Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 151–225

1062 questions total · 15pages · All types, answers revealed

Page 2

Page 3 of 15

Page 4
151
Multi-Selecthard

A risk manager at a retail bank is assessing risks introduced by a new open-source container orchestration platform. The platform will host internal APIs that process non-public customer information. Which TWO of the following are the MOST significant risks that should be prioritized in the risk register? (Choose two.)

Select 2 answers
A.Hard-coded secrets and API keys in container images or orchestration manifests.
B.The platform's community support model may delay resolution of non-security bugs.
C.Lack of a documented container orchestration policy and standards for secure configuration.
D.Increased licensing costs due to the open-source platform's commercial support model.
E.Unpatched vulnerabilities in container images that could lead to unauthorized access to customer data.
AnswersA, E

Hard-coded secrets in images or manifests are easily exposed through image layers, source repositories, or runtime environment variables. In a banking context, exposed API keys could allow attackers to bypass authentication and access customer data. This risk is both highly likely and high impact, and it can be mitigated through secret management tools, image scanning, and secure coding practices, warranting priority in the risk register.

Why this answer

Unpatched container images and hard-coded secrets directly threaten the confidentiality and integrity of non-public customer information. These risks are highly exploitable and can lead to data breaches, regulatory penalties, and reputational damage. Policy gaps, licensing costs, and community support delays are important but secondary; they do not represent immediate, high-impact threats to customer data in a banking context.

Exam trap

The trap here is focusing on governance or cost issues while overlooking that unpatched images and hard-coded secrets are the direct, high-impact threats to customer data.

152
MCQeasy

Refer to the exhibit. A SIEM correlation rule 'Brute_Force_SSH' has fired excessively due to traffic from internal monitoring servers. What is the BEST course of action?

A.Disable the correlation rule to stop false alerts.
B.Increase the threshold to reduce false positives.
C.Investigate the monitoring servers for compromise.
D.Add an exception in the rule to exclude internal monitoring server IPs.
AnswerD

Adding an exception for the internal monitoring server IPs suppresses the noisy false positives at source, so the rule still detects genuine brute-force attempts elsewhere. This is more precise than disabling or lowering the rule's severity, preserving detection coverage.

Why this answer

The excessive alerts are caused by legitimate traffic from internal monitoring servers, not by an actual brute-force attack. Adding an exception to exclude these known IP addresses in the SIEM correlation rule preserves the rule's detection capability for real threats while eliminating the false positives. This is a standard tuning practice for SIEM rules to maintain operational efficiency without disabling security controls.

Exam trap

The trap here is that candidates may confuse 'tuning' with 'disabling' or 'threshold adjustment', failing to recognize that a targeted exception is the most precise and least risky way to handle known false positives from trusted internal sources.

How to eliminate wrong answers

Option A is wrong because disabling the correlation rule entirely removes detection of SSH brute-force attacks, creating a blind spot that attackers could exploit. Option B is wrong because increasing the threshold may reduce false positives but could also cause the rule to miss genuine low-and-slow brute-force attacks, and it does not address the root cause of legitimate monitoring traffic. Option C is wrong because investigating the monitoring servers for compromise is unnecessary and wastes resources, as the traffic is expected from internal monitoring tools, not indicative of an actual compromise.

153
Multi-Selectmedium

Which THREE of the following are typical exclusions in a cyber insurance policy?

Select 3 answers
A.Losses due to power outages without malicious intent
B.Intentional acts by the insured
C.Ransomware payments
D.Acts of war or terrorism
E.Social engineering fraud
AnswersA, B, D

Cyber policies typically exclude physical perils such as power outages without a malicious element, since these are property or business-interruption losses rather than cyber incidents. This exclusion satisfies the stem's requirement by removing non-malicious, non-cyber causes of loss from cover.

Why this answer

Option A (losses due to power outages without malicious intent) is a typical exclusion because cyber policies generally cover malicious cyber events, not non-malicious infrastructure or utility failures that cause business interruption. Option B (intentional acts by the insured) is excluded because insurance cannot cover deliberate wrongdoing or fraudulent conduct by the policyholder, as this would violate the principle of indemnity and public policy. Option D (acts of war or terrorism) is a standard exclusion found in most cyber policies, often tied to war exclusions that remove coverage for state-sponsored or warlike attacks.

Option C (ransomware payments) is not a standard exclusion — many cyber policies explicitly cover ransomware, including reimbursement of ransom payments, subject to conditions. Option E (social engineering fraud) is also not a typical blanket exclusion; it is frequently offered as a covered extension or sub-limit, though it may require specific endorsement rather than being excluded outright.

Exam trap

CRISC often tests the misconception that ransomware and social engineering are excluded, when in fact they are commonly covered (with sub-limits), while power outages, intentional acts, and war/terrorism are the standard exclusions.

154
Multi-Selectmedium

A risk practitioner is identifying risks for an organization that has adopted a bring-your-own-device policy for remote workers. The practitioner wants to document vulnerabilities that increase the likelihood of a data loss event. Which TWO of the following are MOST appropriately classified as vulnerabilities in this scenario? (Choose two.)

Select 2 answers
A.Employees store corporate documents in unmanaged personal cloud storage accounts.
B.A nation-state group is targeting the organization's industry sector.
C.The organization's cyber insurance policy excludes unencrypted device losses.
D.A remote worker's lost laptop could cost the organization regulatory fines.
E.Personal devices lack mandatory full-disk encryption and mobile device management enrollment.
AnswersA, E

This is a vulnerability because it creates an uncontrolled data repository outside the organization's visibility and protection, directly increasing the likelihood that sensitive information is exposed or lost. It reflects a weakness in data handling practices and control coverage rather than an external threat or a business impact. Documenting it as a vulnerability supports targeted controls such as data loss prevention and acceptable use enforcement.

Why this answer

Vulnerabilities are internal weaknesses or control gaps that a threat can exploit to cause harm. Storing corporate documents in unmanaged personal cloud accounts and running personal devices without encryption or management enrollment are both such weaknesses, and each directly raises the likelihood of data loss. The other statements describe a threat actor, a business impact, and an insurance condition, which belong to different components of the risk equation.

Exam trap

The trap here is treating anything undesirable related to the BYOD program, such as a threat actor, an impact statement, or an insurance exclusion, as a vulnerability instead of isolating the internal control weaknesses.

155
MCQhard

Refer to the exhibit. The control test failed because unauthorized access attempts were detected. The remediation plan suggests additional logging. Is this remediation appropriate?

A.No, the control test methodology is flawed.
B.Yes, because the control is detective in nature.
C.Yes, additional logging will help detect future attempts.
D.No, the remediation should focus on strengthening access controls.
AnswerD

Additional logging only records unauthorised attempts; it cannot prevent them, so the failed control remains unaddressed. Since the test detected unauthorised access, the root cause is weak access enforcement, and strengthening access controls directly satisfies that constraint. Logging supports detection and investigation, not prevention, making it an inappropriate primary remediation here.

Why this answer

The control test failure was due to unauthorized access attempts, which indicates a weakness in preventive controls. Adding logging (a detective control) does not address the root cause; the remediation should focus on strengthening access controls (e.g., tightening authentication, authorization, or firewall rules) to prevent unauthorized access in the first place. Logging alone would only record future incidents without reducing their likelihood.

Exam trap

The trap here is that candidates confuse 'detecting' with 'preventing' and assume that adding logging is always a valid remediation, but CRISC emphasizes that remediation must address the root cause of the control failure, not just add monitoring.

How to eliminate wrong answers

Option A is wrong because the control test methodology is not inherently flawed; the test correctly identified unauthorized access attempts, so the issue lies with the control's effectiveness, not the testing approach. Option B is wrong because while the control may be detective in nature, the remediation of adding logging is still inappropriate—it fails to address the preventive weakness that allowed unauthorized access, and detective controls should complement, not replace, preventive measures. Option C is wrong because although additional logging will help detect future attempts, detection without prevention does not remediate the underlying vulnerability; the goal should be to stop unauthorized access, not just log it.

156
MCQmedium

A global investment firm maintains a central risk register. The CISO wants to reduce the number of entries by consolidating risks that share the same root cause. Which action BEST supports this goal while preserving the risk register's integrity?

A.Group risks by the asset they affect and merge them into a single risk statement per asset.
B.Create a parent risk for each shared root cause and link the related risk entries as sub-risks, retaining their individual details.
C.Move all low-rated risks to a separate spreadsheet outside the central register.
D.Delete duplicate entries and rely on the risk owner's memory to recall the original context.
AnswerB

A parent-child structure clusters risks that stem from the same root cause while retaining each entry's likelihood, impact, owner, and treatment. This reduces the apparent volume of top-level entries without losing the granularity needed for treatment and monitoring. It maintains traceability and supports aggregation for reporting to the board, which is exactly what the CISO needs here.

Why this answer

Consolidating by shared root cause is best achieved with a parent-child hierarchy that preserves the details of each underlying risk. This keeps likelihood, impact, ownership, and treatment traceable while reducing clutter at the top level. Deleting, relocating, or asset-merging entries sacrifices granularity, auditability, or aggregation insight, none of which preserves the register's integrity.

Exam trap

The trap here is assuming that fewer register entries always means better risk management, when the real goal is consolidation without loss of traceability or ownership detail.

157
MCQmedium

Which of the following BEST describes the difference between a threat actor who is a 'hacktivist' and one who is an 'organized crime' actor?

A.Hacktivists are motivated by ideology; organized crime actors are motivated by financial gain
B.Hacktivists target only government entities; organized crime targets only businesses
C.Hacktivists are always insiders; organized crime actors are external
D.Hacktivists use advanced persistent threats (APTs); organized crime uses commodity malware
AnswerA

Hacktivists pursue ideological or political ends, attacking targets to publicise a cause. Organised crime actors pursue financial gain, typically through ransomware, fraud or data theft. The axis of difference is motivation, which shapes target selection, persistence and monetisation, making this the best description.

Why this answer

The correct answer is A because it accurately captures the fundamental distinction between hacktivists and organized crime actors: motivation. Hacktivists are driven by ideological, political, or social causes, and their attacks are often symbolic or aimed at raising awareness. Organized crime actors, on the other hand, are primarily motivated by financial gain, engaging in activities like ransomware, fraud, and data theft for profit.

This motivational difference is a core concept in risk management, as it influences the threat's targeting, persistence, and methods.

Exam trap

CRISC often tests the ability to distinguish threat actors by their primary motivation, and candidates may incorrectly focus on targeting or sophistication rather than the underlying driver of ideology versus financial gain.

How to eliminate wrong answers

Option B is wrong because it incorrectly limits hacktivists to targeting only government entities and organized crime to only businesses; in reality, hacktivists can target any organization that opposes their ideology, and organized crime can target any entity that yields financial return. Option C is wrong because it falsely claims hacktivists are always insiders; while insiders can be hacktivists, most hacktivists are external actors, and organized crime actors are not exclusively external. Option D is wrong because it inaccurately associates hacktivists with advanced persistent threats (APTs) and organized crime with commodity malware; APTs are typically state-sponsored or highly sophisticated groups, while hacktivists often use simpler tools, and organized crime may use a mix of commodity and custom malware.

158
MCQmedium

An organization has received a critical vulnerability alert for a web application firewall. The risk owner is on leave. What should the risk manager do?

