Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 976–1050

1062 questions total · 15pages · All types, answers revealed

Page 13

Page 14 of 15

Page 15
976
Multi-Selectmedium

A company is evaluating its control monitoring program. Which TWO of the following are key elements of an effective control monitoring framework? (Choose two.)

Select 2 answers
A.Integration with performance management.
B.Periodic review of KRI thresholds.
C.Use of statistical sampling for all tests.
D.Automated alerts for all control failures.
E.Clearly defined roles and responsibilities.
AnswersB, E

KRIs signal when risk exposure drifts toward unacceptable levels, so reviewing their thresholds periodically keeps monitoring aligned with the current risk appetite. Without that recalibration, alerts either flood or miss genuine deterioration, undermining the framework's ability to trigger timely action.

Why this answer

Periodic review of KRI thresholds is a key element because KRIs must remain aligned with the evolving risk landscape; thresholds that are not reviewed can become obsolete, leading to false positives or missed risk indicators. Clearly defined roles and responsibilities ensure accountability for control execution, monitoring, and escalation, which is foundational to any effective control monitoring framework.

Exam trap

The trap here is that candidates confuse operational efficiency elements (like performance management or full automation) with the foundational governance and risk-alignment components that ISACA emphasizes for effective control monitoring.

977
Matchingmedium

Match each information security objective to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Data is accessible only to authorized parties

Data is accurate and complete

Data is accessible when needed

Actions can be traced to individuals

Why these pairings

The CIA triad (Confidentiality, Integrity, Availability) plus Accountability are core security principles. Correct matches: Confidentiality prevents unauthorized disclosure, Integrity ensures accuracy, Availability guarantees access, and Accountability enables traceability.

978
MCQmedium

An organization is designing its identity and access management architecture. The risk practitioner wants to reduce the risk of credential theft leading to unauthorized access to critical systems. Which of the following is the MOST effective control to address this risk?

A.Enforce a password complexity policy requiring 14 characters with mixed character classes and 60-day expiration.
B.Deploy phishing-resistant multi-factor authentication using FIDO2 security keys for access to critical systems.
C.Require users to complete annual security awareness training covering password hygiene and social engineering.
D.Implement account lockout after five failed attempts and alert the service desk when lockouts occur.
AnswerB

FIDO2 security keys bind authentication to the legitimate origin and use public-key cryptography, so a stolen password or a relayed phishing page cannot produce a valid assertion. This directly breaks the credential theft path into critical systems, which is exactly the risk the architecture must reduce.

Why this answer

Credential theft defeats knowledge-based authentication regardless of password strength, so the strongest mitigation changes the authentication factor itself. Phishing-resistant FIDO2 authentication uses origin-bound public-key cryptography, meaning stolen passwords or relayed phishing sessions cannot authenticate. Complexity rules, lockout, and awareness training are useful supporting controls but do not break the theft-to-access path.

Exam trap

The trap here is assuming that stronger passwords or user education meaningfully prevent attackers who have already stolen valid credentials.

979
Multi-Selectmedium

Which TWO of the following are examples of risk transfer? (Select TWO.)

Select 2 answers
A.Outsourcing IT operations to a third party
B.Implementing encryption
C.Accepting residual risk
D.Buying cyber insurance
E.Conducting security training
AnswersA, D

Outsourcing shifts operational risk to the vendor under contract, so liability for failures transfers rather than being mitigated or avoided. This satisfies the stem's risk transfer definition by moving financial consequence to a third party.

Why this answer

Option A (Outsourcing IT operations to a third party) is correct because risk transfer shifts the financial and operational impact of a risk to another entity via a contractual agreement, such as an SLA or MSA, where the vendor assumes responsibility for the outsourced functions. Option D (Buying cyber insurance) is correct because insurance is the classic form of risk transfer, where the insurer agrees to compensate the organization for covered losses in exchange for premiums, moving the financial consequence of the risk to the insurer. Option B (Implementing encryption) is a risk mitigation or reduction control that lowers the likelihood or impact of a data breach rather than transferring it.

Option C (Accepting residual risk) is risk acceptance, where the organization retains the remaining risk after other treatments. Option E (Conducting security training) is also risk mitigation, reducing human error and improving security awareness rather than shifting risk to a third party.

Exam trap

The distinction between risk transfer and risk mitigation is frequently tested on the CRISC exam. Candidates often confuse controls like encryption or training with transfer mechanisms, when in fact only insurance and outsourcing (with liability transfer) qualify as true risk transfer.

980
MCQhard

A healthcare organization is migrating its electronic health records (EHR) system to a cloud provider. The risk assessment shows that the cloud provider has strong security certifications (e.g., SOC 2 Type II, ISO 27001). However, the organization's legal team is concerned about data sovereignty laws that require patient data to remain within the country. The cloud provider's data centers are located in three regions: one in-country, and two outside. The project manager proposes using only the in-country data center. The IT director warns that this will increase latency and reduce redundancy. The risk manager must propose a response. Which is the BEST option?

A.Accept the legal risk because the cloud provider's certifications are sufficient, and document the decision.
B.Use all three data centers with automatic failover, and rely on the cloud provider's contractual guarantees of data residency.
C.Configure the EHR system to store primary data in the in-country data center, and use the other two centers for disaster recovery with data residency controls ensuring data does not leave the country unless encrypted and with legal approval.
D.Use only the in-country data center and accept the increased availability risk.
AnswerC

This option balances compliance by storing primary data in-country and using other centers for DR with data residency controls, addressing both legal and availability concerns.

Why this answer

It balances compliance with data sovereignty laws (using the in-country data center for primary storage) and maintains redundancy for disaster recovery with data residency controls. Option A is wrong because simply accepting the legal risk based on certifications is not sufficient; data sovereignty laws are regulatory requirements that must be adhered to, and the certifications do not override those laws. Option B is wrong because automatic failover to data centers outside the country would violate data sovereignty laws by allowing patient data to leave the country without proper controls.

Option D is wrong because using only one data center increases availability risk and does not address the legal concerns properly; it avoids the legal risk but introduces high operational risk.

981
MCQhard

A company is implementing a new access control system. During the project, the IT team updates the system configuration without notifying the risk team. This leads to a temporary misconfiguration that exposes sensitive data. Which process should have been followed to prevent this issue?

A.Control design approval
B.Continuous monitoring
C.Change management process
D.Vendor risk assessment
AnswerC

Change management requires configuration changes to be requested, risk-assessed, approved and tested before implementation. The unannounced update bypassed that control, causing the misconfiguration that exposed sensitive data, so this process directly addresses the stem's root cause.

Why this answer

The change management process is the correct answer because it is the formal ITIL/COBIT-aligned control that ensures all configuration changes to production systems are requested, assessed for risk impact, approved by relevant stakeholders (including the risk team), tested, and documented before implementation. In this scenario, the IT team bypassed this process by updating the access control system configuration without notifying the risk team, which is precisely the failure mode change management is designed to prevent. A properly executed change management workflow would have triggered a risk assessment and impact analysis, flagging the sensitive data exposure before the misconfiguration reached production.

Exam trap

CRISC often tests the distinction between preventive controls (change management) and detective controls (continuous monitoring) — candidates frequently select continuous monitoring because it sounds proactive, but the question asks what should have been followed to prevent the issue, not detect it.

How to eliminate wrong answers

Option A is wrong because control design approval is a one-time or periodic activity that validates the design of a control at the outset — it does not govern ongoing operational changes to a live system's configuration. Option B is wrong because continuous monitoring is a detective control that would have identified the misconfiguration after the fact, not a preventive process that stops unauthorized changes from being deployed. Option D is wrong because vendor risk assessment applies to evaluating third-party suppliers and their risk posture, which is irrelevant here since the change was made internally by the IT team.

982
Multi-Selecthard

Which THREE of the following are commonly used techniques for identifying IT risks in a large enterprise?

Select 3 answers
A.Cost-benefit analysis
B.Brainstorming sessions
C.Delphi technique
D.Risk questionnaires
E.SWOT analysis
AnswersB, C, D

Brainstorming sessions bring cross-functional stakeholders together to surface IT risks through facilitated group discussion, drawing on diverse operational knowledge. This satisfies the identification requirement by generating risks not captured by checklists alone, and scales across large enterprise business units.

Why this answer

Brainstorming sessions (B) are a core risk-identification technique in which cross-functional stakeholders and subject-matter experts collectively surface potential threats, vulnerabilities, and failure scenarios across the enterprise. The Delphi technique (C) is also a recognized identification method: it gathers anonymous, iterative expert judgments through rounds of questionnaires and controlled feedback until consensus emerges, which suits large, distributed organizations and reduces bias. Risk questionnaires (D) are commonly used to systematically collect risk information from business units, process owners, and IT staff, often via surveys or checklists, ensuring broad coverage of assets and processes.

Cost-benefit analysis (A) is a decision-support and risk-evaluation tool for comparing the costs of controls against expected benefits, not a technique for identifying risks. SWOT analysis (E) is a strategic-planning framework for assessing strengths, weaknesses, opportunities, and threats; while it can inform risk discussions, it is not one of the standard, commonly cited IT risk-identification techniques in frameworks such as ISO 31000 or ISACA's risk IT guidance.

Exam trap

The trap is that candidates may include SWOT analysis (E) because it contains 'Threats', but ISACA emphasizes more targeted techniques like brainstorming, Delphi, and questionnaires for direct risk identification.

983
MCQeasy

Based on the exhibit, which key risk indicator (KRI) would this log data be MOST useful for calculating?

A.Number of failed authentication attempts per hour.
B.Percentage of successful user logins.
C.Percentage of system uptime.
D.Number of unauthorized changes to system configurations.
AnswerA

Failed authentication attempts per hour is a quantifiable KRI derived directly from authentication log entries, giving a leading indicator of credential-stuffing or brute-force activity. The log data supplies the raw event counts, so this metric satisfies the stem's requirement for a calculable key risk indicator.

Why this answer

The log data shows repeated failed login attempts from multiple IP addresses targeting user accounts, which directly measures authentication failures over time. This makes it the most suitable source for calculating the number of failed authentication attempts per hour, a key risk indicator for brute-force or credential-stuffing attacks.

Exam trap

The trap here is that candidates may confuse authentication failure logs with broader security metrics like system uptime or configuration changes, failing to recognize that KRIs must be directly derivable from the specific log data provided.

How to eliminate wrong answers

Option B is wrong because the log data only shows failed attempts (status: FAILED) and does not include any successful login events to calculate a percentage of successful user logins. Option C is wrong because system uptime is typically measured via server health checks or SNMP monitoring, not from authentication logs that track user login events. Option D is wrong because unauthorized changes to system configurations are tracked through change management logs, configuration management databases (CMDB), or audit trails of system files, not from authentication failure logs.

984
Multi-Selecthard

A risk manager is assessing IT/OT convergence risks at a manufacturing plant. Which TWO of the following are primary risks introduced by connecting industrial control systems to the corporate network?

Select 2 answers
A.Attack path expansion from IT to OT
B.Reduced operational efficiency
C.Increased data storage costs
D.Legacy system vulnerabilities exposed
E.Simplified remote access
AnswersA, D

Bridging IT and OT networks creates a traversable route from the corporate estate into control systems. An attacker who compromises an office workstation can pivot laterally to operational technology, satisfying the stem's requirement to identify a primary convergence risk.

Why this answer

Option A (Attack path expansion from IT to OT) is correct because bridging the corporate network with industrial control systems creates a conduit through which IT-side threats—such as compromised business workstations, phishing footholds, or lateral-movement tools like PsExec—can pivot into OT environments that were previously air-gapped or isolated behind a DMZ, dramatically widening the adversary's reachable attack surface. Option D (Legacy system vulnerabilities exposed) is correct because many ICS/SCADA devices and protocols (e.g., Modbus, DNP3, older Siemens/Rockwell PLCs) were designed without authentication, encryption, or patchability, so once reachable from corporate subnets their unpatched CVEs become exploitable in ways that were not possible under physical segmentation. Option B is not a primary convergence risk—convergence is typically pursued to improve efficiency through better data visibility and analytics, not to reduce it.

Option C is incorrect because increased data storage costs are an incidental IT budgeting concern, not a security risk introduced by IT/OT connectivity. Option E is incorrect because simplified remote access is generally a business benefit of convergence (enabling remote monitoring and diagnostics), even though it must be secured; it is not itself a primary risk introduced by the connection.

Exam trap

CRISC often tests whether candidates can distinguish primary security risks (attack path expansion, legacy vulnerabilities) from operational or financial impacts (efficiency, storage costs) or benefits (simplified remote access), so the trap is selecting non-risk items as primary risks.

985
Multi-Selectmedium

A software company is defining key risk indicators (KRIs) for its cloud service availability risk. The risk owner wants indicators that provide early warning of deteriorating conditions rather than after-the-fact outcomes. Which TWO of the following are the most appropriate leading KRIs for this risk? (Choose two.)

