase, which of the following is the MOST effective approach to identify risks specific to this migration?

A.Review industry risk reports for similar migrations
B.Rely on the cloud provider's published risk documentation
C.Perform a compliance checklist review
D.Conduct a threat modeling exercise focusing on the cloud architecture
AnswerD

Threat modelling systematically examines the cloud architecture's data flows, trust boundaries and entry points, exposing migration-specific risks such as misconfigured storage exposure or insecure APIs. This directly satisfies the planning-phase requirement to identify risks before controls are designed, unlike generic checklists or post-migration audits.

Why this answer

Conducting a threat modeling exercise (D) is the most effective approach because it systematically identifies threats, vulnerabilities, and attack vectors specific to the cloud architecture, data flow, and trust boundaries of the migration. Unlike generic reviews, threat modeling (e.g., using STRIDE or PASTA) directly addresses the unique risks of moving a customer database to a public cloud, such as misconfigured access controls, insecure APIs, or data exposure during transit.

Exam trap

The trap here is that candidates often choose a compliance checklist (C) or industry reports (A) because they seem thorough and authoritative, but the CRISC exam emphasizes that risk identification must be proactive and architecture-specific, not reactive or generic.

How to eliminate wrong answers

Option A is wrong because industry risk reports provide aggregated, historical data that may not reflect the specific architecture, provider, or configuration of this migration, leading to missed context-sensitive risks. Option B is wrong because relying solely on the cloud provider's published risk documentation shifts responsibility and fails to account for the customer's own configuration errors, shared responsibility model gaps, or application-layer vulnerabilities. Option C is wrong because a compliance checklist review only verifies adherence to regulatory standards (e.g., GDPR, PCI DSS) but does not identify technical threats like privilege escalation, data leakage, or denial-of-service risks unique to the cloud deployment.

45
MCQmedium

During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control will cost $100,000 annually and is expected to reduce the ALE by 80%. What is the net benefit of implementing this control?

A.$100,000
B.$300,000
C.$400,000
D.$500,000
AnswerB

The control reduces ALE by 80%, giving an annualised loss reduction of $400,000. Subtracting the $100,000 annual control cost yields a net benefit of $300,000, satisfying the cost-benefit constraint in the stem. This figure represents the residual value gained after funding the control.

Why this answer

The current annual loss expectancy (ALE) is $500,000. An 80% reduction lowers the ALE by $400,000, resulting in a new ALE of $100,000. The annual control cost is $100,000, so the net benefit is the reduction in ALE ($400,000) minus the control cost ($100,000), which equals $300,000.

Exam trap

CRISC often tests the distinction between gross reduction in ALE and net benefit, tricking candidates into forgetting to subtract the annual control cost from the ALE reduction.

How to eliminate wrong answers

Option A is wrong because $100,000 represents only the annual control cost, not the net benefit after accounting for the ALE reduction. Option C is wrong because $400,000 is the gross reduction in ALE (80% of $500,000) but fails to subtract the $100,000 control cost. Option D is wrong because $500,000 is the original ALE before any control is applied, ignoring both the reduction and the cost of the control.

46
Multi-Selectmedium

A risk practitioner is identifying IT risk scenarios for a new e-commerce platform. The platform will process credit card payments and store customer data. Which TWO of the following are examples of external threats that should be considered in the risk identification process? (Choose two.)

Select 2 answers
A.Organized criminal groups targeting payment card data.
B.Hacktivists protesting the company's business practices.
C.Third-party service providers with inadequate security controls.
D.Disgruntled employees with access to customer databases.
E.Software bugs in the e-commerce application code.
AnswersA, B

Organized criminal groups are external threats motivated by financial gain. They often target e-commerce platforms to steal credit card data. This is a classic external threat that must be included in risk identification for a payment-processing platform. Their high capability and resources make them a significant risk factor.

Why this answer

External threats are actors or events outside the organization that can cause harm. Organized criminal groups and hacktivists are both external threat actors with different motivations. They should be included in risk identification for an e-commerce platform.

The other options describe internal threats or vulnerabilities, which are not external threats.

Exam trap

The trap here is conflating vulnerabilities, such as software bugs or weak third-party controls, with external threats, leading to incorrect categorization.

47
MCQmedium

After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?

A.Formally accept the residual risk
B.Re-assess the inherent risk
C.Reduce current controls to lower costs
D.Implement additional controls despite the cost
AnswerA

When residual risk remains above tolerance but further treatment costs exceed the potential loss, formal risk acceptance is the appropriate response. The risk owner documents the decision and escalates to the appropriate authority for sign-off, rather than spending disproportionately on mitigation.

Why this answer

When the residual risk remains above the risk tolerance but the cost of further mitigation exceeds the potential loss, the most appropriate step is to formally accept the residual risk. This decision is based on a cost-benefit analysis showing that additional controls are not economically justified. The risk owner documents the acceptance, acknowledging the remaining exposure within the organization's risk appetite framework.

Exam trap

The CRISC exam often tests the misconception that residual risk must always be reduced to zero or below tolerance regardless of cost, but the correct approach is to accept risk when further mitigation is economically unjustified.

How to eliminate wrong answers

Option B is wrong because re-assessing inherent risk does not address the fact that residual risk is already calculated and above tolerance; inherent risk is the starting point, not the solution to an economic decision. Option C is wrong because reducing current controls would likely increase residual risk further, moving it even farther from tolerance and potentially violating compliance or security baselines. Option D is wrong because implementing additional controls despite the cost violates the fundamental principle of cost-benefit analysis in risk management; it would waste resources without proportional risk reduction.