A.Escalate to the designated alternate risk owner for decision.
B.Apply the patch immediately without consultation.
C.Accept the risk since the impact is unknown.
D.Wait for the risk owner to return to avoid overstepping authority.
AnswerA

Risk decisions require an accountable owner; the primary owner's absence must not stall remediation. Escalating to the pre-designated alternate preserves the ownership and authority chain, enabling a timely, authorised decision on the critical vulnerability rather than leaving it unaddressed.

Why this answer

When the risk owner is unavailable, the risk manager must ensure that risk decisions are still made in a timely manner, especially for critical vulnerabilities. Escalating to the designated alternate risk owner is the correct action because it maintains the chain of accountability and enables an informed decision on whether to apply mitigations, such as patching the WAF, without unnecessary delay.

Exam trap

The trap here is that candidates may assume immediate patching (Option B) is always the correct response for a critical vulnerability, but CRISC emphasizes that risk decisions must be made by the designated risk owner or their alternate, not unilaterally by the risk manager.

How to eliminate wrong answers

Option B is wrong because applying the patch immediately without consultation bypasses the risk owner's authority and could introduce unintended side effects, such as breaking WAF rules or causing service disruption, without a proper risk assessment. Option C is wrong because accepting the risk when the impact is unknown violates the principle of informed risk acceptance; the risk manager must first gather information or escalate to someone with the authority to accept or reject the risk. Option D is wrong because waiting for the risk owner to return could leave a critical vulnerability unaddressed for an extended period, increasing the likelihood of exploitation and violating incident response timelines.

159
Multi-Selecthard

A risk manager is updating the risk report for the IT steering committee. Which THREE elements should be included to provide a comprehensive view of the risk posture?

Select 3 answers
A.Names of all IT employees
B.Risk trend analysis
C.Risk heat map
D.Detailed configuration of each firewall
E.Top risks and their status
AnswersB, C, E

Risk trend analysis reveals whether exposure is rising, falling or stable over successive reporting periods, satisfying the committee's need to judge direction rather than a single snapshot. Plotting inherent and residual risk across cycles exposes deteriorating controls and validates whether prior treatments worked, giving the forward-looking context a comprehensive posture view requires.

Why this answer

Risk trend analysis (B) is correct because tracking how risk exposure changes over time (e.g., increasing, decreasing, or stable risk levels across reporting periods) gives the steering committee insight into whether risk management efforts are effective and where emerging risks are developing. A risk heat map (C) is correct because it visually plots risks by likelihood and impact, enabling the committee to quickly identify and prioritize the highest-exposure areas across the organization's risk posture. Top risks and their status (E) is correct because summarizing the most significant risks along with their current mitigation status, owners, and progress provides the committee with actionable, decision-ready information for governance.

Names of all IT employees (A) is not a risk posture element—it is personnel data with no bearing on risk likelihood, impact, or treatment. Detailed configuration of each firewall (D) is far too granular and technical for a steering-committee risk report; such operational detail belongs in technical security documentation, not executive risk reporting.

Exam trap

ISACA often tests the distinction between operational details (like firewall configs) and strategic risk reporting elements, trapping candidates who confuse granular technical data with the high-level summaries needed for governance-level decision-making.

160
Multi-Selectmedium

A healthcare organization is migrating its electronic health records (EHR) system to a public cloud. The risk manager identifies several risks. Which TWO of the following are the MOST significant risks related to data privacy and regulatory compliance?

Select 2 answers
A.Potential for service downtime affecting patient care.
B.Data residency and jurisdiction issues.
C.Loss of control over the cloud provider's internal access controls.
D.Insufficient encryption of data at rest and in transit.
E.Vendor lock-in due to proprietary APIs.
AnswersB, D

Data may be stored in countries with inadequate privacy laws.

Why this answer

Data residency and jurisdiction issues (B) are a top risk because healthcare data is subject to strict regulations like HIPAA and GDPR, which may require data to remain within specific geographic boundaries. Migrating EHRs to a public cloud can inadvertently place data in regions with different legal protections, exposing the organization to non-compliance and legal penalties.

Exam trap

The trap here is that candidates often confuse operational risks (like downtime) or general security risks (like access control) with the specific regulatory and privacy risks that are most significant for healthcare data in the cloud, while overlooking the foundational compliance requirements of data residency and encryption.

161
MCQmedium

A company is migrating critical applications to the cloud. The risk manager is assessing the shared responsibility model. Which risk is the customer typically responsible for?

A.Network infrastructure maintenance
B.Physical security of data centers
C.Data classification and access control
D.Hypervisor security
AnswerC

Under the shared responsibility model the provider secures the cloud infrastructure, while the customer always owns its data. Classification and access control are therefore customer duties, governing who may reach data and how it is labelled, regardless of the deployment model chosen.

Why this answer

According to the shared responsibility model, the customer is responsible for data, access management, and application-level security.

162
MCQeasy

A global manufacturing company is implementing a new ERP system across multiple regions. The project manager has identified a risk that data migration from legacy systems may cause data corruption, leading to production delays. The risk owner proposes conducting a full data reconciliation after migration. However, the IT director argues that this would be too time-consuming and suggests only sampling data for verification. The risk manager must decide on the risk response. The project timeline is tight, and the company has a low tolerance for data integrity issues. Which of the following is the BEST course of action?

A.Accept the risk and proceed with data sampling to save time
B.Avoid the risk by postponing the ERP implementation
C.Implement the full data reconciliation as proposed by the risk owner
D.Transfer the risk by purchasing insurance for data corruption
AnswerC

Full reconciliation matches every migrated record against the legacy source, detecting all corruption rather than extrapolating from samples. Given the tight timeline but low tolerance for data integrity issues, this response aligns with the organisation's stated risk appetite and avoids production delays from undetected errors.

Why this answer

Full data reconciliation is the correct risk response because the company has a low tolerance for data integrity issues and the risk of data corruption could cause production delays. While time-consuming, this approach directly mitigates the identified risk by ensuring all migrated data is verified, aligning with the risk appetite. Sampling would leave a margin of error unacceptable for a low-tolerance environment, and the other options either fail to address the risk or are impractical.

Exam trap

The trap here is that candidates may choose data sampling (Option A) as a compromise to save time, overlooking that the company's low tolerance for data integrity issues demands full verification, not a statistical shortcut.

How to eliminate wrong answers

Option A is wrong because accepting the risk with data sampling ignores the company's low tolerance for data integrity issues and could leave undetected corruption that causes production delays. Option B is wrong because avoiding the risk by postponing the ERP implementation is an extreme overreaction that does not address the immediate need for migration and would cause significant business disruption. Option D is wrong because transferring the risk via insurance does not prevent data corruption or production delays; it only provides financial compensation after the fact, which does not meet the requirement for data integrity.

163
Multi-Selecthard

A retail company is assessing risk for a legacy point-of-sale system that cannot be patched. The risk team wants to identify controls that would reduce the likelihood of a successful exploitation of known vulnerabilities on these terminals. Which TWO of the following are preventive controls that would BEST reduce the likelihood of exploitation? (Choose two.)

Select 2 answers
A.Conduct quarterly vulnerability scans of the point-of-sale network
B.Segment the point-of-sale terminals onto a dedicated network with strict firewall rules limiting outbound and inbound traffic
C.Enable detailed logging and forward terminal logs to a centralized SIEM for monitoring
D.Deploy application allowlisting on the terminals so only approved executables can run
E.Perform daily backups of terminal configuration and transaction data
AnswersB, D

This is correct because network segmentation with restrictive firewall rules prevents exploitation attempts from reaching the unpatched terminals and limits lateral movement, directly lowering the likelihood that a known vulnerability is successfully exploited. It is a preventive control that reduces exposure even when patching is not feasible on the legacy point-of-sale devices.

Why this answer

Preventive controls reduce the likelihood of a successful attack. Network segmentation with restrictive firewall rules and application allowlisting both stop exploitation attempts from succeeding on unpatched terminals by limiting reachability and blocking unauthorized code execution. Logging, backups, and vulnerability scanning are valuable but are detective or corrective in nature and do not lower the probability of exploitation.

Exam trap

The trap here is treating monitoring, scanning, or backups as if they reduce the likelihood of exploitation, when they are detective or corrective rather than preventive.

164
MCQmedium

A financial services firm has completed a risk assessment of its trading platform. The chief risk officer wants to ensure the assessment results are comparable across business units and that the reasoning behind each likelihood and impact rating is transparent to auditors. Which action BEST supports this objective?

A.Increase the number of risks in the register to ensure no scenario is overlooked
B.Recalculate all risk scores using a 10×10 matrix instead of a 5×5 matrix
C.Assign all risk scoring decisions to a single central analyst
D.Document the rating scales and the specific criteria and evidence used to assign each likelihood and impact value
AnswerD

This is correct because consistent, well-documented rating criteria allow different business units to apply the same scales in comparable ways, and recording the evidence behind each rating gives auditors a clear rationale to review. It directly supports both comparability across units and traceability of assessment judgments for the trading platform risk register.

Why this answer

Comparability and auditability depend on defined rating scales, explicit criteria for each level, and documented evidence supporting each likelihood and impact assignment. These elements let different business units apply the same methodology and let auditors trace how each score was derived, which is more valuable than changing matrix size or centralizing decisions.

Exam trap

The trap here is equating a larger or more granular rating matrix with improved consistency, when consistency actually comes from defined criteria and documented rationale.

165
MCQeasy

During an IT risk assessment, the risk owner decides to accept a risk that falls within the organization's risk appetite. Which of the following actions is most appropriate for the risk owner to take?

A.Document the risk and obtain formal sign-off from the risk owner.
B.Eliminate the business process that creates the risk.
C.Transfer the risk to a third party via insurance.
D.Implement additional controls to reduce the risk to zero.
AnswerA

Acceptance is a deliberate decision, so the risk owner must record the risk in the risk register with its acceptance rationale and obtain formal sign-off. This creates an auditable trail proving the risk was knowingly accepted within the organisation's stated risk appetite, satisfying governance and accountability requirements.

Why this answer

When a risk falls within the organization's risk appetite, the most appropriate action is to formally accept it. The risk owner must document the risk and obtain formal sign-off to ensure accountability and auditability, as required by the risk management framework. This aligns with the principle that risks within appetite do not require additional treatment beyond formal acceptance.

Exam trap

The trap here is that candidates often confuse risk acceptance with risk treatment, assuming that any risk must be mitigated or transferred, but the CRISC exam emphasizes that risks within appetite can be formally accepted without further action.

How to eliminate wrong answers

Option B is wrong because eliminating the business process that creates the risk is a risk avoidance strategy, which is excessive and unnecessary when the risk is within the organization's risk appetite. Option C is wrong because transferring the risk via insurance is a risk treatment option typically reserved for risks that exceed the risk appetite or tolerance, not for those already within acceptable levels. Option D is wrong because implementing additional controls to reduce the risk to zero is impractical and violates the concept of residual risk; risk can rarely be reduced to zero, and doing so would be cost-prohibitive and unnecessary for an accepted risk.

166
Multi-Selectmedium

A risk analyst is building a scenario for a ransomware event affecting a hospital's electronic health record environment. The analyst wants to capture loss magnitude dimensions that are frequently overlooked when only direct recovery costs are counted. Which TWO loss factors should be included to make the magnitude estimate more complete? (Choose two.)

