Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 826–900

1062 questions total · 15pages · All types, answers revealed

Page 11

Page 12 of 15

Page 13
826
MCQmedium

During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?

A.Deploy the application across multiple cloud regions with automated failover
B.Purchase cyber insurance to cover financial losses
C.Implement encryption at rest and in transit
D.Conduct a business impact analysis (BIA)
AnswerA

Deploying across multiple cloud regions with automated failover directly removes the single-region dependency identified by the ARB, satisfying the resilience constraint the stem raises. Unlike backup-only or manual recovery approaches, automated failover maintains service availability during a regional outage, which is the specific risk the proposed architecture currently leaves unmitigated.

Why this answer

The identified risk is the lack of disaster recovery for a single-region cloud deployment. The best mitigation is to deploy across multiple cloud regions with automated failover, which directly addresses the availability and resilience gap by ensuring the application survives a regional outage. This is a preventive/architectural control that reduces both likelihood and impact of downtime.

Exam trap

CRISC often tests the difference between risk mitigation, risk transfer, and risk assessment — candidates select insurance (transfer) or BIA (assessment) when the question asks for the BEST recommendation to mitigate an availability risk, which requires a preventive architectural control.

How to eliminate wrong answers

Option B is wrong because cyber insurance is a financial risk transfer mechanism — it compensates losses after an incident but does not restore service or prevent downtime, so it does not mitigate the availability risk. Option C is wrong because encryption at rest and in transit addresses confidentiality and data protection, not availability or disaster recovery; it is irrelevant to the single-region resilience gap. Option D is wrong because a business impact analysis identifies and quantifies the consequences of disruption, but it is an assessment activity, not a mitigation — it does not reduce the risk itself.

827
MCQhard

A company identifies a high inherent risk in its online payment system. After implementing a Web Application Firewall (WAF) and conducting quarterly penetration tests, the residual risk is assessed as medium. Which of the following best explains the relationship between inherent risk, controls, and residual risk?

A.Residual risk is the inherent risk adjusted for the effectiveness of controls in reducing likelihood and impact.
B.Inherent risk is the risk after controls are applied, while residual risk is the risk before controls.
C.Residual risk equals inherent risk minus the total cost of controls implemented.
D.Inherent risk and residual risk are independent; residual risk is determined solely by threat intelligence.
AnswerA

Inherent risk is the exposure before controls; residual risk is what remains after controls reduce likelihood or impact. The WAF and penetration tests lowered the high inherent risk to medium, demonstrating that adjustment relationship directly.

Why this answer

Residual risk is defined as the risk that remains after controls have been applied to reduce the likelihood and/or impact of a threat exploiting a vulnerability. In this scenario, the high inherent risk was reduced to medium residual risk by the WAF and quarterly penetration tests, which is exactly the relationship described. This is the foundational risk equation in CRISC and ISO 31000.

Exam trap

CRISC often tests the reversal trap — candidates confuse inherent (before controls) with residual (after controls), so read the definitions carefully and anchor on 'inherent = raw, residual = remaining.'

How to eliminate wrong answers

Option B is wrong because it reverses the definitions — inherent risk is the risk before controls, and residual risk is the risk after controls, not the other way around. Option C is wrong because residual risk is not a monetary subtraction of control costs; it is a qualitative or quantitative assessment of remaining exposure after controls reduce likelihood and impact, independent of control cost. Option D is wrong because inherent and residual risk are directly related through the control environment, not independent; residual risk is derived from inherent risk adjusted by control effectiveness, not determined solely by threat intelligence.

828
MCQhard

A company has multiple business units each using different risk assessment methodologies. The risk committee wants consistent monitoring reports. What is the BEST approach to achieve consistency?

A.Develop and mandate a standardized risk assessment methodology.
B.Aggregate risks at the enterprise level using a common taxonomy.
C.Require each business unit to adopt the same risk scoring scale.
D.Create a centralized reporting template with predefined fields.
AnswerA

Mandating one standardised methodology directly satisfies the consistency constraint by removing methodological variance across business units. Identical scoring scales, likelihood definitions and impact criteria let the risk committee aggregate and compare outputs into unified monitoring reports, rather than reconciling incompatible assessments. Standardisation addresses the root cause — divergent methodologies — instead of merely harmonising reporting formats afterwards.

Why this answer

Mandating a standardized risk assessment methodology ensures that all business units apply the same criteria, scales, and processes for identifying, analyzing, and evaluating risks. This eliminates methodological inconsistencies at the source, enabling the risk committee to produce truly comparable and reliable monitoring reports across the enterprise.

Exam trap

The trap here is that candidates confuse output consistency (templates, scales, or taxonomies) with input consistency (the methodology itself), leading them to choose options that only address surface-level uniformity rather than the root cause of inconsistent risk assessments.

How to eliminate wrong answers

Option B is wrong because aggregating risks using a common taxonomy only standardizes the classification of risks, not the underlying assessment methodology; different scoring and evaluation approaches would still produce incompatible results. Option C is wrong because requiring the same risk scoring scale does not address differences in how risks are identified, analyzed, or prioritized—two units using the same scale but different methodologies can still generate inconsistent risk levels for similar exposures. Option D is wrong because a centralized reporting template with predefined fields only standardizes the output format, not the input data or assessment process; if business units use different methodologies, the data entered into the template will remain inconsistent and non-comparable.

829
MCQeasy

A risk practitioner is preparing a risk register for a hospital's new telemedicine platform. During interviews, the CIO states that the platform's availability is critical because clinicians rely on it for urgent consultations. The practitioner needs to document how this business dependency influences risk identification. Which of the following BEST describes the role of business criticality in this context?

A.It establishes the potential business impact if the platform's availability is compromised.
B.It specifies the control framework that must be applied to protect the platform.
C.It determines the likelihood that a threat will exploit a vulnerability on the platform.
D.It defines the risk appetite threshold that the board must approve for the platform.
AnswerA

Business criticality directly informs impact. If clinicians depend on the telemedicine platform for urgent consultations, an availability event can delay care, harm patients, and trigger regulatory and reputational consequences. Documenting this dependency helps the practitioner assign a meaningful impact rating during risk identification, which then drives prioritization and response decisions.

Why this answer

Business criticality expresses how important an asset is to the organization and therefore drives the impact dimension of risk. For a telemedicine platform used in urgent consultations, an availability loss can affect patient safety, regulatory standing, and reputation. Documenting this dependency allows the practitioner to assign a defensible impact rating during identification, which supports later prioritization and response.

Exam trap

The trap here is conflating business criticality, which shapes impact, with likelihood or with governance decisions such as appetite and framework selection.

830
MCQmedium

A company is assessing the risk of a ransomware attack. The security team estimates the threat event frequency as 2 attacks per year, vulnerability as 0.3 (30% chance of success), primary loss as $500,000, and secondary loss as $200,000. What is the annualized loss expectancy (ALE) using the FAIR framework?

A.$420,000
B.$700,000
C.$210,000
D.$1,400,000
AnswerA

Multiplying threat event frequency (2) by vulnerability (0.3) gives a loss event frequency of 0.6 per year. Combining primary and secondary loss yields $700,000 per event. ALE is therefore 0.6 × $700,000 = $420,000, satisfying the FAIR requirement to annualise both loss magnitudes.

Why this answer

The FAIR framework calculates ALE as Threat Event Frequency × Vulnerability × (Primary Loss + Secondary Loss). Here, 2 × 0.3 × ($500,000 + $200,000) = 2 × 0.3 × $700,000 = $420,000. This correctly accounts for the probability of a successful attack and the total loss per incident.

Exam trap

The trap here is that candidates often forget to multiply by the vulnerability factor (0.3) or omit secondary loss, leading to answers like $700,000 or $1,400,000, which ignore the probabilistic nature of successful attacks.

How to eliminate wrong answers

Option B is wrong because it multiplies the total loss ($700,000) by the threat event frequency (2) without considering the vulnerability factor (0.3), yielding $1,400,000, then incorrectly halves it to $700,000. Option C is wrong because it multiplies only the primary loss ($500,000) by vulnerability (0.3) and threat frequency (2), ignoring secondary loss, giving $300,000, then incorrectly divides by 2 to get $210,000. Option D is wrong because it multiplies the total loss ($700,000) by the threat event frequency (2) without applying the vulnerability factor (0.3), resulting in $1,400,000, which overestimates the ALE by ignoring the 30% success probability.

831
MCQmedium

After a risk assessment, the risk owner determines that the residual risk is still above the risk appetite. Which of the following is the MOST appropriate next step?

A.Transfer the risk
B.Ignore the risk
C.Accept the risk
D.Implement additional controls
AnswerD

Residual risk exceeding risk appetite means existing controls are insufficient, so additional controls are needed to reduce risk to an acceptable level. Acceptance, avoidance or transfer would not bring the exposure within the defined tolerance.

Why this answer

When residual risk remains above the risk appetite after initial risk assessment, the most appropriate next step is to implement additional controls to further reduce the risk to an acceptable level. This aligns with the risk treatment process where controls are selected and applied to lower the likelihood or impact of the risk event. Simply transferring, ignoring, or accepting the risk without further action would not address the gap between residual risk and risk appetite.

Exam trap

ISACA often tests the misconception that risk acceptance is always the default next step, but the trap here is that acceptance is only valid when residual risk is within appetite; when it is above, additional controls must be considered first.

How to eliminate wrong answers

Option A is wrong because transferring the risk (e.g., via insurance or outsourcing) does not reduce the inherent risk; it only shifts financial consequences, and the residual risk may still exceed appetite if the transfer is incomplete or not cost-effective. Option B is wrong because ignoring the risk is a deliberate avoidance of responsibility and violates the risk management principle that risks above appetite must be treated, not neglected. Option C is wrong because accepting the risk without implementing additional controls is only appropriate if the residual risk is within the risk appetite; here it is above, so acceptance without further action would be non-compliant with policy.

832
MCQeasy

Based on the exhibit, which risk is MOST likely to be identified during a risk assessment?

A.Weak passwords on user workstations
B.Unauthorized physical access to the data center
C.Lateral movement risk from DMZ to internal network
D.Incomplete audit logs on firewalls
AnswerC

A compromised DMZ host with reachable internal routes lets an attacker pivot inward, exploiting weak segmentation between perimeter and trusted zones. This lateral movement risk is identified because DMZ systems rarely enforce the same internal access controls as core network segments.

Why this answer

The exhibit shows a DMZ architecture where the internal network is separated from the DMZ by a firewall. A risk assessment would identify the potential for an attacker who compromises a DMZ host (e.g., a web server) to pivot through the firewall to the internal network, especially if firewall rules are overly permissive or if the DMZ host has a trust relationship with internal systems. This lateral movement risk is a classic and high-priority finding in such segmented environments.

Exam trap

The trap here is that candidates often focus on obvious vulnerabilities like weak passwords or incomplete logs, but the CRISC exam tests the ability to identify the most significant risk given the architecture—lateral movement from a less trusted zone (DMZ) to a more trusted zone (internal network) is a classic and critical risk in segmented network designs.

How to eliminate wrong answers

Option A is wrong because weak passwords on user workstations are an endpoint security issue typically identified during vulnerability scans or security audits, not a primary risk in a DMZ-to-internal network architecture assessment. Option B is wrong because unauthorized physical access to the data center is a physical security risk that is assessed separately, often through site surveys or access control reviews, and is not directly indicated by the network topology in the exhibit. Option D is wrong because incomplete audit logs on firewalls are a logging and monitoring deficiency, not a direct risk of network traversal; while important, the exhibit's focus on DMZ segmentation points to lateral movement as the more immediate and architecture-specific risk.

833
MCQeasy

A risk assessment reveals a high inherent risk that is within the organization's risk appetite. The risk owner documents the risk and formally accepts it. This is an example of which risk treatment option?

A.Accept
B.Mitigate
C.Transfer
D.Avoid
AnswerA

Acceptance means acknowledging the risk and choosing to bear it without further treatment, which is valid when inherent risk falls within the organisation's stated risk appetite. The risk owner's documented, formal acceptance satisfies that treatment definition.

Why this answer

When a risk is within appetite, it may be formally accepted with sign-off.

834
MCQhard

During a risk assessment, an organization identifies that its legacy ERP system has a high likelihood of failure during peak transaction periods. The system supports critical financial operations. The risk owner proposes to upgrade the system, but the project would take 18 months and require significant capital investment. The CEO questions whether the risk can be reduced to an acceptable level more quickly. Which of the following is the MOST appropriate immediate risk response?

A.Implement enhanced monitoring and manual fallback procedures.
B.Increase cyber insurance coverage.
C.Accept the risk and budget for potential losses.
D.Outsource the ERP hosting to a cloud provider.
AnswerA

Enhanced monitoring plus manual fallback procedures reduce the impact of peak-period ERP failure immediately, without the 18-month upgrade. This satisfies the CEO's demand for a faster response by lowering residual risk to an acceptable level while the longer remediation is planned.