Select 2 answers
A.Average time to restore service after a cloud availability incident.
B.Percentage of virtual machines running without current security patches.
C.Percentage of critical cloud components operating above 80% capacity utilization.
D.Number of unplanned availability outages experienced in the past quarter.
E.Count of single points of failure identified in the cloud architecture during the last review.
AnswersC, E

Capacity utilization above a defined threshold is a leading indicator because it signals approaching resource exhaustion before an outage occurs. It is measurable, tied directly to the availability risk, and provides time to scale infrastructure or rebalance workloads. Leading KRIs such as this give the risk owner an actionable warning window, unlike lagging indicators that only confirm an event after service has already degraded.

Why this answer

Leading KRIs detect conditions that precede an adverse event, giving the risk owner time to act. Capacity utilization thresholds and single points of failure both signal latent availability weaknesses before an outage occurs. Outage counts, mean time to restore, and patch currency either describe past events or relate to a different risk category, so they do not satisfy the requirement for early warning indicators specific to cloud service availability.

Exam trap

The trap here is selecting familiar operational metrics like outage counts or restore times, which are lagging indicators, when the scenario explicitly requires early warning of deteriorating conditions.

986
Matchingmedium

Match each risk management term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Risk level before controls are applied

Risk level after controls are applied

Amount of risk the organization is willing to accept

Acceptable deviation from risk appetite

Why these pairings

The correct matches are Risk with 'effect of uncertainty on objectives', Threat with 'circumstance/event that can adversely impact', and Vulnerability with 'weakness that can be exploited'. Common confusions include swapping definitions between these terms.

987
MCQmedium

A quantitative risk assessment for a server shows an ARO of 0.5 and SLE of $200,000. What is the ALE, and what does it imply?

A.ALE = $400,000; maximum possible loss
B.ALE = $100,000; single loss expectancy
C.ALE = $100,000; expected annual loss
D.ALE = $200,000; annual cost of controls
AnswerC

Multiplying ARO 0.5 by SLE $200,000 yields an ALE of $100,000, representing the expected annual loss from this risk. This satisfies the stem's quantitative requirement, giving management a monetary figure to compare against control costs when prioritising remediation.

Why this answer

ALE (Annualized Loss Expectancy) is calculated as ARO × SLE. With an ARO of 0.5 (the event is expected to occur once every two years) and an SLE of $200,000, the ALE is 0.5 × $200,000 = $100,000. This figure represents the expected average annual financial loss from this risk, which is the value used to justify the cost of controls.

Exam trap

CRISC often tests the confusion between SLE and ALE, and between ARO and its inverse — candidates who multiply SLE by 2 instead of 0.5 land on $400,000.

How to eliminate wrong answers

Option A is wrong because $400,000 results from multiplying SLE by 2 (the inverse of the ARO) rather than by the ARO itself, and 'maximum possible loss' is not what ALE measures. Option B is wrong because $100,000 is the correct numeric value but 'single loss expectancy' describes SLE, not ALE — the label is the error. Option D is wrong because $200,000 is the SLE, not the ALE, and ALE is not the annual cost of controls; it is the expected loss that controls are compared against.

988
MCQeasy

A risk practitioner is documenting how the organization handles the risk that a critical SaaS vendor could suffer an outage that halts order processing. The vendor publishes a 99.9% uptime commitment and will credit service fees if it is missed. Which action BEST addresses the residual business impact that the credit does not cover?

A.Renegotiate the service level agreement to raise the uptime commitment to 99.99%.
B.Increase the cyber insurance limit to cover business interruption losses from vendor outages.
C.Maintain a documented business continuity plan with a manual order-processing fallback and periodic testing.
D.Request the vendor's SOC 2 Type II report and file it with the vendor risk assessment.
AnswerC

Service credits compensate fees, not lost revenue, customer defection, or regulatory deadlines, so the residual impact of a prolonged order-processing halt remains with the organization. A tested manual fallback with defined recovery time objectives keeps orders flowing during an outage and demonstrates that continuity risk has been actively treated rather than merely acknowledged in the vendor contract.

Why this answer

Because service credits only refund fees and cannot restore lost orders, the organization retains the operational impact of a vendor outage. A documented and tested business continuity plan with a manual fallback directly reduces that impact by keeping order processing alive, whereas contract changes, assurance reports, and insurance all leave the business unable to operate during the outage.

Exam trap

The trap here is treating a service-level credit or a higher uptime target as mitigation, when neither restores business operations during an actual outage.

989
MCQmedium

A financial services firm has determined that a critical trading application cannot be patched for a known remote code execution vulnerability because the vendor no longer supports the platform. The risk manager decides to deploy a web application firewall (WAF) with virtual patching and network segmentation to isolate the application from the internal network. Which risk response strategy does this represent?

A.Risk acceptance
B.Risk transfer
C.Risk mitigation
D.Risk avoidance
AnswerC

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Deploying a WAF with virtual patching and network segmentation directly reduces the exploitability of the unpatched application and limits lateral movement, thereby lowering the overall risk. This aligns with the organization's decision to take action rather than transfer, avoid, or accept the risk.

Why this answer

The organization is actively reducing the likelihood and impact of a vulnerability by deploying a WAF and network segmentation. These compensating controls are classic risk mitigation actions. Risk mitigation is the appropriate strategy when an organization chooses to implement controls to bring residual risk within appetite rather than accepting, transferring, or avoiding the risk entirely.

Exam trap

The trap here is confusing risk mitigation with risk avoidance because compensating controls are used instead of removing the vulnerable system.

990
MCQmedium

During a quarterly control effectiveness test, internal audit finds that a detective control missed 15% of security incidents. The control owner claims this is within the acceptable error rate of 20%. However, the risk practitioner notes that the missed incidents were high-severity. What should the risk practitioner do?

A.Accept the control as effective since it is within the threshold
B.Escalate the findings to senior management with a recommendation to enhance the control
C.Implement a compensating control to cover high-severity incidents
D.Recommend revising the KCI threshold to include severity weighting
AnswerB

The 20% tolerance applies to aggregate error rate, not severity-weighted misses. Because the 15% failures were high-severity incidents, the control's residual risk exceeds appetite, so the practitioner must escalate to senior management with a recommendation to enhance the control.

Why this answer

The risk practitioner should escalate the findings to senior management with a recommendation to enhance the control because the detective control's failure to detect 15% of incidents, while within the 20% acceptable error rate, specifically missed high-severity incidents. High-severity incidents pose a disproportionate risk to the organization, and a control that fails to detect them is not effective in mitigating critical risks, regardless of meeting a generic threshold. Escalation ensures that management is aware of the residual risk and can authorize appropriate enhancements, such as tuning the control's detection logic or implementing additional monitoring for high-severity events.

Exam trap

The CRISC exam often tests the misconception that meeting a quantitative KCI threshold automatically means a control is effective, without considering the qualitative severity of the incidents missed.

How to eliminate wrong answers

Option A is wrong because accepting the control as effective based solely on the 20% threshold ignores the materiality of the missed incidents; a control that misses high-severity incidents is not effective for risk management, even if it meets a quantitative KCI. Option C is wrong because implementing a compensating control is a tactical response that should be directed by management after escalation, not a first action by the risk practitioner, and it bypasses the need to address the root cause of the control's failure to detect high-severity incidents. Option D is wrong because revising the KCI threshold to include severity weighting is a metric adjustment that does not directly address the immediate control deficiency; the practitioner must first report the finding to management, who can then decide on metric changes as part of a broader remediation plan.

991
MCQeasy

A retail company's IT risk manager is preparing a report for the board's audit committee. The report must summarize the current status of the top ten IT risks, the effectiveness of related controls, and any changes since the last quarter. Which of the following is the MOST important quality for this report to possess?

A.It includes every identified IT risk in the register to ensure completeness of disclosure.
B.It provides a balanced view of risk exposure and control effectiveness, including areas where remediation is behind schedule.
C.It focuses exclusively on risks that have decreased since the prior reporting period to show progress.
D.It uses detailed technical terminology to demonstrate the depth of the IT risk team's analysis.
AnswerB

Board reporting must be balanced and transparent, presenting both strengths and weaknesses. If the report omits risks with overdue remediation, the audit committee cannot fulfill its oversight role or challenge management. A balanced view supports informed governance decisions and aligns with the principle that risk reporting should enable stakeholders to understand actual exposure, not just favorable results.

Why this answer

The report's primary purpose is to enable the audit committee to oversee IT risk effectively. That requires a balanced presentation of exposures and control effectiveness, including unfavorable information such as overdue remediation. Reports skewed toward technical detail, only positive trends, or exhaustive risk lists fail to support informed governance and can hide material exposures from those accountable for oversight.

Exam trap

The trap here is equating completeness or technical depth with good board reporting, when the real requirement is balanced, decision-useful information for a governance audience.

992
MCQhard

A healthcare organization is performing a risk assessment on its electronic health record (EHR) system. The risk team has identified that a legacy interface engine transmits unencrypted patient data between two internal segments. The organization's risk appetite for data confidentiality breaches is low. The IT team proposes to accept the risk because the segments are internal and firewalls separate them from the internet. Which risk response should the risk practitioner recommend FIRST?

A.Mitigate the risk by implementing encryption for the data in transit between the segments.
B.Avoid the risk by decommissioning the legacy interface engine immediately.
C.Transfer the risk by purchasing cyber insurance covering data breach costs.
D.Accept the risk and document it in the risk register with a review date.
AnswerA

Encrypting the data in transit directly addresses the confidentiality exposure and aligns with the organization's low risk appetite. This is the most effective first response because it reduces the likelihood and impact of interception, even if an attacker compromises an internal segment. Mitigation through encryption is a preventive control that closes the identified gap rather than merely compensating for it financially or accepting it.

Why this answer

Mitigation through encryption is the recommended first response because it directly addresses the unencrypted transmission of patient data and aligns with the organization's low risk appetite for confidentiality breaches. Encryption reduces both the likelihood of successful interception and the impact if interception occurs, providing a proportionate and technically feasible control. Acceptance, transfer, and avoidance are either misaligned with appetite or unnecessarily disruptive given the availability of a targeted preventive control.

Exam trap

The trap here is treating internal network segmentation as an equivalent control to encryption, when an attacker with internal access can still intercept unencrypted traffic.

993
MCQeasy

A company is conducting an IT risk assessment for the first time. Which of the following should be the FIRST step?

A.Identify all IT assets
B.Establish the risk assessment context
C.Analyze the likelihood and impact of threats
D.Implement mitigating controls
AnswerB

Establishing the risk assessment context first defines scope, objectives, risk criteria and stakeholder expectations before any identification or analysis begins, satisfying the stem's requirement for a first step in an initial assessment. Without agreed context, subsequent risk identification lacks boundaries and consistent evaluation criteria, producing unreliable results.

Why this answer

Before any risk assessment activities can begin, the organization must establish the context—defining the scope, risk appetite, criteria for risk evaluation, and the business objectives the assessment supports. Without this foundational step, subsequent identification of assets, threat analysis, or control implementation would lack alignment with business goals and could produce irrelevant or misleading results. This aligns with the ISACA Risk IT framework and the CRISC domain of IT Risk Assessment.

Exam trap

The trap here is that candidates often jump straight to identifying assets (Option A) because it seems like the most tangible first step, but they fail to recognize that without establishing context, the asset inventory may be scoped incorrectly or lack business alignment.

How to eliminate wrong answers

Option A is wrong because identifying all IT assets is a subsequent step that depends on knowing the scope and boundaries defined during context establishment; without context, asset identification may be incomplete or misaligned. Option C is wrong because analyzing likelihood and impact of threats occurs after threats and vulnerabilities have been identified, which itself follows context establishment and asset identification. Option D is wrong because implementing mitigating controls is a risk response activity that occurs only after risks have been assessed, evaluated, and a decision to treat them has been made.

994
Multi-Selectmedium

A retail company is launching a new e-commerce platform. The risk management team has identified that the platform's payment gateway integration could be exploited to intercept customer credit card data. The team proposes several controls. Which of the following are examples of risk mitigation controls? (Choose two.)

Select 2 answers
A.Encrypting payment data in transit using TLS 1.3
B.Purchasing cyber insurance to cover financial losses from a data breach
C.Deciding not to accept credit card payments online
D.Outsourcing the payment processing to a third-party provider
E.Implementing tokenization to replace sensitive card data with non-sensitive equivalents
AnswersA, E

Encrypting payment data in transit with TLS 1.3 is a risk mitigation control that protects the confidentiality and integrity of data as it travels between the customer and the payment gateway. It reduces the likelihood of successful interception and unauthorized access, directly addressing the risk of data compromise during transmission.

Why this answer

Risk mitigation controls reduce the likelihood or impact of a risk. Tokenization and TLS encryption both directly reduce the risk of credit card data interception by making the data unusable or unreadable to attackers. Cyber insurance transfers risk, avoiding online payments avoids risk, and outsourcing shares risk; none of these directly mitigate the technical vulnerability.

Exam trap

The trap here is misclassifying risk transfer or avoidance as mitigation, especially when controls like insurance or outsourcing feel like active responses.

995
MCQhard

During a risk assessment of a legacy system, the assessor finds that no control is currently in place. The inherent risk level is 'critical'. The residual risk will be:

A.Medium
B.Critical
C.High
D.Low
AnswerB

Residual risk equals inherent risk when no control exists, because nothing reduces the likelihood or impact. With inherent risk rated critical, the residual risk remains critical, satisfying the stem's condition that no control is currently in place.