Select 2 answers
A.Regulatory penalties and notification obligations triggered by the breach of patient records.
B.The market price of the cryptocurrency demanded by the attacker at the time of the incident.
C.The salary of the security awareness trainer who delivered last year's phishing education sessions.
D.Business interruption losses from unavailable clinical systems during containment and recovery.
E.The annual license renewal cost the hospital already pays for its endpoint protection platform.
AnswersA, D

Ransomware affecting health records typically triggers statutory notification and penalty exposure under health privacy regulations, and these costs can dwarf the ransom itself. Including them makes the magnitude estimate reflect legal and compliance consequences rather than only restoration effort. This directly addresses the scenario's concern about undercounting loss dimensions beyond direct recovery.

Why this answer

Complete loss magnitude estimates for a ransomware scenario must extend past recovery costs to include consequential and secondary effects. Regulatory penalties and notification duties tied to compromised patient records, along with business interruption from unavailable clinical systems, are two such dimensions. Planned expenses such as license fees and prior training spend are not incident-driven losses and would distort the estimate.

Exam trap

The trap here is treating the ransom demand as the headline loss while omitting regulatory and interruption consequences that usually cost far more.

167
MCQhard

A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?

A.Standardize industrial control protocols
B.Reduce energy consumption
C.Ensure interoperability between IT and OT systems
D.Protect the reliability of the bulk electric system
AnswerD

NERC CIP standards mandate controls such as electronic security perimeters, access management and incident reporting for entities operating bulk electric system assets. Their primary objective is protecting the reliability of that system, satisfying the stem's compliance requirement for the power utility.

Why this answer

NERC CIP (Critical Infrastructure Protection) standards are mandatory reliability standards specifically designed to protect the bulk electric system (BES) from cyber and physical threats. Their primary objective is to ensure the reliable operation of the BES by securing the assets that control and monitor it. This is a regulatory requirement for power utilities in North America.

Exam trap

CRISC often tests the distinction between IT and OT security objectives; candidates may confuse interoperability or protocol standardization with the core reliability mission of NERC CIP.

How to eliminate wrong answers

Option A is wrong because NERC CIP does not standardize industrial control protocols; that is the role of organizations like IEC or IEEE. Option B is wrong because reducing energy consumption is an environmental or efficiency goal, not a cybersecurity reliability objective. Option C is wrong because while interoperability between IT and OT may be a consideration, it is not the primary objective of NERC CIP; the focus is on protecting reliability, not enabling integration.

168
MCQhard

A risk practitioner at a payments processor is reviewing the organization's risk register and notices that several risk entries describe only the consequence, such as 'customer data is exposed.' The practitioner wants each entry to follow the ISACA risk scenario structure. Which of the following should the practitioner add to each entry to complete the scenario?

A.A regulatory citation and an audit finding reference
B.A risk score and a heat map color
C.A control owner and a remediation due date
D.A threat source and an event, with the asset and consequence
AnswerD

The ISACA risk scenario structure combines a threat source, an event, an asset or resource affected, and the resulting consequence. The current entries capture only consequence, so adding the threat source, the event itself, and the affected asset completes the scenario. This makes the register entry testable and lets the practitioner assess likelihood and impact consistently across entries.

Why this answer

ISACA risk scenarios are built from a threat source, an event, the asset or resource at risk, and the consequence. The existing register entries stop at consequence, so the practitioner must add the missing threat source, event, and affected asset to make each scenario complete and analyzable. Ratings, remediation fields, and compliance references are downstream or supplementary information, not structural components of the scenario.

Exam trap

The trap here is treating a risk score or remediation detail as the missing scenario element, when the scenario is incomplete because it lacks a threat source, event, and asset description.

169
MCQeasy

Which type of control is designed to reduce the likelihood of a risk event occurring?

A.Corrective
B.Compensating
C.Preventive
D.Detective
AnswerC

Preventive controls act before an event occurs, blocking or deterring it to lower likelihood. Detective and corrective controls address discovery or recovery after the fact, so they reduce impact rather than probability, which the stem specifically asks about.

Why this answer

Preventive controls are designed to stop a risk event from occurring in the first place. For example, implementing a firewall rule to block unauthorized inbound traffic reduces the likelihood of a network intrusion. This aligns with the CRISC definition of preventive controls as proactive measures that reduce the probability of a risk scenario.

Exam trap

The trap here is that candidates often confuse preventive controls with detective controls, mistakenly thinking that monitoring or alerting (detective) reduces the likelihood of an event, when in fact it only reduces the impact or detection time after the event has occurred.

How to eliminate wrong answers

Option A is wrong because corrective controls are designed to remediate or restore operations after a risk event has occurred, such as restoring data from backup after a ransomware attack, not to reduce the likelihood of the event. Option B is wrong because compensating controls are alternative measures that provide equivalent protection when a primary control is not feasible, such as using additional logging when encryption cannot be applied, but they do not directly reduce the likelihood of the original risk event. Option D is wrong because detective controls are designed to identify and report risk events after they have happened, such as intrusion detection systems (IDS) that alert on malicious traffic, not to prevent the event from occurring.

170
Multi-Selectmedium

A company has a critical production system with a known vulnerability. Due to the system's age, the vendor no longer supports it. The company decides to implement network segmentation and purchase cyber insurance to cover potential losses. Which TWO risk response options are they applying?

Select 2 answers
A.Accept
B.Transfer
C.Avoid
D.Ignore
E.Mitigate
AnswersB, E

Insurance transfers financial risk.

Why this answer

Network segmentation reduces the attack surface by isolating the vulnerable system, which is a classic risk mitigation technique. Purchasing cyber insurance transfers the financial risk of residual losses to a third party, making 'Transfer' the correct second option. Together, these actions address the risk without removing the vulnerability.

Exam trap

The trap here is that candidates confuse 'transfer' with 'mitigate' because insurance is a financial transfer, while segmentation is a technical mitigation, and the question expects you to recognize both as distinct, simultaneous responses.

171
MCQmedium

During a vulnerability assessment, a risk practitioner identifies that a web application is vulnerable to SQL injection, which is listed in the OWASP Top 10. Which type of vulnerability identification technique MOST likely discovered this issue?

A.SAST (Static Application Security Testing)
B.CIS Benchmarks comparison
C.DAST (Dynamic Application Security Testing)
D.DISA STIG scanning
AnswerC

DAST tests a running application from the outside, sending crafted inputs and observing responses, so it detects SQL injection through runtime behaviour. It satisfies the scenario by identifying the exploitable injection flaw in the deployed web application, matching the OWASP Top 10 entry.

Why this answer

DAST (Dynamic Application Security Testing) is correct because it tests a running application from the outside by simulating attacks, such as injecting malicious SQL payloads into input fields, which directly reveals SQL injection vulnerabilities. SQL injection is a runtime flaw that manifests when untrusted input is improperly handled by the application and database, so it is most reliably discovered through dynamic testing. SAST, by contrast, analyzes source code statically and may miss or misidentify injection flaws due to complex data flows.

Thus, DAST is the technique that most likely discovered this issue during a vulnerability assessment.

Exam trap

CRISC often tests the misconception that SAST is the primary method for finding injection flaws because it examines code, but the key differentiator is that DAST tests running applications and is more likely to discover exploitable SQL injection during a vulnerability assessment.

How to eliminate wrong answers

Option A is wrong because SAST analyzes source code without executing it and, while it can flag potential injection patterns, it often produces false positives and cannot confirm exploitability like DAST; moreover, the scenario describes a vulnerability assessment of a running web application, which aligns with dynamic testing. Option B is wrong because CIS Benchmarks are configuration hardening guides for systems and software, not application-layer vulnerability discovery techniques; they do not test for SQL injection. Option D is wrong because DISA STIG scanning checks compliance with security technical implementation guides for hardening, not for runtime application vulnerabilities like SQL injection.

172
MCQmedium

An organization has implemented a continuous monitoring solution for its critical applications. The IT team reports that the monitoring tool generates a high volume of false positives. What is the BEST course of action?

A.Refine the monitoring rules and thresholds to reduce false positives.
B.Disable the monitoring for applications that generate the most false positives.
C.Increase the size of the monitoring team to handle the alerts.
D.Implement additional detective controls for all false positive alerts.
AnswerA

Tuning rules and thresholds addresses the root cause: overly broad signatures or tight baselines generate noise. This restores signal quality so genuine anomalies surface, preserving the continuous monitoring objective rather than disabling alerts or ignoring findings.

Why this answer

Refining monitoring rules and thresholds directly addresses the root cause of false positives by tuning the detection logic to better match actual risk conditions. This aligns with the CRISC principle of optimizing control efficiency rather than accepting or compensating for excessive noise. For example, adjusting anomaly detection thresholds in a SIEM like Splunk or QRadar can reduce alert volume without sacrificing coverage of genuine threats.

Exam trap

The CRISC exam often tests the misconception that increasing resources (team size) or adding more controls is the best response to monitoring inefficiency, when in fact tuning existing controls is the most effective and risk-appropriate action.

How to eliminate wrong answers

Option B is wrong because disabling monitoring for applications that generate false positives eliminates visibility into those systems, creating a blind spot that could allow real incidents to go undetected. Option C is wrong because increasing team size treats the symptom (alert volume) rather than the cause, and is unsustainable if false positives continue to grow. Option D is wrong because implementing additional detective controls for false positive alerts adds unnecessary complexity and cost without fixing the underlying rule misconfiguration, and may even increase noise further.

173
MCQeasy

Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?

A.Business interruption
B.Ransomware attacks
C.Social engineering fraud
D.Acts of war
AnswerD

Cyber insurance policies commonly exclude loss from acts of war, since such catastrophic, state-driven events are deemed uninsurable. A risk manager must recognise this exclusion because it leaves the organisation retaining that risk, requiring separate treatment within the risk register rather than assuming cover.

Why this answer

Acts of war (and sometimes terrorism, nation-state cyber operations, or hostile acts) are a common exclusion in cyber insurance policies. Insurers exclude them because the potential for catastrophic, correlated losses across many policyholders is uninsurable. A risk manager must be aware of this exclusion because it can leave the organization without coverage for state-sponsored cyberattacks.

Exam trap

CRISC often tests common cyber insurance exclusions, and candidates commonly pick 'ransomware attacks' or 'social engineering fraud' because they are frequently discussed in the news — the trap is that these are typically covered (with sublimits), while acts of war is the classic uninsurable exclusion.

How to eliminate wrong answers

Option A (Business interruption) is wrong because business interruption is typically a covered loss (often as an add-on or included coverage) in cyber insurance policies, not a common exclusion. Option B (Ransomware attacks) is wrong because ransomware is generally covered under cyber insurance (though sublimits and coinsurance may apply), and it is not a standard exclusion — in fact, it is a primary reason organizations buy cyber insurance. Option C (Social engineering fraud) is wrong because social engineering fraud is often covered, sometimes as a specific sublimit or endorsement, rather than being a common exclusion — though some policies exclude it unless added, it is not the classic exclusion that acts of war represents.

174
MCQmedium

A retail organization is migrating its point-of-sale (POS) processing to a cloud-hosted payment platform. The risk practitioner must select an encryption approach that protects cardholder data while it is actively being processed in memory by the payment application. Which of the following is the MOST appropriate control for this scenario?