Why this answer

Enhanced monitoring and manual fallback procedures directly address the immediate risk of system failure during peak periods by providing early detection and a contingency plan to maintain critical financial operations. This response can be implemented quickly without the 18-month timeline and capital investment required for a full system upgrade, aligning with the CEO's request for a faster risk reduction.

Exam trap

The trap here is that candidates confuse a long-term strategic solution (system upgrade or cloud migration) with an immediate tactical response, failing to recognize that the question explicitly asks for the 'most appropriate immediate risk response' that can be deployed quickly.

How to eliminate wrong answers

Option B is wrong because cyber insurance coverage does not reduce the likelihood or impact of the ERP failure; it only provides financial compensation after a loss, which is not an immediate risk response. Option C is wrong because accepting the risk and budgeting for potential losses is a passive approach that does nothing to mitigate the high likelihood of failure during peak transactions, leaving critical financial operations exposed. Option D is wrong because outsourcing ERP hosting to a cloud provider involves significant migration effort, potential data residency issues, and contractual timelines that cannot be implemented immediately, and it does not address the legacy system's inherent instability during peak loads.

835
MCQmedium

A financial services firm is identifying risks for a new mobile banking feature that will rely on a third-party identity verification provider. The vendor has provided a SOC 2 Type II report, but the firm has not yet reviewed it. Which of the following BEST describes how the firm should treat the vendor-related risk during identification?

A.Record the vendor dependency as a risk and assess it after reviewing the report's scope, period, and exceptions.
B.Exclude vendor risk from the register because the SOC 2 Type II report demonstrates adequate controls.
C.Transfer the risk entirely to the vendor by referencing the SOC 2 report in the contract.
D.Defer identification until the vendor completes a penetration test of the identity verification platform.
AnswerA

Third-party dependencies are a recognized risk source that must appear in the risk register regardless of vendor assurances. Recording the dependency and then evaluating the SOC 2 Type II report's scope, coverage period, complementary user entity controls, and noted exceptions allows the firm to judge residual risk realistically. This keeps accountability with the firm while using vendor evidence to inform, not replace, its own risk assessment.

Why this answer

Third-party dependencies must be identified and recorded regardless of the assurance a vendor provides. The firm should log the dependency and then assess it using the SOC 2 Type II report's scope, coverage period, complementary user entity controls, and exceptions, so that residual risk is judged realistically. Assurance evidence informs the assessment; it does not remove the dependency from the register or transfer the firm's accountability.

Exam trap

The trap here is treating a SOC 2 Type II report as proof that vendor risk can be excluded from the register rather than as evidence that informs an assessment the firm still owns.

836
Multi-Selecteasy

A financial institution is implementing a new continuous monitoring solution for its transaction processing systems. The solution generates alerts for suspicious activities. Which TWO of the following are essential considerations when defining the alert thresholds?

Select 2 answers
A.Cost of the monitoring solution
B.Historical transaction patterns and baseline deviations
C.Vendor reputation for support
D.Number of employees in the monitoring team
E.The risk appetite of the organization
AnswersB, E

Baselining ensures thresholds reflect normal behavior.

Why this answer

Historical transaction patterns and baseline deviations (B) are essential because alert thresholds must be calibrated to normal behavior to minimize false positives and false negatives. Without understanding typical transaction volumes, values, and frequencies, the monitoring solution cannot distinguish legitimate activity from suspicious anomalies, rendering alerts meaningless.

Exam trap

The trap here is confusing operational or procurement factors (cost, vendor support, team size) with the risk-based, data-driven technical parameters that directly control alert generation.

837
MCQhard

A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?

A.Risk avoidance by decommissioning the system
B.Risk transfer through cyber insurance
C.Risk reduction by implementing redundant systems
D.Risk acceptance because mitigation is too costly
AnswerC

Redundant systems directly address the extreme downtime cost identified in the business impact analysis by eliminating single points of failure. Failover to a standby component maintains availability during hardware or service faults, reducing the probability and duration of outages. This satisfies the mitigation objective where downtime losses outweigh the cost of duplicate infrastructure.

Why this answer

Given the extremely high downtime costs, the most appropriate risk response is risk reduction through implementing redundant systems. This directly addresses the critical system's availability requirement by eliminating single points of failure, thereby reducing both the likelihood and impact of downtime. Decommissioning the system (avoidance) would eliminate the business function entirely, which is typically not viable for a critical system, while insurance (transfer) only provides financial compensation after the loss, not preventing the operational impact of downtime.

Exam trap

The trap here is that candidates may confuse risk transfer (insurance) as a primary solution for high downtime costs, overlooking that insurance does not prevent the operational impact and lost revenue during the outage itself, which is the core concern in this scenario.

How to eliminate wrong answers

Option A is wrong because risk avoidance by decommissioning the system would eliminate the business function that the critical system supports, which is typically not a viable strategy for a system deemed critical to operations. Option B is wrong because risk transfer through cyber insurance only provides financial reimbursement after a loss event, but does not prevent the extremely high operational downtime costs or the associated business disruption. Option D is wrong because risk acceptance is inappropriate when the business impact analysis shows that downtime costs are extremely high and a cost-effective mitigation (like redundancy) is available.

838
Multi-Selecthard

Which THREE of the following are key components of an effective risk treatment plan?

Select 3 answers
A.Assigned responsibilities
B.Risk acceptance criteria
C.A timeline for implementation
D.The risk owner's signature
E.A detailed budget
AnswersA, B, C

Clear ownership ensures accountability.

Why this answer

Assigned responsibilities are a key component of an effective risk treatment plan because they ensure accountability for implementing specific risk mitigation actions. Without clear ownership, tasks may be delayed or overlooked, undermining the plan's execution. This aligns with the CRISC framework's emphasis on defining roles to operationalize risk response.

Exam trap

The trap here is that candidates confuse supporting artifacts (like budgets or signatures) with the core structural components of the plan, which are defined by ISACA as responsibilities, timelines, and acceptance criteria.

839
Multi-Selectmedium

Which TWO of the following are examples of corrective controls?

Select 2 answers
A.Encryption of data at rest
B.Disaster recovery plan execution
C.Intrusion detection system
D.Backup restoration
E.Access control lists
AnswersB, D

Recovery after disaster is corrective.

Why this answer

Disaster recovery plan execution (B) is a corrective control because it is activated after a disruptive event to restore normal operations. It directly addresses the impact of an incident by executing predefined procedures to recover systems and data, thereby correcting the damage caused by the outage or disaster.

Exam trap

The trap here is that candidates often confuse detective controls (like IDS) with corrective controls, because they both involve monitoring or alerting, but corrective controls are specifically about taking action to fix or recover from an incident, not just detecting it.

840
MCQeasy

After a data breach has been contained, what is the most important action for identifying underlying IT risks?

A.Update the risk register
B.Perform a root cause analysis
C.Implement new security controls
D.Review cyber insurance policy
AnswerB

Root cause analysis traces the breach back to the specific control failures and process gaps that permitted it, exposing the underlying IT risks rather than merely the symptom. Containment addresses the immediate incident; only causal investigation reveals what must be remediated to prevent recurrence.

Why this answer

Root cause analysis systematically identifies the weaknesses that allowed the breach, directly contributing to risk identification. Updating the risk register, implementing controls, and reviewing insurance are subsequent steps.

841
Multi-Selectmedium

A risk analyst is reviewing the results of control testing for a critical business process. Which THREE of the following are valid reasons to classify a control as ineffective?

Select 3 answers
A.The control was not executed as per procedure.
B.The control failed during peak load testing.
C.The control design does not address the risk.
D.The control was tested once and passed.
E.The control owner was not available during the test.
AnswersA, B, C

Deviating from procedure compromises control effectiveness.

Why this answer

A control that is not executed as per its documented procedure indicates an operational failure. Even if the control design is sound, failure to follow the procedure means the control did not operate as intended, rendering it ineffective in mitigating the risk.

Exam trap

The trap here is that candidates may confuse a single successful test result with proof of ongoing effectiveness, or mistake an administrative issue (owner unavailability) for a control deficiency, when in fact the control's design and execution are what matter.

842
Drag & Dropmedium

Put the steps for performing a control self-assessment (CSA) in order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

CSA involves defining scope, identifying controls, assessing effectiveness, gap identification, and reporting.

843
MCQmedium

An internal audit report identifies that the IT department did not patch a critical vulnerability in a database server for 90 days. The risk manager wants to identify the root cause risk. Which approach should be used?

A.Interview the database system owner
B.Conduct a new vulnerability scan
C.Update the risk register with the finding
D.Perform a root cause analysis on the patching process
AnswerD

Root cause analysis traces the 90-day patching failure back to its underlying process breakdown, such as missing ownership or change-approval bottlenecks, rather than treating the symptom. This satisfies the risk manager's need to identify the root cause risk within the patching process itself.

Why this answer

The risk manager needs to identify the root cause risk, which requires understanding why the patching process failed to apply a critical security update within the required timeframe. A root cause analysis (RCA) on the patching process systematically examines procedural breakdowns, such as missed scanning cycles, lack of change management approval, or insufficient prioritization of database-specific patches (e.g., Oracle Critical Patch Updates). This approach directly addresses the underlying process deficiency rather than merely documenting or re-verifying the vulnerability.

Exam trap

The trap here is that candidates confuse operational remediation (e.g., rescanning or interviewing) with risk identification analysis, failing to recognize that the question specifically asks for identifying the root cause risk, not just confirming or logging the finding.

How to eliminate wrong answers

Option A is wrong because interviewing the database system owner may provide anecdotal context but does not systematically uncover the procedural or systemic failures in the patching lifecycle, such as scheduling gaps or approval bottlenecks. Option B is wrong because conducting a new vulnerability scan would only confirm the current state of the vulnerability (e.g., whether it is still present or remediated), not reveal why the patch was delayed for 90 days. Option C is wrong because updating the risk register with the finding is a documentation step that records the risk but does not analyze the causal factors behind the patching failure.

844
MCQhard

A risk practitioner is identifying risks for a pharmaceutical company that shares clinical trial data with external research partners. The practitioner learns that partners access the data through a shared portal with role-based access, and that one partner recently terminated its agreement but retained portal credentials. Which of the following is the MOST significant risk identification finding?

A.Clinical trial data is shared with external research partners at all.
B.The portal's role-based access model may not align with the principle of least privilege.
C.Terminated partners retain valid portal credentials after their agreements end.
D.The portal does not enforce multi-factor authentication for partner logins.
AnswerC

The confirmed fact that a former partner still holds working credentials is a concrete risk identification finding. It exposes clinical trial data to unauthorized access by an entity with no current contractual obligation. This orphaned access represents a real threat-to-asset path that must be documented, assessed, and remediated through timely deprovisioning controls.

Why this answer

The strongest finding is the confirmed existence of valid credentials held by a partner whose agreement has ended. That is a concrete threat-to-asset path affecting sensitive clinical trial data, and it must be documented and assessed. General concerns about role design, data sharing, or unstated authentication gaps are either design questions or unsupported assumptions compared with this active exposure.

Exam trap

The trap here is gravitating toward broad design concerns or unstated control gaps instead of the specific, confirmed exposure described in the scenario.

845
Multi-Selectmedium

Which THREE of the following are common business impact categories used in risk scenarios?

Select 3 answers
A.Reputational damage
B.Financial loss
C.Strategic misalignment
D.Regulatory penalty
E.Technical downtime
AnswersA, B, D

Reputational damage is a standard business impact category in risk scenarios, capturing loss of customer trust, brand value and market standing. It is assessed alongside financial, operational and regulatory impacts when quantifying the consequences of an IT risk event.

Why this answer

Reputational damage (A) is a standard business impact category because risk scenarios assess how incidents such as data breaches or outages harm customer trust, brand image, and market standing. Financial loss (B) is universally used in risk scenarios to quantify direct and indirect monetary effects like lost revenue, remediation costs, and reduced shareholder value. Regulatory penalty (D) is also a common business impact category, covering fines, sanctions, and legal enforcement actions imposed by bodies such as GDPR or HIPAA regulators when compliance obligations are breached.

Strategic misalignment (C) is not typically treated as a business impact category in risk scenarios; it is more of a governance or planning concern than a measurable consequence of a realized risk. Technical downtime (E) is an operational/technical effect or cause rather than a business impact category, since it is usually translated into business consequences such as financial loss or reputational damage.

Exam trap

CRISC often tests the distinction between business impact categories and technical or strategic-level factors, tempting candidates to select operational issues like technical downtime or strategic misalignment as impact categories.

846
Multi-Selecthard

During an IT risk assessment, a risk owner has identified a risk with a high inherent risk score. After reviewing control effectiveness, the residual risk remains medium. The organization decides to accept the residual risk. Which TWO of the following actions should the risk owner take?

