Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 76150

983 questions total · 14pages · All types, answers revealed

Page 1

Page 2 of 14

Page 3
76
MCQeasy

A risk assessment that assigns monetary values to assets and calculates expected loss is called:

A.Qualitative
B.Semi-quantitative
C.Comprehensive
D.Quantitative
AnswerD

Quantitative assigns monetary values.

Why this answer

A quantitative risk assessment assigns specific monetary values to assets and calculates expected loss using formulas such as Single Loss Expectancy (SLE) = Asset Value (AV) × Exposure Factor (EF), and Annualized Loss Expectancy (ALE) = SLE × Annualized Rate of Occurrence (ARO). This approach provides objective, numeric risk metrics that support cost-benefit analysis for risk mitigation decisions.

Exam trap

The trap here is that candidates often confuse 'semi-quantitative' with 'quantitative' because both use numbers, but semi-quantitative methods use ordinal scales or weighted scores (e.g., 1-5) rather than actual monetary values and expected loss calculations.

How to eliminate wrong answers

Option A is wrong because qualitative risk assessment uses subjective ratings (e.g., high, medium, low) rather than monetary values and does not calculate expected loss numerically. Option B is wrong because semi-quantitative risk assessment uses ordinal scales or weighted scores to approximate risk levels, but it does not assign precise monetary values or compute expected loss with formulas like SLE and ALE. Option C is wrong because 'comprehensive' is not a recognized category of risk assessment methodology in the CRISC framework; it describes scope, not the quantitative vs. qualitative distinction.

77
MCQmedium

A risk practitioner notices that a key control is tested only once a year, but the associated risk has a high velocity of change. What is the BEST recommendation?

A.Remove the control if it cannot be tested more often
B.Wait for a control failure before increasing frequency
C.Continue annual testing because it meets regulatory requirements
D.Increase testing frequency to quarterly or monthly
AnswerD

Aligns monitoring with risk velocity.

Why this answer

A high velocity of change means the risk profile can shift rapidly between annual tests, leaving the organization exposed for months. Increasing testing frequency to quarterly or monthly ensures that control effectiveness is validated in near real-time, aligning monitoring cadence with risk dynamics. This is a core principle of risk-based monitoring: the testing interval must match the speed at which the risk can materialize.

Exam trap

The trap here is that candidates confuse 'meets regulatory requirements' (Option C) with 'adequate risk management,' failing to recognize that compliance is the floor, not the ceiling, when risk velocity is high.

How to eliminate wrong answers

Option A is wrong because removing a control without a compensating alternative increases residual risk to an unacceptable level; the issue is frequency, not the control's existence. Option B is wrong because waiting for a control failure before increasing frequency is reactive and violates the proactive monitoring mandate of CRISC; a high-velocity risk demands preventive adjustment. Option C is wrong because regulatory compliance is a minimum baseline, not a risk-optimized strategy; annual testing is insufficient when the risk can change in weeks.

78
MCQeasy

An organization uses a third-party SaaS provider for payroll processing. Which of the following is the BEST technique to identify risks associated with this vendor?

A.Request a penetration test report from the vendor
B.Check online user reviews and ratings
C.Read the vendor's marketing materials and case studies
D.Review the vendor's SOC 2 Type II report and conduct an on-site assessment
AnswerD

SOC 2 provides independent assurance; site visit validates controls.

Why this answer

The SOC 2 Type II report provides an independent auditor's assessment of the vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time, which is critical for identifying risks in a payroll SaaS processing sensitive employee data. An on-site assessment allows the organization to verify physical and logical controls, observe operations, and discuss specific risk scenarios directly with vendor personnel, offering a deeper risk identification than any single document or review.

Exam trap

The trap here is that candidates often overvalue a penetration test report (Option A) as the definitive risk identification tool, forgetting that for a SaaS payroll provider, operational and compliance risks (e.g., data privacy, availability, change management) are equally or more critical than pure technical vulnerabilities.

How to eliminate wrong answers

Option A is wrong because a penetration test report, while useful for identifying technical vulnerabilities, is a point-in-time assessment that does not cover the full breadth of operational, privacy, and compliance controls needed for a payroll processor handling sensitive personal data. Option B is wrong because online user reviews and ratings are anecdotal, lack technical depth, and are not a reliable or auditable source for identifying specific control weaknesses or compliance gaps. Option C is wrong because marketing materials and case studies are promotional content designed to highlight successes, not to disclose risks, control failures, or security incidents.

79
MCQeasy

Which of the following is a key component of an IT risk management programme design?

A.Incident response playbooks
B.Risk assessment methodology
C.Vendor security assessment reports
D.Network topology diagrams
AnswerB

The methodology is essential for consistent risk evaluation.

Why this answer

A risk assessment methodology defines the process for identifying, analyzing, and evaluating risks, which is a core component of any risk management programme.

80
MCQmedium

A risk manager is categorizing IT risks. Which risk category would a potential fine for violating GDPR be assigned to?

A.Operational
B.Financial
C.Strategic
D.Compliance
AnswerD

GDPR fines are a compliance risk.

Why this answer

Compliance risk involves violations of laws, regulations, or contractual obligations.

81
MCQmedium

Based on the exhibit, which aspect of risk monitoring is MOST concerning?

A.The vulnerability has been open for three months with no evidence of monitoring or remediation despite a patch being available.
B.The vulnerability severity is critical.
C.The last scan was three months after the initial detection.
D.The risk was accepted by the system owner.
AnswerA

Indicates lack of ongoing monitoring of accepted risks.

Why this answer

The vulnerability has been open for three months with a patch available, yet there is no evidence of monitoring or remediation. This indicates a complete breakdown of the risk monitoring process, as the organization failed to track, escalate, or patch a known critical vulnerability, leaving the system exposed to exploitation. In risk monitoring, the absence of any monitoring activity or remediation action over such a long period is far more concerning than the severity alone, as it reflects a systemic failure in the control environment.

Exam trap

The trap here is that candidates often focus on the technical severity (critical) or the scan frequency, but CRISC emphasizes that the most concerning aspect of risk monitoring is the failure to act on known risks, not the initial risk level or the timing of scans.

How to eliminate wrong answers

Option B is wrong because while a critical severity vulnerability is serious, the severity itself is not the most concerning aspect of risk monitoring; the lack of monitoring and remediation over three months is a greater indicator of process failure. Option C is wrong because the three-month gap between scans, though suboptimal, is not as alarming as the complete absence of monitoring or remediation activity after detection; scanning frequency is a secondary concern when no action is taken on findings. Option D is wrong because risk acceptance by the system owner is a legitimate risk response option when properly documented and approved; the exhibit does not indicate that the acceptance was invalid or that compensating controls were absent, so it is not inherently the most concerning monitoring issue.

82
MCQhard

A company uses a risk control self-assessment (RCSA) process that is conducted annually. During a quarterly review, management discovers that several high-risk controls are no longer effective due to changes in the business environment. Which of the following is the BEST way to enhance the monitoring of these controls?

A.Increase the frequency of the RCSA to quarterly.
B.Assign a risk owner to perform manual checks monthly.
C.Implement compensating controls to reduce the risk.
D.Deploy automated control monitoring tools for continuous assessment.
AnswerD

Continuous monitoring provides timely and objective evidence of control effectiveness.

Why this answer

Automated control monitoring tools provide continuous, real-time assessment of control effectiveness, which is essential when high-risk controls are failing due to dynamic business changes. Unlike periodic manual reviews, automation reduces latency in detecting control degradation and enables immediate remediation, aligning with the CRISC principle of proactive risk monitoring.

Exam trap

The trap here is that candidates confuse 'monitoring enhancement' with 'risk treatment' (Option C) or 'increased frequency of assessment' (Option A), failing to recognize that continuous automated monitoring is the only option that directly addresses the need for real-time detection of control degradation in a dynamic environment.

How to eliminate wrong answers

Option A is wrong because increasing RCSA frequency to quarterly still relies on periodic, point-in-time assessments, which cannot capture real-time control failures between reviews. Option B is wrong because manual monthly checks introduce human error, inconsistency, and delay, and are insufficient for high-risk controls that require near-instantaneous detection of ineffectiveness. Option C is wrong because implementing compensating controls reduces residual risk but does not enhance monitoring of the original controls; it is a risk treatment action, not a monitoring enhancement.

83
MCQeasy

Refer to the exhibit. During a risk identification review, the risk manager sees this IDS alert. What risk does this alert MOST directly indicate?

A.Sensitive data is being exfiltrated from the SQL server.
B.A malware infection is spreading across the network.
C.The organization is under a distributed denial-of-service (DDoS) attack.
D.An internal SQL server is exposed to the internet and may be probed for vulnerabilities.
AnswerD

Alert shows external IP probing internal MSSQL server, indicating internet exposure.

Why this answer

The IDS alert indicates an inbound connection attempt to TCP port 1433 (Microsoft SQL Server) from an external IP address. This directly suggests that an internal SQL server is exposed to the internet, which is a security misconfiguration that allows external entities to probe for vulnerabilities, such as weak credentials or unpatched flaws. While data exfiltration or malware could be subsequent outcomes, the alert itself most immediately signals the exposure and probing risk.

Exam trap

The trap here is that candidates may conflate a single IDS alert indicating exposure with a full-blown attack outcome (exfiltration, malware, DDoS), rather than recognizing that the alert most directly signals the underlying misconfiguration risk of internet-facing internal services.

How to eliminate wrong answers

Option A is wrong because the alert only shows a connection attempt to port 1433, not any evidence of data transfer or exfiltration; exfiltration would require additional indicators like large outbound data flows or SQL query patterns. Option B is wrong because the alert does not show lateral movement, propagation behavior, or malware signatures; a single inbound connection to a database port is not indicative of a spreading infection. Option C is wrong because a DDoS attack would involve a high volume of traffic from multiple sources overwhelming bandwidth or services, not a single SYN packet to a specific database port.

84
Multi-Selectmedium

Which THREE of the following are common elements of a periodic control effectiveness testing program? (Select THREE)

Select 3 answers
A.User training on new controls
B.Quarterly control testing by the risk function
C.Continuous monitoring via SIEM
D.Internal audit review of controls
E.Annual penetration testing
AnswersB, D, E

Quarterly testing is a common periodic activity.

Why this answer

Periodic testing includes internal audit reviews, quarterly testing by the risk function, and annual penetration tests. Continuous monitoring is not periodic, and user training is not a testing activity.