48
Multi-Selecteasy

Which TWO of the following are examples of inherent risk?

Select 2 answers
A.Risk of unauthorized access due to weak password policy
B.Risk of data breach due to unencrypted sensitive data
C.Residual risk after implementing firewalls
D.Risk appetite defined by the board
E.Risk reduction achieved by multifactor authentication
AnswersA, B

Inherent risk is the exposure present before any controls are applied. A weak password policy is a control deficiency that leaves unauthorised access possible in its natural state, so the resulting risk qualifies as inherent rather than residual.

Why this answer

Inherent risk is the level of risk that exists before any controls or mitigations are applied, so option A (risk of unauthorized access due to weak password policy) qualifies because a weak password policy is a control deficiency that leaves the underlying exposure untreated, making unauthorized access an inherent risk. Option B (risk of data breach due to unencrypted sensitive data) also qualifies because storing sensitive data without encryption is an unmitigated condition, so the resulting breach exposure is inherent rather than residual. Option C is incorrect because residual risk is what remains after controls such as firewalls are implemented, which is the opposite of inherent risk.

Option D is incorrect because risk appetite is a governance decision about how much risk an organization is willing to accept, not a risk example. Option E is incorrect because risk reduction from multifactor authentication describes the effect of a control, not an inherent exposure.

Exam trap

The trap here is confusing inherent risk with residual risk or control effectiveness; candidates often pick options that describe the result of controls (like risk reduction) or the state after controls (residual risk) instead of the raw, uncontrolled exposure.

49
Multi-Selectmedium

Which TWO of the following are key risk identification techniques used to identify threats and vulnerabilities in IT systems? (Select exactly 2.)

Select 2 answers
A.Risk mitigation
B.Vulnerability scanning
C.Risk transfer
D.Threat modeling
E.Access control implementation
AnswersB, D

Vulnerability scanning directly satisfies the stem's requirement to identify threats and vulnerabilities in IT systems. It probes hosts and applications against known signature databases, enumerating missing patches, misconfigurations and exposed services. This produces concrete, system-level weakness evidence rather than speculative risk scenarios, making it a core risk identification technique.

Why this answer

Vulnerability scanning (B) is a key risk identification technique because it actively probes systems, networks, and applications with tools like Nessus, Qualys, or OpenVAS to enumerate known CVEs, missing patches, and misconfigurations, producing concrete evidence of existing vulnerabilities. Threat modeling (D) is also a key risk identification technique because it systematically analyzes a system's architecture, data flows, and trust boundaries (e.g., via STRIDE or DREAD) to enumerate potential threats and weaknesses before or during design. By contrast, risk mitigation (A) and risk transfer (C) are risk response/treatment strategies (alongside avoidance and acceptance), not identification methods, and access control implementation (E) is a preventive security control rather than a technique for discovering threats and vulnerabilities.

Exam trap

The trap here is confusing risk identification techniques (like scanning and modeling) with risk response strategies (like mitigation, transfer, or control implementation), leading candidates to select options that are actually post-identification actions.

50
MCQhard

A risk assessment for a healthcare organization reveals a high likelihood of data breaches due to weak encryption on portable devices. The organization decides to deploy full-disk encryption and enforce multi-factor authentication. Which risk response strategy is being applied?

A.Transfer
B.Acceptance
C.Avoidance
D.Mitigation
AnswerD

Full-disk encryption and multi-factor authentication directly reduce the likelihood of portable-device breaches, satisfying the stem's high-likelihood constraint. This is mitigation: applying controls to lower inherent risk rather than transferring it via insurance, avoiding it by ceasing the activity, or accepting it unchanged.

Why this answer

Deploying full-disk encryption and multi-factor authentication directly reduces the likelihood and/or impact of data breaches from weak encryption on portable devices. This is the definition of risk mitigation — applying controls to lower risk to an acceptable level. The organization is actively reducing the vulnerability, not transferring, accepting, or avoiding the risk.

Exam trap

The trap here is that candidates often confuse 'avoidance' with 'mitigation' — avoidance eliminates the risk by discontinuing the activity (e.g., banning portable devices), while mitigation reduces the risk through controls like encryption and MFA.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial burden of a loss to a third party (e.g., cyber insurance), not implementing technical controls like encryption or MFA. Option B is wrong because risk acceptance means acknowledging the risk and taking no proactive action to reduce it, which contradicts the decision to deploy new security measures. Option C is wrong because risk avoidance would mean ceasing the use of portable devices entirely or eliminating the process that creates the risk, not strengthening the protection on those devices.

51
MCQeasy

Which of the following is the BEST practice for determining the frequency of control monitoring activities?

A.Standardize all controls to quarterly monitoring
B.Monitor only after a control failure is detected
C.Set frequency based solely on regulatory minimum requirements
D.Align monitoring frequency with risk level and control effectiveness assessment
AnswerD

Monitoring frequency should reflect the risk each control addresses and how well it currently performs, so higher-risk or weaker controls are tested more often. This risk-based alignment directs limited assurance effort where exposure is greatest, rather than applying a uniform schedule.

Why this answer

Control monitoring frequency should be driven by the assessed risk level and the effectiveness of existing controls. High-risk areas or controls with lower effectiveness require more frequent monitoring to ensure timely detection of failures, while low-risk or highly effective controls can be monitored less often, optimizing resource allocation.

