Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 676–750

1062 questions total · 15pages · All types, answers revealed

Page 9

Page 10 of 15

Page 11
676
MCQmedium

A company is considering outsourcing its data center operations to a cloud provider. Which risk treatment option is the company primarily exercising?

A.Risk avoidance
B.Risk mitigation
C.Risk transfer
D.Risk acceptance
AnswerC

Outsourcing data centre operations shifts the operational risk of hosting, power, and physical security to the cloud provider under contract. The company retains residual and reputational risk, but the primary treatment is transfer, since financial and operational consequences move to a third party.

Why this answer

Risk transfer shifts the financial and operational impact of a risk to a third party, typically through contracts, insurance, or outsourcing arrangements. By outsourcing data center operations to a cloud provider, the company contractsually shifts responsibility for the physical, operational, and infrastructure risks (power, cooling, hardware failure, physical security) to the provider. The risk itself still exists, but the ownership of its consequences is transferred via the service agreement and SLAs.

Exam trap

CRISC often tests the distinction between transferring risk (contractual shift to a third party) and mitigating it (applying controls), so candidates who see 'cloud provider' and think 'security controls' incorrectly pick mitigation.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity or process that generates the risk entirely — the company is still operating its workloads, just on someone else's infrastructure. Option B is wrong because risk mitigation reduces the likelihood or impact of a risk through controls (e.g., encryption, redundancy), whereas outsourcing shifts the responsibility rather than reducing the inherent risk. Option D is wrong because risk acceptance means acknowledging the risk and taking no action, which is the opposite of actively contracting with a cloud provider to offload it.

677
MCQhard

Refer to the exhibit. Based on the exhibit, what is the most appropriate action regarding the control OWF?

A.The control is effective because the traffic was blocked.
B.The control is ineffective because alerts indicate potential malware.
C.The control should be reviewed because the alert frequency is approaching the threshold.
D.No action is needed because the threshold has not been reached.
AnswerC

The alert frequency is nearing the defined threshold, indicating the control is degrading and may soon breach tolerance. Reviewing it now allows remediation before failure, rather than waiting for the threshold to be exceeded, which would leave the risk unmanaged.

Why this answer

The exhibit shows that the OWF (Outbound Web Filtering) control has logged 95 alerts against a threshold of 100. Since the alert frequency is approaching but has not yet reached the threshold, the most appropriate action is to review the control to determine if the threshold is still appropriate or if the control needs tuning. Option C correctly identifies this proactive monitoring step, which aligns with the CRISC domain of Risk and Control Monitoring and Reporting.

Exam trap

The trap here is that candidates assume no action is needed until the threshold is reached, but CRISC emphasizes proactive review when metrics approach thresholds to prevent control failures or misconfigurations.

How to eliminate wrong answers

Option A is wrong because the control being effective is not determined solely by traffic being blocked; the high alert frequency indicates a potential issue that requires review, not a confirmation of effectiveness. Option B is wrong because while alerts may indicate potential malware, the question does not provide evidence that the alerts are false positives or actual malware; the key issue is the frequency approaching the threshold, not the nature of the alerts. Option D is wrong because even though the threshold has not been reached, the proximity to the threshold (95 out of 100) warrants a review to prevent exceeding the threshold and to ensure the control is properly configured.

678
MCQmedium

A software development company is adopting a DevSecOps approach. The risk manager wants to ensure that security risks are identified early in the development lifecycle. Which of the following practices is MOST effective for integrating risk identification into the CI/CD pipeline?

A.Conduct static application security testing (SAST) as part of the build process.
B.Perform dynamic application security testing (DAST) after deployment to production.
C.Implement runtime application self-protection (RASP) in production to block attacks.
D.Require manual code reviews by the security team before each release.
AnswerA

SAST analyzes source code or binaries for security vulnerabilities during the build phase, allowing developers to identify and fix issues early. Integrating SAST into the CI/CD pipeline automates risk identification without slowing down development. It provides immediate feedback and aligns with the shift-left approach, making it the most effective practice for early risk identification in DevSecOps.

Why this answer

SAST integrated into the build process is the most effective for early risk identification because it analyzes code before it is deployed, providing immediate feedback to developers. This shift-left approach reduces the cost and effort of fixing vulnerabilities later. Other practices like DAST, manual reviews, or RASP occur later or are less scalable for continuous integration.

Exam trap

The trap here is selecting DAST or RASP because they are security testing tools, but they do not identify risks early in the development lifecycle as effectively as SAST.

679
MCQeasy

An organization decides to discontinue a high-risk business process that cannot be effectively mitigated. This is an example of which risk treatment option?

A.Risk acceptance
B.Risk transfer
C.Risk mitigation
D.Risk avoidance
AnswerD

Discontinuing the high-risk process eliminates the risk source entirely rather than reducing, transferring or accepting it. Avoidance is the only treatment that removes the activity generating the risk, satisfying the stem's constraint that mitigation cannot effectively reduce it.

Why this answer

Risk avoidance is the deliberate decision to eliminate the activity, process, or asset that gives rise to the risk rather than trying to control it. Discontinuing a high-risk business process removes the risk entirely because the underlying activity no longer exists. This is the only treatment option that makes the risk disappear rather than reducing, sharing, or tolerating it.

Exam trap

The trap here is confusing avoidance with acceptance — both can result in 'doing nothing to the risk,' but avoidance removes the source of risk while acceptance retains it, and the exam uses 'discontinue' or 'cease' as the giveaway keyword for avoidance.

How to eliminate wrong answers

Option A is wrong because risk acceptance means the organization acknowledges the risk and chooses to bear it without action — the process would continue to operate. Option B is wrong because risk transfer involves shifting the risk to a third party (insurance, outsourcing) while the process continues; discontinuing the process does not transfer anything. Option C is wrong because risk mitigation applies controls to reduce likelihood or impact while the process still runs, whereas here the process is being shut down entirely.

680
MCQhard

In the context of threat modeling for a web application, which technique is specifically designed to be integrated into Agile and DevSecOps processes, emphasizing collaboration and visualization?

A.VAST
B.STRIDE
C.TRIKE
D.PASTA
AnswerA

VAST (Visual, Agile, and Simple Threat) modelling produces threat models as scalable, sprint-aligned artefacts, embedding threat identification directly into Agile and DevSecOps workflows. Its visual, collaborative format lets developers and security teams jointly assess threats per user story, satisfying the stem's requirement for a technique designed for Agile integration.

Why this answer

VAST (Visual, Agile, and Simple Threat modeling) is specifically designed for Agile and DevSecOps environments. It emphasizes collaboration and visualization, making it easy to integrate into continuous development processes. Unlike other methodologies, VAST focuses on creating threat models that are actionable and scalable across large organizations.

Exam trap

CRISC often tests the confusion between threat modeling methodologies and their intended use cases, such as mistaking STRIDE for an Agile-friendly approach when it is actually a classification scheme.

How to eliminate wrong answers

Option B is wrong because STRIDE is a threat classification model, not a methodology designed for Agile integration; it focuses on categorizing threats but lacks the collaborative and visualization aspects. Option C is wrong because TRIKE is a risk-based threat modeling methodology that is more compliance-oriented and not specifically tailored for Agile/DevSecOps. Option D is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric methodology that is more heavyweight and not designed for rapid, collaborative Agile processes.

681
MCQhard

A risk manager is evaluating the effectiveness of a control that requires dual authorization for high-value transactions. The Key Control Indicator (KCI) for this control is the rate of transactions processed without dual authorization (i.e., exception rate). If the acceptable exception rate is less than 1% and the observed rate is 2.5%, what is the most appropriate immediate action?

A.Investigate the root cause of the exceptions
B.Redesign the control immediately
C.Accept the risk since the rate is still low
D.Increase the acceptable exception rate to 2.5%
AnswerA

The 2.5% exception rate breaches the 1% acceptable threshold, so the control is failing. Root cause investigation identifies why dual authorisation was bypassed before remediation is chosen, ensuring corrective action addresses the actual failure mechanism rather than symptoms.

Why this answer

The observed exception rate of 2.5% exceeds the acceptable threshold of 1%, indicating a control deficiency. The most appropriate immediate action is to investigate the root cause of the exceptions to determine whether the control is failing due to process gaps, user behavior, or system issues. Root cause analysis (RCA) is a foundational step before any remediation, as it prevents premature redesign or unjustified risk acceptance.

Exam trap

The trap here is that candidates may assume a 2.5% exception rate is still 'low' and choose to accept the risk (Option C), but CRISC emphasizes that any deviation from the acceptable threshold requires investigation and remediation, not automatic acceptance.

How to eliminate wrong answers

Option B is wrong because redesigning the control immediately without understanding why the exceptions occur could introduce new risks or waste resources on an ineffective solution; the control may only need tuning or enforcement. Option C is wrong because accepting a risk that exceeds the defined acceptable exception rate violates the risk appetite and policy, and 2.5% is not 'low' when the threshold is 1%. Option D is wrong because increasing the acceptable exception rate to match the observed rate eliminates the control's effectiveness and undermines the purpose of the KCI, which is to detect and reduce unauthorized transactions.

682
MCQhard

During a risk assessment, the risk practitioner develops a scenario involving a disgruntled employee exfiltrating sensitive customer data through a USB drive. The organization has a strict policy against removable media but lacks technical controls to prevent USB usage. Which element of the risk scenario is the vulnerability?

A.Data exfiltration
B.Lack of technical controls to prevent USB usage
C.Disgruntled employee
D.Sensitive customer data
AnswerB

The vulnerability is the missing technical enforcement of the removable media policy: the absence of controls preventing USB usage is the weakness an attacker exploits. The policy exists, so the gap is technical rather than procedural, enabling the disgruntled employee scenario.

Why this answer

In a risk scenario, the vulnerability is the weakness or gap that can be exploited by a threat. Here, the absence of technical controls to prevent USB usage is the weakness, even though a policy exists. The policy alone does not enforce compliance, so the lack of technical enforcement is the vulnerability.

Exam trap

CRISC often tests the distinction between threat, vulnerability, and asset — candidates frequently mislabel the threat actor or the asset as the vulnerability.

How to eliminate wrong answers

Option A is wrong because data exfiltration is the threat event or impact, not the vulnerability. Option C is wrong because the disgruntled employee is the threat actor (or threat source), not the vulnerability. Option D is wrong because sensitive customer data is the asset at risk, not the vulnerability.

683
MCQeasy

Which of the following best describes risk capacity?

A.The acceptable risk level for each risk category
B.The total risk identified in the risk universe
C.The amount of risk the organization is willing to accept
D.The maximum risk the organization can absorb before threatening viability
AnswerD

Risk capacity defines the absolute upper limit of loss an organisation can withstand before its continued existence is threatened. This satisfies the stem's requirement for the maximum absorbable risk, distinguishing it from risk appetite (willingness) and risk tolerance (acceptable deviation). It reflects the viability threshold, not a preferred operating level.

Why this answer

Risk capacity is the maximum amount of risk an organization can absorb before its viability, solvency, or strategic objectives are threatened — it is an objective, externally-influenced limit. It differs from risk appetite (willingness to accept risk) and risk tolerance (acceptable deviation around appetite). The correct answer captures the 'maximum absorbable' framing that distinguishes capacity from the other risk concepts.

Exam trap

CRISC often tests the confusion between risk appetite, risk tolerance, and risk capacity — candidates frequently pick 'willing to accept' (appetite) when the question asks for the maximum the organization can absorb (capacity).

How to eliminate wrong answers

Option A is wrong because 'the acceptable risk level for each risk category' describes risk tolerance, not capacity — tolerance is the allowable variation around the appetite for a specific category. Option B is wrong because 'the total risk identified in the risk universe' describes the aggregate risk inventory or gross risk exposure, not a capacity limit. Option C is wrong because 'the amount of risk the organization is willing to accept' is the definition of risk appetite — a subjective, board-approved willingness statement, whereas capacity is an objective maximum the organization can withstand.

684
MCQeasy

What is the primary purpose of a control self-assessment (CSA)?

A.To involve process owners in evaluating control effectiveness.
B.To replace external audits.
C.To automate monitoring.
D.To generate compliance reports.
AnswerA

Control self-assessment shifts evaluation to process owners, who judge and document the effectiveness of controls within their own areas. This satisfies the stem's focus on the primary purpose: embedding ownership and accountability rather than relying solely on independent audit testing. It provides earlier, broader risk insight across business processes.

Why this answer

The primary purpose of a control self-assessment (CSA) is to involve process owners in evaluating the effectiveness of controls within their own areas of responsibility. This approach leverages the deep operational knowledge of those who design and execute processes daily, enabling them to identify control gaps and improvement opportunities that external auditors might miss. By fostering ownership and accountability, CSA enhances the control environment without replacing independent assurance functions.

Exam trap

The trap here is that candidates confuse the purpose of CSA with its potential outputs, such as compliance reports or automation, rather than recognizing its core intent to empower process owners in self-evaluation and continuous improvement.

How to eliminate wrong answers

Option B is wrong because CSA is not designed to replace external audits; external audits provide independent, objective assurance that CSA cannot offer due to inherent self-assessment bias. Option C is wrong because CSA is a manual, participatory evaluation process, not an automated monitoring tool; automation may support data collection but is not the core purpose. Option D is wrong because while CSA results can inform compliance reports, generating compliance reports is a secondary output, not the primary purpose; the main goal is to engage process owners in control evaluation.

685
MCQeasy

Which of the following is a key characteristic of a well-maintained risk register?

A.It is maintained solely by the IT department
B.It is static and reviewed annually
C.It is updated regularly to reflect changes
D.It includes only high-impact risks
AnswerC

Risk registers are living documents; regular updates ensure risks, ratings and owners reflect current threats, controls and business changes. Without periodic refresh, the register becomes stale and misdirects risk treatment decisions, defeating its purpose as a decision-support tool.