85
MCQhard

During a quarterly control effectiveness test, internal audit discovers that a key automated control failed 15% of the time due to a software bug. The risk owner decides to accept the risk because the cost to fix the bug is high. What should the risk manager do next?

A.Document the risk acceptance and rationale in the risk register
B.Implement a compensating control
C.Override the risk owner's decision
D.Report the issue to the board immediately
AnswerA

Proper documentation ensures accountability and auditability.

Why this answer

The risk manager's primary responsibility is to formally document the risk acceptance decision, including the rationale provided by the risk owner, in the risk register. This ensures audit trail, transparency, and compliance with governance frameworks such as COBIT or ISO 31000. Since the risk owner has the authority to accept the risk, the risk manager must record it rather than challenge or escalate it without justification.

Exam trap

The trap here is that candidates confuse the risk manager's advisory role with an enforcement role, leading them to choose 'override the risk owner' or 'implement a compensating control' instead of recognizing that documentation is the correct procedural step after a risk acceptance decision.

How to eliminate wrong answers

Option B is wrong because implementing a compensating control would be a risk mitigation action, not a response to a risk acceptance decision; the risk owner has already chosen to accept the risk, so adding controls contradicts that decision unless the risk manager renegotiates. Option C is wrong because the risk manager does not have the authority to override the risk owner's decision; the risk owner is accountable for the risk, and the risk manager's role is advisory and documentation-focused. Option D is wrong because immediate board reporting is not required for a single accepted risk with a documented rationale; escalation to the board is reserved for risks exceeding the organization's risk appetite or for material changes in risk profile, not routine acceptance decisions.

86
MCQmedium

A medium-sized e-commerce company has a risk monitoring program that tracks key risk indicators (KRIs) monthly. One KRI is the percentage of orders with failed payment transactions. The threshold is 2%, but for the past three months, the KRI has been 2.5%, 3.1%, and 2.8%. The risk owner says this is due to a seasonal increase in fraudulent transactions and expects it to return to normal next month. The company has a compensating control that manually reviews flagged transactions. The internal audit team recently tested the compensating control and found it to be 100% effective. The risk committee wants to know if the KRI breach requires action. What should the risk practitioner recommend?

A.Immediately implement additional automated controls to reduce the KRI.
B.Escalate the issue to the board and recommend a risk acceptance.
C.Acknowledge the breach but note that the compensating control is effective, so no immediate action is required; continue to monitor.
D.Lower the KRI threshold to 3% to accommodate seasonal variations.
AnswerC

Appropriate response given the circumstances.

Why this answer

The compensating control (manual review of flagged transactions) has been tested as 100% effective, meaning the residual risk is within acceptable tolerance despite the KRI breach. The risk owner attributes the breach to a seasonal spike, and the risk monitoring program should continue to track the KRI monthly to confirm a return to normal. Immediate action is not warranted when the compensating control fully mitigates the risk, and the risk committee should be informed that the control is effective.

Exam trap

The trap here is that candidates assume any KRI breach automatically requires immediate remediation or escalation, ignoring the critical role of compensating controls in reducing residual risk to an acceptable level.

How to eliminate wrong answers

Option A is wrong because implementing additional automated controls without evidence of control failure is an overreaction that wastes resources; the existing compensating control is 100% effective, so the residual risk is already managed. Option B is wrong because escalation to the board and risk acceptance are premature—the breach is temporary and the compensating control mitigates the risk, so the issue does not meet the threshold for board-level acceptance. Option D is wrong because lowering the KRI threshold to 3% would mask the underlying risk trend and violate the principle of maintaining consistent, objective risk indicators; thresholds should be adjusted only after a formal risk assessment, not to accommodate seasonal variations without analysis.

87
Multi-Selecthard

A risk manager is developing a risk scenario for a potential data breach involving a third-party cloud provider. According to the ISACA risk scenario template, which THREE elements must be included? (Select three.)

Select 3 answers
A.Asset/resource
B.Consequence
C.Control effectiveness
D.Risk owner
E.Threat actor
AnswersA, B, E

The asset affected (e.g., customer data) is a key element.

Why this answer

The ISACA risk scenario template mandates the inclusion of threat actor, asset/resource, and consequence as core elements. These three components define who/what causes the risk, what is affected, and the impact.

88
MCQmedium

An organization has a risk register that includes risks related to regulatory compliance, such as GDPR and SOX. The risk practitioner is now categorizing these risks. Which risk category would BEST fit these compliance-related risks?

A.Financial risk
B.Operational risk
C.Compliance risk
D.Strategic risk
AnswerC

Why this answer

Compliance risks refer to risks associated with violations of laws, regulations, or contractual obligations. GDPR and SOX are regulatory requirements, so they fall under compliance risk.

89
MCQmedium

In IT risk reporting, which level of management typically receives operational risk reporting on a weekly or monthly basis?

A.External auditors
B.Board of directors
C.IT management
D.CISO/CIO
AnswerC

Operational reports are designed for IT managers.

Why this answer

Operational risk reporting is detailed and frequent, intended for IT management who oversee day-to-day operations.

90
Multi-Selecthard

An organization is assessing control effectiveness for a firewall. Which THREE factors should be evaluated to determine control effectiveness? (Select THREE)

Select 3 answers
A.Design adequacy of the firewall rules
B.Operating effectiveness of the firewall
C.Cost of the firewall
D.Relevance to the specific risk scenario
E.Frequency of rule updates
AnswersA, B, D

Design adequacy is a key component.

Why this answer

Control effectiveness is a combination of design adequacy and operating effectiveness. Additionally, the control's ability to address the specific risk (relevance) is important. Frequency alone does not determine effectiveness.

91
MCQeasy

An organization uses threat intelligence feeds from an Information Sharing and Analysis Center (ISAC). What is the PRIMARY benefit of using ISACs?

A.They facilitate sharing of sector-specific threat intelligence
B.They provide free antivirus software to members
C.They offer legally binding threat response protocols
D.They replace the need for internal threat hunting
AnswerA

Correct. ISACs are community-driven organizations that share relevant threat data.

Why this answer

ISACs provide sector-specific threat intelligence and enable trusted information sharing among members, often with real-time alerts on relevant threats.

92
MCQhard

A multinational financial services company has implemented a continuous monitoring program for its trading systems. The program uses automated scripts to check system configurations against a baseline every hour. Recently, the company experienced a significant security incident where a malicious actor exploited a misconfigured firewall rule to exfiltrate sensitive customer data. Post-incident analysis revealed that the misconfiguration had been present for 72 hours before detection. The monitoring scripts did not detect the change because the baseline had been updated two weeks prior to include the misconfiguration as part of a planned change that was later reversed without updating the baseline. The company's change management process requires that all configuration changes be approved and documented, but the reversal of the change was not documented. The incident response team was only alerted when a customer reported suspicious activity. The risk practitioner is tasked with recommending improvements to prevent recurrence. Which of the following is the BEST course of action?

A.Enhance incident response procedures to include notification of customers within 24 hours.
B.Implement a change detection system that compares current configurations to an approved, immutable baseline and alerts on any deviation, with strict change control for baseline updates.
C.Increase the frequency of monitoring scripts to every 30 minutes.
D.Require manual review of all configuration changes by a second analyst.
AnswerB

Addresses root cause of baseline manipulation.

Why this answer

The root cause is that the baseline was updated to include the misconfiguration, and the subsequent reversal was not documented or reflected in the baseline. A change detection system that compares current configurations to an approved, immutable baseline and alerts on any deviation, with strict change control for baseline updates, directly addresses this by ensuring that only approved changes are in the baseline and any unapproved deviation (including reversals) triggers an alert. This prevents the monitoring system from accepting unauthorized changes as normal.

Exam trap

The trap here is that candidates focus on the monitoring frequency or manual review, but the real failure is the baseline integrity—the monitoring system was working correctly but against a corrupted baseline, so the solution must enforce that the baseline itself is immutable and only updated through strict change control.

How to eliminate wrong answers

Option A is wrong because enhancing incident response procedures to notify customers within 24 hours addresses notification timing after detection, not the root cause of the detection failure—the baseline was corrupted and the monitoring scripts did not detect the misconfiguration. Option C is wrong because increasing the frequency of monitoring scripts to every 30 minutes does not solve the problem; the scripts were already running hourly but failed to detect the change because the baseline had been incorrectly updated, so more frequent checks against a corrupted baseline would still miss the misconfiguration. Option D is wrong because requiring manual review of all configuration changes by a second analyst adds a human check but does not address the automated baseline update process that allowed the misconfiguration to be included without detection; the reversal was not documented, so manual review would not catch the baseline corruption unless the reviewer specifically compares against an immutable approved state.

93
MCQeasy

When assessing IT risks, which of the following is the PRIMARY purpose of developing risk scenarios?

A.To calculate the exact financial loss
B.To identify specific threats and vulnerabilities that could impact objectives
C.To satisfy regulatory compliance
D.To create a business continuity plan
AnswerB

Core purpose of scenario development.

Why this answer

The primary purpose of developing risk scenarios in IT risk assessment is to identify specific threats and vulnerabilities that could impact business objectives. Risk scenarios provide a structured narrative that links threat sources, vulnerabilities, and potential impacts, enabling a focused analysis of how adverse events might occur. This is foundational for prioritizing risks and determining appropriate controls, rather than for calculating exact losses, compliance, or continuity planning.

Exam trap

The trap here is that candidates often confuse the purpose of risk scenarios with downstream activities like financial quantification or compliance, when the core goal is to systematically identify and articulate how threats and vulnerabilities can materialize into risk events.

How to eliminate wrong answers

Option A is wrong because risk scenarios are not designed to calculate exact financial loss; they are qualitative or semi-quantitative constructs that estimate potential impact ranges, not precise monetary values. Option C is wrong because while risk scenarios may support compliance efforts, satisfying regulatory requirements is a secondary benefit, not the primary purpose of scenario development. Option D is wrong because creating a business continuity plan is a separate process that may use risk scenarios as input, but the primary purpose of scenarios is to identify and analyze risks, not to produce continuity plans.

94
MCQeasy

Which of the following is a primary goal of the 'Protect' function in the NIST Cybersecurity Framework?

A.Develop and implement appropriate activities to identify the occurrence of a cybersecurity event
B.Develop and implement appropriate safeguards to ensure delivery of critical services
C.Develop and implement appropriate activities to take action regarding a detected cybersecurity event
D.Develop and implement appropriate activities to maintain plans for resilience
AnswerB

Protect includes access control, awareness training, data security, etc.

