Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 751–825

1062 questions total · 15pages · All types, answers revealed

Page 10

Page 11 of 15

Page 12
751
MCQmedium

An organization's risk report shows a risk heat map with several risks in the high-likelihood, high-impact quadrant. What is the most appropriate action for the risk owner?

A.Report to the board without any analysis
B.Ignore the risks as they are inherent
C.Accept the risk without further action
D.Evaluate current controls and consider additional treatment
AnswerD

High-likelihood, high-impact risks sit above appetite, so the owner must assess whether existing controls actually reduce exposure, then decide on additional treatment such as mitigation, transfer or avoidance. Inaction leaves the residual risk unmanaged, breaching the stem's heat-map escalation.

Why this answer

Risks in the high-likelihood, high-impact quadrant exceed the organization's risk appetite and require active treatment. The risk owner should first evaluate the effectiveness of existing controls, then consider additional treatment options (mitigate, transfer, avoid, or accept with justification). Simply accepting or ignoring high-exposure risks is not defensible risk management.

Exam trap

CRISC often tests risk response discipline — candidates pick 'accept' or 'report' because they sound decisive, but high-high risks require control evaluation and treatment consideration, not passive acceptance.

How to eliminate wrong answers

Option A is wrong because reporting to the board without analysis provides no decision support and abdicates the risk owner's responsibility. Option B is wrong because 'inherent risk' does not mean unmanageable; inherent risk is the exposure before controls, and the owner must assess residual risk. Option C is wrong because accepting a high-likelihood, high-impact risk without further action is only valid if it is within appetite and formally documented, which is unlikely in this quadrant.

752
MCQeasy

Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM02 — Ensure Benefits Delivery
C.EDM04 — Ensure Resource Optimization
D.EDM03 — Ensure Risk Optimization
AnswerD

EDM03 — Ensure Risk Optimization sits in the Evaluate, Direct and Monitor domain, covering evaluation of risk appetite, direction of risk responses and monitoring of risk optimisation, exactly matching the stem's description of optimising risk through evaluation, direction and monitoring.

Why this answer

EDM03 — Ensure Risk Optimization is the governance objective that addresses risk management evaluation, direction, and monitoring.

753
MCQhard

You are a risk practitioner at a financial institution that is migrating its core banking system to a cloud provider. The migration plan includes a phased approach, with the first phase moving non-critical applications. However, during the second phase (moving customer-facing applications), the cloud provider experiences a major outage that lasts 6 hours. The outage was caused by a misconfiguration in the provider's network. The institution had conducted a risk assessment and identified cloud provider downtime as a risk, but the treatment plan only included a service level agreement (SLA) with financial penalties. The SLA does not cover the reputational damage and loss of customer trust. The risk register shows that the residual risk level was marked as 'low' before the incident. After the incident, senior management is demanding a review. Which of the following is the MOST appropriate action for the risk practitioner to take?

A.Negotiate a higher penalty in the SLA
B.Initiate a legal claim against the provider
C.Update the risk register to reflect the incident and accept the residual risk
D.Reassess the risk and recommend implementing a multi-cloud architecture for critical applications
AnswerD

The SLA-only treatment failed to address reputational and trust losses, so residual risk was misrated as low. Reassessing and recommending multi-cloud architecture for critical applications removes single-provider dependency, directly addressing the concentration risk the outage exposed and satisfying management's demand for a revised treatment.

Why this answer

The incident revealed that the existing risk treatment (SLA financial penalties) was insufficient to address the actual impact (reputational damage and loss of customer trust). The risk practitioner must reassess the risk with the new information and recommend a more robust mitigation strategy, such as multi-cloud architecture, to reduce the likelihood or impact of a single provider's outage affecting critical customer-facing applications.

Exam trap

The trap here is that candidates may think updating the risk register (Option C) is sufficient, but CRISC emphasizes that after a risk materializes with greater impact than assessed, the risk must be reassessed and the treatment plan revised, not just documented.

How to eliminate wrong answers

Option A is wrong because negotiating a higher penalty in the SLA still does not address the unmitigated reputational damage and loss of customer trust; financial penalties compensate for direct costs but not intangible impacts. Option B is wrong because initiating a legal claim is a reactive, punitive measure that does not improve future resilience and may be precluded by the SLA's limitation of liability clauses. Option C is wrong because simply updating the risk register to reflect the incident and accepting the residual risk ignores the need to reassess and improve controls after a realized risk that exceeded the accepted level.

754
MCQmedium

A risk practitioner is designing a monitoring dashboard for senior management. Which key performance indicator (KPI) would be MOST useful for tracking control effectiveness over time?

A.Number of security incidents reported.
B.Number of transactions processed per hour.
C.Value at Risk (VaR) for operational risk.
D.Percentage of controls passing automated tests.
AnswerD

Automated control tests produce a repeatable, time-series metric showing what proportion of controls actually operate as designed. Tracking this percentage over time reveals control drift or degradation, giving senior management an objective measure of control effectiveness rather than activity or incident volumes.

Why this answer

The percentage of controls passing automated tests directly measures the effectiveness of controls over time. A trend of increasing or stable high percentages indicates that controls are functioning as intended, while a decline signals degradation. This KPI is specifically designed for control monitoring, unlike metrics that measure activity or outcomes.

Exam trap

The trap here is that candidates confuse outcome-based metrics (like incident counts) with control effectiveness metrics, failing to recognize that a KPI for control effectiveness must directly measure control performance, not the consequences of control failure.

How to eliminate wrong answers

Option A is wrong because the number of security incidents reported is a lagging indicator of control failure, not a direct measure of control effectiveness; a low incident count could result from poor detection rather than strong controls. Option B is wrong because transactions processed per hour is a throughput metric for operational efficiency, not a measure of control effectiveness; it does not indicate whether controls on those transactions are working. Option C is wrong because Value at Risk (VaR) for operational risk is a statistical estimate of potential loss, not a real-time or trendable indicator of individual control performance; it aggregates risk rather than measuring control pass/fail rates.

755
Multi-Selecthard

Which THREE of the following control monitoring techniques are considered continuous monitoring?

Select 3 answers
A.Quarterly internal control self-assessments
B.Automated logging and alerting from SIEM tools
C.Real-time validation of input data in applications
D.Annual penetration testing
E.Automated reconciliation of transactions at day end
AnswersB, C, E

Continuous real-time monitoring.

Why this answer

Automated logging and alerting from SIEM tools is considered continuous monitoring because SIEM systems ingest and analyze log data in near real-time, generating alerts for suspicious activities as they occur. This provides ongoing, automated oversight of security events rather than periodic review.

Exam trap

The trap here is that candidates often confuse periodic activities (like quarterly self-assessments or annual penetration tests) with continuous monitoring, failing to recognize that continuous monitoring requires automated, ongoing, or frequent execution rather than scheduled, manual reviews.

756
MCQmedium

A retail company is identifying risks in its supply chain. Which approach is most effective for identifying previously unknown risks?

A.Scenario analysis with supply chain partners
B.Employee surveys
C.Financial audit reports
D.Review of standard risk checklists
AnswerA

Scenario analysis with supply chain partners surfaces previously unknown risks by combining each partner's operational knowledge with hypothetical disruption events, exposing interdependencies and single points of failure that internal reviews miss. This satisfies the stem's requirement to identify risks beyond those already catalogued.

Why this answer

Scenario analysis with supply chain partners is most effective for identifying previously unknown risks because it leverages collaborative brainstorming and 'what-if' thinking to uncover emergent threats that are not captured by historical data or static checklists. This approach is particularly valuable in supply chain contexts where interdependencies, third-party vulnerabilities, and novel disruptions (e.g., a new cyberattack vector targeting a logistics provider) can surface only through joint exploration of hypothetical events. It aligns with the CRISC emphasis on proactive risk identification beyond known patterns.

Exam trap

The trap here is that candidates often choose 'Review of standard risk checklists' because it seems efficient and structured, but CRISC tests the understanding that checklists are inherently limited to known risks and cannot identify novel or previously unencountered threats.

How to eliminate wrong answers

Option B is wrong because employee surveys are typically backward-looking and capture only known or perceived risks based on individual experience, making them ineffective for surfacing novel, systemic, or previously unencountered supply chain threats. Option C is wrong because financial audit reports focus on historical financial controls and compliance gaps, not on forward-looking identification of operational or strategic risks like supplier cyber incidents or geopolitical disruptions. Option D is wrong because standard risk checklists are static and based on known risk categories (e.g., vendor lock-in, natural disasters), so they inherently miss emerging or context-specific risks that have not been codified into the checklist.

757
MCQhard

A risk manager is evaluating the risk of quantum computing for the organization's encryption. The organization uses RSA-2048 for data encryption. What is the PRIMARY consideration in planning for post-quantum cryptography migration?

A.The timeline for quantum computers to break RSA-2048
B.The cost of new encryption algorithms
C.The availability of quantum-resistant hardware
D.The performance impact of post-quantum algorithms
AnswerA

Understanding when quantum computers will be capable of breaking current cryptography is essential for planning migration.

Why this answer

Quantum computers capable of breaking RSA-2048 are not expected within the next few years, so the primary consideration is the timeline for quantum advantage to prioritize migration efforts.

758
MCQmedium

A security analyst is reviewing CVE entries and NVD data to identify vulnerabilities in software assets. This activity is part of which vulnerability identification approach?

A.Configuration vulnerability assessment
B.Application vulnerability identification
C.Operational vulnerability identification
D.Asset-based vulnerability identification
AnswerD

Mapping CVE and NVD data against known software assets identifies vulnerabilities per asset, which is asset-based vulnerability identification. This satisfies the stem's scenario, where the analyst reviews CVEs against the organisation's software inventory rather than scanning hosts or reviewing threat intelligence feeds.

Why this answer

Reviewing CVE entries and NVD data to identify vulnerabilities in software assets is asset-based vulnerability identification, because it maps known vulnerabilities to specific inventoried assets. The approach starts from the asset inventory and correlates it with vulnerability databases. Configuration, application, and operational categories describe different scopes, not the CVE/NVD correlation activity.

Exam trap

The trap is conflating vulnerability identification approaches; candidates may pick 'application vulnerability identification' because CVEs often relate to applications, missing that the activity is asset-inventory-driven.

How to eliminate wrong answers

Option A is wrong because configuration vulnerability assessment focuses on misconfigurations (e.g., CIS benchmarks, hardening checks), not CVE/NVD lookups. Option B is wrong because application vulnerability identification typically involves code review, SAST/DAST, or application-specific testing rather than CVE database correlation. Option C is wrong because operational vulnerability identification relates to processes, people, and operational procedures, not software asset CVE mapping.

759
MCQmedium

A regional bank uses a centralized GRC platform to monitor key risk indicators (KRIs) for operational risk. The chief risk officer (CRO) reviews the monthly risk report and notices that the KRI 'number of system outages exceeding 4 hours' has been consistently reported as 0 for the past six months. However, the IT incident log shows three such outages in the same period. The CRO suspects the KRI is not being accurately reported. What should the risk manager do next?

A.Add additional controls to reduce the likelihood of system outages
B.Update the risk register to reflect the recent outage incidents
C.Investigate the KRI calculation and data feed to identify why outages are not being captured
D.Increase the KRI threshold to 2 outages to align with historical data
AnswerC

The discrepancy between the KRI value and the incident log points to a data or calculation fault, so tracing the KRI's calculation logic and source data feed identifies why outages are excluded before any reporting change.

Why this answer

The risk manager must first investigate the KRI calculation and data feed to determine why the IT incident log shows three outages but the KRI reports zero. Without understanding the root cause of the reporting discrepancy—whether it is a data integration error, a threshold misconfiguration, or a failure in the GRC platform's automated data collection—any subsequent action would be premature and could mask the underlying control monitoring failure.

Exam trap

The trap here is that candidates may confuse the need to remediate the reporting failure with the need to remediate the risk itself, leading them to choose an option that addresses the outages directly (like adding controls or updating the register) rather than first diagnosing the KRI data pipeline.

How to eliminate wrong answers

Option A is wrong because adding additional controls does not address the immediate issue of inaccurate KRI reporting; it assumes the problem is a lack of controls rather than a data integrity or calculation error. Option B is wrong because updating the risk register with the outage incidents is a record-keeping step that does not resolve the root cause of why the KRI failed to capture them; the risk register should reflect accurate data, but the priority is to fix the reporting mechanism. Option D is wrong because increasing the KRI threshold to 2 outages would simply hide the discrepancy by aligning the threshold with the observed data, thereby undermining the KRI's purpose as an early warning indicator and failing to correct the underlying reporting failure.

760
MCQeasy

Which of the following best describes the purpose of an IT risk universe?

A.A catalog of all IT assets and their vulnerabilities
B.A list of all past security incidents
C.A set of risk scenarios used for quantitative analysis
D.A comprehensive inventory of all potential IT risks facing the organization
AnswerD

The IT risk universe is the complete catalogue of plausible IT-related risks that could affect the organisation, providing the scope against which assessments, appetite statements and treatment decisions are framed. It is an inventory of potential risks, not a control register or a list of realised incidents.

Why this answer

An IT risk universe is the comprehensive inventory of all potential IT risks that could affect the organization — it is the master list from which specific risk assessments and scenarios are drawn. It provides the scope for risk management activities and ensures no material risk category is overlooked. It is not limited to assets, incidents, or scenarios.

