Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 901–975

1062 questions total · 15pages · All types, answers revealed

Page 12

Page 13 of 15

Page 14
901
MCQeasy

During a risk assessment, the risk practitioner is identifying threats to an application. Which threat modeling technique is specifically designed to analyze application threats using categories such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?

A.STRIDE
B.VAST
C.TRIKE
D.PASTA
AnswerA

STRIDE is Microsoft's threat modelling framework whose six mnemonic categories — Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service and Elevation of Privilege — map directly onto the stem's listed threat types, making it the technique explicitly designed for categorising application threats.

Why this answer

STRIDE is a threat modeling methodology developed by Microsoft that categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is specifically designed to analyze application threats using these categories, making it the correct answer.

Exam trap

The trap is confusing STRIDE with other threat modeling methodologies like PASTA or TRIKE; candidates must memorize the STRIDE acronym and its categories.

How to eliminate wrong answers

Option B is wrong because VAST (Visual, Agile, and Simple Threat) is a threat modeling methodology focused on scalability and integration with Agile, but it does not use the STRIDE categories. Option C is wrong because TRIKE is a risk-based threat modeling methodology that uses a requirements model and an implementation model, but it does not use the STRIDE mnemonic. Option D is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a seven-step risk-centric threat modeling methodology, but it does not use the STRIDE categories.

902
MCQeasy

A smart manufacturing company has deployed hundreds of IoT sensors and actuators across its production line. These devices are connected directly to the corporate network without any segmentation and communicate using unencrypted protocols. A third-party vendor manages all IoT devices and has administrative access from their own network. Recently, the IT team detected unusual outbound traffic from the IoT segment to unknown IP addresses on the internet. The risk manager is leading a risk identification workshop. Based on this scenario, what is the most critical risk to the organization that should be identified and documented?

A.Unauthorized remote access to the corporate network via the IoT devices
B.Compliance violation with industry regulations
C.Loss of data integrity due to tampering with sensor measurements
D.Physical damage to equipment due to unsafe actuator commands
AnswerA

Unsegmented IoT devices with vendor administrative access and unencrypted protocols create a direct path into the corporate network, so the most critical risk is unauthorised remote access. This satisfies the stem's constraint by addressing the exposure that enables the detected anomalous outbound traffic.

Why this answer

The most critical risk is unauthorized remote access to the corporate network via the IoT devices. The IoT devices are directly connected to the corporate network without segmentation and communicate using unencrypted protocols, while a third-party vendor has administrative access from their own network. The unusual outbound traffic to unknown IP addresses strongly suggests that an attacker has compromised the vendor's network or the devices themselves, using the unencrypted protocols (e.g., MQTT without TLS, Modbus/TCP) to pivot into the corporate network, bypassing perimeter defenses.

Exam trap

ISACA often tests the concept that the most critical risk is the one that is actively occurring and has the highest potential for immediate impact, not the one that is merely possible or a downstream consequence; candidates often pick a compliance or data integrity answer because they focus on data protection rather than network access control.

How to eliminate wrong answers

Option B is wrong because while compliance violations (e.g., GDPR, NIST CSF) are possible, the immediate and most critical risk is the active, confirmed unauthorized access via the observed outbound traffic, not a hypothetical regulatory issue. Option C is wrong because loss of data integrity from tampered sensor measurements is a secondary risk; the primary threat is the attacker already having network access, which enables data manipulation but is not the most critical risk identified from the traffic anomaly. Option D is wrong because physical damage from unsafe actuator commands is a potential consequence, but the direct evidence of unusual outbound traffic indicates an active network breach, making unauthorized access the most critical risk to document first.

903
MCQmedium

An organization implements an intrusion detection system (IDS) to monitor for security incidents. This is an example of which type of control?

A.Detective
B.Corrective
C.Compensating
D.Preventive
AnswerA

An IDS identifies and logs intrusions after they occur, satisfying the stem's requirement to monitor for security incidents. Detective controls discover and report events rather than preventing them, unlike preventive controls. This aligns with CRISC's control classification, where monitoring mechanisms are detective by definition.

Why this answer

An intrusion detection system (IDS) is a detective control because it monitors network traffic or system activity for signs of malicious behavior or policy violations and generates alerts when such patterns are detected. Unlike preventive controls, an IDS does not block or stop the attack in real time; it only identifies and reports the incident for subsequent investigation and response.

Exam trap

The trap here is that candidates often confuse an IDS with an IPS (Intrusion Prevention System), which is a preventive control because it can actively block traffic, whereas the question specifically asks about an IDS, which is purely detective.

How to eliminate wrong answers

Option B (Corrective) is wrong because corrective controls are actions taken to remediate or reverse the effects of an incident after it has been detected, such as patching a vulnerability or restoring from backup, whereas an IDS only alerts and does not perform remediation. Option C (Compensating) is wrong because compensating controls are alternative measures implemented when a primary control cannot be applied, such as using additional logging when encryption is not feasible, but an IDS is a standard control, not a substitute for another control. Option D (Preventive) is wrong because preventive controls are designed to stop an incident before it occurs, like a firewall blocking unauthorized traffic, while an IDS passively monitors and does not block or prevent attacks.

904
MCQeasy

A risk analyst is assessing the risk of a legacy application that stores customer data in plaintext. The application is scheduled for decommissioning in 18 months, but until then it must remain operational. Which of the following is the BEST risk response?

A.Accept the risk because the application will be decommissioned soon and the cost of encryption is not justified.
B.Implement database encryption at rest and in transit for the legacy application as a compensating control until decommissioning.
C.Transfer the risk by purchasing cyber insurance to cover potential data breach costs.
D.Avoid the risk by immediately shutting down the legacy application, even if it disrupts business operations.
AnswerB

Implementing encryption at rest and in transit is a feasible compensating control that protects the data even if the application is compromised. It addresses the plaintext storage risk directly and reduces the potential impact. This is the best response because it mitigates the risk during the remaining operational period without requiring major application changes, and it aligns with data protection best practices.

Why this answer

Implementing encryption at rest and in transit is the best risk response because it directly mitigates the risk of plaintext data exposure. It acts as a compensating control that can be applied without major changes to the legacy application, protecting sensitive data until decommissioning. This approach balances risk reduction with operational continuity, unlike acceptance, transfer, or avoidance which either leave the risk or disrupt business.

Exam trap

The trap here is assuming that because the application will be decommissioned soon, it is acceptable to leave the data unprotected or to rely solely on insurance, rather than applying a feasible technical control.

905
MCQhard

A company is conducting a Risk Identification for a new payment processing system. The team discovers that the system does not have encryption at rest. This is an example of:

A.Control
B.Threat
C.Vulnerability
D.Risk
AnswerC

Absence of encryption at rest is a weakness in the system's controls, not a threat or event. CRISC defines this as a vulnerability: an internal condition that a threat source could exploit, satisfying the stem's classification requirement.

Why this answer

The absence of encryption at rest in a payment processing system is a weakness or flaw that can be exploited, making it a vulnerability. In risk identification, a vulnerability is a condition or weakness in an asset (e.g., database, storage volume) that, if exploited by a threat, could lead to a risk event. Here, the missing encryption at rest (e.g., AES-256 for stored cardholder data) is a specific security gap, not the threat itself or the resulting risk.

Exam trap

The trap here is confusing a vulnerability (the missing encryption) with the risk (the potential for data exposure) or the threat (the attacker who might exploit it), leading candidates to pick 'Risk' or 'Threat' instead of the correct 'Vulnerability'.

How to eliminate wrong answers

Option A is wrong because a control is a safeguard or countermeasure (e.g., enabling encryption at rest via AWS KMS or BitLocker), not the absence of one. Option B is wrong because a threat is a potential cause of an unwanted incident (e.g., an attacker gaining physical access to the storage server), not the missing encryption itself. Option D is wrong because risk is the potential impact of a threat exploiting a vulnerability (e.g., financial loss from data breach), not the vulnerability itself.

906
MCQeasy

Which risk treatment option involves formally acknowledging the risk and taking no further action, provided the risk is within the organization's risk appetite?

A.Avoid
B.Transfer
C.Mitigate
D.Accept
AnswerD

Acceptance means the organisation formally documents the risk and proceeds without mitigation, which is valid only when exposure sits inside the defined risk appetite. This matches the stem's condition of acknowledged inaction within tolerance, unlike avoid, transfer or mitigate.

Why this answer

Risk acceptance is the treatment option where the organization formally acknowledges a risk and decides to take no action because the risk falls within its defined risk appetite. It is a deliberate, documented decision — not neglect — and typically requires management sign-off. This matches the question's description exactly.

Exam trap

The trap is confusing acceptance with avoidance or neglect; CRISC tests whether you recognize that acceptance is a formal, documented decision within risk appetite, not simply ignoring the risk.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity that generates the risk entirely, not acknowledging and tolerating it. Option B is wrong because risk transfer shifts the financial impact to a third party, such as through insurance or outsourcing. Option C is wrong because risk mitigation reduces the likelihood or impact through controls, which is an active response rather than taking no action.

907
MCQmedium

A hospital is deploying IoT medical devices that connect to the network. Which risk is MOST concerning from a cybersecurity perspective?

A.Expanded attack surface due to many devices
B.Data sovereignty compliance
C.Firmware update challenges
D.Vendor lock-in
AnswerA

Each connected IoT medical device adds an entry point, so the aggregate attack surface grows faster than the hospital can patch or monitor it, giving adversaries more unmanaged vectors into clinical networks than any single device weakness.

Why this answer

IoT medical devices dramatically expand the attack surface because each device is a potential entry point, often with weak default credentials, unpatched firmware, and limited security controls. In a hospital, this expansion is the most concerning risk because it multiplies exposure across the network.

Exam trap

The trap is picking firmware update challenges because it sounds technical and specific — candidates overlook that the broader, more strategic risk is the sheer expansion of the attack surface across many unmanaged devices.

How to eliminate wrong answers

Option B is wrong because data sovereignty is a compliance concern, not the primary cybersecurity risk from IoT proliferation. Option C is wrong because firmware update challenges are a real issue but are a subset of the broader attack surface problem. Option D is wrong because vendor lock-in is a business/strategic risk, not a cybersecurity risk.

908
MCQeasy

An organization is implementing a new identity and access management (IAM) system. The risk practitioner is asked to identify the control that would BEST reduce the risk of unauthorized access due to compromised user credentials.

A.Enforcing a strong password policy with complexity and expiration requirements.
B.Implementing multi-factor authentication (MFA) for all user accounts.
C.Implementing account lockout after three failed login attempts.
D.Conducting regular security awareness training for all employees.
AnswerB

MFA requires an additional factor beyond a password, such as a token or biometric, making it significantly harder for an attacker to gain access even if the password is compromised. This directly mitigates the risk of unauthorized access due to stolen credentials. It is the most effective control because it adds a layer that cannot be easily replicated by an attacker who only has the password.

Why this answer

Multi-factor authentication (MFA) is the most effective control to reduce the risk of unauthorized access from compromised credentials because it requires an additional factor that an attacker is unlikely to possess. Password policies, training, and account lockout are useful but do not prevent access when valid credentials are stolen and used. MFA directly addresses the risk by adding a barrier that cannot be overcome with the password alone.

Exam trap

The trap here is assuming that strong password policies or user training alone can prevent unauthorized access, overlooking that stolen credentials can bypass these measures.

909
MCQhard

Based on the exhibit, what is the MOST likely risk scenario?

A.Phishing attack that captured user credentials
B.Brute force attack resulting in account compromise
C.Insider threat from a legitimate user
D.Denial of service attack on the authentication server
AnswerB

Repeated authentication failures against a single account, followed by a successful login, indicate credential guessing rather than malware execution or data exfiltration. The pattern matches brute force leading to account compromise, which is the scenario the exhibit's failed-then-successful logon sequence depicts.

Why this answer

The exhibit shows a high number of failed authentication attempts from a single IP address over a short time window, followed by a successful login. This pattern is characteristic of a brute force attack, where an attacker systematically tries many password combinations until one succeeds, leading to account compromise.

Exam trap

ISACA often tests the distinction between authentication failures from a brute force attack versus a denial of service attack, where candidates mistakenly choose DoS because they see many failed attempts, but the key is that the server remains functional and a successful login occurs.

How to eliminate wrong answers

Option A is wrong because a phishing attack would typically capture credentials via a deceptive email or website, not through a high volume of failed logins from a single source. Option C is wrong because an insider threat from a legitimate user would not generate numerous failed authentication attempts; a legitimate user would likely succeed on the first try or have a few failures due to forgotten passwords, not a sustained brute force pattern. Option D is wrong because a denial of service attack on the authentication server would cause a flood of traffic or requests, overwhelming the server and preventing legitimate logins, but the exhibit shows a successful login after failures, indicating the server remained responsive and the attack targeted a specific account, not the server's availability.