Exam trap

The trap here is that candidates often choose Option C (regulatory minimums) because they confuse compliance-driven minimums with best practice, failing to recognize that risk-based monitoring is more adaptive and effective for real-world risk management.

How to eliminate wrong answers

Option A is wrong because standardizing all controls to quarterly monitoring ignores the varying risk profiles and control effectiveness across different assets and processes, leading to either over-monitoring low-risk areas or under-monitoring high-risk ones. Option B is wrong because monitoring only after a control failure is detected is reactive and violates the principle of continuous monitoring; it allows failures to persist undetected until a breach occurs, increasing exposure. Option C is wrong because setting frequency based solely on regulatory minimum requirements ignores the organization's specific risk appetite and control performance, potentially leaving critical risks unmonitored between compliance cycles.

52
MCQeasy

Which of the following is an example of a 'configuration vulnerability' that should be identified during vulnerability assessment?

A.A buffer overflow in a custom application
B.An SQL injection flaw in a web form
C.Default administrative passwords left unchanged on a network device
D.Missing security patches on a server
AnswerC

Unchanged default administrative passwords on network devices constitute a configuration vulnerability because the weakness arises from how the device was set up, not from a software defect. This satisfies the stem's requirement by exposing an exploitable misconfiguration that vulnerability assessment should identify, since attackers routinely scan for vendor-default credentials.

Why this answer

A configuration vulnerability arises from improper system settings. Leaving default passwords unchanged is a classic configuration weakness.

53
MCQeasy

A risk manager notices that a key risk indicator (KRI) for failed login attempts has exceeded the threshold for three consecutive weeks. Which of the following should be the FIRST action?

A.Investigate the root cause of the increase.
B.Adjust the threshold to reduce false positives.
C.Report the breach to the senior management immediately.
D.Ignore the trend as a statistical anomaly.
AnswerA

A KRI breaching threshold for three consecutive weeks signals a sustained control failure, so root-cause investigation must precede escalation or remediation. This satisfies the FIRST-action constraint by establishing why failed logins rose before selecting treatment, avoiding premature or misdirected responses.

Why this answer

When a KRI exceeds its threshold for multiple consecutive periods, the first action is to investigate the root cause to determine whether the increase indicates a genuine security issue (e.g., brute-force attack, credential stuffing) or a false positive. Jumping to reporting or threshold adjustment without understanding the underlying cause could lead to misallocation of resources or missed detection of an actual threat. This aligns with the CRISC principle that risk indicators must be validated before escalation or remediation.

Exam trap

The trap here is that candidates often choose immediate escalation (Option C) because they assume any threshold breach must be reported, but CRISC emphasizes that the first step is always to investigate and validate the indicator before escalating.

How to eliminate wrong answers

Option B is wrong because adjusting the threshold without first investigating the root cause may mask a real security incident, such as an ongoing brute-force attack, and violates the principle of maintaining KRI integrity. Option C is wrong because immediate reporting to senior management should occur only after the root cause is understood and the risk impact is assessed; premature reporting can cause unnecessary alarm or misinformed decisions. Option D is wrong because ignoring a three-week consistent trend as a statistical anomaly dismisses a potential pattern of malicious activity, such as a distributed password-spraying attack, which is a common oversight in risk monitoring.

54
MCQmedium

An organization deployed a new intrusion detection system (IDS) that generates many alerts. The security team is overwhelmed and has started ignoring some alerts. What is the BEST way to address this issue?

A.Implement a SIEM to filter and prioritize alerts.
B.Deactivate the IDS until it can be properly configured.
C.Tune the IDS to reduce false positive alerts.
D.Hire additional security analysts to handle the alert volume.
AnswerC

Tuning the IDS reduces false positives by adjusting detection thresholds and signatures to match the environment's normal traffic baseline. This directly addresses the alert fatigue constraint in the stem, where excessive benign alerts cause analysts to ignore genuine threats. Fewer false positives restore trust in alerts and preserve detection of real intrusions.

Why this answer

Tuning the IDS to reduce false positive alerts directly addresses the root cause of alert fatigue: excessive noise from misconfigured or overly sensitive detection rules. By adjusting thresholds, signatures, and exclusion lists, the security team can focus on genuine threats without being overwhelmed, which is a core risk monitoring and reporting practice.

Exam trap

The trap here is that candidates often choose 'Implement a SIEM' (Option A) thinking it solves alert overload, but CRISC emphasizes that monitoring tools must first be properly configured before layering additional technology, and tuning the source system is the most direct and cost-effective control.

How to eliminate wrong answers

Option A is wrong because implementing a SIEM to filter and prioritize alerts does not fix the underlying issue of poorly tuned IDS rules; it merely adds another layer that may still pass through excessive false positives, delaying true threat detection. Option B is wrong because deactivating the IDS removes all monitoring capability, creating a security gap that exposes the organization to undetected attacks, which is not a risk-acceptable approach. Option D is wrong because hiring additional analysts only treats the symptom of high alert volume without reducing the noise; it increases operational cost without addressing the root cause of misconfigured detection logic.

55
MCQmedium

A retail company uses a manual control to verify that all credit card transactions are processed by authorized payment terminals. The control requires a store manager to compare a daily transaction log against a list of approved terminal IDs. The company processes an average of 10,000 transactions per day across 200 stores. During a recent internal audit, it was found that 15% of stores had not completed the reconciliation for the past month. The audit also revealed that several unauthorized terminals had been used to process transactions, resulting in a data breach of customer payment information. The company's risk appetite for payment card data security is very low. The current monitoring approach includes a quarterly review of control performance by the internal audit team. The risk manager needs to recommend improvements to the monitoring of this control. Which of the following is the BEST recommendation?

