Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 1051–1062

1062 questions total · 15pages · All types, answers revealed

Page 14

Page 15 of 15

1051
Multi-Selecthard

A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)

Select 3 answers
A.Contract compliance reviews
B.Ongoing monitoring via annual reassessments
C.Review of vendor's cyber insurance policy
D.Initial onboarding assessment including security questionnaires
E.Vendor self-assessment without validation
AnswersA, B, D

Contract compliance reviews verify that the vendor's actual security and privacy practises match the contractual obligations agreed at onboarding, providing the assurance the financial services company needs that third-party risk remains within its stated tolerance throughout the relationship.

Why this answer

Option A (Contract compliance reviews) is correct because an effective vendor risk assessment process must verify that the vendor continuously meets the security, privacy, and service-level obligations defined in the contract, ensuring accountability and detecting drift from agreed controls. Option B (Ongoing monitoring via annual reassessments) is correct because vendor risk is not static; periodic reassessments (at least annually, or upon significant changes) are needed to re-evaluate the vendor's security posture, financial health, and compliance status over the life of the relationship. Option D (Initial onboarding assessment including security questionnaires) is correct because due diligence before engagement is a foundational step—standardized questionnaires (e.g., SIG, CAIQ) help evaluate the vendor's controls, data handling practices, and risk level before any data or access is granted.

Option C is not among the marked correct answers because, while reviewing a vendor's cyber insurance policy can be a useful supplementary check, it is not one of the core components of the risk assessment process itself. Option E is not correct because a vendor self-assessment without independent validation is insufficient—it lacks verification and objectivity, which are essential to a credible risk assessment.

Exam trap

The trap here is that candidates often confuse risk transfer mechanisms (like cyber insurance) with risk assessment activities, leading them to select option C, when in fact insurance does not evaluate the vendor's actual security posture or operational risk.

1052
MCQeasy

When prioritizing risk treatment actions, which factor is most important to consider alongside the risk level?

A.Cost-benefit analysis of controls
B.Number of stakeholders involved
C.Regulatory requirements only
D.Time required to implement controls
AnswerA

Risk level alone cannot justify treatment; the cost of the control must be weighed against the loss it prevents, so cost-benefit analysis determines whether mitigation is worthwhile. This satisfies the stem's requirement for the factor considered alongside risk level when prioritising actions.

Why this answer

Risk treatment prioritization must balance the cost of controls against the expected reduction in risk. A cost-benefit analysis ensures that the selected controls provide a net positive value, preventing over-investment in low-impact risks or under-investment in high-impact ones. This aligns with the ISACA Risk IT Framework, which emphasizes that risk treatment decisions should be economically justified.

Exam trap

The trap here is that candidates often prioritize regulatory compliance or implementation speed over economic justification, but CRISC emphasizes that risk treatment must be cost-effective to ensure sustainable risk management.

How to eliminate wrong answers

Option B is wrong because the number of stakeholders involved does not directly determine the effectiveness or efficiency of risk treatment; while stakeholder input is important, it is secondary to the economic justification of controls. Option C is wrong because regulatory requirements are only one subset of risk treatment drivers; focusing solely on them ignores other critical factors like operational impact and cost, leading to suboptimal risk management. Option D is wrong because time to implement is a scheduling constraint, not a primary decision factor; a quick fix that is not cost-effective may waste resources and fail to address the root risk.

1053
Multi-Selectmedium

An OT environment is being assessed for compliance with IEC 62443. Which TWO of the following are key security requirements of this standard?

Select 2 answers
A.Segmentation of networks into zones and conduits
B.Mandatory cloud-based backup for all control systems
C.Annual penetration testing by an external firm
D.Use of AES-256 encryption for all communications
E.Implementation of security levels (SL) for control systems
AnswersA, E

Defense-in-depth zones and conduits are core concepts.

Why this answer

IEC 62443 requires segmentation of OT networks into zones and conduits to isolate critical control systems from less trusted networks and control communication flows. This is a foundational security requirement because it limits the blast radius of a cyber incident and enforces access controls between different security levels.