Select 2 answers
A.Transfer the risk to a third party
B.Eliminate the activity that creates the risk
C.Obtain sign-off from the risk owner
D.Implement additional controls to reduce risk further
E.Document the risk acceptance formally
AnswersC, E

The risk owner must formally approve acceptance.

Why this answer

The risk owner must formally acknowledge and accept the residual risk after the decision to accept has been made. This sign-off demonstrates that the risk owner is aware of the remaining exposure and agrees to the risk acceptance, which is a key governance step in the risk management process. Without this sign-off, the acceptance is not formally recognized, and accountability remains unclear.

Exam trap

The trap here is that candidates may confuse risk acceptance with other risk treatment options (transfer, avoid, mitigate) and fail to recognize that after deciding to accept, the key actions are formal sign-off and documentation, not further risk reduction or transfer.

847
MCQhard

An organization has a risk appetite statement that says 'We accept up to $5 million in operational losses per year.' However, a new cloud migration project is estimated to have a potential operational loss of $8 million if a critical failure occurs. The risk capacity of the organization is $20 million. What should the risk practitioner recommend?

A.Reject the project because the risk exceeds the risk appetite
B.Implement risk treatment measures to reduce the potential loss to below $5 million
C.Increase the risk appetite to $8 million to align with the project
D.Accept the risk because the risk capacity is $20 million
AnswerB

The $8 million exposure breaches the stated $5 million risk appetite, though it remains within the $20 million risk capacity. Treatment is required to bring the loss below the appetite threshold; merely accepting it would exceed the tolerance the organisation has formally set.

Why this answer

The risk appetite statement sets a clear threshold of $5 million in acceptable operational losses per year. The project's potential loss of $8 million exceeds this appetite, so the risk practitioner should recommend risk treatment measures to bring the potential loss within the appetite. This aligns with the risk management principle of modifying risk to align with organizational risk tolerance before accepting or rejecting a project outright.

Exam trap

CRISC often tests the distinction between risk appetite and risk capacity, and candidates may incorrectly choose to accept the risk because it is within capacity, or reject the project without considering risk treatment.

How to eliminate wrong answers

Option A is wrong because rejecting the project outright is premature; risk treatment can reduce the loss to an acceptable level, allowing the project to proceed with mitigated risk. Option C is wrong because risk appetite is set by senior management and should not be arbitrarily increased to accommodate a single project; doing so undermines the risk governance framework. Option D is wrong because risk capacity ($20 million) represents the maximum loss the organization can withstand, not the acceptable level of risk; accepting the risk would still violate the risk appetite.

848
MCQhard

A Key Control Indicator (KCI) for a critical firewall rule set shows an exception rate of 12% over the past month, exceeding the acceptable threshold of 5%. The control owner is responsible for remediation. Which action should the risk practitioner recommend FIRST?

A.Temporarily disable the firewall rules causing exceptions
B.Implement an automated rule change management process
C.Update the KCI threshold to 12%
D.Conduct a root cause analysis of the exceptions
AnswerD

Root cause analysis identifies why exceptions exceeded the 5% threshold before remediation is chosen. Acting on symptoms risks recurring breaches, so understanding whether the cause is rule misconfiguration, process drift or user behaviour ensures the control owner applies the correct corrective action first.

Why this answer

The first step in addressing an elevated KCI is to investigate the root cause of the exceptions to determine if they are due to rule misconfigurations, policy violations, or other issues before taking corrective action.

849
Multi-Selectmedium

Which TWO of the following are primary sources of IT risk identification? (Select exactly TWO.)

Select 2 answers
A.Incident reports
B.Threat intelligence feeds
C.Asset inventory
D.Risk appetite
E.Policy documents
AnswersA, B

Incident reports document past events and vulnerabilities, revealing risks that materialized.

Why this answer

Incident reports are a primary source of IT risk identification because they provide direct evidence of past security events, such as malware infections, unauthorized access attempts, or system failures. By analyzing incident reports, risk practitioners can identify patterns, root causes, and control weaknesses that represent current or emerging risks. This historical data is essential for updating the risk register and prioritizing remediation efforts based on actual impact.

Exam trap

The trap here is that candidates often mistake asset inventory (a passive inventory list) as a primary risk identification source, when in fact it is a prerequisite for risk assessment but does not itself identify risks; the exam expects you to distinguish between inputs for risk assessment and sources that actively reveal risk events.

850
MCQmedium

During a risk assessment for a new financial application, the risk manager identifies that the application processes sensitive customer data and is accessible from the internet. Which of the following is the MOST appropriate risk scenario to document?

A.The application has several unpatched vulnerabilities that increase the likelihood of a security incident.
B.The application will implement multi-factor authentication to prevent unauthorized access.
C.An attacker could exploit weak authentication mechanisms to gain unauthorized access and exfiltrate customer data, resulting in regulatory fines and reputational damage.
D.The application must comply with PCI DSS requirements for data protection.
AnswerC

This scenario names the asset, threat vector, exploited weakness, and business impact — internet-facing weak authentication leading to exfiltration, fines, and reputational damage. That structure satisfies risk scenario documentation requirements better than generic vulnerability statements.

Why this answer

The most appropriate risk scenario because it follows the standard risk scenario structure: threat (attacker), vulnerability (weak authentication), impact (unauthorized access, data exfiltration, regulatory fines, reputational damage). It directly ties the technical weakness to a business consequence, which is essential for communicating risk to stakeholders. The scenario is specific to the application's internet-facing nature and sensitive data processing, making it actionable for risk treatment.

Exam trap

The trap here is that candidates mistake a vulnerability or a control for a complete risk scenario, failing to include the threat actor and business impact that are required for proper risk identification.

How to eliminate wrong answers

Option A is wrong because it describes a vulnerability (unpatched flaws) without specifying a threat actor, attack vector, or business impact; it is a risk factor, not a complete risk scenario. Option B is wrong because it describes a control (multi-factor authentication) that would mitigate risk, not a risk scenario itself; it confuses a solution with the problem statement. Option D is wrong because it states a compliance requirement (PCI DSS) without linking it to a specific threat, vulnerability, or adverse outcome; it is a control objective, not a risk scenario.

851
MCQmedium

A risk practitioner at a regional bank is building a risk register entry for the loss of a critical core banking application. The head of IT operations insists on recording a single, point-in-time likelihood estimate of 15% derived from last year's incident log, and refuses to consider any range. Which CRISC-aligned principle should the practitioner apply to MOST appropriately represent this IT risk?

A.Replace the likelihood figure with the industry average downtime for comparable core banking platforms.
B.Escalate the disagreement to the board and let it decide whether the 15% figure is acceptable.
C.Multiply the 15% likelihood by the maximum credible loss to obtain a single annualized loss expectancy.
D.Model likelihood and impact as distributions reflecting uncertainty around the estimates.
AnswerD

Risk is inherently uncertain, so a single point estimate overstates precision. Representing likelihood and impact as distributions captures the range of plausible outcomes and lets the bank compare exposures and set tolerances realistically. This aligns with IT risk analysis principles where frequency and magnitude are estimated with ranges, and it gives decision makers visibility into tail scenarios rather than a false sense of accuracy.

Why this answer

Expressing likelihood and impact as distributions acknowledges that estimates carry uncertainty, which is central to sound IT risk analysis. A point estimate of 15% implies false precision and hides tail risk that could threaten the core banking service. Distributions let the bank compare risk against tolerance, prioritize controls, and communicate exposure honestly to stakeholders without overstating confidence in a single number.

Exam trap

The trap here is assuming that a precise-looking percentage from historical logs is inherently more defensible than a range, when in fact it conceals the uncertainty that risk analysis exists to surface.

852
Multi-Selecthard

A risk assessment identifies a high likelihood of a data breach due to insecure APIs. The risk team proposes disabling the APIs until they are secured, implementing a WAF, and purchasing breach insurance. Which THREE risk response options are being considered?

Select 3 answers
A.Remediate
B.Transfer
C.Avoid
D.Mitigate
E.Accept
AnswersB, C, D

Insurance transfers the financial impact.

Why this answer

(Transfer) is correct because purchasing breach insurance transfers the financial risk of a data breach to an insurance provider. Option C (Avoid) is correct because disabling the APIs until they are secured eliminates the risk entirely by removing the vulnerable component. Option D (Mitigate) is correct because implementing a Web Application Firewall (WAF) reduces the likelihood or impact of an API-based attack without removing the API.

Exam trap

A common trap in CRISC is confusing 'remediate' (fixing the root cause) with 'mitigate' (reducing risk without eliminating the cause). Implementing a WAF is a mitigation, not remediation, because the API remains vulnerable at its core.

853
MCQhard

A healthcare organization is required by regulation to retain patient records for seven years. The risk manager is evaluating a new cloud storage solution that offers encryption at rest but stores data in multiple jurisdictions. Which of the following is the MOST critical risk consideration when selecting this solution?

A.The encryption algorithm used by the cloud provider
B.The availability of the cloud service and its uptime guarantees
C.The physical security of the cloud provider's data centers
D.The legal and regulatory requirements for data residency in each jurisdiction
AnswerD

Healthcare data is subject to strict privacy laws that may prohibit storage in certain jurisdictions or require specific safeguards for cross-border transfers. Storing data in multiple jurisdictions could violate these laws, leading to fines and reputational damage. Therefore, understanding and complying with data residency requirements is the most critical risk consideration.

Why this answer

For a healthcare organization, regulatory compliance is paramount. Storing patient records in multiple jurisdictions can breach data residency laws, resulting in severe penalties. While encryption, physical security, and availability are relevant, they do not address the legal risk of unauthorized cross-border data storage.

The risk manager must prioritize compliance with data residency requirements before other technical controls.

Exam trap

The trap here is focusing on technical controls like encryption or physical security while overlooking the legal and regulatory implications of data residency, which can invalidate the entire solution.

854
MCQeasy

Which COBIT 2019 governance objective focuses on ensuring that the enterprise's risk appetite and tolerance are understood, articulated, and communicated, and that risk is managed appropriately?

A.EDM04 — Ensure Resource Optimization
B.EDM03 — Ensure Risk Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM01 — Ensure Governance Framework Setting and Maintenance
AnswerB

EDM03 governs risk by setting appetite and tolerance, then directing risk management across the enterprise. The stem requires an objective covering articulation and communication of risk appetite plus appropriate treatment, which is precisely EDM03's remit within the Evaluate, Direct and Monitor domain.

Why this answer

EDM03 — Ensure Risk Optimization is the COBIT 2019 governance objective specifically designed to ensure that the enterprise's risk appetite and risk tolerance are defined, communicated, and understood, and that risk is managed within those boundaries. It focuses on aligning risk management with enterprise objectives and ensuring that residual risk is acceptable.

Exam trap

The trap here is that candidates often confuse 'risk optimization' (EDM03) with 'resource optimization' (EDM04) because both terms include 'optimization,' but EDM03 is the only one that explicitly addresses risk appetite, tolerance, and management.

How to eliminate wrong answers

Option A is wrong because EDM04 — Ensure Resource Optimization focuses on managing IT resources (applications, information, infrastructure, people) efficiently and effectively, not on risk appetite or tolerance. Option C is wrong because EDM02 — Ensure Benefits Delivery is concerned with optimizing value from IT-enabled investments and services, not with risk management. Option D is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance deals with establishing and maintaining the governance framework (structures, principles, processes), not directly with risk appetite articulation or risk management.

855
MCQhard

After implementing controls, the risk remaining is called:

A.Control risk
B.Acceptable risk
C.Residual risk
D.Inherent risk
AnswerC

Residual risk is the exposure that remains after controls have been implemented and inherent risk has been mitigated. It represents the gap between total risk and the effect of existing controls, which is precisely what the question describes following control implementation.

Why this answer

Residual risk is the risk that remains after controls have been implemented to mitigate the original (inherent) risk. It represents the exposure the organization still carries and must consciously accept, transfer, or further mitigate. This is a core CRISC definition tested repeatedly.

Exam trap

CRISC often tests the distinction between residual risk (remaining after controls) and acceptable risk (the threshold the organization tolerates) — candidates pick 'acceptable risk' because it sounds like the endpoint, but the question asks for the remaining risk itself.

How to eliminate wrong answers

Option A is wrong because 'control risk' is not a standard CRISC term for post-control residual exposure — control risk typically refers to the risk that a control fails to prevent or detect an error, which is a component of audit risk, not the remaining risk after controls. Option B is wrong because 'acceptable risk' (or risk tolerance/appetite) is the threshold of risk the organization is willing to accept, not the actual remaining risk itself; residual risk may be above or below the acceptable threshold. Option D is wrong because inherent risk is the risk before controls are applied, which is the opposite of what the question asks.

856
MCQmedium

A company uses a third-party vendor to process customer data. The vendor's security control monitoring reports show no issues. However, the company's internal monitoring detects anomalies in vendor response times. What is the BEST interpretation?