Why this answer

Residual risk is the level of risk remaining after controls are applied. Since the scenario explicitly states that no control is currently in place, the residual risk remains identical to the inherent risk level, which is 'critical'. Therefore, the residual risk is also critical.

Exam trap

The trap here is that candidates may assume residual risk is always lower than inherent risk, forgetting that without any controls, residual risk equals inherent risk by definition.

How to eliminate wrong answers

Option A is wrong because 'Medium' would imply that some risk reduction has occurred, but with no controls applied, the risk cannot be lowered from critical to medium. Option C is wrong because 'High' suggests a partial reduction in risk, which is not possible when no control exists to mitigate the inherent critical risk. Option D is wrong because 'Low' would require effective controls to significantly reduce the risk, which is absent in this scenario.

996
MCQmedium

During an IT risk assessment, the risk practitioner calculates the inherent risk score for a critical application as 25 (on a 5×5 matrix). After evaluating control effectiveness, the residual risk score is 9. What can be inferred about the controls?

A.Controls are effective in reducing the risk level
B.Additional controls are unnecessary
C.Controls are not effective because residual risk remains
D.The inherent risk was overestimated
AnswerA

Residual risk of 9 is substantially lower than the inherent risk of 25, showing the controls reduced exposure. This drop demonstrates the controls are effective, as residual risk reflects remaining risk after control effectiveness is applied to inherent risk.

Why this answer

Inherent risk of 25 (5×5 matrix, maximum) dropping to residual risk of 9 after control evaluation demonstrates that the controls materially reduced the risk exposure. A reduction from 25 to 9 is significant, indicating the controls are functioning as intended to mitigate the identified threat. This is the standard interpretation in CRISC risk analysis.

Exam trap

CRISC often tests the misconception that any remaining residual risk means controls are ineffective, when in fact residual risk is expected and its reduction ratio indicates effectiveness.

How to eliminate wrong answers

Option B is wrong because a residual risk of 9 is not zero — additional controls may still be warranted depending on the organization's risk appetite, so claiming they're unnecessary is an unsupported leap. Option C is wrong because residual risk remaining does not mean controls failed; residual risk is expected after controls, and the drop from 25 to 9 shows effectiveness. Option D is wrong because there's no evidence the inherent risk was overestimated — the assessment stands, and the control evaluation is a separate step.

997
Multi-Selecteasy

Which TWO of the following are primary sources of risk identification for IT projects?

Select 2 answers
A.Social media monitoring
B.Vendor marketing materials
C.Project documentation (e.g., scope, schedule, budget)
D.Stakeholder interviews
E.Industry benchmark reports
AnswersC, D

Project documentation such as scope, schedule and budget captures assumptions, dependencies and constraints that seed the risk register. Reviewing these artefacts surfaces schedule slippage, scope creep and funding shortfalls, making them a primary identification source for IT projects.

Why this answer

Project documentation (C) is a primary risk-identification source because reviewing the scope, schedule, and budget exposes concrete risk triggers such as unclear requirements, aggressive timelines, and funding shortfalls that are specific to the project. Stakeholder interviews (D) are also a primary source, since stakeholders—sponsors, users, vendors, and team members—hold expert judgment and direct knowledge of assumptions, constraints, and concerns that surface risks not visible in artifacts alone. Both are recognized inputs to the Identify Risks process in standards such as PMBOK, where project documents and stakeholder analysis feed directly into risk registers.

By contrast, social media monitoring (A) and industry benchmark reports (E) are secondary or external environmental inputs that may inform risk generally but are not primary project-level sources, and vendor marketing materials (B) are promotional and biased rather than a reliable risk-identification input.

Exam trap

The trap here is that candidates often mistake external or secondary sources (like industry reports or social media) as primary risk identification sources, when in fact only project-specific documentation and direct stakeholder engagement are considered primary for IT projects.

998
Multi-Selecthard

A global manufacturing company is designing its IT risk reporting program. The board has requested that reports be actionable, comparable over time, and aligned with the enterprise risk management framework. Which TWO of the following characteristics are MOST important for the IT risk reports to meet these objectives? (Choose two.)

Select 2 answers
A.Reports include only risks that have been fully mitigated to zero residual risk.
B.Reports are customized for each business unit using different risk scales to reflect local priorities.
C.Reports are generated monthly using raw technical vulnerability scan outputs.
D.Reports use consistent risk scoring criteria and definitions across all business units.
E.Reports present risk information in business context, including potential impact on strategic objectives.
AnswersD, E

Consistent scoring criteria and definitions enable comparability across business units and over time. Without a common taxonomy and rating scale, the board cannot reliably compare risks or track trends. This directly supports the requirement for comparable reporting and alignment with the enterprise risk management framework, which depends on standardized risk language and metrics.

Why this answer

Actionable, comparable, and ERM-aligned reporting requires consistent risk scoring criteria and definitions so risks can be compared across units and over time. It also requires presenting risk in business context, linking technical findings to strategic objectives so the board can prioritize. Raw scan outputs and zero-residual-risk filters fail to provide meaningful governance information, and divergent local scales break comparability.

Exam trap

The trap here is assuming that more frequent or more detailed technical reporting automatically improves board-level risk reporting, when comparability and business context are what make reports actionable and ERM-aligned.

999
MCQhard

A financial services firm is deploying a security information and event management (SIEM) platform. The risk practitioner is asked to advise on how to keep the alert pipeline trustworthy so that detection and response decisions rest on reliable data. Which of the following is the MOST important control to prioritize?

A.Enable full packet capture retention for at least ninety days across all network segments.
B.Tune correlation rules to reduce the number of alerts reaching the analyst queue.
C.Protect the integrity and time synchronization of log sources and the collection path end to end.
D.Maximize the number of log sources ingested so that no event type is missed.
AnswerC

Detection and response decisions depend on logs being authentic and correctly ordered in time. If an attacker can alter logs in transit or manipulate host clocks, correlation breaks down and incidents can be hidden or fabricated. Securing the collection path and enforcing consistent time synchronization is therefore the foundational control for a trustworthy pipeline.

Why this answer

A SIEM is only as reliable as the events it receives, so the priority is ensuring those events are authentic and consistently time-stamped. Protecting log sources and the transport path against tampering, and synchronizing clocks, prevents attackers from hiding activity or fabricating evidence. Volume, tuning, and packet capture all matter operationally but none of them restores confidence in data that could have been altered.

Exam trap

The trap here is equating more logging and better tuning with trustworthy detection, when the real dependency is the integrity and time ordering of the events themselves.

1000
MCQhard

A risk practitioner is asked to reduce the number of KRIs tracked from 50 to 20. Which KRIs should be prioritized for removal?

A.KRIs that have been consistently below threshold for two years
B.KRIs that are not directly mapped to any risk in the risk register
C.KRIs that require manual data collection
D.KRIs that have high volatility
AnswerB

KRIs lacking a risk-register mapping measure nothing the organisation has agreed to manage, so they consume tracking effort without informing risk decisions. Removing them first satisfies the stem's constraint of cutting 50 KRIs to 20 while preserving indicators tied to registered risks, keeping the remaining set aligned to actual exposure.

Why this answer

KRIs that are not directly mapped to any risk in the risk register provide no actionable insight for risk monitoring or decision-making. Removing them reduces noise and ensures the remaining 20 KRIs are all linked to specific risks, which is essential for effective risk-based reporting and resource allocation.

Exam trap

The trap here is that candidates often confuse operational efficiency (manual collection) or statistical behavior (low threshold, high volatility) with the fundamental requirement that every KRI must be directly traceable to a specific risk in the risk register.

How to eliminate wrong answers

Option A is wrong because KRIs consistently below threshold for two years may indicate effective controls or low inherent risk, but they could still be valuable for confirming risk acceptance or control effectiveness; removal should be based on relevance, not just low readings. Option C is wrong because manual data collection is a cost or efficiency concern, not a criterion for whether a KRI is meaningful for risk monitoring; a manually collected KRI can still be critical if it maps to a high-priority risk. Option D is wrong because high volatility in a KRI often signals a risk that requires close monitoring; removing volatile KRIs could blind the organization to emerging threats or control failures.

1001
Multi-Selecthard

Which THREE of the following are valid risk identification methods according to ISACA's Risk IT Framework? (Select exactly 3.)

Select 3 answers
A.Segregation of duties
B.Scenario analysis
C.Risk acceptance
D.SWOT analysis
E.Brainstorming
AnswersB, D, E

Scenario analysis is a recognised risk identification method in ISACA's Risk IT Framework, exploring plausible future events to surface risks. It satisfies the stem's requirement by providing a structured, forward-looking technique that complements other valid identification methods listed in the framework.

Why this answer

Scenario analysis (B) is a valid risk identification method in ISACA's Risk IT Framework because it explores plausible future events and their potential impact on IT objectives, helping surface risks that routine monitoring might miss. SWOT analysis (D) is also valid, as it systematically examines internal strengths and weaknesses plus external opportunities and threats to identify risks affecting IT strategy and operations. Brainstorming (E) is likewise a recognized identification technique, using structured group discussion to elicit a broad range of potential IT risk events from stakeholders.

Segregation of duties (A) is a preventive control that reduces fraud and error risk rather than a method for identifying risks, and risk acceptance (C) is a risk response option in the Risk IT process, not an identification technique.

Exam trap

The trap here is that candidates often confuse risk identification techniques with risk response or control activities, mistakenly selecting segregation of duties or risk acceptance as valid identification methods when they are actually part of risk mitigation and risk treatment processes.

1002
MCQeasy

A hospital's IT risk manager is preparing a quarterly risk report for the executive committee. The report currently lists 240 technical vulnerabilities with CVSS scores but no business context. The CIO asks for a report that helps executives decide where to allocate limited remediation funding. Which change best aligns the report with risk response and reporting objectives?

A.Report only the total count of vulnerabilities and the percentage remediated within the past quarter.
B.Group vulnerabilities by the business processes and assets they affect, and express exposure in terms of potential impact and likelihood.
C.Sort the vulnerabilities alphabetically by vendor name so the report is easier to navigate.
D.Increase the report's technical depth by including exploit code snippets and packet captures for each vulnerability.
AnswerB

Executive decision-making requires business context, not raw technical counts. Mapping vulnerabilities to the processes and assets they threaten, then expressing exposure through impact and likelihood, lets leaders compare remediation options against organizational objectives and risk appetite. This transforms a technical inventory into actionable risk information, which is the core purpose of risk reporting to senior stakeholders.

Why this answer

Risk reporting to executives must translate technical findings into business language. Grouping vulnerabilities by affected processes and assets and expressing exposure through impact and likelihood gives leaders the context needed to prioritize remediation spending against organizational objectives. Raw counts, technical artifacts, or alphabetical ordering do not support funding decisions because they omit the business consequences that drive risk-based prioritization.

Exam trap

The trap here is equating more technical detail or cleaner formatting with better risk reporting, when executives actually need business impact and likelihood context to make funding decisions.

1003
MCQmedium

A manufacturer is identifying IT risk associated with a legacy inventory management system that no longer receives vendor security patches. The risk practitioner documents the unsupported platform as a vulnerability. Which additional asset-based factor should the practitioner evaluate to determine how this vulnerability contributes to overall risk?

A.The frequency of the organization's internal audit cycle
B.The value and criticality of the asset to business operations
C.The total count of open findings in the risk register
D.The number of vendors in the organization's third-party inventory
AnswerB

A vulnerability's contribution to risk depends on what the affected asset supports and how critical it is. Evaluating the legacy inventory system's value and criticality to manufacturing operations determines the potential business consequence if the unpatched platform is exploited, which converts an abstract technical weakness into a meaningful risk statement that management can prioritize against other risks.

Why this answer

Vulnerabilities gain risk significance through the assets they affect, so determining the value and criticality of the legacy inventory system establishes the potential business consequence of exploitation. Without this asset context, an unpatched platform is merely a technical finding. Vendor counts, audit cadence, and open finding totals are organizational metrics that do not describe how much loss the manufacturer would suffer from this specific vulnerability.

Exam trap

The trap here is treating a vulnerability as inherently risky without linking it to asset criticality, when identical weaknesses produce vastly different risk depending on the business value of the affected asset.

1004
MCQhard

A global retailer is identifying IT risks related to a new cloud-based point-of-sale (POS) system. The risk practitioner wants to use a top-down approach. Which of the following is the MOST appropriate starting point for this approach?

A.Reviewing the service level agreement with the cloud provider.
B.Mapping the POS system to the retailer's strategic objectives and critical business processes.
C.Cataloging all cloud infrastructure components used by the POS system.
D.Conducting a vulnerability scan of the cloud POS environment.
AnswerB

A top-down approach begins with the organization's strategy and critical business processes, then identifies IT risks that could impede them. Mapping the POS system to strategic objectives ensures that risk identification is aligned with what matters most to the business. This helps prioritize risks that could affect revenue, customer trust, and regulatory compliance.