A.Implement confidential computing using hardware-based trusted execution environments (TEEs) for the payment workload.
B.Encrypt the payment database tablespaces using transparent data encryption (TDE).
C.Enable TLS 1.3 for all connections between the POS terminals and the cloud payment platform.
D.Store all cardholder data in a tokenized vault and replace PANs with surrogate values in the payment application.
AnswerA

Confidential computing isolates the payment workload inside a hardware-backed trusted execution environment so that memory contents remain encrypted and inaccessible to the hypervisor, host OS, or cloud operator even while the application actively processes them. This directly satisfies the requirement to protect cardholder data in use, which transport and at-rest encryption cannot achieve.

Why this answer

Cardholder data exists in three states, and each requires a different control: in transit, at rest, and in use. The scenario specifies active in-memory processing, which only confidential computing with hardware trusted execution environments addresses, because the enclave keeps memory encrypted and isolated from privileged software. Transport encryption and at-rest encryption leave the processing window exposed.

Exam trap

The trap here is assuming that any strong encryption control, such as TLS or database encryption, automatically covers data in every state.

175
MCQhard

After implementing security controls, a risk assessment shows a residual risk of data exfiltration with a probability of 5% and potential loss of $10 million. The organization's risk appetite allows a maximum acceptable risk level of 3% probability for such impact. The cost of further mitigation is $1 million. What is the best risk response?

A.Implement additional controls to reduce probability to 2%
B.Accept the residual risk
C.Purchase cybersecurity insurance
D.Discontinue the process
AnswerA

Further mitigation brings risk within appetite.

Why this answer

The residual risk has a probability of 5% and a potential loss of $10 million, resulting in an expected loss of $500,000. The organization's risk appetite allows a maximum probability of 3% for such an impact, so the current risk exceeds the acceptable threshold. Implementing additional controls for $1 million to reduce the probability to 2% brings the risk within the risk appetite (expected loss of $200,000) and is cost-effective because the reduction in expected loss ($300,000) is less than the control cost, but the primary driver is compliance with risk appetite, not pure cost-benefit.

Exam trap

The trap here is that candidates focus on the cost-benefit analysis (mitigation cost vs. reduced expected loss) and incorrectly conclude that acceptance is cheaper, ignoring that risk appetite is a binding constraint that overrides pure financial calculations.

How to eliminate wrong answers

Option B is wrong because accepting the residual risk would violate the organization's risk appetite, which explicitly caps probability at 3% for this impact level; acceptance is only valid when risk is within tolerance. Option C is wrong because purchasing cybersecurity insurance transfers financial risk but does not reduce the probability of data exfiltration; it would still leave the probability at 5%, exceeding the risk appetite threshold, and insurance premiums often require residual risk to be within appetite. Option D is wrong because discontinuing the process is an extreme risk avoidance response that would eliminate the business function entirely, which is disproportionate when a cost-effective mitigation exists to bring risk within appetite.

176
MCQmedium

A risk manager is identifying risks for an organization that uses a hybrid cloud environment. The organization stores sensitive data on-premises and in the cloud. Which of the following is the MOST effective method for identifying risks related to data residency and compliance?

A.Conduct a penetration test of the cloud environment
B.Review data flow diagrams and legal requirements for each jurisdiction
C.Perform a configuration review of cloud security settings
D.Review the cloud provider's SOC 2 report
AnswerB

Data flow diagrams map exactly where sensitive data resides, moves and is processed across on-premises and cloud boundaries, while jurisdiction-specific legal requirements define the compliance obligations. Together they expose residency and regulatory risks that generic checklists miss.

Why this answer

Reviewing data flow diagrams alongside legal requirements for each jurisdiction is the most effective method because it directly maps where sensitive data resides, transits, and is processed across on-premises and cloud environments, enabling precise identification of residency and compliance gaps. This approach aligns with CRISC's emphasis on risk identification through understanding data lineage and regulatory obligations, rather than relying on post-deployment security tests or generic reports.

Exam trap

The trap here is that candidates confuse security testing (penetration tests, configuration reviews) with compliance risk identification, overlooking that data residency and legal requirements demand a process-oriented review of data flows and jurisdictional rules, not just technical controls.

How to eliminate wrong answers

Option A is wrong because a penetration test assesses security vulnerabilities (e.g., misconfigurations, exploit paths) but does not evaluate data residency or compliance with jurisdictional laws like GDPR or CCPA. Option C is wrong because a configuration review of cloud security settings checks for technical controls (e.g., encryption, IAM policies) but cannot reveal whether data storage locations violate specific residency requirements. Option D is wrong because a SOC 2 report provides assurance on a cloud provider's controls (e.g., security, availability) but does not detail data flow paths or legal compliance for each jurisdiction where data resides.

177
Multi-Selectmedium

Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)

Select 3 answers
A.Exclusions for acts of war or state-sponsored attacks
B.Incident response prerequisites such as mandatory use of approved vendors
C.Coverage scope for different incident types
D.Company's stock price volatility
E.Office location and building security
AnswersA, B, C

War and state-sponsored attack exclusions remove cover for precisely the severe, costly incidents many organisations most need to transfer. Reviewing these exclusions satisfies the evaluation criterion of identifying retained risk, because excluded events remain the organisation's financial responsibility.

Why this answer

Cyber insurance policies have specific coverage scopes, exclusions (e.g., war, negligence), and prerequisites (e.g., multi-factor authentication). Premium factors like security controls also affect cost.

178
MCQhard

A multinational organization uses multiple risk management systems that do not integrate with each other. The risk team manually consolidates data into a spreadsheet for reporting. This process is error-prone and time-consuming. Which of the following is the BEST long-term solution to improve risk monitoring and reporting?

A.Standardize the spreadsheet format across all departments
B.Implement a centralized governance, risk, and compliance (GRC) platform with automated data feeds
C.Train risk owners on how to better manually report risks
D.Assign dedicated staff to perform additional manual reviews of the spreadsheet
AnswerB

A centralised GRC platform with automated feeds removes the manual spreadsheet consolidation that causes errors and delay, directly addressing the fragmented, non-integrated systems named in the stem. Automated data ingestion gives continuous, consistent risk monitoring and reporting across the multinational estate, which point fixes to individual systems cannot achieve.

Why this answer

Implementing a centralized GRC platform with data feeds from all systems automates integration and reduces errors. Option A is wrong because standardizing spreadsheets still requires manual consolidation. Option C is wrong because training does not address the system integration issue.

Option D is wrong because simply adding more manual reviews increases overhead.

179
MCQmedium

A retail company is moving its customer loyalty application to a SaaS platform. The risk practitioner must ensure that the cloud provider's security controls are adequate. Which of the following is the MOST effective way to obtain assurance over the provider's controls?

A.Rely on the provider's ISO 9001 certification.
B.Conduct a penetration test of the provider's environment.
C.Review the provider's SOC 2 Type II report.
D.Request the provider's completed security questionnaire.
AnswerC

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of the provider's controls over a period of time. This gives the risk practitioner evidence that controls are not only designed appropriately but have been tested and operated effectively, which directly supports risk assessment and monitoring of the outsourced service.

Why this answer

A SOC 2 Type II report is specifically designed to provide independent assurance over a service organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy. It covers both design and operating effectiveness over a period, making it the most reliable evidence for a risk practitioner assessing a cloud provider's control environment.

Exam trap

The trap here is assuming that any certification or questionnaire response provides equivalent assurance, when only an independent audit report over a period demonstrates operating effectiveness.

180
MCQhard

A financial institution uses a quantitative risk assessment for a core banking system. The annual loss expectancy (ALE) is calculated as $500,000 with a single loss expectancy (SLE) of $2,500,000. What is the annualized rate of occurrence (ARO)?

A.5.0
B.2.0
C.0.5
D.0.2
AnswerD

An ARO of 0.2 satisfies the stem's quantitative relationship, since ALE equals SLE multiplied by ARO. Dividing $500,000 by $2,500,000 yields 0.2, meaning the loss event is expected once every five years. This directly reconciles the given single loss expectancy with the stated annual loss expectancy.

Why this answer

The annualized rate of occurrence (ARO) is derived from the formula ALE = SLE × ARO. Given ALE = $500,000 and SLE = $2,500,000, solving for ARO yields $500,000 / $2,500,000 = 0.2. This means the core banking system is expected to experience a loss event once every five years on average.

Exam trap

The trap here is that candidates often mistakenly invert the formula, dividing SLE by ALE to get 5.0, or confuse ARO with a percentage, leading to 0.5, instead of correctly applying ALE = SLE × ARO to solve for ARO.

How to eliminate wrong answers

Option A is wrong because 5.0 would result from incorrectly dividing SLE by ALE (2,500,000 / 500,000), which reverses the formula. Option B is wrong because 2.0 would come from dividing ALE by a misapplied factor or confusing ARO with a multiplier. Option C is wrong because 0.5 would arise from misplacing the decimal or assuming a 50% chance per year, which does not match the calculated ratio.

181
MCQmedium

A risk practitioner is reviewing the organization's vulnerability management process. The team currently relies on the Common Vulnerability Scoring System (CVSS) base score alone to prioritize remediation. The CISO asks for a more risk-based prioritization approach. Which of the following should the practitioner recommend as the MOST effective enhancement?

A.Incorporate the Exploit Prediction Scoring System (EPSS) score and asset criticality into the prioritization.
B.Replace CVSS base scores with the Common Weakness Enumeration (CWE) identifiers for all findings.
C.Apply a uniform 30-day remediation deadline to all high and critical CVSS findings.
D.Increase the frequency of authenticated vulnerability scans from monthly to weekly.
AnswerA

EPSS estimates the probability that a vulnerability will be exploited in the wild within 30 days, and combining it with asset criticality aligns remediation with actual business risk. CVSS base score alone reflects intrinsic severity, not likelihood of exploitation or business impact. This enhancement directly supports risk-based prioritization, which is a core CRISC objective.

Why this answer

Risk-based vulnerability prioritization requires combining likelihood of exploitation with business impact. EPSS provides an empirical, forward-looking probability of exploitation, while asset criticality reflects the business consequence if the asset is compromised. Together they allow the team to focus remediation on the findings that present the greatest actual risk, rather than treating all high CVSS findings as equivalent.

Exam trap

The trap here is assuming that a higher CVSS base score always means higher risk, when exploit likelihood and asset context often change the true priority.

182
MCQhard

When developing IT risk scenarios, connecting them to business impact is critical. Which of the following BEST describes how a risk practitioner should link a technical scenario to business impact?

A.Assign a likelihood rating and an inherent risk score
B.Quantify the impact in terms of financial loss, regulatory penalty, and operational disruption
C.Describe the technical steps of the attack in detail
D.Reference industry benchmarks for similar scenarios
AnswerB

Expressing impact as financial loss, regulatory penalty and operational disruption links the technical scenario to business consequences using the standard impact categories, satisfying the stem's requirement to connect technical risk to business impact. This translation lets leadership compare and prioritise risks using consistent, decision-ready terms.

Why this answer

Quantifying impact in terms of financial loss, regulatory penalty, and operational disruption best links a technical risk scenario to business impact because it translates technical events into measurable business consequences. This allows risk to be expressed in terms that executives and business owners can understand and prioritize. It also supports cost-benefit analysis of risk treatment options.

Exam trap

CRISC often tests the difference between risk assessment (likelihood/impact scoring) and business impact analysis; candidates may pick likelihood scoring or technical description when the question specifically asks how to link to business impact, which requires quantification in business terms.

How to eliminate wrong answers

Option A is wrong because assigning likelihood and inherent risk scores rates the risk but does not connect it to business impact; it remains a technical or abstract rating. Option C is wrong because describing technical attack steps provides threat detail but does not articulate business consequences. Option D is wrong because referencing industry benchmarks gives context but does not quantify the organization's specific business impact.