Exam trap

CRISC often tests the distinction between the risk universe and its inputs; candidates may pick 'catalog of assets and vulnerabilities' because it sounds comprehensive, missing that the universe is about risks, not assets.

How to eliminate wrong answers

Option A is wrong because a catalog of IT assets and vulnerabilities is an asset inventory or vulnerability register, which feeds into but is not the same as the risk universe. Option B is wrong because a list of past security incidents is historical incident data, which may inform the risk universe but does not define it. Option C is wrong because a set of risk scenarios for quantitative analysis is a subset derived from the risk universe, not the universe itself.

761
MCQhard

A healthcare organization is migrating its electronic health records (EHR) to a SaaS provider. The provider offers a standard contract with a 99.9% uptime SLA but no right to audit. The risk manager is concerned about data integrity and availability. Which of the following is the BEST risk response to address the lack of audit rights?

A.Transfer the risk by purchasing cyber insurance that covers data breaches at the SaaS provider.
B.Implement a redundant on-premises EHR system to mitigate the risk of provider failure.
C.Negotiate a contract amendment to include audit rights or obtain independent third-party attestations such as SOC 2 Type II reports.
D.Accept the risk because the SLA guarantees uptime and the provider is reputable.
AnswerC

Negotiating audit rights or accepting independent attestations like SOC 2 Type II provides assurance over the provider's controls without direct auditing. SOC 2 reports cover security, availability, and confidentiality, which are critical for EHR data. This is a practical risk response that balances assurance with vendor relationships, reducing risk to an acceptable level while maintaining compliance with regulations like HIPAA.

Why this answer

The best response is to obtain assurance through contractual audit rights or independent attestations like SOC 2 Type II. This directly addresses the lack of visibility into the provider's controls, which is critical for data integrity and compliance. Other options either accept the risk without assurance, implement costly redundancies that do not solve the problem, or transfer financial risk without addressing the control gap.

Exam trap

The trap here is assuming that an uptime SLA or cyber insurance adequately addresses the risk of not having audit rights, when the core issue is lack of assurance over the provider's security controls.

762
MCQmedium

A risk analyst is preparing a risk register for a new customer relationship management (CRM) system hosted in a public cloud. For each identified risk, the analyst assigns a likelihood rating (1–5) and an impact rating (1–5) based on team consensus, and then multiplies the two scores to produce a risk score. Which risk assessment approach is the analyst using?

A.Semi-quantitative risk analysis
B.Quantitative risk analysis
C.Monte Carlo simulation
D.Qualitative risk analysis
AnswerA

This is correct because semi-quantitative analysis uses numeric rating scales for likelihood and impact but the values are derived from qualitative judgments rather than measured frequencies or monetary losses. Multiplying ordinal ratings produces a relative risk score that supports ranking and prioritization, which matches the analyst's use of consensus-based 1–5 ratings for the CRM system.

Why this answer

Multiplying ordinal likelihood and impact ratings generates a relative risk score, which is characteristic of semi-quantitative analysis. The ratings originate from expert consensus rather than measured frequencies or financial values, so the result is not a true quantitative loss estimate, and it is more structured than a purely qualitative high/medium/low label.

Exam trap

The trap here is assuming that any method producing numbers is automatically quantitative, when ordinal consensus ratings multiplied together remain semi-quantitative.

763
MCQmedium

During a risk identification workshop, the business process owner states that a key system has no documented dependencies. What is the BEST next step for the risk practitioner?

A.Ask the system administrator to provide a list after the workshop
B.Postpone the workshop until dependencies are mapped
C.Assume the system has no dependencies
D.Document the missing dependency information as a risk in the risk register
AnswerD

Recording the undocumented dependencies in the risk register captures the uncertainty as an identified risk, satisfying the workshop's objective of risk identification. This preserves the gap for later assessment and treatment, rather than resolving it prematurely through interviews or technical discovery, which belong to risk analysis or response activities.

Why this answer

Undocumented dependencies represent an unknown risk that must be captured in the risk register to ensure visibility and subsequent analysis. By documenting the missing dependency information as a risk, the risk practitioner formally acknowledges the gap, enabling further investigation into potential single points of failure, cascading failures, or unmonitored interconnections that could impact system availability or integrity.

Exam trap

The trap here is that candidates may think the immediate priority is to gather the missing data (Option A) or halt the workshop (Option B), rather than recognizing that the risk practitioner's first duty is to formally record the identified gap as a risk to ensure it is tracked and managed.

How to eliminate wrong answers

Option A is wrong because asking the system administrator to provide a list after the workshop delays the identification process and does not immediately address the risk of unknown dependencies; the risk practitioner should capture the gap in the risk register first to ensure it is not forgotten. Option B is wrong because postponing the workshop halts the entire risk identification effort unnecessarily; the workshop can continue with other items while the dependency gap is noted and addressed later. Option C is wrong because assuming the system has no dependencies is a dangerous assumption that ignores the possibility of hidden integration points, shared infrastructure, or upstream/downstream services that could cause significant disruption if unaccounted for.

764
MCQeasy

Which risk treatment option involves eliminating the activity that creates the risk?

A.Accept
B.Transfer
C.Avoid
D.Mitigate
AnswerC

Avoidance eliminates the activity generating the risk entirely, satisfying the stem's requirement to remove the source rather than mitigate, transfer or accept it. Unlike mitigation, which reduces likelihood or impact, avoidance erases the exposure by discontinuing the underlying process, making it the only treatment that structurally removes risk at origin.

Why this answer

(Avoid) is correct because risk avoidance involves discontinuing the activity or process that gives rise to the risk. In IT risk management, this means removing the vulnerable system, decommissioning a service, or ceasing a business function entirely to eliminate the risk exposure. For example, if an organization decides to shut down a legacy FTP server to avoid the risk of data interception, it is applying the avoid treatment.

Exam trap

The trap here is that candidates often confuse 'avoid' with 'mitigate' because both involve reducing risk, but avoid eliminates the activity entirely while mitigate keeps the activity running with controls in place.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and choosing to tolerate it without taking action to reduce or eliminate it, which does not remove the activity. Option B is wrong because risk transfer shifts the financial impact of a risk to a third party (e.g., through cyber insurance or outsourcing) but does not eliminate the underlying activity or threat. Option D is wrong because risk mitigation (or reduction) implements controls to lower the likelihood or impact of a risk, such as applying patches or encrypting data, but the activity that creates the risk continues to operate.

765
MCQhard

A risk practitioner is preparing a quarterly report for the board risk committee. Senior management wants the report to show that IT risk is being managed within appetite, but the practitioner discovers that two critical control failures were identified three weeks ago and remediation is only 40 percent complete. Which approach best satisfies the practitioner's reporting obligation?

A.Report the failures with their current remediation status, the residual risk exposure, and an expected completion date.
B.Report only that remediation is 40 percent complete, without describing the underlying failures or their impact.
C.Exclude the failures from the report because remediation is already underway and the exposure is temporary.
D.Report the control failures only after remediation is complete so the committee receives final, accurate information.
AnswerA

Transparent reporting of material control failures, current remediation progress, residual exposure, and a target date gives the committee the information it needs to judge whether risk remains within appetite. This preserves the integrity of risk reporting and allows governance bodies to direct resources or escalate. It also creates an auditable record that the issue was known and actively managed rather than concealed.

Why this answer

Risk reporting must give governance bodies a timely, accurate view of material exposures and the status of treatment. Disclosing the control failures along with remediation progress, residual risk, and an expected completion date lets the risk committee judge appetite alignment and direct action. Suppressing or diluting the information misstates the control environment and undermines oversight.

Exam trap

The trap here is equating incomplete remediation with immaturity of the issue, and therefore concluding it is too early to report.

766
MCQeasy

An organization is implementing a new access control system to prevent unauthorized access to sensitive data. Which type of control is being implemented?

A.Detective control
B.Compensating control
C.Preventive control
D.Corrective control
AnswerC

A preventive control stops unauthorised access attempts before they succeed, which matches the stated objective of preventing access to sensitive data. Unlike detective or corrective controls, it acts on the cause at the point of entry rather than identifying or remediating after the event.

Why this answer

An access control system that prevents unauthorized access to sensitive data is a preventive control because it enforces security policies before access is granted. Technologies like mandatory access control (MAC) or role-based access control (RBAC) with Access Control Lists (ACLs) block unauthorized users at the point of entry, reducing the risk of data exposure.

Exam trap

The trap here is that candidates confuse preventive controls with detective controls because both involve monitoring, but preventive controls actively block access (e.g., firewall deny rules) while detective controls only log or alert after the fact.

How to eliminate wrong answers

Option A is wrong because detective controls, such as audit logs or intrusion detection systems, identify unauthorized access after it has occurred, not prevent it. Option B is wrong because compensating controls are alternative measures used when primary controls are not feasible, such as additional monitoring for legacy systems, not the primary access control system itself. Option D is wrong because corrective controls, like data restoration from backups or revoking compromised credentials, address damage after an incident, not prevent initial unauthorized access.

767
MCQeasy

Which control type is designed to stop a risk event from occurring?

A.Detective
B.Compensating
C.Preventive
D.Corrective
AnswerC

Preventive controls act before or during an event to block it from occurring, such as segregation of duties, approvals, or firewalls. This directly satisfies the requirement to stop a risk event rather than detect or mitigate its consequences afterwards.

Why this answer

Preventive controls are designed to stop a risk event from occurring in the first place, such as firewalls, access controls, encryption, and segregation of duties. They act before the event, reducing likelihood. This is the defining characteristic that distinguishes them from detective and corrective controls.

Exam trap

CRISC often tests the timing distinction between control types — preventive (before), detective (during/after), corrective (after) — and candidates frequently confuse 'compensating' as a timing category rather than an alternative-implementation category.

How to eliminate wrong answers

Option A is wrong because detective controls identify that an event has already occurred (e.g., IDS, logs, audits) — they do not stop it. Option B is wrong because compensating controls are alternative measures used when a primary control cannot be implemented; they may be preventive, detective, or corrective, but 'compensating' describes the control's role, not its timing. Option D is wrong because corrective controls act after an event to restore systems or reduce impact (e.g., backups, incident response), not to prevent occurrence.

768
MCQhard

An insurance company's risk committee is reviewing a new mobile claims application. A penetration test found that the app stores authentication tokens in plaintext in the device's shared application storage, where any other app on a rooted or jailbroken device can read them. The development team proposes to add certificate pinning. Which of the following is the MOST appropriate risk response?

A.Accept the finding because certificate pinning will prevent token interception by malicious applications.
B.Mitigate the finding by storing tokens in the platform's secure hardware-backed keystore and removing them from shared application storage.
C.Avoid the risk by blocking the application from running on rooted or jailbroken devices.
D.Transfer the risk by purchasing a cyber liability policy that covers mobile application data breaches.
AnswerB

The confirmed weakness is plaintext token storage readable by other applications, so the direct fix is to move tokens into the operating system's hardware-backed keystore, such as iOS Keychain or Android Keystore, which isolates secrets per application. This addresses the root cause rather than a related but different threat, making it the correct risk response.

Why this answer

When a penetration test identifies plaintext storage of authentication tokens in shared application storage, the root cause is insecure secret handling on the endpoint. Moving tokens into the platform's hardware-backed keystore binds them to the application and blocks other apps from reading them. Certificate pinning, insurance, and root detection either address different threats or fail to remove the vulnerability, so remediation of the storage design is the correct response.

Exam trap

The trap here is confusing a transport-layer control with an at-rest data protection problem, which leads to accepting a finding that remains fully exploitable.

769
Multi-Selecthard

A manufacturing company is evaluating the risks of connecting its OT network to the IT network. Which THREE risks are MOST significant due to IT/OT convergence?

Select 3 answers
A.Expansion of attack paths from IT to OT systems
B.Legacy OT devices lacking modern security controls
C.Compliance with GDPR
D.Potential for physical damage and safety incidents
E.Increased data storage costs
AnswersA, B, D

Interconnecting IT and OT exposes previously isolated industrial control systems to IT-borne threats, letting attackers pivot from compromised business hosts into operational technology. This expanded attack surface is the direct consequence of convergence described in the stem.

Why this answer

Option A is correct because IT/OT convergence creates bridges between previously isolated environments, allowing attackers who compromise IT systems (e.g., via phishing or unpatched enterprise apps) to pivot laterally into OT networks and reach industrial control systems. Option B is correct because many OT devices such as PLCs, RTUs, and HMIs run legacy operating systems and proprietary protocols (e.g., Modbus, DNP3) with no authentication, encryption, or patch support, making them inherently vulnerable once exposed to IT-side threats. Option D is correct because compromised OT systems can directly manipulate physical processes—causing equipment damage, production outages, or safety incidents that endanger personnel, which is a uniquely severe consequence not present in pure IT breaches.

Option C is not a convergence-specific risk; GDPR governs personal data protection and is largely irrelevant to OT process control data. Option E is incorrect because data storage costs are a general IT operational concern, not a significant security or safety risk arising from IT/OT convergence.

Exam trap

CRISC often tests the misconception that IT/OT convergence is primarily a compliance or cost issue — the exam expects you to recognize that safety, physical damage, and expanded attack paths are the dominant risks.