Why this answer

The Protect function focuses on implementing safeguards to limit or contain the impact of a potential cybersecurity event.

95
MCQeasy

Which component of the NIST Cybersecurity Framework is primarily concerned with developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Detect
B.Identify
C.Recover
D.Protect
AnswerD

Correct. Protect develops and implements safeguards.

Why this answer

The Protect function in NIST CSF outlines safeguards to manage cybersecurity risk and ensure service delivery.

96
MCQmedium

In assessing control effectiveness, an IS auditor evaluates both design adequacy and operating effectiveness. Which of the following indicates that a control is operating effectively?

A.The control is approved by management
B.The control has been tested and works as designed
C.The control is inexpensive to implement
D.The control is documented in policy
AnswerB

Testing confirms operating effectiveness.

Why this answer

Operating effectiveness means the control has been tested and consistently produces the intended result in practice. Even if a control is well-designed, it may fail during actual operation due to misconfiguration, human error, or environmental changes. Testing confirms that the control functions as designed under real conditions, which is the definitive indicator of operating effectiveness.

Exam trap

The trap here is confusing control design (what is planned or documented) with control operation (what actually happens in practice), leading candidates to select policy or approval as evidence of effectiveness.

How to eliminate wrong answers

Option A is wrong because management approval only indicates that the control design is authorized, not that it is actually working in production. Option C is wrong because cost is a factor in control selection and efficiency, not a measure of whether the control operates effectively. Option D is wrong because documentation in policy only proves the control exists on paper, not that it is executed correctly or consistently.

97
MCQeasy

A risk manager is using a 5×5 likelihood-impact matrix to assess a set of identified risks. What is the PRIMARY advantage of using this qualitative method?

A.It provides objective and comparable risk scores across organizations.
B.It is quick and easy to communicate to stakeholders.
C.It produces financially meaningful results for cost-benefit analysis.
D.It requires less data but is time-consuming to complete.
AnswerB

Qualitative heat maps are simple to understand and communicate.

Why this answer

Qualitative risk analysis using heat maps is quick and easy to communicate to stakeholders, making it a common initial assessment tool.

98
MCQmedium

A company is migrating its legacy on-premises applications to a public cloud environment. Which risk identification technique is most appropriate for this scenario?

A.Control self-assessment
B.Threat modeling
C.SWOT analysis
D.Business impact analysis (BIA)
AnswerB

Threat modeling systematically identifies threats and vulnerabilities in system architecture, making it ideal for migration projects.

Why this answer

Threat modeling is the most appropriate risk identification technique for migrating legacy on-premises applications to a public cloud environment because it systematically identifies potential security threats, vulnerabilities, and attack vectors specific to the new cloud architecture. This technique evaluates how the application's design, data flows, and trust boundaries change when moved to a cloud provider like AWS, Azure, or GCP, enabling proactive mitigation of risks such as misconfigured storage, insecure APIs, or compromised identity management.

Exam trap

The trap here is that candidates often confuse SWOT analysis (a business strategy tool) with a technical risk identification technique, or mistakenly think control self-assessment is sufficient for identifying new risks in a fundamentally different architecture like cloud.

How to eliminate wrong answers

Option A is wrong because control self-assessment is a subjective evaluation of existing controls by internal staff, which is not designed to identify new risks arising from a technology migration like cloud adoption. Option C is wrong because SWOT analysis is a high-level strategic planning tool that assesses strengths, weaknesses, opportunities, and threats at an organizational level, not a technical risk identification method for specific application migration scenarios. Option D is wrong because business impact analysis (BIA) focuses on quantifying the impact of disruptions to critical business functions, not on identifying technical threats or vulnerabilities in a new cloud environment.

99
MCQhard

A financial institution is migrating its core banking system from an on-premises data center to a public cloud infrastructure. The migration is planned in phases over 18 months. The IT risk manager is tasked with identifying risks during the transition. During the first phase, the team moves non-critical applications to the cloud. A vulnerability assessment of the cloud environment reveals that several virtual machines have default administrative credentials enabled. Additionally, the cloud security group configuration for the application tier allows inbound SSH from the entire internet (0.0.0.0/0). The risk manager also learns that the cloud provider's shared responsibility model is not fully understood by the operations team, who believe the provider is responsible for all security controls. The institution's risk appetite statement allows for moderate risk tolerance but prohibits any exposure that could lead to unauthorized access to customer financial data. Which of the following risk scenarios should the risk manager identify as the MOST critical to address immediately?

A.The operations team's misunderstanding of the shared responsibility model
B.The cloud provider may not have adequate security controls for the institution's data
C.The phased migration introduces complexity that may cause configuration drift
D.Default credentials on virtual machines combined with unrestricted inbound SSH from the internet
AnswerD

Direct and immediate risk of unauthorized access to systems handling sensitive data.

Why this answer

The combination of default credentials on VMs and unrestricted inbound SSH from the internet (0.0.0.0/0) creates an immediate, exploitable vulnerability that could allow attackers to gain unauthorized access to the application tier. This directly violates the institution's risk appetite, which prohibits any exposure that could lead to unauthorized access to customer financial data. Option A, while a concern, is a management issue that does not present an immediate technical exploit.

Option B is incorrect because the cloud provider's security controls are part of the shared responsibility model, but the provider is not responsible for the customer's misconfigurations. Option C is a longer-term risk that may arise during migration but is not as urgent as the active vulnerability in D.

100
MCQeasy

An IT manager is identifying risks for a new cloud application. Which of the following is the BEST source for identifying specific threats relevant to cloud services?

A.Employee suggestions
B.Internal audit findings
C.Vendor marketing materials
D.Industry threat reports
AnswerD

Industry reports provide relevant and current threat data.

Why this answer

Industry threat reports (Option D) are the BEST source because they aggregate real-world threat intelligence specific to cloud environments, such as data from the Cloud Security Alliance (CSA) or Verizon DBIR, detailing attack vectors like misconfigured APIs, insecure interfaces, and shared technology vulnerabilities. Unlike internal or vendor sources, these reports provide empirical, up-to-date data on threats actively targeting cloud services, enabling a risk assessment grounded in actual incident patterns rather than assumptions or marketing claims.

Exam trap

The trap here is that candidates may choose internal audit findings (Option B) thinking they are authoritative, but they fail to recognize that internal audits are retrospective and limited to existing controls, whereas industry threat reports provide forward-looking, external threat intelligence essential for identifying emerging cloud-specific risks.

How to eliminate wrong answers

Option A is wrong because employee suggestions are subjective, anecdotal, and lack the systematic, evidence-based threat data needed for a formal risk assessment; they may reflect personal biases or limited visibility into cloud-specific attack patterns. Option B is wrong because internal audit findings focus on compliance gaps and control deficiencies within the organization's existing environment, not on emerging or external threats specific to cloud service models (IaaS, PaaS, SaaS) like side-channel attacks or provider-side vulnerabilities. Option C is wrong because vendor marketing materials are promotional and designed to highlight product strengths, not to disclose realistic threat scenarios; they often downplay risks such as multi-tenancy isolation failures or shared responsibility model ambiguities.

101
MCQeasy

A financial institution monitors the number of unauthorized access attempts to its core banking system. The risk owner recommends increasing the monitoring frequency from daily to hourly because a recent attack exploited a delayed detection. Which of the following is the PRIMARY benefit of this change?

A.Faster detection of anomalies
B.Lower cost of monitoring
C.Increased system performance
D.Reduced false positive rate
AnswerA

Hourly monitoring detects anomalies sooner than daily, reducing the attack window.

Why this answer

Increasing monitoring frequency from daily to hourly reduces the time between an unauthorized access attempt and its detection. This faster detection enables the security team to respond more quickly to anomalies, minimizing the potential impact of an attack that exploits delayed detection, such as a brute-force or credential-stuffing campaign.

Exam trap

The trap here is that candidates may confuse 'increased monitoring frequency' with 'improved system performance' or 'reduced false positives,' when in reality the primary benefit is always faster detection of anomalies, not cost savings or performance gains.

How to eliminate wrong answers

Option B is wrong because increasing monitoring frequency typically increases operational costs (e.g., more log storage, processing, and analysis), not lowers them. Option C is wrong because more frequent monitoring adds overhead to the system (e.g., additional log writes and queries), which can degrade performance rather than increase it. Option D is wrong because increasing monitoring frequency does not inherently reduce false positives; in fact, it may increase them due to more data points and potential noise, unless additional tuning is applied.

102
MCQmedium

A security analyst notices that the number of failed login attempts has significantly increased over the past week. The SIEM alerts are not being triggered because the threshold was set too high. What is the MOST effective immediate action to improve monitoring?

A.Implement a new authentication system with biometrics.
B.Lower the threshold for failed login alerts in the SIEM.
C.Enable all SIEM rules to capture every event.
D.Review logs manually each day to identify anomalies.
AnswerB

Directly fixes the issue of missed alerts.

Why this answer

B is correct because the immediate issue is that the SIEM alert threshold is set too high, causing failed login attempts to go undetected. Lowering the threshold directly addresses the monitoring gap by ensuring that the SIEM generates alerts for anomalous failed login activity, enabling timely incident response without requiring a system overhaul.

Exam trap

The trap here is that candidates may choose a more 'secure' but non-immediate option like biometrics (A) or a broad-brush approach like enabling all rules (C), failing to recognize that the question specifically asks for the 'most effective immediate action' to fix the monitoring gap caused by a misconfigured threshold.

How to eliminate wrong answers

Option A is wrong because implementing a new authentication system with biometrics is a long-term control improvement that does not address the immediate monitoring failure; it also introduces new costs and complexity without fixing the SIEM threshold issue. Option C is wrong because enabling all SIEM rules to capture every event would generate excessive noise, overwhelming analysts with false positives and potentially causing alert fatigue, which degrades monitoring effectiveness. Option D is wrong because reviewing logs manually each day is reactive, inefficient, and does not scale; it fails to provide real-time alerting and relies on human attention, which is error-prone and unsustainable for detecting a surge in failed logins.

103
MCQeasy

A multinational corporation is assessing the risk of a new cloud-based customer relationship management (CRM) system. The risk manager conducts a qualitative risk assessment using a risk matrix that plots likelihood vs. impact. Which of the following is the PRIMARY benefit of using a qualitative approach over a quantitative approach in this context?