910
MCQmedium

A hospital's risk practitioner is building a risk register entry for the loss of a critical electronic health record (EHR) system. The practitioner wants to express the risk in a way that combines the probability of the event with the magnitude of its business impact so that leadership can compare it against other enterprise risks. Which of the following BEST represents this expression?

A.Risk score derived from a likelihood and impact matrix
B.Key risk indicator (KRI) threshold breach count
C.Annualized loss expectancy (ALE)
D.Control self-assessment (CSA) result
AnswerA

A likelihood-and-impact matrix produces a risk score that combines how probable the event is with how severe its effect would be, which is exactly what the practitioner needs for comparison against other enterprise risks. It accommodates both financial and nonfinancial impacts such as patient safety and regulatory exposure. This is the standard qualitative or semi-quantitative expression used in an IT risk register.

Why this answer

Risk must be expressed so that dissimilar risks can be compared and prioritized. Combining likelihood with impact in a matrix yields a risk score that reflects both dimensions, works for financial and nonfinancial consequences, and aligns with how IT risk registers are typically populated. Monetary measures such as annualized loss expectancy address only expected financial loss, while control self-assessment results and indicator breach counts are inputs to assessment rather than the risk expression itself.

Exam trap

The trap here is assuming that any quantified or numeric value, such as annualized loss expectancy or a count of indicator breaches, automatically satisfies the requirement to combine likelihood with impact.

911
MCQmedium

A risk analyst is prioritizing remediation efforts across four identified risks. The analyst has likelihood and impact ratings but must also account for the speed at which each risk could materialize and the organization's ability to respond. Which concept is the analyst applying to adjust the prioritization?

A.Risk appetite
B.Control maturity
C.Inherent risk
D.Risk velocity
AnswerD

Risk velocity describes how quickly a risk can materialize and cause impact, which directly affects prioritization beyond static likelihood and impact scores. A risk with moderate likelihood and impact but very high velocity may warrant faster action than a slower, larger risk because there is little time to react. Considering velocity alongside response capability is exactly what the analyst is doing here.

Why this answer

Risk velocity captures how fast a risk can produce impact, and it changes prioritization because a fast-moving risk leaves little time for detection and response. Two risks with identical likelihood and impact scores can require very different urgency when one unfolds over months and the other over minutes. Folding velocity and response capability into prioritization directs attention to the exposures where delay is most costly.

Exam trap

The trap here is assuming that likelihood multiplied by impact fully determines priority, ignoring how quickly the risk can materialize.

912
MCQmedium

In the FAIR framework, Loss Event Frequency (LEF) is calculated as:

A.Threat Event Frequency + Vulnerability
B.Annualized Rate of Occurrence × Single Loss Expectancy
C.Loss Magnitude × Vulnerability
D.Threat Event Frequency × Vulnerability
AnswerD

FAIR decomposes Loss Event Frequency into Threat Event Frequency multiplied by Vulnerability, where Vulnerability is the probability that a threat event becomes a loss event. This differs from Loss Magnitude, which is a separate factor in the risk calculation.

Why this answer

In the FAIR (Factor Analysis of Information Risk) framework, Loss Event Frequency (LEF) is the probable frequency of loss events in a given timeframe. It is derived by multiplying Threat Event Frequency (TEF) — how often a threat agent acts — by Vulnerability, which is the probability that a threat event becomes a loss event. This product yields LEF.

Exam trap

CRISC often tests the FAIR formula by mixing it with traditional ALE (ARO × SLE); candidates who memorize ALE but not FAIR's decomposition pick the ARO × SLE option.

How to eliminate wrong answers

Option A is wrong because LEF is a product, not a sum, of TEF and Vulnerability; adding them is mathematically meaningless in FAIR. Option B is wrong because ARO × SLE is the classic Annualized Loss Expectancy (ALE) formula from traditional risk analysis, not FAIR's LEF. Option C is wrong because Loss Magnitude × Vulnerability describes a component of risk (Loss Magnitude is the other half of FAIR's risk equation), not LEF.

913
MCQmedium

A risk practitioner at a regional hospital is building a risk register and needs to classify each identified risk by its source. During interviews, staff describe a recurring situation: a radiology scheduling application has no automated account deprovisioning, so terminated employees retain access for weeks until a supervisor manually reports them. Which risk identification category BEST describes this finding?

A.A threat event, because terminated employees could intentionally misuse their retained access.
B.A vulnerability, because the absence of automated deprovisioning is a weakness that an actor could exploit.
C.A control objective, because the hospital should define a target for account removal timing.
D.A risk appetite statement, because the hospital has implicitly accepted delayed deprovisioning.
AnswerB

A vulnerability is a weakness in a process, system, or control that a threat source can exploit. The lack of automated account deprovisioning for the radiology scheduling application is precisely such a weakness: it exists independently of any attacker and persists until the process is corrected. Classifying it correctly drives remediation toward implementing automated lifecycle management rather than toward monitoring or accepting the residual exposure.

Why this answer

The missing automated deprovisioning capability is a weakness in an IT process that a threat source could exploit, which by definition is a vulnerability. Identifying it as such allows the risk practitioner to link it to relevant threat sources, assess likelihood and impact, and drive remediation such as automated identity lifecycle management. Threat events describe occurrences, appetite statements describe tolerance, and control objectives describe desired outcomes, none of which match the observed condition.

Exam trap

The trap here is assuming that because a terminated employee could cause harm, the finding must be classified as a threat event rather than as the underlying weakness itself.

914
MCQmedium

In the FAIR framework, what does Loss Event Frequency (LEF) represent?

A.The number of threat events per year
B.The expected number of loss events per year
C.The probability that a threat event will result in a loss
D.The total financial loss per event
AnswerB

Loss Event Frequency quantifies how often threat events are expected to result in loss, expressed as a rate per unit time. In FAIR it is derived from threat event frequency and vulnerability, and is multiplied by loss magnitude to yield risk.

Why this answer

LEF is the product of Threat Event Frequency (TEF) and Vulnerability (V), representing how often a loss event is expected to occur.

915
MCQmedium

During a risk assessment, a risk is assigned a likelihood of 'High' and an impact of 'Medium' on a 5×5 heat map. What is the risk rating?

A.Critical
B.Low
C.Medium
D.High
AnswerD

A combination of High likelihood and Medium impact yields a High risk rating in most 5×5 matrices.

Why this answer

On a 5x5 heat map, likelihood and impact are typically rated on a scale of 1 to 5. A likelihood of 'High' (often 4) and impact of 'Medium' (often 3) combine to a risk rating that is usually 'High' in most standard risk matrices. The exact rating depends on the organization's risk matrix, but in common CRISC contexts, High likelihood and Medium impact yield a High risk rating.

Exam trap

The trap is assuming a specific numerical mapping without considering the organization's matrix; candidates must recognize that High likelihood and Medium impact typically result in High risk, not Medium or Critical.

How to eliminate wrong answers

Option A is wrong because 'Critical' typically requires both High likelihood and High impact, or a very high combined score. Option B is wrong because 'Low' would require Low likelihood and Low impact. Option C is wrong because 'Medium' would typically result from Medium likelihood and Medium impact, or Low likelihood and High impact, etc.

Option D is correct because High likelihood and Medium impact generally map to High risk.

916
Multi-Selectmedium

A multinational retailer's IT risk manager must define key risk indicators (KRIs) for its third-party payment processing relationships. Which TWO characteristics must the selected KRIs exhibit to be effective for ongoing risk monitoring? (Choose two.)

Select 2 answers
A.They are kept confidential from the vendor so the vendor cannot influence the reported results.
B.They are tied to a specific risk statement and have defined thresholds that trigger escalation.
C.They are reviewed and updated only during the annual enterprise risk assessment cycle.
D.They are measurable at a defined frequency from data the organization can reliably obtain.
E.They are expressed exclusively as monetary values so executives can compare them to budget.
AnswersB, D

An effective KRI links directly to an identified risk and carries thresholds that dictate when action or escalation is required. Without this linkage, the metric is just operational reporting. With it, the retailer knows that a breach of the threshold signals increasing exposure and initiates the documented risk response process, keeping monitoring connected to governance rather than producing data with no decision path.

Why this answer

Effective KRIs are quantifiable on a reliable schedule and explicitly tied to a risk with thresholds that drive escalation. Those two properties turn measurement into monitoring. Restricting indicators to monetary units, refreshing them only annually, or hiding them from the vendor all break the feedback loop that makes an indicator actionable for third-party payment risk.

Exam trap

The trap here is assuming an indicator must be financial or confidential to be credible, when usefulness depends on reliable periodic measurement and a threshold linked to a specific risk.

917
MCQmedium

An organization uses the CISA Known Exploited Vulnerabilities (KEV) catalog as a primary source for vulnerability identification. This catalog is BEST described as:

A.An application vulnerability scanning tool
B.A commercial threat intelligence feed
C.A configuration vulnerability assessment benchmark
D.A list of known exploited vulnerabilities maintained by the US government
AnswerD

The KEV catalog is maintained by the US Cybersecurity and Infrastructure Security Agency, listing vulnerabilities with confirmed exploitation in the wild. It satisfies the stem by providing an authoritative government-sourced feed for prioritising vulnerability identification, rather than a general vulnerability database.

Why this answer

The CISA Known Exploited Vulnerabilities (KEV) catalog is a publicly maintained list published by the US Cybersecurity and Infrastructure Security Agency (CISA) that enumerates vulnerabilities confirmed to be actively exploited in the wild. It is not a scanning tool, commercial feed, or configuration benchmark — it is a curated reference list used to prioritize patching. Organizations use it to drive remediation deadlines, especially under Binding Operational Directive 22-01 for US federal agencies.

Exam trap

CRISC often tests whether candidates confuse a curated vulnerability list (KEV) with a scanning tool or commercial feed — the trap is assuming any vulnerability-related resource must be a scanner or paid intelligence service.

How to eliminate wrong answers

Option A is wrong because the KEV catalog does not scan anything — it is a static, curated list, not a vulnerability scanner like Nessus or Qualys. Option B is wrong because KEV is a free, publicly available US government resource, not a commercial threat intelligence feed such as Recorded Future or Mandiant. Option C is wrong because configuration benchmarks (e.g., CIS Benchmarks, DISA STIGs) define secure configuration baselines, whereas KEV lists specific exploited CVEs.

918
MCQeasy

When reporting risk and control monitoring results to the board of directors, which of the following formats is MOST effective?

A.Narrative reports describing findings in paragraphs.
B.Visual dashboards with key metrics and trend indicators.
C.Oral summary without supporting documentation.
D.Detailed spreadsheets with raw data for each control.
AnswerB

Visual dashboards with key metrics and trend indicators translate complex risk and control data into patterns and direction that a board can absorb quickly. They satisfy the stem's effectiveness requirement by supporting governance decisions, unlike dense tabular or purely technical reporting.

Why this answer

The board of directors requires a high-level, synthesized view of risk and control effectiveness to make strategic decisions. Visual dashboards with key metrics and trend indicators are most effective because they enable rapid comprehension of the risk posture, control performance, and emerging issues without overwhelming directors with granular data. This format aligns with the principle of reporting to governance bodies, which focuses on actionable insights rather than operational details.

Exam trap

The trap here is that candidates may choose narrative reports (A) thinking they provide 'complete context,' but CRISC emphasizes that board reporting must be concise and visual to support rapid strategic decisions, not exhaustive detail.

How to eliminate wrong answers

Option A is wrong because narrative reports in paragraphs are time-consuming for board members to parse and can obscure critical trends or outliers, making them less effective for quick decision-making at the governance level. Option C is wrong because an oral summary without supporting documentation lacks verifiable evidence and audit trail, which is unacceptable for formal board reporting where accountability and traceability are required. Option D is wrong because detailed spreadsheets with raw data for each control present information overload, burying key risk indicators and trends in granularity that is inappropriate for a board whose focus is strategic oversight, not operational control details.

919
MCQeasy

Based on the exhibit, what is the primary risk response strategy demonstrated by this firewall rule?

A.Risk Transfer
B.Risk Acceptance
C.Risk Mitigation
D.Risk Avoidance
AnswerC

The firewall blocks specific IP ranges, reducing the probability of attacks.

Why this answer

The firewall rule denies inbound traffic on TCP port 443 (HTTPS) from any source to any destination. This directly reduces the attack surface by blocking a specific protocol, which is a classic risk mitigation action. By implementing a technical control to reduce the likelihood or impact of a threat, the organization is applying risk mitigation, not transferring, accepting, or avoiding the risk entirely.

Exam trap

The trap here is confusing risk mitigation (reducing risk with controls) with risk avoidance (eliminating the risk by ceasing the activity), as candidates often think blocking a port is 'avoiding' the risk when it is actually reducing it while the underlying service remains operational.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial impact of a risk to a third party (e.g., insurance or outsourcing), not implementing a firewall rule. Option B is wrong because risk acceptance means formally acknowledging the risk without taking action to reduce it, whereas this rule actively reduces exposure. Option D is wrong because risk avoidance would mean eliminating the activity or asset that creates the risk (e.g., decommissioning the web server entirely), not just blocking a specific port.