A.Increase internal audit reviews of the control to monthly.
B.Implement disciplinary actions for store managers who skip reconciliations.
C.Automate the reconciliation by integrating the transaction log with the approved terminal list.
D.Provide refresher training to all store managers on the procedure.
AnswerC

Automating the reconciliation removes the human failure that left 15% of stores unchecked, enforcing every transaction against the approved terminal list daily. Given the very low risk appetite and demonstrated breach, this satisfies the need for reliable, continuous control monitoring rather than periodic manual review.

Why this answer

The control failure is systemic: 15% of stores skipped manual reconciliation, and unauthorized terminals processed transactions, indicating the manual control is not reliably performed at scale (10,000 transactions/day, 200 stores). Automating the reconciliation by integrating the transaction log with the approved terminal list removes human error, enforces consistency, and provides timely detection aligned with the very low risk appetite for payment card data. This is the best recommendation because it addresses the root cause (manual, error-prone process) rather than treating symptoms.

Exam trap

CRISC often tests whether candidates choose a control improvement that addresses the root cause versus administrative actions (training, discipline, more audits) that only treat symptoms, especially when risk appetite is very low.

How to eliminate wrong answers

Option A is wrong because increasing internal audit reviews to monthly only improves oversight frequency; it does not fix the underlying manual control that 15% of stores already failed to perform, so detection remains after-the-fact. Option B is wrong because disciplinary actions are a deterrent, not a control improvement; they do not prevent unauthorized terminals from processing transactions and rely on managers already not complying. Option D is wrong because refresher training addresses awareness but not the structural weakness of a manual reconciliation process that is impractical at 10,000 transactions/day across 200 stores.

56
MCQeasy

A retail company is conducting a risk assessment for its point-of-sale (POS) systems. The risk team determines that the inherent risk of a malware attack is high. The company implements endpoint detection and response (EDR) tools and network segmentation. After these controls, the risk is re-evaluated. What is this re-evaluated risk called?

A.Control risk
B.Detection risk
C.Inherent risk
D.Residual risk
AnswerD

Residual risk is the remaining risk after controls have been implemented. After deploying EDR tools and network segmentation, the risk of a malware attack is reduced but not eliminated. The re-evaluated risk level is therefore the residual risk, which reflects the effectiveness of the controls.

Why this answer

Residual risk is the risk that remains after controls are implemented. In this scenario, the company applied EDR and network segmentation to reduce the high inherent risk of malware. The re-evaluated risk is the residual risk, which should be compared to the organization's risk appetite to determine if further action is needed.

Exam trap

The trap here is confusing residual risk with inherent risk or control risk, especially when a scenario describes both before and after control states.

57
MCQeasy

A risk practitioner has completed a risk assessment and documented the findings. Management must now decide how to address each identified risk. Which of the following BEST describes the purpose of the risk response process?

A.To document the inherent risk rating for each asset so it can be reported to regulators
B.To transfer ownership of every risk to the information security team for remediation
C.To eliminate all identified risks regardless of the cost of the controls required
D.To select and implement actions that bring residual risk within the organization's risk appetite
AnswerD

The risk response process exists to move exposure from its assessed level to a level the organization is willing to tolerate. Selecting and implementing mitigation, transfer, avoidance, or authorized acceptance achieves that alignment. It is the bridge between knowing what the risk is and doing something proportionate about it, and it is judged by whether residual risk lands within the appetite the board has approved.

Why this answer

Risk response is the decision and action phase that follows assessment. Its purpose is to bring residual risk into alignment with the organization's risk appetite through mitigation, transfer, avoidance, or authorized acceptance. It is not about eliminating all risk, merely documenting ratings, or centralizing ownership in one team; it is about taking proportionate, accountable action on the exposures that matter.

Exam trap

The trap here is confusing the documentation of risk ratings with the act of responding to risk, when recording a rating leaves the exposure unchanged.

58
MCQmedium

An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?

A.Risk assessment methodology
B.Risk treatment process
C.Risk management policy
D.Risk register
AnswerA

A defined risk assessment methodology supplies common criteria, scales and scoring, so different business units identify and evaluate risks consistently. Without it, assessments vary by assessor and cannot be aggregated, failing the stem's requirement for enterprise-wide consistency in identification and assessment.

Why this answer

A risk assessment methodology provides a standardized approach for identifying, analyzing, and evaluating risks. It ensures that all business units use consistent criteria, scales, and processes, which is essential for comparing and aggregating risks across the enterprise. Without a common methodology, risk assessments become subjective and inconsistent, undermining the risk management program.

Exam trap

CRISC often tests the distinction between governance elements (policy) and operational elements (methodology, process, register); candidates may incorrectly choose the policy because it sounds foundational, but the question asks for the component ensuring consistent identification and assessment, which is the methodology.

How to eliminate wrong answers

Option B is wrong because the risk treatment process focuses on selecting and implementing controls after risks are assessed; it does not ensure consistent identification and assessment. Option C is wrong because the risk management policy sets high-level direction and objectives but does not provide the detailed procedures needed for consistent risk identification and assessment. Option D is wrong because the risk register is a tool for recording and tracking risks; it depends on the methodology to populate it consistently and does not itself ensure consistency.

59
MCQmedium

An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?

A.Accept
B.Avoid
C.Mitigate
D.Transfer
AnswerD

Outsourcing with contractual penalties shifts financial loss from security breaches to the cloud provider. Transfer moves risk to a third party via contract, unlike avoid, mitigate or accept. The penalties clause confirms the loss is borne externally, satisfying the transfer definition.