A.The vendor's monitoring is accurate; the anomalies are false positives.
B.The anomalies may indicate a control gap in the vendor's environment.
C.The internal monitoring should be disabled to avoid confusion.
D.The vendor's monitoring is more reliable than internal monitoring.
AnswerB

Vendor self-reported monitoring can miss degradation that only manifests externally, so response-time anomalies suggest an undetected control weakness rather than proof of compliance. This interpretation satisfies the stem's requirement to reconcile clean vendor reports against the company's own observed evidence.

Why this answer

The discrepancy between the vendor's security monitoring reports (showing no issues) and the company's internal monitoring (detecting anomalies in response times) suggests a potential control gap in the vendor's environment. Response time anomalies can indicate underlying security issues such as resource exhaustion, data exfiltration, or compromised systems that the vendor's monitoring may not be capturing. This misalignment warrants further investigation rather than dismissal.

Exam trap

The trap here is that candidates may assume vendor monitoring reports are authoritative and dismiss internal anomalies as false positives, failing to recognize that independent monitoring is a critical control for detecting gaps in third-party security.

How to eliminate wrong answers

Option A is wrong because dismissing anomalies as false positives without investigation is a risky assumption; response time anomalies can be early indicators of security incidents like DDoS attacks or unauthorized data transfers. Option C is wrong because disabling internal monitoring would eliminate a valuable independent verification layer, violating the principle of defense in depth and reducing visibility into vendor performance and security. Option D is wrong because vendor monitoring reports are not inherently more reliable; they may lack coverage of certain metrics (e.g., response time) or be subject to reporting biases, and internal monitoring provides a necessary cross-check.

857
MCQeasy

When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?

A.Shared responsibility model misunderstandings
B.Data may be stored in jurisdictions with different privacy laws
C.Multi-tenancy isolation gaps
D.Vendor lock-in due to proprietary APIs
AnswerB

Data sovereignty concerns arise because cloud providers may replicate or store data in jurisdictions whose privacy laws differ from the organisation's own, potentially breaching regulatory obligations. This legal exposure, not encryption or availability, is the key risk when assessing cloud computing.

Why this answer

Data sovereignty is a key concern in cloud computing risk because data may be stored in jurisdictions with different privacy laws. This means that data could be subject to legal requirements that conflict with the organization's own compliance obligations, such as GDPR or HIPAA.

Exam trap

The trap is confusing data sovereignty with other cloud risks like shared responsibility or multi-tenancy; candidates must focus on the legal jurisdiction aspect.

How to eliminate wrong answers

Option A is wrong because shared responsibility model misunderstandings relate to security responsibilities, not specifically data sovereignty. Option C is wrong because multi-tenancy isolation gaps are a security concern, not a legal jurisdiction issue. Option D is wrong because vendor lock-in is a strategic risk, not directly about data sovereignty.

858
MCQhard

A multinational corporation is assessing the risk of non-compliance with GDPR. Which of the following is the BEST approach to quantify the potential fine?

A.Base the estimate on the organization's annual global turnover
B.Estimate based on the cost of cyber insurance premiums
C.Calculate the cost of data breach using the Ponemon Institute model
D.Use industry benchmarks for data breach costs
AnswerA

GDPR Article 83 sets fines at up to 4% of total worldwide annual turnover or EUR 20 million, whichever is higher. Basing the estimate on global turnover directly reflects this statutory formula, giving a defensible quantified maximum exposure.

Why this answer

Under GDPR, the maximum fine for non-compliance is the greater of €20 million or 4% of the organization's annual global turnover. Therefore, basing the estimate on annual global turnover directly aligns with the regulatory formula used by supervisory authorities, making it the most accurate and defensible quantification approach for potential fines.

Exam trap

ISACA often tests the distinction between regulatory fines (which follow a fixed statutory formula) and broader breach costs (which include operational, reputational, and legal expenses), leading candidates to mistakenly select a comprehensive cost model like Ponemon instead of the turnover-based regulatory calculation.

How to eliminate wrong answers

Option B is wrong because cyber insurance premiums reflect market pricing for risk transfer, not the statutory penalty calculation defined in GDPR Article 83. Option C is wrong because the Ponemon Institute model estimates the total cost of a data breach (including detection, notification, and lost business), not the regulatory fine specifically. Option D is wrong because industry benchmarks for data breach costs are averages across sectors and do not incorporate the organization-specific turnover figure that GDPR mandates for fine calculation.

859
MCQmedium

An organization is implementing a new access control system to protect sensitive data. Which type of control is most appropriate for preventing unauthorized access?

A.Detective control
B.Preventive control
C.Corrective control
D.Compensating control
AnswerB

Preventive controls stop unauthorised access attempts before they succeed, directly satisfying the stem's requirement to prevent rather than merely detect or correct. Authentication, authorisation and encryption mechanisms block intrusion at the point of entry, unlike detective controls that only reveal breaches after the fact.

Why this answer

A preventive control is designed to stop unauthorized access from occurring in the first place, which is exactly what an access control system does — it enforces authentication and authorization before granting access to sensitive data. Preventive controls are the primary defense against unauthorized access because they act before the security event occurs. This is the most appropriate control type for the stated objective.

Exam trap

CRISC often tests the preventive vs. detective distinction — candidates pick detective because access control systems generate logs, but the primary purpose of an access control system is to prevent unauthorized access, not to detect it after the fact.

How to eliminate wrong answers

Option A is wrong because a detective control identifies unauthorized access after it has occurred (e.g., IDS, audit logs, SIEM alerts) — it does not prevent access, only detects it. Option C is wrong because a corrective control remediates damage or restores systems after an incident (e.g., backups, patch management, incident response) — it operates after the fact, not before. Option D is wrong because a compensating control is an alternative measure used when a primary control cannot be implemented (e.g., compensating for a missing encryption control with network segmentation); it is not the primary control type for preventing unauthorized access.

860
MCQmedium

A company is evaluating controls for a high-risk process. Which control type is designed to stop a risk event from occurring?

A.Preventive
B.Detective
C.Corrective
D.Compensating
AnswerA

Preventive controls act before or during an event to stop it occurring, such as segregation of duties or access restrictions. Detective and corrective controls instead identify or remediate events after the fact, so they do not satisfy this requirement.

Why this answer

A preventive control is designed to stop a risk event from occurring by implementing barriers or safeguards before the event can happen. For a high-risk process, this might include access control lists (ACLs) on a firewall that block unauthorized traffic, or input validation routines in an application that reject malformed data before it can trigger a buffer overflow. By proactively eliminating the threat vector, preventive controls reduce the likelihood of the risk event to zero for the protected path.

Exam trap

A common pitfall in CRISC is confusing preventive controls with detective controls. For example, a candidate might see a control that identifies a threat (e.g., an IDS alert) and mistakenly classify it as preventive, when in fact it only detects the event after it has begun.

How to eliminate wrong answers

Option B is wrong because detective controls, such as intrusion detection systems (IDS) or log monitoring, only identify that a risk event has occurred or is in progress; they do not prevent it. Option C is wrong because corrective controls, like restoring from a backup after a ransomware attack or applying a patch to fix a vulnerability, are activated after the risk event has already happened to restore normal operations. Option D is wrong because compensating controls, such as using a web application firewall (WAF) as an alternative when a required preventive control (e.g., secure coding) cannot be implemented, provide an alternative measure but are not designed to stop the risk event from occurring in the first place; they are a fallback, not a primary prevention mechanism.

861
MCQhard

A company's key risk indicator (KRI) for 'failed login attempts' has exceeded its threshold by 20%. The control owner reports that a recent firewall change caused false positives. What should the risk practitioner do FIRST?

A.Validate the KRI data and investigate the root cause
B.Implement additional controls to reduce failed logins
C.Revert the firewall change immediately
D.Increase the KRI threshold to eliminate false positives
AnswerA

The firewall change is a plausible alternative cause, so the KRI value itself may be unreliable. Validating the data and tracing the root cause establishes whether the threshold breach is genuine before escalating, avoiding wasted response effort on a false positive.

Why this answer

The first step in risk management is to validate the data and understand the root cause before taking action. A KRI exceeding its threshold may be due to false positives from a firewall change, so the practitioner must confirm whether the alert is genuine. Investigating the root cause ensures that any response is based on accurate information and addresses the actual issue, rather than reacting to a symptom.

Exam trap

CRISC often tests the tendency to jump to corrective actions before validating the data, but the correct first step is always to investigate and confirm the root cause.

How to eliminate wrong answers

Option B is wrong because implementing additional controls before validating the KRI could lead to unnecessary changes and does not address the root cause. Option C is wrong because reverting the firewall change immediately is a reactive action that may not be necessary if the KRI is a false positive, and it could introduce other risks. Option D is wrong because increasing the threshold to eliminate false positives is a dangerous practice that masks potential real issues and undermines the purpose of the KRI.

862
Multi-Selecthard

A third-party vendor is classified as high risk due to its access to sensitive data. Which THREE activities should be part of ongoing monitoring for this vendor?

Select 3 answers
A.Contract compliance reviews to ensure terms are met.
B.Requiring SOC 2 Type II certification before contract signing.
C.Continuous monitoring via shared threat intelligence platforms.
D.Annual reassessment of the vendor's security posture.
E.Initial onboarding security questionnaire review.
AnswersA, C, D

Contract compliance reviews verify the vendor still meets agreed security, privacy and service terms, directly addressing the sensitive-data access that makes this vendor high risk. Reviews detect drift from contractual obligations before it becomes a reportable exposure.

Why this answer

Option A is correct because ongoing monitoring for a high-risk vendor must include contract compliance reviews, which verify that the vendor continues to meet agreed security, privacy, and service-level terms throughout the relationship, not just at signing. Option C is correct because continuous monitoring via shared threat intelligence platforms provides real-time visibility into emerging threats, indicators of compromise, and the vendor's security posture, which is essential for a vendor with access to sensitive data. Option D is correct because annual reassessment of the vendor's security posture is a recurring due-diligence activity that re-evaluates controls, risk ratings, and changes in the vendor's environment over time.

Option B is not part of ongoing monitoring because requiring SOC 2 Type II certification is a pre-contract due-diligence step performed before signing, not a continuous monitoring activity. Option E is also not ongoing monitoring because the initial onboarding security questionnaire review occurs only at the start of the relationship and does not provide continuous oversight.

Exam trap

The trap here is confusing pre-contract due diligence activities (like SOC 2 certification or initial questionnaires) with ongoing monitoring activities, leading candidates to select options that are valid but belong to a different phase of the vendor risk management lifecycle.

863
MCQhard

A company is implementing a new cloud-based customer relationship management (CRM) system. The risk manager has identified that the vendor's security controls may not meet the company's requirements. Which of the following is the BEST way to address this risk?

A.Deny the existence of the risk
B.Purchase cyber insurance to cover potential losses
C.Avoid using the cloud CRM system
D.Include security requirements in the contract and perform regular vendor audits
AnswerD

Contractual security requirements establish enforceable vendor obligations, and regular audits verify ongoing compliance with those controls. This addresses the identified gap between the vendor's controls and the company's requirements through both preventive and detective measures.

Why this answer

The best way to address the risk that a vendor's security controls may not meet requirements is to include explicit security requirements in the contract and perform regular vendor audits. This contractual and assurance-based approach directly mitigates the risk by establishing enforceable obligations and ongoing verification. It aligns with risk management principles of treating risk through controls and monitoring rather than ignoring, transferring, or eliminating the business capability.

Exam trap

CRISC often tests the misconception that transferring risk via insurance is always the best answer, when in fact addressing the root cause through contractual controls and assurance is typically the preferred risk treatment.

How to eliminate wrong answers

Option A is wrong because denying the existence of a risk is not a valid risk response; it leaves the organization exposed and violates risk management fundamentals. Option B is wrong because purchasing cyber insurance transfers some financial impact but does not address the root cause of inadequate vendor security controls, and it does not ensure compliance with requirements. Option C is wrong because avoiding the cloud CRM system entirely may be an overreaction that eliminates business benefits; risk avoidance is only appropriate when the risk is unacceptable and no other treatment is feasible, which is not stated here.

864
MCQmedium

A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?

A.Investigate the root cause of the high exception rate
B.Increase the acceptable threshold to 20%
C.Replace the control with a different one
D.Escalate to the board immediately
AnswerA

A 15% exception rate signals the control is failing beyond tolerance, so the control owner must first determine why exceptions occur before remediating. Root-cause investigation identifies whether the issue is rule design, process adherence or tooling, informing corrective action.

Why this answer

A KCI exception rate exceeding the threshold indicates a process failure, not necessarily a control failure. The control owner must first perform root cause analysis to determine whether the exceptions are due to misconfigured rules, policy violations, or environmental changes before taking corrective action. This aligns with the CRISC principle that control owners are responsible for monitoring and improving control effectiveness through investigation.