770
Multi-Selecthard

A multinational corporation is developing a risk treatment plan for a newly identified risk: a critical vendor's financial instability could disrupt the supply chain. The risk manager is considering several options. Which TWO of the following are examples of risk mitigation controls that directly reduce the likelihood or impact of this risk? (Choose two.)

Select 2 answers
A.Accepting the risk and documenting it in the risk register
B.Purchasing supply chain insurance to cover losses from vendor failure
C.Requiring the vendor to provide audited financial statements quarterly
D.Transferring the risk to the vendor via a contract clause
E.Qualifying a second supplier for critical components
AnswersC, E

Monitoring the vendor's financial health through audited statements enables early detection of instability, allowing the organization to take proactive measures. This reduces the likelihood of unexpected disruption by providing time to find alternatives or adjust contracts. It is a mitigation control that addresses the risk's likelihood through ongoing monitoring.

Why this answer

Qualifying a second supplier and requiring audited financial statements are both mitigation controls. The second supplier reduces impact by providing redundancy, while financial monitoring reduces likelihood by enabling early intervention. Insurance and contract clauses transfer risk, and acceptance does nothing to reduce it, so they are not mitigation.

Exam trap

The trap here is confusing risk transfer with mitigation, assuming that any action involving contracts or insurance reduces risk, but transfer only shifts financial consequences.

771
MCQhard

A risk assessment reveals that the likelihood of a phishing attack is high, and the impact is moderate. The organization decides to implement security awareness training and email filtering. This is an example of which risk treatment?

A.Risk acceptance
B.Risk avoidance
C.Risk mitigation
D.Risk transfer
AnswerC

Security awareness training and email filtering reduce the likelihood and impact of phishing, which is the defining characteristic of risk mitigation. Unlike risk avoidance, which eliminates the activity, or transference via insurance, mitigation lowers the existing risk exposure while the activity continues.

Why this answer

Risk mitigation (also called risk reduction) involves taking actions to reduce the likelihood and/or impact of a risk. Implementing security awareness training reduces the likelihood of successful phishing, and email filtering reduces both likelihood and impact. This is the classic definition of mitigation.

Exam trap

CRISC often tests the distinction between mitigation and transfer, luring candidates toward 'transfer' when insurance or outsourcing is mentioned, but here the controls are internal and directly reduce likelihood/impact, so mitigation is correct.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action (or accepting residual risk), which contradicts the decision to implement controls. Option B is wrong because risk avoidance means eliminating the activity or asset that gives rise to the risk entirely (e.g., discontinuing the email system), not adding controls. Option D is wrong because risk transfer shifts the financial impact to a third party (e.g., cyber insurance, outsourcing), whereas here the organization is directly reducing the risk through internal controls.

772
MCQmedium

A risk analyst is building a control assessment for a payment processing environment. She needs to determine whether a new control objective is adequately addressed. She has identified the control objective, the associated risk, and the control activity. Which of the following should she do NEXT to complete the control assessment?

A.Identify additional risks that could affect the same control objective and add them to the assessment scope.
B.Perform a business impact analysis to quantify the potential loss from the risk.
C.Revisit the risk register to confirm the risk rating and update the risk appetite statement.
D.Test the operating effectiveness of the control activity and document the results.
AnswerD

Testing operating effectiveness is the next logical step after identifying the control objective, risk, and control activity. It verifies whether the control actually works as intended and provides evidence for the control assessment conclusion. Without testing, the assessment is only design-level and cannot support a conclusion about whether the control objective is met in practice.

Why this answer

After defining the control objective, risk, and control activity, the assessor must test the control's operating effectiveness to determine whether the objective is actually met. Design alone does not prove effectiveness. Testing produces evidence that supports a conclusion, which is the purpose of a control assessment in IT risk management.

Exam trap

The trap here is assuming that identifying the control activity completes the assessment, when in fact effectiveness testing is required to validate that the control works as intended.

773
Multi-Selectmedium

A risk practitioner is evaluating the effectiveness of a security awareness program. Which TWO indicators would BEST measure whether the program is positively influencing risk culture? (Select TWO)

Select 2 answers
A.Time spent on training per employee
B.Number of security policies updated
C.Increase in reported phishing attempts by employees
D.Number of employees who completed training
E.Decrease in incidents caused by human error
AnswersC, E

Rising employee reports of phishing demonstrate proactive detection behaviour rather than passive compliance, directly evidencing a culture where staff treat security as their responsibility. This satisfies the stem's requirement for an indicator that the programme positively influences risk culture, since reporting suspicious emails reflects engagement and psychological safety rather than mere training completion.

Why this answer

Option C is correct because a rise in reported phishing attempts demonstrates that employees are actively recognizing and reporting suspicious emails, which reflects heightened security awareness and a stronger risk culture rather than a failure. Option E is correct because a reduction in incidents caused by human error directly shows that employee behavior has changed in a way that lowers organizational risk, which is the ultimate goal of a security awareness program. Options A and D are activity or completion metrics that only show participation, not whether awareness or behavior actually improved.

Option B measures policy maintenance work, not the workforce's risk culture or the program's influence on employee behavior.

Exam trap

The trap here is confusing activity-based metrics (time spent, completion rates) with outcome-based metrics (behavior change, incident reduction), which is a common CRISC pitfall when evaluating program effectiveness.

774
MCQhard

A risk practitioner is using the MITRE ATT&CK framework to identify threats relevant to a financial services firm's cloud-hosted trading platform. The practitioner wants to focus on techniques adversaries use after obtaining initial access to cloud infrastructure. Which of the following BEST describes how ATT&CK should be applied in this risk identification effort?

A.Replace the organization's risk taxonomy with ATT&CK tactic categories to simplify risk register reporting.
B.Use ATT&CK technique identifiers as the sole basis for prioritizing risk treatment budgets across the firm.
C.Map relevant ATT&CK techniques to the platform's assets and controls to identify gaps in detection and mitigation coverage.
D.Use ATT&CK techniques to assign a numerical likelihood score to each identified risk in the register.
AnswerC

ATT&CK is designed to describe adversary behavior in a structured way, and mapping its techniques to assets and controls reveals where detection and mitigation coverage is missing. For a cloud trading platform, this could highlight weak coverage of credential access or data exfiltration techniques. The output feeds risk identification by showing which credible adversary behaviors are not addressed, enabling the practitioner to build scenarios grounded in real tactics rather than generic threat lists.

Why this answer

ATT&CK is most valuable in risk identification when its techniques are mapped to the organization's assets and existing controls, exposing coverage gaps in detection and mitigation. It describes adversary behavior but does not supply likelihood scores, replace a risk taxonomy, or determine budget priorities by itself. The practitioner should use the mapping to build credible scenarios and then combine that insight with likelihood, impact, and risk appetite to drive treatment decisions.

Exam trap

The trap here is treating ATT&CK as a scoring or taxonomy replacement framework, when its actual role is to describe adversary behavior that must be mapped to assets and controls.

775
MCQeasy

Which of the following is the PRIMARY purpose of a risk register in the risk identification phase?

A.Assign risk owners
B.Document identified risks and their characteristics
C.Calculate risk scores
D.Track remediation progress
AnswerB

Documenting identified risks and their characteristics is the register's core function during identification, capturing each risk's cause, category, and potential impact before any assessment occurs. This satisfies the stem's identification-phase constraint, since quantification and prioritisation belong to later risk analysis and evaluation stages, not to identification itself.

Why this answer

The primary purpose of a risk register during the risk identification phase is to systematically document each identified risk along with its key characteristics, such as the risk description, cause, impact, and potential triggers. This foundational record ensures that all risks are captured before any subsequent analysis or response planning occurs, aligning with the CRISC domain of IT Risk Identification.

Exam trap

The trap here is that candidates confuse the risk register's role in identification with later-phase activities like ownership assignment or scoring, leading them to select options that describe downstream processes rather than the immediate documentation purpose.

How to eliminate wrong answers

Option A is wrong because assigning risk owners is a governance activity that typically occurs after risks have been documented and analyzed, not during the initial identification phase. Option C is wrong because calculating risk scores is part of the risk analysis phase, which follows identification and relies on the documented characteristics in the register. Option D is wrong because tracking remediation progress belongs to the risk response and monitoring phases, long after the register has been populated with identified risks.

776
Multi-Selecteasy

A company is considering using a qualitative risk assessment approach to evaluate IT risks. Which TWO of the following are advantages of qualitative risk analysis over quantitative risk analysis?

Select 2 answers
A.Easily comparable across organizations
B.Provides financially meaningful results
C.Quick to perform
D.Easy to communicate to stakeholders
E.Objective and repeatable
AnswersC, D

Qualitative analysis relies on judgement and descriptive scales rather than numeric modelling, so assessments can be completed quickly without lengthy data gathering or statistical computation. This speed suits broad risk registers where quantitative precision is not justified by available data or budget.

Why this answer

Option C is correct because qualitative risk analysis relies on relative scales such as High/Medium/Low or ordinal rankings rather than collecting precise monetary values and statistical data, so assessments can be completed quickly with far less data gathering and calculation effort. Option D is correct because qualitative outputs expressed in simple descriptive terms (for example, a risk matrix rating of High) are readily understood by non-technical stakeholders, executives, and business owners who may lack a financial or statistical background. By contrast, option A is wrong because qualitative ratings are subjective and scale-dependent, so results are not easily comparable across different organizations that use different criteria or rating scales.

Option B is wrong because financially meaningful results, such as annualized loss expectancy (ALE) derived from single loss expectancy (SLE) and annualized rate of occurrence (ARO), are a hallmark of quantitative analysis, not qualitative. Option E is wrong because qualitative analysis is inherently subjective and depends on expert judgment, making it less objective and repeatable than quantitative methods.

Exam trap

CRISC often tests the qualitative-versus-quantitative trade-off — candidates confuse 'easy to communicate' with 'comparable across organizations' and pick the wrong advantage.

777
Multi-Selectmedium

A retail company is implementing a new point-of-sale (POS) system that accepts contactless payments. The risk practitioner identifies that the existing network segmentation between the POS environment and the corporate network is inadequate. The risk committee asks for compensating controls that will reduce the risk of lateral movement from a compromised POS terminal. Which TWO of the following controls BEST address this risk? (Choose two.)

Select 2 answers
A.Store payment card data in a centralized encrypted database on the corporate network to simplify management.
B.Implement network access control (NAC) that requires POS terminals to authenticate and comply with a hardened configuration before joining the network.
C.Enable full disk encryption on all POS terminals to protect payment card data at rest.
D.Deploy a next-generation firewall between the POS network and the corporate network with rules that deny all traffic except required payment processor endpoints.
E.Conduct quarterly vulnerability scans of the POS environment to identify missing patches.
AnswersB, D

Network access control ensures that only compliant, authenticated POS devices can connect to the network. This reduces the likelihood that a compromised or unauthorized device can establish a foothold and move laterally. By enforcing hardened configurations and device identity, NAC acts as a preventive control that complements segmentation and directly addresses the risk of lateral movement from a compromised terminal.

Why this answer

Lateral movement from a compromised POS terminal is best mitigated by preventive controls that restrict network traffic and enforce device trust. A next-generation firewall with least-privilege rules limits what the POS network can reach, and network access control ensures only compliant, authenticated devices connect. Together they compensate for weak segmentation by reducing the pathways and trust an attacker can exploit.

Encryption, scanning, and centralization do not directly block lateral movement.

Exam trap

The trap here is selecting data protection controls like encryption or detective controls like scanning when the risk is specifically about network lateral movement.

778
MCQmedium

An organization is designing a risk dashboard for senior management. Which of the following is the MOST important characteristic of the key risk indicators (KRIs) displayed?

A.They are updated in real-time.
B.They are directly linked to the risk appetite thresholds.
C.They are based on accurate historical data.
D.They are cost-effective to collect and maintain.
AnswerB

KRIs tied directly to risk appetite thresholds let senior management judge instantly whether exposure sits within tolerated limits, which is the dashboard's core purpose. This satisfies the stem's emphasis on decision-usefulness for executives, unlike generic metrics or historical trend data.

Why this answer

For a risk dashboard designed for senior management, the most important characteristic of KRIs is that they are directly linked to risk appetite thresholds. This linkage ensures that the dashboard provides actionable insights by immediately signaling when risk levels exceed or approach the organization's defined tolerance limits, enabling timely decision-making. Without this direct connection, even real-time or accurate data would fail to convey whether the organization is operating within acceptable risk boundaries.

Exam trap

The trap here is that candidates often choose 'real-time updates' (Option A) because they assume senior management needs the most current data, but the CRISC exam emphasizes that KRIs must be actionable and aligned with risk appetite thresholds to be meaningful for decision-making, not just timely.

How to eliminate wrong answers

Option A is wrong because real-time updates are not the most important characteristic; while timeliness is valuable, a KRI that updates in real-time but is not tied to risk appetite thresholds provides no context for whether the current risk level is acceptable or requires action. Option C is wrong because accurate historical data, though useful for trend analysis, does not by itself indicate whether current risk levels are within the organization's risk appetite; the dashboard's primary purpose is to monitor current status against thresholds, not to display historical accuracy. Option D is wrong because cost-effectiveness is an operational consideration, not a defining characteristic of KRI effectiveness; a KRI that is cheap to collect but not linked to risk appetite thresholds fails to serve the dashboard's core monitoring and alerting function.