920
MCQeasy

A small manufacturing company is conducting its first IT risk assessment. The company has a flat network with no segmentation, and all employees have administrative access to their workstations. The risk practitioner identifies that a malware infection on one workstation could easily spread to the entire network. The company has a limited budget for IT security improvements. Which of the following risk treatment options is MOST cost-effective and practical?

A.Accept the risk because the company's data is not highly sensitive.
B.Deploy endpoint protection software on all workstations and restrict administrative rights for users.
C.Implement network segmentation and a next-generation firewall.
D.Purchase cyber insurance to cover potential losses.
AnswerB

Low cost, high impact on limiting malware spread.

Why this answer

The most cost-effective and practical because deploying endpoint protection software provides immediate defense against known malware, while restricting administrative rights prevents users from installing unauthorized software or making system changes that could introduce malware. This combination directly addresses the root cause of the risk—unrestricted user privileges and lack of basic malware defenses—without requiring expensive network redesign or ongoing insurance premiums.

Exam trap

The trap here is that candidates may choose network segmentation (Option C) as the ideal technical solution, but the question emphasizes cost-effectiveness and practicality for a small company with a limited budget, making the simpler, cheaper controls in Option B the better choice.

How to eliminate wrong answers

Option A is wrong because accepting the risk ignores the high likelihood and potential impact of a malware infection spreading across a flat network, even if data is not highly sensitive; operational downtime and recovery costs can be significant for a small company. Option C is wrong because network segmentation and a next-generation firewall are more expensive and complex to implement than endpoint protection and privilege restriction, making them less practical for a limited budget. Option D is wrong because cyber insurance does not reduce the likelihood or impact of a malware infection; it only provides financial compensation after a loss, which may not cover all costs (e.g., reputational damage, operational downtime) and often requires proof of basic security controls.

921
MCQmedium

Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a control?

A.Control exception rate
B.Number of risk events in the last quarter
C.Time since last audit
D.Percentage of employees who completed security awareness training
AnswerA

Control exception rate quantifies how often a control fails to operate as intended, directly evidencing control effectiveness. Risk appetite thresholds, incident counts and loss totals measure outcomes or tolerance rather than the control's own operating performance.

Why this answer

A Key Control Indicator (KCI) measures how well a specific control is operating. Control exception rate — the frequency with which a control fails or is bypassed — directly measures control effectiveness, making it a textbook KCI. The other options measure risk events, audit timing, or training completion, which are KRIs or compliance metrics.

Exam trap

CRISC often tests the distinction between KCIs (control effectiveness) and KRIs (risk exposure); candidates who pick 'number of risk events' or 'training completion' confuse risk indicators with control indicators.

How to eliminate wrong answers

Option B is wrong because the number of risk events is a Key Risk Indicator (KRI) measuring realized risk, not control performance. Option C is wrong because time since last audit is an assurance scheduling metric, not a measure of control effectiveness. Option D is wrong because training completion percentage measures a training program's reach (a compliance or awareness metric), not the operational effectiveness of a specific control.

922
MCQmedium

A risk practitioner at a healthcare payer is building the risk identification taxonomy for a new claims-processing platform. The CISO asks why the taxonomy must explicitly distinguish between a 'threat event' and a 'loss event' rather than treating both as 'risk' in the register. Which statement BEST justifies that distinction?

A.A threat event is measured only in monetary terms, while a loss event is measured only in qualitative severity ratings such as high, medium, or low.
B.A threat event is recorded only in the risk register, while a loss event is recorded only in the incident management system, so the two never need to be linked.
C.A threat event is always externally sourced from attackers, whereas a loss event is always internally sourced from employee error or process failure.
D.A threat event is a potential occurrence that may exploit a vulnerability, while a loss event is a realized occurrence that has already produced an adverse business impact.
AnswerD

This is the correct framing. In CRISC terminology, a threat event is a circumstance or occurrence with the potential to cause loss by exploiting a vulnerability; it has not yet produced impact. A loss event is the materialized outcome that has actually generated adverse business, financial, or regulatory consequences. Separating them lets the practitioner model likelihood against threats and model impact only against realized events, which keeps scenario estimation and control design logically consistent across the taxonomy.

Why this answer

The taxonomy must separate potential from realized occurrences because likelihood estimation attaches to threat events while impact estimation attaches to events that have actually caused harm. A threat event may exploit a vulnerability without ever producing loss, and a loss event confirms that the exposure materialized. Keeping them distinct allows the practitioner to model scenarios, set likelihood and impact parameters independently, and later feed realized outcomes back into the assessment to validate or adjust prior estimates.

Exam trap

The trap here is assuming the difference between a threat event and a loss event is who caused it rather than whether adverse impact has actually been realized.

923
MCQmedium

Which of the following is the primary purpose of a Key Risk Indicator (KRI)?

A.Measure the effectiveness of controls
B.Document historical incidents
C.Comply with regulatory requirements
D.Provide early warning of changing risk levels
AnswerD

A Key Risk Indicator provides early warning by tracking measurable metrics against defined thresholds, signalling when risk exposure is trending beyond acceptable tolerance. This satisfies the stem's requirement for the primary purpose: enabling proactive risk response before incidents materialise, rather than retrospective reporting or control testing.

Why this answer

The primary purpose of a Key Risk Indicator (KRI) is to provide an early warning of changing risk levels, enabling proactive risk management before an adverse event occurs. KRIs track specific metrics that signal shifts in risk exposure, such as the number of unpatched critical vulnerabilities or failed login attempts, allowing organizations to adjust controls or resources in advance. This forward-looking function distinguishes KRIs from lagging indicators like control effectiveness metrics or incident logs.

Exam trap

The trap here is that candidates confuse KRIs with KPIs or control metrics, mistakenly thinking KRIs measure control effectiveness (Option A) rather than providing early warning of risk changes.

How to eliminate wrong answers

Option A is wrong because measuring the effectiveness of controls is the purpose of Key Performance Indicators (KPIs) or control testing, not KRIs; KRIs focus on risk exposure changes, not control performance. Option B is wrong because documenting historical incidents is the role of incident logs or post-mortem reports, whereas KRIs are forward-looking and designed to predict rather than record past events. Option C is wrong because while KRIs may support regulatory compliance indirectly, their primary purpose is not compliance; compliance requirements are met through specific control frameworks and reporting, not through the early-warning function of KRIs.

924
MCQmedium

An incident occurs due to a control that was thought to be automated but was actually manual. The risk register did not reflect this. What is the MOST likely root cause?

A.Insufficient control monitoring and verification
B.Inadequate risk assessment methodology
C.Poorly designed controls
D.Lack of management support for risk management
AnswerA

The register assumed automation that never existed, so nobody validated the control's actual operating mode. Insufficient control monitoring and verification let the manual reality go undetected, meaning the risk assessment rested on an unconfirmed design assumption rather than tested evidence.

Why this answer

The core issue is that the control was believed to be automated but was actually manual, and this discrepancy was not captured in the risk register. This indicates a failure in the ongoing process of verifying that controls are operating as designed, which is the essence of control monitoring and verification. Without periodic testing or validation, the organization cannot confirm the control's effectiveness or its true nature, leading to an inaccurate risk posture.

Exam trap

The CRISC exam often tests the distinction between a control being 'poorly designed' versus 'not operating as intended' — the trap here is that candidates see a control failure and immediately assume a design flaw, when the real issue is a lack of verification that the control's implementation matches its documented design.

How to eliminate wrong answers

Option B is wrong because an inadequate risk assessment methodology would typically result in a failure to identify or evaluate risks initially, not a failure to detect that an existing control's implementation (automated vs. manual) has changed or was misrepresented. Option C is wrong because the control itself may be well-designed for its intended purpose; the root cause is the lack of verification that it is actually automated, not a design flaw. Option D is wrong because while management support is important, the immediate technical root cause is the absence of a monitoring and verification process that would have caught the discrepancy; lack of support is a broader organizational issue, not the most direct cause of this specific incident.

925
Drag & Dropmedium

Sequence the steps for developing a disaster recovery plan (DRP).

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

DRP development begins with BIA, prioritization, strategy selection, documentation, and testing.

926
MCQhard

A healthcare organization's risk register shows that a critical server lacks vendor support and has a high inherent risk of failure. The risk owner proposes to implement redundant hardware and a failover cluster. The cost of the redundancy is $200,000, while the estimated annual loss from failure is $150,000. Which factor is MOST important for the risk practitioner to consider when evaluating this proposed risk response?

A.The likelihood of the server failing in the next year
B.The cost of the control compared to the expected loss
C.The risk tolerance of the IT department
D.The residual risk after implementing the redundancy
AnswerB

The fundamental principle of risk response is that the cost of mitigation should not exceed the expected loss. Here, the control costs $200,000 annually while the expected loss is $150,000, indicating a negative return on security investment. The risk practitioner should recommend a more cost-effective solution or consider risk acceptance, as the proposed redundancy is not economically justified based on the given figures.

Why this answer

The risk practitioner must perform a cost-benefit analysis. The proposed control costs $200,000, while the expected annual loss is $150,000, meaning the control costs more than the risk it mitigates. Unless there are intangible or regulatory factors, the response is not cost-effective.

The most important factor is the comparison of control cost to expected loss, which guides whether to mitigate, accept, or seek a cheaper alternative.

Exam trap

The trap here is focusing on residual risk or likelihood without performing the cost-benefit calculation that reveals the control is more expensive than the potential loss.

927
MCQeasy

A risk practitioner is selecting a risk analysis technique for a new payment processing system. The team has limited historical loss data, wants to incorporate expert judgment, and needs to prioritize risks for management review. Which technique is MOST appropriate?

A.Business impact analysis to determine recovery time and recovery point objectives for the payment system.
B.Fault tree analysis to trace the logical combinations of failures that could cause a payment outage.
C.Monte Carlo simulation using historical loss distributions from the past five years.
D.Delphi technique to gather and converge expert opinions on likelihood and impact.
AnswerD

The Delphi technique collects anonymous expert judgments over iterative rounds until consensus emerges, which fits the lack of historical data and the need to use expert opinion. It reduces bias from dominant personalities and produces a defensible ranking of risks for management review. This makes it well suited to prioritizing risks for a new payment system where loss history is thin.

Why this answer

When historical loss data is scarce and expert judgment must be captured, the Delphi technique provides a structured, anonymous, iterative approach that converges on consensus estimates of likelihood and impact. It reduces individual bias and yields a defensible prioritization suitable for management review. Quantitative methods like Monte Carlo require reliable data, while fault tree and business impact analysis serve different analytical purposes.

Exam trap

The trap here is defaulting to a quantitative method like Monte Carlo when the scenario explicitly states that historical loss data is limited.

928
MCQeasy

Which of the following is an example of a preventive control?

A.Encryption of sensitive data
B.Incident response plan
C.Intrusion detection system
D.Security logs
AnswerA

Encryption renders sensitive data unreadable to unauthorised parties before an incident occurs, stopping disclosure rather than detecting it afterwards. That proactive blocking of the threat event is what defines a preventive control, unlike detective or corrective controls that act during or after compromise.

Why this answer

Encryption of sensitive data is a preventive control because it stops unauthorized parties from reading the data in the first place, even if they gain access to the storage or transmission medium. It acts before an incident causes harm by rendering the data unintelligible without the correct key. This aligns with the CRISC definition of preventive controls, which are designed to deter or stop an event from occurring or reduce its impact before it happens.

Exam trap

CRISC often tests the distinction between control types by presenting controls that seem protective but are actually detective or corrective, such as intrusion detection systems or incident response plans, leading candidates to misclassify them as preventive.

How to eliminate wrong answers

Option B is wrong because an incident response plan is a corrective control—it guides actions after an incident has occurred to contain and recover. Option C is wrong because an intrusion detection system is a detective control—it identifies and alerts on malicious activity but does not prevent it. Option D is wrong because security logs are a detective control—they record events for later analysis and auditing, not prevention.

929
MCQeasy

During a quarterly control review, the risk team discovers that a key manual approval control was bypassed in 15% of transactions due to a recent process change. What is the FIRST action the risk practitioner should take?

A.Restore the original control process immediately.
B.Conduct a root cause analysis to determine why the bypass occurred.
C.Update the risk register to reflect the increased residual risk.
D.Escalate to senior management with a recommendation for disciplinary action.
AnswerB

Root cause analysis establishes why the process change caused the bypass before remediation is chosen, preventing recurrence rather than treating symptoms. Investigating first satisfies the need to understand the control failure's origin, since corrective or disciplinary action without diagnosis risks repeating the same gap.

Why this answer

The first action is to conduct a root cause analysis (B) to understand why the control was bypassed, as required by the CRISC process of identifying the underlying cause before taking corrective or compensating actions. This aligns with the risk monitoring and reporting domain, where a control deficiency must be analyzed to determine if it is a systemic process failure, a training gap, or a deliberate override. Without this analysis, any subsequent action—such as restoring the original control or updating the risk register—may be premature or misdirected.