Exam trap

ISACA often tests the misconception that exceeding a KCI threshold automatically requires escalation or control replacement, when in fact the immediate step is always root cause analysis to determine if the threshold breach is a temporary anomaly or a systemic issue.

How to eliminate wrong answers

Option B is wrong because arbitrarily increasing the threshold to 20% masks the underlying issue and violates the principle of maintaining risk appetite; thresholds should be based on risk tolerance, not adjusted to avoid alarms. Option C is wrong because replacing the control without understanding why exceptions occurred is premature and could introduce new risks; the existing control may be effective if the root cause is addressed. Option D is wrong because escalation to the board is reserved for material risk events or control failures that exceed the risk appetite after investigation; a 15% exception rate does not warrant board-level escalation as an immediate action.

865
Multi-Selecthard

An IT risk manager is developing KRIs for a critical application. Which TWO of the following are leading indicators that the risk level may be increasing? (Select TWO)

Select 2 answers
A.Average patch lag time increasing
B.Failed authentication spike
C.Audit findings of control deficiencies
D.Number of successful intrusions
E.Number of security incidents in the past month
AnswersA, B

Patch lag measures exposure duration before remediation, so lengthening lag signals accumulating unpatched vulnerabilities and rising likelihood of exploitation. It is a leading indicator because it predicts future incidents rather than reporting past losses, satisfying the KRI requirement for forward-looking risk trend data.

Why this answer

Option A (Average patch lag time increasing) is correct because a growing delay between patch release and deployment is a leading indicator: it signals accumulating unpatched vulnerabilities and weakening patch management before any exploit or incident occurs. Option B (Failed authentication spike) is correct because a sudden rise in failed logons is a leading indicator of credential-stuffing, brute-force, or password-spraying activity, which precedes a potential account compromise. Option C is a lagging indicator because audit findings document control deficiencies that already exist, reflecting past state rather than predicting future risk increase.

Option D is a lagging indicator since successful intrusions are realized events that have already occurred. Option E is also lagging because counting past security incidents measures historical impact, not forward-looking risk trajectory.

Exam trap

CRISC often tests the distinction between leading and lagging indicators, and candidates frequently select incident counts or audit findings because they sound risk-related, missing that these are backward-looking outcomes rather than predictive signals.

866
MCQhard

A hospital's risk team is assessing a clinical imaging archive. The team determines that a ransomware event would encrypt the archive and disrupt diagnostic services, with an estimated single-loss magnitude of $2,000,000. Existing controls reduce the likelihood of a successful attack to an estimated 0.4 occurrences per year. What is the annualized loss expectancy (ALE) for this risk?

A.$2,000,000
B.$2,400,000
C.$5,000,000
D.$800,000
AnswerD

This is correct because ALE equals single loss expectancy multiplied by annualized rate of occurrence. With a single-loss magnitude of $2,000,000 and an annualized rate of 0.4, the calculation is $2,000,000 × 0.4 = $800,000. This represents the expected average annual loss from ransomware affecting the clinical imaging archive given the stated control effectiveness.

Why this answer

Annualized loss expectancy is the product of the loss from a single event and the estimated number of such events per year. Multiplying the $2,000,000 single-loss magnitude by the 0.4 annualized rate of occurrence yields an expected average annual loss of $800,000, which the hospital can use to compare against the cost of additional ransomware controls.

Exam trap

The trap here is confusing single loss expectancy with annualized loss expectancy, or dividing the loss by the frequency instead of multiplying.

867
Multi-Selectmedium

A risk practitioner is designing a risk report for the board of directors. Which TWO content elements are most appropriate for strategic risk reporting? (Select two.)

Select 2 answers
A.Trend analysis of top key risk indicators
B.List of all control deficiencies
C.Names of employees who failed phishing tests
D.Risk heat map showing overall risk exposure
E.Detailed log analysis results
AnswersA, D

Board-level strategic reporting requires forward-looking insight, and trend analysis of top key risk indicators shows whether exposure is rising or falling against appetite over time, enabling directors to govern direction rather than review past operational detail.

Why this answer

Option A (Trend analysis of top key risk indicators) is correct because the board needs a forward-looking, aggregated view of how the organization's most significant risks are changing over time, and KRIs distilled to the top risks give directors the directional insight required for strategic oversight rather than operational detail. Option D (Risk heat map showing overall risk exposure) is correct because a heat map aggregates likelihood and impact across the enterprise into a single visual that lets the board quickly grasp the overall risk profile and prioritize where to focus governance attention. The remaining options do not belong at the strategic level: B (List of all control deficiencies) is an exhaustive operational/audit artifact better suited to management or the audit committee, C (Names of employees who failed phishing tests) is personally identifiable, tactical HR/security data inappropriate for board reporting, and E (Detailed log analysis results) is raw technical data that belongs to IT operations or security teams, not strategic risk reporting.

Exam trap

The trap here is that candidates confuse operational reporting details (like control deficiencies or phishing test results) with strategic-level content, failing to recognize that the board requires aggregated, decision-useful summaries rather than granular data.

868
MCQmedium

A bank is identifying IT risks and categorizes a potential data breach as both a compliance risk (due to GDPR) and a reputational risk. This is an example of:

A.Multiple risk categories for a single risk
B.Risk aggregation
C.Improper risk classification
D.Risk scenario overlap
AnswerA

A single data breach event is being recorded against two distinct risk taxonomies simultaneously: regulatory compliance under GDPR and reputational damage. That dual tagging demonstrates one risk mapping to multiple categories, not separate risks or a single classification.

Why this answer

A single risk can belong to multiple categories; this is normal in risk categorization.

869
MCQhard

During a risk assessment, the risk manager finds that a critical application has a single point of failure in its network path. The application's availability requirement is 99.99%. The current design achieves only 99.9% uptime. Which risk metric should be calculated first?

A.Annualized Loss Expectancy (ALE) based on potential downtime cost.
B.Risk gap between required and current service level.
C.Exposure factor (EF) representing the percentage of loss.
D.Single loss expectancy (SLE) for a single outage event.
AnswerB

The gap quantifies the shortfall between the 99.99% availability requirement and the 99.9% design, expressing exposure in service-level terms. Calculating it first frames how much improvement the single point of failure must deliver before treatment options are assessed.

Why this answer

The risk manager must first quantify the risk gap between the required 99.99% availability (approximately 52.56 minutes of downtime per year) and the current 99.9% availability (approximately 525.6 minutes per year). This gap of 473.04 minutes per year establishes the magnitude of the risk exposure before any financial calculations (ALE, SLE, EF) can be performed, as those metrics depend on knowing the actual downtime that needs to be costed.

Exam trap

The trap here is that candidates rush to calculate financial metrics (ALE, SLE, EF) without first establishing the foundational risk gap, which is the prerequisite for any meaningful quantitative risk analysis.

How to eliminate wrong answers

Option A is wrong because Annualized Loss Expectancy (ALE) requires the annual rate of occurrence (ARO) and single loss expectancy (SLE), which themselves depend on knowing the risk gap first; calculating ALE without the gap would use incorrect downtime figures. Option C is wrong because Exposure Factor (EF) is a percentage of asset value lost per incident, but the question asks for the first metric to calculate, and EF is derived after the risk gap is understood. Option D is wrong because Single Loss Expectancy (SLE) is calculated as asset value × exposure factor, and without first establishing the risk gap (the actual downtime difference), the SLE would be based on the wrong outage duration.

870
MCQhard

A risk analyst is assessing a critical application's inherent risk. After implementing controls, the residual risk is calculated as high. The analyst determines that the control design is adequate but operating effectiveness is poor. Which factor most likely explains the high residual risk?

A.Control design is inadequate
B.Control operating effectiveness is poor
C.Risk appetite was misstated
D.Inherent risk is too low
AnswerB

Residual risk reflects inherent risk after controls operate, not merely after they are designed. Adequate design with poor operating effectiveness means controls fail to mitigate in practise, so the high residual risk is explained by ineffective operation rather than design weakness.

Why this answer

Residual risk is the risk remaining after controls are applied, and it is a function of both control design and control operating effectiveness. The scenario explicitly states the design is adequate but operating effectiveness is poor, meaning the controls exist on paper but are not functioning as intended in practice. Poor operating effectiveness therefore leaves the original inherent risk largely unmitigated, producing a high residual risk despite good design.

Exam trap

The trap here is conflating control design with control operating effectiveness; candidates see 'adequate design' and assume the control must be working, overlooking that a well-designed control can still fail in operation and leave residual risk high.

How to eliminate wrong answers

Option A is wrong because the scenario explicitly states the control design is adequate, so inadequate design cannot be the cause of the high residual risk. Option C is wrong because risk appetite is a governance threshold for how much risk an organization is willing to accept; a misstated appetite would not change the calculated residual risk level itself. Option D is wrong because inherent risk being too low would tend to produce a lower, not higher, residual risk, and it contradicts the premise that the application is critical.

871
MCQhard

A software company has completed a risk assessment showing that a critical SaaS platform has a residual risk above appetite due to weak vendor access controls. Budget is limited and the remediation will take six months. The CISO must decide how to proceed while the risk remains elevated. Which action BEST aligns with CRISC risk response principles?

A.Transfer the risk to the SaaS vendor by sending a notification letter describing the control weaknesses.
B.Document an interim compensating control, set a remediation timeline, and obtain formal risk acceptance from the accountable business owner until closure.
C.Lower the inherent risk rating in the register so that residual risk falls within the approved appetite.
D.Suspend all access to the SaaS platform until the vendor access controls are fully remediated.
AnswerB

When residual risk exceeds appetite and full remediation cannot be immediate, the appropriate response is to apply interim compensating controls, commit to a timeline, and have the accountable business owner formally accept the remaining risk. This maintains transparency, assigns ownership, and keeps the exposure visible to governance. It aligns with CRISC principles because risk decisions belong to the business owner, not solely to security.

Why this answer

With residual risk above appetite and remediation requiring six months, the sound approach is to implement interim compensating controls, establish a remediation timeline, and obtain formal acceptance from the accountable business owner. This keeps exposure transparent and owned while respecting business continuity. Suspending service, manipulating ratings, or merely notifying the vendor do not appropriately manage the risk or satisfy governance and reporting expectations.

Exam trap

The trap here is treating a notification letter as risk transfer or lowering a risk score as a response, when real transfer requires contractual or insurance mechanisms and ratings must reflect evidence.

872
MCQeasy

Which risk assessment approach is most appropriate for a new technology that has limited historical data and high uncertainty?

A.Quantitative risk assessment using ALE calculations.
B.Bow-tie analysis to map causes and consequences.
C.Automated risk scoring based on industry benchmarks.
D.Delphi technique with a panel of experts.
AnswerD

The Delphi technique aggregates iterative, anonymous expert judgement, which suits novel technology where historical data is scarce and uncertainty high. Expert consensus substitutes for the missing empirical base, reducing individual bias through controlled feedback rounds.

Why this answer

The Delphi technique is most appropriate for a new technology with limited historical data and high uncertainty because it leverages the collective judgment of a panel of experts through iterative, anonymous rounds to reach a consensus on risk likelihood and impact. This approach does not rely on historical loss data or predefined benchmarks, making it ideal for novel or emerging technologies where empirical data is scarce.

Exam trap

The trap here is that candidates often choose quantitative methods like ALE (Option A) because they seem more 'objective,' failing to recognize that such methods are data-dependent and inappropriate when historical data is absent or unreliable.

How to eliminate wrong answers

Option A is wrong because quantitative risk assessment using ALE (Annualized Loss Expectancy) calculations requires reliable historical data on frequency and magnitude of losses, which is unavailable for a new technology with high uncertainty. Option B is wrong because bow-tie analysis is a structured method for mapping known causes and consequences of a specific risk event, but it presupposes a clear understanding of threat scenarios and controls, which is lacking when historical data is limited. Option C is wrong because automated risk scoring based on industry benchmarks assumes that the technology's risk profile aligns with established patterns from similar technologies, which is invalid for a novel technology where benchmarks do not exist or are not applicable.

873
MCQeasy

An organization's board has issued a risk appetite statement indicating that the company is willing to accept a moderate level of operational risk but has zero tolerance for compliance violations. This statement primarily defines which of the following?

A.Risk tolerance thresholds
B.Risk criteria
C.Risk appetite
D.Risk capacity
AnswerC

The statement expresses the board's willingness to accept moderate operational risk while tolerating zero compliance violations, which is the definition of risk appetite: the amount and type of risk an organisation is prepared to pursue or retain. Risk tolerance instead quantifies acceptable deviation around that appetite.

Why this answer

The board's statement explicitly articulates the organization's willingness to accept a moderate level of operational risk while having zero tolerance for compliance violations. This is the definition of risk appetite: the amount and type of risk an organization is willing to pursue or retain in pursuit of its objectives. Risk appetite is set at the strategic level and guides risk tolerance thresholds and risk criteria.