779
MCQhard

During a risk identification workshop, the team identifies a potential data leakage from a legacy system. What is the FIRST step the risk owner should take?

A.Implement encryption immediately
B.Document the risk and its source
C.Assign a risk score
D.Report to senior management
AnswerB

Recording the risk and its source in the risk register creates the documented basis for subsequent analysis, evaluation and treatment. Until captured, the data leakage cannot be assessed or assigned, so documentation is the prerequisite first step before any response.

Why this answer

The first step for the risk owner is to formally document the risk and its source. This ensures that the identified data leakage from the legacy system is captured in the risk register, establishing a baseline for analysis and treatment. Without documentation, subsequent steps like risk scoring, control implementation, or escalation cannot be properly justified or tracked.

Exam trap

The trap here is that candidates often jump to immediate remediation (like encryption) or escalation, forgetting that formal documentation is the mandatory first step to ensure traceability and compliance with risk management processes.

How to eliminate wrong answers

Option A is wrong because implementing encryption immediately is a premature control decision; the risk must first be documented and analyzed to determine if encryption is appropriate, feasible, and cost-effective for the legacy system. Option C is wrong because assigning a risk score occurs after the risk has been documented and its impact and likelihood have been assessed, not as the first step. Option D is wrong because reporting to senior management is an escalation step that typically follows risk analysis and prioritization, not the initial action upon identification.

780
MCQeasy

A retail company is implementing a new point-of-sale (POS) system that will process credit card transactions. The risk manager is reviewing the network architecture and notes that the POS devices will be on the same flat network as employee workstations and guest Wi-Fi. Which of the following is the MOST effective risk mitigation to protect cardholder data?

A.Require multi-factor authentication (MFA) for all POS transactions.
B.Implement full-disk encryption on all POS devices to protect data at rest.
C.Deploy an intrusion detection system (IDS) to monitor for malicious traffic.
D.Segment the POS network from other networks and apply strict firewall rules.
AnswerD

Network segmentation isolates the POS system from less secure environments, reducing the attack surface and limiting lateral movement in case of a breach. Strict firewall rules enforce least privilege, allowing only necessary traffic. This is a fundamental PCI DSS requirement and the most effective way to protect cardholder data from threats originating from employee workstations or guest Wi-Fi.

Why this answer

Network segmentation with strict firewall rules is the most effective mitigation because it isolates the POS environment from other networks, preventing attackers from pivoting from compromised workstations or guest Wi-Fi. This aligns with PCI DSS requirements and reduces the scope of compliance. Other controls like encryption, IDS, or MFA are valuable but do not address the fundamental risk of a flat network.

Exam trap

The trap here is choosing encryption or monitoring as the primary control, while overlooking that network segmentation directly prevents unauthorized access to cardholder data.

781
Multi-Selecthard

A multinational bank must report technology risk to its board risk committee each quarter. The committee has asked the risk team to strengthen the reporting so it drives decisions rather than just describing activity. Which TWO of the following changes would BEST achieve that objective? (Choose two.)

Select 2 answers
A.Include a longer narrative describing every control test performed during the quarter.
B.Add trend analysis showing how key risk indicators have moved against their thresholds over several reporting periods.
C.Delegate the entire board report to the IT operations manager to reduce preparation time.
D.Report each key risk indicator against its defined appetite and tolerance with clear breach status.
E.Increase the number of metrics reported from twenty to sixty to provide more coverage.
AnswersB, D

Trend analysis converts point-in-time metrics into a directional picture, letting the committee see whether exposure is improving or deteriorating relative to thresholds. That context supports decisions about resource allocation and escalation because members can judge whether current controls are working. Without trends, each report is an isolated snapshot and the committee cannot tell whether prior interventions produced results.

Why this answer

Reporting that drives decisions must connect metrics to the limits leadership approved and show direction over time. Trend analysis against thresholds and breach status against appetite both give the committee a basis to act, such as approving remediation funding or accepting a documented exception. Expanded narratives, more metrics, or delegated authorship add volume or shift perspective without improving the committee's ability to decide.

Exam trap

The trap here is equating more data and longer narratives with better risk reporting for a board committee.

782
MCQmedium

A risk practitioner is analyzing the threat landscape for a hospital's connected medical devices. The devices run legacy operating systems that cannot be patched and are accessible from the clinical network. Which factor MOST increases the likelihood of exploitation?

A.The devices are manufactured by multiple vendors with varying support lifecycles.
B.The hospital's incident response plan has not been tested in the last twelve months.
C.The devices are connected to the clinical network and run unpatched legacy operating systems.
D.Clinical staff have not received security awareness training on phishing emails.
AnswerC

Unpatched legacy systems expose known vulnerabilities, and network connectivity from the clinical network provides an attack path to reach them. Together these factors directly raise the likelihood that a threat actor can exploit the devices. This combination is the most significant likelihood driver because it removes both the barrier of unknown weaknesses and the barrier of inaccessibility.

Why this answer

Likelihood of exploitation increases when a vulnerable asset is also reachable by a threat actor. The legacy, unpatched operating systems provide known exploitable weaknesses, and connectivity from the clinical network provides the path to reach them. Together they create a direct, low-friction attack opportunity.

The other factors affect response readiness, coordination, or unrelated vectors and do not create the same immediate exposure.

Exam trap

The trap here is selecting a control weakness such as untested response or awareness training when the question asks specifically about likelihood of exploitation.

783
Multi-Selecthard

A risk practitioner at a financial services firm is identifying IT risk scenarios for a new mobile banking application. The firm uses the ISACA risk scenario development approach. Which TWO of the following are essential components of a well-defined risk scenario? (Choose two.)

Select 2 answers
A.The asset or business process at risk.
B.The regulatory penalty schedule for data breaches.
C.The threat actor and their motivation.
D.The specific control framework used to mitigate the risk.
E.The annualized loss expectancy (ALE) calculation.
AnswersA, C

The asset or business process is the target of the risk event and is central to the scenario. Without specifying what is at risk, the scenario cannot be evaluated for impact or linked to business objectives. For the mobile banking app, the asset might be customer credentials or transaction data, which determines the potential business consequences.

Why this answer

A well-defined risk scenario includes the threat actor and motivation, the asset or business process at risk, the vulnerability or condition that enables the event, and the potential impact. The threat actor and asset are the two essential components listed here. Together they frame the event so that likelihood and impact can be assessed and appropriate risk responses can be selected.

Exam trap

The trap here is selecting risk treatment elements, such as control frameworks or quantitative loss calculations, as if they were part of the risk scenario definition rather than outputs of later risk analysis and response.

784
MCQhard

A financial services firm has a risk register entry for a critical trading application. The business owner proposes adding a redundant data center to reduce downtime risk. The risk practitioner notes that the redundancy will cost $2 million annually and reduce expected annual loss from $3 million to $500,000. Which factor is MOST important for the risk practitioner to evaluate before recommending approval?

A.Whether the redundant data center will eliminate all downtime risk for the trading application.
B.Whether the business owner has the authority to approve the $2 million annual expenditure.
C.Whether the redundant data center aligns with the firm's risk appetite and tolerance.
D.Whether the $2 million annual cost is lower than the $3 million expected annual loss.
AnswerC

Risk response decisions must be evaluated against the organization's risk appetite and tolerance. Even if the control is cost-effective, it should not be recommended if it pushes residual risk below tolerance in a way that misallocates resources, or if the business is unwilling to accept the operational complexity. Alignment with appetite ensures the response is appropriate for the firm's objectives and governance.

Why this answer

Before recommending a risk response, the practitioner must confirm alignment with the organization's risk appetite and tolerance. The cost-benefit analysis supports the redundancy, but appetite alignment ensures the response is consistent with governance and strategic objectives. Evaluating appetite and tolerance is the overarching criterion that determines whether a control is appropriate, not merely whether it is affordable or technically feasible.

Exam trap

The trap here is fixating on the cost-benefit arithmetic and overlooking that risk appetite and tolerance are the governing criteria for response selection.

785
MCQmedium

During a threat modeling exercise for a new web application, the team uses STRIDE. Which threat type under STRIDE corresponds to an attacker modifying data in transit?

A.Repudiation
B.Information Disclosure
C.Tampering
D.Spoofing
AnswerC

Tampering covers unauthorised modification of data, including data in transit, so it directly matches the attacker altering packets between endpoints. Spoofing concerns identity falsification, Information Disclosure concerns exposure, and Repudiation concerns denying actions, none of which describe modifying data mid-transit.

Why this answer

In STRIDE, Tampering refers to the unauthorized modification of data, whether at rest or in transit. An attacker modifying data in transit (e.g., man-in-the-middle altering a message) is the canonical example of Tampering. It violates integrity.

Exam trap

CRISC often tests the STRIDE mnemonic and candidates frequently confuse Tampering (integrity) with Spoofing (authentication) or Repudiation (non-repudiation), especially when the scenario mentions an attacker 'intercepting' traffic, which could suggest multiple threat types.

How to eliminate wrong answers

Option A is wrong because Repudiation refers to the ability of a user to deny performing an action, addressed by non-repudiation controls like digital signatures and audit logs — it does not describe data modification. Option B is wrong because Information Disclosure refers to unauthorized access to or exposure of data (confidentiality breach), not modification. Option D is wrong because Spoofing refers to impersonating a user, system, or process (authentication breach), such as forging a source IP or identity, not altering data content.

786
MCQmedium

An IT risk manager is reviewing the results of a recent risk assessment. The organization has a risk appetite that allows for low residual risk. One identified risk has an inherent risk score of 15 (on a scale of 1-25) and currently has no controls. Which of the following is the BEST recommendation for this risk?

A.Accept the risk because the score is moderate.
B.Implement controls to reduce the residual risk to an acceptable level.
C.Transfer the risk via cyber insurance.
D.Avoid the risk by discontinuing the business process.
AnswerB

Implementing controls directly lowers residual risk by mitigating the inherent risk score of 15, satisfying the organisation's low risk appetite. Since no controls currently exist, this is the only option that reduces exposure to an acceptable level, aligning treatment with the defined tolerance.

Why this answer

The inherent risk score of 15 (out of 25) is moderate, but the organization's risk appetite allows only low residual risk. Since there are currently no controls, the residual risk equals the inherent risk of 15, which exceeds the acceptable threshold. Therefore, implementing controls is the best recommendation to reduce the residual risk to a level that aligns with the risk appetite.

Exam trap

The trap here is that candidates see a moderate score (15 out of 25) and assume acceptance is appropriate, but they overlook the specific risk appetite constraint that requires low residual risk, making acceptance invalid without controls.

How to eliminate wrong answers

Option A is wrong because accepting the risk when the residual risk (currently 15) exceeds the low-risk appetite threshold violates the organization's risk tolerance policy; acceptance is only appropriate when residual risk is within appetite. Option C is wrong because transferring risk via cyber insurance does not reduce the inherent or residual risk score—it only provides financial compensation after a loss, and the organization's risk appetite requires low residual risk, not just financial coverage. Option D is wrong because avoiding the risk by discontinuing the business process is an extreme measure typically reserved for risks that cannot be mitigated to an acceptable level or where the cost of mitigation exceeds the benefit; here, controls can likely reduce the residual risk to an acceptable level without eliminating the business process.

787
MCQeasy

A risk practitioner is reviewing system logs and notices multiple failed login attempts from a foreign IP address. This observation is an example of which type of risk identification activity?

A.Control self-assessment
B.Threat intelligence gathering
C.Incident and event monitoring
D.Vulnerability scanning
AnswerC

Incident and event monitoring directly satisfies the stem's requirement: reviewing system logs to detect multiple failed foreign login attempts. This activity identifies risks through operational event data, capturing attempted intrusions as they occur. Unlike threat intelligence feeds or control self-assessments, it relies on real-time log analysis, precisely matching the observed failed-login pattern.

Why this answer

The observation of multiple failed login attempts from a foreign IP address is a direct result of reviewing system logs, which is a core component of incident and event monitoring. This activity involves the continuous surveillance of security events to detect anomalies, such as brute-force attacks, and is a reactive risk identification technique that identifies risks based on actual occurrences.

Exam trap

The trap here is that candidates confuse 'threat intelligence gathering' (which uses external feeds) with the internal log analysis of actual events, but the question specifically describes reviewing system logs, which is a direct example of incident and event monitoring.

How to eliminate wrong answers

Option A is wrong because control self-assessment is a proactive, internal review process where control owners evaluate the design and effectiveness of controls, not a log review of real-time events. Option B is wrong because threat intelligence gathering involves collecting and analyzing external data about emerging threats (e.g., from ISACs or threat feeds), not reviewing internal system logs for specific failed login attempts. Option D is wrong because vulnerability scanning is a scheduled, automated process that identifies known weaknesses in systems (e.g., missing patches or misconfigurations), not the detection of ongoing attack patterns like repeated failed logins.

788
MCQmedium

According to the NIST Cybersecurity Framework, which function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Identify
B.Protect
C.Respond
D.Detect
AnswerB

The Protect function covers developing and implementing safeguards — access control, awareness training, data security and protective technology — to ensure delivery of critical infrastructure services. This matches the stem's wording precisely, distinguishing it from Identify, Detect, Respond and Recover.