Exam trap

The trap here is that candidates often jump to 'restore the original control' (A) because it seems like a quick fix, but CRISC emphasizes that the first step in any control deficiency is to understand the root cause before taking action.

How to eliminate wrong answers

Option A is wrong because immediately restoring the original control process may not address the root cause of the bypass, could introduce new inefficiencies, and ignores the possibility that the process change was intentional for valid business reasons. Option C is wrong because updating the risk register to reflect increased residual risk is a subsequent step, not the first action; the risk practitioner must first understand the cause and impact of the bypass before documenting the risk. Option D is wrong because escalating to senior management with a recommendation for disciplinary action is premature without first analyzing the root cause; the bypass may be due to a process design flaw or lack of training rather than intentional misconduct.

930
MCQeasy

A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?

A.Risk treatment plan
B.Risk register
C.Risk management policy
D.Risk assessment methodology
AnswerC

The risk management policy establishes the organisation's overall intent, scope, objectives and governance for risk, providing the mandate from which frameworks, processes and procedures are subsequently derived. Creating it first ensures all later risk activities align with approved direction.

Why this answer

A risk management policy establishes the principles, objectives, and responsibilities for risk management, providing a foundation for all other risk management activities.

931
MCQeasy

What is the primary purpose of a risk heat map in IT risk reporting?

A.Show control performance metrics
B.Display risk trends over time
C.Provide a visual representation of risk levels
D.List upcoming risk events
AnswerC

A risk heat map plots likelihood against impact, using colour coding to show which risks sit in high, medium or low bands. This satisfies the reporting need by letting management and the board quickly compare risk levels across the portfolio and prioritise treatment.

Why this answer

A risk heat map visualizes risks based on likelihood and impact, helping prioritize attention.

932
MCQhard

A risk manager is reviewing the risk register and notices that several risks have been identified as 'high' but no risk owner has been assigned. Which of the following is the MOST appropriate action to ensure proper risk identification going forward?

A.Provide training to risk owners on their responsibilities.
B.Assign risk owners after the risk assessment is completed.
C.Conduct an audit of the risk identification process.
D.Update the risk identification policy to mandate that risk owners be identified during the initial risk identification phase.
AnswerD

Amending the risk identification policy embeds ownership assignment as a mandatory step, preventing recurrence rather than fixing individual register entries. This addresses the root cause: the process itself permitted risks to be recorded without accountable owners.

Why this answer

The risk identification phase should include assigning risk owners to ensure accountability from the outset. Without a risk owner, identified risks cannot be properly managed, monitored, or escalated. Mandating owner assignment during initial identification embeds ownership into the process, preventing gaps in risk governance.

Exam trap

The trap here is that candidates often choose an audit (Option C) as a corrective action, but the question asks for the MOST appropriate action to ensure proper risk identification going forward, which requires a preventive policy change, not a retrospective review.

How to eliminate wrong answers

Option A is wrong because providing training to risk owners assumes they have already been assigned, but the core issue is that no owners exist for high risks; training does not solve the missing assignment. Option B is wrong because assigning risk owners after the risk assessment is completed delays accountability and violates the principle that owners should be identified during risk identification to enable timely response planning. Option C is wrong because conducting an audit of the risk identification process is a detective control that identifies past failures but does not proactively ensure proper identification going forward; it does not mandate owner assignment.

933
MCQhard

A risk practitioner is assessing a customer-facing API that processes payment tokens. The team has documented the threat community, the vulnerability, and the potential loss magnitude, but the assessment stalls because no one can agree on how often the threat would realistically attempt exploitation. Which factor is the practitioner attempting to establish to complete this scenario-based risk analysis?

A.Threat event frequency, describing how often the threat community is expected to act against the asset.
B.Control effectiveness rating for the compensating controls already deployed around the API.
C.Asset criticality tier assigned by the business owner based on revenue dependency.
D.Residual risk level remaining after the current control set is applied to the API.
AnswerA

The disagreement concerns how often exploitation would realistically be attempted, which is precisely the frequency of threat events acting against the asset. Establishing this rate lets the team combine it with vulnerability and loss magnitude to derive risk. The scenario explicitly names threat community, vulnerability, and loss magnitude as settled, leaving frequency as the missing factor.

Why this answer

Scenario-based analysis needs a frequency dimension to convert an identified vulnerability and loss magnitude into a risk estimate. The team has the threat community, the vulnerability, and the loss exposure; the unresolved question of how often exploitation would be attempted is the threat event frequency. Without it, no defensible risk calculation or prioritization can be completed.

Exam trap

The trap here is conflating how often an attack is attempted with how likely it is to succeed, which is a separate vulnerability-based factor.

934
Multi-Selectmedium

A company is performing a qualitative risk analysis for a new cloud migration project. Which TWO of the following are recognized limitations of qualitative risk analysis?

Select 2 answers
A.Risk ratings are not easily comparable across different organizations
B.It requires extensive historical data
C.It is time-consuming and complex to perform
D.Results are subjective and depend on the assessor's judgment
E.It provides financially precise loss estimates
AnswersA, D

Qualitative ratings rely on subjective scales and organisational context, so a 'high' in one company rarely maps to a 'high' elsewhere. This subjectivity prevents meaningful cross-organisational comparison, satisfying the limitation that ratings are not easily comparable between different organisations.

Why this answer

Option A is correct because qualitative risk analysis produces ordinal ratings (such as High/Medium/Low) that are defined by each organization's own scales and risk criteria, so the resulting ratings lack a common quantitative baseline and cannot be reliably compared across different organizations. Option D is correct because qualitative analysis relies on expert opinion, experience, and judgment rather than numeric measurement, making the ratings inherently subjective and dependent on the assessor's bias, expertise, and interpretation. Options B, C, and E are not limitations of qualitative analysis: it is specifically chosen because it requires little historical data (B is wrong), it is generally faster and simpler than quantitative analysis (C is wrong), and it does not produce financially precise loss estimates—that is the domain of quantitative risk analysis using techniques like Monte Carlo simulation or expected monetary value (E is wrong).

Exam trap

CRISC often tests whether candidates confuse limitations of qualitative vs. quantitative analysis — the trap is attributing quantitative traits (historical data, financial precision) to qualitative methods.

935
MCQeasy

A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which risk response is most appropriate?

A.Mitigate by applying the patch
B.Avoid by taking the application offline
C.Accept the risk
D.Transfer via insurance
AnswerA

Applying the vendor patch removes the unpatched-software condition enabling SQL injection, reducing likelihood and impact to acceptable levels. Mitigation is appropriate because a known, available fix exists, satisfying the assessment finding rather than transferring, avoiding or accepting the risk.

Why this answer

Applying the vendor-released patch directly reduces the likelihood and impact of the SQL injection vulnerability, which is the definition of risk mitigation. Since a patch exists and the application is critical, mitigation is both feasible and the most appropriate response — it addresses the root cause rather than avoiding, accepting, or transferring the consequence.

Exam trap

CRISC often tests the distinction between mitigation and avoidance — candidates pick 'take offline' thinking it is the safest response, but avoidance is only appropriate when the risk cannot be mitigated cost-effectively.

How to eliminate wrong answers

Option B is wrong because taking a critical application offline is risk avoidance, which is disproportionate — it eliminates the risk by eliminating the business function, causing unacceptable operational impact when a patch is available. Option C is wrong because accepting the risk is inappropriate for a critical application with a known, patchable SQL injection vulnerability — acceptance is reserved for low-impact risks or when no cost-effective response exists. Option D is wrong because transferring via insurance compensates financial loss after an incident but does not prevent the SQL injection from occurring or protect the data — it is a financial response, not a technical control.

936
MCQhard

An organization uses a quantitative risk analysis method. The annualized loss expectancy (ALE) for a specific risk is calculated as $500,000. The cost of implementing a control is $150,000 per year, and it is expected to reduce the ALE by 80%. What is the net benefit of implementing the control?

A.$50,000
B.$400,000
C.$250,000
D.$350,000
AnswerC

The control cuts the $500,000 ALE by 80%, giving a $400,000 reduction in expected annual loss. Subtracting the $150,000 annual control cost yields a net benefit of $250,000, satisfying the stem's quantitative comparison of risk reduction against control cost.

Why this answer

The current ALE is $500,000. An 80% reduction means the ALE decreases by $400,000, resulting in a new ALE of $100,000. The annual control cost is $150,000.

The net benefit is the reduction in ALE ($400,000) minus the control cost ($150,000), which equals $250,000. Option C is correct because it correctly calculates the net benefit as the risk reduction minus the control cost.

Exam trap

The trap here is that candidates often confuse the gross reduction in ALE ($400,000) with the net benefit, forgetting to subtract the annual control cost, leading them to select Option B.

How to eliminate wrong answers

Option A is wrong because $50,000 would result from incorrectly subtracting the control cost from the new ALE ($100,000 - $150,000 = -$50,000) or miscomputing the reduction. Option B is wrong because $400,000 is the gross reduction in ALE, not the net benefit after subtracting the $150,000 control cost. Option D is wrong because $350,000 would result from subtracting the control cost from the original ALE ($500,000 - $150,000) or from incorrectly calculating the reduction as 80% of the control cost.

937
MCQeasy

A financial institution is selecting a risk assessment methodology for evaluating cybersecurity risks across its critical systems. Which of the following is the PRIMARY consideration when choosing between qualitative and quantitative approaches?

A.The skill level of the risk assessment team
B.The organization's risk appetite statement
C.Compliance with regulatory requirements
D.Availability of reliable numerical data for risk factors
AnswerD

Quantitative methods require credible numerical data for likelihood and impact; without it, results are unreliable. Qualitative approaches suit scenarios lacking such data, so data availability is the primary driver when selecting between the two for critical systems.

Why this answer

The choice between qualitative and quantitative risk assessment hinges on the availability of reliable numerical data. Quantitative methods require precise, objective data (e.g., asset values, historical loss frequencies, exposure factors) to compute metrics like Annualized Loss Expectancy (ALE). Without such data, the results would be misleading, making qualitative approaches (using ordinal scales and expert judgment) more appropriate.

This is the primary technical gate, as it directly determines the feasibility and validity of the quantitative model.

Exam trap

The trap here is that candidates confuse 'primary consideration' with 'most important factor overall' and pick regulatory compliance (C), but the question specifically asks for the consideration that determines the choice between the two methodologies, which is data availability.

How to eliminate wrong answers

Option A is wrong because while team skill affects execution, it is not the primary consideration; a skilled team can adapt to either methodology, but the data foundation must exist first. Option B is wrong because the risk appetite statement guides risk acceptance thresholds, not the selection of a methodology; both qualitative and quantitative outputs can be mapped to appetite. Option C is wrong because regulatory requirements typically mandate a risk assessment process (e.g., NIST CSF, ISO 27001) but do not prescribe a specific methodology (qualitative vs. quantitative); compliance can be achieved with either.

938
Multi-Selecthard

An organization is implementing IEC 62443 for its industrial control systems. Which THREE of the following are key requirements of IEC 62443? (Select three.)

Select 3 answers
A.Applying security levels (SL) to each zone based on risk
B.Ensuring all industrial components have a secure development lifecycle (SDL)
C.Using proprietary protocols to enhance performance
D.Conducting a risk assessment to identify security zones and conduits
E.Implementing a single-vendor solution to reduce complexity
AnswersA, B, D

IEC 62443 requires segmentation into zones and conduits, with each zone assigned a target security level derived from assessed risk. This risk-based SL assignment is a foundational requirement, directly matching the stem's option and governing the countermeasures each zone must implement.

Why this answer

Option A is correct because IEC 62443 requires assigning Security Levels (SL 1–4) to each zone and conduit based on the assessed risk, so that target security levels can be defined and verified for the assets within them. Option B is correct because IEC 62443-4-1 specifies secure development lifecycle (SDL) requirements for product suppliers, including practices such as threat modeling, secure coding, and vulnerability handling for industrial components. Option D is correct because the standard mandates a risk assessment as the foundation for identifying zones and conduits, which are then used to segment the ICS network and apply appropriate countermeasures.

Option C is incorrect because IEC 62443 promotes open, standards-based and interoperable protocols rather than proprietary ones, which can hinder security monitoring and integration. Option E is incorrect because the standard favors defense-in-depth and segmentation across multiple vendors and layers, not single-vendor lock-in, which does not by itself reduce risk.

Exam trap

CRISC often tests the misconception that IEC 62443 mandates proprietary or single-vendor solutions, when in fact it is a risk-based, multi-vendor standard centered on zones, conduits, security levels, and secure development.

939
MCQhard

A risk practitioner is evaluating the risk that a cloud provider's regional outage disrupts a company's order management system. The company has a recovery time objective (RTO) of four hours, but the provider's documented regional recovery capability is estimated at twelve hours. Which of the following BEST characterizes the risk exposure this gap represents?