Exam trap

The trap here is confusing risk appetite with risk tolerance or risk capacity; candidates often pick 'risk tolerance thresholds' because the statement seems to define limits, but the key is that it expresses willingness, which is appetite.

How to eliminate wrong answers

Option A is wrong because risk tolerance thresholds are the specific measurable limits or boundaries derived from the risk appetite, not the high-level statement itself. Option B is wrong because risk criteria are the terms of reference used to evaluate the significance of risk, such as impact and likelihood scales, not the board's willingness to accept risk. Option D is wrong because risk capacity is the maximum amount of risk an organization can bear before it threatens its viability, which is a constraint, not a statement of willingness.

874
MCQeasy

An organization is implementing a new control to prevent unauthorized access to its critical database. Which type of control is most appropriate for this requirement?

A.Compensating control
B.Preventive control
C.Corrective control
D.Detective control
AnswerB

A preventive control stops unauthorised access attempts before they succeed, directly satisfying the requirement to prevent access to the critical database. Detective controls would only identify breaches after the fact, and corrective controls remediate afterwards, neither meeting the stated prevention objective.

Why this answer

A preventive control is the most appropriate because it directly stops unauthorized access before it can occur. For a critical database, this could involve implementing database-level access control lists (ACLs), network firewall rules restricting traffic to specific IP ranges, or mandatory multi-factor authentication (MFA) on the database service. These mechanisms enforce the security policy at the point of entry, blocking the threat actor before any interaction with the data.

Exam trap

The trap here is that candidates often confuse 'preventive' with 'detective' controls, mistakenly choosing detective controls (like logging) because they are more visible in audit reports, but the question explicitly asks for a control that 'prevents' access, which requires a proactive blocking mechanism.

How to eliminate wrong answers

Option A is wrong because a compensating control is an alternative measure used when the primary control cannot be implemented due to technical or business constraints, not the first choice for a direct requirement like preventing unauthorized access. Option C is wrong because a corrective control (e.g., restoring a database from a backup after a breach) acts after an incident has occurred, failing to meet the requirement to prevent access in the first place. Option D is wrong because a detective control (e.g., database audit logs or intrusion detection systems) only identifies unauthorized access after it has happened, providing no proactive prevention.

875
MCQmedium

A risk practitioner is preparing a risk report for the executive committee. The committee has limited time and has previously complained that reports contain too much technical detail. Which approach BEST communicates the most critical IT risks to this audience?

A.Focus on the number of vulnerabilities detected in the latest technical scan.
B.Provide the full risk register with all identified risks and their control test results.
C.Summarize the top risks by business impact and alignment with risk appetite, with recommended actions.
D.Present only risks that have already resulted in a confirmed loss or incident.
AnswerC

Executive reporting succeeds when it translates technical findings into business consequence and links them to the appetite leadership approved. Ranking by impact and appetite alignment focuses attention on decisions the committee can actually make, such as funding treatment or accepting a documented exception. Recommended actions close the loop by giving the committee a clear choice rather than raw data.

Why this answer

Executive risk reporting must be selective, business-oriented, and connected to appetite. Summarizing top risks by business impact and appetite alignment, with recommended actions, gives the committee what it needs to govern: which exposures matter, how they compare to tolerance, and what decisions are required. Full registers, scan counts, and incident-only reporting either overwhelm, mislead, or arrive too late.

Exam trap

The trap here is assuming that more comprehensive technical data automatically produces a more useful executive risk report.

876
MCQmedium

A risk scenario is being developed for a phishing attack leading to credential theft. Using ISACA's risk scenario template, which component would describe the 'threat event'?

A.A user clicks a malicious link in a phishing email
B.The organization's email security filter fails to block the phishing email
C.The attacker is an organized crime group based overseas
D.The compromised credentials are used to access a financial system
AnswerA

The threat event is the actual occurrence that initiates harm, so a user clicking a malicious link in a phishing email precisely describes the event itself, distinct from the threat source (external attacker) and the vulnerability (susceptible user). This satisfies the scenario component capturing what happens.

Why this answer

In ISACA's risk scenario template, the 'threat event' component describes the specific action or occurrence that triggers risk — here, a user clicking a malicious link in a phishing email. This is the initiating event that, combined with the threat actor and vulnerable asset, produces the risk. The threat event is distinct from the threat actor (who), the vulnerability (what weakness), and the impact (what happens next).

Exam trap

CRISC often tests the risk scenario template by mixing actor, event, vulnerability, and impact in the answer choices; candidates must isolate the 'event' as the action that occurs, not the actor who performs it or the consequence that follows.

How to eliminate wrong answers

Option B is wrong because the email filter failing to block the phishing email describes a control failure or vulnerability, not the threat event itself — it is the condition that allows the event to occur. Option C is wrong because identifying the attacker as an organized crime group describes the threat actor (or threat source), not the event. Option D is wrong because using compromised credentials to access a financial system describes the impact or consequence of the event, not the event that initiated the scenario.

877
Multi-Selecthard

A risk practitioner is assessing the risk of a distributed denial-of-service (DDoS) attack against an online retailer's public storefront. The CISO asks which factors would MOST directly increase the likelihood that such an attack would succeed in disrupting service. (Choose two.)

Select 2 answers
A.The retailer's marketing team runs frequent flash sales with unpredictable traffic spikes.
B.The retailer accepts multiple payment card brands at checkout.
C.The storefront's public IP addresses are easily discoverable through DNS records.
D.The retailer's customer service team is outsourced to a third party.
E.The storefront has no upstream DDoS mitigation or scrubbing capability.
AnswersC, E

Easily discoverable origin addresses lower the effort required to target the storefront directly, letting attackers bypass content delivery networks and aim at the unprotected origin. This raises the likelihood of disruption because the attacker can reach the infrastructure that lacks absorption capacity. Obscuring or rotating origin addresses is a recognized DDoS hardening measure precisely because discoverability increases exposure.

Why this answer

DDoS success hinges on whether attack traffic can reach and overwhelm the target. Missing upstream mitigation lets traffic hit the origin unfiltered, and discoverable origin IP addresses let attackers bypass protective layers to strike directly. Together these conditions materially raise the likelihood of service disruption, while payment options, marketing spikes, and support outsourcing do not directly determine whether the attack succeeds.

Exam trap

The trap here is selecting factors that merely complicate operations, such as flash sales, instead of the exposure conditions that directly enable attack traffic to reach the origin.

878
Multi-Selecteasy

An organization is implementing controls to mitigate the risk of data exfiltration. Which TWO control types would be considered preventive? (Select TWO)

Select 2 answers
A.Incident response plan
B.Backup restoration procedures
C.Log monitoring and analysis
D.Access controls to restrict data access
E.Data encryption at rest and in transit
AnswersD, E

Access controls restrict who can reach data, directly blocking exfiltration attempts before they occur. This satisfies the stem's preventive requirement by enforcing authorisation at the point of access, denying unauthorised reads or transfers. Unlike detective controls, which log after the fact, access controls stop the action itself, making them a genuine preventive measure.

Why this answer

Option D (access controls to restrict data access) is preventive because it stops unauthorized users from reaching sensitive data in the first place, enforcing least privilege and authorization before any exfiltration attempt can succeed. Option E (data encryption at rest and in transit) is preventive because it renders intercepted or stolen data unreadable without the keys, blocking the exfiltration objective even if data is copied or transmitted. By contrast, A (incident response plan) is reactive, guiding actions after a breach has occurred, and B (backup restoration procedures) is corrective/recovery-oriented, restoring data after loss or corruption.

Option C (log monitoring and analysis) is detective, since it identifies and alerts on suspicious activity rather than stopping it beforehand.

Exam trap

CRISC often tests the confusion between preventive and detective controls, tempting candidates to select monitoring or response plans as preventive when they are actually detective or corrective.

879
Multi-Selecthard

A financial services firm is defining the scope of its annual IT risk assessment. The board has asked the risk team to ensure the assessment covers both internal and external factors that could affect the confidentiality of customer data. Which TWO activities should the team include to meet this expectation? (Choose two.)

Select 2 answers
A.Review last year's audit findings and assume the same scope remains valid.
B.Limit the assessment to systems managed by the internal IT department.
C.Inventory and classify all internal systems and data repositories that store or process customer information.
D.Survey employees about their personal opinions on data privacy regulations.
E.Map external threat sources and the attack surface exposed through third-party integrations.
AnswersC, E

An accurate inventory with data classification is foundational because you cannot assess risk to assets you have not identified. It reveals where customer data resides internally, which systems are in scope, and which owners are accountable. Without this, the assessment could omit critical repositories and produce an incomplete picture of confidentiality exposure, so it directly supports the board's expectation.

Why this answer

A complete assessment scope requires knowing what must be protected and what could threaten it. Inventorying and classifying internal data repositories establishes the internal view, while mapping external threat sources and third-party attack surface establishes the external view. Prior findings, internal-only limits, and opinion surveys do not deliver this coverage, so they cannot fulfill the board's request.

Exam trap

The trap here is equating a previous year's scope with a current one, or assuming internal systems alone represent the full confidentiality exposure.

880
MCQhard

A security operations center (SOC) analyst notices multiple failed login attempts from an internal IP address followed by a successful login from an unusual geographic location. Which risk identification technique should the risk manager use to assess this as a potential risk?

A.Run a phishing simulation for the user
B.Review the logs manually for other indicators
C.Conduct a vulnerability scan on the workstation
D.Perform user and entity behavior analytics (UEBA) on the user account
AnswerD

UEBA baselines normal account activity, so the internal-IP failures followed by a login from an unusual location surface as anomalous behaviour rather than isolated events. This satisfies the scenario's need to identify the pattern as a potential risk, such as compromised credentials or impossible travel.

Why this answer

User and entity behavior analytics (UEBA) uses behavioral baselines and anomaly detection to identify patterns such as multiple failed logins followed by a successful login from an unusual geographic location, which is indicative of account compromise and a potential risk. Option A is incorrect because a phishing simulation tests user susceptibility to phishing attacks, not behavioral anomalies in login patterns. Option B is incorrect because manual log review is time-consuming and may not effectively detect subtle behavioral deviations without automated analysis.

Option C is incorrect because a vulnerability scan focuses on system vulnerabilities, not user behavior.

881
MCQeasy

An organization's risk register lists a risk with an annualized loss expectancy (ALE) of $200,000. A proposed control would reduce the ALE to $50,000, and the control costs $40,000 per year to operate. What is the value of the control's risk reduction?

A.$10,000
B.$200,000
C.$150,000
D.$40,000
AnswerC

The value of the risk reduction is the original ALE minus the residual ALE: $200,000 - $50,000 = $150,000. This represents the expected annual loss avoided by implementing the control. Comparing this to the $40,000 annual control cost shows a positive net benefit, making the control economically justified from a quantitative standpoint.

Why this answer

The value of the risk reduction is the difference between the original ALE and the residual ALE after the control is applied. Here, $200,000 minus $50,000 equals $150,000. This figure represents the expected annual loss avoided.

Comparing it to the $40,000 annual control cost yields a net benefit of $110,000, indicating the control is cost-effective.

Exam trap

The trap here is confusing the control's operating cost or net benefit with the risk reduction value, when the risk reduction is strictly the drop in expected annual loss before and after the control.

882
Multi-Selectmedium

A risk practitioner is reviewing the risk register for a cloud-based customer relationship management (CRM) system. The register contains several entries, and the practitioner must identify which entries represent inherent risk rather than residual risk. Which two of the following entries are examples of inherent risk? (Choose two.)

Select 2 answers
A.The CRM system stores customer personally identifiable information, and a breach could result in regulatory fines.
B.The vendor's SOC 2 report shows no exceptions, and the risk is considered acceptable.
C.The organization has a disaster recovery plan that is tested annually and meets recovery objectives.
D.The CRM vendor's data center is located in a region prone to hurricanes, and no redundancy is currently in place.
E.After implementing multi-factor authentication and encryption, the likelihood of unauthorized access is rated low.
AnswersA, D

This entry describes the inherent exposure associated with storing sensitive data and the potential regulatory consequences. It does not mention any controls that would reduce the risk, so it represents the raw risk before mitigation. Inherent risk includes the value of the asset and the impact of a threat event, which this entry captures through the data sensitivity and fine potential.

Why this answer

Inherent risk is the level of risk before any controls are applied. The entry about the hurricane-prone data center with no redundancy and the entry about storing personally identifiable information with potential regulatory fines both describe raw exposures without reference to mitigating controls. The other entries mention implemented controls, control effectiveness reports, or recovery plans, which relate to residual risk after treatment.

Exam trap

The trap here is equating any risk register entry with inherent risk, when entries that mention implemented controls or control effectiveness actually describe residual risk.

883
MCQmedium

A financial services firm's risk committee has approved a risk response plan for its core payment platform. The plan requires monthly tracking of key risk indicators (KRIs) and quarterly reporting of control test results to the board. Six months later, the CIO asks the risk manager to confirm that the approved response is still appropriate given new regulatory guidance. Which of the following should the risk manager do FIRST?