Why this answer

The NIST Cybersecurity Framework's Protect function (PR) covers the safeguards needed to ensure delivery of critical infrastructure services — including access control, awareness training, data security, information protection processes, maintenance, and protective technology. It is the function that directly addresses preventive controls.

Exam trap

CRISC often tests the confusion between Protect and Detect — candidates may pick Detect thinking it covers safeguards, but Detect is about discovering events, while Protect is about implementing preventive safeguards.

How to eliminate wrong answers

Option A is wrong because Identify (ID) focuses on understanding the business context, assets, and risks — it is about discovery and governance, not implementing safeguards. Option C is wrong because Respond (RS) covers actions taken during or after a detected incident (response planning, communications, analysis, mitigation). Option D is wrong because Detect (DE) focuses on discovering cybersecurity events through monitoring and anomaly detection, not on implementing safeguards.

789
MCQeasy

In the context of IT governance, which COBIT 2019 process is specifically focused on ensuring risk optimization?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM04 — Ensure Resource Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM03 — Ensure Risk Optimization
AnswerD

EDM03 — Ensure Risk Optimization sits in the Evaluate, Direct and Monitor domain, tasking the governing body with ensuring IT-related risk appetite, tolerance and capacity are understood and optimised. It is the COBIT 2019 process explicitly scoped to risk optimisation.

Why this answer

COBIT 2019's EDM03 — Ensure Risk Optimization is the governance process specifically focused on ensuring that IT-related risk is identified, assessed, and managed within the enterprise's risk appetite. It is part of the Evaluate, Direct, and Monitor (EDM) domain, which is the governance domain.

Exam trap

CRISC often tests the distinction between EDM03 (Ensure Risk Optimization) and APO12 (Manage Risk) — candidates may confuse governance-level risk oversight with management-level risk execution.

How to eliminate wrong answers

Option A is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance focuses on establishing and maintaining the governance framework, not on risk optimization. Option B is wrong because EDM04 — Ensure Resource Optimization focuses on optimizing IT resources (people, infrastructure, applications), not risk. Option C is wrong because EDM02 — Ensure Benefits Delivery focuses on optimizing the value contribution of IT investments, not risk.

790
MCQeasy

A regional insurance company has just completed an IT risk assessment and documented the identified risks in a central repository. The risk practitioner now wants to ensure that each risk has an assigned owner, a defined response, and a status that can be tracked over time. Which of the following should the practitioner use to meet these needs?

A.A control self-assessment (CSA) questionnaire
B.A risk register
C.An IT service continuity plan
D.A business impact analysis (BIA)
AnswerB

A risk register is the central repository that records each identified risk along with attributes such as owner, response, status, and target dates. It provides the structure needed to track risks over time and supports reporting to management and the board. For the insurance company's newly assessed IT risks, the register is the natural place to assign accountability and monitor treatment progress.

Why this answer

The central repository for documented risks, with fields for ownership, response, and status, is the risk register. It is the mechanism that turns assessment output into managed, trackable items and provides the basis for reporting on treatment progress. The other artifacts listed serve different purposes: impact analysis, control assessment, and continuity planning all feed or complement risk management but do not replace the register.

Exam trap

The trap here is selecting a familiar governance artifact such as a business impact analysis or continuity plan simply because it is related to risk, when the requirement is specifically a tracking repository.

791
MCQmedium

Which of the following is an example of a detective control?

A.Backup restoration after data loss
B.Firewall rules blocking unauthorized traffic
C.Requiring two-factor authentication
D.Intrusion detection system (IDS) alerts
AnswerD

An IDS detects and alerts on intrusions after or during occurrence, which is the defining characteristic of a detective control. It satisfies the stem by identifying events rather than preventing them, unlike firewalls or access controls.

Why this answer

An intrusion detection system (IDS) monitors network traffic for suspicious activity and generates alerts when it detects potential threats. This is a detective control because it identifies and reports security incidents after they occur, rather than preventing them. IDS alerts provide visibility into ongoing or past attacks, enabling incident response.

Exam trap

The trap here is confusing preventive controls (like firewalls and authentication) with detective controls (like IDS), as candidates often misclassify controls based on their general security function rather than their specific timing relative to the incident.

How to eliminate wrong answers

Option A is wrong because backup restoration after data loss is a corrective control, not a detective control; it recovers data after an incident has occurred. Option B is wrong because firewall rules blocking unauthorized traffic is a preventive control, as it stops threats before they reach the network. Option C is wrong because requiring two-factor authentication is a preventive control that verifies identity before granting access, not a mechanism to detect incidents after they happen.

792
MCQhard

A financial services firm is adopting a DevSecOps model. The risk practitioner wants to ensure that security risks are identified and addressed as early as possible in the software development lifecycle. Which of the following practices BEST supports this objective?

A.Conducting a penetration test immediately before production deployment.
B.Requiring developers to complete annual secure coding training.
C.Performing dynamic application security testing (DAST) on a staging environment.
D.Integrating static application security testing (SAST) into the continuous integration pipeline.
AnswerD

SAST tools analyze source code for security flaws as developers commit changes, providing immediate feedback. This integration into the CI pipeline embeds security into the earliest stages of development, allowing issues to be fixed before they propagate. It directly supports the DevSecOps principle of identifying and addressing risks early.

Why this answer

Integrating SAST into the CI pipeline allows security checks to run automatically with every code commit, giving developers immediate feedback on vulnerabilities. This shifts security left, enabling fixes during development when they are cheapest and fastest to resolve. Other practices like penetration testing, training, and DAST are valuable but do not provide the same early, continuous, code-level risk detection.

Exam trap

The trap here is equating any security testing with shifting left; only practices embedded in the early coding and build stages truly identify risks as early as possible.

793
Multi-Selecthard

A global company is moving its critical applications to a public cloud. Which THREE of the following are key risk considerations in the shared responsibility model?

Select 3 answers
A.Physical security of data centers
B.Identity and access management
C.Compliance with regulatory requirements for data handling
D.Data encryption and key management
E.Network firewall configuration
AnswersB, C, D

Identity and access management sits with the customer in the shared responsibility model. The provider secures the platform, but the company must manage its own users, roles, federated identities, and privileged access, so weak IAM controls remain a significant risk when moving critical applications to public cloud.

Why this answer

In the shared responsibility model, the cloud provider secures the physical infrastructure, while the customer remains responsible for securing what they put in the cloud. Option B (Identity and access management) is correct because the customer must manage their own users, roles, permissions, and authentication mechanisms (e.g., IAM policies, MFA) to prevent unauthorized access to cloud resources. Option C (Compliance with regulatory requirements for data handling) is correct because the customer is accountable for ensuring that data stored and processed in the cloud meets applicable laws and standards such as GDPR, HIPAA, or PCI DSS, even though the provider may offer compliant infrastructure.

Option D (Data encryption and key management) is correct because protecting data at rest and in transit, along with managing encryption keys (e.g., via KMS or customer-managed keys), is a customer responsibility in the shared model. Option A (Physical security of data centers) is not a customer risk consideration because the cloud provider is responsible for physical security of its facilities. Option E (Network firewall configuration) is not marked correct because, while customers often manage firewalls and security groups, the question asks for key risk considerations in the shared responsibility model, and firewall configuration is a specific control rather than a broad risk category like IAM, compliance, or encryption/key management.

Exam trap

CRISC often tests the boundary of the shared responsibility model—candidates incorrectly include provider-owned controls like physical security or overlook customer-owned domains like key management and compliance.

794
MCQmedium

A risk practitioner is performing a cost-benefit analysis for a proposed control. The annualized loss expectancy (ALE) for a risk is currently $500,000. The proposed control will reduce the ALE by 80%, and the annual cost of the control is $150,000. What is the net benefit of implementing the control?

A.$100,000
B.$250,000
C.$400,000
D.$350,000
AnswerB

Reducing the $500,000 ALE by 80% yields an annualized loss expectancy of $100,000, a $400,000 risk reduction. Subtracting the control's $150,000 annual cost gives a net benefit of $250,000, satisfying the stem's cost-benefit requirement. This figure represents the residual value after control costs.

Why this answer

The control reduces the ALE by 80%, so the risk reduction benefit is 0.80 × $500,000 = $400,000. The net benefit is the benefit minus the control cost: $400,000 − $150,000 = $250,000. This represents the expected annual savings after implementing the control.

Exam trap

The trap is forgetting to subtract the control's annual cost from the risk reduction benefit, or incorrectly subtracting the cost from the residual ALE instead of the benefit.

How to eliminate wrong answers

Option A ($100,000) is wrong because it incorrectly subtracts the control cost from the remaining ALE ($100,000) rather than from the risk reduction benefit. Option C ($400,000) is wrong because it represents the gross benefit (80% of ALE) without subtracting the $150,000 control cost. Option D ($350,000) is wrong because it likely results from miscalculating the reduction (e.g., using 70% instead of 80%) or subtracting the wrong amount.

795
MCQhard

An organization uses a SIEM to automatically test access control rules on a continuous basis. This is an example of which type of monitoring?

A.Continuous monitoring
B.Key Risk Indicator monitoring
C.Vulnerability scanning
D.Periodic control testing
AnswerA

Automated SIEM rules testing access control rules on a continuous basis constitute continuous monitoring: control assessment occurs in real time or near real time rather than at discrete intervals, so deviations are detected as they arise instead of during periodic point-in-time reviews.

Why this answer

A SIEM that automatically tests access control rules on a continuous basis performs ongoing validation of rule effectiveness and compliance. This is a classic example of continuous monitoring, where security controls are assessed in real-time or near-real-time without manual intervention, ensuring that access policies remain effective against evolving threats.

Exam trap

The trap here is confusing continuous monitoring with periodic control testing. Many candidates incorrectly assume that automated testing must be a scheduled vulnerability scan, but the key differentiator is the 'continuous' nature versus scheduled intervals. In the context of CRISC, continuous monitoring is a risk response strategy that provides real-time assurance over controls.

How to eliminate wrong answers

Option B is wrong because Key Risk Indicator (KRI) monitoring focuses on tracking specific risk metrics (e.g., number of failed logins) rather than directly testing the functionality of access control rules. Option C is wrong because vulnerability scanning identifies known software vulnerabilities (e.g., missing patches) in systems, not the correctness or enforcement of access control rules. Option D is wrong because periodic control testing occurs at scheduled intervals (e.g., quarterly audits), whereas the scenario explicitly states 'continuous basis', which implies ongoing, automated validation rather than discrete, scheduled tests.

796
MCQeasy

Which control implementation activity involves updating system configurations and user access rights when a new security tool is deployed?

A.User training
B.Project management
C.Documentation update
D.Change management
AnswerD

Change management governs configuration baselines and access rights whenever a new tool alters the environment, ensuring updates are authorised, tested and documented. It directly satisfies the stem's requirement to control system configuration and user access changes during deployment, preventing unauthorised or untested modifications.

Why this answer

Deploying a new security tool requires updating system configurations and user access rights, which directly impacts the operational environment. Change management (Option D) is the formal process that governs these modifications to ensure they are authorized, tested, and documented, minimizing risk of disruption or security gaps. This aligns with the CRISC domain of Risk Response and Reporting, where controlled changes are a key risk mitigation activity.

Exam trap

The trap here is that candidates may confuse 'change management' with 'project management' because both involve planning and coordination, but change management specifically governs the technical alterations to configurations and access rights, whereas project management handles the broader initiative's logistics.

How to eliminate wrong answers

Option A is wrong because user training focuses on educating personnel on how to use the new tool, not on updating system configurations or access rights. Option B is wrong because project management oversees the overall deployment timeline, budget, and resources, but does not directly handle the technical updates to configurations and access controls. Option C is wrong because documentation update records the changes after they are made, but it is not the activity that performs the actual configuration and access right updates.

797
MCQmedium

A multinational corporation is conducting a risk assessment for its supply chain. The risk team has identified a critical supplier that provides a unique component. The supplier is located in a region prone to natural disasters. The team wants to evaluate the risk and determine the appropriate risk response. Which of the following should be the FIRST step in this evaluation?

A.Implement a dual-sourcing strategy immediately.
B.Determine the likelihood and impact of a disruption from the supplier.
C.Purchase insurance to cover potential losses from supply chain disruption.
D.Identify alternative suppliers that can provide the component.
AnswerB

The first step in risk evaluation is to assess the likelihood and impact of the risk event. For the critical supplier, this means estimating how probable a disruption is (based on the region's disaster history) and what the consequences would be (e.g., production halts, financial losses). This analysis provides the basis for prioritizing the risk and selecting an appropriate response. Without this, any response would be arbitrary.

Why this answer

The first step in evaluating a risk is to assess its likelihood and impact. This provides the necessary information to prioritize the risk and decide on an appropriate response. Identifying alternatives, purchasing insurance, or implementing dual sourcing are potential responses that should be considered only after the risk has been evaluated.

Starting with a response could lead to misallocation of resources.

Exam trap

The trap here is jumping to a risk response, such as finding alternative suppliers or buying insurance, before assessing the likelihood and impact of the risk.

798
Multi-Selectmedium

A risk manager is evaluating the application of IEC 62443 for industrial control systems. Which THREE of the following are key security requirements addressed by this standard?

Select 3 answers
A.Environmental monitoring (temperature, humidity)
B.Identification and authentication control
C.System integrity
D.Physical security of data centers
E.Use control (authorization)
AnswersB, C, E

Ensures only authorized users and devices access the system.