Why this answer

A top-down risk identification approach starts with the organization's strategic objectives and critical business processes, then identifies IT risks that could affect them. Mapping the POS system to these objectives ensures that risk identification is business-driven and prioritizes risks with the greatest potential impact on the retailer's goals. This approach contrasts with bottom-up methods that begin with assets or vulnerabilities.

Exam trap

The trap here is equating technical activities like vulnerability scanning or asset cataloging with a top-down approach, when top-down actually begins with business strategy and objectives.

1005
MCQmedium

A large retailer is implementing a new point-of-sale (POS) system. The project manager wants to identify risks related to payment card data security. Which risk identification technique would be MOST effective for this purpose?

A.Risk register review from past projects
B.Brainstorming session with the project team
C.Data Flow Diagram (DFD) review
D.SWOT analysis
AnswerC

A data flow diagram review maps where cardholder data enters, moves through, and leaves the POS system, exposing interception and storage points. This satisfies the payment card data security focus by revealing risks tied to actual data movement rather than generic threat lists.

Why this answer

A Data Flow Diagram (DFD) review is most effective because it visually maps how payment card data moves through the POS system—from card swipe to authorization to storage—identifying exactly where data is at rest, in transit, or processed. This allows the team to pinpoint specific PCI DSS control gaps (e.g., unencrypted transmission, unnecessary retention) that other techniques might miss.

Exam trap

The trap here is that candidates often choose 'Brainstorming session with the project team' because it seems collaborative and proactive, but they fail to recognize that for technical data security risks, a structured, visual analysis like a DFD review is far more precise and complete.

How to eliminate wrong answers

Option A is wrong because a risk register from past projects captures generic historical risks but cannot reveal the unique data flows, integration points, or PCI DSS compliance gaps specific to this new POS system. Option B is wrong because a brainstorming session with the project team relies on subjective, unstructured input and may overlook subtle data-handling vulnerabilities that only a systematic diagram-based analysis can expose. Option D is wrong because SWOT analysis evaluates strengths, weaknesses, opportunities, and threats at a strategic level, not the granular technical details of payment data movement and storage required for PCI DSS risk identification.

1006
MCQhard

A technology startup is developing a mobile payment application. During a risk identification workshop, the team identifies a risk that the application may not comply with Payment Card Industry Data Security Standard (PCI DSS) requirements. What is the BEST way to categorize this risk?

A.Compliance risk.
B.Strategic risk.
C.Operational risk.
D.Reputational risk.
AnswerA

PCI DSS is a mandated external standard, so failing to meet it is a regulatory obligation breach. Compliance risk specifically covers violations of laws, regulations and standards, which is the precise axis here rather than operational or strategic risk.

Why this answer

Non-compliance with PCI DSS is a direct violation of regulatory requirements, making it a compliance risk. For a mobile payment application handling cardholder data, PCI DSS mandates specific security controls (e.g., encryption of PAN, access controls, logging). Failure to meet these standards exposes the startup to fines, legal sanctions, and potential loss of the ability to process payments.

Exam trap

The trap here is that candidates confuse the primary risk category (compliance) with the potential business impact (reputational or operational), but CRISC expects the root cause—failure to meet a regulatory standard—to be classified as compliance risk.

How to eliminate wrong answers

Option B (Strategic risk) is wrong because strategic risk relates to high-level business decisions (e.g., entering a new market, choosing a technology stack) that affect long-term goals, not a specific regulatory mandate. Option C (Operational risk) is wrong because operational risk involves failures in day-to-day processes, systems, or human error (e.g., server downtime, transaction processing errors), not a compliance gap. Option D (Reputational risk) is wrong because reputational risk is a consequence of other risks (e.g., a data breach from non-compliance), not the primary categorization of the risk itself.

1007
MCQmedium

Refer to the exhibit. If the control objective is to prevent unauthorized access via MFA, what does this test result indicate?

A.The control is ineffective because only 30 logins were sampled.
B.The control is fully effective.
C.The control is effective only if MFA is required for all users.
D.The control is effective for the sample but may not be for the population.
AnswerD

Testing a sample cannot prove the MFA control operates across the entire population, so the result supports effectiveness only for tested items. Residual risk remains that untested accounts bypass MFA, meaning the control objective is not fully assured.

Why this answer

Sampling only tests a subset of the population, so a passing result on 30 logins provides assurance only about those sampled items — it does not prove the control operates effectively across the entire population. This is the fundamental limitation of audit sampling: the conclusion is limited to the sample unless statistical sampling with a defined confidence level is used.

Exam trap

The trap is treating a passing sample as proof of full control effectiveness; candidates forget that sampling provides reasonable, not absolute, assurance and that conclusions are limited to the tested population.

How to eliminate wrong answers

Option A is wrong because sample size alone does not make a control ineffective; 30 items can be an adequate sample if statistically justified, and the result shown is a pass. Option B is wrong because full effectiveness cannot be claimed from a sample — that would require testing the entire population or a statistically valid sample with appropriate confidence. Option C is wrong because the test result does not address whether MFA is required for all users; that is a scope/design question, not what the sample result indicates.

1008
Multi-Selectmedium

Which THREE of the following are components of Loss Magnitude in the FAIR framework?

Select 3 answers
A.Reputational damage
B.Vulnerability severity
C.Incident response costs
D.Recovery costs
E.Threat event frequency
AnswersA, C, D

Reputational damage is a secondary loss factor within FAIR's Loss Magnitude, capturing downstream consequences beyond primary response costs. It satisfies the stem's requirement by representing a distinct loss form (secondary) that organisations must quantify alongside productivity and response losses when assessing risk.

Why this answer

In the FAIR (Factor Analysis of Information Risk) framework, Loss Magnitude is the probable loss resulting from a risk event and is decomposed into primary and secondary loss forms, each with six loss categories: productivity, response, replacement, fines and judgments, competitive advantage, and reputation. Option A (Reputational damage) is correct because reputation loss is one of the six secondary loss categories that make up Loss Magnitude. Option C (Incident response costs) is correct because response costs — the expense of managing an incident (forensics, communications, management time) — are one of the six loss categories within Loss Magnitude.

Option D (Recovery costs) is correct because replacement/recovery costs, the expense of restoring or replacing assets after an event, are likewise one of the six Loss Magnitude categories. Option B (Vulnerability severity) is not part of Loss Magnitude; vulnerability is a factor in the Frequency/Loss Event Probability side of the FAIR ontology (resistance strength against threat capability). Option E (Threat event frequency) is not part of Loss Magnitude either; it is a primary factor under Loss Event Frequency in FAIR.

Exam trap

The trap is confusing factors from Loss Event Frequency (vulnerability severity, threat event frequency) with components of Loss Magnitude — candidates must remember that FAIR separates frequency and magnitude, and only certain costs and impacts belong to magnitude.

1009
Multi-Selectmedium

Which TWO are characteristics of inherent risk?

Select 2 answers
A.Based on the effectiveness of current controls
B.Used to determine control gap
C.Risk level before controls
D.Risk level after controls
E.Based on the assumption that no controls exist
AnswersC, E

Inherent risk is the exposure that exists before any controls, mitigations or countermeasures are applied. It establishes the baseline against which residual risk is compared, so the risk level prior to controls is a defining characteristic rather than a by-product of control effectiveness.

Why this answer

Option C is correct because inherent risk is defined as the level of risk that exists before any controls are applied, representing the raw exposure of an asset or process to a threat. Option E is correct because inherent risk is assessed under the assumption that no controls exist, which establishes a baseline against which control effectiveness can later be measured. Together, these two characteristics distinguish inherent risk from residual risk, which is the risk remaining after controls are implemented.

Option A is incorrect because basing risk on the effectiveness of current controls describes residual risk, not inherent risk. Option B is incorrect because determining the control gap is a derived analysis activity that compares inherent and residual risk, not a defining characteristic of inherent risk itself. Option D is incorrect because the risk level after controls is the definition of residual risk.

Exam trap

The trap here is that candidates often confuse inherent risk with residual risk, mistakenly thinking that inherent risk includes the effect of existing controls, which is a common misconception tested in CRISC questions.

1010
MCQeasy

A risk analyst is identifying threats to a retail bank's newly deployed public application programming interface (API) that allows third-party fintech partners to initiate account transfers. Which of the following is the MOST relevant threat to consider during risk identification for this API?

A.A regional power outage causes the bank's secondary data center to fail over to the primary site.
B.An attacker exploits broken object level authorization to initiate transfers from accounts they do not own.
C.An insider in the facilities team accidentally spills coffee on a server in the data center.
D.A competitor hires a private investigator to photograph the bank's executive team at a conference.
AnswerB

Broken object level authorization is a leading API threat, especially where endpoints accept account or object identifiers. For an API that initiates transfers, this flaw lets an authenticated but unauthorized party manipulate another customer's account. This directly threatens integrity and financial loss, making it the most relevant threat to identify. It is listed in the OWASP API Security Top 10 and is common in fintech integrations with insufficient per-object access checks.

Why this answer

The most relevant threat to a public API that initiates account transfers is abuse of authorization logic, such as broken object level authorization, because it directly enables unauthorized financial transactions. Physical accidents, competitive intelligence, and power outages are generic threats that do not address the specific exposure created by exposing transfer functionality to third parties. Identifying API-specific threats ensures controls such as object-level access checks and strong authentication are designed appropriately.

Exam trap

The trap here is selecting a familiar generic threat like a power outage or physical accident instead of the API-specific authorization abuse that directly threatens transfer integrity.

1011
MCQmedium

A risk manager is evaluating a control that addresses a high-risk finding from an internal audit. Which of the following is the MOST important factor in determining whether the control is effective?

A.The vendor's reputation for providing reliable security solutions
B.Key control indicators (KCIs) such as control deficiency rate and test results
C.The cost of the control relative to the asset value
D.The control's alignment with industry best practices
AnswerB

KCIs provide measurable evidence of how reliably the control performs in practise, directly satisfying the audit finding's requirement to prove effectiveness. Deficiency rate and test results reveal whether the control operates consistently, which is the decisive factor when a high-risk finding demands demonstrable, ongoing assurance rather than design intent alone.

Why this answer

B is correct because the effectiveness of a control is determined by its ability to reduce risk to an acceptable level, which is directly measured by key control indicators (KCIs) such as the control deficiency rate and test results. These metrics provide empirical evidence of whether the control is operating as intended and mitigating the identified high-risk finding. Without such performance data, any assessment of effectiveness is speculative.

Exam trap

The trap here is that candidates often confuse 'alignment with best practices' (Option D) with proof of effectiveness, but CRISC requires evidence of actual control performance, not just theoretical compliance.

How to eliminate wrong answers

Option A is wrong because a vendor's reputation does not guarantee that the specific control implementation is effective in the organization's unique environment; effectiveness must be validated through actual testing and monitoring. Option C is wrong because cost relative to asset value is a factor in cost-benefit analysis, not a direct measure of control effectiveness; a low-cost control can be effective, and a high-cost control can fail. Option D is wrong because alignment with industry best practices is a design consideration, not a proof of operational effectiveness; a control may follow best practices but still have implementation flaws or be insufficient for the specific risk context.

1012
Multi-Selectmedium

An organization is integrating IT risk into its enterprise risk management (ERM) program. Which TWO of the following are key benefits of this integration?

Select 2 answers
A.Reduces the overall risk appetite of the organization
B.Eliminates the need for separate IT risk reporting
C.Guarantees that all IT risks are mitigated
D.Ensures IT risk is considered in strategic decisions
E.Provides a consistent risk language across the organization
AnswersD, E

Embedding IT risk into ERM feeds technology exposure into enterprise-level planning, so strategic decisions account for IT risk alongside financial and operational risk. This satisfies the integration goal of aligning IT risk with strategic decision-making.

Why this answer

Option D is correct because integrating IT risk into ERM ensures that technology-related exposures are evaluated alongside financial, operational, and strategic risks when leadership makes strategic decisions, so IT risk becomes part of governance rather than a siloed technical concern. Option E is correct because ERM integration establishes common risk terminology, scales, and criteria (for example, shared likelihood/impact definitions and risk appetite statements), giving the whole organization a consistent risk language for identifying, assessing, and reporting IT and non-IT risks. Option A is incorrect because integration does not inherently reduce the organization's risk appetite; risk appetite is set by leadership and integration only helps align IT risk with it.

Option B is incorrect because IT risk still requires its own reporting detail and metrics even when aggregated into ERM. Option C is incorrect because no framework guarantees that all IT risks are mitigated; integration improves visibility and prioritization, not elimination of all risk.

Exam trap

CRISC often tests the difference between benefits of integration (strategic alignment, consistent language) and misconceptions (eliminating reporting, guaranteeing mitigation, reducing appetite) — candidates frequently select absolute statements like 'eliminates' or 'guarantees' which are almost always wrong in risk management contexts.

1013
MCQeasy

A risk practitioner is facilitating a risk assessment workshop for a new cloud-based customer relationship management (CRM) system. The business owner is eager to launch the system and states that the risk assessment is unnecessary because the cloud provider is ISO 27001 certified. Which of the following is the MOST appropriate response from the risk practitioner?