Why this answer

Outsourcing data center operations to a cloud provider with contractual penalties for security breaches shifts the financial impact of a risk event to a third party. This is the definition of risk transfer, where the organization pays another party (via contract, insurance, or outsourcing) to bear the risk. The strict contractual penalties ensure the provider absorbs the cost if a breach occurs, which is the hallmark of transfer.

Exam trap

CRISC often tests the distinction between risk transfer and risk mitigation, where candidates incorrectly choose 'mitigate' because contractual penalties seem like a control, but the key is that the financial impact is shifted to a third party.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and retaining the potential loss without taking action to shift or reduce it; here the organization is actively shifting the loss to the provider. Option B is wrong because risk avoidance means eliminating the activity or process that generates the risk entirely (e.g., not outsourcing at all), whereas the organization is continuing the activity but shifting the risk. Option C is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact of the risk while retaining it, not transferring the financial consequence to a third party via contract.

60
MCQmedium

An organization uses a qualitative risk assessment methodology. During a recent assessment, several risks were rated as 'high' due to vague definitions. What is the BEST way to improve the accuracy of the assessment?

A.Switch to a quantitative methodology
B.Assign a single expert to rate all risks
C.Use historical loss data as the primary input
D.Define clear and objective rating criteria for likelihood and impact
AnswerD

Vague high ratings stem from subjective interpretation of likelihood and impact. Defining clear, objective rating criteria gives assessors consistent anchors, so ratings reflect actual risk rather than individual judgement, directly fixing the inconsistency described in the stem.

Why this answer

Vague rating criteria lead to inconsistent and subjective risk scores. By defining clear and objective rating criteria for likelihood and impact, the organization ensures that all assessors apply the same standards, reducing ambiguity and improving the accuracy of the qualitative assessment.

Exam trap

The trap here is that candidates often assume quantitative methods are always more accurate, but the question specifically highlights vague definitions as the root cause, which is best addressed by refining the qualitative criteria rather than changing the methodology.

How to eliminate wrong answers

Option A is wrong because switching to a quantitative methodology does not address the root cause of vague definitions; it introduces new requirements for numerical data that may not be available or reliable, and does not inherently improve the consistency of risk ratings. Option B is wrong because assigning a single expert to rate all risks introduces personal bias and does not eliminate the underlying problem of vague criteria; it merely centralizes the subjectivity. Option C is wrong because historical loss data is often incomplete, not directly applicable to emerging threats, and may not reflect current control effectiveness; using it as the primary input does not resolve the ambiguity in rating definitions.

61
MCQhard

A risk manager is evaluating the potential impact of quantum computing on the organization's encryption infrastructure. The organization uses RSA-2048 for key exchanges and digital signatures. According to current quantum computing projections, what is the MOST urgent risk management action to take?

A.Immediately replace all RSA-2048 keys with symmetric encryption
B.Begin a cryptographic inventory and develop a migration plan to post-quantum cryptography
C.Purchase cyber insurance to cover potential losses from quantum attacks
D.Increase the RSA key length to 4096 bits
AnswerB

RSA-2048 is vulnerable to Shor's algorithm, so a cryptographic inventory identifying where RSA is used, followed by migration planning toward post-quantum algorithms, addresses the harvest-now-decrypt-later threat. This satisfies the stem's urgency requirement, since long-lived encrypted data can be captured today and decrypted later.

Why this answer

Quantum computers capable of breaking RSA-2048 are not imminent but expected within 10-20 years. The most urgent action is to start planning for post-quantum cryptography migration, as it requires long lead times for assessment and implementation.

62
MCQmedium

An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:

A.Residual risk calculation
B.Inherent risk assessment
C.Cost-benefit analysis
D.Risk acceptance
AnswerC

Cost-benefit analysis weighs the WAF's implementation cost against the reduced likelihood and impact of a successful SQL injection attack, which is exactly the comparison described. Control selection and risk assessment lack the explicit monetary trade-off, while residual risk evaluation occurs after treatment.

Why this answer

The risk manager is comparing the cost of implementing the WAF against the likelihood and potential impact of a SQL injection attack. This direct comparison of mitigation cost to risk reduction benefit is the essence of a cost-benefit analysis, which determines whether the control is economically justified. It is not a calculation of residual or inherent risk, nor is it an acceptance decision.

Exam trap

The trap here is that candidates confuse the evaluation of a control's cost against risk reduction with inherent risk assessment, but inherent risk is calculated without any controls in place, whereas this scenario explicitly involves weighing the cost of a specific control against the risk it mitigates.

How to eliminate wrong answers

Option A is wrong because residual risk calculation determines the risk remaining after controls are implemented, not the evaluation of whether to implement a control in the first place. Option B is wrong because inherent risk assessment evaluates the risk level before any controls are applied, without considering the cost of mitigation. Option D is wrong because risk acceptance is a formal decision to tolerate a risk without implementing additional controls, which is not what is happening when the manager evaluates the cost of a proposed control.

63
MCQmedium

A Key Risk Indicator (KRI) that shows a rising trend in the average time to apply critical security patches suggests:

A.Decreasing risk of exploitation
B.Stable risk level
C.Increasing risk of exploitation
D.Improved control effectiveness
AnswerC

A rising average patch time means critical vulnerabilities remain exploitable for longer, widening the window attackers can leverage. The KRI measures exposure duration, so the upward trend directly signals growing likelihood of successful exploitation rather than improved remediation.