Why this answer

IEC 62443 is a series of standards specifically designed for the security of Industrial Automation and Control Systems (IACS). It addresses cybersecurity requirements to protect these systems from cyber threats. Identification and authentication control (B) is a foundational requirement, ensuring that only authorized users and devices can access the system, which is critical for preventing unauthorized access to industrial processes.

Exam trap

The trap here is that candidates may confuse general operational or physical security measures (like environmental monitoring or data center security) with the specific cybersecurity controls mandated by IEC 62443 for industrial control systems.

799
MCQmedium

A company has implemented an automated control monitoring system that generates alerts when transactions exceed predefined thresholds. The system has been in production for six months. The risk team notices that the number of alerts has been decreasing, while actual control failures have remained constant. Which of the following is the MOST likely cause?

A.Employees have learned to bypass the monitoring system
B.The control effectiveness has improved significantly
C.The data feed from transaction systems has degraded, causing missing data
D.The thresholds were automatically adjusted to be more restrictive
AnswerC

A degraded data feed means fewer transactions reach the monitoring engine, so fewer threshold breaches are detected even though genuine control failures continue unchanged. The falling alert count reflects missing input data rather than improved control effectiveness, explaining the divergence from the constant failure rate.

Why this answer

A decreasing alert volume with constant control failures strongly suggests the monitoring system is no longer receiving complete transaction data, so fewer transactions are evaluated and fewer threshold breaches are detected. A degraded data feed (missing or delayed records) would suppress alerts without any real improvement in control effectiveness. This is a classic monitoring integrity issue: the control may still be failing at the same rate, but the detection mechanism is blind to it.

Exam trap

CRISC often tests the misconception that fewer alerts automatically means better control effectiveness, when in fact a degraded data feed can mask ongoing control failures and produce a false sense of security.

How to eliminate wrong answers

Option A is wrong because employees bypassing the system would typically not reduce alerts — bypassed transactions would either be invisible (which is a data feed issue) or would still trigger alerts if they exceed thresholds; there is no evidence of deliberate evasion. Option B is wrong because if control effectiveness had improved, actual control failures would decrease, but the question states failures remained constant. Option D is wrong because more restrictive thresholds would increase, not decrease, the number of alerts.

800
MCQmedium

An organization is developing a new cloud-based application that will process personal data of EU citizens. The risk manager is assessing the shared responsibility model with the cloud service provider (CSP). Which of the following is the MOST critical risk to address in the risk assessment?

A.Lack of encryption at rest
B.Vendor lock-in due to proprietary APIs
C.Data sovereignty and cross-border data transfer restrictions
D.Multi-tenancy isolation failures
AnswerC

Under GDPR, personal data of EU citizens may not be transferred to jurisdictions lacking adequate protection, and the CSP controls where replicas and backups reside. This legal constraint sits with the organisation, not the provider, so it must be assessed explicitly.

Why this answer

When processing EU citizens' personal data in the cloud, the most critical risk is data sovereignty and cross-border transfer restrictions under GDPR. The regulation limits transfers of personal data outside the EU/EEA unless adequate safeguards (e.g., Standard Contractual Clauses, adequacy decisions) are in place. A CSP may store or replicate data in regions the organization did not intend, creating legal exposure that outweighs the other technical risks.

Exam trap

CRISC often tests the distinction between technical security risks and regulatory compliance risks — candidates pick encryption or isolation because they sound like 'security,' missing that GDPR data sovereignty is the dominant legal risk when EU personal data is involved.

How to eliminate wrong answers

Option A is wrong because lack of encryption at rest is a serious control gap, but it is a mitigable technical control and does not carry the same legal/regulatory weight as unlawful cross-border transfer under GDPR. Option B is wrong because vendor lock-in is a strategic and cost risk, not a regulatory compliance risk — it does not expose the organization to fines or enforcement actions. Option D is wrong because multi-tenancy isolation failures are a real cloud risk, but CSPs typically contractually address isolation, and a breach is a security incident rather than the primary compliance risk in this GDPR-specific scenario.

801
MCQhard

A risk practitioner is facilitating a workshop to identify risks for a new customer data analytics platform. During the session, participants repeatedly describe how a competitor might copy the platform's features and how a regulator might question the platform's data retention practices. The practitioner wants to ensure the workshop produces structured risk statements rather than general concerns. Which of the following should the practitioner do NEXT?

A.Reframe each concern into a risk statement linking a threat source, an asset, an event, and a potential business impact.
B.Convert the concerns into control gaps so the security team can begin remediation planning immediately.
C.Escalate the workshop outputs to the board for a risk appetite decision before further analysis.
D.Record the concerns as-is in the risk register and assign owners for follow-up.
AnswerA

Structured risk statements connect a threat source, an affected asset, a specific event, and a business consequence. Reframing the competitor and regulator concerns this way converts vague worries into assessable risks with identifiable likelihood and impact drivers. This enables consistent scoring, ownership, and control mapping, which is exactly what the workshop is meant to produce.

Why this answer

Risk identification produces structured statements that pair a threat source with an asset, an event, and a business impact. The workshop's raw concerns about competitors and regulators must be reframed this way so they can be scored, owned, and linked to controls. Registering, escalating, or converting them directly to control gaps bypasses the identification discipline and yields outputs that cannot be consistently managed.

Exam trap

The trap here is assuming that any concern voiced in a risk workshop is already a risk statement ready for the register.

802
MCQmedium

A company uses the FAIR model to perform a quantitative risk analysis. The threat event frequency (TEF) is estimated at 10 per year, vulnerability (V) is 0.5, and loss magnitude (LM) per event is $50,000. What is the annualized loss expectancy (ALE)?

A.$25,000
B.$50,000
C.$500,000
D.$250,000
AnswerD

FAIR derives annualised loss expectancy by multiplying threat event frequency, vulnerability and loss magnitude. Here 10 events per year multiplied by 0.5 vulnerability gives five loss events annually, and five multiplied by $50,000 yields $250,000, satisfying the quantitative calculation the stem requests.

Why this answer

In the FAIR model, ALE = TEF × Vulnerability × Loss Magnitude. Here, TEF = 10, V = 0.5, LM = $50,000. So ALE = 10 × 0.5 × $50,000 = $250,000.

This represents the expected annual loss from the risk event.

Exam trap

The trap is omitting the vulnerability factor and simply multiplying TEF by LM, or misplacing decimal points when converting percentages.

How to eliminate wrong answers

Option A ($25,000) is wrong because it results from multiplying TEF × V × LM incorrectly (e.g., 10 × 0.5 × 5000). Option B ($50,000) is wrong because it equals only the loss magnitude per event, ignoring frequency and vulnerability. Option C ($500,000) is wrong because it equals TEF × LM (10 × $50,000) without applying the vulnerability factor.

803
MCQeasy

An organization has implemented a new firewall rule to block malicious IP addresses. This is an example of which type of control?

A.Directive control
B.Preventive control
C.Corrective control
D.Detective control
AnswerB

Blocking malicious IP addresses stops the traffic before it reaches the target, so the control acts on the threat event itself rather than detecting it afterwards or repairing damage. Prevention is the defining characteristic, distinguishing it from detective controls such as logging and corrective controls such as restoration.

Why this answer

A firewall rule that blocks malicious IP addresses is a preventive control because it proactively stops unauthorized traffic before it can reach the internal network. By filtering packets based on source IP addresses, the firewall enforces access control policies at the network layer, preventing potential attacks from ever being initiated. This aligns with the CRISC definition of preventive controls, which are designed to avoid or deter undesirable events.

Exam trap

The trap here is confusing preventive controls with detective controls, as candidates often think of firewalls as 'detecting' threats, but the key distinction is that a firewall rule actively blocks (prevents) traffic, not merely logs or alerts on it.

How to eliminate wrong answers

Option A is wrong because directive controls are policies, procedures, or guidelines that define acceptable behavior (e.g., an acceptable use policy), not technical mechanisms that block traffic. Option C is wrong because corrective controls are applied after an incident to restore operations (e.g., restoring from backup after a ransomware attack), not to block threats in real time. Option D is wrong because detective controls identify and log malicious activity after it has occurred (e.g., intrusion detection system alerts), whereas a firewall rule actively prevents the traffic from entering.

804
MCQmedium

An organization’s continuous monitoring program includes automated vulnerability scanning and log review. Which of the following is a Key Risk Indicator (KRI) that would BEST signal an increasing risk of a successful network breach?

A.Average time to patch critical vulnerabilities
B.Spike in failed authentication attempts from external IPs
C.Number of firewall rule changes per month
D.Percentage of systems with up-to-date antivirus signatures
AnswerB

Failed external authentication attempts are a leading indicator: they rise before a breach succeeds, revealing active credential-guessing or brute-force activity against exposed services. Unlike lagging measures such as confirmed incidents, this spike gives continuous monitoring data that signals escalating likelihood, directly satisfying the KRI requirement for early warning.

Why this answer

A Key Risk Indicator (KRI) is a forward-looking metric that signals changes in risk exposure. A spike in failed authentication attempts from external IPs is a leading indicator of attempted unauthorized access — such as brute-force or credential-stuffing attacks — and directly signals increasing likelihood of a successful network breach. It is actionable and tied to a specific threat vector.

Exam trap

CRISC often tests the distinction between KRIs (leading, risk-signaling metrics) and KPIs (performance/coverage metrics) — candidates frequently pick control-effectiveness metrics like patch time or AV coverage instead of threat-activity indicators.

How to eliminate wrong answers

Option A is wrong because average time to patch critical vulnerabilities is more of a Key Performance Indicator (KPI) for patch management effectiveness — it measures process efficiency, not directly an increasing breach risk signal. Option C is wrong because the number of firewall rule changes per month measures change activity; while excessive changes can introduce risk, the metric alone does not signal an active or increasing breach threat. Option D is wrong because percentage of systems with up-to-date antivirus signatures is a compliance/coverage KPI — high coverage is good, but it does not indicate an increasing risk of breach; it measures control effectiveness, not threat activity.

805
MCQhard

A financial institution is implementing a new online banking platform. The risk assessment identified that the platform will handle sensitive customer data and must comply with GDPR and local banking regulations. The project team proposes encrypting all data at rest and in transit, implementing multi-factor authentication (MFA), and conducting quarterly penetration tests. However, the risk owner is concerned about the residual risk of a sophisticated phishing attack that could bypass MFA. The board has a low risk appetite. What is the BEST way to address this residual risk?

A.Purchase cyber insurance to transfer the financial impact of a potential phishing attack.
B.Implement advanced phishing-resistant MFA (e.g., FIDO2) and conduct regular employee phishing simulation training.
C.Reduce the project scope to exclude online banking and revert to a less risky channel.
D.Accept the residual risk because the existing controls (encryption, MFA, pen tests) already provide reasonable assurance.
AnswerB

Phishing-resistant MFA such as FIDO2 uses origin-bound cryptographic credentials that cannot be replayed by proxy phishing sites, directly mitigating the MFA-bypass residual risk. Combining it with simulation training addresses the human factor, aligning treatment with the board's low risk appetite.

Why this answer

The residual risk is a sophisticated phishing attack that could bypass MFA, and the board has a low risk appetite, so the risk must be reduced rather than transferred or accepted. Implementing phishing-resistant MFA such as FIDO2/WebAuthn (hardware security keys or passkeys) removes the shared-secret and OTP weaknesses that phishing kits exploit, and pairing it with ongoing phishing simulation training hardens the human layer. This directly addresses the specific residual risk while preserving the business value of the online banking platform.

Exam trap

CRISC often tests the distinction between risk response types (avoid, mitigate, transfer, accept) — candidates pick insurance (transfer) or acceptance because they sound pragmatic, but a low risk appetite plus an identified residual risk demands a mitigation answer that reduces likelihood, not one that merely moves or tolerates the impact.

How to eliminate wrong answers

Option A is wrong because cyber insurance only transfers the financial consequence of a phishing loss; it does not reduce the likelihood of the attack and leaves the low-appetite board exposed to the underlying risk. Option C is wrong because reducing scope to exclude online banking is a risk-avoidance overreaction that destroys business value when a targeted control (phishing-resistant MFA) can bring the risk within appetite. Option D is wrong because accepting the residual risk contradicts the board's stated low risk appetite, and standard MFA plus pen tests do not mitigate real-time adversary-in-the-middle phishing that defeats OTP-based MFA.

806
MCQmedium

You are the risk manager for a healthcare organization that uses an electronic health records (EHR) system. The system has a built-in audit log that records all access to patient data. Recently, the Chief Information Security Officer (CISO) raised a concern that there have been multiple reports of unauthorized access to patient records, but the audit log analysis has not identified any suspicious activity. You have been asked to investigate. Your review of the audit log configuration reveals that the system only logs successful access events, not failed access attempts. Additionally, the log retention period is set to 30 days, and the logs are stored in a flat file on the same server as the EHR application. The monitoring team manually reviews the logs at the end of each month. Which of the following is the MOST significant risk associated with the current monitoring approach?

A.Storing logs on the same server as the EHR application exposes them to alteration or deletion if the server is compromised.
B.The 30-day log retention period is too short to detect long-term patterns of unauthorized access.
C.Manual review of logs is ineffective and may miss critical events; automated monitoring should be implemented.
D.The audit log does not capture failed access attempts, which could indicate brute-force attacks or unauthorized access attempts.
AnswerA

Flat-file logs on the EHR application server share its compromise boundary, so an attacker gaining server access could alter or delete evidence of unauthorised access. This directly undermines log integrity and the investigation's reliability, making it the most significant risk.