183
MCQmedium

A national retail chain is building a risk register for its new e-commerce platform. The CISO asks the risk practitioner to identify the inherent risk associated with a recently disclosed SQL injection vulnerability in a third-party payment gateway module. Which of the following BEST describes inherent risk in this scenario?

A.The risk that exists before any controls or mitigation efforts are applied to the SQL injection vulnerability in the payment gateway module.
B.The risk that the third-party payment gateway vendor will fail to patch the SQL injection vulnerability within the agreed service level agreement.
C.The risk that the organization's risk appetite statement will be exceeded due to the SQL injection vulnerability.
D.The level of risk that remains after the organization implements compensating controls such as a web application firewall and input validation.
AnswerA

Inherent risk is the raw risk exposure before controls are considered. For the SQL injection vulnerability, this means the potential impact and likelihood assuming no compensating controls exist. This baseline helps the risk practitioner prioritize and later measure the effectiveness of controls. The scenario specifically asks for inherent risk, making this the correct characterization.

Why this answer

Inherent risk is the level of risk before any controls or mitigation actions are applied. In the context of the SQL injection vulnerability, it represents the raw exposure that the organization faces if nothing is done. This baseline is essential for risk practitioners to prioritize risks and later evaluate the effectiveness of controls by comparing inherent and residual risk.

The other options describe residual risk, vendor-specific risk, or risk appetite exceedance, none of which define inherent risk.

Exam trap

The trap here is confusing inherent risk with residual risk, especially when controls are mentioned in the scenario.

184
MCQmedium

Refer to the exhibit. The SIEM alert triggered, but the security team did not respond because they were investigating another incident. What is the BEST way to prevent such monitoring gaps in the future?

A.Implement a ticketing system to track alert handling.
B.Hire additional security analysts to handle peak loads.
C.Increase the threshold to reduce false positives.
D.Configure automatic escalation to a secondary response team if the alert is not acknowledged within a set time.
AnswerD

Automatic escalation to a secondary response team when an alert goes unacknowledged within a defined window ensures coverage during concurrent incidents. This satisfies the need to close monitoring gaps caused by the primary team being occupied elsewhere.

Why this answer

It directly addresses the monitoring gap caused by analyst unavailability. By configuring automatic escalation to a secondary response team if an alert is not acknowledged within a set time, the organization ensures that no alert is left unattended even when the primary team is occupied. This is a standard operational resilience control in SIEM workflows, often implemented via playbook automation or SOAR integration.

Exam trap

The trap here is that candidates often choose 'Hire additional security analysts' (Option B) as a capacity solution, but the question specifically tests the concept of operational resilience through automated failover, not just staffing levels.

How to eliminate wrong answers

Option A is wrong because a ticketing system tracks alert handling but does not automatically reassign or escalate unacknowledged alerts; it only logs the event, leaving the gap unaddressed. Option B is wrong because hiring additional analysts increases capacity but does not guarantee coverage during peak loads or when the team is already engaged; it is a scaling solution, not a failover mechanism. Option C is wrong because increasing the threshold to reduce false positives may suppress legitimate alerts, increasing the risk of missing real incidents; it does not solve the problem of unacknowledged alerts.

185
MCQmedium

Which of the following best describes the purpose of tactical risk reporting?

A.To satisfy regulatory compliance requirements
B.To inform the board of directors about strategic risk exposure
C.To provide daily operational metrics to system administrators
D.To enable the CISO to make informed decisions about risk mitigation priorities
AnswerD

Tactical reporting translates risk data into prioritised mitigation actions for senior security leadership, supporting near-term resource allocation decisions. Strategic reporting addresses long-term risk appetite, while operational reporting handles day-to-day execution, so tactical reporting uniquely equips the CISO to sequence mitigation priorities.

Why this answer

Tactical risk reporting is designed to provide mid-level management, such as the CISO, with actionable insights to prioritize risk mitigation activities. It focuses on operational risk decisions, not strategic oversight or daily metrics, enabling informed choices about resource allocation and remediation timelines.

Exam trap

The trap here is confusing the audience and time horizon of reporting levels—candidates often mistake tactical reporting for operational metrics (Option C) because both involve technical details, but tactical reporting is decision-focused for management, not daily task execution.

How to eliminate wrong answers

Option A is wrong because tactical risk reporting is not primarily for regulatory compliance; compliance reporting is a separate function that addresses specific legal or contractual requirements. Option B is wrong because informing the board about strategic risk exposure is the purpose of strategic risk reporting, which covers high-level, long-term risk posture. Option C is wrong because providing daily operational metrics to system administrators is the role of operational or technical reporting, not tactical reporting, which targets management decisions.

186
MCQhard

A software development company uses a third-party cloud provider to host its source code repositories. The risk practitioner discovers that the provider's contract does not include a right-to-audit clause. The provider has a strong security reputation but is unwilling to add the clause. The company's risk appetite for third-party risk is low. Which action should the risk practitioner recommend FIRST?

A.Terminate the contract and migrate the source code to an in-house data center.
B.Request that the provider provide a SOC 2 Type II report as a compensating control.
C.Accept the risk because the provider has a strong security reputation.
D.Conduct a risk assessment to determine the potential impact of the missing right-to-audit clause.
AnswerD

Before deciding on a risk response, the risk practitioner must first assess the risk. The missing right-to-audit clause could limit the company's ability to verify the provider's security controls, potentially increasing risk. A formal risk assessment will quantify the impact and likelihood, enabling an informed decision that aligns with the company's low risk appetite.

Why this answer

The first step in risk response is to assess the risk. The missing right-to-audit clause creates uncertainty about the provider's security controls, which is particularly concerning given the low risk appetite. A risk assessment will evaluate the likelihood and impact, allowing the risk practitioner to recommend an appropriate response, such as negotiating alternative assurance, accepting with compensating controls, or terminating the contract.

Exam trap

The trap here is jumping to a response like termination or acceptance without first assessing the risk, or assuming that a SOC 2 report fully compensates for the lack of a right-to-audit clause.

187
MCQmedium

An IT risk report for the board of directors should primarily focus on:

A.Specific control failures with root cause analysis
B.Detailed technical vulnerability scan results
C.Operational incident counts
D.Top risks, trends, and control performance metrics
AnswerD

Boards govern rather than operate, so they need aggregated top risks, directional trends and control performance metrics to judge whether risk appetite is being met. Operational detail and raw incident logs obscure this strategic view, failing the stem's board-reporting purpose.

Why this answer

A board-level IT risk report should communicate the most significant risks, emerging trends, and the effectiveness of controls in mitigating those risks. This enables directors to make informed strategic decisions and fulfill governance responsibilities. Operational details are typically reserved for management-level reporting.

Exam trap

CRISC often tests the confusion between operational reporting for management and strategic risk reporting for the board, tempting candidates to choose detailed technical data.

How to eliminate wrong answers

Option A is wrong because specific control failures with root cause analysis are too granular for a board audience and belong in management or audit reports. Option B is wrong because detailed technical vulnerability scan results are operational and not strategic; the board needs aggregated risk exposure, not raw scan data. Option C is wrong because operational incident counts are tactical metrics that do not convey the overall risk posture or control effectiveness required for governance.

188
Multi-Selectmedium

Which TWO of the following are examples of continuous monitoring activities? (Select TWO.)

Select 2 answers
A.Continuous vulnerability scanning
B.Annual penetration testing
C.Quarterly user access reviews
D.Automated SIEM rule-based alerts for suspicious activity
E.Monthly review of audit logs
AnswersA, D

Continuous vulnerability scanning qualifies because it runs on an automated, recurring schedule rather than at a single point in time, satisfying the stem's requirement for ongoing detection. Unlike periodic assessments, it feeds findings into risk registers continuously, enabling timely remediation decisions within the organisation's risk tolerance thresholds.

Why this answer

Continuous vulnerability scanning (A) is correct because it runs on an ongoing, automated schedule to detect new weaknesses as they emerge, which is the defining characteristic of a continuous monitoring activity. Automated SIEM rule-based alerts for suspicious activity (D) is also correct because SIEM correlation rules evaluate event streams in real time and generate alerts continuously, providing ongoing detection rather than point-in-time assessment. By contrast, annual penetration testing (B) and quarterly user access reviews (C) are periodic, scheduled point-in-time activities, and monthly review of audit logs (E) is a recurring but interval-based manual review, so none of these qualify as continuous monitoring.

189
MCQhard

An insurance company is expanding into a new country and must identify IT risks arising from local data protection law, which requires customer data to remain within national borders. The risk practitioner is mapping this requirement into the enterprise risk register. Which of the following is the MOST appropriate way to characterize this risk?

A.As a technology risk owned by the infrastructure team, because data residency is enforced through server location.
B.As a compliance risk with no linkage to strategic objectives, since the requirement is external and mandatory.
C.As an enterprise risk that links the legal obligation to the market-entry objective, with ownership shared among legal, compliance, and technology stakeholders.
D.As an operational risk to be accepted until a regulator raises a concern, at which point it can be reassessed.
AnswerC

Data residency obligations cross legal, technology, and strategic boundaries, so the risk belongs in the enterprise register with clear linkage to the expansion objective and shared ownership. This framing lets leadership compare the cost of compliant local hosting and controls against the value of the new market, and ensures treatment decisions are made at the right level. It also supports consistent reporting to the board alongside other expansion risks.

Why this answer

A cross-border data residency obligation affects legal compliance, technology architecture, and the strategic decision to enter a market, so it belongs in the enterprise risk register with clear linkage to business objectives and shared ownership. This placement lets leadership weigh treatment costs against expansion value. Treating it as purely technical, isolated from strategy, or deferred until enforcement all misplace the risk and weaken governance.

Exam trap

The trap here is classifying a legal obligation as solely a technology or compliance issue and missing its connection to the strategic objective and enterprise-level ownership.

190
MCQmedium

A retail bank is building a risk register for its newly deployed mobile payment API. The CISO asks the risk practitioner to classify the risk that attackers could manipulate the API request parameters to bypass transaction limits. Under which CRISC risk identification category should this risk PRIMARILY be recorded?

A.IT security risk
B.IT project risk
C.IT operational risk
D.IT compliance risk
AnswerA

Tampering with API parameters to circumvent transaction limits is an intentional compromise of confidentiality, integrity, or authorized use, which is the definition of security risk. Recording it as a security risk links it to threat modeling, secure code review, and authorization testing, and it aligns with how CRISC expects practitioners to separate deliberate adversarial events from accidental operational failures or compliance gaps.

Why this answer

The risk described is a deliberate adversarial action that violates the integrity and authorized use of the payment API, which is the essence of IT security risk. Placing it in that category ensures it is assessed against threat actors, exploitable vulnerabilities, and security controls, and it drives the right treatment such as input validation and authorization hardening, rather than being handled as an availability, compliance, or delivery issue.

Exam trap

The trap here is assuming that any risk involving a live system or an application defect automatically belongs in IT operational risk instead of recognizing the deliberate adversarial intent that makes it a security risk.

191
MCQhard

Your organization is undergoing a merger and acquisition. The IT risk assessment team is tasked with evaluating the target company's IT environment. During the assessment, you discover that the target company uses a legacy ERP system that is no longer supported by the vendor. They have no disaster recovery plan for this system, and it contains financial data critical to the merged entity. The integration timeline is aggressive, and replacing the system would delay the merger by 18 months. The executive team is reluctant to delay. What is the BEST risk treatment option?