Why this answer

A well-maintained risk register must be a living document that is updated regularly to reflect changes in the internal and external environment, such as new threats, changes in business processes, or the effectiveness of risk responses. This ensures that risk information remains current and relevant for decision-making. Regular updates enable timely risk response and support continuous risk monitoring, which is a core principle of risk management frameworks like COSO ERM and ISO 31000.

Exam trap

CRISC often tests the misconception that a risk register is a one-time or annual exercise, when in fact it must be continuously updated to remain effective.

How to eliminate wrong answers

Option A is wrong because risk management is a cross-functional responsibility, not solely the IT department's; business units, senior management, and other stakeholders must contribute to ensure all relevant risks are captured and owned. Option B is wrong because a static register reviewed only annually fails to capture emerging risks or changes in risk appetite and can become outdated quickly, undermining its usefulness. Option D is wrong because a risk register should include all identified risks, not just high-impact ones; low-impact or moderate risks may still require monitoring and can escalate over time, and excluding them can lead to blind spots.

686
Multi-Selectmedium

A security awareness program is being designed to promote a risk-aware culture. Which TWO elements are most critical for the program's success?

Select 2 answers
A.Establishing a risk committee
B.Mandatory annual testing with pass/fail
C.Detailed technical training for all staff
D.Tone from the top
E.Communicating risk in business terms
AnswersD, E

Visible executive sponsorship and consistent leadership messaging establish that risk management matters, shaping employee behaviour across the organisation. Without tone from the top, awareness activities lack credibility and authority, undermining the risk-aware culture the programme is designed to promote.

Why this answer

Option D, 'Tone from the top,' is critical because a risk-aware culture must be visibly championed by senior leadership; when executives model and reinforce risk-conscious behavior, employees perceive security as a genuine organizational priority rather than a compliance formality. Option E, 'Communicating risk in business terms,' is equally essential because awareness messages framed around business impact—such as financial loss, reputational damage, or operational disruption—resonate with staff and drive risk-informed decision-making far better than abstract technical jargon. Together, these two elements establish both the authority and the relevance needed for a sustainable security awareness program.

Option A is not among the marked correct answers because a risk committee is a governance structure that supports risk management but is not itself a critical element of awareness-program success. Option B is not marked correct because mandatory pass/fail testing can create a compliance checkbox mentality rather than fostering genuine risk awareness. Option C is not marked correct because detailed technical training for all staff is unnecessary and impractical; awareness programs should target relevant behaviors, not deep technical expertise.

Exam trap

CRISC often tests the difference between structural elements (committees, training) and cultural drivers (tone from the top, business communication), tricking candidates into selecting process-oriented options.

687
MCQmedium

A risk analyst uses a 5x5 heat map to evaluate a set of IT risks. For a particular risk, the likelihood is rated as 4 (likely) and impact as 5 (very high). What is the resulting risk rating?

A.Low
B.Medium
C.Critical
D.High
AnswerC

Multiplying likelihood 4 by impact 5 yields a score of 20 on the 5x5 matrix. That score falls within the highest band, which the heat map labels Critical, reflecting a risk demanding immediate treatment and escalation.

Why this answer

On a standard 5x5 risk heat map, the risk score is the product of likelihood and impact: 4 × 5 = 20. A score of 20 falls in the highest band of the matrix, which is typically labeled Critical (or Extreme). This reflects that a likely event with very high impact demands immediate executive attention and treatment.

Exam trap

The trap is that candidates may misremember the banding thresholds or assume a 4x5 score is only 'High' — CRISC expects you to compute the product (20) and recognize it lands in the Critical/Extreme top band of a 5x5 matrix.

How to eliminate wrong answers

Option A is wrong because Low ratings on a 5x5 matrix correspond to scores of roughly 1–4 (e.g., likelihood 1–2 with impact 1–2), far below the 20 produced here. Option B is wrong because Medium typically covers mid-range scores such as 5–9, which would require much lower likelihood or impact values. Option D is wrong because High usually covers the 10–15 band (e.g., 3×5 or 5×3), whereas 4×5 = 20 sits in the top Critical/Extreme band above High.

688
MCQmedium

In the context of ERM integration, IT risk is typically considered a subset of which broader risk category?

A.Strategic risk
B.Financial risk
C.Compliance risk
D.Operational risk
AnswerD

IT risk arises from failures in technology, people and processes supporting service delivery, which is precisely the scope of operational risk. It is therefore treated as a subset of operational risk within ERM, not of strategic, financial or compliance risk categories.

Why this answer

In Enterprise Risk Management (ERM) integration, IT risk is typically categorized as a subset of operational risk because it directly impacts the availability, integrity, and confidentiality of information systems and data, which are core operational assets. Operational risk encompasses failures in internal processes, people, and systems, and IT risk—such as system outages, data breaches, or software defects—falls squarely within this domain. This alignment is reinforced by frameworks like COSO and ISO 31000, which treat technology-related failures as operational risk events.

Exam trap

The trap here is that candidates confuse IT risk with compliance risk (Option C) because many IT failures have regulatory implications (e.g., GDPR breaches), but IT risk is fundamentally about operational continuity, not just legal adherence.

How to eliminate wrong answers

Option A is wrong because strategic risk involves high-level decisions that affect long-term business goals (e.g., market entry or M&A), not the day-to-day technology failures that IT risk addresses. Option B is wrong because financial risk focuses on market fluctuations, credit, and liquidity, whereas IT risk is about system reliability and security, not monetary instruments. Option C is wrong because compliance risk is a subset of operational risk that deals with legal and regulatory adherence, but IT risk is broader, covering non-compliance issues like system performance and availability.

689
MCQmedium

During a risk assessment, a risk practitioner identifies that a legacy application uses a deprecated encryption protocol. The application is critical for business operations and cannot be patched. Which of the following is the BEST approach to assess the risk?

A.Replace the application with a modern alternative
B.Analyze the threat landscape and existing compensating controls to determine residual risk
C.Assign a high inherent risk score without further analysis
D.Immediately escalate to senior management for an exception
AnswerB

Since the deprecated protocol cannot be patched, the practitioner must evaluate threat exposure alongside existing compensating controls to quantify residual risk. This determines whether the unpatched weakness is tolerable, directly addressing the constraint that remediation is impossible for this critical application.

Why this answer

The best approach to assess risk for a legacy application using a deprecated encryption protocol (e.g., SSL 3.0 or TLS 1.0) is to analyze the threat landscape and existing compensating controls. This allows the risk practitioner to determine the residual risk by considering factors such as whether the application is only accessible on an isolated network segment, whether network-level encryption (e.g., IPsec or a VPN tunnel) is in place, and whether the protocol is vulnerable to specific attacks like POODLE or BEAST. Simply assigning a high inherent risk score without further analysis (Option C) ignores compensating controls, while immediate escalation (Option D) or replacement (Option A) are risk treatment decisions, not risk assessment activities.

Exam trap

The trap here is that candidates confuse risk assessment with risk treatment, mistakenly selecting Option A (replacement) or Option D (escalation) as the 'best approach' when the question specifically asks for the assessment step, not the remediation step.

How to eliminate wrong answers

Option A is wrong because replacing the application is a risk treatment (mitigation) decision, not a risk assessment activity; the question asks for the best approach to assess the risk, not to resolve it. Option C is wrong because assigning a high inherent risk score without further analysis fails to consider compensating controls (e.g., network segmentation, VPN tunneling, or application-layer proxies) that could reduce the likelihood or impact, leading to an inaccurate risk assessment. Option D is wrong because immediately escalating to senior management for an exception is a governance action that should occur after the risk has been properly assessed, not as the assessment itself; it bypasses the necessary analysis of threats and controls.

690
MCQhard

A retail bank's risk practitioner is assessing the risk that a core banking system outage could halt transaction processing. The practitioner wants to identify the specific conditions or characteristics of the environment that could allow the outage to occur or worsen its effect, rather than the events themselves. Which of the following is the practitioner identifying?

A.Vulnerabilities
B.Threat events
C.Risk appetite statements
D.Key performance indicators
AnswerA

Vulnerabilities are the weaknesses or conditions in people, processes, technology, or the environment that a threat can exploit to cause harm. Characteristics such as an end-of-life operating system, an untested failover process, or a single network path are exactly these conditions. Identifying them lets the practitioner connect specific threats to the banking system and target controls that reduce the chance or severity of an outage.

Why this answer

Risk identification separates the threat, which is what can cause harm, from the vulnerability, which is the condition that allows the threat to succeed or magnifies the consequence. The practitioner's focus on characteristics of the environment that permit or worsen an outage therefore points to vulnerabilities. Documenting these conditions is what enables the organization to select controls that address the actual weaknesses in the core banking environment.

Exam trap

The trap here is conflating vulnerabilities with threat events, because both appear in risk statements; the distinguishing question is whether the item is a weakness that exists in the environment or an occurrence that acts upon it.

691
MCQmedium

A retail company monitors its key risk indicator (KRI) for credit card transaction fraud. The KRI has exceeded the established threshold for three consecutive days, but the weekly control performance report shows all fraud detection controls operating effectively. What should the risk practitioner do FIRST?

A.Immediately enhance the fraud detection controls.
B.Report the KRI breach to the board and recommend risk acceptance.
C.Adjust the KRI threshold to align with current control performance.
D.Investigate the data source of the KRI to ensure accuracy and timeliness.
AnswerD

A KRI breaching threshold while controls report effective signals a measurement problem, not a control failure. Verifying the KRI's source data for accuracy and timeliness rules out false positives before escalating or re-tuning thresholds, which is the appropriate first step.

Why this answer

The KRI breach may be caused by data inaccuracies or delays in the data feed, not by an actual increase in fraud. Investigating the data source ensures the KRI is reliable before taking any further action, aligning with the principle of validating monitoring data before making control decisions.

Exam trap

The trap here is that candidates assume a KRI breach always indicates a control failure, leading them to immediately enhance controls or adjust thresholds, rather than first verifying the data integrity of the KRI itself.

How to eliminate wrong answers

Option A is wrong because enhancing controls without verifying the KRI data could waste resources on a non-existent problem. Option B is wrong because reporting to the board and recommending risk acceptance is premature without confirming the KRI's accuracy and timeliness. Option C is wrong because adjusting the threshold to match control performance would mask a potential data quality issue and violate the integrity of the KRI as an early warning indicator.

692
MCQhard

A risk practitioner is assessing the risk of a legacy application that supports a critical business process. The application vendor no longer provides security patches. The business cannot replace the application within the next 12 months due to budget constraints. Which of the following is the MOST appropriate risk treatment?

A.Transfer the risk by purchasing cyber insurance and take no other action
B.Accept the risk without any additional controls because the business cannot afford to replace the application
C.Implement compensating controls such as network segmentation and enhanced monitoring, and document the risk with a time-bound acceptance
D.Avoid the risk by immediately shutting down the legacy application
AnswerC

Since the application cannot be replaced immediately, compensating controls can reduce the likelihood or impact of exploitation. Documenting the risk with a time-bound acceptance ensures it is formally acknowledged and reviewed. This is a pragmatic treatment that balances risk reduction with business constraints, and it aligns with risk management principles.

Why this answer

When a legacy application cannot be replaced immediately, the best treatment is to apply compensating controls to reduce risk while formally accepting the residual risk with a defined review period. This approach addresses the risk pragmatically and maintains alignment with business constraints and risk appetite.

Exam trap

The trap here is assuming that budget constraints force either full acceptance or avoidance, overlooking compensating controls and time-bound acceptance.

693
Multi-Selecthard

A risk practitioner is using the TRIKE threat modeling methodology. Which TWO of the following are characteristics of TRIKE?

Select 2 answers
A.It is a requirements-based model
B.It is designed for analyzing denial-of-service threats
C.It is a visual, agile methodology for DevSecOps
D.It uses actor and asset views
E.It focuses on attack trees and threat libraries
AnswersA, D

TRIKE is a requirements-based threat modelling methodology, satisfying the stem's need for its defining characteristic. Unlike risk-based approaches, it frames security as meeting stakeholder requirements, using a requirements model and implementation model to systematically identify threats and assign acceptable risk levels.

Why this answer

TRIKE is requirements-based and uses actor- and asset-centric views.

694
MCQmedium

You are the IT risk manager at a multinational corporation that recently migrated its customer database to a cloud-based platform. The database contains personally identifiable information (PII) subject to GDPR. During a routine vulnerability scan, you discover that the database is accessible from the internet without encryption (port 1433 open). The cloud provider's shared responsibility model indicates that securing the database configuration is the customer's responsibility. You have identified the risk as high likelihood and high impact. The business owner argues that the database is only accessible to a limited IP range and that encryption would degrade performance. Which course of action should you recommend to treat the risk?

A.Transfer the risk by purchasing cyber insurance
B.Close the port or implement a VPN, and enforce encryption
C.Accept the risk because the IP restriction reduces likelihood
D.Implement a web application firewall (WAF) to monitor traffic
AnswerB

Closing port 1433 or tunnelling via VPN removes internet exposure, and encryption protects PII in transit, directly addressing the GDPR confidentiality risk. This treats both the high-likelihood access path and the unencrypted transmission, rather than accepting the business owner's performance argument.

Why this answer

The risk is high likelihood and high impact, and the database is exposed to the internet without encryption, violating GDPR. The most effective risk treatment is to mitigate the risk by closing the port or using a VPN and enforcing encryption. This directly addresses the vulnerability and reduces both likelihood and impact.

Other options do not adequately treat the risk.

Exam trap

CRISC often tests the confusion between risk transfer and risk mitigation; insurance does not reduce the risk itself, only its financial impact.