A.It provides precise monetary values for risk exposure.
B.It reduces the time required for data collection and analysis.
C.It allows for easy comparison of risks across different business units.
D.It eliminates the need for expert judgment.
AnswerB

Qualitative assessment is faster due to less data requirement.

Why this answer

In a qualitative risk assessment, the risk manager uses subjective ratings (e.g., high, medium, low) for likelihood and impact rather than gathering hard financial data. This approach significantly reduces the time and effort needed for data collection and analysis because it avoids the complex calculations, historical loss data gathering, and monetary valuation required by quantitative methods. For a new cloud-based CRM system, where historical incident data may be scarce, qualitative assessment enables a faster initial risk evaluation.

Exam trap

The trap here is that candidates often confuse 'qualitative' with 'easier to compare' (Option C) or think it provides monetary precision (Option A), when in reality the primary benefit is speed and reduced data collection effort, especially for new or cloud-based systems where quantitative data is scarce.

How to eliminate wrong answers

Option A is wrong because qualitative assessments do not provide precise monetary values; they use ordinal scales (e.g., high/medium/low) rather than dollar amounts, which is the defining characteristic of quantitative analysis. Option C is wrong because while qualitative matrices can facilitate comparison, the primary benefit over quantitative is not ease of comparison—quantitative methods actually allow more objective cross-unit comparisons via normalized financial metrics. Option D is wrong because qualitative approaches still heavily rely on expert judgment; they do not eliminate it, and in fact, they depend on subjective input from stakeholders and SMEs.

104
MCQeasy

A risk owner wants to implement continuous monitoring for a set of critical controls. Which of the following is the PRIMARY benefit of continuous monitoring over periodic testing?

A.Timely detection of control failures.
B.Elimination of manual testing.
C.Compliance with regulatory requirements.
D.Reduced cost of control testing.
AnswerA

Continuous monitoring enables immediate awareness of failures.

Why this answer

Continuous monitoring provides timely detection of control failures, which is its primary benefit over periodic testing. This enables faster response to issues, reducing the window of exposure. Option B (Elimination of manual testing) is incorrect because continuous monitoring may reduce but not eliminate manual testing.

Option C (Compliance with regulatory requirements) is a benefit but not the primary one. Option D (Reduced cost) is not necessarily true; continuous monitoring can be more expensive to implement initially.

105
Matchingmedium

Match each key risk indicator (KRI) to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Measures availability risk

Measures access control risk

Measures vulnerability management risk

Measures security awareness risk

Why these pairings

In CRISC, KRIs like MTTD, MTTR, vulnerability percentage, and incident count provide early warning. Common mistakes include confusing MTTD and MTTR, or mixing incident count with vulnerability metrics.

106
MCQhard

A bank's risk committee reviews a monthly risk report that includes KRIs. One KRI shows that the number of failed transactions due to system errors is trending upward. The control owner states that the trend is within the risk appetite. However, the report also shows that the number of customer complaints is stable. What should the risk manager do FIRST?

A.Escalate to the board of directors.
B.Accept the control owner's assessment and continue monitoring.
C.Investigate the root cause of the increasing failed transactions.
D.Recommend increasing the monitoring frequency.
AnswerC

Understanding the cause is essential before any decision.

Why this answer

The upward trend in failed transactions due to system errors, even if within risk appetite, indicates a potential control degradation or emerging risk that requires root cause analysis. The risk manager must first investigate the underlying cause (e.g., software bugs, database contention, or network latency) to determine if the trend signals a systemic issue that could breach risk appetite thresholds or impact customer experience, despite stable complaints. This aligns with the CRISC principle of proactive risk monitoring, where unexplained KRI deviations trigger investigation before escalation or acceptance.

Exam trap

The trap here is that candidates assume a stable customer complaint count validates the control owner's risk appetite assertion, but CRISC emphasizes that KRIs must be investigated for root cause even when within thresholds, as leading indicators (failed transactions) may precede lagging indicators (complaints).

How to eliminate wrong answers

Option A is wrong because escalating to the board is premature without first understanding the root cause; the board should only be informed of material risks after analysis confirms a significant threat. Option B is wrong because accepting the control owner's assessment without investigation ignores the principle that a KRI trend, even within appetite, may indicate a control weakness or emerging risk that requires validation. Option D is wrong because increasing monitoring frequency addresses symptom detection but does not resolve the underlying cause of the upward trend; root cause analysis must precede any change in monitoring cadence.

107
MCQeasy

During a control monitoring review, a risk analyst discovers that the control owner has not been performing the required monthly reconciliations. What should the analyst do FIRST?

A.Contact the control owner to understand the reason for non-performance.
B.Escalate to the risk committee for immediate action.
C.Update the risk register to reflect control deficiency.
D.Recommend removal of the control as it is not being followed.
AnswerA

Understanding the cause helps determine the appropriate response.

Why this answer

The first step in any control monitoring review is to investigate the root cause of a control failure before taking further action. Contacting the control owner allows the risk analyst to determine whether the non-performance was due to a process issue, resource constraint, or a deliberate decision, which informs the appropriate remediation. Jumping to escalation or documentation without understanding the context could lead to incorrect risk treatment or unnecessary disruption.

Exam trap

The trap here is that candidates often confuse 'first step' with 'most impactful action' and choose to escalate or update the register immediately, failing to recognize that understanding the reason for non-performance is a prerequisite for any subsequent action.

How to eliminate wrong answers

Option B is wrong because escalating to the risk committee for immediate action bypasses the initial investigation step; the committee should only be involved after the analyst understands the cause and determines that the risk is significant enough to warrant escalation. Option C is wrong because updating the risk register to reflect a control deficiency should occur only after confirming the deficiency is valid and understanding its root cause; premature updates may introduce inaccuracies. Option D is wrong because recommending removal of a control based solely on non-performance ignores the possibility that the control is still necessary and that the issue is with execution, not the control design.

108
MCQeasy

A security team identifies a critical vulnerability in a web application that cannot be patched immediately. They deploy a web application firewall (WAF) to block exploitation attempts. This is an example of:

A.Risk Transfer
B.Risk Mitigation
C.Risk Avoidance
D.Risk Acceptance
AnswerB

Deploying a WAF reduces risk, so it is mitigation.

Why this answer

Deploying a WAF to block exploitation attempts directly reduces the likelihood and/or impact of the vulnerability being exploited, which is the definition of risk mitigation. The WAF acts as a compensating control, filtering malicious traffic (e.g., SQL injection, XSS payloads) at the application layer (HTTP/HTTPS) without patching the underlying code. This aligns with the CRISC domain of Risk Response and Mitigation, where controls are implemented to bring residual risk within acceptable tolerance.

Exam trap

The CRISC exam often tests the distinction between risk mitigation (implementing a control to reduce risk) and risk avoidance (eliminating the activity entirely), so candidates mistakenly choose avoidance when they see a vulnerability that cannot be patched, but the key is that the application remains in use with a compensating control.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial impact of a risk to a third party (e.g., purchasing cyber insurance or outsourcing to a managed security provider), not deploying a technical control like a WAF. Option C is wrong because risk avoidance would require ceasing the activity that introduces the risk (e.g., taking the web application offline or removing the vulnerable feature entirely), not implementing a control to allow continued operation. Option D is wrong because risk acceptance means formally acknowledging the risk and taking no action to reduce it, whereas deploying a WAF is an active countermeasure that reduces the risk level.

109
Multi-Selectmedium

A risk assessment of a critical financial application identifies a high inherent risk due to outdated software. The risk manager is considering mitigation options. Which TWO of the following would be considered preventive controls?

Select 2 answers
A.Configuring access controls
B.Deploying an intrusion detection system
C.Implementing a patch management process
D.Establishing a backup and recovery plan
E.Conducting regular security audits
AnswersA, C

Access controls prevent unauthorized access.

Why this answer

Configuring access controls is a preventive control because it proactively restricts unauthorized users from accessing the financial application, reducing the likelihood of a security incident. By enforcing least privilege and authentication mechanisms, it directly mitigates the risk of exploitation of the outdated software by limiting who can interact with it.

Exam trap

The trap here is confusing detective controls (like IDS or audits) or recovery controls (like backups) with preventive controls, especially when the question emphasizes 'mitigation options' for outdated software—candidates often overlook that patching is a direct preventive measure against known vulnerabilities.

110
MCQmedium

A risk practitioner is designing a risk dashboard for the executive team. The organization has a high risk appetite for revenue-generating activities but a low risk appetite for regulatory compliance. Which combination of metrics should be prominently displayed?

A.Key risk indicators (KRIs) for revenue-related risks and regulatory compliance status.
B.Percentage of controls tested and employee training completion rates.
C.Vendor risk ratings and number of security incidents.
D.Number of open remediation items and budget variance for risk projects.
AnswerA

Directly aligns to the stated risk appetites.

Why this answer

The executive team needs visibility into metrics that directly align with the organization's stated risk appetite: high appetite for revenue-generating activities (monitored via KRIs for revenue-related risks) and low appetite for regulatory compliance (monitored via compliance status). This ensures the dashboard provides actionable, risk-informed insights rather than operational or administrative data.

Exam trap

The trap here is that candidates often confuse operational metrics (like control testing percentages or training completion) with risk indicators, failing to recognize that the dashboard must directly reflect the organization's stated risk appetite for revenue and compliance, not just general security hygiene.

How to eliminate wrong answers

Option B is wrong because percentage of controls tested and employee training completion rates are operational or compliance process metrics, not risk indicators that reflect the organization's specific risk appetite for revenue and regulatory compliance. Option C is wrong because vendor risk ratings and number of security incidents are tactical, third-party and security event metrics that do not directly map to the dual risk appetite focus on revenue generation and regulatory compliance. Option D is wrong because number of open remediation items and budget variance for risk projects are project management and remediation tracking metrics, not strategic risk indicators that inform the executive team about alignment with risk appetite.

111
MCQmedium

A university is implementing a new online learning management system (LMS) that will store student records, grades, and personal information. During the risk assessment, the IT team identifies that the LMS vendor's default configuration allows students to see each other's email addresses in the class roster. This could lead to privacy violations under FERPA regulations. The vendor states that this feature can be disabled in the settings but doing so will require manual configuration for each course. The university has a moderate risk appetite and wants to launch the system within two weeks. Which of the following is the MOST appropriate risk response?