A.Immediately escalate to the board that the existing risk response plan is invalid and must be replaced.
B.Commission a penetration test of the payment platform to produce fresh technical evidence for the committee.
C.Suspend the quarterly board reporting until the regulatory guidance has been fully interpreted by legal counsel.
D.Reassess the risk and control environment against the new regulatory guidance to determine whether the approved response remains within tolerance.
AnswerD

The approved response was based on assumptions that new regulatory guidance may have altered. CRISC practice requires reassessing the risk, evaluating whether existing controls still mitigate it to within tolerance, and only then proposing changes to the risk response. This preserves the traceability of the risk decision and gives the committee evidence on which to act, rather than reacting to guidance in isolation.

Why this answer

When the external environment changes, the risk practitioner must first determine whether the previously approved risk response still keeps the risk within the organization's tolerance. That means reassessing the risk, the effectiveness of existing controls, and the alignment of the response with new regulatory expectations before recommending any change. This maintains evidence-based governance and gives the risk committee a defensible basis for deciding whether to accept, modify, or escalate the response.

Exam trap

The trap here is assuming that any new regulatory guidance automatically invalidates the approved risk response and warrants immediate board escalation.

884
MCQmedium

During a risk assessment, a control self-assessment (CSA) indicates that a key control is operating effectively. However, an independent audit finds multiple control failures. Which of the following is the MOST likely reason for this discrepancy?

A.The audit tested different samples
B.The control environment changed
C.The CSA participants lacked objectivity
D.The CSA was conducted too recently
AnswerC

CSA relies on control owners assessing their own controls, so a favourable result can reflect self-interest or insufficient challenge rather than genuine effectiveness. Independent audit testing provides the objectivity the CSA participants lacked, exposing failures the self-assessment masked.

Why this answer

The most likely reason for the discrepancy is that the CSA participants lacked objectivity. Control self-assessments are performed by process owners or staff who may have a vested interest in reporting favorable results, leading to biased or incomplete evaluations. In contrast, an independent audit applies objective testing procedures, which are more likely to uncover actual control failures that the CSA missed or downplayed.

Exam trap

The trap here is that candidates often choose 'The audit tested different samples' because they focus on sampling variability, but the real issue is the lack of objectivity in the self-assessment process, which is a core CRISC concept in risk and control monitoring.

How to eliminate wrong answers

Option A is wrong because while different sample sizes or selection methods could cause minor variations, the fundamental issue here is systemic bias in the CSA, not sampling differences; an independent audit would typically use statistically valid samples that are representative of the population. Option B is wrong because if the control environment changed after the CSA but before the audit, the audit would note the change as a finding, not report multiple control failures that contradict a recent effective CSA. Option D is wrong because the recency of the CSA would actually reduce the likelihood of environmental changes causing discrepancies; the core problem is the lack of objectivity in the self-assessment, not the timing.

885
Multi-Selectmedium

An organization is using the FAIR framework to perform a quantitative risk analysis for a data breach scenario. Which TWO of the following are components of the Annualized Loss Expectancy (ALE) calculation in FAIR?

Select 2 answers
A.Annualized Rate of Occurrence (ARO)
B.Loss Event Frequency (LEF)
C.Single Loss Expectancy (SLE)
D.Loss Magnitude (LM)
E.Exposure Factor (EF)
AnswersB, D

Loss Event Frequency is a primary FAIR factor, combined with Loss Magnitude to derive Annualized Loss Expectancy. It captures how often a threat event occurs annually, satisfying the quantitative analysis requirement. ALE equals LEF multiplied by Loss Magnitude, so LEF is a direct input component.

Why this answer

In FAIR, ALE is calculated as Loss Event Frequency (LEF) multiplied by Loss Magnitude (LM), so option B (Loss Event Frequency) and option D (Loss Magnitude) are the two correct components. LEF represents how often a loss event is expected to occur per year, while LM represents the probable magnitude of loss from a single event, and their product yields the annualized loss expectancy. Option A (ARO) and option C (SLE) belong to the classic SLE × ARO = ALE formula, not to FAIR's terminology, even though they are conceptually related.

Option E (Exposure Factor) is an input used to derive SLE in the traditional formula (SLE = AV × EF) and is not a direct component of FAIR's ALE calculation.

Exam trap

The trap is that candidates may select ARO, SLE, or EF because they are familiar from traditional risk analysis, but FAIR specifically defines ALE as LEF × LM.

886
MCQeasy

A control test reveals a 100% pass rate for a detective control. What does this indicate?

A.The control is operating effectively
B.The control is too expensive to maintain
C.The control is compensating for other weaknesses
D.The associated risk has been fully mitigated
AnswerA

A 100% pass rate means every sampled instance of the detective control operated as designed, with no exceptions or deviations identified. This evidences that the control is operating effectively, giving the risk practitioner reasonable assurance that the risk it addresses is being detected as intended.

Why this answer

A 100% pass rate for a detective control indicates that every time the control was tested, it successfully detected the condition or event it was designed to identify. This demonstrates the control is operating effectively, meaning it is functioning as intended and providing the expected level of assurance. For example, if the detective control is an intrusion detection system (IDS) that correctly alerts on all test attack patterns, a 100% pass rate confirms its detection logic and signature updates are working correctly.

Exam trap

The trap here is that candidates often confuse a control's effectiveness (pass rate) with risk mitigation, assuming a perfect detection rate means the risk is fully addressed, but detective controls only provide visibility, not prevention or reduction of risk likelihood.

How to eliminate wrong answers

Option B is wrong because a 100% pass rate does not provide any information about the cost of maintaining the control; cost is a separate consideration related to cost-benefit analysis, not operational effectiveness. Option C is wrong because a 100% pass rate on a detective control does not imply it is compensating for other weaknesses; compensating controls are typically preventive or detective controls that address gaps in primary controls, and a high pass rate alone does not indicate such a relationship. Option D is wrong because a 100% pass rate on a detective control does not mean the associated risk has been fully mitigated; detective controls only identify incidents after they occur, they do not prevent or reduce the likelihood of the risk, and full risk mitigation would require preventive controls or risk acceptance.

887
MCQeasy

Which of the following is a characteristic of IoT devices that increases cybersecurity risk?

A.Built-in hardware security modules
B.Limited processing power for security features
C.Standardized communication protocols
D.Regular automatic firmware updates
AnswerB

Constrained CPUs and memory prevent IoT devices from running robust encryption, patching, or intrusion detection, so security controls are weakened or omitted. This processing limitation directly widens the attack surface, satisfying the stem's characteristic that increases cybersecurity risk.

Why this answer

IoT devices are frequently constrained by cost, size, and power, which limits CPU, memory, and battery. This directly restricts their ability to run strong encryption, host-based firewalls, secure boot, or frequent patching, expanding the attack surface. Limited processing power is therefore a structural characteristic that elevates cybersecurity risk.

Exam trap

The trap here is that candidates may equate 'standardized protocols' or 'automatic updates' with risk, when in fact those are generally risk-reducing; the exam tests whether you recognize that resource constraints — not standards — are the inherent IoT weakness.

How to eliminate wrong answers

Option A is wrong because hardware security modules (HSMs) or secure elements actually reduce risk by protecting keys and enabling secure boot. Option C is wrong because standardized communication protocols can improve interoperability and, when security is built in (e.g., TLS, MQTT over TLS), they do not inherently increase risk. Option D is wrong because regular automatic firmware updates are a mitigating control that reduces risk, not a risk-increasing characteristic.

888
MCQhard

A bank's risk committee is reviewing a proposal to increase the risk appetite threshold for third-party data processing failures from 2 to 5 incidents per year. The head of internal audit objects, noting that three such failures occurred in the last 12 months and one caused a regulatory finding. Which action should the risk committee take FIRST?

A.Evaluate whether existing third-party controls and remediation plans can bring incident frequency within the current threshold before changing the appetite.
B.Immediately approve the new threshold to align reporting with actual performance and close the audit finding.
C.Reject the proposal and take no further action because the current threshold already reflects the board's intent.
D.Delegate the decision to the third-party management team since they own the vendor relationships.
AnswerA

Changing risk appetite to match current performance inverts the intended relationship: appetite should drive acceptable exposure, not be adjusted to accommodate poor results. The committee should first assess whether control improvements can reduce incident frequency to the existing threshold. Only after determining that the threshold is unachievable or misaligned with strategy should appetite revision be considered, with audit and regulatory implications weighed.

Why this answer

Risk appetite defines the level of risk the organization is willing to accept and should guide performance, not be retrofitted to justify it. Before raising the threshold, the committee must determine whether improved third-party controls can reduce failures to within the existing limit. Adjusting appetite to match poor results would normalize the exposure, conflict with the regulatory finding, and weaken governance oversight.

Exam trap

The trap here is treating risk appetite as a reporting calibration that should match actual performance, rather than a governance boundary that performance must be brought into alignment with.

889
MCQhard

A multinational retailer's risk register shows a high inherent risk for its point-of-sale (POS) payment environment. After implementing tokenization, the risk owner records a residual risk rating of low. During the next quarterly review, the internal audit team finds that several legacy POS terminals still transmit clear-text card data. Which risk response principle was violated?

A.Risk response must be validated against actual control coverage before residual risk is reported.
B.Risk response must transfer residual risk to a third party whenever inherent risk is rated high.
C.Risk response must be approved by the board before any residual risk rating can be lowered.
D.Risk response must always prioritize risk avoidance over risk mitigation for payment environments.
AnswerA

Residual risk represents what remains after controls are applied, so it must reflect verified control effectiveness across the entire scope. Reporting low residual risk while legacy terminals still transmit clear-text data overstates control coverage and understates exposure. The risk owner should have validated that tokenization covered all in-scope terminals before adjusting the rating, making this the violated principle.

Why this answer

Residual risk is only meaningful when it reflects validated control effectiveness across the full scope of the risk. The risk owner lowered the rating based on tokenization without confirming that legacy terminals were included, so the reported low residual risk was inaccurate. Risk response and reporting require evidence that controls operate as designed before risk ratings are adjusted downward, and audit findings should trigger reassessment of the affected register entries.

Exam trap

The trap here is treating residual risk as a theoretical calculation after a control is purchased, rather than a validated measurement of control coverage and effectiveness.

890
MCQeasy

Which of the following is the PRIMARY purpose of a risk register in an IT risk management program?

A.To document and track identified risks and their treatment plans
B.To provide a historical record of past incidents
C.To calculate key risk indicators (KRIs)
D.To ensure compliance with regulatory requirements
AnswerA

A risk register records each identified risk, its owner, likelihood and impact ratings, and the agreed treatment plan, giving management a single authoritative view for tracking and reporting. This documentation and tracking function is its primary purpose within the IT risk management programme.

Why this answer

The risk register is the central repository for documenting identified risks, their assessed impact and likelihood, and the corresponding treatment plans (e.g., mitigate, accept, transfer, avoid). Its primary purpose is to provide a structured, living record that enables ongoing tracking, prioritization, and management of risk treatment activities throughout the IT risk management lifecycle.

Exam trap

The trap here is that candidates confuse the risk register's primary purpose with secondary benefits like compliance or metrics, leading them to choose options that describe outputs or uses of the register rather than its core function of documenting and tracking risks and treatments.

How to eliminate wrong answers

Option B is wrong because a risk register is forward-looking and focused on current and future risks, not a historical log of past incidents (that would be an incident log or post-mortem database). Option C is wrong because key risk indicators (KRIs) are metrics derived from risk data to provide early warning signals, but the risk register itself does not calculate them; it stores the underlying risk data that may feed KRI calculations. Option D is wrong while compliance may be a benefit of using a risk register, its primary purpose is risk management and treatment tracking, not specifically ensuring regulatory compliance (which is the role of compliance frameworks and audit programs).

891
Multi-Selecthard

Which THREE of the following are common challenges in risk reporting?

Select 3 answers
A.Timeliness of information.
B.Over-reliance on automated tools.
C.Data accuracy issues.
D.Too much detail.
E.Lack of board support.
AnswersA, C, D

Outdated information reduces the value of risk reports.

Why this answer

Timeliness of information is a common challenge in risk reporting because risk data must be current to support effective decision-making. If reports are delayed, the organization may act on outdated risk profiles, leading to inappropriate responses. Real-time or near-real-time reporting is often required, but data aggregation and processing latency can introduce delays.

Exam trap

ISACA CRISC often tests the distinction between challenges in risk reporting versus challenges in risk assessment or risk management governance, so candidates mistakenly select 'over-reliance on automated tools' or 'lack of board support' because they are familiar risk-related issues, but they are not specific to the reporting process itself.

892
MCQmedium

An organization uses a qualitative risk assessment and assigns a likelihood of '3' and impact of '4' on a 5-point scale. The heat map defines risk scores 12-25 as high. What is the risk rating?