A.A control deficiency in the provider's disaster recovery testing program.
B.An inherent risk that cannot be mitigated through any contractual arrangement.
C.A risk that should be accepted because cloud outages are outside the company's control.
D.A residual risk that exceeds the company's risk appetite for this process.
AnswerD

The company requires recovery within four hours, but the provider's capability implies up to twelve hours of downtime, so the residual exposure after existing arrangements exceeds the stated tolerance. That gap is a residual risk above appetite, which should trigger treatment options such as multi-region design, alternate providers, or revised recovery objectives. It is the clearest characterization of the exposure described.

Why this answer

The four-hour recovery objective against a twelve-hour provider capability means the remaining exposure after current arrangements exceeds what the company is willing to tolerate. That is residual risk above appetite, and it should drive treatment decisions such as multi-region architecture, alternate recovery arrangements, or renegotiated service levels rather than being accepted or dismissed as inherent.

Exam trap

The trap here is treating the gap as an inherent, uncontrollable cloud risk, when the company can still reduce impact through architecture, contracts, and contingency planning.

940
Multi-Selecteasy

Which TWO of the following are examples of external risk identification sources? (Choose two.)

Select 2 answers
A.Incident response reports from the security operations center
B.Regulatory bulletins from government agencies
C.Internal vulnerability scan reports
D.Threat intelligence feeds from industry sources
E.Industry benchmarking reports
AnswersB, D

External compliance requirements.

Why this answer

Regulatory bulletins from government agencies (Option B) are external risk identification sources because they originate outside the organization and provide authoritative information on compliance requirements, legal changes, and mandated controls. Threat intelligence feeds from industry sources (Option D) are also external, as they aggregate data on emerging threats, vulnerabilities, and attack patterns from third-party vendors or open-source communities, helping organizations proactively adjust defenses. The other options (A, C, E) are internal sources or are not primarily used for risk identification from an external perspective.

Exam trap

The trap here is that candidates often confuse internal operational reports (like incident response or vulnerability scans) with external sources, failing to recognize that 'external' means information originating outside the organization's own systems and processes.

941
Multi-Selectmedium

Which THREE of the following are key considerations when selecting a risk response option?

Select 3 answers
A.Cost-benefit analysis of controls
B.Impact of the risk without controls
C.Risk appetite of the organization
D.Current control effectiveness
E.Legal and regulatory requirements
AnswersA, C, E

Cost-effectiveness is crucial.

Why this answer

A cost-benefit analysis of controls (Option A) is a key consideration because it ensures that the cost of implementing a risk response (e.g., a technical control like an intrusion prevention system or encryption) does not exceed the value of the asset being protected or the expected reduction in risk. This aligns with the principle of cost-effective risk mitigation, where the residual risk must be acceptable relative to the investment.

Exam trap

The trap here is that candidates confuse factors used in risk assessment (like impact without controls or current control effectiveness) with factors used in risk response selection, which specifically requires evaluating organizational appetite, cost-benefit, and mandatory legal/regulatory obligations.

942
MCQhard

A financial institution is implementing a new risk monitoring tool that aggregates data from multiple sources. The tool is expected to provide real-time dashboards for risk committees. However, during user acceptance testing, the dashboards show inconsistent data due to time zone differences across sources. What is the best approach to resolve this?

A.Modify the dashboard to display each source's local time separately.
B.Ask each source to adjust their time zone to the corporate headquarters time zone.
C.Standardize all timestamps to Coordinated Universal Time (UTC) during data ingestion.
D.Use the time zone of the majority of sources and convert others.
AnswerC

Normalising every source's timestamps to UTC at ingestion removes the offset discrepancies causing inconsistent dashboards. Converting once, centrally, ensures all aggregated records share one comparable time axis, so real-time committee views reconcile correctly regardless of each source's local time zone.

Why this answer

Standardizing all timestamps to Coordinated Universal Time (UTC) during data ingestion ensures a single, unambiguous reference point for all aggregated data. This eliminates the root cause of inconsistency—differing local time zones—at the point of data entry, allowing the real-time dashboards to display consistent, comparable metrics regardless of the source's geographic location. This approach aligns with the principle of normalizing data at the earliest stage of the data pipeline, which is a fundamental practice in risk monitoring and reporting.

Exam trap

The trap here is that candidates often choose Option A, thinking that displaying local times separately is a 'user-friendly' solution, but they fail to recognize that the core requirement is consistent, comparable data for risk committees, not individual source readability.

How to eliminate wrong answers

Option A is wrong because displaying each source's local time separately does not resolve the inconsistency; it merely exposes the problem, making it impossible for risk committees to compare data across sources in a unified, real-time view. Option B is wrong because asking each source to adjust their time zone to corporate headquarters time is impractical, error-prone, and introduces a single point of failure; it also fails to account for daylight saving time changes and does not scale across multiple time zones. Option D is wrong because using the time zone of the majority of sources and converting others introduces bias and still leaves a subset of data with potential conversion errors, especially during daylight saving transitions, and does not guarantee consistency across all sources.

943
MCQmedium

A risk manager is prioritizing risks based on their inherent risk scores. Which of the following factors should be considered when prioritizing treatment actions?

A.The cost-benefit analysis of controls
B.The residual risk after controls
C.Only the inherent risk score
D.The likelihood of control failure
AnswerA

Prioritising treatment requires weighing each control's cost against the risk reduction it delivers, so inherent scores alone are insufficient. Cost-benefit analysis determines whether a treatment is justified, ensuring resources target risks where mitigation value exceeds expense.

Why this answer

When prioritizing treatment actions, the risk manager must weigh the cost of implementing controls against the benefit (risk reduction) they deliver. A high inherent risk may not justify an expensive control if the residual risk is already acceptable or the control cost exceeds the expected loss. Cost-benefit analysis ensures treatment is economically justified and resources are allocated where they reduce risk most efficiently.

Exam trap

CRISC often tests the misconception that the highest inherent risk always gets treated first — the trap is ignoring that cost-benefit analysis determines whether and how to treat.

How to eliminate wrong answers

Option B is wrong because residual risk is an output of treatment, not the primary input for prioritizing which treatment to apply — it informs whether further action is needed but does not by itself rank options. Option C is wrong because prioritizing on inherent risk score alone ignores control cost, feasibility, and business impact, leading to over- or under-investment. Option D is wrong because likelihood of control failure is a factor in control design and monitoring, not the primary basis for prioritizing treatment actions across the risk portfolio.

944
Multi-Selectmedium

A risk practitioner is evaluating the organization's vulnerability management programme. The organization scans its internal network weekly, but the CIO is concerned that critical internet-facing services are not adequately covered. Which TWO of the following changes would MOST improve the identification of exploitable vulnerabilities on externally exposed assets? (Choose two.)

Select 2 answers
A.Require business units to self-attest quarterly that their internet-facing applications have no known vulnerabilities.
B.Implement continuous external attack surface scanning that includes discovery of unknown internet-facing assets.
C.Correlate vulnerability scan results with threat intelligence feeds to prioritize vulnerabilities known to be actively exploited.
D.Deploy a web application firewall (WAF) in front of all internet-facing applications and enable blocking mode.
E.Increase the frequency of credentialed internal vulnerability scans from weekly to daily.
AnswersB, C

Continuous external scanning detects exposed services and previously unknown assets, such as shadow IT or forgotten cloud instances, that a weekly internal scan would miss. Because attackers target exactly these externally reachable services, identifying and inventorying them is a prerequisite to assessing and remediating exploitable vulnerabilities on the true external attack surface.

Why this answer

Improving identification of exploitable vulnerabilities on internet-facing services requires seeing the full external attack surface and knowing which findings matter. Continuous external attack surface scanning discovers and inventories exposed assets, including unknown ones, while threat intelligence correlation prioritizes vulnerabilities that attackers are actively exploiting, focusing remediation where it reduces real risk.

Exam trap

The trap here is assuming that more frequent internal scanning or a protective WAF identifies externally exposed vulnerabilities, when discovery and prioritization are the actual gaps.

945
Multi-Selectmedium

A company is assessing the impact of a potential ransomware attack. Which TWO impact categories are considered operational impacts?

Select 2 answers
A.Share price impact
B.System downtime
C.Regulatory fines
D.Productivity loss
E.Customer trust loss
AnswersB, D

System downtime directly satisfies the operational impact criterion, as it halts service delivery and disrupts business processes. Unlike financial or reputational categories, operational impacts concern the availability and functioning of systems and people. Ransomware encrypting production servers causes exactly this disruption, making downtime a core operational consequence.

Why this answer

Operational impacts are those that directly affect the day-to-day functioning of the business, so B (System downtime) is correct because a ransomware attack encrypting servers or endpoints halts services and prevents normal operations until systems are restored. D (Productivity loss) is also correct because employees cannot perform their tasks while systems, files, and applications are unavailable, directly reducing operational output. A (Share price impact) is a financial/market impact rather than an operational one, and C (Regulatory fines) is a legal/compliance impact.

E (Customer trust loss) is a reputational impact, so it does not belong in the operational category.

Exam trap

CRISC often tests the overlap between impact categories, tempting candidates to classify financial consequences like fines or share price as operational because they stem from an operational event.

946
MCQeasy

An organization wants to promote a risk-aware culture. Which initiative best supports this goal?

A.Focusing only on technical controls
B.Limiting risk awareness training to IT staff
C.Punishing employees who cause security incidents
D.Encouraging incident reporting without blame
AnswerD

Blame-free incident reporting removes the fear of punishment, so staff surface errors and near-misses early. This transparency gives management accurate risk data and reinforces that risk identification is everyone's responsibility, which is the foundation of a risk-aware culture.

Why this answer

Encouraging incident reporting without blame directly supports a risk-aware culture by removing the fear of punishment, which motivates employees to report issues promptly. This allows the organization to identify and respond to risks early, rather than hiding them, and aligns with the risk response principle of learning from incidents to improve controls.

Exam trap

The trap here is that candidates may confuse a risk-aware culture with strict enforcement or technical fixes, but CRISC emphasizes that culture is built on trust and open communication, not punishment or siloed training.

How to eliminate wrong answers

Option A is wrong because focusing only on technical controls ignores the human and cultural factors that are essential for a risk-aware culture; technical controls alone cannot address behavioral risks like failure to report incidents. Option B is wrong because limiting risk awareness training to IT staff excludes other departments (e.g., finance, HR, operations) that also handle sensitive data and face risks, creating blind spots in the organization's risk posture. Option C is wrong because punishing employees who cause security incidents discourages reporting, leading to hidden risks and missed opportunities for root cause analysis, which undermines a proactive risk culture.

947
MCQmedium

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The organization uses role-based access control (RBAC) but has experienced several incidents where employees retained access to systems after transferring to different departments. Which of the following is the MOST effective control to address this risk?

A.Implement mandatory password rotation every 30 days for all users.
B.Conduct periodic user access reviews with managers certifying that their direct reports have appropriate access.
C.Integrate the HR system with the IAM system to automatically revoke old roles and grant new roles upon a change in employee status or department.
D.Require all employees to sign an acceptable use policy annually.
AnswerC

Automating role changes based on HR events ensures that access rights are updated immediately when an employee transfers, eliminating the lag that leads to retained access. This preventive control directly addresses the root cause: the lack of timely de-provisioning and re-provisioning of access when roles change. It reduces reliance on manual processes and periodic reviews.

Why this answer

The root cause of the incidents is that access rights are not updated when employees change roles. The most effective control is to automate the synchronization of role changes from HR to the IAM system, ensuring timely revocation of old access and assignment of new access. This preventive control addresses the issue at the source and reduces reliance on periodic reviews.

Exam trap

The trap here is selecting periodic access reviews or password policies, which are detective or irrelevant, instead of a preventive automated provisioning control triggered by HR events.

948
MCQmedium

A risk manager is evaluating the cost-effectiveness of a proposed control. The control costs $50,000 annually to implement and maintain. The current annual loss expectancy (ALE) for the risk is $200,000, and the control is expected to reduce the ALE by 70%. What is the net benefit (or loss) of implementing the control?

A.Net benefit of $90,000
B.Net loss of $10,000
C.Net benefit of $140,000
D.Net loss of $50,000
AnswerA

The control reduces ALE by 70% of $200,000, giving a $140,000 mitigated loss. Subtracting the $50,000 annual control cost yields a $90,000 net benefit. This satisfies the stem's cost-effectiveness comparison between control spend and risk reduction.

Why this answer

The control reduces the ALE by 70%, so the mitigated ALE is $200,000 × 0.30 = $60,000, meaning the control saves $140,000 in expected annual loss. Subtracting the $50,000 annual control cost gives a net benefit of $140,000 − $50,000 = $90,000. This is the standard ALE-based cost-benefit calculation used in CRISC risk treatment decisions.

Exam trap

CRISC often tests whether candidates confuse gross savings with net benefit — the most common error is selecting the $140,000 figure by forgetting to subtract the control's annual cost, or misreading the 70% as applying to the cost rather than the ALE.