A.Perform a penetration test instead of a risk assessment to satisfy security requirements.
B.Agree with the business owner and skip the risk assessment since the provider is certified.
C.Explain that certification reduces some third-party risks but the organization must still assess its own risks and controls.
D.Escalate the matter to senior management because the business owner is refusing to comply with policy.
AnswerC

ISO 27001 certification provides assurance about the provider's security program, but the customer must still assess risks related to configuration, data integration, user access, and compliance. The risk assessment is necessary to identify and manage the organization's specific risks. The practitioner should educate the business owner on shared responsibility. This response is balanced and accurate.

Why this answer

ISO 27001 certification provides assurance that the cloud provider has a robust security management system, but it does not eliminate the customer's responsibility to assess its own risks. The organization must still evaluate risks related to data integration, user access, configuration, and compliance. The risk practitioner should explain this shared responsibility model.

Skipping the assessment or substituting it with a penetration test would be inappropriate.

Exam trap

The trap here is assuming that a vendor's certification completely transfers or eliminates the customer's risk, ignoring the shared responsibility model.

1014
MCQeasy

A company's control monitoring dashboard shows that a key control has been operating effectively for six months. However, a recent audit revealed a material weakness. Which of the following is the MOST likely reason?

A.The KRI thresholds were set incorrectly.
B.The control was not tested during the period.
C.The monitoring frequency was too low.
D.The control owner was not trained.
AnswerA

Incorrect thresholds can prevent detection of control failures, leading to a false effective status.

Why this answer

The dashboard shows the control operating effectively for six months, yet a material weakness was found. This discrepancy most likely arises because the Key Risk Indicator (KRI) thresholds were set incorrectly, meaning the monitoring system was calibrated to report acceptable risk levels even when the control was actually failing. Incorrect thresholds cause false positives in the dashboard, masking the true control deficiency.

Exam trap

The trap here is that candidates assume a control operating effectively on a dashboard must be working correctly, overlooking that the dashboard's accuracy depends on correctly configured KRI thresholds.

How to eliminate wrong answers

Option B is wrong because the control was being monitored continuously via the dashboard, implying it was tested; the issue is not lack of testing but flawed measurement. Option C is wrong because monitoring frequency being too low would typically show gaps or missing data points, not a consistent six-month record of effectiveness. Option D is wrong because lack of training would likely cause inconsistent control operation or procedural errors, not a systematic dashboard misrepresentation of effectiveness.

1015
MCQhard

A risk practitioner is facilitating a risk identification workshop for a retail bank's new real-time payments service. Business stakeholders keep proposing controls such as multifactor authentication and transaction limits as 'risks.' Which action BEST keeps the identification phase technically sound?

A.Reframe each suggestion by asking what adverse event the control is meant to prevent, and record that adverse event as the risk.
B.Escalate to the CISO because stakeholders who cannot distinguish controls from risks should not participate in risk identification workshops.
C.Accept the control suggestions as risks but tag them so they are excluded later during risk evaluation and treatment planning.
D.Record both the controls and the underlying events in the register, then let the risk committee decide which entries to retain.
AnswerA

This is the correct technique. Controls are responses to risk, so the practitioner must surface the underlying event the control addresses. Asking what could go wrong that multifactor authentication or transaction limits would mitigate yields genuine risks such as account takeover or unauthorized high-value transfers. The controls are then captured separately in treatment planning, where they belong. This keeps the identification phase focused on uncertain events affecting objectives and preserves a clean, estimable register for the retail bank.

Why this answer

Risk identification captures uncertain events that could affect objectives, while controls are the responses selected later during risk treatment. When stakeholders offer a control, the practitioner should ask what adverse event it is meant to prevent and record that event as the risk. This preserves the register's integrity, allows likelihood and impact to be estimated meaningfully, and keeps the control where it belongs, in treatment planning, so evaluation and appetite comparison remain coherent.

Exam trap

The trap here is treating a control suggestion as a risk entry instead of translating it back into the adverse event the control is intended to prevent.

1016
MCQhard

A multinational corporation operates in 15 countries with decentralized control monitoring systems. Each regional office uses different tools and processes for monitoring operational risks. The corporate risk team has consolidated quarterly reports, but the board recently raised concerns about inconsistencies and late identification of emerging risks. A root cause analysis revealed that regional monitoring teams define key risk indicators (KRIs) differently and report on different timeframes. Additionally, there is no centralized platform to aggregate data. The risk manager must recommend a solution that balances local autonomy with global visibility. Which option is the most effective?

A.Create a policy requiring regional risk teams to follow the same KRI definitions and reporting schedule.
B.Implement a centralized risk and control monitoring platform that aggregates data and enforces common reporting standards.
C.Standardize monitoring tools across all regions globally.
D.Increase the frequency of board risk committee meetings to twice per month.
AnswerB

A centralised platform enforces common KRI definitions and reporting timeframes across all regions, eliminating the definitional and cadence inconsistencies the root cause analysis identified, while aggregated dashboards give the board timely global visibility without removing regional ownership of monitoring.

Why this answer

A centralized risk and control monitoring platform that aggregates data while enforcing common reporting standards directly addresses the root causes: inconsistent KRI definitions, differing timeframes, and no aggregation mechanism. It preserves local autonomy in how regions execute monitoring while giving the corporate risk team and board consistent, timely global visibility. This is the only option that solves both the standardization and aggregation problems simultaneously.

Exam trap

CRISC often tests the difference between a policy-only fix (which addresses definitions but not aggregation) and a platform-based fix (which addresses both) — candidates pick the policy answer because it sounds simpler and cheaper, but it fails to solve the board's visibility problem.

How to eliminate wrong answers

Option A is wrong because a policy mandating identical KRI definitions and schedules addresses consistency but not aggregation or timeliness — regions would still report through disconnected tools, and the board would still lack a consolidated view. Option C is wrong because standardizing tools globally is a heavy-handed, expensive approach that may not fit regional regulatory or operational differences, and it does not by itself enforce common KRI definitions or reporting cadence. Option D is wrong because increasing board meeting frequency treats the symptom (late identification) rather than the cause (no aggregation, inconsistent KRIs) and adds overhead without improving data quality.

1017
MCQhard

In a qualitative risk assessment using a 5x5 heat map, an IT risk is rated with likelihood 4 and impact 5. According to typical heat map conventions (5=Critical, 4=High, 3=Medium, 2=Low, 1=Informational), what is the overall risk rating?

A.Low
B.Medium
C.High
D.Critical
AnswerD

Correct. 4x5=20 is in the critical range (15-25).

Why this answer

In a typical 5x5 risk heat map, the overall risk rating is determined by the intersection of likelihood and impact values. With likelihood 4 and impact 5, the cell falls in the 'Critical' zone (commonly defined as likelihood 4-5 and impact 4-5). This aligns with the convention where 5=Critical, 4=High, 3=Medium, 2=Low, 1=Informational, making D the correct answer.

Exam trap

The trap here is that candidates may incorrectly multiply likelihood and impact (4 x 5 = 20) and then try to map that product to a rating, rather than using the heat map's intersection logic, leading them to choose 'High' instead of 'Critical'.

How to eliminate wrong answers

Option A is wrong because a likelihood of 4 and impact of 5 produce a risk score well above the threshold for 'Low' (which typically covers likelihood 1-2 and impact 1-2). Option B is wrong because 'Medium' risk usually corresponds to likelihood 2-3 and impact 2-3, not the high values given. Option C is wrong because while 'High' (rating 4) is close, the combination of likelihood 4 and impact 5 maps to the highest severity zone (Critical), not High, in standard heat map conventions.

1018
Multi-Selecteasy

An organization is considering adopting the NIST Cybersecurity Framework to manage cybersecurity risk. Which of the following are core functions of the framework? (Choose TWO.)

Select 2 answers
A.Prevent
B.Mitigate
C.Protect
D.Analyze
E.Identify
AnswersC, E

Protect is a NIST CSF core function, encompassing access control, awareness training, data security and protective technology. It satisfies the framework's structure by delivering the safeguards that limit or contain the impact of a potential cybersecurity event.

Why this answer

The NIST Cybersecurity Framework defines five core functions: Identify, Protect, Detect, Respond, and Recover. Option E (Identify) is correct because it covers understanding the organization's assets, risks, and governance to prioritize cybersecurity efforts. Option C (Protect) is correct because it encompasses safeguards such as access control, awareness training, and data security to limit or contain the impact of a potential cybersecurity event.

Options A (Prevent), B (Mitigate), and D (Analyze) are not among the five core functions, even though they describe related risk-management concepts; the framework uses Detect, Respond, and Recover instead of those terms.

Exam trap

CRISC often tests the exact five functions of the NIST CSF, and candidates may confuse them with other risk management terms like 'Prevent' or 'Mitigate' which are not part of the core functions.

1019
Multi-Selecthard

A risk practitioner is assessing a proposed bring-your-own-device (BYOD) programme for a law firm where attorneys will access matter files containing privileged client data. The CISO asks which controls are MOST important to reduce the risk of data leakage from lost or compromised personal devices. (Choose two.)

Select 2 answers
A.Require attorneys to sign an acceptable use policy acknowledging that personal devices may be inspected.
B.Block all access to matter files from outside the firm's office network by IP allowlisting.
C.Increase cyber insurance limits to cover regulatory fines from client data breaches.
D.Deploy mobile device management (MDM) with remote wipe and containerization of firm data.
E.Enforce full-device encryption with keys escrowed by the firm and require a device passcode.
AnswersD, E

MDM with remote wipe and a managed container lets the firm selectively remove or lock matter files without erasing the attorney's personal photos and apps. Containerization keeps privileged data inside an encrypted, policy-controlled space, so a compromised personal app cannot freely read or exfiltrate client information.

Why this answer

The two controls that actually prevent privileged client data from being exposed when a personal device is lost or compromised are escrowed full-device encryption and MDM with remote wipe plus containerization. Together they protect data at rest and allow selective removal of firm data, while the other choices are policy, perimeter, or financial measures that do not stop the leakage scenario.

Exam trap

The trap here is selecting policy or insurance options because they sound comprehensive, when the scenario asks specifically for controls that reduce data leakage from lost or compromised personal devices.

1020
MCQeasy

An organization purchases cyber insurance to cover potential losses from data breaches. This is an example of:

A.Risk Avoidance
B.Risk Transfer
C.Risk Mitigation
D.Risk Acceptance
AnswerB

Cyber insurance shifts the financial consequence of a data breach to an insurer for a premium, which is risk transfer. The organisation retains the risk itself but transfers the potential loss, unlike avoidance, reduction or acceptance.

Why this answer

Purchasing cyber insurance transfers the financial risk of a data breach to the insurer, making it a classic example of risk transfer. In risk management, transfer shifts the impact of a loss to a third party (e.g., an insurance carrier) without eliminating the underlying threat or vulnerability. This aligns with the CRISC domain of Risk Response and Mitigation, where transfer is a distinct response strategy.

Exam trap

The trap here is that candidates confuse risk transfer with risk mitigation, thinking insurance reduces the likelihood of a breach, when in fact it only shifts the financial consequences.

How to eliminate wrong answers

Option A is wrong because risk avoidance would mean eliminating the activity that causes the risk (e.g., not storing any sensitive data), not insuring against it. Option C is wrong because risk mitigation involves implementing controls (e.g., encryption, firewalls) to reduce the likelihood or impact of a breach, not transferring financial liability. Option D is wrong because risk acceptance means formally acknowledging the risk and bearing the potential loss without purchasing insurance or implementing additional controls.

1021
MCQmedium

A critical vendor is being onboarded. The vendor risk appetite policy requires SOC 2 Type II reports for critical vendors. The vendor has provided a SOC 2 Type I report. What should the risk manager do?

A.Request a SOC 2 Type II report from the vendor
B.Downgrade the vendor to a lower tier
C.Exempt the vendor from the requirement
D.Accept the Type I report as sufficient
AnswerA

The policy mandates SOC 2 Type II, which tests control operating effectiveness over a period (typically 6–12 months), whereas Type I only attests design at a single point in time. Requesting the Type II report satisfies the critical vendor requirement directly.

Why this answer

The vendor risk appetite policy explicitly requires SOC 2 Type II reports for critical vendors, and the vendor only provided a Type I report. The risk manager must enforce the policy as written, so the correct action is to request the Type II report from the vendor. Accepting a Type I or exempting the vendor would violate the stated policy and undermine the control.

Exam trap

CRISC often tests the difference between SOC 2 Type I and Type II — candidates may think Type I is 'good enough' or that downgrading the vendor is a pragmatic solution, but the exam expects strict adherence to the stated policy and the correct escalation path.

How to eliminate wrong answers

Option B is wrong because downgrading the vendor to a lower tier is a policy change that has not been authorized and does not address the missing Type II report — it sidesteps the requirement rather than fulfilling it. Option C is wrong because exempting the vendor from the requirement bypasses the risk appetite policy without proper exception approval and would leave a critical vendor unassessed. Option D is wrong because a SOC 2 Type I report only covers the suitability of controls at a point in time, not their operating effectiveness over a period — it does not satisfy a Type II requirement.