Exam trap

A common pitfall is misunderstanding that 'security levels' (SL) in IEC 62443 are indeed a key requirement—they define the target security capability for each zone/conduit (SL 1-4). The trap is that some candidates may view SL as merely a classification rather than an actionable requirement, but the standard mandates implementing appropriate SLs for each zone. Option B (mandatory cloud backup) and D (AES-256 encryption) are not explicit requirements of IEC 62443, while annual external testing (C) may be recommended but is not a key requirement like zones/conduits and SLs.

1054
MCQmedium

A risk practitioner at a regional hospital is building a risk register entry for the loss of availability of the electronic health record (EHR) system. The CIO asks which element of the risk scenario establishes the frequency with which the loss event is expected to occur so that the register can be prioritized against other entries. Which component of the risk scenario should the practitioner document?

A.Secondary risk
B.Threat event frequency
C.Primary loss magnitude
D.Vulnerability
AnswerB

Threat event frequency expresses how often a threat agent is expected to act against the asset and is the component that quantifies the rate at which the loss event is anticipated. For the EHR availability entry, this value drives the annualized loss expectancy calculation and allows consistent comparison with other register entries, which is exactly what the CIO needs for prioritization.

Why this answer

Threat event frequency is the factor-based component that states how often the threat community is expected to act against the asset, so it is the element that establishes occurrence rate for the risk register entry. Loss magnitude components describe impact, while vulnerabilities describe exploitable weaknesses. Only threat event frequency directly supports the annualized loss expectancy comparison the CIO wants for prioritizing the EHR availability risk.

Exam trap

The trap here is confusing a vulnerability, which is a weakness that may be exploited, with threat event frequency, which is the expected rate at which a threat agent actually acts against the asset.

1055
MCQeasy

A retail company is migrating its e-commerce order database to a public cloud provider. The database stores customer names, addresses, and partial payment card numbers. The risk practitioner must determine who is accountable for protecting this data once it resides with the provider. Which of the following principles BEST guides this determination?

A.Accountability is transferred to the provider only when the retailer purchases the highest-tier support plan.
B.The cloud provider assumes full accountability for data protection once the data is stored in its environment.
C.Accountability follows the shared responsibility model, where the retailer remains accountable for its data regardless of where it is hosted.
D.Accountability is jointly held, so the retailer and provider must each protect the data equally and can rely on the other's controls.
AnswerC

Under the shared responsibility model, the provider secures the cloud infrastructure while the customer remains accountable for the security of its data, identities, and configurations. Moving data to a public cloud does not transfer regulatory or contractual accountability. This principle correctly frames how the retailer must govern protection of customer records.

Why this answer

Cloud adoption changes where data resides but not who is answerable for it. In the shared responsibility model the provider secures facilities, hardware, and the hypervisor, while the customer remains accountable for data classification, access management, encryption choices, and regulatory compliance. The retailer therefore keeps accountability for customer records and must design controls and contracts accordingly, regardless of the service tier purchased.

Exam trap

The trap here is believing that outsourcing infrastructure also outsources accountability, when governance responsibility for data remains with the originating organization.

1056
Multi-Selectmedium

Which THREE of the following are key components of an effective risk response plan?

Select 3 answers
A.Documented risk response strategy (e.g., avoid, mitigate, transfer, accept)
B.Detailed implementation timeline
C.Assigned ownership and accountability
D.Regulatory impact analysis
E.Resource allocation and budget
AnswersA, C, E

The chosen strategy is a fundamental part of the plan.

Why this answer

A documented risk response strategy (e.g., avoid, mitigate, transfer, accept) is a key component because it formally defines the chosen approach for addressing each identified risk. This documentation ensures that the response aligns with the organization's risk appetite and provides a clear directive for subsequent actions, such as implementing controls or transferring risk via insurance.

Exam trap

The trap here is that candidates confuse project management components (like timelines and detailed schedules) with the strategic, decision-oriented components of a risk response plan, leading them to select 'Detailed implementation timeline' instead of recognizing that ownership, strategy, and budget are the three pillars CRISC emphasizes.

1057
MCQmedium

A hospital uses a patient portal that allows patients to access their medical records. The portal has experienced multiple brute-force login attempts. The risk manager wants to identify the most critical risk scenario. Which of the following should be prioritized?