How to eliminate wrong answers

Option B (net loss of $10,000) is wrong because it appears to subtract the control cost from the wrong base or miscalculates the 70% reduction — the correct savings are $140,000, not $40,000. Option C (net benefit of $140,000) is wrong because it reports the gross savings and forgets to subtract the $50,000 annual control cost. Option D (net loss of $50,000) is wrong because it treats the entire control cost as a loss without applying the 70% ALE reduction, ignoring the benefit side of the equation.

949
MCQhard

A bank is adopting a third-party API gateway to expose account balance services to fintech partners. The risk practitioner must ensure that a partner's excessive or unusual API consumption cannot degrade service for other partners or core banking systems. Which control is MOST appropriate to address this risk?

A.Implement per-partner rate limiting and quotas at the API gateway, with circuit breakers to shed load before core systems are affected.
B.Encrypt account balance responses with a format-preserving encryption scheme before returning them.
C.Require all partners to sign a service level agreement specifying maximum transaction volumes.
D.Enforce mutual TLS between partners and the API gateway for all balance requests.
AnswerA

The stated risk is that one partner's consumption degrades service for others and for core systems. Per-partner rate limiting and quotas cap each consumer's volume, while circuit breakers stop cascading overload from reaching core banking. Together they directly contain the blast radius of a single misbehaving partner, which is exactly the risk described.

Why this answer

The risk is availability degradation caused by disproportionate consumption from one partner. Enforcing per-partner rate limits and quotas at the gateway constrains each consumer, and circuit breakers prevent overload from propagating into core banking. Contractual caps, mutual TLS and response encryption address expectations, authentication and confidentiality respectively, none of which stop a single partner from exhausting shared capacity.

Exam trap

The trap here is choosing a contractual or cryptographic control when the risk is about availability and capacity exhaustion by one consumer.

950
MCQhard

An organization uses Key Control Indicators (KCIs) to measure the effectiveness of its firewall change management process. Which KCI would best indicate a process deficiency?

A.Exception rate for changes not following the standard process
B.Percentage of changes approved by the change advisory board
C.Average time to implement a change
D.Number of firewall rules added per month
AnswerA

A high exception rate shows changes bypassing the standard process, revealing weak enforcement or impractical procedures. Unlike volume or cycle-time metrics, exceptions directly evidence control breakdown, making this the strongest indicator of deficiency in firewall change management.

Why this answer

A Key Control Indicator (KCI) measures whether a control is operating effectively. An exception rate for changes not following the standard process directly indicates how often the firewall change management process is bypassed or failing, which is a clear sign of process deficiency. The other options measure activity or volume, not control effectiveness.

Exam trap

CRISC often tests the distinction between KCIs (control effectiveness) and KPIs (performance) — candidates may pick 'average time to implement' as a deficiency indicator, but that is an efficiency metric, not a control effectiveness measure.

How to eliminate wrong answers

Option B is wrong because the percentage of changes approved by the change advisory board measures process adherence for changes that go through the CAB, but a high approval rate could simply mean the CAB approves everything, and it does not indicate deficiency. Option C is wrong because average time to implement a change is an efficiency metric, not a control effectiveness indicator; slow changes may be due to complexity, not a control failure. Option D is wrong because the number of firewall rules added per month is a volume metric that reflects activity, not whether the change management control is working.

951
MCQeasy

A small e-commerce company has identified a high-risk vulnerability in its payment processing system that could expose customer credit card data. The IT team recommends immediately patching the system, but the patch requires a 4-hour downtime during peak sales hours. The risk manager proposes accepting the risk until the next scheduled maintenance window in two weeks. The CEO is concerned about potential fines from PCI DSS non-compliance. What is the BEST course of action?

A.Delay the patch until the next maintenance window but document the risk acceptance with CEO sign-off.
B.Accept the risk and schedule the patch during the next maintenance window as originally planned.
C.Apply the patch immediately during peak hours, accepting the revenue loss from downtime.
D.Implement a compensating control (e.g., web application firewall) and schedule the patch during off-peak hours within 48 hours.
AnswerD

A web application firewall filters malicious traffic while the patch is deferred, reducing exposure during the two-week gap, and off-peak patching within 48 hours restores compliance faster than the maintenance window. This satisfies the PCI DSS and downtime constraints simultaneously.

Why this answer

The best course of action balances risk mitigation, business continuity, and compliance. Implementing a compensating control such as a web application firewall reduces the immediate exposure of the vulnerability while allowing the patch to be scheduled during off-peak hours within a short timeframe (48 hours), avoiding both peak-hour downtime and prolonged exposure. This aligns with CRISC's emphasis on risk response options that are proportionate and timely, and it addresses the CEO's PCI DSS compliance concern by reducing the window of non-compliance.

Exam trap

CRISC often tests whether candidates default to 'accept the risk' or 'patch immediately' when the correct answer is a balanced compensating control that addresses both risk and business impact.

How to eliminate wrong answers

Option A is wrong because delaying the patch for two weeks with only documented risk acceptance leaves the payment system exposed to a high-risk vulnerability for an extended period, which is not proportionate given the PCI DSS exposure and the availability of a compensating control. Option B is wrong because simply accepting the risk without any mitigation ignores the severity of the vulnerability and the compliance implications, and 'accept' is the weakest of the four risk responses when a high-risk issue affects cardholder data. Option C is wrong because applying the patch immediately during peak hours causes unnecessary revenue loss and business disruption when a compensating control plus off-peak patching achieves the same risk reduction with far less impact.

952
MCQeasy

A risk practitioner is interviewing business unit leaders to identify IT risks for an annual risk assessment. One leader states that the customer relationship management system is critical because sales staff cannot work without it. Which of the following BEST describes the risk practitioner's next action to validate this input?

A.Accept the leader's statement and record the CRM system as a high-risk asset in the register.
B.Escalate the statement to the board risk committee for a final criticality decision.
C.Schedule a penetration test of the CRM system to determine its risk level.
D.Cross-reference the CRM system's criticality with business impact analysis and dependency data.
AnswerD

Interview input is valuable but should be validated against objective sources such as the business impact analysis, recovery time objectives, and upstream and downstream dependencies. Cross-referencing confirms whether the CRM system truly supports critical business processes and how long an outage could be tolerated. This evidence-based validation strengthens the risk register and ensures criticality ratings reflect actual business impact rather than individual perception.

Why this answer

Stakeholder interviews are a key risk identification technique, but their outputs should be corroborated with objective evidence. Comparing the CRM criticality claim against the business impact analysis, recovery objectives, and dependency maps confirms whether the system genuinely supports critical processes. This validation reduces bias, improves the accuracy of the risk register, and supports defensible prioritization of risk treatment.

Exam trap

The trap here is treating a single stakeholder's strong statement as sufficient evidence of asset criticality instead of validating it against documented business impact and dependency data.

953
MCQeasy

During a control monitoring review, the auditor finds that a control designed to detect unauthorized access has not triggered any alerts in six months. What should the risk practitioner do first?

A.Document the lack of alerts as evidence of effectiveness.
B.Redesign the control with different parameters.
C.Test the control to ensure it is functioning correctly.
D.Increase the frequency of monitoring.
AnswerC

Six months without a single alert suggests the detection logic may be broken rather than that no unauthorised access occurred. Testing the control first verifies whether it can actually generate alerts, distinguishing a genuine control failure from a benign absence of events before any other action.

Why this answer

The absence of alerts does not automatically confirm that the control is working; it could indicate that the control has failed silently or that the detection logic is misconfigured. The risk practitioner must first test the control (e.g., by simulating an unauthorized access attempt) to verify that it can actually detect and alert on violations. Only after confirming correct functionality can the lack of alerts be interpreted as evidence of effectiveness.

Exam trap

The trap here is that candidates assume a lack of alerts equals a lack of incidents, rather than recognizing that it could indicate a control failure, and they jump to redesign or increase monitoring without first validating the control's operational state.

How to eliminate wrong answers

Option A is wrong because documenting the lack of alerts as evidence of effectiveness assumes the control is operational without verification, which ignores the possibility of a silent failure (e.g., a broken SIEM rule or a disabled detection agent). Option B is wrong because redesigning the control with different parameters is premature and wasteful; the issue may be a simple configuration error or a false negative, not a fundamental design flaw. Option D is wrong because increasing monitoring frequency does not address the root cause—if the control is not detecting unauthorized access, more frequent checks will only produce more false negatives or miss the same failures.

954
MCQhard

A multinational corporation is identifying risks associated with cross-border data transfers. Which regulation's risk identification requirements are most relevant?

A.PCI DSS
B.GDPR
C.HIPAA
D.SOX
AnswerB

GDPR governs transfers of personal data outside the European Economic Area, imposing lawful transfer mechanisms, safeguards and documentation duties. Its risk identification requirements therefore map directly to the cross-border transfer scenario, unlike regulations focused on other domains or jurisdictions.

Why this answer

The General Data Protection Regulation (GDPR) is the most relevant regulation for risk identification in cross-border data transfers because it explicitly governs the transfer of personal data from the European Economic Area (EEA) to third countries. GDPR requires organizations to identify and assess risks related to adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and potential data localization conflicts. This regulation directly addresses the legal and technical risks of moving data across borders, such as exposure to differing privacy laws and surveillance regimes.

Exam trap

The trap here is that candidates often confuse PCI DSS or HIPAA as relevant because they involve sensitive data, but they lack the specific cross-border transfer risk identification requirements that GDPR mandates, leading to an incorrect choice based on data sensitivity rather than regulatory scope.

How to eliminate wrong answers

Option A is wrong because PCI DSS focuses on protecting cardholder data within payment card transactions and does not specifically address cross-border data transfer risks or require adequacy assessments for international data flows. Option C is wrong because HIPAA governs protected health information (PHI) within the United States and does not impose cross-border transfer risk identification requirements for data leaving the U.S. jurisdiction. Option D is wrong because SOX mandates internal controls over financial reporting and does not contain provisions for cross-border data transfer risk identification or data protection adequacy mechanisms.

955
MCQeasy

Which of the following is the BEST example of promoting a risk-aware culture within an organization?

A.Implementing strict penalties for security violations
B.Assigning risk ownership to IT only
C.Encouraging incident reporting without blame
D.Conducting annual security training
AnswerC

Encouraging incident reporting without blame directly satisfies the stem's cultural objective: staff surface near misses and control failures, generating the data risk assessment depends on. A blame response suppresses disclosure, leaving risks invisible to management. This builds the shared ownership and transparency that a risk-aware culture requires, unlike one-off training or policy documents.

Why this answer

A blame-free incident reporting culture is the foundation of a risk-aware environment. When employees feel safe to report errors or near-misses without fear of punishment, the organization can collect accurate data on control weaknesses and emerging threats, enabling proactive risk response. This aligns with the COBIT 5 principle of fostering a culture of openness and learning, which is essential for effective risk management.

Exam trap

CRISC candidates often mistakenly believe that punitive measures or compliance-focused training are the best ways to foster a risk-aware culture. However, the key is a blame-free reporting environment that encourages openness and learning.

How to eliminate wrong answers

Option A is wrong because strict penalties for security violations create a culture of fear, which discourages incident reporting and drives issues underground, undermining risk awareness and learning. Option B is wrong because assigning risk ownership exclusively to IT ignores that risk is a business-wide concern; effective risk management requires ownership across all departments, including legal, finance, and operations. Option D is wrong because annual security training, while important, is a periodic compliance activity that does not by itself embed continuous risk awareness into daily behaviors or encourage proactive reporting of incidents.

956
MCQhard

A Key Risk Indicator (KRI) for vulnerability management is the "average patch lag time" (number of days between patch release and deployment). In the last month, this metric increased from 15 days to 45 days. How should the risk practitioner interpret this change?

A.The KRI is not relevant because patch lag is a control indicator, not a risk indicator.
B.The risk level has decreased because patches are being evaluated more thoroughly.
C.The risk level remains unchanged because patch lag is a lagging indicator.
D.The risk level has increased because exposure to known vulnerabilities has grown.
AnswerD

Patch lag rising from 15 to 45 days means systems remain unpatched longer, extending exposure to known exploitable vulnerabilities. The KRI movement therefore signals increased risk, satisfying the interpretation that the metric's deterioration reflects a higher likelihood of exploitation.

Why this answer

An increase in average patch lag from 15 to 45 days means critical vulnerabilities remain exploitable for a longer window, directly increasing exposure to known threats. Since KRIs are designed to signal changes in risk levels, a rising KRI indicates the risk level has increased and warrants attention. The correct interpretation is that the organization's exposure to known vulnerabilities has grown.

Exam trap

CRISC often tests whether candidates confuse a rising KRI with improved controls — the trap is interpreting a longer patch lag as 'more thorough evaluation' when it actually signals increased exposure and deteriorating risk posture.

How to eliminate wrong answers

Option A is wrong because patch lag is a valid KRI — it measures a risk driver (exposure window) even though it also reflects control performance; KRIs and KCIs can overlap, and the metric is explicitly used as a KRI here. Option B is wrong because a longer patch lag does not mean patches are being evaluated more thoroughly — it means they are being deployed more slowly, which increases risk, not decreases it. Option C is wrong because whether a metric is leading or lagging does not determine whether risk has changed; a 3x increase in patch lag clearly signals increased risk regardless of indicator type.