How to eliminate wrong answers

Option A is wrong because transferring risk via insurance does not reduce the likelihood or impact of a data breach; it only provides financial compensation after an incident. Option C is wrong because accepting the risk is inappropriate for a high-risk scenario with regulatory implications; IP restriction alone is not sufficient. Option D is wrong because a WAF monitors HTTP traffic, not database traffic on port 1433, and does not encrypt data.

695
MCQmedium

A vendor risk manager is tiering vendors based on the criticality of services and data access. A vendor that processes sensitive customer data for a core business application should be classified as which tier?

A.Critical
B.Low
C.Medium
D.High
AnswerA

Processing sensitive customer data for a core business application combines high data sensitivity with direct operational dependency, the defining criteria for the critical tier. Lower tiers cover vendors with limited data access or non-core services, so this classification satisfies the stem's tiering requirement.

Why this answer

A vendor processing sensitive customer data for a core business application poses the highest potential impact on confidentiality, integrity, and availability. This aligns with the definition of a Critical tier, where failure or breach would cause severe business disruption, regulatory penalties, and reputational damage. The classification is driven by the combination of sensitive data access and the application's essential role in business operations.

Exam trap

The trap here is that candidates may confuse 'High' with 'Critical' because both imply significant risk, but CRISC defines Critical as the highest tier reserved for vendors whose failure would cause catastrophic business impact, often involving sensitive data and core processes simultaneously.

How to eliminate wrong answers

Option B is wrong because a Low tier is reserved for vendors with no access to sensitive data and minimal impact on business operations, which does not apply here. Option C is wrong because a Medium tier typically involves vendors with some data access but not to sensitive customer data, and their services are not core to business continuity. Option D is wrong because a High tier, while indicating significant risk, is often used for vendors with critical services but limited sensitive data access; the presence of both sensitive customer data and a core business application elevates the risk to Critical.

696
MCQmedium

A risk practitioner is creating a risk scenario for a ransomware attack. Which of the following is the BEST sequence to describe the scenario using the ISACA risk scenarios template?

A.Asset/resource, event, threat actor, timing, detection, response, threat type
B.Threat type, event, asset/resource, threat actor, timing, detection, response
C.Threat actor, threat type, event, asset/resource, timing, detection, response
D.Event, threat actor, asset/resource, timing, detection, response, threat type
AnswerC

Why this answer

The correct option is C, which orders the scenario as threat actor, threat type, event, asset/resource, timing, detection, and response. This matches the ISACA risk scenario template logic: it starts with who initiates the attack (threat actor), then the nature of the threat (threat type, e.g., ransomware/malware), then the event (the ransomware incident), then the affected asset/resource, followed by timing and the detection and response elements. Options A, B, and D misplace key components such as putting asset/resource or event before the threat actor or threat type, which breaks the causal sequence used in the ISACA template.

Therefore, only C provides the BEST sequence for describing a ransomware risk scenario.

697
MCQhard

A financial institution is evaluating the risk of a new mobile payment application. The risk team calculates the Annual Loss Expectancy (ALE) as $500,000 based on a single loss expectancy (SLE) of $100,000 and an annual rate of occurrence (ARO) of 5. After implementing a new encryption control at a cost of $150,000 per year, the ALE is reduced to $200,000. What is the residual risk in terms of ALE after one year of control operation?

A.$200,000
B.$500,000
C.$350,000
D.$300,000
AnswerA

The encryption control lowers the annualised loss from $500,000 to $200,000, so residual risk equals the post-control ALE of $200,000. This directly satisfies the stem's request for residual risk after one year, being the remaining ALE once the control's effect is applied, before comparing it against the $150,000 annual control cost.

Why this answer

The residual risk is the remaining Annual Loss Expectancy (ALE) after controls are applied. Since the ALE after implementing the encryption control is explicitly stated as $200,000, that is the residual risk after one year of control operation. The control cost of $150,000 is a separate cost-of-control figure and does not reduce the ALE further; it is used for cost-benefit analysis, not for calculating residual risk.

Exam trap

The trap here is that candidates mistakenly subtract the control cost from the original or reduced ALE, thinking residual risk equals ALE minus control expenditure, when in fact residual risk is simply the post-control ALE as stated.

How to eliminate wrong answers

Option B ($500,000) is wrong because it represents the original ALE before any controls were implemented, ignoring the risk reduction from the encryption control. Option C ($350,000) is wrong because it incorrectly subtracts the control cost ($150,000) from the original ALE ($500,000), confusing cost of control with risk reduction. Option D ($300,000) is wrong because it incorrectly subtracts the control cost from the reduced ALE ($200,000), which is not how residual risk is calculated; residual risk is the remaining ALE after controls, not net of control costs.

698
MCQhard

During a quarterly risk review, the CISO notes that the number of failed authentication attempts has increased by 300% over the last month. The IT team confirms no changes to authentication systems. This metric is BEST categorized as which of the following?

A.Key Performance Indicator (KPI)
B.Service Level Agreement (SLA) metric
C.Key Risk Indicator (KRI)
D.Key Control Indicator (KCI)
AnswerC

Failed authentication attempts are a measurable metric tracking exposure to credential-based attacks, so the 300% rise signals changing risk likelihood. A KRI quantifies risk exposure and trends, unlike a KPI which measures operational performance, making it the correct categorisation for this authentication anomaly.

Why this answer

A Key Risk Indicator (KRI) is a metric used to signal a change in risk exposure. A 300% increase in failed authentication attempts, with no changes to the authentication system, strongly indicates a potential ongoing brute-force attack or credential stuffing campaign, directly elevating the risk of unauthorized access. This metric is not measuring performance (KPI), contractual service levels (SLA), or the effectiveness of a specific control (KCI), but rather a change in the risk landscape.

Exam trap

The trap here is confusing a KRI with a KPI or KCI because all three are metrics, but a KRI specifically measures changes in risk exposure (like a sudden spike in failed logins), not operational performance or control effectiveness.

How to eliminate wrong answers

Option A is wrong because a Key Performance Indicator (KPI) measures the efficiency or effectiveness of a process or system (e.g., average authentication response time), not a change in risk exposure. Option B is wrong because a Service Level Agreement (SLA) metric is a contractual target for service availability or performance (e.g., 99.9% uptime), not a leading indicator of security risk. Option D is wrong because a Key Control Indicator (KCI) measures the operational health or performance of a specific control (e.g., percentage of accounts with MFA enabled), whereas a spike in failed logins is a direct risk signal, not a control performance metric.

699
MCQeasy

Which of the following is an example of a corrective control?

A.Incident response plan
B.Access control list
C.Security awareness training
D.Log monitoring
AnswerA

An incident response plan is corrective because it defines the actions taken after a detected event to contain damage, eradicate the threat and restore normal operations. It satisfies the stem's requirement for a control that remediates rather than prevents or detects, distinguishing it from preventive and detective controls.

Why this answer

A corrective control is designed to remediate or restore after an incident has occurred, reducing the impact and returning the environment to normal operation. An incident response plan is the canonical example: it defines the procedures, roles, and steps to contain, eradicate, and recover from a security incident. It acts after the fact, which is the defining characteristic of a corrective control.

Exam trap

CRISC often tests the preventive/detective/corrective taxonomy, and candidates frequently misclassify incident response as detective because it involves investigation — the key is that it acts after the event to remediate, making it corrective.

How to eliminate wrong answers

Option B is wrong because an access control list is a preventive control — it stops unauthorised access before it happens. Option C is wrong because security awareness training is a preventive control that reduces the likelihood of human error or social-engineering success. Option D is wrong because log monitoring is a detective control — it identifies events as or after they occur but does not remediate them.

700
MCQeasy

Which of the following is a key component of an IT risk management programme that documents identified risks, their likelihood, and impact?

A.Risk management policy
B.Risk register
C.Business continuity plan
D.Incident response plan
AnswerB

A risk register is the central artefact that records each identified risk alongside its assessed likelihood and impact, giving the programme a single documented view for prioritisation and tracking. It directly satisfies the stem's requirement to document risks, likelihood and impact.

Why this answer

The risk register is the central repository within an IT risk management programme that formally documents identified risks, their assessed likelihood, and potential impact. It serves as the authoritative record for tracking risk ownership, mitigation status, and residual risk levels, enabling ongoing monitoring and reporting. Without a risk register, an organization cannot systematically manage or communicate its risk posture.

Exam trap

The trap here is that candidates confuse the risk register with the risk management policy, mistakenly thinking the policy document contains the detailed risk inventory, when in fact the policy only sets the governance framework while the register holds the operational risk data.

How to eliminate wrong answers

Option A is wrong because a risk management policy defines the high-level principles, objectives, and responsibilities for risk management, but it does not contain the specific inventory of identified risks, their likelihood, or impact. Option C is wrong because a business continuity plan (BCP) focuses on maintaining or restoring operations after a disruption, not on documenting the full spectrum of identified IT risks and their attributes. Option D is wrong because an incident response plan (IRP) outlines procedures for detecting, responding to, and recovering from security incidents, but it does not serve as the ongoing record of all identified risks, their likelihood, and impact.

701
MCQmedium

An organization is implementing a new access control system. Which of the following is the MOST important consideration during the implementation phase?

A.Control ownership assignment
B.User training
C.Change management
D.Documentation update
AnswerC

Change management governs how the access control system is transitioned into production, covering impact assessment, testing, approval and rollback. This satisfies the implementation-phase constraint by controlling disruption to live access rights, preventing outages or unauthorised access during cutover.

Why this answer

During the implementation phase of a new access control system, change management is the most critical consideration because it ensures that all changes to the authentication and authorization infrastructure are controlled, tested, and approved before deployment. Without a formal change management process, misconfigurations in protocols like LDAP, RADIUS, or SAML can lead to security gaps or service outages, making it the foundational control for a successful rollout.

Exam trap

The trap here is that candidates often confuse 'most important during implementation' with 'most important overall,' leading them to select user training or documentation, but CRISC emphasizes that uncontrolled changes introduce the highest risk of failure and security incidents during the deployment phase.

How to eliminate wrong answers

Option A is wrong because control ownership assignment is a governance activity that occurs during the design or planning phase, not during implementation; it defines who is accountable for the control after deployment, but does not address the immediate risks of introducing new technology. Option B is wrong because user training, while important for adoption, is a post-implementation or operational activity that does not mitigate the technical risks of misconfiguration or integration failure during the actual deployment of the access control system. Option D is wrong because documentation update is a supporting activity that should occur throughout the lifecycle, but it is not the most critical consideration during implementation; failing to update documentation does not directly cause security incidents or system downtime like a poorly managed change can.

702
MCQeasy

A company has implemented a new control to detect unauthorized access attempts. What is the PRIMARY purpose of monitoring this control?

A.To provide evidence for regulatory audits.
B.To reduce the number of unauthorized access attempts.
C.To confirm the control is working effectively.
D.To calculate the residual risk level.
AnswerC

Monitoring generates evidence about whether the detection control actually identifies unauthorised access attempts as designed, revealing gaps, misconfigurations or failures. This confirms ongoing control effectiveness, which is the primary purpose the stem asks about, rather than merely recording incidents.

Why this answer

The primary purpose of monitoring a detective control, such as one that detects unauthorized access attempts, is to confirm that the control is operating effectively as designed. Monitoring provides ongoing assurance that the control is correctly identifying and logging unauthorized access events, which is essential for maintaining the security posture and for timely incident response.

Exam trap

The trap here is confusing the purpose of monitoring a control (verifying its effectiveness) with the purpose of the control itself (detecting or preventing incidents), leading candidates to choose a benefit like audit evidence or risk calculation instead.

How to eliminate wrong answers

Option A is wrong because while monitoring logs can provide evidence for audits, that is a secondary benefit, not the primary purpose of monitoring a detective control. Option B is wrong because a detective control does not reduce the number of unauthorized access attempts; it only detects them after they occur. Option D is wrong because calculating residual risk is a risk assessment activity that uses control effectiveness data, but the immediate purpose of monitoring is to verify control operation, not to compute risk levels.

703
MCQmedium

A risk practitioner has completed a risk assessment for a new cloud-based payroll platform. The business owner wants to proceed immediately because the platform will save $200,000 annually. The residual risk exceeds the organization's risk appetite, and no compensating controls are in place. Which action should the risk practitioner recommend FIRST?

A.Escalate the risk to the appropriate risk owner for a formal risk response decision.
B.Accept the risk because the financial benefit outweighs the potential loss.
C.Document the risk in the risk register and take no further action.
D.Implement additional controls immediately and then inform the business owner.
AnswerA

When residual risk exceeds appetite, the practitioner's role is to escalate to the accountable risk owner, who has authority to select avoid, mitigate, transfer, or accept. Escalation preserves governance and ensures the decision is made at the correct level with full visibility of the gap between assessed risk and tolerance, rather than being decided informally by the practitioner or project team.

Why this answer

Residual risk above appetite requires a formal decision by the risk owner, not by the practitioner or the business sponsor. Escalation ensures the accountable party evaluates response options and either approves mitigation, transfers the risk, avoids the initiative, or grants a documented exception. Simply accepting, controlling, or logging the risk would bypass the governance process that defines who may decide.

Exam trap

The trap here is assuming that a strong business case justifies accepting risk that already exceeds the stated risk appetite.

704
MCQeasy

A database error log shows repeated login failures followed by a successful authentication. Which control failure is MOST likely?

A.Account lockout policy is not enforced
B.No multi-factor authentication
C.Insufficient failed login monitoring
D.Weak password policy
AnswerA

Account should have been locked after a few failures.

Why this answer

The repeated login failures followed by a successful authentication indicate that the account lockout policy was not enforced. Without a lockout threshold, an attacker can perform unlimited password attempts until they guess the correct credential. This is a direct failure of the account lockout control, which is designed to prevent brute-force attacks by disabling the account after a defined number of failed attempts (e.g., 5 failures within 15 minutes per NIST SP 800-63B).