A.Transfer the risk by requiring students to sign a consent form allowing email disclosure.
B.Avoid the risk by selecting a different LMS vendor that does not have this issue.
C.Reduce the risk by disabling the feature globally through a script or administrative override before launch.
D.Accept the risk because the exposure is limited to email addresses and not grades.
AnswerC

Quick mitigation without launch delay.

Why this answer

The most appropriate risk response because it reduces the privacy risk by disabling the email visibility feature globally via a script or administrative override, aligning with the university's moderate risk appetite and two-week launch deadline. This approach directly addresses the FERPA violation without requiring manual per-course configuration, enabling a timely deployment while maintaining control over student data exposure.

Exam trap

The trap here is that candidates may choose 'Accept the risk' (Option D) by underestimating the regulatory weight of FERPA, assuming email addresses are low-risk, while failing to recognize that any PII exposure, even seemingly minor, can trigger compliance violations and reputational damage.

How to eliminate wrong answers

Option A is wrong because transferring risk via student consent forms does not eliminate the FERPA violation; FERPA prohibits disclosure of personally identifiable information (PII) like email addresses without prior written consent, and requiring consent for a default exposure shifts liability but still violates regulatory compliance if consent is not obtained for all students. Option B is wrong because avoiding the risk by selecting a different LMS vendor would likely delay the launch beyond two weeks, contradicting the university's timeline and moderate risk appetite, and may introduce other unassessed risks. Option D is wrong because accepting the risk ignores that email addresses are considered PII under FERPA, and the exposure could lead to privacy violations and regulatory penalties, which is inconsistent with a moderate risk appetite that seeks to mitigate rather than tolerate such compliance risks.

112
MCQmedium

A retail company has a risk monitoring program that tracks key risk indicators (KRIs) for its e-commerce platform. One KRI measures the number of failed payment transactions as a percentage of total transactions. The threshold is set at 2%. Over the past quarter, the KRI has been fluctuating between 1.8% and 2.5%, breaching the threshold several times. Each time the KRI exceeded the threshold, the risk owner performed a manual investigation and found that the failures were due to transient network issues that resolved on their own. The risk owner has now requested that the threshold be raised to 3% to avoid unnecessary investigations. The risk practitioner is evaluating this request. What should the risk practitioner do?

A.Approve the threshold increase since investigations have not found any significant issues.
B.Suggest implementing automated remediation for network issues instead of raising the threshold.
C.Recommend a root cause analysis to determine why network issues are recurring before considering a threshold change.
D.Reject the request and require investigation of every breach.
AnswerC

Addresses the underlying issue.

Why this answer

The recurring network issues causing threshold breaches indicate an underlying problem that needs to be addressed, not just a threshold adjustment. Raising the threshold without understanding the root cause could mask a significant risk to transaction integrity and revenue. A root cause analysis (RCA) would identify whether the transient network issues stem from infrastructure, configuration, or external dependencies, enabling a proper control response.

Exam trap

The trap here is that candidates may assume raising the threshold is a simple risk acceptance decision, but CRISC emphasizes that risk responses must be based on understanding the root cause, not just adjusting metrics to avoid investigations.

How to eliminate wrong answers

Option A is wrong because approving the threshold increase without investigation ignores the fact that the 2% threshold was set based on risk appetite; raising it to 3% could allow an unacceptable level of failed transactions to go unmonitored, potentially leading to customer dissatisfaction and financial loss. Option B is wrong because suggesting automated remediation assumes the network issues are fully understood and can be programmatically resolved, but without root cause analysis, automation might address symptoms rather than the underlying cause, and could introduce new risks if misconfigured. Option D is wrong because requiring investigation of every breach without considering the pattern of transient, self-resolving issues is inefficient and could lead to alert fatigue, but it does not address the need to understand why the network issues recur.

113
MCQeasy

An IT risk report to the board of directors should primarily focus on which of the following?

A.Strategic risks and risk trends affecting the organization
B.Specific control test results for each system
C.Vendor risk assessment scores for all third parties
D.Detailed weekly operational incidents
AnswerA

The board needs a strategic overview of risks and trends.

Why this answer

The board of directors requires a high-level view of IT risk that aligns with business strategy and enterprise risk management. Strategic risks and risk trends provide the necessary context for informed decision-making, focusing on the aggregate impact of risk on organizational objectives rather than operational minutiae.

Exam trap

The CRISC exam often tests the distinction between operational reporting (tactical, detailed) and strategic reporting (aggregated, trend-based), and the trap here is that candidates mistake granular data (like control test results or incident logs) as more 'thorough' or 'accurate' for the board, when in fact the board needs summarized, risk-based insights.

How to eliminate wrong answers

Option B is wrong because specific control test results for each system are too granular for the board; they are more appropriate for operational management and internal audit reporting. Option C is wrong because vendor risk assessment scores for all third parties are tactical details that should be summarized into aggregate risk exposure or trends for board-level reporting. Option D is wrong because detailed weekly operational incidents are operational metrics, not strategic risk information, and would overwhelm the board with noise rather than actionable insight.

114
Multi-Selecthard

A risk assessment team is prioritizing IT risks for treatment. Which THREE factors should be considered when prioritizing risks? (Select THREE)

Select 3 answers
A.Industry standards for similar risks
B.The inherent risk score of each risk
C.Cost-benefit analysis of potential controls
D.Residual risk after existing controls
E.The risk owner's personal preference
AnswersB, C, D

Higher inherent risks typically get higher priority.

Why this answer

The inherent risk score provides a baseline measure of risk without considering controls, which is essential for prioritizing which risks require immediate attention. This score is typically calculated as a product of likelihood and impact, and it helps the team focus on the most severe potential threats first.

Exam trap

The trap here is that candidates may confuse 'factors to consider when prioritizing risks' with 'inputs to risk assessment' and incorrectly select industry standards (Option A) as a direct prioritization factor, when in fact they are used for benchmarking or compliance, not for ranking treatment urgency.

115
MCQeasy

Which TWO of the following are best practices for risk reporting to senior management?

A.Provide actionable recommendations based on risk trends
B.Avoid discussing risk appetite to prevent confusion
C.Present detailed technical analysis for every risk
D.Focus on key risk areas and exceptions
E.Include all available risk data for transparency
AnswerA, D

Actionable insights drive decision-making.

Why this answer

Risk reporting to senior management should be actionable, focusing on trends and recommendations that enable informed decision-making. Senior leaders need concise, strategic insights rather than raw data, so providing recommendations based on risk trends aligns with the principle of risk-based decision support.

Exam trap

The trap here is that candidates confuse transparency with completeness, failing to recognize that senior management needs distilled, actionable insights rather than exhaustive data dumps.

How to eliminate wrong answers

Option B is wrong because avoiding discussion of risk appetite prevents senior management from understanding the organization's risk tolerance, which is essential for aligning risk responses with business objectives. Option C is wrong because presenting detailed technical analysis for every risk overwhelms senior management, who require summarized, high-level information rather than granular technical details. Option E is wrong because including all available risk data for transparency leads to information overload, obscuring key risk areas and exceptions that require attention.

116
MCQeasy

Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?

A.Failed authentication spike
B.Number of accounts created
C.Password reset frequency
D.Number of successful logins
AnswerA

Correct: failed authentication spike signals potential attack.

Why this answer

A spike in failed authentications can indicate an attempted credential attack, serving as a leading KRI.

117
MCQhard

A financial services firm uses SAST and DAST tools in its application security testing. However, they are struggling to prioritize vulnerabilities from the large number of findings. Which additional technique would BEST help identify the most critical vulnerabilities in the context of business risk?

A.OWASP ZAP automated scanner
B.Manual penetration testing
C.CVE database search
D.IAST (Interactive Application Security Testing)
AnswerD

IAST provides accurate, context-aware results with fewer false positives.

Why this answer

IAST combines SAST and DAST with runtime analysis to pinpoint vulnerabilities that are actually exploitable in the running application, reducing false positives and focusing on business-critical issues.

118
MCQeasy

An organization has a risk appetite that is risk-averse. Which risk treatment option would be most aligned with this appetite?

A.Avoid the risk by discontinuing the activity
B.Mitigate the risk with controls
C.Accept the risk
D.Transfer the risk through insurance
AnswerA

Avoidance aligns with risk-averse appetite.

Why this answer

A risk-averse organization prioritizes avoiding exposure to threats. Discontinuing the activity that introduces the risk (option A) eliminates the threat source entirely, ensuring no residual risk remains. This aligns directly with a risk-averse appetite, where even low-probability, high-impact events are unacceptable.

Exam trap

The trap here is that candidates often confuse 'risk transfer' with 'risk elimination,' assuming insurance removes all risk, when in fact it only covers financial loss, leaving operational and reputational risks intact.

How to eliminate wrong answers

Option B is wrong because mitigating with controls reduces risk to an acceptable level but does not eliminate it; residual risk remains, which contradicts a fully risk-averse stance. Option C is wrong because accepting risk means the organization retains the full exposure, which is contrary to a risk-averse appetite that seeks to avoid any potential loss. Option D is wrong because transferring risk through insurance shifts financial liability but does not remove the operational threat; the organization still faces the event's consequences, such as downtime or reputational damage, which a risk-averse entity would find unacceptable.

119
Multi-Selectmedium

A company is evaluating control types for a new system. The security team proposes implementing an intrusion detection system (IDS) and a backup restoration process. Which TWO control types do these represent, respectively?

Select 2 answers
A.Deterrent
B.Preventive
C.Compensating
D.Detective
E.Corrective
AnswersD, E

IDS is a detective control.

Why this answer

IDS detects ongoing attacks (detective), backup restoration helps recover after an incident (corrective).

120
Multi-Selectmedium

Which TWO of the following are essential components of an effective control monitoring program?

Select 2 answers
A.A defined baseline for normal system behavior.
B.A comprehensive list of all controls in the organization.
C.A manual checklist for each control reviewed daily.
D.Real-time alerting for all control failures.
E.Clearly defined roles and responsibilities for monitoring activities.
AnswersA, E

Baselines help identify deviations.

Why this answer

A defined baseline for normal system behavior is essential because it provides the reference point against which monitoring tools can detect anomalies, deviations, or potential control failures. Without a baseline, it is impossible to distinguish routine activity from suspicious or unauthorized changes, rendering monitoring alerts meaningless. This baseline is typically established through statistical modeling, threshold tuning, or historical analysis of logs and metrics.

Exam trap

The trap here is that candidates confuse 'control inventory' (Option B) with 'monitoring program components,' or assume that all control failures must trigger real-time alerts (Option D), when in fact effective monitoring prioritizes based on risk and uses baselines to reduce noise.