957
MCQeasy

A risk practitioner is reviewing the organization's risk register and notices that a risk related to a legacy payroll system has been assigned an owner from the IT department. The risk owner is responsible for which of the following?

A.Implementing the technical controls to mitigate the risk.
B.Performing the annual risk assessment for the payroll system.
C.Managing the risk and ensuring appropriate responses are executed.
D.Approving the risk appetite statement for the organization.
AnswerC

The risk owner is accountable for managing the risk, which includes selecting and overseeing risk responses, monitoring the risk, and reporting on its status. For the legacy payroll system, the risk owner would ensure that mitigation, transfer, avoidance, or acceptance decisions are made and carried out, and that the risk remains within acceptable levels.

Why this answer

The risk owner is accountable for managing a specific risk, including selecting and monitoring risk responses and ensuring the risk stays within acceptable limits. This role is distinct from control implementation, risk assessment, and appetite approval. Clearly defining risk ownership ensures that someone is accountable for each risk and that responses are executed and reported appropriately.

Exam trap

The trap here is confusing the risk owner's accountability for managing the risk with hands-on tasks like implementing controls or performing assessments, which belong to other roles.

958
MCQhard

An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?

A.The patching process is effective because the KRI is still below 60 days
B.The KRI should be replaced with a lagging indicator
C.The vulnerability risk is increasing and requires management attention
D.The risk is within appetite because the increase is gradual
AnswerC

The KRI has breached the 20-day risk appetite threshold, rising from 15 to 30 days, so vulnerability exposure is worsening. This trend signals that patch management controls are degrading, requiring management attention to remediate the control weakness before the risk exceeds tolerance further.

Why this answer

The KRI has risen from 15 to 30 days, exceeding the 20-day risk appetite threshold. When a KRI breaches its threshold, it signals that the risk is outside acceptable limits and requires management attention. The correct conclusion is that vulnerability risk is increasing and must be addressed.

Exam trap

The trap is that candidates may rationalize the increase as 'gradual' or compare it to an irrelevant benchmark (60 days) instead of the defined 20-day threshold — CRISC expects you to treat threshold breaches as clear signals requiring management action.

How to eliminate wrong answers

Option A is wrong because the 60-day figure is arbitrary and not the defined threshold — the threshold is 20 days, and the KRI has exceeded it, so the process is not effective. Option B is wrong because replacing a KRI with a lagging indicator does not address the rising risk; KRIs are specifically chosen to be forward-looking, and swapping them out is not a valid response to a threshold breach. Option D is wrong because the risk is not within appetite — the KRI has crossed the 20-day threshold, and a gradual increase does not make it acceptable; thresholds are binary triggers for action.

959
Multi-Selecteasy

A company is designing its risk and control monitoring program. Which TWO of the following are key attributes of effective monitoring?

Select 2 answers
A.All controls should be monitored at the same frequency.
B.Monitoring should only be performed by external auditors.
C.Monitoring results should be communicated to stakeholders.
D.Monitoring should be independent of the control owner.
E.Monitoring frequency should be determined by control criticality.
AnswersC, E

Communication enables informed decision-making.

Why this answer

Effective monitoring requires that results are communicated to stakeholders to ensure informed decision-making and timely remediation. Without communication, monitoring loses its value as stakeholders cannot act on identified risks or control deficiencies.

Exam trap

The trap here is that candidates often confuse independence as a mandatory attribute for all monitoring, whereas the CRISC framework recognizes that control owner self-assessment is a valid monitoring technique, and independence is only required for specific assurance activities like internal audits.

960
MCQhard

An energy utility's board risk committee receives a quarterly IT risk report showing that overall risk exposure is within appetite, yet a recent regulatory audit identified unpatched internet-facing systems. The risk manager must improve the report so the committee is not misled in the future. Which change is MOST effective?

A.Delegate preparation of the IT risk report entirely to the internal audit function going forward.
B.Add a section that reconciles reported risk ratings against independent audit and assessment findings.
C.Increase the reporting frequency from quarterly to monthly without changing the content or data sources.
D.Replace quantitative risk ratings with a purely qualitative red, amber, and green status for each risk.
AnswerB

The gap between an in-appetite dashboard and an audit finding signals that self-reported data was incomplete or optimistic. Reconciling reported ratings with independent findings exposes divergence, forces explanation of root causes, and strengthens the credibility of the report. It also creates a feedback loop so that audit results update the risk register rather than sitting outside the reporting process.

Why this answer

When a board dashboard shows acceptable exposure while an independent audit finds real gaps, the reporting process lacks validation. Reconciling reported ratings with audit and assessment findings surfaces divergence, drives root-cause analysis, and ensures independent evidence updates the register. Changing frequency or format, or shifting authorship to audit, leaves the underlying data integrity problem intact.

Exam trap

The trap here is assuming that more frequent reporting or simpler visual formats will fix a credibility problem that actually stems from unvalidated self-reported data.

961
MCQmedium

An organization is integrating IT risk into its enterprise risk management (ERM) program. What is the primary benefit of this integration?

A.It allows IT to operate independently
B.It eliminates all IT risks
C.It reduces the need for IT controls
D.It ensures IT risks are viewed in the context of business objectives
AnswerD

Integrating IT risk into ERM translates technical exposures into business-impact terms, so leadership evaluates them alongside strategic, financial and operational risks. This satisfies the stem's primary-benefit requirement by ensuring IT risks are assessed against business objectives rather than managed in an isolated technical silo.

Why this answer

Integrating IT risk into enterprise risk management (ERM) ensures that IT risks are evaluated in the context of business objectives, enabling prioritization of risk responses that align with strategic goals. This alignment prevents IT from operating in a silo and ensures that risk decisions support overall business value, not just technical compliance.

Exam trap

The trap here is that candidates mistakenly think integration means IT risks are eliminated or that IT can ignore business context, when in fact integration demands that IT risks be translated into business impact terms to drive appropriate control decisions.

How to eliminate wrong answers

Option A is wrong because integrating IT risk into ERM requires IT to align with business objectives, not operate independently; independence would create silos and increase misalignment. Option B is wrong because no risk management process can eliminate all IT risks; residual risk always remains, and the goal is to manage risk to an acceptable level, not zero. Option C is wrong because integration typically increases the need for well-designed IT controls to address risks that are now visible in the business context; reducing controls would increase exposure.

962
MCQeasy

A software development company identifies that developers are storing API keys in plaintext within source code repositories. The risk practitioner proposes a risk treatment plan that includes implementing a secrets management solution and rotating all exposed keys. The Chief Technology Officer asks how the risk practitioner will confirm that the treatment plan is reducing the risk over time. Which metric is MOST appropriate for monitoring the effectiveness of this risk response?

A.The number of secrets detected in source code repositories during automated scans each sprint.
B.The percentage of developers who have completed secure coding training in the last year.
C.The mean time to rotate API keys after a developer reports a suspected exposure.
D.The total number of API keys currently managed by the secrets management solution.
AnswerA

Automated scanning for secrets in source code directly measures whether developers are still storing credentials insecurely. A downward trend in detected secrets indicates the secrets management solution and training are working. This metric is leading and actionable, allowing the risk practitioner to track the effectiveness of the treatment plan over time and address recurring issues in specific teams or repositories.

Why this answer

The most appropriate metric directly measures whether the risky behavior is decreasing. Automated scans for secrets in source code provide objective, recurring evidence of plaintext credentials. A declining trend confirms the secrets management solution and process changes are effective.

Metrics such as total managed keys, rotation time, and training completion are indirect or reactive and do not demonstrate that insecure storage has been reduced over time.

Exam trap

The trap here is choosing a metric that measures tool adoption or training completion instead of the actual reduction of insecure secrets in code.

963
MCQmedium

An organization calculates the annualized loss expectancy (ALE) for a cyber attack scenario. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 2. What is the ALE?

A.$25,000
B.$50,000
C.$200,000
D.$100,000
AnswerD

Annualized loss expectancy equals single loss expectancy multiplied by annualized rate of occurrence: $50,000 × 2 = $100,000. This quantifies the expected yearly loss for the scenario, giving risk practitioners the figure used to compare against the cost of proposed controls.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Given an SLE of $50,000 and an ARO of 2, the ALE is $50,000 × 2 = $100,000. This is the expected financial loss from the cyber attack scenario over one year.

Exam trap

The trap here is that candidates often confuse the relationship between SLE and ARO, mistakenly dividing instead of multiplying, or misapplying the ARO as a squared term, leading to incorrect ALE values like $25,000 or $200,000.

How to eliminate wrong answers

Option A is wrong because $25,000 would result from dividing the SLE by the ARO (50,000 / 2), which incorrectly treats the relationship as a division rather than multiplication. Option B is wrong because $50,000 equals the SLE alone, ignoring the ARO of 2, which would only be correct if the ARO were 1. Option C is wrong because $200,000 would result from multiplying the SLE by the ARO squared (50,000 × 4), a common miscalculation that confuses the ARO with a frequency multiplier.

964
MCQhard

A global logistics company's risk practitioner is identifying risks for a new customs-clearance application. She wants to ensure the risk identification is complete before moving to analysis. Which of the following approaches BEST supports completeness of the risk identification?

A.Running an automated vulnerability scan against the application's internet-facing components and importing the results
B.Reviewing only the application's architecture diagrams and data flow documentation produced by the development team
C.Interviewing the application's lead developer about the technologies and frameworks used to build the system
D.Facilitating structured workshops with business, IT, compliance, and third-party representatives using a risk taxonomy as a prompt
AnswerD

Structured workshops that bring together business, IT, compliance, and third-party perspectives, prompted by a risk taxonomy, systematically surface risks across categories that no single group would identify alone. The taxonomy prevents gaps and the cross-functional dialogue exposes interdependencies, making this the most complete approach before analysis begins.

Why this answer

Complete risk identification requires broad, structured input across business, technology, compliance, and third-party perspectives. A facilitated workshop using a risk taxonomy as a prompt systematically covers categories and surfaces interdependencies that single-source methods miss. Documentation reviews, vulnerability scans, and individual interviews each provide narrow slices and cannot by themselves ensure completeness before analysis.

Exam trap

The trap here is equating a technical scan or documentation review with complete risk identification, when completeness requires cross-functional and taxonomy-driven coverage.

965
MCQmedium

An organization is evaluating cyber insurance options. Which of the following factors is MOST likely to influence the insurance premium?

A.The organization's annual revenue
B.The number of employees in the IT department
C.The organization's cybersecurity maturity and incident history
D.The organization's credit rating
AnswerC

Insurers price premiums according to assessed risk, so demonstrated cybersecurity maturity and prior incident history directly determine underwriting confidence and coverage terms. Stronger controls and fewer breaches lower perceived loss likelihood, reducing the premium charged.

Why this answer

An organization's cybersecurity maturity and incident history (C) is the most direct factor influencing cyber insurance premiums because insurers assess the likelihood and potential cost of a claim based on the organization's security controls, past breaches, and risk management practices. A mature security posture with few incidents lowers the perceived risk and therefore the premium.

Exam trap

The trap is selecting revenue (A) because it is a familiar underwriting factor for other insurance types — candidates must recognize that cyber insurance uniquely weights security maturity and incident history as the primary premium drivers.

How to eliminate wrong answers

Option A is wrong because annual revenue affects the potential size of a claim (higher revenue = higher potential loss), but it is a secondary factor — insurers weight security posture more heavily because it directly predicts the probability of an incident. Option B is wrong because the number of IT staff is not a standard underwriting factor; what matters is the effectiveness of controls, not headcount. Option D is wrong because credit rating is relevant to financial insurance products but is not a primary factor in cyber insurance underwriting — insurers focus on security controls, incident history, and industry risk profile.

966
Multi-Selectmedium

A risk practitioner is developing risk scenarios for a new cloud service. Which THREE of the following elements should be included in a complete risk scenario?

Select 3 answers
A.Threat event
B.Threat actor
C.Consequence
D.Response plan
E.Detection mechanism
AnswersA, B, C

A complete risk scenario must identify what could happen; the threat event supplies that initiating occurrence, such as a data breach or service compromise. Without it, the scenario lacks the causal trigger needed to link actor, asset and consequence.

Why this answer

A complete risk scenario must describe the threat event (A), i.e., the specific incident or action that could occur (such as data breach, service outage, or misconfiguration), because it defines what risk is being assessed. It must also identify the threat actor (B), the party or source capable of causing the event (e.g., malicious insider, external attacker, or accidental user), since likelihood and motivation depend on who or what triggers it. The consequence (C) is equally essential, as it captures the resulting business impact or harm (e.g., financial loss, regulatory penalty, reputational damage) that the scenario is meant to evaluate.