Why this answer

A rising trend in the average time to apply critical security patches indicates that systems remain vulnerable for longer periods, increasing the likelihood of exploitation. This is a lagging indicator of control effectiveness and directly points to increased risk.

Exam trap

Candidates may confuse KRIs with KPIs and think a rising trend in a security metric means improved performance, but here it's a risk indicator.

How to eliminate wrong answers

Option A is wrong because decreasing risk would be indicated by a falling trend in patch time, not rising. Option B is wrong because a rising trend indicates a change, not stability. Option D is wrong because improved control effectiveness would result in faster patching, not slower.

64
MCQhard

In the FAIR framework, loss magnitude (LM) is composed of primary loss and secondary loss. Which of the following is an example of secondary loss?

A.Incident response costs
B.Lost business due to reputation damage
C.Legal notification costs
D.System restoration expenses
AnswerB

Lost business from reputation damage is a secondary loss because it is a consequential, stakeholder-driven effect rather than the direct primary loss from the threat event itself. FAIR separates these: primary loss hits the affected asset, while secondary loss captures reactions such as customer defection, satisfying the stem's requirement for a secondary-loss example.

Why this answer

Secondary loss includes indirect costs like reputational damage, loss of customer trust, and share price impact.

65
MCQhard

A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?

A.Perform a new risk assessment
B.Interview control owners
C.Review risk register updates
D.Conduct a control testing and audit review
AnswerD

Control testing and audit review examines whether the technical controls operate as designed and whether staff actually follow them, directly addressing the suspected compliance gap. It produces evidence of control effectiveness, confirming whether residual risk remains elevated because of non-adherence rather than poor control design.

Why this answer

Conducting a control testing and audit review directly assesses whether controls are operating as intended, providing evidence of compliance or non-compliance. This is the most effective way to verify if controls are being followed. Option A (perform a new risk assessment) is indirect and does not focus on control effectiveness.

Option B (interview control owners) relies on self-reporting and may not be objective. Option C (review risk register updates) does not provide evidence of actual control operation.

66
MCQmedium

A risk analyst is assessing a newly discovered vulnerability in an internet-facing server. The analyst collects several data points: the vulnerability has a CVSS base score of 9.8, there are known exploits in the wild, and the server is critical for processing customer transactions. However, the organization's intrusion detection system has a signature that blocks the specific exploit, and the server is patched monthly. The analyst must determine the risk level. Which of the following should the analyst use to BEST assess the risk?

A.A qualitative risk assessment using a likelihood-impact matrix that incorporates the effectiveness of existing controls and threat intelligence.
B.The CVSS base score alone, because it provides a standardized severity rating.
C.The exploitability subscore of CVSS, because it measures the difficulty of exploiting the vulnerability.
D.The asset's replacement cost, because risk is a function of financial impact.
AnswerA

This approach integrates the vulnerability severity with the organization's control environment (IDS, patching) and real-world threat data (exploits in the wild) to produce a contextual risk rating. It aligns with CRISC's emphasis on business-relevant risk assessment. The analyst can then prioritize remediation based on actual risk exposure rather than raw severity.

Why this answer

The analyst must assess risk by combining vulnerability severity, threat activity, existing controls, and asset criticality. A qualitative matrix that incorporates control effectiveness and threat intelligence provides a business-contextualized risk rating, which is essential for prioritization. CVSS base scores or subscores are inputs but not sufficient alone, and financial impact alone misses likelihood and control factors.

Exam trap

The trap here is assuming that a high CVSS base score directly equates to high organizational risk without considering compensating controls and threat context.

67
Multi-Selectmedium

A risk practitioner is reviewing the organization's cryptographic key management practices after an audit finding. Which TWO of the following practices are MOST important to protect the confidentiality and integrity of cryptographic keys throughout their lifecycle? (Choose two.)

Select 2 answers
A.Document key custodians in the configuration management database and review the list annually.
B.Define and enforce a cryptoperiod for each key type with scheduled rotation and retirement.
C.Use the same master key across all environments to simplify key management and reduce operational cost.
D.Email encrypted key backups to the security team's shared mailbox for disaster recovery availability.
E.Store keys in a hardware security module (HSM) or managed key vault with strict access controls.
AnswersB, E

A defined cryptoperiod limits the volume of data protected by a single key and bounds the damage if a key is compromised. Scheduled rotation, rekeying, and secure retirement ensure keys do not outlive their intended use, satisfying lifecycle governance requirements and reducing exposure from undetected key compromise.

Why this answer

Protecting keys across their lifecycle requires both a secure execution and storage environment and disciplined lifecycle governance. Hardware security modules or managed vaults keep key material confidential and enforce access, while a defined cryptoperiod with rotation and retirement limits how much data any single key protects. Email distribution of backups, shared master keys across environments, and custodian documentation do not provide these protections.

Exam trap

The trap here is selecting administrative documentation or convenience-driven practices as if they protected the key material itself.

68
MCQhard

A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?

A.A planned system upgrade may cause two hours of downtime during maintenance window
B.A vendor is late in delivering a software patch for a low-severity bug
C.A new cloud service may inadvertently expose customer PII due to misconfiguration
D.An employee mistakenly deletes a non-critical test database
AnswerC

Misconfiguration exposing customer PII breaches data-protection obligations, so it sits squarely in the low-tolerance compliance category rather than the moderate operational risk the company accepts. That mismatch with the stated risk appetite triggers immediate escalation to senior management, since regulatory penalties and notification duties cannot be absorbed within the accepted operational threshold.