121
MCQmedium

During an IT risk assessment, the risk owner identifies a high inherent risk for a legacy system. After implementing a firewall and intrusion detection system, the residual risk is calculated. Which of the following best describes residual risk?

A.The risk level before any controls are implemented
B.The risk level after considering control effectiveness
C.The risk that is transferred to a third party
D.The risk that is accepted without action
AnswerB

Residual risk is inherent risk adjusted for control effectiveness.

Why this answer

Residual risk is the level of risk that remains after controls have been implemented and their effectiveness has been factored in. In this scenario, the firewall and intrusion detection system are controls that reduce the inherent risk, but some risk (e.g., from zero-day exploits or misconfigurations) will persist, which is the residual risk.

Exam trap

The trap here is confusing residual risk with inherent risk (Option A) or with risk response strategies like transfer (Option C) or acceptance (Option D), rather than recognizing it as the risk remaining after control implementation.

How to eliminate wrong answers

Option A is wrong because it describes inherent risk, which is the risk level before any controls are implemented, not after. Option C is wrong because it describes risk transfer (e.g., via insurance or outsourcing), which is a risk response strategy, not the remaining risk after controls. Option D is wrong because it describes risk acceptance, which is a decision to tolerate the residual risk without further action, not the residual risk itself.

122
MCQhard

A large financial institution has implemented a risk monitoring framework that includes KRIs for operational risk. Recently, a critical KRI related to trade settlement errors has been showing an upward trend, but it remains within the approved threshold. The risk manager is concerned because the trend indicates potential control degradation. The control owner argues that since the KRI is still within threshold, no action is needed. The risk manager wants to determine the best course of action to address the trend before it breaches the threshold. The organization's risk policy requires proactive monitoring. What should the risk manager do?

A.Conduct a detailed analysis to understand the root cause and consider adjusting the threshold or implementing control enhancements.
B.Implement additional controls immediately.
C.Report the trend to the audit committee.
D.Update the threshold to reflect the new normal.
AnswerA

Root cause analysis enables informed decision-making aligned with proactive monitoring.

Why this answer

Proactive monitoring requires understanding the root cause of the trend before taking action. Option A is correct because it involves conducting a detailed analysis first, then considering threshold adjustments or control enhancements based on findings. This aligns with the organization's risk policy.

Option B implements controls without understanding the cause, which may be premature. Option C reports to the audit committee without analysis, which is not the first step. Option D updates the threshold without addressing the underlying issue, masking the problem.

123
MCQmedium

An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?

A.Data sovereignty of sensor data stored in the cloud
B.Inability to patch vulnerabilities in legacy IoT devices
C.Interoperability issues between different sensor protocols
D.High energy consumption of sensors
AnswerB

Unpatchable devices pose a persistent security risk that cannot be easily mitigated.

Why this answer

IoT devices with limited firmware update capabilities create a long-term vulnerability, as they cannot be patched against newly discovered flaws. This expands the attack surface and increases risk over time.

124
Multi-Selecthard

An organization is performing a quantitative risk analysis using the FAIR framework. Which THREE of the following are direct components of the FAIR model?

Select 3 answers
A.Single Loss Expectancy
B.Loss Event Frequency
C.Threat Event Frequency
D.Annualized Loss Expectancy
E.Vulnerability
AnswersB, C, E

LEF is a primary component in FAIR.

Why this answer

FAIR components include Loss Event Frequency (LEF), Threat Event Frequency (TEF), Vulnerability, and Loss Magnitude. Annualized Loss Expectancy (ALE) is a derived metric, not a direct component. Single Loss Expectancy is a component of ALE but not a separate FAIR component.

125
MCQmedium

An organization's board has set a risk appetite statement that says: 'We accept moderate levels of operational risk but will not tolerate any compliance violations.' During risk identification, which type of risk should be given the HIGHEST priority?

A.Reputational risks
B.Compliance risks
C.Operational risks
D.Strategic risks
AnswerB

Zero tolerance makes compliance risks the highest priority.

Why this answer

Given the zero-tolerance for compliance violations, compliance risks must be prioritized to ensure they are identified and managed accordingly.

126
MCQmedium

A company is assessing a new vendor that will have access to its customer database. The vendor's security questionnaire reveals they lack SOC 2 certification. According to risk tiering, the vendor is classified as critical. What should the company do?

A.Accept the vendor because the questionnaire indicates other strong controls.
B.Require the vendor to obtain SOC 2 Type II certification before contract signing.
C.Proceed with the contract but increase monitoring frequency.
D.Lower the vendor's tier to medium to avoid the requirement.
AnswerB

For critical vendors, SOC 2 Type II is typically mandatory; the vendor must comply or be rejected.

Why this answer

A critical-tier vendor with access to sensitive customer data requires independent assurance of security controls. SOC 2 Type II certification provides a rigorous, audited assessment of controls over a period of time, which is essential for a high-risk vendor. Requiring this certification before contract signing ensures the vendor meets the necessary security baseline before any data is exposed.

Exam trap

The trap here is that candidates may underestimate the importance of independent audit evidence for critical vendors and mistakenly choose increased monitoring (Option C) as a sufficient compensating control, when in fact it does not address the root need for verified, preventive controls before data access is granted.

How to eliminate wrong answers

Option A is wrong because accepting a critical-tier vendor based solely on a self-reported questionnaire, even with strong controls, lacks independent verification and audit rigor, which is a key requirement for high-risk data access. Option C is wrong because proceeding with the contract and increasing monitoring frequency does not address the lack of foundational, audited controls; monitoring is a detective control, not a preventive one, and is insufficient for a critical vendor. Option D is wrong because lowering the vendor's tier to avoid a requirement is a form of risk avoidance that circumvents proper risk management and policy, and it does not actually reduce the inherent risk of the vendor's access to sensitive data.

127
MCQmedium

Refer to the exhibit. A risk manager reviews the vulnerability scan output. According to the policy, what is the required risk response?

A.Accept the risk
B.Transfer the risk
C.Avoid by disabling the service
D.Mitigate by patching or compensating controls
AnswerD

Remediation is required.

Why this answer

The vulnerability scan output indicates a critical remote code execution vulnerability in the Apache Struts2 framework (CVE-2017-5638). According to policy, the required risk response is to mitigate by patching or implementing compensating controls because the vulnerability has a known exploit and high severity, making acceptance or transfer inappropriate without remediation.

Exam trap

The trap here is that candidates may choose 'Avoid by disabling the service' thinking it is the safest option, but CRISC emphasizes that risk avoidance should only be used when the risk cannot be mitigated to an acceptable level and the business can operate without the asset; patching is the primary response for known vulnerabilities.

How to eliminate wrong answers

Option A is wrong because accepting the risk is only appropriate when the impact and likelihood are low or when the cost of mitigation exceeds the potential loss; here, a critical remote code execution vulnerability with active exploits in the wild cannot be accepted without justification. Option B is wrong because transferring the risk (e.g., via cyber insurance) does not eliminate the underlying technical vulnerability; the attacker can still exploit the unpatched service, and insurance does not prevent the breach. Option C is wrong because avoiding by disabling the service would eliminate the functionality that the business relies on, which is a disproportionate response unless the service is non-essential; patching or compensating controls (e.g., WAF rules) are the standard, less disruptive approach.

128
MCQhard

During a risk assessment, a risk manager is evaluating the effectiveness of a firewall rule set. The manager notes that the firewall logs show a high number of dropped packets from a specific IP range, but no policy changes have been made. The manager suspects the firewall rule set may be misconfigured. Which of the following should the manager do FIRST?

A.Conduct a penetration test on the firewall.
B.Immediately block the IP range.
C.Review the change management records for the firewall.
D.Update the risk register with a new risk.
AnswerC

Change records can reveal if unauthorized or incorrect changes were made.

Why this answer

The first step when a misconfiguration is suspected without any known policy changes is to verify the change management records. This ensures that any recent modifications to the firewall rule set are accounted for, ruling out unauthorized or undocumented changes before proceeding with more invasive actions like penetration testing or blocking IP ranges.

Exam trap

The trap here is that candidates often jump to immediate remediation (blocking the IP range) or escalation (updating the risk register) without first investigating the root cause through change management records, which is the foundational step in IT risk assessment.

How to eliminate wrong answers

Option A is wrong because conducting a penetration test on the firewall is an intrusive and resource-intensive step that should only be performed after verifying that no recent changes have been made; it could also disrupt operations if the misconfiguration is severe. Option B is wrong because immediately blocking the IP range is a reactive measure that may disrupt legitimate traffic and does not address the root cause of the suspected misconfiguration; it should only be considered after confirming the issue through change records. Option D is wrong because updating the risk register with a new risk is premature without first understanding the cause of the dropped packets; the risk register should be updated only after the misconfiguration is confirmed and its impact assessed.

129
MCQhard

During a threat modeling exercise using the STRIDE methodology, a security analyst identifies a threat where an attacker can modify data in transit between a web server and database. Which STRIDE category does this threat belong to?

A.Repudiation
B.Tampering
C.Spoofing
D.Information Disclosure
AnswerB

Tampering is the modification of data.

Why this answer

Tampering involves unauthorized modification of data, which is the 'T' in STRIDE.

130
MCQhard

A financial institution is implementing a cloud-based data analytics platform. The data includes personally identifiable information (PII) of customers in multiple jurisdictions. Which of the following is the MOST critical risk consideration?

A.Vendor lock-in due to proprietary APIs
B.Shared responsibility model gaps
C.Data sovereignty and compliance with local regulations
D.Multi-tenancy isolation risks
AnswerC

Non-compliance can result in significant fines and legal penalties.

Why this answer

The most critical risk is data sovereignty and compliance with local regulations because PII from multiple jurisdictions is subject to varying legal requirements (e.g., GDPR in Europe, CCPA in California, LGPD in Brazil). A cloud-based analytics platform processes and stores this data, and failure to comply can result in severe fines, legal action, and reputational damage. Unlike technical risks like vendor lock-in or multi-tenancy, non-compliance is a direct regulatory and business risk that cannot be mitigated by standard cloud controls alone.

Exam trap

The trap here is that candidates often focus on technical risks like shared responsibility or multi-tenancy, but CRISC emphasizes that regulatory compliance (especially with PII across jurisdictions) is the highest-priority risk because it carries direct legal and financial consequences that cannot be overridden by technical controls.