Exam trap

The trap here is that candidates confuse a detective control (monitoring) with a preventive control (lockout), or assume that MFA would have prevented the successful login, when in fact the question focuses on the repeated failures preceding success, which is the hallmark of a missing lockout policy.

How to eliminate wrong answers

Option B is wrong because multi-factor authentication (MFA) mitigates credential theft after password compromise, but it does not prevent the brute-force attack itself; the question focuses on the repeated failures leading to success, which is a lockout failure. Option C is wrong because insufficient failed login monitoring is a detective control failure, not a preventive one; the log shows the failures were recorded, so monitoring exists, but the attack succeeded due to a missing preventive control. Option D is wrong because a weak password policy (e.g., short or common passwords) makes guessing easier, but the core issue is that unlimited attempts were allowed; even a strong password can be brute-forced if no lockout is enforced.

705
MCQeasy

After a risk assessment, the risk owner states that the residual risk for a specific asset is within the organization's risk tolerance. Which of the following BEST describes the action that should be taken?

A.Transfer the risk to a third party
B.Implement additional controls to reduce risk further
C.Formally accept the risk and document the decision
D.Reassess the risk using a quantitative method
AnswerC

When residual risk falls within tolerance, the risk owner formally accepts it and records the decision. Documented acceptance provides an audit trail, assigns accountability and satisfies governance requirements, rather than mandating further treatment or transfer.

Why this answer

When the risk owner confirms that residual risk is within the organization's risk tolerance, the appropriate action is to formally accept the risk and document the decision. This is a standard risk treatment option (risk acceptance) under the ISACA Risk IT Framework, where no further controls are needed because the residual risk level is already acceptable. Documenting the acceptance ensures auditability and accountability for the decision.

Exam trap

The trap here is that candidates often confuse 'residual risk within tolerance' with a need to 'transfer' or 'mitigate further,' failing to recognize that risk acceptance is the correct treatment when the risk level is already acceptable.

How to eliminate wrong answers

Option A is wrong because transferring the risk (e.g., via cyber insurance or outsourcing) is unnecessary when the residual risk is already within tolerance; transfer would introduce additional cost and complexity without benefit. Option B is wrong because implementing additional controls would over-engineer the risk response, wasting resources on reducing risk below the accepted tolerance level, which violates the principle of cost-effective risk management. Option D is wrong because reassessing the risk using a quantitative method is not required; the risk has already been assessed and the residual risk is within tolerance—reassessment would be redundant and delay the decision.

706
Multi-Selecteasy

Which TWO are primary objectives of IT risk identification?

Select 2 answers
A.Assign risk owners
B.Determine risk appetite
C.Identify threats and vulnerabilities
D.Inventory assets
E.Implement controls
AnswersC, D

Identifying threats and vulnerabilities directly satisfies the stem's requirement to surface the sources of potential loss before assessment. Risk identification catalogues what could exploit an asset and where weaknesses exist, giving Microsoft Entra ID governance and control design its raw input. Without this, subsequent analysis and response lack defined scope.

Why this answer

Risk identification is the process of discovering and documenting the elements that could produce loss, so option C ("Identify threats and vulnerabilities") is correct because threats (e.g., malware, insider misuse, natural events) and vulnerabilities (e.g., unpatched software, weak access controls) are the fundamental inputs that define what risks exist. Option D ("Inventory assets") is also correct because you cannot identify risk without knowing what assets exist and their value; asset inventory (hardware, software, data, people, facilities) establishes the scope and context against which threats and vulnerabilities are assessed. By contrast, option A ("Assign risk owners") belongs to risk response/treatment, where accountability is delegated after risks are documented, not to the identification step itself.

Option B ("Determine risk appetite") is a governance decision made by senior management to set acceptable risk thresholds, which frames but does not perform identification. Option E ("Implement controls") is part of risk mitigation/treatment, occurring after risks have been identified, analyzed, and evaluated.

Exam trap

The trap here is that candidates confuse the outputs of risk identification (threats, vulnerabilities, assets) with later-stage activities like assigning ownership or implementing controls, leading them to select options A or E incorrectly.

707
MCQhard

An organization notices a spike in failed authentication attempts over the past week. This metric is best classified as which type of risk indicator?

A.Key Control Indicator (KCI)
B.Lagging indicator
C.Key Risk Indicator (KRI)
D.Compliance metric
AnswerC

A Key Risk Indicator tracks measurable trends in risk exposure over time, so a week-long spike in failed authentication attempts fits precisely. Unlike a Key Performance Indicator, which measures operational efficiency, a KRI signals changing likelihood or impact, satisfying the stem's requirement to classify this authentication metric as a risk indicator.

Why this answer

A spike in failed authentication attempts is a direct measure of a risk condition (e.g., brute-force attacks or credential stuffing) that can lead to unauthorized access. This metric is best classified as a Key Risk Indicator (KRI) because it tracks changes in risk exposure over time, enabling proactive risk response. Unlike a KCI, which measures control effectiveness, or a lagging indicator, which reports past incidents, this metric signals an evolving threat in near real-time.

Exam trap

In the CRISC exam, candidates often confuse KRIs and KCIs. The trap here is that failed authentication attempts directly measure risk exposure (KRI) rather than control performance (KCI), even though a control like account lockout might influence the metric.

How to eliminate wrong answers

Option A is wrong because a Key Control Indicator (KCI) measures the performance or effectiveness of a specific control (e.g., percentage of accounts with multi-factor authentication enabled), not the raw frequency of failed authentication attempts. Option B is wrong because a lagging indicator reports outcomes after they have occurred (e.g., number of successful breaches), whereas failed authentication attempts are a leading indicator of potential compromise. Option D is wrong because a compliance metric measures adherence to regulatory or policy requirements (e.g., password complexity rules), not the real-time operational risk of authentication failures.

708
MCQhard

A risk manager is evaluating the security of a new containerized application deployment in a hybrid cloud environment. The organization uses Kubernetes for orchestration and must ensure that container images are free from known vulnerabilities before deployment. Which of the following controls is MOST effective for this purpose?

A.Integrating a container image scanning tool into the CI/CD pipeline.
B.Enforcing network policies to restrict container-to-container communication.
C.Using a service mesh to encrypt all traffic between microservices.
D.Implementing runtime security monitoring using a tool like Falco.
AnswerA

Container image scanning tools integrated into the CI/CD pipeline automatically scan images for known vulnerabilities before deployment. This shift-left approach prevents vulnerable images from reaching production. It aligns with the requirement to ensure images are free from known vulnerabilities, as scanning occurs at build time and can block deployment if critical issues are found.

Why this answer

The most effective control for ensuring container images are free from known vulnerabilities before deployment is to integrate image scanning into the CI/CD pipeline. This allows automated detection and blocking of vulnerable images at build time. Runtime monitoring, network policies, and service meshes address other security aspects but do not meet the pre-deployment vulnerability assurance requirement.

Exam trap

The trap here is focusing on runtime or network controls when the requirement is specifically about pre-deployment vulnerability assurance of container images.

709
Multi-Selectmedium

A risk manager is facilitating a risk identification workshop for a new cloud migration initiative. Which TWO techniques are most effective for identifying potential IT risks at this stage?

Select 2 answers
A.Calculating the annualized loss expectancy (ALE) for each identified risk
B.Interviewing business unit managers and IT architects
C.Conducting a cost-benefit analysis of security controls
D.Reviewing post-incident reports from previous cloud migrations
E.Performing a vulnerability scan on the existing infrastructure
AnswersB, D

Stakeholder interviews elicit operational threats and business concerns.

Why this answer

Interviewing business unit managers and IT architects (Option B) is effective because it leverages domain expertise to surface operational and technical risks specific to the cloud migration, such as data residency constraints, API dependencies, or shared responsibility model gaps. This qualitative technique captures tacit knowledge that quantitative methods or automated scans cannot, making it ideal for the early identification stage.

Exam trap

The trap here is confusing risk identification (discovering what could go wrong) with risk analysis (quantifying likelihood/impact) or risk evaluation (comparing against criteria), leading candidates to select ALE calculation or cost-benefit analysis as identification techniques.

710
MCQmedium

A hospital's radiology department wants to let contracted teleradiologists read CT scans from home. The scans contain protected health information (PHI) and must remain within the hospital's HIPAA compliance boundary. The CIO asks the risk practitioner to recommend an access approach that minimizes the risk of PHI residing on unmanaged personal devices. Which of the following is the BEST recommendation?

A.Provide teleradiologists with virtual desktop infrastructure (VDI) sessions hosted in the hospital's data center, with local drive and clipboard redirection disabled.
B.Issue each teleradiologist a hospital-owned laptop with full-disk encryption and require them to sign an acceptable use policy.
C.Publish the CT images to a password-protected cloud file-sharing folder and email time-limited download links to each teleradiologist.
D.Grant teleradiologists VPN access to the PACS and let them install the vendor's diagnostic viewer on their personal computers.
AnswerA

VDI keeps PHI inside the hospital-controlled data center because only pixels are streamed to the endpoint, and disabling drive and clipboard redirection prevents scans from being copied to unmanaged home devices. This directly limits data-at-rest exposure while preserving the teleradiology workflow, making it the strongest control for the stated risk.

Why this answer

Centralizing PHI in hospital-controlled infrastructure while presenting only a remote display is the most effective way to keep protected health information off unmanaged endpoints. Virtual desktop infrastructure with drive and clipboard redirection disabled preserves clinical workflow yet blocks the common exfiltration paths of copy, print, and local save. Endpoint-centric alternatives leave PHI resident outside the compliance boundary and are far harder to govern.

Exam trap

The trap here is assuming that encryption on a laptop or VPN transport alone satisfies HIPAA, when the real exposure is PHI stored on devices the organization does not control.

711
MCQeasy

A risk practitioner is using a 5×5 heat map with likelihood and impact ratings. Which of the following is a key advantage of this qualitative risk analysis approach?

A.It provides objective, financially meaningful results.
B.It eliminates the need for expert judgment in risk assessment.
C.It is quick and easy to communicate to stakeholders.
D.It allows direct comparison of risk levels across different organizations.
AnswerC

A 5×5 heat map plots likelihood against impact on a simple grid, so stakeholders grasp relative risk positions without quantitative modelling or specialist statistical skills. This directly satisfies the stem's qualitative constraint, enabling fast, intuitive communication and prioritisation during workshops where numerical data is unavailable or unnecessary.

Why this answer

Qualitative risk analysis using a 5×5 heat map is designed to be quick to perform and easy to communicate visually to non-technical stakeholders. The color-coded matrix (e.g., red for high risk, green for low risk) allows immediate understanding of risk priorities without requiring complex calculations, making it ideal for initial risk assessments and board-level reporting.

Exam trap

The trap here is that candidates often confuse qualitative analysis with providing objective financial data (Option A), but qualitative methods like heat maps are inherently subjective and ordinal, not monetary.

How to eliminate wrong answers

Option A is wrong because qualitative analysis does not provide objective, financially meaningful results; it relies on subjective ordinal scales (e.g., high, medium, low) rather than monetary values or quantitative metrics like Annualized Loss Expectancy (ALE). Option B is wrong because qualitative analysis heavily depends on expert judgment to assign likelihood and impact ratings; it does not eliminate the need for expertise. Option D is wrong because the 5×5 heat map uses organization-specific definitions for likelihood and impact scales, which are not standardized across different organizations, preventing direct comparison of risk levels.

712
MCQeasy

In a risk-aware culture, which of the following behaviors is MOST encouraged?

A.Focusing only on compliance requirements
B.Assigning blame to individuals for security breaches
C.Hiding minor incidents to maintain performance metrics
D.Reporting security incidents without fear of blame
AnswerD

Blame-free incident reporting encourages staff to surface errors and near-misses promptly. This transparency supplies management with accurate risk data and signals that identifying risk is valued over concealing it, which is the behaviour a risk-aware culture most rewards.

Why this answer

In a risk-aware culture, the primary goal is to encourage transparency and continuous improvement in risk management. Reporting security incidents without fear of blame (Option D) is most encouraged because it enables timely detection, analysis, and remediation of threats, directly supporting the Risk Response and Reporting domain by fostering an environment where incidents are escalated promptly rather than concealed.

Exam trap

The trap here is that candidates may confuse a risk-aware culture with a compliance-driven or blame-oriented culture, mistakenly thinking that strict accountability or adherence to rules is the primary driver, rather than the psychological safety that enables open incident reporting.

How to eliminate wrong answers

Option A is wrong because focusing only on compliance requirements ignores residual risks and emerging threats that are not covered by regulatory checklists, leading to a false sense of security. Option B is wrong because assigning blame to individuals for security breaches discourages reporting and shifts focus from systemic root-cause analysis to punitive measures, which undermines a learning culture. Option C is wrong because hiding minor incidents to maintain performance metrics violates the principle of transparency and can allow small issues to escalate into major breaches, compromising the organization's risk posture.

713
MCQeasy

Which of the following is the primary purpose of a risk heat map in a risk report?

A.To track compliance with regulations
B.To detail remediation plans
C.To prioritize risks based on likelihood and impact
D.To show control performance over time
AnswerC

A risk heat map plots risks on likelihood and impact axes, enabling stakeholders to see which exposures cluster in high-severity zones and therefore warrant attention first. This visual ranking directly supports the report's purpose of prioritising risks for treatment decisions.

Why this answer

A risk heat map visually plots risks on a grid based on their likelihood (probability) and impact (consequence), enabling stakeholders to quickly identify which risks require immediate attention. This prioritization is the primary purpose because it directly supports risk response decisions by highlighting high-priority risks that exceed the organization's risk appetite.

Exam trap

The trap here is that candidates often confuse a risk heat map with a control effectiveness dashboard, mistakenly thinking its purpose is to show control performance over time, when in fact it is solely a prioritization tool based on likelihood and impact.