1022
MCQhard

A risk manager is using the FAIR model to quantify cyber risk. After analyzing a ransomware scenario, the probable loss event frequency (LEF) is estimated at 0.2 per year, and the probable loss magnitude (LM) is $5 million. What is the annualized loss expectancy (ALE) in this scenario?

A.$500,000
B.$250,000
C.$5,000,000
D.$1,000,000
AnswerD

Multiplying loss event frequency (0.2) by loss magnitude ($5 million) yields $1,000,000 annualised loss expectancy, satisfying the FAIR requirement to express risk as a monetary annual figure. This correctly applies the ALE formula, giving the risk manager a quantified basis for comparing the ransomware scenario against other risks.

Why this answer

Annualized Loss Expectancy (ALE) is calculated as Loss Event Frequency (LEF) multiplied by Loss Magnitude (LM). Here, LEF = 0.2 per year and LM = $5,000,000, so ALE = 0.2 × $5,000,000 = $1,000,000. This represents the expected annualized financial loss from the ransomware scenario.

Exam trap

CRISC often tests whether candidates can correctly apply the ALE formula and avoid confusing it with LM alone or misapplying the frequency — the trap is picking the Loss Magnitude ($5M) or miscalculating the multiplication.

How to eliminate wrong answers

Option A ($500,000) is wrong because it would result from multiplying 0.1 × $5M or 0.2 × $2.5M, neither of which matches the given inputs. Option B ($250,000) is wrong because it would result from 0.05 × $5M, which misapplies the LEF. Option C ($5,000,000) is wrong because it is simply the Loss Magnitude without applying the frequency — it ignores the probability of occurrence entirely.

1023
Multi-Selectmedium

A retail company is conducting a risk assessment for its new e-commerce platform. The assessment team is identifying inherent risks and wants to ensure they consider both internal and external factors that could increase the likelihood of a risk event. Which TWO of the following are examples of external factors that can increase inherent risk? (Choose two.)

Select 2 answers
A.New data privacy regulations imposed by the government.
B.The increasing sophistication of cybercriminals targeting retail payment systems.
C.The company's decision to use outdated encryption algorithms.
D.The company's high employee turnover rate in the IT department.
E.The lack of security awareness training for the company's employees.
AnswersA, B

New data privacy regulations are an external factor because they are imposed by an outside authority and can affect the organization's compliance obligations. Non-compliance can lead to fines and reputational damage, increasing the impact of a risk event. Regulations are part of the external environment and can change the risk landscape. They are not controlled by the organization, so they are considered when assessing inherent risk.

Why this answer

External factors that increase inherent risk are those outside the organization's control, such as the evolving threat landscape and new regulations. The sophistication of cybercriminals and government-imposed data privacy regulations are both external. Internal factors like lack of training, outdated encryption, and high turnover are within the organization's control and are considered internal vulnerabilities or weaknesses.

Exam trap

The trap here is confusing internal weaknesses, such as lack of training or outdated encryption, with external factors like threat actor capabilities or regulatory changes.

1024
MCQmedium

A multinational retailer operates in a jurisdiction that requires all payment data to remain within national borders. The risk practitioner is asked to verify that a newly deployed cloud payment service complies with this requirement before it goes live. Which activity best provides this assurance?

A.Reviewing the cloud provider's publicly available service level agreement for uptime commitments.
B.Confirming that the provider holds a current ISO/IEC 27001 certification for its information security management system.
C.Verifying the configured data storage and processing regions and obtaining contractual commitments on data location.
D.Obtaining the cloud provider's general SOC 2 Type II report covering security and availability.
AnswerC

Residency compliance depends on both technical configuration and legal commitment. Confirming that the service is provisioned only in in-country regions, including backups and disaster recovery, demonstrates where data actually resides, while contractual language obligates the provider to maintain that restriction. Together they give direct, verifiable assurance tied to the specific regulatory requirement before go-live.

Why this answer

Data residency obligations are satisfied only by evidence of where data actually resides plus a binding commitment that it stays there. Verifying the provisioned regions, including replication and backup locations, and securing contractual data-location terms directly addresses the regulatory requirement. General certifications and availability agreements speak to security or uptime, not geographic confinement of payment data.

Exam trap

The trap here is accepting a well-known security certification as proof of regulatory data residency compliance.

1025
MCQmedium

A financial services firm's IT risk register shows that a legacy payment gateway has a high inherent risk of data breach. Management decides to purchase a cyber insurance policy that covers up to $5 million per incident, while keeping the gateway in production unchanged. Which risk response option has management chosen?

A.Risk mitigation
B.Risk avoidance
C.Risk acceptance
D.Risk transfer
AnswerD

Risk transfer shifts the financial consequence of a risk to a third party, typically through insurance or contractual agreements. By purchasing a cyber insurance policy while leaving the gateway in production, management accepts the operational risk but transfers the financial impact up to $5 million to the insurer. This matches the definition of risk transfer in CRISC risk response.

Why this answer

The scenario describes management choosing to keep the high-risk payment gateway in production while purchasing an insurance policy to cover financial losses. This is risk transfer because the financial impact of a potential breach is shifted to the insurer. Risk mitigation would require implementing controls to reduce likelihood or impact, avoidance would require eliminating the gateway, and acceptance would mean bearing the loss without transferring it.

Exam trap

The trap here is assuming that any risk response involving insurance automatically counts as risk mitigation because it reduces financial exposure, when in fact insurance transfers the financial consequence rather than reducing the underlying likelihood or impact.

1026
Matchingmedium

Match each compliance framework to its primary focus.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Information security management system

Cybersecurity risk management framework

Payment card data security

Healthcare data privacy and security

Why these pairings

The correct matches align each framework with its primary regulatory focus. Common confusions occur between security-focused frameworks like PCI DSS and privacy-focused ones like HIPAA, or between data protection (GDPR) and financial reporting (SOX).

1027
MCQmedium

An internal audit found that a control designed to prevent duplicate payments was bypassed in 5% of transactions. The control owner argues that the control is still effective because the bypass rate is low. What is the BEST response from a risk perspective?

A.Accept the bypass rate as within acceptable tolerance.
B.Document that the control is 95% effective and close the finding.
C.Investigate why bypasses occur and implement compensating controls.
D.Re-classify the control as a detective control instead of preventive.
AnswerC

A 5% bypass rate means the preventive control is not operating as designed, so its effectiveness claim is unsupported. Investigating root causes and adding compensating controls addresses the residual risk directly, rather than accepting an unverified bypass rate as tolerable.

Why this answer

The best response because a 5% bypass rate indicates a control weakness that could lead to financial loss or fraud. From a risk perspective, the root cause of the bypasses must be investigated to understand why the control is being overridden, and compensating controls should be implemented to mitigate the residual risk. Simply accepting or documenting the rate without action ignores the potential for systemic issues or targeted exploitation.

Exam trap

The trap here is that candidates may assume a low bypass rate is automatically acceptable (Option A) or that documenting effectiveness is sufficient (Option B), without recognizing that risk management requires understanding and addressing the root cause of control failures, not just measuring their frequency.

How to eliminate wrong answers

Option A is wrong because accepting the bypass rate as within acceptable tolerance without understanding the root cause or business impact is premature and ignores the risk that even a 5% bypass could result in significant duplicate payments over time. Option B is wrong because documenting the control as 95% effective and closing the finding fails to address the underlying control weakness and does not ensure that the bypasses are not indicative of a larger process or system flaw. Option D is wrong because re-classifying the control as detective instead of preventive does not resolve the issue; it merely changes the label, while the control's purpose (preventing duplicate payments) remains unfulfilled, and the bypasses still need to be addressed.

1028
MCQmedium

An organization is updating its IT risk universe. Which of the following is the MOST important factor to consider when defining the universe?

A.Historical loss data only
B.All potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks
C.Risks that are within the current budget to mitigate
D.Only risks that have been realized in the past year
AnswerB

Defining the risk universe requires capturing every plausible IT risk before any assessment or scoring occurs. Restricting it to high-likelihood items would blind the organisation to low-probability, high-impact threats across cyber, operational, compliance, third-party, project and change domains, undermining the completeness the universe demands.

Why this answer

The IT risk universe should be comprehensive — it must capture all potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks. Defining the universe is an identification exercise, not a prioritization exercise; filtering by likelihood, budget, or past occurrence at this stage would create blind spots and undermine the risk register's completeness.

Exam trap

CRISC often tests the misconception that risk identification should be filtered by likelihood, budget, or historical occurrence, when in fact the universe must be comprehensive before any prioritization occurs.

How to eliminate wrong answers

Option A is wrong because relying only on historical loss data is backward-looking and misses emerging or unexperienced risks that have never materialized but could still be severe. Option C is wrong because limiting the universe to risks within the current mitigation budget conflates identification with treatment — risks should be identified first and prioritized later based on appetite and cost. Option D is wrong because restricting to risks realized in the past year excludes low-frequency/high-impact events and new threat vectors, which is exactly the kind of gap that causes major incidents.

1029
MCQhard

A multinational retailer's risk committee is reviewing its risk register. The CISO argues that a newly identified vulnerability in the point-of-sale system should be escalated immediately to the board. The risk manager notes that the vulnerability has a low likelihood of exploitation and existing compensating controls reduce the impact to a tolerable level. Which of the following is the MOST appropriate action for the risk manager to take?

A.Document the vulnerability in the risk register with its assessed likelihood, impact, and compensating controls, and report it through the normal risk reporting process.
B.Override the CISO's assessment and remove the vulnerability from the risk register to avoid unnecessary alarm.
C.Escalate the vulnerability to the board because all identified vulnerabilities must be reported to the highest governance body.
D.Close the vulnerability without documentation because the compensating controls already reduce the risk to an acceptable level.
AnswerA

The risk manager should apply the organization's risk assessment criteria, document the vulnerability with its likelihood, impact, and compensating controls, and route it through the standard reporting process. Since the residual risk is tolerable, board escalation is not required. This approach maintains an accurate risk register and respects defined escalation thresholds based on risk appetite.

Why this answer

The risk manager should follow the organization's established risk assessment and reporting criteria. Since the vulnerability has low likelihood and compensating controls keep residual risk within tolerance, it does not meet the threshold for board escalation. Documenting it in the risk register with supporting rationale and reporting through normal channels ensures accurate risk visibility while avoiding unnecessary escalation.

Exam trap

The trap here is equating a CISO's escalation request with a governance requirement, leading to unnecessary board reporting instead of applying the organization's defined risk appetite and escalation thresholds.

1030
MCQhard

You are the IT risk manager for a mid-sized e-commerce company that processes over 10,000 transactions per day. The company recently migrated its customer database from an on-premises SQL Server to a cloud-based PostgreSQL instance on AWS RDS. The database contains personally identifiable information (PII) including names, addresses, and credit card numbers (stored as encrypted tokens). The migration was performed by the DevOps team with minimal involvement from the security team. Two weeks after the migration, the company experienced a data breach where an attacker exfiltrated a subset of customer records. The forensic investigation revealed that the attacker exploited a misconfigured security group that allowed inbound traffic from the internet on port 5432 (PostgreSQL default port). Additionally, the database had a publicly accessible endpoint, and the master user password was weak (eight characters, no special characters). The attacker used a brute-force attack to guess the password. The security group has since been corrected, and the password has been changed to a strong one. The breach notification laws require reporting within 72 hours. The CEO wants to understand the root cause and prevent recurrence. As the risk manager, which of the following actions should you recommend as the MOST effective to prevent a similar incident?

A.Implement infrastructure-as-code (IaC) security scanning and policy enforcement in the CI/CD pipeline to prevent insecure configurations.
B.Deploy an intrusion detection system (IDS) to monitor database traffic for brute-force attempts.
C.Hire a dedicated database administrator to review all database configurations weekly.
D.Conduct quarterly security audits of cloud infrastructure configurations.
AnswerA

Infrastructure-as-code scanning catches the misconfigured security group and publicly accessible endpoint before deployment, enforcing policy in the CI/CD pipeline the DevOps team already uses. This directly addresses the root cause: security controls were bypassed during migration, so shifting detection left prevents recurrence without relying on manual review.

Why this answer

The root cause is the misconfigured security group and weak password, both of which stem from insufficient security review and lack of automated controls. Implementing infrastructure-as-code (IaC) security scanning and policy enforcement in the CI/CD pipeline would automatically catch and block insecure configurations (e.g., publicly accessible database, weak passwords) before deployment, thus preventing similar incidents. Option B is incorrect because an IDS detects attacks in progress but does not prevent the initial misconfiguration.

Option C is incorrect because relying on a single DBA to manually review all configurations weekly is error-prone and does not scale. Option D is incorrect because quarterly audits are too infrequent to catch misconfigurations that could be exploited immediately after deployment.

1031
Multi-Selecteasy

Which TWO of the following are key attributes of effective risk reporting?

Select 2 answers
A.Includes full risk register details
B.Only issued when a risk incident occurs
C.Provides actionable information for decision-makers
D.Tailored to the specific needs of the audience
E.Sent to all employees by email
AnswersC, D

Purpose of reporting.