Why this answer

The risk appetite statement explicitly declares low tolerance for compliance risk, and exposing customer PII triggers regulatory/legal obligations (e.g., GDPR, CCPA, contractual data-protection clauses). Because compliance risk is the organization's stated low-tolerance area, any scenario with potential PII exposure must be escalated immediately to senior management. The other scenarios fall within the 'moderate operational risk' appetite the company has already accepted.

Exam trap

CRISC often tests the distinction between risk appetite/tolerance statements and incident severity — candidates pick the most dramatic-sounding operational event instead of matching the scenario to the stated low-tolerance category (compliance).

How to eliminate wrong answers

Option A is wrong because planned maintenance downtime is a routine operational risk that falls within the company's stated moderate operational risk appetite. Option B is wrong because a late patch for a low-severity bug is a minor operational/supply-chain issue, not a compliance breach. Option D is wrong because deleting a non-critical test database is an operational incident with no regulatory or PII implications and is within the accepted operational risk tolerance.

69
MCQhard

A risk practitioner notices that the number of failed authentication attempts has spiked by 300% over the past week. Which of the following actions should be taken FIRST?

A.Report the spike to the board
B.Implement multi-factor authentication
C.Increase the frequency of password changes
D.Analyze the logs to identify the source and nature of the attempts
AnswerD

Analysing logs establishes whether the 300% spike reflects a brute-force attack, misconfigured application or credential-stuffing campaign. This satisfies the first-action constraint by determining the source and nature of the attempts before escalating, blocking or notifying, avoiding a premature response to an unidentified cause.

Why this answer

The first step in responding to a security incident, such as a 300% spike in failed authentication attempts, is to analyze the logs to determine the source and nature of the activity. This aligns with the NIST incident response lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery) where analysis precedes any containment or reporting action. Without understanding whether the spike is due to a brute-force attack, a misconfigured application, or a credential-stuffing campaign, any subsequent action could be premature or ineffective.

Exam trap

The trap here is that candidates often jump to implementing a security control (like MFA or password changes) as a first response, but CRISC emphasizes that analysis and understanding of the risk must precede any response action.

How to eliminate wrong answers

Option A is wrong because reporting a spike to the board without first analyzing the logs is premature; the board requires actionable, analyzed information, not raw alerts. Option B is wrong because implementing multi-factor authentication (MFA) is a long-term control that should be designed and deployed after understanding the attack vector, not as an immediate response to a log spike. Option C is wrong because increasing the frequency of password changes does not address the root cause of failed authentication attempts (e.g., brute force or credential stuffing) and can actually weaken security by encouraging weak passwords; it is not a first-response action.

70
MCQmedium

During an IT risk assessment, a risk owner identifies a risk that is within the organization's risk appetite. The recommended risk treatment option is to:

A.Accept the risk with formal sign-off.
B.Avoid the risk by eliminating the activity.
C.Transfer the risk through cyber insurance.
D.Mitigate the risk by implementing additional controls.
AnswerA

Acceptance is the appropriate treatment when a risk falls within the organisation's defined risk appetite, since no further mitigation is justified. Formal sign-off preserves accountability and creates an audit trail, satisfying the stem's requirement that the risk owner document the decision rather than transfer, avoid or mitigate it.

Why this answer

When a risk is within appetite, the appropriate response is to accept it, with formal documentation and sign-off by the risk owner.

71
Multi-Selecthard

A multinational corporation is implementing continuous monitoring of its compliance with data privacy regulations across multiple jurisdictions. Which TWO of the following are significant challenges to this approach?

Select 2 answers
A.Inconsistent regulatory requirements across jurisdictions.
B.The need for manual data collection.
C.High cost of automation tools.
D.Difficulty in establishing a single data repository.
E.Lack of skilled personnel.
AnswersA, D

Different laws require tailored monitoring criteria, complicating a unified system.

Why this answer

A is correct because data privacy regulations (e.g., GDPR, CCPA, LGPD) have conflicting requirements for data retention, consent, breach notification, and cross-border transfer. Continuous monitoring must reconcile these differences, often requiring jurisdiction-specific rule sets and mapping controls to multiple legal frameworks, which introduces significant complexity and risk of non-compliance.

Exam trap

The trap here is that candidates often select 'Lack of skilled personnel' (E) as a generic challenge, but the CRISC exam focuses on the technical and process-oriented obstacles specific to continuous monitoring across jurisdictions, such as inconsistent requirements (A) and data repository conflicts (D).

72
MCQeasy

A risk assessment that assigns monetary values to assets and calculates expected loss is called:

A.Qualitative
B.Semi-quantitative
C.Comprehensive
D.Quantitative
AnswerD

Quantitative risk assessment assigns monetary values to assets and calculates expected loss (probability × impact), producing numeric results. This satisfies the stem's requirement for financial valuation and expected-loss calculation, unlike qualitative approaches that rank risks descriptively without monetary figures.

Why this answer

A quantitative risk assessment assigns specific monetary values to assets and calculates expected loss using formulas such as Single Loss Expectancy (SLE) = Asset Value (AV) × Exposure Factor (EF), and Annualized Loss Expectancy (ALE) = SLE × Annualized Rate of Occurrence (ARO). This approach provides objective, numeric risk metrics that support cost-benefit analysis for risk mitigation decisions.

Exam trap

The trap here is that candidates often confuse 'semi-quantitative' with 'quantitative' because both use numbers, but semi-quantitative methods use ordinal scales or weighted scores (e.g., 1-5) rather than actual monetary values and expected loss calculations.