How to eliminate wrong answers

Option A is wrong because tracking compliance with regulations is a function of compliance dashboards or audit reports, not a risk heat map, which focuses on risk prioritization rather than regulatory adherence. Option B is wrong because detailing remediation plans is the purpose of a risk treatment plan or action tracker, while a heat map only shows the current risk posture without prescribing specific remediation steps. Option D is wrong because showing control performance over time is the role of control effectiveness metrics or trend charts, whereas a heat map provides a static snapshot of risk levels at a point in time, not historical control performance.

714
MCQeasy

A company has implemented a new cloud-based customer relationship management (CRM) system. The IT risk manager is tasked with identifying risks related to this system. Which of the following is the MOST important risk identification technique to use initially?

A.Conducting a series of interviews with key users of the CRM
B.Performing a penetration test on the CRM environment
C.Facilitating a risk workshop with IT, business, and security stakeholders
D.Automated vulnerability scanning of the CRM system
AnswerC

A facilitated workshop draws IT, business, and security stakeholders together, surfacing risks across the CRM's data, integration, and vendor dimensions that any single team would miss. For a newly implemented cloud system, this broad, structured input is the most valuable initial identification technique.

Why this answer

A facilitated risk workshop brings together IT, business, and security stakeholders to collectively identify risks across the full scope of the new CRM system, including business process, data, compliance, and technical dimensions. This cross-functional collaboration is the most effective initial technique because it surfaces risks that no single group would see alone, aligning with CRISC's emphasis on enterprise-wide risk identification. It also establishes shared ownership and a common risk language early in the system lifecycle.

Exam trap

CRISC often tests the distinction between risk identification and risk assessment techniques, causing candidates to select technical testing methods like penetration testing or scanning when the question asks for the initial identification approach.

How to eliminate wrong answers

Option A is wrong because interviews with key users capture only a narrow operational perspective and miss strategic, compliance, and infrastructure risks that business and IT stakeholders would raise. Option B is wrong because a penetration test is a technical validation activity performed after risks are identified, not an initial identification technique, and it only covers exploitable vulnerabilities. Option D is wrong because automated vulnerability scanning is a point-in-time technical control assessment that identifies known weaknesses in the environment but does not address business, process, or third-party risks associated with the CRM.

715
MCQeasy

Which type of control is primarily designed to prevent an unwanted event from occurring?

A.Corrective control
B.Detective control
C.Directive control
D.Preventive control
AnswerD

Preventive controls intervene on the causal pathway before the unwanted event materialises, stopping it from occurring at all. Detective controls identify events after the fact and corrective controls restore conditions afterwards, so only preventive satisfies the stem's prevention requirement.

Why this answer

A preventive control is designed to stop an unwanted event from occurring in the first place, such as a firewall blocking malicious traffic or a lock preventing unauthorized access. It acts before the event, unlike detective or corrective controls that act after.

Exam trap

CRISC often tests the distinction between preventive and detective controls, with candidates confusing 'detect' with 'prevent' when the question asks about stopping an event before it occurs.

How to eliminate wrong answers

Option A is wrong because corrective controls are implemented after an event to restore systems or mitigate damage, such as backups or incident response. Option B is wrong because detective controls identify and record events after they occur, such as IDS or audit logs, but do not prevent them. Option C is wrong because directive controls provide guidance or instructions to influence behavior, such as policies or procedures, but they do not technically enforce prevention.

716
MCQmedium

A manufacturing firm's risk practitioner is facilitating a workshop to identify IT risks for a new industrial control system (ICS) rollout. Operational engineers, IT staff, and a third-party integrator are present. Which of the following approaches BEST supports comprehensive IT risk identification in this setting?

A.Postpone identification until the ICS has been in production for six months so real incidents can be observed.
B.Rely solely on the third-party integrator's risk assessment because they designed the ICS architecture.
C.Ask only the IT security team to complete a vulnerability scan and treat the scan output as the risk list.
D.Facilitate a structured, cross-functional workshop using techniques such as brainstorming and scenario analysis, supplemented by asset and threat information.
AnswerD

Bringing operations, IT, and the integrator together surfaces technical, process, and business perspectives that no single group holds. Structured techniques such as scenario analysis and brainstorming, informed by asset inventories and threat intelligence, produce risks expressed in business terms and build shared ownership. ISACA guidance favors such facilitated approaches because they capture tacit knowledge and reduce the blind spots that siloed identification creates.

Why this answer

Cross-functional, structured workshops combine the operational, technical, and business knowledge needed to identify risks comprehensively, and supplementing them with asset and threat data grounds the discussion in evidence. Relying on a vendor, a single team's scan output, or waiting for live incidents all narrow the input or defer identification until treatment is far more costly.

Exam trap

The trap here is equating a technical vulnerability scan with risk identification, when scans capture weaknesses rather than business-relevant risks.

717
Multi-Selecthard

Which THREE of the following are key indicators that a risk identification process is effective? (Choose three.)

Select 3 answers
A.The process identifies all known vulnerabilities
B.The process covers all critical business processes
C.The process involves input from key stakeholders across the organization
D.The process is repeated at regular intervals or triggered by significant changes
E.The process is completed within budget
AnswersB, C, D

Coverage of all critical business processes demonstrates that risk identification is comprehensive, satisfying the completeness criterion an effective process requires. Gaps in critical processes would leave material risks undetected, so full scope confirms the process captures exposures across the organisation's most significant operations rather than only isolated areas.

Why this answer

Option B is correct because an effective risk identification process must cover all critical business processes, ensuring that risks to essential operations, revenue streams, and service delivery are surfaced rather than only technical or peripheral concerns. Option C is correct because involving key stakeholders across the organization brings diverse perspectives from business, IT, legal, compliance, and operations, which improves completeness and accuracy of identified risks. Option D is correct because risk identification is not a one-time event; repeating it at regular intervals or when significant changes occur (new systems, mergers, regulatory shifts, threat landscape changes) keeps the risk register current and relevant.

Option A is not correct because identifying 'all known vulnerabilities' is an unrealistic and overly narrow goal—risk identification focuses on risks, not just vulnerabilities, and completeness of vulnerability enumeration is not the measure of process effectiveness. Option E is not correct because completing the process within budget reflects cost efficiency, not effectiveness; a process can be cheap yet miss critical risks.

Exam trap

The trap here is that candidates confuse project management metrics (like budget or schedule) with risk management effectiveness indicators, leading them to select 'completed within budget' instead of recognizing that coverage, stakeholder input, and timeliness are the true measures of a robust risk identification process.

718
MCQmedium

The exhibit shows a log entry from a GRC system. Which of the following is the MOST significant concern regarding this risk score update?

A.The control effectiveness status was not updated alongside the risk score
B.The inherent risk score decreased without any change in the business environment
C.The comment does not provide sufficient detail on the mitigation project
D.The risk owner was not notified of the change
AnswerA

Without updating control effectiveness, residual risk cannot be accurately assessed.

Why this answer

The risk score update without a corresponding update to the control effectiveness status creates a data integrity issue in the GRC system. Since the residual risk score is calculated as inherent risk multiplied by (1 - control effectiveness), changing the score without adjusting the effectiveness metric means the system's risk calculation is now inconsistent and unreliable for monitoring and reporting purposes.

Exam trap

ISACA often tests the candidate's ability to identify data integrity issues in risk calculations rather than focusing on procedural or documentation details, so the trap here is that candidates may choose the comment detail option (C) because it seems like a common audit finding, but the core issue is the mathematical inconsistency in the risk score update.

How to eliminate wrong answers

Option B is wrong because a decrease in inherent risk score could be legitimate if the business environment changed (e.g., new compensating controls, reduced asset value), and the question does not state that no change occurred. Option C is wrong because while a detailed comment is good practice, the lack of detail is not the most significant concern; the core issue is the mismatch between the score and the control effectiveness status. Option D is wrong because notifying the risk owner is an operational step, but the immediate and most significant concern is the data inconsistency in the GRC system that undermines the accuracy of risk reporting.

719
MCQmedium

A manufacturing company uses IoT sensors on the factory floor to monitor equipment performance. The sensors transmit data to a central server via Wi-Fi. During a risk identification workshop, the operations manager reveals that some sensors are operating on outdated firmware with known vulnerabilities. The IT director proposes replacing all sensors at a high cost. The risk team notes that a breach could cause production downtime but the sensors only collect non-sensitive operational data. The company has a low tolerance for downtime. What should the risk team identify as the most critical risk?

A.Operational disruption from a potential cyber attack exploiting sensor vulnerabilities.
B.Legal liability from non-compliance with safety standards.
C.Reputational damage from a data leak.
D.Financial loss from replacing sensors.
AnswerA

Outdated firmware with known vulnerabilities on internet-connected sensors creates a credible attack path, and the company's low downtime tolerance makes production disruption the most critical impact. Although the data is non-sensitive, exploitation could halt factory operations, which aligns with the stated risk appetite.

Why this answer

The most critical risk is operational disruption from a cyber attack exploiting the known vulnerabilities in the outdated IoT sensor firmware. Since the company has a low tolerance for downtime, any breach that causes production stoppage directly impacts business continuity, outweighing the non-sensitive nature of the data collected. The sensors' Wi-Fi connectivity provides an attack surface for lateral movement or denial-of-service, making exploitation a high-probability, high-impact event.

Exam trap

The trap here is that candidates focus on data sensitivity (reputation or legal liability) instead of operational impact, failing to recognize that for a manufacturing company with low downtime tolerance, production disruption is the most critical risk even if the data is non-sensitive.

How to eliminate wrong answers

Option B is wrong because the scenario does not mention any safety standards or regulatory compliance requirements; the sensors collect non-sensitive operational data, not safety-critical parameters. Option C is wrong because the sensors only collect non-sensitive operational data, so a data leak would not cause reputational damage; the risk is operational, not data confidentiality. Option D is wrong because the financial loss from replacing sensors is a cost of mitigation, not a risk; the risk is the potential operational disruption, and the high replacement cost is a factor in risk treatment decisions, not the risk itself.

720
MCQeasy

An organization defines its risk appetite as 'no more than one major security incident per year.' During the year, a major incident occurs. The monitoring team reports this to the risk committee. What should be the NEXT step?

A.Immediately change the risk appetite to tolerate two incidents per year.
B.Review the incident to determine if risk appetite needs adjustment.
C.Report the breach to the board of directors.
D.Accept the incident and continue with current controls.
AnswerB

The incident breached the stated risk appetite, so the committee must examine what occurred and judge whether the one-incident threshold remains realistic. Reviewing the incident to decide if the appetite needs adjustment is the logical governance follow-up before further treatment decisions.

Why this answer

The next step should be to review the incident to determine if the risk appetite needs adjustment. Risk appetite is a high-level statement of how much risk an organization is willing to accept. When an incident exceeds the stated appetite, it indicates that either the appetite was unrealistic or controls are inadequate.

A review helps determine whether to adjust the appetite or improve controls. This is a proactive governance step.

Exam trap

The trap here is thinking that the immediate response is to change the risk appetite or escalate to the board. Candidates might overlook the need for a review to inform the decision.

How to eliminate wrong answers

Option A is wrong because changing the risk appetite immediately without analysis is reactive and undermines the risk management process. Option C is wrong because reporting to the board may be necessary eventually, but the immediate next step is to review the incident. Option D is wrong because simply accepting the incident without review ignores the breach of appetite and may lead to further incidents.

721
MCQeasy

A hospital's risk practitioner is identifying risks to its electronic health record platform. The practitioner documents that a single system administrator holds the only account with rights to restore the production database, and no documented procedure exists for that task. Which risk factor does this finding PRIMARILY represent?

A.A risk appetite statement
B.A control objective
C.A vulnerability
D.A threat event
AnswerC

A vulnerability is a weakness or gap that a threat can exploit or that increases the chance or severity of loss. Concentrating restore rights in one person with no documented procedure is exactly such a weakness, because illness, departure, or error by that individual could prevent recovery. Naming it a vulnerability correctly points treatment toward cross-training, role separation, and written recovery runbooks for the electronic health record platform.

Why this answer

The finding describes a condition, not an event or a desired state: one person uniquely holds restore rights and no procedure exists. That condition is a vulnerability because it can be exploited by ordinary events such as illness, turnover, or human error, and it amplifies the impact of any incident affecting the database. Recognizing it as a vulnerability directs remediation toward cross-training, documented runbooks, and separation of duties.

Exam trap

The trap here is reading the missing procedure as a documentation or compliance issue rather than as an exploitable weakness in the recovery capability.

722
Multi-Selecthard

An organization is implementing continuous monitoring for its critical systems. Which THREE of the following activities are examples of continuous monitoring? (Select three.)

Select 3 answers
A.Annual internal audit of access controls
B.Weekly vulnerability scanning of all servers
C.Real-time monitoring of firewall logs for anomalies
D.Automated correlation of security events via SIEM
E.Quarterly review of user access rights by managers
AnswersB, C, D

Weekly vulnerability scanning runs on a recurring, automated schedule across all servers, giving ongoing visibility of emerging weaknesses rather than a one-off assessment. This recurring cadence satisfies the continuous monitoring requirement, distinguishing it from periodic point-in-time audits.

Why this answer

Weekly vulnerability scanning of all servers (B) is continuous monitoring because it runs on a recurring, automated schedule that repeatedly detects new weaknesses and configuration drift across the environment. Real-time monitoring of firewall logs for anomalies (C) qualifies because it continuously ingests and inspects traffic events to detect suspicious activity as it occurs. Automated correlation of security events via SIEM (D) is continuous monitoring because the SIEM aggregates and correlates log data from multiple sources in near real time to generate alerts.

In contrast, an annual internal audit of access controls (A) and a quarterly review of user access rights (E) are periodic, point-in-time assessments rather than ongoing automated monitoring activities.