A.Avoid the risk by excluding the legacy system from the merger and migrating data to a new system.
B.Accept the risk because the system has been running for years without issue.
C.Mitigate by developing a disaster recovery plan and implementing compensating controls such as regular backups and manual procedures.
D.Transfer the risk to the target company's previous owners.
AnswerC

Replacing the unsupported ERP would delay the merger 18 months, which executives reject, so mitigation is the viable treatment. A disaster recovery plan plus backups and manual procedures addresses the absence of recovery capability while compensating for the vendor's withdrawn support.

Why this answer

The legacy ERP system contains critical financial data and cannot be replaced without an 18-month delay, making risk mitigation the most practical approach. Developing a disaster recovery plan and implementing compensating controls (e.g., regular backups, manual procedures) reduces the likelihood and impact of a system failure while allowing the merger to proceed on schedule. This aligns with the CRISC principle of treating risk by reducing residual risk to an acceptable level without blocking business objectives.

Exam trap

The trap here is that candidates may choose Option B (accept the risk) because the system has been stable historically, but CRISC expects you to recognize that unsupported systems with no DR plan represent an unmanaged risk that requires active mitigation, not passive acceptance.

How to eliminate wrong answers

Option A is wrong because excluding the legacy system and migrating data to a new system would effectively replace it, causing the same 18-month delay the executive team wants to avoid; this is a risk avoidance strategy that is not feasible given the aggressive timeline. Option B is wrong because accepting the risk based solely on historical uptime ignores the fact that the system is unsupported, has no disaster recovery plan, and contains critical financial data—past performance does not guarantee future reliability, especially without vendor patches or support. Option D is wrong because transferring risk to the target company's previous owners is impractical post-acquisition; contractual indemnification may exist, but it does not address the ongoing operational risk of the unsupported system within the merged entity, and such transfer is typically limited to legal liability, not technical risk.

192
MCQhard

An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:

A.Risk transfer
B.Risk acceptance
C.Risk mitigation
D.Risk avoidance
AnswerA

Liability clauses and cyber insurance shift the financial consequence of payroll errors to the vendor and insurer, while the organisation retains operational responsibility. This is risk transfer, satisfying the stem's high inherent risk mitigated through contractual and insurance mechanisms rather than avoidance or reduction.

Why this answer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or contractual liability clauses. Here, the vendor contract includes liability clauses and the organization obtains cyber insurance — both mechanisms shift financial consequences away from the organization. This is the defining characteristic of risk transfer, making it the correct answer.

Exam trap

CRISC often tests the distinction between risk transfer and risk mitigation, and candidates commonly pick 'risk mitigation' because the scenario mentions a vendor contract — the trap is that liability clauses and insurance shift financial impact (transfer), while mitigation would involve reducing the likelihood or impact of the error itself.

How to eliminate wrong answers

Option B (Risk acceptance) is wrong because acceptance means acknowledging the risk and deciding to bear it without further treatment — here, the organization is actively shifting financial impact via contract and insurance, not accepting it. Option C (Risk mitigation) is wrong because mitigation reduces the likelihood or impact of the risk through controls (e.g., validation checks, segregation of duties) — the scenario does not describe reducing payroll error likelihood, only shifting financial consequences. Option D (Risk avoidance) is wrong because avoidance means eliminating the activity or not undertaking it — the organization is proceeding with outsourcing, not avoiding the risk.

193
MCQmedium

A company is developing risk scenarios for business impact analysis. Which of the following scenario components directly links the risk event to potential financial loss?

A.Vulnerability
B.Threat actor
C.Consequence
D.Asset
AnswerC

Consequence describes the resulting impact of a risk event materialising, quantified in financial, operational or regulatory terms. It satisfies the scenario component that directly links the event to potential financial loss, unlike cause, threat source or event description.

Why this answer

In risk scenario development, the consequence component describes the outcome or impact that results from a threat exploiting a vulnerability against an asset — and it is the consequence that is translated into financial loss estimates during business impact analysis. Without a defined consequence, there is no direct linkage from the risk event to monetary impact.

Exam trap

CRISC often tests the distinction between the components of a risk scenario — candidates confuse the asset or vulnerability with the consequence, but only the consequence expresses the financial loss linkage.

How to eliminate wrong answers

Option A is wrong because a vulnerability is a weakness that could be exploited; it is an input to the scenario, not the element that expresses financial loss. Option B is wrong because the threat actor is the entity that may exploit the vulnerability; it describes who or what causes the event, not the resulting impact. Option D is wrong because the asset is the thing of value that could be affected; while asset valuation feeds into impact calculation, the asset itself is not the component that directly links the event to financial loss — the consequence is.

194
MCQmedium

A risk owner is reviewing a control that has a deficiency rate of 15%. The target deficiency rate is less than 5%. Which of the following is the MOST appropriate immediate action?

A.Investigate the root cause of the high deficiency rate
B.Increase the target deficiency rate to 15%
C.Report the deficiency to the external auditor
D.Accept the risk and document the decision
AnswerA

A 15% deficiency rate against a sub-5% target signals the control is failing materially. Root-cause investigation must precede remediation, otherwise corrective actions address symptoms rather than the underlying process, configuration or ownership failure driving the gap.

Why this answer

A deficiency rate of 15% against a target of less than 5% indicates a control failure that requires immediate remediation. Investigating the root cause is the first step in the risk response process to identify why the control is failing and to determine the appropriate corrective action, aligning with the Risk Response and Reporting domain's emphasis on addressing control deficiencies before considering acceptance or reporting.

Exam trap

The trap here is that candidates may choose 'Accept the risk and document the decision' (Option D) because they confuse risk acceptance with a standard response to control deficiencies, but CRISC emphasizes that acceptance is only appropriate after a formal risk assessment and when remediation is not feasible or cost-justified.

How to eliminate wrong answers

Option B is wrong because increasing the target deficiency rate to 15% would lower the control standard without addressing the underlying failure, effectively ignoring the risk and violating the principle of maintaining control effectiveness. Option C is wrong because reporting the deficiency to the external auditor is premature; the immediate action should be internal investigation and remediation, not external disclosure, which occurs after analysis and as part of formal reporting cycles. Option D is wrong because accepting the risk without understanding the root cause or attempting remediation bypasses the risk treatment process; acceptance should be a deliberate decision after evaluating the impact and likelihood, not the first action upon discovering a high deficiency rate.

195
Multi-Selectmedium

A company is considering risk transfer for a new IT project. Which TWO options represent valid risk transfer mechanisms? (Select TWO)

Select 2 answers
A.Accepting the risk with sign-off
B.Purchasing cyber insurance
C.Implementing access controls
D.Discontinuing the project
E.Outsourcing with liability clauses
AnswersB, E

Cyber insurance transfers the financial impact of a realised risk to the insurer in exchange for premiums, leaving the organisation to bear only deductibles and uncovered losses. This satisfies the stem's requirement for a valid risk transfer mechanism, since the monetary consequence, not the risk itself, is shifted.

Why this answer

Option B (Purchasing cyber insurance) is a valid risk transfer mechanism because the organization pays a premium to shift the financial impact of covered cyber events, such as data breaches or ransomware, to the insurer. Option E (Outsourcing with liability clauses) is also valid risk transfer because contractual liability clauses shift specified responsibilities and financial consequences for incidents to the third-party vendor. Option A (Accepting the risk with sign-off) is risk acceptance, not transfer, since the organization retains the risk.

Option C (Implementing access controls) is risk mitigation/reduction through preventive controls. Option D (Discontinuing the project) is risk avoidance, as the activity creating the risk is eliminated.

Exam trap

CRISC often tests the confusion between risk response strategies — candidates frequently misclassify mitigation (controls) or avoidance (discontinuing) as transfer, when transfer specifically requires a third party to assume the financial impact.

196
Multi-Selecthard

Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)

Select 3 answers
A.Risk trend analysis over time
B.Risk heat map showing current risk levels
C.Names of all third-party vendors with contracts
D.List of top risks and their mitigation status
E.Detailed control deficiency descriptions
AnswersA, B, D

Trend analysis over time reveals whether risk exposure is rising, falling or stable, letting senior management judge whether current mitigation spending is working. Without this longitudinal view, the report shows only a static snapshot and cannot support the forward-looking direction the board needs for risk appetite decisions.

Why this answer

Option A (Risk trend analysis over time) is essential because senior management needs to see whether the organization's risk posture is improving, worsening, or stable across reporting periods, which supports strategic decisions rather than a single point-in-time snapshot. Option B (Risk heat map showing current risk levels) is correct because a heat map visually prioritizes risks by likelihood and impact, enabling executives to quickly grasp the current risk landscape and focus attention on the highest-exposure areas. Option D (List of top risks and their mitigation status) is correct because it tells leadership which risks matter most and whether remediation efforts are on track, directly supporting accountability and resource allocation.

Option C is not essential because listing every third-party vendor with contract details is a procurement or vendor-management artifact, not a concise risk-reporting element for senior management. Option E is not essential because detailed control deficiency descriptions are operational-level detail better suited to audit or control-owner reports, whereas senior management needs aggregated, decision-oriented risk information.

Exam trap

The trap here is that candidates confuse operational detail (like vendor lists or control descriptions) with strategic reporting content, failing to recognize that senior management needs aggregated, decision-focused information rather than granular technical data.

197
MCQmedium

A university is deploying a new student information system that will store grades, financial aid records, and health center notes. The risk practitioner must determine the data classification that drives encryption, access, and retention requirements. Which factor is MOST important in setting that classification?

A.The vendor's default classification assigned in the student information system's configuration templates.
B.The volume of records the system will hold and the projected annual growth rate.
C.The cost of the encryption and access management tools required to protect the system.
D.The potential harm to students and the university if the data is disclosed, altered, or unavailable.
AnswerD

Data classification exists to match protection to impact, so the governing factor is the harm that unauthorized disclosure, modification, or loss would cause to individuals and the institution. Health notes and financial aid records carry regulatory and reputational consequences far beyond their storage cost, and that impact analysis correctly drives the encryption, access, and retention controls.

Why this answer

Classification should be driven by the impact of compromise, because that impact determines how strong encryption, access, and retention controls must be. Student health notes and financial aid records cause significant harm if exposed or altered, so harm analysis is the correct basis. Volume, tooling cost, and vendor defaults are operational or commercial factors that cannot reliably indicate sensitivity.

Exam trap

The trap here is choosing a convenient operational metric such as record volume or vendor default instead of analyzing the harm that disclosure or alteration would cause.

198
MCQhard

A company has a low risk appetite but high risk tolerance. Which of the following scenarios is consistent with this situation?

A.The company avoid controls and accepts high risk
B.The company invests heavily in cybersecurity controls but accepts some residual risk
C.The company has aggressive growth targets and accepts any IT risk
D.The company invests minimally in controls and has low residual risk
AnswerB

Risk appetite is the level of risk the organisation is willing to pursue, while tolerance is the acceptable deviation from that appetite. Heavy investment in controls reflects low appetite, and accepting residual risk shows tolerance for variation within limits.

Why this answer

A low risk appetite means the company is unwilling to accept high levels of risk, while high risk tolerance indicates it can absorb the financial or operational impact of residual risk that remains after controls are applied. Investing heavily in cybersecurity controls reduces inherent risk to a low residual level, aligning with the low appetite, and the acceptance of some residual risk is consistent with the high tolerance. This scenario reflects a balanced approach where controls are prioritized to meet appetite, and tolerance allows for manageable leftover risk.