How to eliminate wrong answers

Option A is wrong because vendor lock-in due to proprietary APIs is a strategic risk, not the most critical when PII and regulatory compliance are at stake; it can be mitigated through standard API abstraction or multi-cloud strategies. Option B is wrong because shared responsibility model gaps are important but typically address security controls (e.g., encryption, access management) rather than the fundamental legal obligation to store data within specific geographic boundaries. Option D is wrong because multi-tenancy isolation risks are a security concern but are secondary to the primary risk of violating data residency laws, which can lead to immediate regulatory penalties.

131
MCQhard

An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?

A.Increased number of malware infections
B.Unauthorized access to corporate financial systems
C.Manipulation of operational parameters leading to equipment damage
D.Denial of service affecting IT services
AnswerC

This can result in physical damage, safety incidents, and environmental harm, making it the highest priority.

Why this answer

In OT environments, the highest priority risk involves safety implications and physical consequences, such as an attacker manipulating operational parameters to cause equipment damage or safety incidents.

132
MCQmedium

A company is implementing COBIT 2019 and wants to ensure that risk management activities are aligned with business objectives. Which governance objective is primarily responsible for evaluating, directing, and monitoring risk management?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM04 — Ensure Resource Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM03 — Ensure Risk Optimization
AnswerD

EDM03 is specifically designed to evaluate, direct, and monitor risk management.

Why this answer

COBIT 2019 defines EDM03 (Ensure Risk Optimization) as the governance objective that covers evaluating, directing, and monitoring risk management to optimize risk exposure.

133
MCQmedium

A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?

A.Model bias
B.Adversarial attacks
C.Lack of explainability
D.Data privacy in training
AnswerC

Explainability is required by regulations for credit decisions; lack thereof can lead to non-compliance.

Why this answer

Regulated decisions require explainability. If the AI model cannot provide explanations, the institution risks regulatory non-compliance and potential legal challenges.

134
MCQeasy

Which type of control testing is typically performed on a continuous basis using automated tools?

A.Annual penetration test
B.Manual control walkthrough
C.Quarterly internal audit review
D.Continuous monitoring
AnswerD

Continuous monitoring is automated and ongoing.

Why this answer

Continuous monitoring uses automated tools like SIEM rules, log monitoring, and vulnerability scanning to provide ongoing assurance over control effectiveness.

135
MCQeasy

Based on the exhibit, what risk does this database error MOST directly indicate?

A.Risk of data inconsistency due to concurrency issues
B.SQL injection vulnerability
C.Unauthorized access to employee records
D.Insufficient disk space for transactions
AnswerA

Deadlocks can cause partial updates and data inconsistency.

Why this answer

The database error indicates a concurrency control failure, such as a deadlock or serialization anomaly, which directly leads to data inconsistency when multiple transactions execute simultaneously without proper isolation. This is a classic risk in multi-user database environments where ACID properties are violated, resulting in lost updates or dirty reads.

Exam trap

The trap here is that candidates confuse a database concurrency error with security vulnerabilities like SQL injection, but the error message and context point to transaction management failures rather than input validation or access control issues.

How to eliminate wrong answers

Option B is wrong because SQL injection is an application-layer attack exploiting unsanitized input, not a database concurrency error. Option C is wrong because unauthorized access involves authentication or authorization failures, not transaction-level conflicts. Option D is wrong because insufficient disk space would cause transaction failures or write errors, not the concurrency-specific error shown in the exhibit.

136
MCQhard

Based on the risk register exhibit, which of the following is the MOST appropriate risk response for R-0042?

A.Mitigate the risk by implementing additional encryption controls
B.Transfer the risk to a third-party insurer
C.Avoid the risk by discontinuing storage of PII
D.Accept the risk and continue monitoring
AnswerD

Since residual risk is below the risk appetite threshold, acceptance is appropriate.

Why this answer

R-0042 is a low-likelihood, low-impact risk involving PII stored with AES-256 encryption and strict access controls. The residual risk is within the organization's risk appetite, making acceptance with continued monitoring the most appropriate response. Mitigation, transfer, or avoidance would introduce unnecessary cost or operational disruption for a risk already well-controlled.

Exam trap

The trap here is that candidates often assume any risk involving PII must be mitigated or avoided, ignoring the risk register's explicit low-likelihood and low-impact ratings and the existing strong controls, which make acceptance the most cost-effective and appropriate response.

How to eliminate wrong answers

Option A is wrong because the risk register shows encryption (AES-256) is already implemented, so adding further encryption controls would provide negligible risk reduction and is not cost-effective. Option B is wrong because transferring the risk to a third-party insurer is typically reserved for high-impact, low-frequency risks (e.g., data breach liability), not for a low-impact, low-likelihood risk already within appetite. Option C is wrong because discontinuing storage of PII would avoid the risk entirely but is a drastic measure that would disrupt business operations and is disproportionate to the low severity of R-0042.

137
Multi-Selecthard

An enterprise is migrating to a public cloud environment. Which THREE of the following are critical cloud-specific risk considerations?

Select 3 answers
A.Multi-tenancy isolation failures
B.On-premises network latency
C.Data sovereignty and legal jurisdiction
D.Shared responsibility model gaps
E.Legacy system compatibility
AnswersA, C, D

Improper isolation can lead to data leakage between tenants.

Why this answer

Cloud-specific risks include data sovereignty, multi-tenancy isolation, and shared responsibility model gaps. Vendor lock-in is also common but not always considered 'critical' for all migrations.

138
MCQmedium

An organization is adopting machine learning for credit scoring decisions. Which of the following risks is MOST critical from a regulatory compliance perspective?

A.Model bias leading to unfair outcomes
B.Data privacy during model training
C.Adversarial attacks on the model
D.Lack of model explainability for automated decisions
AnswerD

Many regulations require explanations for automated credit decisions.

Why this answer

Regulatory frameworks like GDPR and the EU AI Act emphasize the right to explanation for automated decisions. Without model explainability, the organization cannot demonstrate compliance with transparency requirements, making it the most critical risk from a regulatory compliance perspective.

Exam trap

A common pitfall on the CRISC exam is confusing operational risks (like bias or adversarial attacks) with regulatory compliance risks, where explainability is the primary legal requirement for automated decision systems.

How to eliminate wrong answers

Option A is wrong because while model bias is a significant ethical and regulatory concern, it is often a subset of the broader explainability issue; regulators primarily mandate that decisions be explainable to detect and mitigate bias. Option B is wrong because data privacy during model training is important but is typically addressed by data protection impact assessments and anonymization techniques, not the core compliance requirement for automated decision systems. Option C is wrong because adversarial attacks are a security risk that can affect model integrity, but they are not directly tied to regulatory compliance requirements for transparency and accountability in automated credit scoring.

139
MCQeasy

A risk manager is identifying risks for a new mobile payment application. The application will use end-to-end encryption. Which of the following is the BEST source of risk information for identifying potential threats?

A.Industry benchmark risk assessments from similar organizations
B.Threat intelligence feeds specific to the financial services sector
C.Previous internal audit reports on legacy applications
D.Vendor-provided security white papers for the encryption product
AnswerB

Threat intelligence provides current, relevant threat information for risk identification.

Why this answer

Threat intelligence feeds specific to the financial services sector provide real-time, contextualized information about emerging threats, attack patterns, and vulnerabilities targeting mobile payment systems. Since the application uses end-to-end encryption, the risk manager needs to identify threats that could bypass or undermine encryption (e.g., side-channel attacks, key interception, or man-in-the-middle attacks on the handshake), which generic or historical sources would not capture. This source is the best because it is current, sector-specific, and directly relevant to the technology stack.

Exam trap

The trap here is that candidates confuse 'historical internal data' (Option C) or 'generic benchmarks' (Option A) as reliable for risk identification, when in fact only current, external, and sector-specific threat intelligence can identify emerging threats that bypass encryption or target the application's unique implementation.

How to eliminate wrong answers

Option A is wrong because industry benchmark risk assessments from similar organizations are historical and aggregated, lacking the specificity to identify novel threats targeting a new mobile payment application with end-to-end encryption; they may also be outdated by the time of use. Option C is wrong because previous internal audit reports on legacy applications focus on past vulnerabilities and controls for older systems, which do not reflect the unique attack surface of a new mobile payment app using modern encryption protocols like TLS 1.3 or E2EE. Option D is wrong because vendor-provided security white papers for the encryption product are promotional and biased, often omitting real-world threat scenarios or zero-day vulnerabilities that could affect the application's specific implementation.

140
MCQmedium

Based on the exhibit, what is the MOST appropriate immediate risk response?

A.Transfer the risk
B.Accept the risk
C.Implement compensating controls
D.Ignore the risk
AnswerC

Compensating controls reduce risk until a patch is available.

Why this answer

The exhibit indicates a critical vulnerability in a core network device (e.g., a Cisco router with a known CVE in its IOS) that is actively being exploited. Implementing compensating controls, such as deploying an access control list (ACL) to block the exploit's specific traffic pattern or enabling Control Plane Policing (CoPP), immediately reduces the attack surface while a permanent patch is scheduled. This is the most appropriate response because it directly mitigates the risk without waiting for a vendor fix or accepting potential compromise.

Exam trap

The trap here is that candidates often confuse 'accept the risk' as a valid immediate response when the question emphasizes 'immediate,' failing to recognize that compensating controls are the correct first step to reduce exposure before acceptance or transfer can be considered.

How to eliminate wrong answers

Option A is wrong because transferring the risk (e.g., via cyber insurance) does not reduce the immediate technical exposure; the vulnerability remains exploitable on the device. Option B is wrong because accepting the risk would leave the critical network infrastructure open to active exploitation, which is unacceptable given the severity and known exploit. Option D is wrong because ignoring the risk is not a valid risk response in CRISC; it represents negligence and violates the principle of due care, especially when a technical control can be rapidly applied.

141
MCQeasy

Refer to the exhibit. A SIEM correlation rule 'Brute_Force_SSH' has fired excessively due to traffic from internal monitoring servers. What is the BEST course of action?

A.Disable the correlation rule to stop false alerts.
B.Increase the threshold to reduce false positives.
C.Investigate the monitoring servers for compromise.
D.Add an exception in the rule to exclude internal monitoring server IPs.
AnswerD

Targeted tuning reduces false positives.