Exam trap

The trap here is that candidates often confuse periodic reviews (like quarterly or annual audits) with continuous monitoring, failing to recognize that continuous monitoring requires frequent, automated, or real-time data collection rather than infrequent manual checks.

723
MCQmedium

A financial services firm is conducting a risk assessment for a new mobile banking application. The risk practitioner needs to evaluate the likelihood of a threat exploiting a vulnerability. Which of the following factors is MOST relevant when assessing the likelihood of a threat event?

A.The regulatory penalties that could result from a data breach involving the mobile application.
B.The monetary value of the assets that could be impacted by the threat event.
C.The technical skill and motivation of threat actors targeting the mobile banking application.
D.The effectiveness of the controls currently in place to prevent or detect the threat event.
AnswerC

Likelihood of a threat event is heavily influenced by the threat actor's capability and motivation. A highly skilled and motivated attacker is more likely to attempt and succeed in exploiting a vulnerability. In the mobile banking context, financially motivated cybercriminals with advanced skills pose a higher likelihood of attack. This factor directly addresses the probability of the threat event occurring, making it the most relevant for likelihood assessment.

Why this answer

When assessing likelihood, the risk practitioner focuses on factors that influence the probability of a threat event, such as threat capability, motivation, and the attractiveness of the target. In this scenario, the technical skill and motivation of threat actors targeting the mobile banking application directly affect how likely an attack is. Asset value, control effectiveness, and regulatory penalties are more related to impact or residual risk, not the inherent likelihood of the threat event.

Exam trap

The trap here is selecting asset value or regulatory penalties as likelihood factors, when they actually measure impact.

724
MCQmedium

A mid-sized retail company operates 50 stores across three regions. Each store uses a point-of-sale (POS) system that transmits credit card transactions to a centralized payment processor. The company recently deployed a new SaaS-based inventory management application that connects to the POS system via API. The IT department has no formal process for tracking third-party connections. The risk manager suspects that unknown or unauthorized connections may exist. During a risk identification review, the risk manager discovers that the POS vendor's API documentation was shared with the inventory SaaS provider without a non-disclosure agreement (NDA). Additionally, the API keys for the POS system are stored in plain text configuration files on the inventory SaaS application server. The company's security policy requires encryption of all sensitive data in transit and at rest. Which of the following should the risk manager prioritize as the HIGHEST risk scenario to document in the risk register?

A.Exposure of POS system API keys stored in plain text on the inventory SaaS server
B.The POS system may not be PCI DSS compliant due to API sharing without NDA
C.No formal process for tracking third-party connections
D.The lack of an NDA with the inventory SaaS provider
AnswerA

Plain-text API keys on the SaaS server breach the policy requiring encryption at rest and grant direct access to POS transaction functions, making unauthorised payment activity and data exposure the most immediate, highest-impact scenario to document.

Why this answer

The plain-text storage of API keys on the inventory SaaS server represents an active, exploitable vulnerability that directly violates the company's encryption-at-rest policy. Unlike the other options, this is a confirmed technical control failure that could allow an attacker to impersonate the POS system, intercept or manipulate credit card transactions, and compromise the entire payment processing pipeline. The risk is immediate and high-impact because the keys are already exposed, not merely a procedural gap or missing legal agreement.

Exam trap

The trap here is that candidates often prioritize procedural or compliance gaps (like missing NDAs or lack of formal processes) over a concrete, exploitable technical vulnerability, failing to recognize that a realized risk with immediate impact must be documented before addressing root causes.

How to eliminate wrong answers

Option B is wrong because PCI DSS compliance is a regulatory requirement, not a risk scenario; the lack of an NDA does not automatically make the POS system non-compliant, and PCI DSS focuses on technical controls (e.g., encryption, access control) rather than contractual agreements. Option C is wrong because the absence of a formal process for tracking third-party connections is a governance weakness, not a specific, realized risk scenario with a clear threat and vulnerable asset; it is a root cause, not a risk event to document. Option D is wrong because the lack of an NDA is a legal and contractual gap, not a technical risk; while it may lead to intellectual property exposure, it does not directly expose sensitive data or systems to immediate compromise like the plain-text API keys do.

725
MCQmedium

A software development company is launching a new mobile application that will collect user location data. The risk manager identifies that the data collection could violate privacy regulations if not properly disclosed. The legal team recommends updating the privacy policy and obtaining explicit user consent. Which risk response strategy is this?

A.Risk avoidance
B.Risk transfer
C.Risk acceptance
D.Risk mitigation
AnswerD

Updating the privacy policy and obtaining explicit consent are controls that reduce the likelihood of privacy violations and regulatory fines. These actions mitigate the risk by ensuring transparency and user agreement, aligning with legal requirements. Therefore, this is a risk mitigation strategy, as the company is actively reducing the risk's potential impact.

Why this answer

By updating the privacy policy and obtaining explicit consent, the company is implementing controls to reduce the likelihood of privacy violations. This is a mitigation strategy because it addresses the risk directly through compliance measures. Avoidance would mean not collecting data, transfer would involve shifting liability, and acceptance would mean doing nothing.

Exam trap

The trap here is thinking that compliance actions are avoidance because they follow regulations, but they are actually mitigation since the risky activity continues with added controls.

726
Multi-Selecthard

A risk practitioner is calculating the residual risk for a critical asset. Which THREE factors should be considered?

Select 3 answers
A.Cost of controls
B.Control design adequacy
C.Risk appetite
D.Inherent risk level
E.Control operating effectiveness
AnswersB, D, E

Residual risk depends on how much inherent risk the controls are capable of mitigating, which is determined by design adequacy. A poorly designed control cannot reduce exposure regardless of how diligently it is operated, so design adequacy directly shapes the residual risk figure.

Why this answer

Residual risk is the risk remaining after controls are applied. To calculate it, you must know the inherent risk level (the risk before controls) and then assess how effectively controls reduce that risk. Control design adequacy and operating effectiveness determine how much the inherent risk is mitigated, directly impacting the residual risk calculation.

Exam trap

The trap here is confusing factors that influence the decision to accept residual risk (like risk appetite and cost of controls) with the direct inputs required to calculate the residual risk level itself.

727
MCQmedium

A global company uses a critical third-party vendor for data processing. The inherent risk is high, but the vendor has implemented robust controls. However, due to recent geopolitical instability, the vendor's physical location is at risk. The risk owner recommends purchasing a business continuity insurance policy. Which risk response is being applied?

A.Transfer
B.Avoid
C.Accept
D.Mitigate
AnswerA

Purchasing insurance shifts the financial consequence of a disruption to an insurer, which is the defining characteristic of risk transfer. The vendor's location risk remains, but its monetary impact moves elsewhere, satisfying the stem's description of the risk owner's chosen response.

Why this answer

Purchasing a business continuity insurance policy transfers the financial impact of the risk to a third party (the insurer), which is the definition of the transfer response. The vendor's robust controls address some risk, but the geopolitical risk remains and is being shifted via insurance. This is a classic example of risk transfer through insurance.

Exam trap

CRISC often tests the difference between transfer and mitigate, so candidates may pick mitigate because controls are mentioned, but the specific action of buying insurance is transfer.

How to eliminate wrong answers

Option B is wrong because avoidance would mean eliminating the activity or vendor relationship entirely, which is not happening here. Option C is wrong because acceptance means acknowledging the risk and taking no action (or establishing a contingency), whereas here a specific action (buying insurance) is taken. Option D is wrong because mitigation reduces the probability or impact through controls, but the action described is financial risk transfer, not control implementation.

728
MCQmedium

An organization is implementing COBIT 2019 and the board has requested assurance that risk management activities are aligned with business objectives. Which governance objective is primarily focused on ensuring risk optimization through evaluation, direction, and monitoring?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM02 — Ensure Benefits Delivery
C.EDM03 — Ensure Risk Optimization
D.EDM04 — Ensure Resource Optimization
AnswerC

EDM03 — Ensure Risk Optimization is the governance objective covering evaluation, direction and monitoring of risk management, ensuring it aligns with business objectives. It sits within the Evaluate, Direct and Monitor domain, matching the board's assurance request.

Why this answer

COBIT 2019's EDM03 — Ensure Risk Optimization is the governance objective that ensures enterprise risk management activities are aligned with business objectives by evaluating, directing, and monitoring risk appetite, tolerance, and capacity. It is the EDM domain objective specifically focused on risk optimization, making it the correct answer for the board's assurance need described.

Exam trap

CRISC often tests the distinction between EDM03 (governance-level risk optimization) and APO12 (management-level risk execution), and candidates frequently pick EDM01 because it sounds like the overarching governance objective rather than the risk-specific one.

How to eliminate wrong answers

Option A is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance focuses on establishing and maintaining the governance framework, not specifically risk optimization. Option B is wrong because EDM02 — Ensure Benefits Delivery focuses on optimizing value from investments and services, not risk. Option D is wrong because EDM04 — Ensure Resource Optimization focuses on ensuring adequate, competent, and optimized resources (people, infrastructure), not risk management alignment.

729
MCQhard

After a major system upgrade, the control testing team reports that a critical automated control failed intermittently. The control owner states it's a temporary glitch. What is the best course of action?

A.Replace the control with a manual one.
B.Perform a root cause analysis before deeming it effective.
C.Increase frequency of monitoring.
D.Accept the risk and document the finding.
AnswerB

Intermittent failure of an automated control signals a genuine defect rather than a transient glitch, so effectiveness cannot be assumed. Root cause analysis identifies the underlying fault before the control is re-tested and reliance placed upon it.

Why this answer

An intermittent failure in a critical automated control requires a root cause analysis (RCA) to determine whether the issue is a transient software bug, a configuration error, or a deeper systemic flaw. Without understanding the root cause, the control cannot be deemed effective, and simply replacing, monitoring, or accepting the risk could leave the organization exposed to material control failures. The RCA should examine system logs, error codes, and change management records to isolate the intermittent behavior.

Exam trap

The trap here is that candidates may assume a temporary glitch is benign and choose to accept the risk (D) or increase monitoring (C), but the CRISC exam emphasizes that any control failure—especially intermittent ones—must be investigated to ensure the control's design is sound and the risk is properly understood.

How to eliminate wrong answers

Option A is wrong because replacing an automated control with a manual one introduces human error, latency, and scalability issues, and does not address the underlying technical glitch—it may also violate compliance requirements for automated controls. Option C is wrong because increasing monitoring frequency only detects the failure more often but does not prevent or resolve the intermittent issue, leading to false confidence and potential missed failures during monitoring gaps. Option D is wrong because accepting the risk without understanding the root cause is premature and violates the principle of informed risk acceptance; the finding must be analyzed to determine if the risk is truly acceptable or requires remediation.

730
MCQmedium

After a significant cybersecurity incident, the board requests a report on the effectiveness of the security controls that were in place. Which reporting approach would BEST demonstrate the controls' performance?

A.List all controls and their test results
B.Show the number of vulnerabilities patched
C.Provide a summary of the incident timeline
D.Compare control test results against defined KRIs and risk appetite
AnswerD

Comparing control test results against defined KRIs and risk appetite directly evidences whether controls performed within tolerated limits, satisfying the board's demand for effectiveness rather than mere activity. KRIs quantify control performance, while risk appetite supplies the benchmark, so deviations expose residual risk in business terms the board can act on.

Why this answer

Comparing control test results against defined Key Risk Indicators (KRIs) and risk appetite directly demonstrates whether the controls are operating within acceptable risk thresholds. This approach provides the board with a clear, quantitative assessment of control effectiveness relative to the organization's risk tolerance, which is the core objective of risk and control monitoring and reporting.

Exam trap

The trap here is that candidates often confuse operational metrics (like patching counts or incident timelines) with control effectiveness reporting, which must be tied to risk appetite and KRIs to demonstrate whether controls are actually managing risk within acceptable boundaries.

How to eliminate wrong answers

Option A is wrong because merely listing all controls and their test results provides raw data without context, failing to show how the controls performed against the organization's risk appetite or KRIs. Option B is wrong because showing the number of vulnerabilities patched is a metric of remediation activity, not a measure of control effectiveness; it does not indicate whether the controls prevented or detected the incident. Option C is wrong because providing a summary of the incident timeline describes what happened during the incident but does not evaluate whether the controls were effective in mitigating the risk.

731
Multi-Selectmedium

An organization is migrating on-premises applications to a public cloud. Which THREE of the following should be considered as key risk identification activities?

Select 3 answers
A.Mapping network security group rules to existing firewall policies.
B.Performing a cost-benefit analysis of the migration.
C.Calculating the total cost of ownership.
D.Identifying data residency and compliance requirements.
E.Assessing shared responsibility model gaps.
AnswersA, D, E

Mapping network security group rules to existing firewall policies exposes where cloud-native, stateful, default-deny enforcement diverges from the on-premises rule sets, revealing misconfigurations, overly permissive ingress and coverage gaps. This directly satisfies the stem's migration constraint: controls assumed equivalent during lift-and-shift must be re-verified, not inherited.

Why this answer

Option A is correct because mapping existing firewall policies to cloud network security group (NSG) rules is a risk identification activity: it exposes gaps, overly permissive rules, or missing controls that could leave migrated workloads exposed after the move. Option D is correct because identifying data residency and compliance requirements (e.g., GDPR, HIPAA, PCI DSS, or sovereign data-location mandates) surfaces legal and regulatory risks that can block or reshape a migration. Option E is correct because assessing shared responsibility model gaps clarifies which security controls the provider handles versus which remain the customer's duty, revealing misconfigurations or unowned risks in IaaS, PaaS, and SaaS layers.

Options B and C are not risk identification activities; a cost-benefit analysis and total cost of ownership calculation are financial justification and planning exercises that address economic feasibility rather than identifying security, compliance, or operational risks.

Exam trap

The trap here is that candidates often confuse financial analysis activities (like cost-benefit analysis or TCO) with risk identification, but CRISC focuses on identifying threats, vulnerabilities, and control gaps, not cost optimization.