A.Denial of service due to excessive login attempts.
B.Unauthorized access to patient medical records.
C.Insufficient encryption of data in transit.
D.Phishing attacks targeting portal users.
AnswerB

Brute-force attempts threaten credential compromise, and success grants access to patient medical records, causing privacy breach, regulatory penalties and clinical harm. This scenario carries the highest impact and likelihood, so it warrants prioritisation over lesser availability or nuisance risks.

Why this answer

The most critical risk scenario from brute-force login attempts is unauthorized access to patient medical records, as this directly compromises patient privacy and violates HIPAA regulations. While denial of service is a concern, the primary impact of successful brute-force attacks is data breach, not service availability. The risk manager must prioritize the confidentiality of protected health information (PHI) over other operational risks.

Exam trap

The trap here is that candidates may focus on the immediate technical symptom (denial of service) rather than the primary business impact (unauthorized data access), which is the core of risk identification in CRISC.

How to eliminate wrong answers

Option A is wrong because denial of service from excessive login attempts is a temporary availability issue, not the most critical risk; brute-force attacks primarily aim to gain access, not to overwhelm the system, and rate limiting or account lockout policies can mitigate DoS. Option C is wrong because insufficient encryption of data in transit is a separate vulnerability related to data exposure during transmission (e.g., missing TLS), not directly caused by brute-force login attempts; the question focuses on the consequence of brute-force attacks, not encryption weaknesses. Option D is wrong because phishing attacks are a different attack vector involving social engineering to steal credentials, not a direct result of brute-force attempts; the scenario explicitly describes brute-force login attempts, not phishing.

1058
MCQhard

A risk assessment identifies that a legacy system has a high risk of failure with no available vendor support. The organization decides to decommission the system and migrate to a modern platform. This is:

A.Risk Avoidance
B.Risk Transfer
C.Risk Mitigation
D.Risk Acceptance
AnswerA

Decommissioning the legacy system eliminates the risk entirely by removing the asset and its exposure, rather than transferring, mitigating or accepting it. Eliminating the activity that generates the risk is the defining characteristic of risk avoidance.

Why this answer

Decommissioning the legacy system and migrating to a modern platform eliminates the risk entirely by removing the vulnerable asset from the environment. This is the definition of risk avoidance, as the organization chooses not to engage with the risk at all rather than reducing or transferring it. The decision directly addresses the high risk of failure and lack of vendor support by removing the system from operation.

Exam trap

The trap here is that candidates often confuse risk avoidance with risk mitigation, mistakenly thinking that any proactive action (like migrating) is a form of mitigation, whereas avoidance specifically means ceasing the activity that generates the risk.

How to eliminate wrong answers

Option B is wrong because risk transfer would involve shifting the financial impact of failure to a third party (e.g., purchasing cyber insurance or outsourcing to a managed service provider), not removing the system. Option C is wrong because risk mitigation would involve implementing controls to reduce the likelihood or impact of failure (e.g., adding monitoring, applying patches, or isolating the system) while keeping it operational. Option D is wrong because risk acceptance means formally acknowledging the risk and its potential consequences without taking action, which contradicts the active decision to decommission and migrate.

1059
MCQeasy

During a control monitoring review, it is discovered that a detective control has a high false positive rate. What is the MOST significant impact of this issue?

A.Loss of confidence in the control by management.
B.Increased risk of missing actual security incidents.
C.Reduced system performance due to alert processing.
D.Increased cost of investigating alerts.
AnswerB

A high false positive rate floods reviewers with benign alerts, causing alert fatigue and desensitisation. Genuine indicators get dismissed or overlooked among the noise, so actual security incidents escape detection, directly undermining the detective control's purpose.

Why this answer

A high false positive rate in a detective control leads to alert fatigue, where security personnel may ignore or dismiss alerts, increasing the risk that actual security incidents are missed. Option A is a consequence but not the most significant. Option C may occur but is secondary.

Option D is an operational impact but does not directly increase risk.

1060
MCQmedium

A control monitoring system generates an alert when transaction volumes exceed 10,000 per hour. Recently, the system has been generating false positives during peak business hours due to legitimate seasonal spikes. Which of the following is the BEST approach to reduce false positives while maintaining effective monitoring?