How to eliminate wrong answers

Option A is wrong because qualitative risk assessment uses subjective ratings (e.g., high, medium, low) rather than monetary values and does not calculate expected loss numerically. Option B is wrong because semi-quantitative risk assessment uses ordinal scales or weighted scores to approximate risk levels, but it does not assign precise monetary values or compute expected loss with formulas like SLE and ALE. Option C is wrong because 'comprehensive' is not a recognized category of risk assessment methodology in the CRISC framework; it describes scope, not the quantitative vs. qualitative distinction.

73
Multi-Selecthard

A risk manager is assessing the security posture of a containerized application deployment in a public cloud. The organization uses Kubernetes for orchestration. Which TWO of the following are the MOST significant risks specific to this environment? (Choose two.)

Select 2 answers
A.Container images may contain vulnerable dependencies that are not patched regularly.
B.Container orchestration platforms automatically enforce network segmentation, eliminating the risk of lateral movement.
C.The cloud provider's shared responsibility model means the organization is not responsible for the security of the underlying nodes.
D.Kubernetes secrets are stored unencrypted by default in etcd, allowing attackers with access to etcd to retrieve sensitive data.
E.Kubernetes RBAC is enabled by default and cannot be misconfigured, so access control risks are minimal.
AnswersA, D

Container images often include third-party libraries and base images that may have known vulnerabilities. If not scanned and patched regularly, these vulnerabilities can be exploited to compromise the container and potentially the host. This is a significant risk in containerized environments because images are immutable and may be reused across deployments, propagating vulnerabilities.

Why this answer

The most significant risks are vulnerable container images and unencrypted Kubernetes secrets in etcd. Vulnerable images can introduce exploitable flaws, while unencrypted secrets can be read by attackers with etcd access. Both are specific to containerized Kubernetes environments and require proactive controls such as image scanning and etcd encryption.

The other options describe misconceptions or false assumptions that do not represent the primary risks.

Exam trap

The trap here is being misled by statements that assume automatic security controls, such as automatic network segmentation or default RBAC, rather than recognizing the actual risks of unpatched images and unencrypted secrets.

74
MCQmedium

A risk practitioner notices that a key control is tested only once a year, but the associated risk has a high velocity of change. What is the BEST recommendation?

A.Remove the control if it cannot be tested more often
B.Wait for a control failure before increasing frequency
C.Continue annual testing because it meets regulatory requirements
D.Increase testing frequency to quarterly or monthly
AnswerD

Quarterly or monthly testing matches control verification to the risk's high velocity of change, closing the exposure window that annual testing leaves open. Frequent retesting detects control degradation before it materially affects residual risk, satisfying the stem's requirement that assurance cadence align with how quickly the underlying risk landscape shifts.

Why this answer

A high velocity of change means the risk profile can shift rapidly between annual tests, leaving the organization exposed for months. Increasing testing frequency to quarterly or monthly ensures that control effectiveness is validated in near real-time, aligning monitoring cadence with risk dynamics. This is a core principle of risk-based monitoring: the testing interval must match the speed at which the risk can materialize.

Exam trap

The trap here is that candidates confuse 'meets regulatory requirements' (Option C) with 'adequate risk management,' failing to recognize that compliance is the floor, not the ceiling, when risk velocity is high.

How to eliminate wrong answers

Option A is wrong because removing a control without a compensating alternative increases residual risk to an unacceptable level; the issue is frequency, not the control's existence. Option B is wrong because waiting for a control failure before increasing frequency is reactive and violates the proactive monitoring mandate of CRISC; a high-velocity risk demands preventive adjustment. Option C is wrong because regulatory compliance is a minimum baseline, not a risk-optimized strategy; annual testing is insufficient when the risk can change in weeks.

75
MCQeasy

An organization uses a third-party SaaS provider for payroll processing. Which of the following is the BEST technique to identify risks associated with this vendor?

A.Request a penetration test report from the vendor
B.Check online user reviews and ratings
C.Read the vendor's marketing materials and case studies
D.Review the vendor's SOC 2 Type II report and conduct an on-site assessment
AnswerD

A SOC 2 Type II report provides independent evidence over time that the vendor's controls operate effectively, while an on-site assessment verifies actual implementation. Together they identify payroll-processing risks the vendor's self-reported claims would miss.

Why this answer

The SOC 2 Type II report provides an independent auditor's assessment of the vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time, which is critical for identifying risks in a payroll SaaS processing sensitive employee data. An on-site assessment allows the organization to verify physical and logical controls, observe operations, and discuss specific risk scenarios directly with vendor personnel, offering a deeper risk identification than any single document or review.

Exam trap

The trap here is that candidates often overvalue a penetration test report (Option A) as the definitive risk identification tool, forgetting that for a SaaS payroll provider, operational and compliance risks (e.g., data privacy, availability, change management) are equally or more critical than pure technical vulnerabilities.

How to eliminate wrong answers

Option A is wrong because a penetration test report, while useful for identifying technical vulnerabilities, is a point-in-time assessment that does not cover the full breadth of operational, privacy, and compliance controls needed for a payroll processor handling sensitive personal data. Option B is wrong because online user reviews and ratings are anecdotal, lack technical depth, and are not a reliable or auditable source for identifying specific control weaknesses or compliance gaps. Option C is wrong because marketing materials and case studies are promotional content designed to highlight successes, not to disclose risks, control failures, or security incidents.

Page 1 of 15

Page 2