732
MCQeasy

An organization is conducting a vulnerability assessment of its IT assets. Which of the following sources is MOST authoritative for identifying known software vulnerabilities?

A.DISA STIGs
B.OWASP Top 10
C.NVD (National Vulnerability Database)
D.CIS Benchmarks
AnswerC

The NVD is the US government's authoritative repository, enriching CVE entries with CVSS scores, CPE applicability and remediation references. Unlike vendor advisories or forums, it provides standardised, independently curated vulnerability data, making it the most authoritative source for identifying known software vulnerabilities.

Why this answer

The National Vulnerability Database (NVD), maintained by NIST, is the U.S. government repository that enriches and standardizes CVE data with CVSS scores, CWE classifications, and CPE applicability statements. It is the most authoritative public source for identifying known software vulnerabilities because it aggregates and normalizes vulnerability data from vendors and researchers worldwide. Vulnerability scanners and risk tools routinely sync with NVD feeds to identify known CVEs.

Exam trap

CRISC often tests the distinction between vulnerability databases (NVD) and configuration benchmarks (STIGs, CIS) or awareness lists (OWASP Top 10) — candidates who pick STIGs or CIS Benchmarks confuse secure configuration guidance with known-vulnerability identification.

How to eliminate wrong answers

Option A is wrong because DISA STIGs are configuration hardening benchmarks for specific systems — they prescribe secure settings, not a catalog of known software vulnerabilities. Option B is wrong because the OWASP Top 10 is an awareness document listing the ten most critical web application security risks (e.g., injection, broken access control), not a database of specific known vulnerabilities with identifiers. Option D is wrong because CIS Benchmarks are consensus-based configuration guidelines for operating systems and applications — like STIGs, they address secure configuration rather than enumerating known software vulnerabilities.

733
MCQhard

A key control indicator (KCI) for a critical access control shows a deficiency rate of 12% for the quarter, exceeding the target of 5%. Which of the following should be the risk practitioner's PRIMARY action?

A.Investigate root causes of the high deficiency rate
B.Escalate the deficiency to the board immediately
C.Implement compensating controls to reduce risk
D.Increase the frequency of control testing
AnswerA

A KCI breach signals the control is failing, so the practitioner must first establish why the 12% deficiency rate exceeds the 5% target before selecting remediation. Root-cause investigation is the diagnostic step that determines whether the variance reflects a control design flaw, an execution gap or a measurement error.

Why this answer

The primary action is to investigate root causes because a KCI deficiency rate of 12% against a 5% target indicates a systemic control failure. Without understanding why the access control is failing (e.g., misconfigured role-based access control (RBAC) rules, stale user entitlements, or bypassed multi-factor authentication), any subsequent remediation may be ineffective. Root cause analysis ensures the risk practitioner addresses the underlying issue rather than applying a superficial fix.

Exam trap

The trap here is that candidates often choose 'implement compensating controls' or 'increase testing frequency' because they focus on immediate risk reduction, but the CRISC exam emphasizes that understanding the root cause is the foundational step before any remediation action.

How to eliminate wrong answers

Option B is wrong because escalating a 12% deficiency rate directly to the board without first performing root cause analysis bypasses the risk management process; the board requires actionable insights, not raw metrics. Option C is wrong because implementing compensating controls before understanding the root cause may introduce unnecessary complexity and cost, and could mask the real problem rather than solve it. Option D is wrong because increasing the frequency of control testing only provides more data points on the same failing control; it does not reduce the deficiency rate or address why the control is underperforming.

734
MCQmedium

A risk manager notices that a key risk indicator (KRI) has been consistently above the threshold for three months. What should be the first action?

A.Adjust the threshold to a higher value.
B.Implement additional controls immediately.
C.Review the KRI definition and data source for accuracy.
D.Escalate to senior management immediately.
AnswerC

Verifying the KRI's definition and data source comes first because a sustained threshold breach may reflect measurement error rather than genuine risk exposure. Confirming the indicator's accuracy and collection method prevents escalation based on faulty data, satisfying the need to validate the signal before committing resources to treatment.

Why this answer

Before escalating or implementing additional controls, it is important to verify the accuracy of the KRI data and definition. Option C is correct because data integrity issues are a common cause of false alarms. Option A is premature without verification.

Option B is reactive without understanding the root cause. Option D is premature; escalation should follow verification.

735
MCQmedium

The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?

A.$400,000
B.$250,000
C.$150,000
D.$350,000
AnswerB

The control lowers annualised loss expectancy by $400,000 ($500,000 − $100,000), then deducts the $150,000 annual cost, giving a net benefit of $250,000. This directly satisfies the stem's cost-effectiveness constraint by quantifying residual risk reduction against control expenditure.

Why this answer

The net benefit of a control is calculated as the reduction in Annualized Loss Expectancy (ALE) minus the annual cost of the control. The ALE reduction is $500,000 - $100,000 = $400,000. Subtracting the $150,000 annual control cost gives a net benefit of $250,000.

Exam trap

CRISC often tests whether candidates confuse the gross risk reduction (ALE before minus ALE after) with the net benefit, which requires subtracting the control's annual cost.

How to eliminate wrong answers

Option A is wrong because $400,000 represents only the gross ALE reduction before subtracting the control's annual cost. Option C is wrong because $150,000 is simply the annual cost of the control, not the net benefit. Option D is wrong because $350,000 does not correspond to any valid calculation from the given figures (it appears to be a miscalculation such as subtracting only part of the cost).

736
MCQmedium

A risk practitioner is prioritizing IT risks for treatment. Which factor should be the PRIMARY basis for prioritization?

A.Ease of implementing controls
B.Risk level (inherent or residual)
C.Cost of controls
D.Business unit manager's preference
AnswerB

Risk level drives prioritisation because it combines likelihood and impact into a single comparable value, whether inherent or residual. Treatment resources should target the highest-rated risks first, so this factor directly satisfies the stem's requirement to rank IT risks for remediation.

Why this answer

Risk prioritization must be driven by the level of risk itself — whether inherent or residual — because that reflects the likelihood and impact the organization actually faces. CRISC frames risk treatment as a response to evaluated risk, so the magnitude of risk determines what gets addressed first. Ease, cost, and personal preference are inputs to the treatment decision, not the primary basis for ranking risks.

Exam trap

CRISC often tests the distinction between risk-based prioritization and cost/feasibility-based prioritization, tempting candidates to pick 'cost of controls' because it sounds pragmatic.

How to eliminate wrong answers

Option A is wrong because ease of implementing controls is a feasibility consideration applied after risk is ranked, not a measure of risk severity. Option C is wrong because cost of controls is part of the cost-benefit analysis for treatment, not the basis for prioritizing which risks matter most. Option D is wrong because a business unit manager's preference is subjective and not a risk-based criterion; CRISC requires objective, risk-driven prioritization.

737
MCQhard

A company calculates the annualized loss expectancy (ALE) for a server outage as $75,000. The cost to implement a high-availability solution is $200,000 with a lifespan of 5 years and annual maintenance of $10,000. What is the residual risk if the solution reduces outage likelihood by 90%?

A.$50,000
B.$7,500
C.$42,500
D.$57,500
AnswerB

Reducing outage likelihood by 90% leaves 10% of the original $75,000 ALE, giving $7,500 residual risk. This satisfies the stem's requirement to quantify risk remaining after the high-availability control, correctly applying the likelihood reduction to the ALE rather than subtracting implementation costs, which belong in a separate cost-benefit calculation.

Why this answer

$7,500. The annualized loss expectancy (ALE) before mitigation is $75,000. The high-availability solution reduces outage likelihood by 90%, so the residual ALE is 10% of $75,000 = $7,500.

The cost of the solution ($200,000 capital with $10,000 annual maintenance over 5 years) is used to calculate the cost-benefit or net present value, but does not directly affect the residual risk figure, which is purely the remaining expected loss after controls are applied.

Exam trap

The trap here is that candidates often mistakenly include the cost of the control (annualized or total) in the residual risk calculation, confusing residual risk (the remaining expected loss) with the net financial benefit or cost of the solution.

How to eliminate wrong answers

Option A ($50,000) is wrong because it incorrectly subtracts the annualized cost of the solution (e.g., $40,000 annualized capital plus $10,000 maintenance = $50,000) from the original ALE, confusing residual risk with net benefit. Option C ($42,500) is wrong because it likely results from subtracting only the capital cost annualized ($40,000) from the original ALE, ignoring the 90% reduction factor. Option D ($57,500) is wrong because it appears to subtract the annual maintenance ($10,000) and a partial capital cost from the original ALE, or mistakenly applies the 90% reduction to the cost instead of the likelihood.

738
Multi-Selecteasy

Which THREE of the following are examples of risk mitigation controls? (Select THREE.)

Select 3 answers
A.Firewall
B.Outsourcing IT helpdesk
C.Encryption
D.Security awareness training
E.Cyber insurance
AnswersA, C, D

Firewalls reduce the likelihood of network attacks.

Why this answer

A firewall is a risk mitigation control because it enforces network security policies by filtering traffic based on rules, thereby reducing the likelihood of unauthorized access or attacks. It directly reduces the probability of a threat exploiting a vulnerability, which is the essence of mitigation.

Exam trap

The trap here is confusing risk mitigation (which reduces likelihood or impact) with risk transfer (which shifts the financial burden to another party), leading candidates to incorrectly select outsourcing or insurance as mitigation controls.

739
MCQhard

An organization uses the PASTA threat modeling methodology for a new e-commerce platform. Which of the following is a key characteristic of PASTA?

A.It is a requirements-based model that uses a risk management perspective
B.It uses visual diagrams to represent threats in an agile manner
C.It emphasizes business impact analysis and attack simulation
D.It focuses on agile development and integrates with DevSecOps
AnswerC

PASTA is a seven-stage, attacker-centric methodology that aligns threat modelling with business objectives, using business impact analysis and attack simulation to quantify risk against organisational goals. This distinguishes it from code-centric approaches such as STRIDE, which categorise threats rather than simulate attacks.

Why this answer

PASTA (Process for Attack Simulation and Threat Analysis) is a seven-stage, risk-centric threat modeling methodology that explicitly aligns technical threats with business objectives. Its defining characteristic is that it starts from business impact analysis and uses attack simulation to validate which threats actually matter. This business-impact-first, adversary-simulation approach distinguishes it from code-centric or diagram-centric models.

Exam trap

The trap here is confusing PASTA with STRIDE or generic agile threat modeling — candidates pick 'requirements-based' or 'visual diagrams' because those sound like threat modeling, missing PASTA's business-impact and attack-simulation identity.

How to eliminate wrong answers

Option A is wrong because 'requirements-based model using a risk management perspective' describes STRIDE-per-element or LINDDUN-style approaches more than PASTA's attack-simulation emphasis. Option B is wrong because visual diagramming in an agile manner is characteristic of tools like Microsoft Threat Modeling Tool or attack trees, not PASTA's core identity. Option D is wrong because DevSecOps integration is a general practice, not a defining characteristic of PASTA specifically.

740
Multi-Selectmedium

Which THREE of the following are components of an effective IT risk reporting structure for a large enterprise? (Select THREE)

Select 3 answers
A.Strategic risk reporting to the board on a semi-annual basis
B.Tactical risk reporting to the CISO on a quarterly basis
C.Annual risk reporting to IT operational staff
D.Daily risk reporting to the board
E.Operational risk reporting to IT management on a weekly basis
AnswersA, B, E

Board-level strategic risk reporting on a semi-annual cadence matches the governance oversight layer of a large enterprise, giving directors aggregated, forward-looking risk exposure without operational noise. This satisfies the stem's requirement for a reporting structure spanning strategic, tactical and operational tiers.

Why this answer

Option A is correct because strategic risk reporting to the board on a semi-annual basis aligns with the board's governance and oversight role, giving directors a periodic, high-level view of enterprise risk posture without overwhelming them with operational detail. Option B is correct because tactical risk reporting to the CISO on a quarterly basis matches the CISO's responsibility for managing the information security risk program and provides a cadence suitable for tracking risk treatment progress and emerging threats. Option E is correct because operational risk reporting to IT management on a weekly basis supports timely decision-making on day-to-day control failures, incidents, and remediation activities that require rapid attention.

Option C is not appropriate because annual reporting to IT operational staff is too infrequent for the operational level, where risks change quickly and require continuous awareness. Option D is not appropriate because daily risk reporting to the board is excessive and misaligned with the board's strategic oversight role, which relies on summarized, periodic reporting rather than daily operational data.

Exam trap

The trap here is that candidates confuse the frequency and audience for risk reporting, assuming that more frequent reporting to higher levels is always better, when in fact the board needs less frequent, strategic summaries and operational staff need more frequent, detailed updates.

741
MCQeasy

You are the risk manager for a healthcare provider. A risk assessment identified that patient data is transmitted over unencrypted connections between clinics and the data center. The existing controls include strong network perimeter defenses. The risk is rated as high. Management is concerned about the cost of implementing encryption. You have proposed a control that encrypts data in transit. However, the network team argues that the perimeter controls are sufficient. What is the MOST appropriate response?

A.Transfer the risk to a third party by outsourcing data transmission.
B.Accept the risk because perimeter controls are in place.
C.Reduce the risk rating to medium since perimeter controls provide compensating security.
D.Implement encryption as recommended because it addresses the vulnerability directly.
AnswerD

Encryption directly remediates the unencrypted-transmission vulnerability, which perimeter controls cannot address once traffic leaves the trusted boundary. Accepting the network team's argument would leave the high-rated risk untreated, so the control should be implemented as recommended.