Why this answer

Storing audit logs on the same server as the EHR application violates the principle of log segregation. If the server is compromised, an attacker can alter or delete the logs to cover their tracks, making detection impossible. This is the most significant risk because it directly undermines the integrity and availability of the evidence needed to investigate unauthorized access.

Exam trap

The trap here is that candidates focus on the operational deficiencies (short retention, manual review, missing failed attempts) rather than the foundational security control failure of log segregation, which is the most critical risk because it compromises the entire audit trail.

How to eliminate wrong answers

Option B is wrong because while a 30-day retention period may be suboptimal for long-term pattern analysis, it is not the most significant risk given that the logs are already vulnerable to tampering and the current manual review process would likely miss patterns regardless. Option C is wrong because although manual review is inefficient, the core issue is that even with automated monitoring, the logs stored on the same server could be destroyed or altered before any alert is triggered. Option D is wrong because while missing failed access attempts is a gap, the lack of logging for failed attempts is less critical than the complete loss of log integrity if the server is compromised.

807
Multi-Selecthard

An organization is planning for post-quantum cryptography migration. Which THREE of the following are key considerations for this migration?

Select 3 answers
A.Inventory of all cryptographic assets and dependencies
B.Replacing all existing hardware immediately
C.Crypto agility to easily replace algorithms
D.Timeline estimates for when quantum computers can break current cryptography
E.Eliminating cloud services to reduce risk
AnswersA, C, D

Knowing where cryptography is used is essential.

Why this answer

A comprehensive inventory of cryptographic assets and dependencies is essential to identify all systems, applications, and data that rely on current cryptographic algorithms (e.g., RSA, ECDSA, Diffie-Hellman). Without this inventory, the organization cannot prioritize migration efforts, assess impact, or ensure that no legacy cryptographic dependency is overlooked during the transition to post-quantum algorithms.

Exam trap

The trap here is that candidates may confuse 'crypto agility' (Option C) with 'immediate hardware replacement' (Option B), or assume that cloud services must be eliminated (Option E) rather than recognizing that inventory, agility, and timeline are the three core strategic considerations for a phased, risk-based migration.

808
MCQeasy

A risk analyst is reviewing monthly control test results. One control failed testing twice in a row. What is the FIRST step the analyst should take?

A.Report the failure in the next risk report to management.
B.Perform a root cause analysis of the control failure.
C.Update the risk register with a higher inherent risk rating.
D.Escalate the failure to the risk committee immediately.
AnswerB

A repeat failure signals the control itself is flawed, not merely an isolated lapse. Root cause analysis identifies why it failed before redesigning or replacing the control, satisfying the stem's requirement for the first step rather than jumping to remediation.

Why this answer

The first step when a control fails testing twice in a row is to perform a root cause analysis (RCA) to understand why the failure occurred. Without identifying the underlying cause, any corrective action or reporting would be premature and could lead to ineffective remediation. This aligns with the CRISC focus on proactive risk monitoring and control improvement before escalating or updating risk ratings.

Exam trap

The trap here is that candidates often jump to reporting or escalation (options A or D) because they confuse operational incident response with risk management, but CRISC emphasizes that understanding the root cause is the prerequisite for any subsequent action.

How to eliminate wrong answers

Option A is wrong because reporting the failure to management without first understanding the root cause could result in incomplete or misleading information, and management expects actionable insights, not just raw failure data. Option C is wrong because updating the risk register with a higher inherent risk rating should only occur after the root cause is understood and the control's effectiveness is reassessed; inherent risk is about the risk before controls, not a reaction to control failures. Option D is wrong because immediate escalation to the risk committee is an overreaction for a single control failure pattern; escalation should follow a defined threshold or after RCA indicates a significant control deficiency.

809
MCQeasy

A risk practitioner is reviewing the results of a risk assessment and needs to determine the risk level for a series of identified risks. The organization uses a risk matrix with likelihood and impact scales. Which of the following is the PRIMARY purpose of determining the risk level?

A.To document the risk register for audit purposes only
B.To eliminate all risks that are above the organization's risk appetite
C.To prioritize risks for treatment and allocate resources effectively
D.To calculate the exact financial loss from each risk
AnswerC

Risk level combines likelihood and impact to indicate the significance of a risk. The primary purpose is to enable prioritization so that resources are directed to the most significant risks first. This supports risk-based decision making and aligns treatment efforts with the organization's risk appetite and objectives.

Why this answer

Determining risk level via likelihood and impact allows the organization to rank risks and focus attention and resources on the most significant ones. This prioritization is essential for effective risk treatment and for aligning risk management with business objectives and risk appetite.

Exam trap

The trap here is assuming risk level must be precise or that all above-appetite risks must be eliminated, rather than used for prioritization.

810
MCQeasy

A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?

A.Mitigate by implementing encryption
B.Accept the risk
C.Avoid by discontinuing data processing
D.Transfer via cyber insurance
AnswerA

Implementing encryption directly removes the regulatory exposure, satisfying the requirement that personal data be encrypted at rest. With moderate cost against high non-compliance risk, mitigation offers the best value; acceptance, avoidance or transfer would leave the legal obligation unmet. Encryption is the precise control the regulation mandates.

Why this answer

Mitigating the risk by implementing encryption is the most appropriate response because the cost is moderate and the risk of non-compliance is high. Encryption directly addresses the regulatory requirement and reduces the risk to an acceptable level. This aligns with risk management principles where high-impact risks with feasible controls should be mitigated.

Exam trap

CRISC often tests the misconception that transferring risk via insurance is sufficient for compliance, or that acceptance is viable when the risk is high; candidates must recognize that mitigation is the correct response when the cost is reasonable and the risk is significant.

How to eliminate wrong answers

Option B is wrong because accepting the risk is inappropriate when non-compliance carries high penalties and the cost to mitigate is moderate; acceptance is only suitable for low-impact risks or when mitigation is too costly. Option C is wrong because avoiding the risk by discontinuing data processing would likely disrupt business operations and is not proportionate to the moderate cost of encryption. Option D is wrong because transferring the risk via cyber insurance does not address the regulatory requirement for encryption at rest; insurance may cover financial losses but does not achieve compliance.

811
MCQmedium

A company decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?

A.Mitigate
B.Accept
C.Avoid
D.Transfer
AnswerD

Cyber insurance shifts the financial consequence of a breach to an insurer rather than reducing likelihood or impact through controls. This is transfer, satisfying the stem's scenario: the risk itself remains, but the loss burden is contractually moved to a third party in exchange for premiums.

Why this answer

Purchasing cyber insurance shifts the financial consequences of a data breach to a third party (the insurer) in exchange for a premium. In risk treatment terminology, this is risk transfer (also called risk sharing). The organization still owns the risk of the breach occurring, but the financial impact is contractually transferred, making 'Transfer' the correct answer.

Exam trap

CRISC often tests the distinction between risk transfer and risk mitigation, as candidates may incorrectly assume that buying insurance reduces the likelihood of a breach (mitigation) rather than just transferring the financial impact.

How to eliminate wrong answers

Option A (Mitigate) is wrong because mitigation involves implementing controls to reduce the likelihood or impact of a risk (e.g., firewalls, encryption), not paying a third party to assume financial responsibility. Option B (Accept) is wrong because acceptance means acknowledging the risk and deciding to bear the potential losses without taking any action to transfer or reduce it; buying insurance is an active treatment, not passive acceptance. Option C (Avoid) is wrong because avoidance means eliminating the risk entirely by not engaging in the activity that creates it (e.g., not storing customer data), whereas insurance does not eliminate the risk—it only compensates for losses.

812
MCQhard

During a merger and acquisition (M&A) due diligence, the IT risk manager needs to identify risks in the target company's IT environment. Which approach is most effective for comprehensive risk identification?

A.Send a detailed questionnaire to the target's IT department
B.Review the target's public financial reports
C.Conduct a war gaming exercise
D.Conduct an on-site assessment of the target's IT infrastructure
AnswerD

An on-site assessment directly inspects the target's live infrastructure, configurations and controls, exposing undocumented risks that questionnaires and document reviews miss. It satisfies the due diligence constraint of identifying risks across an unfamiliar environment, where reliance on self-reported data is unreliable. Physical and technical observation reveals gaps in the actual estate.

Why this answer

An on-site assessment (Option D) allows the IT risk manager to directly observe the target's IT infrastructure, including physical security, network configurations, and operational practices. This hands-on approach uncovers risks that may be hidden or misrepresented in self-reported questionnaires, such as outdated firmware, unpatched systems, or insecure network segmentation. It provides the most comprehensive and accurate risk identification for M&A due diligence.

Exam trap

The trap here is that candidates may overestimate the reliability of self-reported data from questionnaires (Option A) because it seems systematic and efficient, but the CRISC exam emphasizes that direct verification through on-site assessment is essential for comprehensive risk identification in M&A due diligence.

How to eliminate wrong answers

Option A is wrong because a detailed questionnaire relies on self-reporting by the target's IT department, which may omit or downplay critical risks due to lack of awareness or intentional concealment, and cannot verify the actual state of systems like patch levels or firewall rules. Option B is wrong because public financial reports focus on monetary performance and regulatory filings, not on technical IT risks such as insecure configurations, unpatched vulnerabilities, or inadequate access controls. Option C is wrong because war gaming exercises are designed to test strategic responses to hypothetical scenarios, not to identify existing technical risks in a target's IT environment, and they lack the granularity needed for infrastructure-level assessment.

813
MCQeasy

A retail company's risk register shows that a point-of-sale system vulnerability has a high likelihood and high impact. The IT team proposes applying a vendor patch, but the patch has not been tested with the custom payment application. Which risk response strategy is being considered?

A.Risk transfer
B.Risk acceptance
C.Risk mitigation
D.Risk avoidance
AnswerC

Mitigation involves implementing controls to reduce the likelihood or impact of a risk. Applying a vendor patch directly reduces the likelihood of exploitation of the POS vulnerability. The fact that the patch is untested with the custom application introduces a new risk, but the intended response strategy remains mitigation because the goal is to lower the original risk.

Why this answer

The IT team is proposing a patch to reduce the likelihood of exploitation, which is a mitigation response. Mitigation is the appropriate strategy when an organization chooses to implement controls to lower risk rather than accept, transfer, or avoid it. The untested patch introduces a secondary risk that must be managed, but the primary response strategy remains mitigation.

Exam trap

The trap here is confusing mitigation with acceptance because the patch is untested, but the intent to reduce risk through a control defines mitigation.

814
MCQhard

During a control implementation project, the risk manager discovers that the resource requirements have increased significantly, making the original cost-benefit analysis invalid. What should the risk manager do first?

A.Continue the project and request additional budget later
B.Escalate to the board for approval of additional funds
C.Cancel the project immediately
D.Perform a revised cost-benefit analysis
AnswerD

Revised resource requirements invalidate the original cost-benefit analysis, so recalculating costs against expected benefits restores the basis for a go/no-go decision. Performing this revised analysis first gives management accurate figures before any scope, budget or approval changes are considered.

Why this answer

When resource requirements change enough to invalidate the original cost-benefit analysis, the risk manager's first step is to perform a revised cost-benefit analysis to reassess whether the control is still justified relative to the risk it mitigates. This provides the objective data needed before any decision to continue, escalate, or cancel. CRISC emphasizes that risk decisions must be based on current, accurate information rather than assumptions.

Exam trap

CRISC often tests the instinct to escalate or cancel when costs change — the correct first step is always to gather updated information (revised cost-benefit analysis) before making a governance decision.

How to eliminate wrong answers

Option A is wrong because continuing the project and requesting budget later bypasses governance and commits resources without validating whether the control still provides value relative to its new cost. Option B is wrong because escalating to the board for additional funds is premature — the board needs a revised cost-benefit analysis to make an informed decision, and escalation without that analysis violates the risk management process. Option C is wrong because cancelling immediately is an overreaction; the revised analysis may show the control is still cost-effective, and cancellation without analysis ignores the risk exposure the control was meant to address.

815
MCQmedium

A financial services firm's risk practitioner is building a risk register entry for a customer-facing mobile banking application hosted in a public cloud. The application stores PII and processes payments. Management wants to understand the inherent risk before any controls are considered. Which of the following BEST represents the inherent risk of this asset?

A.The likelihood and impact of loss assuming no controls are in place, derived from the threat environment and the asset's value and exposure.
B.The aggregate cost of the security controls deployed to protect the mobile application and its supporting cloud infrastructure.
C.The likelihood and impact of loss after all implemented controls have been applied and validated by internal audit.
D.The maximum regulatory fine the firm could face if the application suffered a data breach involving customer PII.
AnswerA

Inherent risk is assessed before considering the mitigating effect of controls, using the threat landscape, asset value, and exposure. For this mobile banking app, that means evaluating realistic threat events against the PII and payment data it handles, independent of any existing security measures. This gives management a baseline against which control effectiveness and residual risk can later be compared.

Why this answer

Inherent risk is the exposure that exists before controls are applied, built from the threat environment and the value and exposure of the asset. For a mobile banking app holding PII and processing payments, the practitioner must assess realistic threat events and their potential impacts without crediting existing safeguards. This baseline enables meaningful comparison once control effectiveness is evaluated and residual risk is determined.