Why this answer

Effective risk reporting must provide actionable information that enables decision-makers to prioritize and respond to risks. Option C is correct because reports should highlight key risk indicators (KRIs), trends, and control effectiveness, not just raw data, so that management can make informed decisions about risk treatment and resource allocation.

Exam trap

The trap here is that candidates often mistake completeness (full risk register) for effectiveness, not realizing that effective reporting is about relevance and conciseness for the specific audience, not data volume.

1032
MCQeasy

An organization is designing a risk indicator monitoring program for its key financial risks. Which of the following is the BEST example of a key risk indicator (KRI) for credit risk?

A.Percentage of loans that are in default or non-performing.
B.Number of employees who completed cybersecurity training.
C.Percentage of network uptime over the past month.
D.Employee turnover rate in the finance department.
AnswerA

Non-performing and defaulted loans directly measure realised credit deterioration, quantifying exposure to borrower failure. As a KRI it tracks the likelihood and magnitude of credit loss, giving forward-looking warning of rising counterparty risk rather than operational or market indicators.

Why this answer

A key risk indicator (KRI) for credit risk must directly measure the likelihood or impact of a borrower failing to meet their obligations. The percentage of loans that are in default or non-performing is a direct, quantitative measure of credit risk exposure, as it reflects the actual realization of credit losses. This aligns with the CRISC focus on monitoring risk levels to trigger timely responses.

Exam trap

The trap here is that candidates confuse KRIs with KPIs or operational metrics, selecting a generic performance measure (like training completion or uptime) instead of a risk-specific indicator that directly quantifies credit exposure.

How to eliminate wrong answers

Option B is wrong because the number of employees who completed cybersecurity training is a key performance indicator (KPI) for security awareness, not a KRI for credit risk; it measures activity, not the creditworthiness of borrowers. Option C is wrong because percentage of network uptime is an operational risk KRI related to IT availability, not a measure of credit risk. Option D is wrong because employee turnover rate in the finance department is a human resources metric that may indicate operational inefficiency but does not directly measure the probability of default or credit loss.

1033
MCQhard

A multinational bank is subject to GDPR and local data protection laws. The risk practitioner is reviewing a risk treatment plan for a new customer analytics platform that will process personal data across three jurisdictions. The plan proposes to rely on the vendor's standard contractual clauses (SCCs) as the primary control for cross-border data transfers. Which factor is MOST important for the risk practitioner to evaluate when assessing the adequacy of this risk response?

A.Whether the vendor's SCCs have been updated to the latest regulatory version and whether a transfer impact assessment has been completed for each jurisdiction.
B.Whether the analytics platform uses encryption in transit and at rest for all personal data.
C.Whether the vendor has a SOC 2 Type II report covering the analytics platform's security controls.
D.Whether the vendor's data retention policy aligns with the bank's internal records management schedule.
AnswerA

SCCs are a legal transfer mechanism, but their adequacy depends on the current regulatory version and a jurisdiction-specific transfer impact assessment. The risk practitioner must verify that the clauses are valid and that local laws do not undermine them. This evaluation ensures the control actually mitigates the regulatory and legal risk of cross-border transfers, rather than merely appearing compliant on paper.

Why this answer

When SCCs are used as a cross-border transfer control, their adequacy depends on being current with regulatory requirements and being supported by a transfer impact assessment for each destination jurisdiction. The risk practitioner must evaluate legal validity and local law conflicts, not just technical security or retention practices. This ensures the risk response actually mitigates the regulatory risk of unlawful data transfers under GDPR and local laws.

Exam trap

The trap here is focusing on technical security controls like encryption or SOC 2 reports when the risk is the legal adequacy of the cross-border transfer mechanism.

1034
MCQmedium

A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:

A.Risk Transfer
B.Risk Mitigation
C.Risk Acceptance
D.Risk Avoidance
AnswerB

Manual overrides and added monitoring reduce the likelihood or impact of the legacy system's failure while it remains in service, which is risk mitigation. The system cannot be replaced immediately, so avoidance and acceptance are ruled out; the controls lower the high likelihood identified in the assessment.

Why this answer

Implementing manual overrides and additional monitoring reduces the probability or impact of the legacy system failure without eliminating the risk entirely. This is the definition of risk mitigation, as it applies controls to lower the residual risk to an acceptable level while the system remains in operation.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk acceptance' because the system is still running with known vulnerabilities, but the key differentiator is that active controls are being applied to reduce the risk, not merely acknowledged.

How to eliminate wrong answers

Option A is wrong because risk transfer would involve shifting the financial burden of failure to a third party (e.g., purchasing cyber insurance or outsourcing the system), not adding internal controls. Option C is wrong because risk acceptance means formally acknowledging the risk without taking any action to reduce it, which contradicts the decision to implement overrides and monitoring. Option D is wrong because risk avoidance would require removing the system or the activity causing the risk, such as decommissioning the legacy system entirely, which is explicitly stated as not immediately possible.

1035
MCQeasy

Which of the following is a limitation of quantitative risk analysis?

A.Results are not comparable across organizations.
B.It is data-intensive and time-consuming.
C.It is subjective and difficult to communicate.
D.It does not provide financially meaningful values.
AnswerB

Quantitative risk analysis assigns monetary values and probabilities, requiring substantial historical loss data, modelling expertise, and calculation effort. This data-intensive, time-consuming nature limits its practicality, satisfying the stem's request for a genuine limitation rather than a benefit of the quantitative approach.

Why this answer

Quantitative risk analysis assigns numeric, often monetary, values to risk using models such as ALE (SLE × ARO) or Monte Carlo simulation. Its principal drawback is that it requires substantial historical loss data, asset valuations, and modeling effort, making it resource-intensive and slow to perform compared with qualitative approaches like risk matrices. This data dependency and time cost is the recognized limitation tested here.

Exam trap

CRISC often tests the confusion between qualitative and quantitative limitations—candidates incorrectly attribute subjectivity and communication difficulty (qualitative weaknesses) to quantitative analysis, or mistake its financial comparability for a drawback.

How to eliminate wrong answers

Option A is wrong because quantitative results expressed in monetary terms are actually highly comparable across organizations and business units—that comparability is a key advantage, not a limitation. Option C is wrong because subjectivity and communication difficulty are hallmarks of qualitative analysis (e.g., Delphi, risk matrices), not quantitative methods, which produce objective numeric outputs. Option D is wrong because quantitative analysis specifically delivers financially meaningful values such as ALE and expected loss, which is its primary strength.

1036
MCQmedium

A software development company is assessing risks related to its cloud infrastructure. The risk team uses a qualitative approach and creates a risk register. During a review, the team notices that a risk related to unauthorized access to customer data has a likelihood rating of 4 (on a 5-point scale) and an impact rating of 5. The risk owner decides to implement multi-factor authentication (MFA) and role-based access control (RBAC). After implementation, the likelihood rating is reduced to 2, while impact remains 5. What is the PRIMARY purpose of updating the risk register with these new ratings?

A.To satisfy regulatory requirements for risk documentation
B.To document the cost of the controls implemented
C.To reflect the current risk posture and support risk-based decision making
D.To provide evidence for the internal audit team
AnswerC

Updating the risk register with new likelihood and impact ratings after implementing controls reflects the current residual risk. This information is essential for prioritizing risks, allocating resources, and making informed risk-based decisions. It ensures that management has an accurate view of the risk landscape and can determine if further action is needed.

Why this answer

The risk register is a living document that should be updated to reflect changes in risk levels after controls are implemented. Updating the ratings provides an accurate view of residual risk, which supports prioritization, resource allocation, and risk-based decision making. While compliance and audit are important, they are not the primary purpose of the update.

Exam trap

The trap here is focusing on secondary benefits like compliance or audit evidence, rather than the core purpose of maintaining an accurate risk profile for decision making.

1037
Multi-Selecthard

A risk practitioner is assessing the security of an organization's use of public cloud infrastructure. The organization stores sensitive data in object storage buckets. Which TWO of the following are the MOST significant risks related to misconfigured cloud storage? (Choose two.)

Select 2 answers
A.Insufficient logging and monitoring of access to bucket objects.
B.Use of a single cloud region for data residency.
C.Inability to export data due to vendor lock-in.
D.Unauthorized public access to data due to overly permissive bucket policies.
E.Lack of encryption at rest for stored objects.
AnswersA, D

Without adequate logging and monitoring, unauthorized access or changes to bucket contents may go undetected. This impairs incident detection and response, and prevents accountability. For sensitive data, the inability to detect and investigate access is a critical risk that compounds the impact of any misconfiguration.

Why this answer

Misconfigured cloud storage most often results in data exposure through overly permissive access policies and goes unnoticed due to insufficient logging and monitoring. These two risks directly affect confidentiality and the ability to detect and respond to incidents. Other options are either less directly related to misconfiguration or are not security risks in the same sense.

Exam trap

The trap here is focusing on encryption or availability concerns when the primary risks of misconfiguration are unauthorized access and lack of detection.

1038
MCQmedium

A hospital's radiology department wants to let referring physicians upload imaging orders through a new web portal that stores protected health information (PHI). The risk practitioner must ensure the portal meets the HIPAA Security Rule. Which of the following is the MOST appropriate control to implement first?

A.Deploy full-disk encryption on all endpoint devices used by referring physicians.
B.Sign a business associate agreement with the portal software vendor.
C.Conduct a risk analysis to identify threats and vulnerabilities to the PHI processed by the portal.
D.Implement role-based access control for all portal users.
AnswerC

The HIPAA Security Rule requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI. This risk analysis is the foundational first step that drives the selection of all subsequent administrative, physical, and technical safeguards for the new portal.

Why this answer

The HIPAA Security Rule is built on a risk management framework, and its first required implementation specification is an accurate and thorough risk analysis. Before selecting encryption, access controls, or contracts, the organization must identify and evaluate the risks to electronic PHI. That analysis then informs the selection of reasonable and appropriate safeguards for the portal.

Exam trap

The trap here is assuming that a specific technical safeguard like encryption is always the first step, when HIPAA requires a risk analysis to drive control selection.

1039
MCQeasy

During a risk assessment for a critical financial application, the IT risk manager identifies a vulnerability in the application's authentication module. The exploit would require authenticated access. Which risk rating is most appropriate if the vulnerability has a CVSS base score of 9.0, but the application is behind a strong firewall and requires two-factor authentication?

A.Medium, after considering the compensating controls
B.Low, because the application requires authenticated access
C.High, because CVSS base score is 9.0
D.Very high, due to the criticality of the application
AnswerA

CVSS base scores assume no environmental mitigations. The firewall restricting exposure and two-factor authentication raising exploitation difficulty are compensating controls that reduce likelihood, so the contextual rating drops from critical to medium despite the 9.0 base score.

Why this answer

The CVSS base score of 9.0 reflects the intrinsic severity of the vulnerability, but the final risk rating must incorporate compensating controls. The strong firewall and two-factor authentication (2FA) significantly reduce the likelihood of exploitation, as the attacker would need to bypass both network-level filtering and an additional authentication factor. In CRISC methodology, risk is a function of likelihood and impact; here, the controls lower the likelihood, resulting in a Medium residual risk rating despite the high base score.

Exam trap

The trap here is that candidates assume a high CVSS base score automatically dictates a High or Very High risk rating, ignoring the CRISC principle that risk must be evaluated after applying compensating controls and environmental modifiers.

How to eliminate wrong answers

Option B is wrong because requiring authenticated access does not automatically make the risk Low; the vulnerability still exists and could be exploited by an authenticated user, and the CVSS score already accounts for the attack vector (network) and complexity (low). Option C is wrong because the CVSS base score alone does not determine the final risk rating; it must be adjusted for environmental and compensating controls per the CVSS specification (e.g., modified attack vector, modified authentication). Option D is wrong because application criticality influences impact but not the final risk rating without considering likelihood; the compensating controls reduce the likelihood, so Very High is not appropriate.

1040
MCQeasy

When integrating IT risk into the enterprise risk management (ERM) program, what is the PRIMARY benefit?

A.Improved compliance with IT standards
B.Reduced IT operational costs
C.Increased frequency of risk assessments
D.Better alignment of IT risk with business objectives
AnswerD

Embedding IT risk within ERM expresses technical exposures in business-impact terms, so decisions weigh them against strategic objectives rather than treating them as isolated technology issues. This satisfies the stem's primary-benefit requirement, giving leadership a consolidated, objective-aligned view of risk.

Why this answer

Integrating IT risk into ERM ensures that IT risk decisions are directly linked to business strategy and objectives, enabling leadership to prioritize risks that could impact critical business outcomes. This alignment is the primary benefit because it transforms IT risk from a technical concern into a strategic business driver, facilitating better resource allocation and governance.

Exam trap

The trap here is that candidates confuse operational benefits (cost reduction, compliance, or process frequency) with the strategic benefit of business alignment, which is the core purpose of integrating IT risk into ERM.

How to eliminate wrong answers

Option A is wrong because improved compliance with IT standards is a secondary outcome, not the primary benefit; compliance supports risk management but does not inherently align IT risk with business goals. Option B is wrong because reducing IT operational costs is a potential operational efficiency gain, not the core purpose of ERM integration, which focuses on strategic risk alignment rather than cost-cutting. Option C is wrong because increased frequency of risk assessments is a tactical process change that does not guarantee better business alignment; ERM integration prioritizes relevance and decision-making over assessment cadence.