Why this answer

Encrypting data in transit directly addresses the vulnerability of unencrypted connections, which is the root cause of the high risk. Perimeter controls like firewalls and IDS/IPS do not protect the confidentiality of data once it leaves the protected network boundary, as they cannot prevent interception on the wire. Implementing encryption (e.g., TLS 1.2/1.3 or IPsec) ensures end-to-end confidentiality regardless of perimeter strength.

Exam trap

The trap here is that candidates may overestimate the effectiveness of perimeter controls (e.g., firewalls) as a compensating control for data-in-transit encryption, failing to recognize that they operate at different OSI layers and cannot prevent interception of unencrypted traffic after it leaves the network boundary.

How to eliminate wrong answers

Option A is wrong because transferring risk to a third party does not eliminate the vulnerability; the third party would still need to encrypt data in transit, and outsourcing introduces additional risks like vendor management and data sovereignty. Option B is wrong because accepting the risk ignores the high-risk rating and the fact that perimeter controls do not protect data in transit from eavesdropping attacks such as packet sniffing or man-in-the-middle (MITM) exploits. Option C is wrong because reducing the risk rating based on compensating controls is a subjective adjustment that violates risk assessment principles; perimeter controls do not compensate for the lack of encryption, as they operate at different layers (network vs. transport/application).

742
MCQeasy

Which of the following is a limitation of qualitative risk analysis?

A.It cannot be used for regulatory compliance.
B.It provides subjective results that are not comparable across organizations.
C.It requires specialized software to perform.
D.It is too data-intensive and time-consuming.
AnswerB

Qualitative analysis ranks risk using descriptive scales such as high, medium and low, derived from judgement rather than measured monetary values. Those ratings reflect each assessor's context and criteria, so results cannot be reliably benchmarked against another organisation's ratings.

Why this answer

Qualitative risk analysis relies on subjective judgment, expert opinion, and descriptive scales (e.g., High/Medium/Low), which makes results inherently subjective and difficult to compare across different organizations or even different teams. This lack of standardization and reproducibility is its primary limitation.

Exam trap

CRISC often tests the misconception that qualitative analysis is unusable for compliance or requires heavy tooling, when its true limitation is subjectivity and lack of cross-organizational comparability.

How to eliminate wrong answers

Option A is wrong because qualitative analysis can absolutely support regulatory compliance—many frameworks (ISO 27005, NIST RMF) accept qualitative or semi-quantitative approaches. Option C is wrong because qualitative analysis typically requires no specialized software; spreadsheets or simple matrices suffice. Option D is wrong because qualitative analysis is generally less data-intensive and faster than quantitative analysis, not more so.

743
MCQmedium

An organization is designing an IT risk management program. Which of the following should be the PRIMARY consideration when developing a risk register?

A.Aligning risk categories with the COSO internal control framework
B.Ensuring that the register is integrated with the enterprise risk management system
C.Automating the risk register with real-time risk monitoring tools
D.Capturing risk details, including impact, likelihood, and mitigation status
AnswerD

A risk register's core purpose is documenting each identified risk with its impact, likelihood and mitigation status, enabling prioritisation and tracking. Capturing these details is the primary consideration because it drives all subsequent risk decisions.

Why this answer

The primary purpose of a risk register is to serve as the central repository that documents identified risks along with their key attributes—impact, likelihood, mitigation status, ownership, and timelines. Without capturing these core details, the register cannot support risk prioritization, decision-making, or tracking of remediation efforts. Options A, B, and C describe supporting or enhancing elements, but they are secondary to the fundamental requirement of recording essential risk information.

Therefore, D is the primary consideration.

Exam trap

CRISC often tests the distinction between foundational elements and supporting enhancements; candidates may be tempted to choose integration or automation as the 'primary' consideration, but the exam expects recognition that capturing core risk attributes is the essential first step.

How to eliminate wrong answers

Option A is wrong because aligning risk categories with COSO is a useful structuring approach, but it is not the primary consideration—the register must first capture risk details; COSO alignment is a framework choice, not the core purpose. Option B is wrong because integration with the enterprise risk management system is important for aggregation and reporting, but it is an architectural consideration that presupposes the register already contains complete risk data. Option C is wrong because automation with real-time monitoring is an advanced capability that enhances efficiency and timeliness, but it is not fundamental—a risk register can be effective without automation, as long as it captures the necessary risk information.

744
MCQeasy

Which of the following BEST describes inherent risk?

A.The risk level before any controls are applied
B.The level of risk after implementing controls
C.The amount of risk the organization is willing to accept
D.The risk level that remains after considering existing controls
AnswerA

Inherent risk captures exposure before any mitigating controls, exactly matching the stem's requirement. Unlike residual risk, which reflects exposure remaining after controls operate, inherent risk establishes the baseline against which control effectiveness is measured during risk assessment, informing whether additional treatment is justified.

Why this answer

Inherent risk is defined as the level of risk that exists in the absence of any controls or mitigations. It represents the raw, untreated risk exposure that an organization faces from a specific threat-vulnerability pair, such as the risk of data exfiltration from an unpatched web server before any firewall rules, intrusion detection systems, or encryption are applied.

Exam trap

The trap here is confusing inherent risk with residual risk, as many candidates mistakenly think that 'risk after controls' is the starting point, but CRISC defines inherent risk as the risk level before any controls are applied.

How to eliminate wrong answers

Option B is wrong because it describes residual risk, which is the risk level after controls are implemented. Option C is wrong because it defines risk appetite, the amount of risk an organization is willing to accept, not inherent risk. Option D is wrong because it also describes residual risk, which is the risk remaining after considering existing controls, not the baseline before controls.

745
MCQeasy

An e-commerce company is conducting an IT risk assessment for its order management system. The risk team has identified a risk that the system could fail during peak holiday traffic, causing revenue loss. The team needs to estimate the potential financial impact of this event to inform treatment decisions. Which activity is the team performing?

A.Risk identification
B.Risk analysis
C.Risk response
D.Risk monitoring
AnswerB

Risk analysis involves evaluating the nature and magnitude of an identified risk, including estimating potential financial impact and likelihood. The team has already identified the peak-traffic failure risk and is now determining its financial consequence to guide treatment. This estimation step is a core part of risk analysis within the IT risk assessment process.

Why this answer

After a risk is identified, risk analysis evaluates its likelihood and potential impact. The team has already named the peak-traffic failure risk and is now estimating its financial consequence, which is impact analysis within the broader risk analysis step. This estimation supports informed risk response decisions, such as investing in capacity or redundancy for the order management system.

Exam trap

The trap here is confusing risk analysis with risk response, when estimating impact is analysis and choosing how to treat the risk comes afterward.

746
MCQmedium

A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?

A.Vendor lock-in
B.Multi-tenancy isolation
C.Misconfiguration of access controls
D.Data sovereignty compliance
AnswerC

In the shared responsibility model, the provider secures the cloud infrastructure while the customer configures identity and access controls. Misconfigured permissions, such as overly broad roles or public buckets, are the customer's responsibility and are frequently overlooked, exposing sensitive customer data.

Why this answer

In the shared responsibility model, the cloud provider secures the infrastructure (security OF the cloud), while the customer is responsible for securing what they put IN the cloud—including access controls, identity management, and configuration of their own applications and data. Misconfiguration of access controls is the most commonly overlooked risk because organizations often assume the provider handles all security, leading to overly permissive IAM roles, exposed storage buckets, or weak authentication. This risk is directly under the customer's control and is a leading cause of cloud data breaches, making it the most critical to address.

Exam trap

CRISC often tests the misconception that the cloud provider handles all security, leading candidates to overlook customer-side misconfigurations like access controls and instead focus on provider-managed risks such as multi-tenancy isolation or vendor lock-in.

How to eliminate wrong answers

Option A is wrong because vendor lock-in is a strategic and financial risk related to dependency on a single provider, not a direct security control failure in the shared responsibility model; it is typically addressed through architectural design and exit strategies, not immediate access control remediation. Option B is wrong because multi-tenancy isolation is primarily the cloud provider's responsibility to ensure logical separation between tenants; while customers should verify it, it is not the most likely to be overlooked by the customer since providers invest heavily in isolation mechanisms and it is less actionable for the customer. Option D is wrong because data sovereignty compliance is a legal and regulatory risk concerning where data is stored and processed, which is important but often addressed through contractual agreements and region selection, not a day-to-day configuration risk that is frequently overlooked in the shared responsibility model.

747
MCQmedium

An organization is evaluating the risk of a ransomware attack. Using the FAIR framework, which of the following components directly multiplies to calculate Loss Event Frequency (LEF)?

A.Control Effectiveness and Residual Risk
B.Annual Loss Expectancy and Single Loss Expectancy
C.Primary Loss and Secondary Loss
D.Threat Event Frequency and Vulnerability
AnswerD

FAIR defines Loss Event Frequency as the probable frequency of threat events that become losses. It is calculated by multiplying Threat Event Frequency by Vulnerability, where Vulnerability is the probability that a threat event becomes a loss.

Why this answer

In FAIR, Loss Event Frequency (LEF) is calculated as Threat Event Frequency (TEF) multiplied by Vulnerability (V).

748
MCQhard

After implementing controls for a high-risk IT process, the residual risk is calculated as medium. The risk owner argues that the controls are not adequate because the inherent risk was critical. Which of the following should be the primary basis for determining control adequacy?

A.The number of controls implemented
B.The reduction from inherent risk to residual risk based on control effectiveness
C.The cost of controls relative to the asset value
D.The industry standards for similar processes
AnswerB

Control adequacy is judged by how far controls reduce inherent risk to residual risk, reflecting actual control effectiveness. A critical inherent rating alone does not prove controls are inadequate; the residual medium result shows measurable reduction, so the owner's argument misreads the basis for adequacy.

Why this answer

Control adequacy should be determined by the reduction from inherent risk to residual risk based on control effectiveness. The goal of controls is to mitigate risk to an acceptable level; if residual risk is medium and within the organization's risk appetite, the controls may be adequate regardless of the inherent risk being critical. The risk owner's argument that controls are inadequate solely because inherent risk was critical is flawed; what matters is the effectiveness of the controls in reducing risk.

Exam trap

CRISC often tests the misconception that controls must eliminate all risk or that inherent risk level dictates control adequacy; candidates should focus on residual risk versus risk appetite and control effectiveness.

How to eliminate wrong answers

Option A is wrong because the number of controls implemented does not indicate effectiveness; a single well-designed control can be more effective than multiple poorly designed ones. Option C is wrong because while cost is a factor in control selection, it is not the primary basis for determining adequacy; adequacy is about risk reduction, not cost. Option D is wrong because industry standards provide guidance but do not determine adequacy for a specific organization's risk appetite and context; the organization's own risk tolerance and the actual risk reduction achieved are more important.

749
Multi-Selecthard

A company's IT risk manager is evaluating Key Risk Indicators (KRIs) for the cybersecurity function. Which TWO of the following are valid examples of leading KRIs?

Select 2 answers
A.System downtime due to security incidents
B.Patch lag metric for critical systems
C.Failed authentication spike detection
D.Number of audit findings related to access controls
E.Number of successful cyber attacks in the past quarter
AnswersB, C

Patch lag measures the interval between vulnerability disclosure and remediation, quantifying exposure before exploitation occurs. It satisfies the stem's leading requirement by predicting future breach likelihood rather than reporting past incidents, and targets critical systems where unpatched flaws most directly elevate residual risk.

Why this answer

Option B (Patch lag metric for critical systems) is a valid leading KRI because it measures the time between patch release and deployment, a predictive indicator of exposure to known vulnerabilities before an incident occurs. Option C (Failed authentication spike detection) is also a leading KRI because a sudden increase in failed logins can signal credential-stuffing, brute-force, or password-spraying attempts, providing an early warning of an imminent compromise. In contrast, Option A (System downtime due to security incidents) is a lagging indicator, as it records impact after an incident has already happened.

Option D (Number of audit findings related to access controls) is a lagging compliance metric reflecting past control weaknesses rather than forward-looking risk. Option E (Number of successful cyber attacks in the past quarter) is likewise lagging, since it counts breaches that have already succeeded.

Exam trap

The trap here is confusing lagging indicators (which measure past events like downtime or audit findings) with leading indicators (which predict future risk), leading candidates to select outcome-based metrics like successful attacks instead of proactive measures like patch lag.

750
MCQhard

In the FAIR model, which component represents the probable frequency, within a given timeframe, that a threat agent will act against an asset?

A.Vulnerability
B.Loss Event Frequency (LEF)
C.Annualized Rate of Occurrence (ARO)
D.Threat Event Frequency (TEF)
AnswerD

Threat Event Frequency quantifies how often, within a defined timeframe, a threat agent is expected to act against an asset. It sits within the FAIR loss event frequency branch, feeding vulnerability and primary loss estimates.

Why this answer

In the FAIR model, Threat Event Frequency (TEF) is the component that estimates how often, within a given timeframe, a threat agent (such as a hacker or malware) will initiate an action against an asset. This directly matches the question's definition of 'probable frequency that a threat agent will act against an asset.' TEF is a primary input for calculating Loss Event Frequency (LEF) and ultimately risk.

Exam trap

The trap here is that candidates confuse Loss Event Frequency (LEF) with Threat Event Frequency (TEF), because LEF is the more commonly cited output in risk reports, but the question specifically asks for the frequency of the threat agent acting, not the resulting loss event.

How to eliminate wrong answers

Option A is wrong because Vulnerability represents the probability that an asset cannot resist a threat event, not the frequency of threat agent actions. Option B is wrong because Loss Event Frequency (LEF) is the probable frequency of loss events occurring, which is derived from Threat Event Frequency (TEF) and Vulnerability, not the raw frequency of threat agent actions. Option C is wrong because Annualized Rate of Occurrence (ARO) is a quantitative risk assessment metric used in other frameworks (like NIST or ISO) to estimate the number of times a loss is expected per year, not a specific FAIR component for threat agent action frequency.

Page 9

Page 10 of 15

Page 11