Exam trap

The trap here is confusing risk appetite (the willingness to take risk) with risk tolerance (the capacity to withstand risk), leading candidates to incorrectly associate high tolerance with accepting high risk, when in fact high tolerance allows for acceptance of residual risk after controls are applied.

How to eliminate wrong answers

Option A is wrong because avoiding controls and accepting high risk directly contradicts a low risk appetite, which demands risk reduction, not acceptance of high risk. Option C is wrong because aggressive growth targets and accepting any IT risk ignore the low risk appetite, which would reject unmitigated high-risk initiatives. Option D is wrong because investing minimally in controls would leave high inherent risk unaddressed, resulting in residual risk that exceeds a low appetite, and low residual risk cannot be achieved without adequate controls.

199
MCQhard

An organization uses the PASTA threat modeling methodology. In which stage would the team identify threat agents and their capabilities?

A.Define objectives
B.Threat analysis
C.Vulnerability analysis
D.Decompose application
AnswerB

Threat analysis is the PASTA stage that enumerates threat agents, their capabilities, motivations and objectives, mapping them against the application's assets and attack surface. This directly satisfies the stem's requirement to identify threat agents and capabilities, distinguishing it from decomposition, attack modelling and risk/impact analysis stages.

Why this answer

PASTA's third stage involves profiling threat agents and their capabilities.

200
MCQhard

A global manufacturer's risk committee is defining the organization's risk capacity and risk appetite for IT risk. The chief risk officer asks the practitioner to clarify how these two concepts relate. Which of the following statements is MOST accurate?

A.Risk appetite applies only to financial risks, while risk capacity applies only to IT and operational risks.
B.Risk appetite is the maximum loss the organization can absorb, while risk capacity is the amount of risk management is willing to pursue for returns.
C.Risk capacity is the maximum risk the organization can bear, and risk appetite is the amount of risk it is willing to accept, with appetite normally set within capacity.
D.Risk capacity and risk appetite are interchangeable terms that both describe management's willingness to accept risk.
AnswerC

Capacity reflects the outer boundary of risk the organization can absorb before objectives or solvency are threatened, while appetite is the deliberate, lower level of risk it chooses to take. Setting appetite inside capacity leaves a buffer for unexpected events and keeps strategic risk-taking sustainable. This relationship is the foundation for deriving risk tolerances and limits that the committee can monitor.

Why this answer

Risk capacity defines the outer limit of risk the organization can absorb, while risk appetite is the lower, deliberately chosen level of risk it is willing to accept to pursue objectives. Appetite is normally set within capacity so that a buffer remains for unexpected losses. This hierarchy lets the committee translate strategy into tolerances and limits, and it prevents risk-taking from silently approaching the point where the organization's viability is threatened.

Exam trap

The trap here is swapping the definitions so that capacity sounds like willingness and appetite sounds like ability, which inverts the entire governance hierarchy.

201
MCQeasy

A risk practitioner is using a 5×5 heat map to assess IT risks. Which of the following is the primary advantage of this qualitative approach?

A.Produces financially meaningful loss estimates
B.Requires less data and time to implement
C.Provides objective and comparable risk scores across organizations
D.Eliminates subjectivity in risk ratings
AnswerB

A 5×5 heat map plots likelihood against impact using ordinal ratings, so it needs no quantitative loss data or statistical modelling. This satisfies the scenario's need for a fast, low-data qualitative assessment, though it sacrifices precision.

Why this answer

A 5×5 heat map is a qualitative risk assessment tool that uses ordinal scales (e.g., low, medium, high) for likelihood and impact. Its primary advantage is that it requires less data and time to implement compared to quantitative methods, which demand detailed financial data and complex calculations. This makes it practical for rapid, high-level IT risk prioritization when precise data is unavailable.

Exam trap

The trap here is that candidates often confuse 'qualitative' with 'objective' or 'comparable,' but qualitative methods are inherently subjective and context-dependent, unlike quantitative methods that produce numeric, comparable outputs.

How to eliminate wrong answers

Option A is wrong because qualitative heat maps do not produce financially meaningful loss estimates; they use subjective ordinal scales (e.g., 'high impact') rather than monetary values, which is a key limitation. Option C is wrong because qualitative scores are subjective and depend on the assessor's judgment, making them not objectively comparable across different organizations or even different teams within the same organization. Option D is wrong because the approach does not eliminate subjectivity; in fact, it relies on expert judgment to assign ratings, which introduces inherent bias and variability.

202
MCQeasy

A risk manager notices that a key risk indicator (KRI) for system downtime has exceeded the threshold for two consecutive months. What is the MOST appropriate immediate action?

A.Revise the KRI threshold to a higher value.
B.Archive the current KRI and define a new one.
C.Update the risk register with the new KRI value.
D.Escalate to the risk owner for investigation.
AnswerD

Escalating to the risk owner triggers investigation into why downtime breached the KRI threshold twice, enabling root-cause analysis and corrective action. This satisfies the immediate-action requirement, since the owner holds authority to assess and respond to the indicator breach.

Why this answer

When a KRI exceeds its threshold for two consecutive months, the immediate priority is to investigate the root cause and assess whether the risk is materializing. Escalating to the risk owner ensures that the appropriate subject matter expert analyzes the situation, determines if controls are failing, and decides on corrective actions. Revising the threshold or replacing the KRI without investigation would bypass the monitoring and response process, potentially masking a real risk event.

Exam trap

The trap here is that candidates assume a breached KRI automatically means the threshold is wrong, leading them to choose threshold revision (Option A) instead of recognizing that the immediate action must be investigation to determine if the risk is materializing.

How to eliminate wrong answers

Option A is wrong because revising the KRI threshold to a higher value without investigation would arbitrarily reduce sensitivity and could hide a genuine increase in risk exposure, violating the principle that KRIs should be objective and aligned with risk appetite. Option B is wrong because archiving the current KRI and defining a new one without understanding why the threshold was breached discards valuable monitoring data and fails to address the underlying risk condition. Option C is wrong because updating the risk register with the new KRI value is a documentation step that should follow investigation and remediation, not be the immediate action when a threshold breach indicates a potential risk event.

203
MCQeasy

A company implements a new automated control to monitor user access rights. The control sends a daily report of any users with excessive privileges. What is the PRIMARY benefit of this control?

A.Enables timely remediation of access violations
B.Reduces the number of user access reviews
C.Eliminates the need for manual checks
D.Provides real-time alerts for critical changes
AnswerA

Daily reporting of users holding excessive privileges lets the team identify and revoke inappropriate access promptly, shrinking the exposure window. This satisfies the primary benefit sought: timely remediation of access violations before they can be exploited.

Why this answer

The primary benefit of an automated control that sends a daily report of users with excessive privileges is that it enables timely remediation of access violations. By providing a regular, scheduled summary of privilege anomalies, the control allows the IT security team to investigate and revoke unauthorized access within a defined timeframe (e.g., 24 hours), reducing the window of exposure. This aligns with the principle of continuous monitoring and rapid response, which is critical for minimizing risk from privilege creep or misconfigured roles.

Exam trap

The trap here is that candidates confuse 'automated reporting' with 'real-time alerting' or assume that automation completely replaces manual processes, but the question specifically describes a daily report, which is a detective control focused on timely (not immediate) remediation, not a preventive or real-time control.

How to eliminate wrong answers

Option B is wrong because the control does not reduce the number of user access reviews; it automates the detection of excessive privileges, but periodic manual reviews (e.g., quarterly recertifications) are still required by compliance frameworks like SOX or PCI DSS to validate that access is appropriate. Option C is wrong because the control does not eliminate the need for manual checks; it only automates the reporting of excessive privileges, but manual verification of the report's accuracy, investigation of false positives, and remediation actions are still necessary. Option D is wrong because the control sends a daily report, not real-time alerts; real-time alerts would require a different mechanism (e.g., SIEM correlation rules or syslog triggers) that immediately notify on privilege changes, whereas this control is batch-oriented and designed for periodic review.

204
MCQeasy

Which of the following is the BEST indicator that an organization's IT risk assessment process is effective?

A.The risk register contains a large number of risks
B.Risk appetite statements are clearly defined
C.Risk assessments are performed annually
D.Risk treatment plans are implemented within agreed timelines
AnswerD

An effective risk assessment produces treatment decisions that are actually executed; measuring whether risk treatment plans are implemented within agreed timelines demonstrates that assessment outputs drive real remediation, rather than remaining documentation. This evidences the process's operational effectiveness.

Why this answer

The effectiveness of an IT risk assessment process is ultimately measured by whether identified risks are actually treated within agreed timelines. Option D directly demonstrates that the organization moves from risk identification to remediation, closing the risk management loop. Without timely implementation of treatment plans, even the most thorough risk assessments provide no reduction in actual risk exposure.

Exam trap

The trap here is that candidates confuse inputs or prerequisites (like risk appetite or scheduled assessments) with the output-based evidence of effectiveness, which is the actual closure of risk treatment actions within agreed timelines.

How to eliminate wrong answers

Option A is wrong because a large number of risks in the register does not indicate effectiveness; it may indicate poor risk aggregation, excessive risk tolerance, or failure to treat risks. Option B is wrong because clearly defined risk appetite statements are a prerequisite for effective risk assessment, not a measure of the assessment process itself. Option C is wrong because performing risk assessments annually only indicates compliance with a schedule, not that the assessments are accurate, actionable, or lead to risk reduction.

205
MCQhard

A multinational corporation is implementing a risk treatment plan for a critical vendor that has poor security controls. The risk practitioner has recommended contract renegotiation to include security requirements, but the vendor refuses. The business unit insists on continuing the relationship due to cost savings. The risk practitioner's next step should be to:

A.Document the risk in the risk register and continue monitoring without escalation.
B.Escalate the issue to the risk committee for a decision on risk acceptance.
C.Implement compensating controls internally to reduce the vendor risk.
D.Terminate the vendor relationship immediately without further discussion.
AnswerB

When a risk exceeds appetite and the business unit is unwilling to mitigate, the risk practitioner must escalate to the risk committee or appropriate governance body for a formal risk acceptance decision. This ensures that the decision is made at the right level and documented. The risk practitioner does not have authority to accept risk on behalf of the organization.

Why this answer

The risk practitioner must escalate to the risk committee when the business unit refuses to mitigate a risk that exceeds appetite. The committee has the authority to accept the risk on behalf of the organization. Simply documenting or implementing controls without addressing the governance gap would leave the organization exposed without proper oversight.

Exam trap

The trap here is assuming that documenting the risk or applying compensating controls is sufficient, bypassing the need for formal escalation and risk acceptance by the appropriate authority.

206
Multi-Selectmedium

A healthcare organization is assessing risks to its electronic health record (EHR) system. The risk team is evaluating the likelihood of a threat event. Which TWO factors are MOST relevant when estimating the likelihood of a threat exploiting a vulnerability? (Choose two.)

Select 2 answers
A.The number of users with access to the EHR system
B.The skill level and motivation of the threat actor
C.The ease of discovery and exploitability of the vulnerability
D.The regulatory fines associated with a data breach
E.The cost of implementing additional security controls
AnswersB, C

The skill level and motivation of a threat actor directly influence the probability that a vulnerability will be exploited. A highly skilled and motivated attacker is more likely to identify and successfully exploit weaknesses. This factor is a core component of threat likelihood estimation in risk assessments, as it reflects the capability and intent of potential adversaries.