1041
MCQeasy

A hospital's IT risk register lists a risk that its medical imaging archive could become unavailable. The risk owner has documented the risk, set a review date, and decided to take no action because the potential impact is within the hospital's risk appetite. Which risk treatment option has the risk owner selected?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerB

Acceptance is the deliberate decision to retain a risk without additional treatment when it falls within the organization's risk appetite. Documenting the risk, assigning an owner, and setting a review date are the hallmarks of formal acceptance, because the organization retains awareness and re-evaluates if conditions change. The hospital's decision matches this definition exactly: no action taken, exposure acknowledged, and the risk remains on the register.

Why this answer

Formal risk acceptance occurs when an organization decides to retain a risk because it falls within the defined risk appetite, while documenting the decision, assigning an owner, and scheduling periodic review. The hospital's actions match this pattern precisely. Mitigation would add controls, avoidance would remove the activity, and transfer would shift the impact to a third party; none of those occurred, so acceptance is the correct characterization.

Exam trap

The trap here is assuming that taking no action is always negligence, when a documented, owner-assigned, review-scheduled decision within appetite is the legitimate treatment known as acceptance.

1042
MCQeasy

After a risk assessment, a company decides to stop using a third-party service that has high residual risk. This is an example of:

A.Risk Mitigation
B.Risk Avoidance
C.Risk Transfer
D.Risk Acceptance
AnswerB

Risk avoidance eliminates the activity generating the risk entirely, so the high residual risk from the third-party service ceases to exist rather than being reduced, transferred or accepted. Discontinuing the service satisfies the stem's constraint of removing exposure, unlike mitigation which would retain the relationship while adding controls.

Why this answer

By discontinuing the use of the third-party service, the company eliminates the risk entirely rather than reducing or accepting it. This is the definition of risk avoidance, where the activity giving rise to the risk is ceased. The decision is based on the residual risk being too high to be acceptable or cost-effectively mitigated.

Exam trap

The trap here is that candidates confuse 'avoidance' with 'mitigation' because both involve action, but avoidance eliminates the risk source entirely, whereas mitigation reduces but does not remove the risk.

How to eliminate wrong answers

Option A is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact of a risk, not stopping the activity entirely. Option C is wrong because risk transfer would involve shifting the risk to another party (e.g., through insurance or outsourcing), not ceasing the service. Option D is wrong because risk acceptance means formally acknowledging and tolerating the residual risk without taking further action, which is the opposite of stopping the service.

1043
MCQeasy

An external audit finds that a control is not operating as designed. The auditor recommends corrective action. What should the risk practitioner do FIRST?

A.Implement the auditor's recommendation immediately
B.Develop a remediation plan with the control owner
C.Update the risk register with the auditor's finding
D.Assess the impact of the control deficiency on residual risk
AnswerD

Assessing how the control deficiency affects residual risk establishes whether exposure exceeds tolerance before any remediation is chosen. This determines urgency and priority, ensuring corrective action is proportionate rather than reacting to the audit finding alone.

Why this answer

The risk practitioner must first assess the impact of the control deficiency on residual risk because the finding may not represent a material risk to the organization. Without understanding the severity and likelihood of the risk, any remediation or reporting could be misprioritized. This aligns with the CRISC framework's emphasis on risk-based decision-making before action.

Exam trap

The trap here is that candidates confuse the urgency of an audit finding with the need for immediate action, when the correct first step is always to evaluate the risk impact before any remediation or reporting.

How to eliminate wrong answers

Option A is wrong because implementing the auditor's recommendation immediately bypasses risk analysis and may waste resources on low-impact findings or introduce unintended side effects. Option B is wrong because developing a remediation plan without first understanding the risk impact could lead to misaligned controls or over-investment in non-critical areas. Option C is wrong because updating the risk register is a documentation step that should follow the impact assessment to ensure the register reflects accurate risk levels.

1044
MCQeasy

A hospital network is identifying IT risks for its newly deployed medical imaging archive. The risk practitioner wants to document risks in a way that links each risk to the business process it could disrupt. Which CRISC concept is the practitioner applying when connecting an IT risk to the business objective it threatens?

A.Risk identification through business process mapping.
B.Penetration testing of the imaging network.
C.Control self-assessment of the imaging archive configuration.
D.Vulnerability scanning of the archive servers.
AnswerA

Linking an IT risk to the business process and objective it can disrupt is the essence of business process mapping during risk identification. It ensures risks are framed in terms of business impact, not just technical faults, so prioritization reflects what the hospital actually cares about, such as timely diagnosis and patient safety. This business-centric framing is a core CRISC expectation.

Why this answer

Connecting each IT risk to the business process and objective it can disrupt is business process mapping within risk identification. It shifts the conversation from technical faults to business consequences, enabling the hospital to prioritize risks that affect patient care and regulatory obligations. This linkage is what makes a risk register useful for decision making rather than a mere inventory of technical issues.

Exam trap

The trap here is confusing an assurance activity like scanning or testing, which finds weaknesses, with the identification activity that ties a risk to the business objective it endangers.

1045
MCQmedium

You are a risk analyst for a financial institution that uses a legacy mainframe system for core banking transactions. The mainframe is critical for daily operations, but it is no longer supported by the vendor. The system has known vulnerabilities that cannot be patched due to compatibility issues. The institution has a risk appetite that is very low for any disruption to core banking services. Recently, there was a minor outage caused by a hardware failure, which was resolved quickly, but it highlighted the system's fragility. The IT director proposes to migrate to a modern system, but the migration will take 2 years and cost $5 million. The board is concerned about the cost and timeline. You need to recommend an immediate risk treatment to reduce the likelihood of a major outage while the migration is underway. Which of the following is the BEST course of action?

A.Accept the risk because the migration plan is in place.
B.Implement redundant hardware for critical components and conduct regular failover testing.
C.Negotiate with the vendor for extended support.
D.Purchase business interruption insurance to cover potential losses.
AnswerB

Redundant hardware plus failover testing reduces the likelihood that a single component failure causes a major outage, addressing the fragility highlighted by the recent incident. It is immediate, unlike the two-year migration, and suits the very low disruption appetite.

Why this answer

Implementing redundant hardware for critical components and conducting regular failover testing directly reduces the likelihood of a major outage by addressing the single point of failure exposed by the recent hardware failure. This is an immediate risk treatment that does not depend on the 2-year migration timeline, and it aligns with the institution's very low risk appetite for core banking disruption.

Exam trap

The trap here is that candidates may choose option D (insurance) because it seems like a quick financial fix, but CRISC emphasizes that risk treatment must first address likelihood reduction before considering financial transfer, especially when the risk appetite is very low.

How to eliminate wrong answers

Option A is wrong because simply accepting the risk while the migration is underway ignores the immediate fragility highlighted by the recent outage and the known unpatched vulnerabilities; risk acceptance is not appropriate when the risk appetite is very low and a treatment is feasible. Option C is wrong because the system is no longer supported by the vendor, so negotiating for extended support is unlikely to succeed or may only provide limited, costly patches that do not address the hardware fragility; it also does not reduce the likelihood of a hardware-related outage. Option D is wrong because purchasing business interruption insurance only transfers the financial impact of a major outage, not the likelihood of it occurring; it does nothing to reduce the probability of a disruption, which is the primary concern given the very low risk appetite.

1046
MCQmedium

When using STRIDE for threat modeling, which threat category involves an attacker gaining unauthorized access to a system by pretending to be a legitimate user?

A.Repudiation
B.Information Disclosure
C.Tampering
D.Spoofing
AnswerD

Spoofing covers impersonating a legitimate user, system or component to gain unauthorised access. Pretending to be a valid user directly matches this STRIDE category, unlike Tampering, Repudiation, Information Disclosure, Denial of Service or Elevation of Privilege.

Why this answer

Spoofing in STRIDE refers to impersonating something or someone else to gain unauthorized access, such as using stolen credentials.

1047
MCQmedium

Which of the following threat actors is MOST likely to be motivated by financial gain and possess moderate to high technical capabilities?

A.Organized crime
B.Hacktivist
C.Nation-state APT
D.Script kiddie
AnswerA

Organised crime groups pursue profit through ransomware, business email compromise and fraud, funding the moderate-to-high technical capability the stem requires. Unlike hacktivists driven by ideology or insiders exploiting authorised access, they deliberately invest in tooling and skills, making them the threat actor whose primary motivation is financial gain.

Why this answer

Organized crime groups are primarily motivated by financial gain and often have sophisticated technical skills to carry out attacks such as ransomware, data theft, or fraud.

1048
MCQmedium

In developing a risk scenario, connecting a threat event to business impact is crucial. Which of the following is the BEST example of a properly connected risk scenario?

A.A firewall misconfiguration allows unauthorized access, causing a security incident.
B.A ransomware attack encrypts files, leading to IT department overtime.
C.An insider steals data, leading to legal fees.
D.A DDoS attack causes website unavailability for 4 hours, resulting in $500,000 lost sales and customer churn.
AnswerD

This scenario chains a specific threat event (DDoS attack) to a measurable operational consequence (four hours of website unavailability) and then to quantified business impact ($500,000 lost sales plus customer churn), demonstrating the causal linkage the stem demands.

Why this answer

A properly connected risk scenario must link a specific threat event to a quantified or clearly articulated business impact. Option D does this precisely: a DDoS attack (threat event) causes website unavailability for 4 hours (operational impact) resulting in $500,000 lost sales and customer churn (financial and reputational business impact). This chain from threat to measurable business consequence is what CRISC expects in risk scenario development.

Exam trap

CRISC often tests the threat-to-business-impact linkage — candidates select answers that stop at technical or IT-internal consequences instead of tracing through to financial, regulatory, or reputational business impact.

How to eliminate wrong answers

Option A is wrong because it stops at 'security incident' — a technical outcome, not a business impact, so the scenario is incomplete. Option B is wrong because 'IT department overtime' is an internal operational cost, not a meaningful business impact like revenue loss, regulatory penalty, or customer defection. Option C is wrong because while legal fees are a business impact, the scenario lacks specificity — no quantification, no timeframe, and no clear linkage to organizational objectives, making it weaker than D.

1049
Multi-Selecthard

Which THREE of the following are essential components of a risk register that should be documented during risk identification? (Select exactly 3.)

Select 3 answers
A.Quantified monetary impact
B.Risk owner
C.Root cause
D.Mitigation plan
E.Risk description
AnswersB, C, E

Assigning a named risk owner satisfies the accountability requirement of risk identification, ensuring each entry has a person responsible for monitoring and treatment. The register must record this alongside the risk description and assessment, so ownership is traceable rather than left with the risk team collectively.

Why this answer

The risk register must capture B (Risk owner), because every identified risk needs an accountable individual responsible for monitoring and managing it throughout its lifecycle. C (Root cause) is essential because documenting the underlying source or driver of the risk enables proper analysis and effective treatment rather than just addressing symptoms. E (Risk description) is required to clearly articulate the nature of the risk, including the event, its potential consequences, and context, so it can be understood and prioritized.

A (Quantified monetary impact) is not always essential at the identification stage, since qualitative or semi-quantitative assessments may suffice initially and quantification often occurs later during analysis. D (Mitigation plan) is a risk treatment output that follows assessment and is not a core identification component, as the register first needs to record the risk itself before responses are defined.

Exam trap

The trap here is that candidates often confuse the risk identification phase with the risk assessment phase, selecting 'Quantified monetary impact' because they think it is needed upfront, when in fact it is only determined after the risk has been identified and analyzed.

1050
MCQhard

After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:

A.Risk Transfer
B.Risk Avoidance
C.Risk Acceptance
D.Risk Mitigation
AnswerC

Proceeding with a launch where residual risk exceeds appetite, while monitoring regularly, is deliberate risk acceptance. The organisation acknowledges the exposure and chooses to retain it rather than mitigate, transfer or avoid it, which defines acceptance as the risk response.

Why this answer

The risk manager's decision to proceed with the launch despite residual risk exceeding the risk appetite, while committing to regular monitoring, is the definition of risk acceptance. In IT risk management, this acknowledges that the remaining risk is tolerable for business objectives, and the monitoring plan ensures any escalation is detected early. This is not a passive decision but an active, documented acceptance of the residual risk level.

Exam trap

In the CRISC exam, the nuance is that risk acceptance is not inaction but a deliberate, documented decision to tolerate residual risk above appetite with ongoing monitoring, which candidates mistakenly confuse with risk mitigation or avoidance.

How to eliminate wrong answers

Option A is wrong because risk transfer would involve shifting the financial impact of the risk to a third party (e.g., cyber insurance or outsourcing), not proceeding with internal monitoring. Option B is wrong because risk avoidance would mean canceling or not launching the product to eliminate the risk entirely, which contradicts the decision to proceed. Option D is wrong because risk mitigation would require implementing additional controls to reduce the residual risk below the appetite, not accepting it above the threshold.

Page 13

Page 14 of 15

Page 15