A.Disable the alerting during peak hours
B.Implement manual review of all alerts during peak hours
C.Apply dynamic thresholding that adjusts based on historical baseline
D.Increase the alert threshold to 15,000 transactions per hour
AnswerC

Dynamic thresholding replaces the fixed 10,000-per-hour limit with a baseline derived from historical transaction patterns, so seasonal peaks no longer breach the threshold. This preserves detection of genuine anomalies while eliminating the legitimate-spike false positives the static rule produces.

Why this answer

Dynamic thresholding uses historical baselines to automatically adjust alerting thresholds in response to predictable patterns, such as seasonal spikes. This approach reduces false positives during peak hours while preserving the system's ability to detect anomalous transaction volumes that deviate from the learned baseline, ensuring effective monitoring without manual intervention.

Exam trap

The trap here is that candidates mistakenly choose a static threshold increase (Option D) thinking it solves false positives, but CRISC expects adaptive controls that align with risk-based monitoring principles, not rigid rule changes.

How to eliminate wrong answers

Option A is wrong because disabling alerting during peak hours creates a blind spot, allowing genuine security or operational incidents to go undetected during the busiest period. Option B is wrong because manual review of all alerts during peak hours is not scalable, introduces human latency, and defeats the purpose of automated monitoring; it also increases operational overhead without addressing the root cause of false positives. Option D is wrong because simply raising the threshold to 15,000 transactions per hour is a static, one-size-fits-all fix that would still generate false positives during higher seasonal spikes and could miss true anomalies that fall below the new fixed threshold.

1061
MCQmedium

A risk manager is using the FAIR model to quantify cyber risk. Which of the following inputs is MOST directly used to calculate probable financial loss?

A.Annualized loss expectancy (ALE)
B.Loss event frequency and loss magnitude
C.Vulnerability severity scores (CVSS)
D.Number of security incidents per year
AnswerB

FAIR decomposes probable loss into two independent factors: loss event frequency (how often a threat event occurs) and loss magnitude (the financial impact per event). Multiplying these produces the probable financial loss figure, so both inputs are required directly.

Why this answer

The FAIR (Factor Analysis of Information Risk) model calculates probable financial loss by combining Loss Event Frequency (LEF)—how often a threat event occurs—with Loss Magnitude (LM)—how much each event costs. These two factors are the core inputs to FAIR's risk quantification, producing a loss distribution rather than a single point estimate. This makes option B the most direct input pair.

Exam trap

CRISC often tests whether candidates confuse FAIR's inputs with traditional ALE formula components—candidates pick ALE thinking it is a foundational input, when FAIR actually generates loss distributions that feed into ALE, not the reverse.

How to eliminate wrong answers

Option A is wrong because ALE is an output of traditional quantitative risk analysis (SLE × ARO), not an input to FAIR—FAIR actually produces loss exceedance curves that can inform ALE but does not use ALE as an input. Option C is wrong because CVSS scores measure technical vulnerability severity, not financial loss; FAIR requires translating vulnerability into frequency and magnitude, so CVSS alone is insufficient. Option D is wrong because the number of security incidents per year is only a partial proxy for Loss Event Frequency and ignores Loss Magnitude entirely, so it cannot by itself calculate probable financial loss.

1062
MCQhard

An organization uses a Key Control Indicator (KCI) to measure control effectiveness. The KCI shows a control deficiency rate of 12% over the past quarter, exceeding the target threshold of 5%. Which action is MOST appropriate as an initial response?

A.Report the deficiency to the board for oversight
B.Increase the frequency of control testing to monthly
C.Immediately replace the control with a more robust one
D.Conduct a root cause analysis of the deficiencies
AnswerD

A 12% deficiency rate against a 5% threshold signals the control is not operating effectively. Root cause analysis is the appropriate initial step, establishing why deficiencies occur before selecting remediation, avoiding premature fixes that address symptoms rather than the underlying failure.

Why this answer

A high deficiency rate indicates the control is not working as intended. The first step is to investigate root causes to determine necessary remediation.

Page 14

Page 15 of 15