Response plan (D) and detection mechanism (E) are controls or mitigation elements, not core components of the risk scenario itself; they belong to risk treatment and monitoring rather than scenario definition.

Exam trap

CRISC often tests the boundary between risk identification and risk response — the trap is selecting 'response plan' or 'detection mechanism' because they sound risk-related, when a scenario is strictly about the threat, actor, and consequence.

967
MCQhard

A risk manager is assessing the potential impact of quantum computing on the organization's cryptographic infrastructure. What is the MOST immediate action the organization should take?

A.Purchase quantum-resistant hardware security modules
B.Conduct a cryptographic inventory to identify vulnerable systems
C.Immediately replace all encryption with post-quantum algorithms
D.Discontinue use of public key cryptography
AnswerB

Quantum computing threatens asymmetric cryptography once sufficiently powerful machines exist, but remediation depends on knowing where cryptography is deployed. A cryptographic inventory identifies vulnerable systems, algorithms and key lengths, giving the baseline required before migration planning can begin, making it the most immediate and actionable step.

Why this answer

The first step is to inventory all cryptographic systems to understand where quantum-vulnerable algorithms are used, enabling a migration plan.

968
MCQmedium

An organization recently experienced a data breach due to a misconfigured cloud storage bucket. As part of the IT risk assessment, which control should be prioritized to prevent recurrence?

A.Require management approval for all cloud storage changes.
B.Implement mandatory annual security awareness training for all employees.
C.Increase the frequency of third-party penetration testing.
D.Deploy automated cloud configuration scanning and remediation tools.
AnswerD

Automated scanning continuously detects and remediates misconfigured bucket permissions, directly addressing the root cause of the breach. Manual reviews cannot scale across dynamic cloud environments, so this control satisfies the need to prevent recurrence through consistent, policy-driven configuration enforcement.

Why this answer

Automated cloud configuration scanning and remediation tools directly address the root cause of a misconfigured cloud storage bucket by continuously monitoring cloud infrastructure against security baselines (e.g., CIS benchmarks) and automatically correcting deviations. This prevents recurrence by catching misconfigurations in real time, rather than relying on manual approval processes or periodic testing that may miss transient changes.

Exam trap

The trap here is that candidates often choose Option A (management approval) because it seems like a strong administrative control, but CRISC emphasizes that preventive technical controls—especially automated ones—are prioritized over manual processes for recurring technical risks like cloud misconfigurations.

How to eliminate wrong answers

Option A is wrong because requiring management approval for all cloud storage changes introduces a manual bottleneck that does not prevent misconfigurations from being deployed; it only adds a review step that may still miss technical misconfigurations, especially in dynamic cloud environments with Infrastructure as Code (IaC). Option B is wrong because mandatory annual security awareness training, while valuable for general security hygiene, does not address the specific technical failure of a misconfigured cloud bucket—training cannot prevent automated or scripted misconfigurations that bypass human interaction. Option C is wrong because increasing the frequency of third-party penetration testing provides only periodic snapshots of security posture and cannot detect or remediate misconfigurations that occur between tests; it is a detective control, not a preventive one.

969
MCQmedium

A risk manager is reviewing the risk treatment plan for a new mobile banking application. The plan includes implementing multi-factor authentication (MFA) and conducting regular vulnerability scans. The risk manager wants to ensure that the controls are operating effectively. Which of the following should be performed to verify the effectiveness of the controls?

A.Gap analysis
B.Business impact analysis (BIA)
C.Control testing
D.Risk assessment
AnswerC

Control testing involves evaluating whether controls are designed and operating effectively. It can include walkthroughs, inspections, and re-performance. For MFA and vulnerability scans, testing might involve attempting to bypass MFA or reviewing scan reports to ensure they are complete and timely. This provides assurance that the controls are functioning as intended and mitigating the risk.

Why this answer

To verify that controls are operating effectively, the risk manager should perform control testing. This involves examining and testing the controls to ensure they are implemented correctly and functioning as intended. Risk assessment, gap analysis, and BIA serve different purposes and do not provide assurance on control effectiveness.

Exam trap

The trap here is confusing control testing with risk assessment; risk assessment identifies risks, but control testing verifies that controls mitigate those risks effectively.

970
MCQmedium

An organization is migrating its customer relationship management (CRM) system to a SaaS provider. The vendor's audit report shows a SOC 2 Type II opinion with no exceptions, but the report's period ended eight months ago. The risk practitioner must assess whether the residual risk is acceptable. Which action BEST addresses the gap in assurance?

A.Perform a penetration test against the SaaS provider's production environment to validate its controls directly.
B.Request a bridge letter or gap letter covering the period since the report ended and review the vendor's remediation of any changes.
C.Require the vendor to purchase cyber insurance and name the organization as an additional insured as a compensating control.
D.Accept the SOC 2 Type II report as sufficient evidence because it was issued by an independent CPA firm.
AnswerB

A bridge letter documents the vendor's controls and any changes during the gap between the audit period end and the current date. Reviewing it, along with any reported incidents or control changes, provides the missing assurance for the current period and allows the risk practitioner to judge whether residual risk remains acceptable.

Why this answer

SOC 2 Type II reports are point-in-time documents that cover only the stated audit period. When the report is stale, the risk practitioner needs evidence of controls during the gap. A bridge or gap letter is the standard mechanism for that period, supplemented by review of changes and incidents, allowing an informed residual risk determination.

Exam trap

The trap here is assuming that a Type II SOC 2 report provides perpetual assurance, when it only covers the specific audit period and requires a bridge letter for the gap.

971
MCQmedium

An organization is implementing a new cloud-based customer relationship management (CRM) system. Which of the following risk categories would BEST describe the risk of the CRM system failing to meet performance expectations?

A.Compliance risk
B.Strategic risk
C.Operational risk
D.Reputational risk
AnswerC

Operational risk covers losses from inadequate or failed internal processes, people and systems. A CRM failing to meet performance expectations is a service delivery failure within live operations, not a credit, market or strategic risk, so operational risk is the appropriate category.

Why this answer

Operational risk is the correct answer because it encompasses risks arising from inadequate or failed internal processes, people, systems, or external events that disrupt business operations. A CRM system failing to meet performance expectations directly impacts day-to-day operations such as sales, customer service, and data management. This is a classic operational risk scenario, as it involves the technology and processes that support core business functions.

Exam trap

CRISC often tests the distinction between risk categories, and candidates frequently confuse operational risk with strategic or reputational risk when a system fails to meet expectations, overlooking that performance issues are fundamentally operational.

How to eliminate wrong answers

Option A is wrong because compliance risk relates to violations of laws, regulations, or internal policies, not performance shortfalls. Option B is wrong because strategic risk involves high-level business strategy, market positioning, or long-term goals, not operational performance of a system. Option D is wrong because reputational risk concerns damage to brand or public image, which may be a consequence of operational failure but is not the primary risk category for performance expectations.

972
MCQmedium

A company's risk monitoring report shows that a key risk indicator (KRI) has exceeded the threshold for three consecutive months. What is the MOST appropriate action?

A.Conduct a root cause analysis and implement corrective actions.
B.Wait for the KRI to return to normal on its own.
C.Raise the threshold to avoid future breaches.
D.Implement temporary manual controls.
AnswerA

Three consecutive breaches indicate the KRI is not transient, so root cause analysis identifies why the threshold is persistently exceeded and corrective actions restore the control. This addresses the underlying driver rather than merely re-reporting or adjusting the threshold.

Why this answer

A KRI that has exceeded its threshold for three consecutive months indicates a persistent risk condition, not a transient anomaly. The most appropriate action is to conduct a root cause analysis to identify the underlying issue and implement corrective actions to bring the risk back within acceptable levels. This aligns with the CRISC domain of Risk and Control Monitoring and Reporting, which emphasizes proactive remediation over passive observation or threshold manipulation.

Exam trap

The trap here is that candidates may confuse a persistent KRI breach with a temporary spike and choose to wait (Option B) or adjust the threshold (Option C), failing to recognize that the CRISC framework mandates investigation and corrective action for sustained deviations.

How to eliminate wrong answers

Option B is wrong because waiting for the KRI to return to normal on its own ignores the persistent nature of the breach and assumes a self-correcting mechanism, which is not a valid risk management strategy. Option C is wrong because raising the threshold to avoid future breaches is a form of risk acceptance without justification and undermines the integrity of the KRI as an early warning indicator. Option D is wrong because implementing temporary manual controls without first understanding the root cause may address symptoms but not the underlying risk, and manual controls often introduce operational inefficiencies and are not sustainable.

973
MCQhard

A multinational retailer operates point-of-sale terminals in 30 countries. During an IT risk assessment, the risk analyst notes that a single compromised terminal could expose payment card data across multiple jurisdictions, each with different breach notification laws. The CISO asks the analyst to determine the MOST appropriate risk metric to communicate this exposure to the board. Which of the following should the analyst use?

A.The CVSS base score of the vulnerability present on the point-of-sale terminals
B.The percentage of terminals running an unsupported operating system
C.The number of unpatched vulnerabilities on point-of-sale terminals
D.The annualized loss expectancy for a payment card data breach scenario
AnswerD

Annualized loss expectancy combines the estimated frequency of a breach event with the expected loss per event, including regulatory penalties, notification costs, forensic fees, and card replacement across jurisdictions. This gives the board a single monetary figure that reflects both likelihood and multi-jurisdictional impact, enabling comparison against risk appetite and investment decisions. It directly communicates the exposure in the language executives use for capital allocation.

Why this answer

Board-level risk communication requires a metric that integrates likelihood and business impact. Annualized loss expectancy does this by multiplying event frequency by expected loss per event, capturing regulatory penalties, notification costs, and remediation expenses that vary across 30 jurisdictions. Technical indicators such as CVSS scores, patch counts, and unsupported-OS percentages describe control state or vulnerability severity but omit consequence and frequency, making them unsuitable for expressing enterprise exposure.

Exam trap

The trap here is equating vulnerability severity or control coverage with risk, when risk requires combining likelihood with business impact, especially in a multi-jurisdictional regulatory context.

974
MCQhard

A risk team is assessing a legacy inventory system that supports a product line scheduled for retirement in nine months. The system has an unpatched vulnerability that cannot be remediated without breaking vendor support, and the business has confirmed it will not extend the product line. Which risk response is MOST appropriate for the remaining exposure?

A.Accept the risk with documented justification, because the exposure is bounded by the scheduled decommissioning date.
B.Transfer the risk by purchasing a standalone cyber insurance policy covering legacy system vulnerabilities.
C.Mitigate the vulnerability by applying the vendor patch immediately and accepting any resulting support disruption.
D.Avoid the risk by shutting down the inventory system immediately and ceasing the product line ahead of schedule.
AnswerA

The exposure has a defined end date and no planned business continuation, so accepting it with documented rationale and monitoring is proportionate and avoids disruptive remediation. Acceptance is valid when the risk falls within tolerance and the cost of treatment exceeds the benefit. The scenario supplies exactly those conditions: imminent retirement and infeasible patching.

Why this answer

When exposure is bounded by a firm decommissioning date and remediation would cause greater harm than the residual risk itself, documented acceptance with monitoring is the proportionate response. It preserves business continuity through the retirement window, keeps the decision auditable, and avoids introducing new operational risk through disruptive patching or premature shutdown.

Exam trap

The trap here is reflexively choosing mitigation because a vulnerability exists, without weighing the imminent retirement that makes treatment cost exceed the benefit.

975
MCQmedium

During a merger and acquisition (M&A) due diligence, the acquiring company's IT risk manager is tasked with identifying risks in the target's IT environment. Which of the following would be the MOST effective technique to uncover hidden risks?

A.Analyze the target's existing risk register
B.Perform an on-site technical assessment and interview key IT staff
C.Review the target's IT policies and procedures
D.Conduct a network vulnerability scan
AnswerB

An on-site technical assessment combined with staff interviews exposes undocumented configurations, shadow IT, unsupported systems and cultural issues that paper reviews and questionnaires miss, making it the most effective technique for uncovering hidden risks during due diligence.

Why this answer

An on-site technical assessment combined with interviews of key IT staff is the most effective technique because it uncovers undocumented risks, shadow IT, cultural issues, and technical debt that documents and scans alone cannot reveal. Interviews provide context about how systems are actually used versus how they are documented, and on-site observation can expose physical and operational risks.

Exam trap

CRISC often tests the distinction between reviewing existing documentation (which reflects known risks) and performing independent assessment (which uncovers hidden risks) — candidates pick the risk register or policy review because they are easier, but those do not reveal undisclosed risks.

How to eliminate wrong answers

Option A is wrong because the target's risk register reflects what the target has already identified and may omit hidden or undisclosed risks — it is not an independent verification technique. Option C is wrong because policies and procedures describe intended controls, not actual implementation, and may be outdated or aspirational. Option D is wrong because a network vulnerability scan identifies technical vulnerabilities but does not uncover process, personnel, or governance risks, and it may be limited by access restrictions during due diligence.

Page 12

Page 13 of 15

Page 14