A.Critical
B.Medium
C.Low
D.High
AnswerD

Multiplying likelihood 3 by impact 4 gives a risk score of 12. The heat map classifies scores from 12 to 25 as high, so the score falls within the high band and the rating is High.

Why this answer

Risk score = 3 × 4 = 12, which falls in the high range (12-25).

893
MCQhard

A hospital's risk team is assessing a new telehealth platform. The vendor reports that its encryption module was certified two years ago. The team wants to determine whether the residual risk of relying on that module is acceptable. Which action should the team take FIRST?

A.Immediately terminate the vendor contract because the certification is expired.
B.Accept the vendor's certification as sufficient evidence and close the risk.
C.Request the vendor's current vulnerability scan results and patch history for the module.
D.Re-rate the inherent risk to zero because encryption is in place.
AnswerC

Residual risk depends on the control's current effectiveness, not its historical certification. Requesting recent scan results and patch history gives the team evidence about whether known vulnerabilities remain unaddressed in the module. That data lets the team judge whether the encryption still provides the protection assumed in the risk calculation, making it the essential first step before deciding on acceptance.

Why this answer

Residual risk must be judged from current evidence about control effectiveness. An older certification says little about whether the encryption module still blocks today's exploits. Obtaining up-to-date scan results and patch records gives the team the factual basis to determine whether the remaining exposure is tolerable, which is the necessary first step before any treatment decision.

Exam trap

The trap here is treating a past certification as ongoing proof of control effectiveness, when residual risk requires current, verifiable evidence.

894
MCQmedium

An organization wants to promote a risk-aware culture. Which of the following actions is MOST effective for encouraging employees to report incidents without fear?

A.Reward employees for zero incidents
B.Establish a non-punitive incident reporting policy
C.Implement automated monitoring tools
D.Conduct security awareness training annually
AnswerB

A non-punitive policy removes the fear of blame or reprisal, which is the specific barrier stopping employees from reporting incidents. Awareness campaigns or training alone cannot overcome that fear, so this directly satisfies the stem's constraint of encouraging reporting without fear.

Why this answer

A non-punitive incident reporting policy directly removes the fear of retaliation or blame, which is the primary barrier to reporting. By guaranteeing that employees will not be punished for reporting incidents (including their own mistakes), the organization encourages transparency and timely disclosure. This aligns with CRISC principles of fostering a risk-aware culture where risk information flows freely.

Other options do not address the fear factor; rewards for zero incidents can actually discourage reporting, automated tools don't change human behavior, and annual training is insufficient to build trust.

Exam trap

CRISC often tests the difference between technical controls and cultural enablers; candidates may mistakenly choose automated monitoring or training as the most effective, overlooking that fear of punishment is a human factor that only policy can address.

How to eliminate wrong answers

Option A is wrong because rewarding zero incidents incentivizes employees to hide incidents to earn rewards, directly undermining reporting. Option C is wrong because automated monitoring tools detect issues but do not address the cultural fear that prevents employees from voluntarily reporting incidents. Option D is wrong because annual security awareness training, while useful for knowledge, does not create a safe environment for reporting; it may even increase fear if it emphasizes punishment.

895
MCQmedium

An organization is implementing a continuous monitoring solution for its network. Which of the following is an example of continuous monitoring?

A.Monthly control testing by internal audit
B.Annual penetration testing
C.Quarterly access reviews
D.Daily automated vulnerability scanning
AnswerD

Daily automated vulnerability scanning repeatedly and systematically inspects network assets on a scheduled basis, generating current findings without manual intervention. This satisfies continuous monitoring's defining characteristic of ongoing automated observation, unlike one-off assessments or periodic manual reviews that capture only point-in-time snapshots.

Why this answer

Continuous monitoring means ongoing, automated observation of controls and risk indicators at frequent intervals. Daily automated vulnerability scanning fits this definition because it runs repeatedly without manual intervention and provides near-real-time visibility into the control environment. The other options are periodic, point-in-time activities.

Exam trap

CRISC often tests the distinction between continuous monitoring (frequent, automated) and periodic activities (monthly, quarterly, annual); candidates who focus on the depth of the activity rather than its frequency pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because monthly control testing is periodic, not continuous — it provides a snapshot once a month. Option B is wrong because annual penetration testing is an infrequent, deep-dive assessment, the opposite of continuous monitoring. Option C is wrong because quarterly access reviews are periodic attestations, not automated continuous observation.

896
MCQmedium

A company has identified that its legacy financial system has a high inherent risk due to outdated architecture. The system cannot be replaced for three years. What is the best risk treatment strategy?

A.Accept the risk and allocate contingency funds for potential incidents.
B.Transfer the risk by purchasing cyber insurance.
C.Avoid the risk by discontinuing the system immediately.
D.Implement compensating controls such as network segmentation and enhanced monitoring.
AnswerD

Because replacement is impossible for three years, risk must be mitigated rather than avoided or transferred. Network segmentation limits lateral movement and enhanced monitoring detects compromise attempts, directly reducing the high inherent risk posed by the outdated architecture while the legacy system remains in production.

Why this answer

When a legacy system cannot be replaced for three years, the most effective risk treatment is to reduce the likelihood and impact of exploitation through compensating controls. Network segmentation limits lateral movement from the legacy system, and enhanced monitoring (e.g., SIEM with custom rules for anomalous traffic) provides early detection of compromise. This aligns with the ISACA risk treatment principle of risk reduction when avoidance or transfer is not feasible.

Exam trap

The trap here is that candidates often choose risk acceptance (Option A) or transfer (Option B) without recognizing that high inherent risk demands active reduction measures, especially when the system cannot be decommissioned.

How to eliminate wrong answers

Option A is wrong because accepting the risk without active reduction measures ignores the high inherent risk from outdated architecture, and contingency funds alone do not prevent data breaches or system downtime. Option B is wrong because cyber insurance transfers financial impact but does not reduce the operational or reputational risk; insurers may also deny claims if compensating controls are absent. Option C is wrong because discontinuing the system immediately would halt critical business operations, and the question explicitly states the system cannot be replaced for three years, making avoidance impractical.

897
MCQeasy

During IT risk identification, which document serves as the central repository for all identified risks, their characteristics, and current status?

A.Threat model
B.Vulnerability database
C.Business impact analysis
D.Risk register
AnswerD

The risk register is the central repository recording each identified risk, its characteristics (likelihood, impact, owner) and current status. It satisfies the stem's requirement for a single consolidated record supporting ongoing IT risk identification and tracking.

Why this answer

The risk register is the central repository that documents all identified risks, including their characteristics (e.g., likelihood, impact, risk rating), risk owners, mitigation plans, and current status. It is a key tool in the risk identification and assessment process, as defined in CRISC and ISO 31000.

Exam trap

The trap is confusing the risk register with other risk-related documents like the BIA or threat model; candidates must remember that the risk register is the central repository for all identified risks.

How to eliminate wrong answers

Option A is wrong because a threat model is a structured approach to identifying and analyzing threats to a system, not a repository for all risks. Option B is wrong because a vulnerability database lists known vulnerabilities, not the organization's identified risks with their characteristics and status. Option C is wrong because a business impact analysis (BIA) assesses the impact of disruptions to business functions, but it is not the central repository for all risks.

898
MCQhard

A hospital network is deploying a new medical imaging archive. The risk practitioner learns that the vendor's support engineers require remote access to the archive for maintenance. Which of the following is the BEST control to manage the third-party access risk?

A.Implement privileged access management with session recording, just-in-time elevation, and full session brokering through a jump host.
B.Grant vendor engineers a dedicated local administrator account with a strong password rotated every 90 days.
C.Require the vendor to carry cyber insurance and provide a certificate of insurance annually.
D.Require vendor engineers to sign an annual acceptable use policy before access is granted.
AnswerA

Privileged access management with just-in-time elevation, brokered sessions, and recording ensures vendor engineers receive only the access needed for the approved maintenance window, that credentials are vaulted rather than shared, and that every action is attributable. This directly controls the third-party access risk while preserving the audit trail required for regulated medical data.

Why this answer

Third-party remote access creates standing privileged exposure that must be constrained technically, not just contractually. Privileged access management with just-in-time elevation, credential vaulting, session brokering, and recording limits vendor reach to approved windows and produces attributable evidence. Policy signatures, standing admin accounts, and insurance certificates leave the actual access path uncontrolled.

Exam trap

The trap here is treating contractual or administrative assurances, such as policy sign-off or insurance, as equivalent to a technical control over privileged sessions.

899
MCQeasy

You are the IT risk manager for a financial institution that processes high-value transactions. The organization uses a cloud-based core banking system and on-premises servers for backup. During a recent risk assessment, you identified that the cloud provider's service-level agreement (SLA) guarantees 99.9% uptime, but the organization's business impact analysis (BIA) indicates that every hour of downtime costs $500,000. The current recovery time objective (RTO) for the core banking system is 4 hours, but the actual recovery capability is 6 hours due to manual steps in failover. The risk owner has accepted this risk informally. You are asked to recommend a course of action to the risk committee. Which of the following is the most appropriate recommendation?

A.Accept the risk because the cloud provider's SLA covers 99.9% uptime.
B.Continue with informal acceptance since the risk owner has already accepted it.
C.Reduce the RTO to 2 hours to align with industry best practices.
D.Document the risk gap (actual recovery of 6 hours vs. RTO of 4 hours) and present it to the risk committee for formal risk acceptance or remediation.
AnswerD

Documenting the 6-hour actual recovery against the 4-hour RTO and escalating to the risk committee converts informal acceptance into formal, documented risk acceptance or remediation, satisfying governance requirements for a high-value transaction system where downtime costs $500,000 hourly.

Why this answer

The organization has a critical risk gap: the actual recovery capability (6 hours) exceeds the stated RTO (4 hours), meaning the business would incur $1M in losses (2 hours × $500K) before recovery completes. The risk owner's informal acceptance is insufficient for a financial institution processing high-value transactions; formal documentation and risk committee approval are required for governance and regulatory compliance. Presenting the gap enables informed decision-making on whether to accept the risk formally or invest in remediation (e.g., automating failover to meet the 4-hour RTO).

Exam trap

The trap here is that candidates confuse the cloud provider's SLA with the organization's RTO/RTA gap, or assume informal risk acceptance is sufficient, when CRISC emphasizes formal documentation and committee-level decision-making for risks exceeding thresholds.

How to eliminate wrong answers

Option A is wrong because the cloud provider's 99.9% SLA (8.76 hours annual downtime) does not address the specific gap between the 4-hour RTO and 6-hour actual recovery; it only covers cloud uptime, not the manual failover delays causing the breach. Option B is wrong because informal acceptance lacks the formal documentation and risk committee oversight required by CRISC best practices and regulatory standards (e.g., FFIEC guidelines for financial institutions), leaving the organization exposed to unmanaged risk. Option C is wrong because reducing the RTO to 2 hours without addressing the underlying manual failover process would widen the gap (actual 6 hours vs. new RTO of 2 hours), increasing potential losses to $2M per incident, and is not a feasible remediation without significant investment.

900
MCQmedium

A manufacturing company is integrating its operational technology (OT) network with the corporate IT network to enable real-time data analytics. Which of the following risks should be prioritized during the risk assessment?

A.Attack path expansion from IT to OT networks
B.Incompatibility of IT and OT software versions
C.Increased latency in OT communications
D.Loss of data integrity in analytics dashboards
AnswerA

Integrating IT and OT creates bidirectional conduits, so compromised corporate credentials or endpoints can pivot into operational technology, disrupting physical production. This attack path expansion directly addresses the stem's priority: the newly bridged trust boundary between previously air-gapped OT and corporate IT, where Microsoft Entra ID compromise could cascade into safety-critical systems.

Why this answer

Integrating OT and IT networks creates a new attack path from the IT network to the OT network. Since OT systems often lack modern security controls and run legacy protocols (e.g., Modbus, DNP3), an attacker who compromises the IT network can pivot into the OT environment, potentially disrupting physical processes. This risk is prioritized because it introduces a direct, high-impact threat to safety and availability that did not exist before the integration.

Exam trap

The trap here is that candidates often focus on operational risks like latency or compatibility (options B and C) because they seem more immediate to the integration, but CRISC prioritizes security risks that introduce new attack vectors with potential for physical damage.

How to eliminate wrong answers

Option B is wrong because software version incompatibility is a compatibility or integration issue, not a security risk that would be prioritized in a risk assessment focused on security; it is typically addressed during project planning or testing. Option C is wrong because increased latency in OT communications is a performance or operational risk, not a security risk; while important, it does not represent the primary threat introduced by network integration. Option D is wrong because loss of data integrity in analytics dashboards is a consequence of a security incident (e.g., tampering) but not the root risk; the prioritized risk is the attack path that enables such tampering.

Page 11

Page 12 of 15

Page 13