Why this answer

The excessive alerts are caused by legitimate traffic from internal monitoring servers, not by an actual brute-force attack. Adding an exception to exclude these known IP addresses in the SIEM correlation rule preserves the rule's detection capability for real threats while eliminating the false positives. This is a standard tuning practice for SIEM rules to maintain operational efficiency without disabling security controls.

Exam trap

The trap here is that candidates may confuse 'tuning' with 'disabling' or 'threshold adjustment', failing to recognize that a targeted exception is the most precise and least risky way to handle known false positives from trusted internal sources.

How to eliminate wrong answers

Option A is wrong because disabling the correlation rule entirely removes detection of SSH brute-force attacks, creating a blind spot that attackers could exploit. Option B is wrong because increasing the threshold may reduce false positives but could also cause the rule to miss genuine low-and-slow brute-force attacks, and it does not address the root cause of legitimate monitoring traffic. Option C is wrong because investigating the monitoring servers for compromise is unnecessary and wastes resources, as the traffic is expected from internal monitoring tools, not indicative of an actual compromise.

142
MCQmedium

Based on the exhibit, which vulnerability poses the HIGHEST risk to the organization?

A.CVE-2022-9876 on the file server
B.CVE-2023-5678 on the web server
C.CVE-2023-1234 on the critical server
D.All vulnerabilities pose equal risk
AnswerC

Unpatched critical vulnerability with high CVSS score.

Why this answer

C is correct because the critical server hosts the organization's most sensitive data or core business applications, and CVE-2023-1234 is a remote code execution vulnerability with a CVSS score of 9.8, allowing an unauthenticated attacker to fully compromise the server. The combination of high asset criticality and severe exploitability makes this the highest risk, as defined by the risk formula (Likelihood × Impact).

Exam trap

The trap here is that candidates often focus solely on the CVSS score or vulnerability type without considering the asset's criticality, leading them to choose a high-severity vulnerability on a non-critical asset over a slightly lower-severity one on a critical server.

How to eliminate wrong answers

Option A is wrong because CVE-2022-9876 on the file server is a medium-severity directory traversal vulnerability (CVSS 6.5) that requires authenticated access, limiting its exploitability and impact compared to a remote code execution on a critical asset. Option B is wrong because CVE-2023-5678 on the web server is a cross-site scripting (XSS) vulnerability (CVSS 6.1) that only affects client-side users and does not grant server-level access, making it less impactful than a critical server compromise. Option D is wrong because risk is not equal across vulnerabilities; it must be assessed based on asset criticality, threat likelihood, and vulnerability severity, which differ significantly among the options.

143
Multi-Selectmedium

Which THREE of the following are typical exclusions in a cyber insurance policy?

Select 3 answers
A.Losses due to power outages without malicious intent
B.Intentional acts by the insured
C.Ransomware payments
D.Acts of war or terrorism
E.Social engineering fraud
AnswersA, B, D

Non-malicious infrastructure failures are typically excluded.

Why this answer

Common exclusions include acts of war, intentional acts by the insured, and infrastructure failure without malicious intent. Some policies also exclude social engineering.

144
MCQhard

Refer to the exhibit. The control test failed because unauthorized access attempts were detected. The remediation plan suggests additional logging. Is this remediation appropriate?

A.No, the control test methodology is flawed.
B.Yes, because the control is detective in nature.
C.Yes, additional logging will help detect future attempts.
D.No, the remediation should focus on strengthening access controls.
AnswerD

Root cause is unauthorized access; need stronger preventive controls.

Why this answer

The control test failure was due to unauthorized access attempts, which indicates a weakness in preventive controls. Adding logging (a detective control) does not address the root cause; the remediation should focus on strengthening access controls (e.g., tightening authentication, authorization, or firewall rules) to prevent unauthorized access in the first place. Logging alone would only record future incidents without reducing their likelihood.

Exam trap

The trap here is that candidates confuse 'detecting' with 'preventing' and assume that adding logging is always a valid remediation, but CRISC emphasizes that remediation must address the root cause of the control failure, not just add monitoring.

How to eliminate wrong answers

Option A is wrong because the control test methodology is not inherently flawed; the test correctly identified unauthorized access attempts, so the issue lies with the control's effectiveness, not the testing approach. Option B is wrong because while the control may be detective in nature, the remediation of adding logging is still inappropriate—it fails to address the preventive weakness that allowed unauthorized access, and detective controls should complement, not replace, preventive measures. Option C is wrong because although additional logging will help detect future attempts, detection without prevention does not remediate the underlying vulnerability; the goal should be to stop unauthorized access, not just log it.

145
MCQmedium

Which of the following BEST describes the difference between a threat actor who is a 'hacktivist' and one who is an 'organized crime' actor?

A.Hacktivists are motivated by ideology; organized crime actors are motivated by financial gain
B.Hacktivists target only government entities; organized crime targets only businesses
C.Hacktivists are always insiders; organized crime actors are external
D.Hacktivists use advanced persistent threats (APTs); organized crime uses commodity malware
AnswerA

Correct. This aligns with common definitions.

Why this answer

Hacktivists are typically motivated by political or social causes, while organized crime groups are primarily financially motivated.

146
MCQmedium

An organization has received a critical vulnerability alert for a web application firewall. The risk owner is on leave. What should the risk manager do?

A.Escalate to the designated alternate risk owner for decision.
B.Apply the patch immediately without consultation.
C.Accept the risk since the impact is unknown.
D.Wait for the risk owner to return to avoid overstepping authority.
AnswerA

Proper escalation ensures accountability and timely response.

Why this answer

When the risk owner is unavailable, the risk manager must ensure that risk decisions are still made in a timely manner, especially for critical vulnerabilities. Escalating to the designated alternate risk owner is the correct action because it maintains the chain of accountability and enables an informed decision on whether to apply mitigations, such as patching the WAF, without unnecessary delay.

Exam trap

The trap here is that candidates may assume immediate patching (Option B) is always the correct response for a critical vulnerability, but CRISC emphasizes that risk decisions must be made by the designated risk owner or their alternate, not unilaterally by the risk manager.

How to eliminate wrong answers

Option B is wrong because applying the patch immediately without consultation bypasses the risk owner's authority and could introduce unintended side effects, such as breaking WAF rules or causing service disruption, without a proper risk assessment. Option C is wrong because accepting the risk when the impact is unknown violates the principle of informed risk acceptance; the risk manager must first gather information or escalate to someone with the authority to accept or reject the risk. Option D is wrong because waiting for the risk owner to return could leave a critical vulnerability unaddressed for an extended period, increasing the likelihood of exploitation and violating incident response timelines.

147
Multi-Selecthard

A risk manager is updating the risk report for the IT steering committee. Which THREE elements should be included to provide a comprehensive view of the risk posture?

Select 3 answers
A.Names of all IT employees
B.Risk trend analysis
C.Risk heat map
D.Detailed configuration of each firewall
E.Top risks and their status
AnswersB, C, E

Trends show whether risk is increasing or decreasing.

Why this answer

Risk trend analysis is essential for a comprehensive risk report because it shows how the organization's risk posture has changed over time, enabling the IT steering committee to identify emerging threats and assess the effectiveness of past risk responses. This aligns with CRISC's emphasis on continuous monitoring and reporting of risk indicators to support informed decision-making.

Exam trap

ISACA often tests the distinction between operational details (like firewall configs) and strategic risk reporting elements, trapping candidates who confuse granular technical data with the high-level summaries needed for governance-level decision-making.

148
MCQmedium

Refer to the exhibit. A security analyst reviews firewall logs and sees repeated authentication failures for VPN tunnel attempts between two IP addresses. What is the MOST appropriate action?

A.Block the source IP (203.0.113.5) at the firewall.
B.Contact the destination IP owner to verify credentials.
C.Update the VPN policy to allow all authentication methods.
D.Ignore the logs as routine failed attempts.
AnswerA

Blocking the attacking IP mitigates threat.

Why this answer

Repeated authentication failures for VPN tunnel attempts between two IP addresses indicate a potential brute-force attack or misconfigured credentials. Blocking the source IP (203.0.113.5) at the firewall is the most appropriate immediate action to mitigate the threat, as it stops further attempts without disrupting legitimate traffic. This aligns with the CRISC domain of Risk and Control Monitoring and Reporting, where timely response to anomalous events is critical.

Exam trap

The trap here is that candidates may choose Option B (contacting the destination IP owner) because they assume a credential issue, but the question emphasizes repeated failures from a single source IP, which is a classic sign of an attack requiring immediate blocking, not administrative coordination.

How to eliminate wrong answers

Option B is wrong because contacting the destination IP owner to verify credentials is a slow, manual process that does not address the immediate security risk; the logs show repeated failures, not a single credential issue, and the source IP may be malicious. Option C is wrong because updating the VPN policy to allow all authentication methods would weaken security by permitting weaker or unauthenticated methods, potentially enabling successful attacks. Option D is wrong because ignoring the logs as routine failed attempts overlooks the pattern of repeated failures, which could indicate an active brute-force attack or reconnaissance, violating monitoring and response best practices.

149
Multi-Selectmedium

A healthcare organization is migrating its electronic health records (EHR) system to a public cloud. The risk manager identifies several risks. Which TWO of the following are the MOST significant risks related to data privacy and regulatory compliance?

Select 2 answers
A.Potential for service downtime affecting patient care.
B.Data residency and jurisdiction issues.
C.Loss of control over the cloud provider's internal access controls.
D.Insufficient encryption of data at rest and in transit.
E.Vendor lock-in due to proprietary APIs.
AnswersB, D

Data may be stored in countries with inadequate privacy laws.

Why this answer

Data residency and jurisdiction issues (B) are a top risk because healthcare data is subject to strict regulations like HIPAA and GDPR, which may require data to remain within specific geographic boundaries. Migrating EHRs to a public cloud can inadvertently place data in regions with different legal protections, exposing the organization to non-compliance and legal penalties.

Exam trap

The trap here is that candidates often confuse operational risks (like downtime) or general security risks (like access control) with the specific regulatory and privacy risks that are most significant for healthcare data in the cloud, while overlooking the foundational compliance requirements of data residency and encryption.

150
MCQmedium

A company is migrating critical applications to the cloud. The risk manager is assessing the shared responsibility model. Which risk is the customer typically responsible for?

A.Network infrastructure maintenance
B.Physical security of data centers
C.Data classification and access control
D.Hypervisor security
AnswerC

The customer must manage data classification and who has access to it.

Why this answer

According to the shared responsibility model, the customer is responsible for data, access management, and application-level security.

Page 1

Page 2 of 14

Page 3