Exam trap

The trap here is confusing inherent risk with residual risk or with control cost, which leads to understating exposure before controls are evaluated.

816
Multi-Selectmedium

A healthcare provider has experienced repeated phishing incidents that led to credential compromise. The risk committee has approved a new email security control that will quarantine suspicious messages and enforce multifactor authentication. Which TWO activities are essential to validate that the control is operating effectively after implementation? (Choose two.)

Select 2 answers
A.Review the vendor's marketing materials and SOC 2 report to confirm the product supports quarantine and MFA features.
B.Conduct periodic control testing by simulating phishing campaigns and reviewing whether messages are quarantined and MFA is enforced.
C.Confirm that the project to implement the control was completed within the approved budget and schedule.
D.Ask employees to sign an acknowledgment that they have read the updated acceptable use policy.
E.Collect and analyze control performance metrics, such as the percentage of suspicious emails quarantined and MFA challenge success rates, and report exceptions.
AnswersB, E

Simulated phishing campaigns and verification of MFA enforcement directly test whether the new control performs as designed against realistic attack patterns. This produces evidence about control effectiveness rather than assuming implementation equals effectiveness. Periodic testing also reveals configuration drift and user bypass behaviors, allowing the risk committee to confirm that the approved risk response is actually reducing the phishing exposure.

Why this answer

Validation of a control requires evidence that it operates as intended in the production environment. Simulated phishing tests combined with MFA enforcement checks directly exercise the control against realistic threats, while performance metrics and exception reporting provide continuous, quantifiable evidence of effectiveness. Vendor documentation, policy acknowledgment, and project delivery metrics may support the program but do not demonstrate that the control is actually working.

Exam trap

The trap here is treating vendor certifications and policy attestations as evidence of control effectiveness, when only direct testing and performance monitoring demonstrate operating effectiveness.

817
Multi-Selectmedium

A risk manager is designing an IT risk management programme. Which THREE of the following are essential components of a risk management policy?

Select 3 answers
A.Risk assessment methodology
B.Specific risk treatment plans
C.Risk appetite statement
D.Detailed risk register
E.Roles and responsibilities for risk management
AnswersA, C, E

Methodology defines how risks are assessed.

Why this answer

A risk assessment methodology is an essential component of a risk management policy because it defines the standardized approach for identifying, analyzing, and evaluating IT risks. Without a prescribed methodology, risk assessments would be inconsistent, making it impossible to compare risks across the organization or to align them with the risk appetite. The policy must mandate a repeatable process, such as NIST SP 800-30 or ISO 31010, to ensure objectivity and defensibility in risk decisions.

Exam trap

The trap here is that candidates confuse operational artifacts (risk treatment plans and risk registers) with policy-level components, failing to recognize that the policy sets the framework and mandates, not the specific details of each risk response.

818
Multi-Selecthard

During an IT risk assessment, the risk team identifies a high inherent risk for a legacy application. The team is evaluating control options. Which THREE are considered preventive controls?

Select 3 answers
A.Log monitoring
B.Encryption of data at rest
C.Change management process
D.Access controls
E.Backup restoration procedures
AnswersB, C, D

Encrypting data at rest is preventive because it stops unauthorised parties reading stored data even if media is accessed, removing the exposure before it occurs. This likelihood-reducing, pre-event mechanism satisfies the stem's preventive control criterion.

Why this answer

Preventive controls aim to stop risk events. Access controls, encryption, and change management are preventive. Logs are detective, backup restoration is corrective.

819
MCQeasy

An organization has decided to purchase cyber insurance to cover potential losses from a ransomware event affecting its order-processing systems. Which risk response has the organization selected?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerD

Purchasing insurance shifts the financial consequence of a specified loss to a third party in exchange for a premium. The risk itself still exists and the systems remain exposed, but the monetary impact is contractually borne by the insurer within policy limits and conditions. This is the defining characteristic of transfer as a risk response.

Why this answer

Insurance is the classic transfer response: a premium is exchanged for the insurer's assumption of defined financial losses. The operational risk of ransomware remains with the organization, which is why transfer is often paired with mitigation. Avoidance would end the activity, mitigation would reduce likelihood or impact directly, and acceptance would retain the loss without external coverage.

Exam trap

The trap here is treating insurance as mitigation because it feels like a protective measure rather than a financial arrangement.

820
MCQmedium

A risk owner decides to accept a risk because the cost of mitigation exceeds the potential loss, and the risk level is within the organization's risk appetite. What should the risk owner do next?

A.Implement detective controls to monitor the risk
B.Reassess the risk using quantitative analysis
C.Transfer the risk to a third party via insurance
D.Document the risk and obtain formal sign-off
AnswerD

Acceptance is only valid once recorded; the risk owner must document the decision, its rationale and the accepted risk level, then obtain formal sign-off from the appropriate authority. This creates the audit trail demonstrating the acceptance was deliberate and within risk appetite.

Why this answer

When a risk owner decides to accept a risk because mitigation costs exceed potential loss and the risk is within appetite, the next step is to document the risk and obtain formal sign-off. This ensures accountability, creates an audit trail, and aligns with governance requirements. Acceptance must be an informed, documented decision.

Exam trap

CRISC often tests the importance of formal documentation and sign-off for risk acceptance, but candidates may skip to implementing controls or reassessing, missing the governance step.

How to eliminate wrong answers

Option A is wrong because implementing detective controls is a mitigation action, which contradicts the decision to accept the risk. Option B is wrong because reassessing with quantitative analysis is unnecessary if the risk is already within appetite and the decision is made. Option C is wrong because transferring the risk via insurance is a different treatment option, not the next step after acceptance.

821
MCQhard

An organization has a legacy system that cannot be patched due to vendor end-of-life. The system processes non-critical data. The risk manager has determined that the likelihood of exploitation is low, but the impact would be high. Which risk response strategy is MOST appropriate?

A.Mitigate the risk by applying vendor patches.
B.Avoid the risk by decommissioning the system immediately.
C.Transfer the risk by purchasing cyber insurance.
D.Accept the risk with compensating controls such as network segmentation.
AnswerD

Acceptance suits a low-likelihood, non-critical system where remediation is impossible, and compensating controls such as network segmentation reduce the high impact without patching. The vendor end-of-life constraint rules out mitigation through patching, making acceptance with controls the pragmatic response.

Why this answer

The system processes non-critical data and cannot be patched, making risk acceptance with compensating controls the most appropriate strategy. Network segmentation reduces the likelihood of exploitation by isolating the legacy system from critical assets, while the low likelihood and non-critical data make decommissioning or insurance less suitable. This aligns with CRISC best practices for legacy systems where patching is impossible and the risk is within the organization's risk appetite.

Exam trap

ISACA often tests the misconception that 'high impact' always requires mitigation or avoidance, but the trap here is that when likelihood is low and the data is non-critical, acceptance with compensating controls is the most cost-effective and appropriate response per the risk management framework.

How to eliminate wrong answers

Option A is wrong because the vendor has ended support, meaning no patches are available, so mitigation via patching is technically infeasible. Option B is wrong because decommissioning immediately is an extreme response for a system processing non-critical data with low exploitation likelihood; it would likely cause unnecessary operational disruption and cost. Option C is wrong because cyber insurance transfers financial risk but does not reduce the likelihood or impact of exploitation; it is a secondary response and not the most appropriate primary strategy for a low-likelihood, high-impact scenario where compensating controls can be applied.

822
Multi-Selectmedium

A risk practitioner is designing a key risk indicator (KRI) program for a cloud-hosted customer portal. The CISO wants indicators that provide early warning of deteriorating risk conditions rather than reporting losses that have already occurred. Which TWO of the following are the MOST appropriate KRIs for this objective? (Choose two.)

Select 2 answers
A.Number of confirmed data breaches reported to regulators in the last quarter
B.Total annual cost of cyber insurance premiums for the customer portal
C.Percentage of critical portal servers with missing high-severity patches older than 30 days
D.Average time to close security incidents after they have been detected
E.Number of privileged accounts lacking multifactor authentication on the portal
AnswersC, E

Unpatched high-severity vulnerabilities are a leading indicator because they measure a condition that raises the likelihood of a future compromise before any incident occurs. Tracking the percentage of servers outside the 30-day window provides an early warning signal tied directly to the threat landscape. This aligns with the CISO's request for predictive rather than lagging indicators.

Why this answer

Leading indicators measure conditions that precede loss, such as unpatched high-severity vulnerabilities and privileged accounts without multifactor authentication. Both can be tracked continuously and remediated before an attacker exploits them. Breach counts, insurance premiums, and incident closure times all describe outcomes or costs that appear only after risk has already materialized.

Exam trap

The trap here is selecting operational security metrics that feel proactive, such as incident closure time, when they actually measure events that have already occurred.

823
Multi-Selecthard

A company is implementing a risk identification process for third-party risks. Which THREE factors should be considered when identifying risks from a critical software vendor?

Select 3 answers
A.Number of employees at vendor
B.Vendor's compliance with relevant regulations
C.Service level agreements (SLAs)
D.Vendor's history of security incidents
E.Vendor's financial stability
AnswersB, D, E

Regulatory non-compliance by the vendor creates legal, contractual, and reputational exposure for the organisation, particularly where the vendor processes regulated data. Assessing the vendor's adherence to applicable regulations identifies compliance-driven third-party risk, one of the factors required when identifying risks from a critical software vendor.

Why this answer

Option B is correct because a critical software vendor's compliance with relevant regulations (e.g., GDPR, HIPAA, PCI DSS, SOX) directly determines legal, contractual, and data-protection exposure, and non-compliance is itself an identifiable third-party risk. Option D is correct because a documented history of security incidents (breaches, ransomware, vulnerabilities, downtime) is a concrete indicator of the likelihood and impact of future third-party risk. Option E is correct because the vendor's financial stability affects continuity of service, ability to remediate vulnerabilities, and the risk of sudden insolvency or acquisition that could disrupt critical software support.

Option A does not belong because headcount alone is not a meaningful risk indicator — a small vendor can be highly secure and a large one poorly controlled. Option C does not belong because SLAs are contractual performance terms used to manage or transfer risk after identification, not a factor for identifying the risk itself.

Exam trap

CRISC often tests the distinction between risk identification inputs (compliance, incident history, financial stability) and downstream contractual/operational artifacts (SLAs) or irrelevant size metrics (employee count), causing candidates to select SLAs because they sound risk-related.

824
MCQmedium

A financial services firm is migrating its customer relationship management (CRM) system to a SaaS provider. The risk practitioner must assess the provider's security posture. Which of the following is the MOST reliable source of assurance?

A.A SOC 2 Type II report covering the relevant trust services criteria.
B.The provider's marketing materials and security whitepaper.
C.The provider's completed self-assessment questionnaire.
D.A penetration test report the provider commissioned last year.
AnswerA

A SOC 2 Type II report is an independent auditor's opinion on the design and operating effectiveness of controls over a period of time. It provides reliable evidence about security, availability, and confidentiality controls relevant to a SaaS provider. For a CRM holding customer data, this report gives the most credible assurance of the provider's control environment.

Why this answer

For a SaaS provider handling customer data, the most reliable assurance comes from an independent audit of controls over time. A SOC 2 Type II report provides exactly that, covering relevant trust services criteria. Other sources are either self-reported, point-in-time, or not designed for comprehensive risk assessment.

Exam trap

The trap here is treating a self-assessment or a one-time penetration test as equivalent to an independent, period-based audit of controls.

825
MCQeasy

Which of the following is a primary concern when using AI/ML models for decisions subject to regulatory oversight?

A.Adversarial attacks
B.Model bias
C.Explainability of model decisions
D.Data privacy in training
AnswerC

Explainability directly addresses the regulatory constraint: overseers must be able to audit and justify automated decisions. Unlike accuracy or performance, explainability determines whether an organisation can demonstrate compliance and accountability to regulators, satisfying the stem's oversight requirement. Opaque models, even accurate ones, fail this obligation because decisions cannot be traced or defended.

Why this answer

When AI/ML models drive decisions subject to regulatory oversight (e.g., credit, hiring, healthcare), explainability is the primary concern because regulators and affected individuals must understand how a decision was reached. Without explainability, the organization cannot demonstrate compliance with laws like GDPR Article 22 (right to explanation) or fair lending regulations, and cannot defend decisions in audits or disputes.

Exam trap

CRISC often tests the difference between technical AI risks (adversarial attacks, bias, privacy) and regulatory/oversight risks — candidates pick bias or privacy because they are prominent AI concerns, missing that explainability is the linchpin for regulatory accountability.

How to eliminate wrong answers

Option A is wrong because adversarial attacks are a security concern, but they are not the primary regulatory issue — regulators focus on whether decisions can be explained and justified, not on whether inputs can be manipulated. Option B is wrong because model bias is a critical fairness concern and often a regulatory focus, but it is a subset of the broader explainability problem — you cannot detect or remediate bias without understanding how the model reaches decisions. Option D is wrong because data privacy in training is important, but it concerns the input data, not the decision-making process that regulators scrutinize; privacy can be addressed with anonymization and consent, whereas explainability is intrinsic to the model's architecture.

Page 10

Page 11 of 15

Page 12