Why this answer

Likelihood estimation in risk assessment focuses on factors that influence the probability of a threat exploiting a vulnerability. The skill and motivation of the threat actor and the ease of discovery and exploitability of the vulnerability are direct determinants of that probability. Regulatory fines, user count, and control costs are related to impact or treatment, not likelihood.

Exam trap

The trap here is selecting impact-related factors such as regulatory fines or control costs when asked about likelihood, as these influence the severity of consequences rather than the probability of occurrence.

207
MCQhard

An organization's risk committee reviews a risk heat map showing that a key IT risk has moved from the "high" to "medium" category. However, the associated control's effectiveness has decreased from 95% to 85%. What is the most likely explanation?

A.The control testing frequency was increased.
B.The inherent risk has decreased due to external factors.
C.The risk assessment methodology was changed.
D.The control owner has implemented additional compensating controls.
AnswerB

A heat map plots residual risk, which combines inherent risk and control effectiveness. A fall in inherent risk from external factors can outweigh the control's decline from 95% to 85%, lowering residual risk from high to medium.

Why this answer

The risk heat map shows a reduction in residual risk from high to medium, yet the control effectiveness dropped from 95% to 85%. This apparent contradiction is best explained by a decrease in inherent risk—the risk before controls are applied. If inherent risk falls (e.g., due to external factors like new regulations or reduced threat activity), the residual risk can decrease even if the control becomes less effective, because the starting risk level is lower.

Exam trap

The trap here is that candidates assume a decrease in control effectiveness must always increase residual risk, ignoring that a simultaneous decrease in inherent risk can more than compensate, leading to a net reduction in residual risk.

How to eliminate wrong answers

Option A is wrong because increasing control testing frequency typically improves control effectiveness or detects failures earlier, not decreases it; it would not cause effectiveness to drop from 95% to 85%. Option C is wrong because changing the risk assessment methodology could alter how risk is categorized, but the question states the control's effectiveness has measurably decreased, which is a factual change in control performance, not a methodological reclassification. Option D is wrong because implementing additional compensating controls would generally increase overall control effectiveness or at least maintain it, not reduce it from 95% to 85%.

208
Multi-Selecthard

A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?

Select 3 answers
A.The impact of the risk on operational productivity
B.The likelihood of the threat event occurring
C.The cost of the insurance premium relative to the expected loss
D.The residual risk after insurance is applied
E.The extent of coverage and exclusions in the policy
AnswersC, D, E

Comparing premium against expected loss establishes whether transferring the risk is economically rational. This satisfies the stem's evaluation requirement by testing cost-effectiveness: if premiums approach or exceed probable losses, retention or mitigation may deliver better value than insurance.

Why this answer

Option C is correct because the premium is the direct cost of transferring the risk, and it must be weighed against the expected loss (likelihood × impact) to determine whether the transfer is economically worthwhile. Option D is correct because insurance rarely eliminates a risk entirely; the high deductible and any uncovered portions leave a residual risk that the organization still owns and must evaluate. Option E is correct because the policy's coverage limits and exclusions define exactly which attack types and loss amounts are actually transferred, directly determining the transfer's effectiveness.

Option A is not correct here because operational productivity impact is a factor in assessing the risk itself, not in evaluating whether the insurance transfer works. Option B is likewise not correct because the likelihood of the threat event is an input to the original risk assessment, not a measure of the transfer's effectiveness.

Exam trap

CRISC often tests the misconception that buying insurance equals eliminating risk — candidates must recognize that deductibles, exclusions, and premium economics determine the actual effectiveness of the transfer, not the mere existence of a policy.

209
MCQmedium

An organization's risk register contains a risk with a very high impact but very low likelihood. The risk response strategy should be:

A.Mitigate
B.Avoid
C.Transfer
D.Accept
AnswerD

Very low likelihood combined with very high impact does not justify the cost of avoidance, transfer or mitigation. Acceptance is appropriate because the expected loss is small, though the risk should still be monitored and a contingency plan retained.

Why this answer

When a risk has very high impact but very low likelihood, the most cost-effective response is often acceptance, because the probability of occurrence is so low that the cost of mitigation, avoidance, or transfer would exceed the expected benefit. Accepting the risk means the organization formally acknowledges it and monitors it, but does not allocate resources to reduce or transfer it. This aligns with the principle of risk appetite and cost-benefit analysis in IT risk management.

Exam trap

The trap here is that candidates mistakenly choose 'Mitigate' or 'Transfer' for any high-impact risk, failing to weigh the low likelihood against the cost of the response, which is a core concept in risk treatment decisions.

How to eliminate wrong answers

Option A is wrong because mitigation involves reducing the likelihood or impact through controls, which would incur ongoing costs that are not justified for a risk with very low likelihood. Option B is wrong because avoidance means eliminating the risk entirely by discontinuing the activity, which is an extreme measure that would likely disrupt business operations unnecessarily for a low-probability event. Option C is wrong because transfer (e.g., insurance or outsourcing) typically involves premium payments or contractual costs that are not warranted when the likelihood of the risk materializing is negligible.

210
MCQeasy

An organization is implementing a new identity and access management (IAM) system. The risk manager is tasked with identifying risks associated with the migration from legacy authentication to single sign-on (SSO). Which of the following is the GREATEST risk during this migration?

A.Users may reuse strong passwords across multiple systems.
B.Users may experience increased convenience, leading to reduced security awareness.
C.Legacy authentication accounts may remain active, creating orphan accounts.
D.Help desk call volumes may increase due to SSO authentication failures.
AnswerC

Migrating to SSO leaves legacy authentication accounts active if deprovisioning is incomplete, creating orphan accounts that bypass SSO controls. These unmanaged credentials are the greatest risk because they evade the new centralised authentication and oversight.

Why this answer

Orphan accounts are the greatest risk because legacy authentication accounts that remain active after SSO migration create unmonitored, unmanaged access paths that attackers can exploit to bypass the new centralized controls. These accounts often retain old credentials, lack MFA enforcement, and are not covered by SSO's centralized logging and deprovisioning, making them a persistent and high-impact exposure.

Exam trap

CRISC often tests the distinction between operational/availability concerns (help desk volume, convenience) and genuine security risks (orphan accounts, unmanaged access) — candidates are tempted by plausible-sounding but lower-impact operational answers.

How to eliminate wrong answers

Option A is wrong because password reuse across systems is a general hygiene issue, not a migration-specific risk, and SSO actually reduces the number of credentials users must manage. Option B is wrong because increased convenience reducing security awareness is a cultural/behavioral concern, not a direct technical risk introduced by the migration, and it is speculative rather than a concrete exposure. Option D is wrong because increased help desk call volume is an operational cost/availability issue, not a security risk, and it is temporary and low impact compared to orphaned privileged access.

211
MCQmedium

An organization identifies a risk that is within its risk appetite. The risk owner decides to formally document the risk and accept it without implementing additional controls. Which of the following is required for this risk acceptance?

A.Avoidance of the business process
B.Transfer of risk to an insurance provider
C.Formal sign-off by the risk owner
D.Implementation of compensating controls
AnswerC

Risk acceptance requires the risk owner to formally sign off, documenting accountability for the decision to tolerate the risk without added controls. This satisfies the requirement that acceptance be authorised at the appropriate level, since the risk falls within the stated risk appetite.

Why this answer

Acceptance requires formal documentation and sign-off by the risk owner, acknowledging the risk within appetite.

212
Multi-Selecthard

Which THREE of the following are typical components of a risk scenario?

Select 3 answers
A.Impact
B.Threat source
C.Probability
D.Vulnerability
E.Control
AnswersA, B, D

Impact quantifies the consequence if the risk event occurs, expressed in financial, operational or regulatory terms. It is a core component of a risk scenario, alongside the threat source and the event itself, enabling consistent comparison and prioritisation.

Why this answer

A risk scenario typically combines a threat source, a vulnerability, and an impact, so options B, D, and A are correct. B (Threat source) is right because a risk scenario must identify who or what could cause harm, such as an attacker, malware, or environmental event. D (Vulnerability) is right because the scenario must describe the weakness or exposure that the threat source could exploit, such as an unpatched service or misconfiguration.

A (Impact) is right because the scenario must state the potential consequence or harm to the asset, such as data loss, downtime, or financial damage. C (Probability) is not a core component of the scenario itself; it is an assessment or estimate applied to the scenario, and E (Control) is a mitigating measure, not a defining element of the risk scenario.

Exam trap

The trap here is that candidates confuse the components of a risk scenario (threat source, vulnerability, impact) with the elements of risk analysis (probability, control effectiveness), leading them to incorrectly select Probability or Control as scenario components.

213
Multi-Selectmedium

An organization is assessing control effectiveness for a key process. Which TWO aspects should be evaluated to determine if a control is effective?

Select 2 answers
A.Operating effectiveness
B.Compliance with industry standards
C.Number of control owners
D.Design adequacy
E.Cost of implementation
AnswersA, D

Operating effectiveness verifies the control performs consistently as designed over the review period, through testing evidence such as samples, logs or observations. Combined with design adequacy, it establishes whether the control genuinely mitigates the risk within the key process.

Why this answer

Operating effectiveness (A) is correct because a control must actually function as intended over time—evidenced by testing that it is applied consistently, by the right people, at the right frequency—to confirm it mitigates the risk in practice. Design adequacy (D) is correct because a control must first be properly designed to address the identified risk at the right point in the process; a well-designed control that operates as intended is the basis for concluding effectiveness. Together, design adequacy and operating effectiveness are the two standard dimensions used when assessing control effectiveness (as in ISACA/COBIT and audit frameworks).

Compliance with industry standards (B) is not the criterion for effectiveness—a control can be effective even if it exceeds or differs from a standard, and standards compliance is a separate conformance question. The number of control owners (C) is irrelevant to effectiveness; ownership count says nothing about whether the control mitigates risk. Cost of implementation (E) is a cost-benefit consideration, not a measure of whether the control achieves its objective.

Exam trap

The trap is confusing control effectiveness with control compliance or efficiency; candidates may select 'compliance with industry standards' because it sounds important, but effectiveness is about design and operation, not external benchmarks.

214
MCQmedium

A risk practitioner at a financial services firm is updating the risk register. For a risk involving unauthorized access to the customer database, the risk owner has decided to purchase a cyber liability insurance policy that covers breach-related costs. Which risk response option has the risk owner selected?

A.Risk acceptance
B.Risk mitigation
C.Risk transfer
D.Risk avoidance
AnswerC

Purchasing insurance shifts the financial impact of a risk to a third party. This is a classic example of risk transfer, where the organization pays a premium to transfer the potential financial loss. The risk itself (unauthorized access) is not eliminated, but the financial consequences are shared or shifted to the insurer, which is a valid risk response under CRISC.

Why this answer

The risk owner chose to purchase insurance, which is a financial arrangement that shifts the potential loss to an insurer. This is a textbook example of risk transfer. The other options do not match because the organization is not eliminating the activity (avoidance), not implementing controls to reduce likelihood or impact (mitigation), and not simply bearing the risk without action (acceptance).

Exam trap

The trap here is confusing risk transfer with risk mitigation because both involve taking action, but transfer specifically shifts financial impact to a third party while mitigation reduces the risk itself.

215
MCQhard

A software development company is assessing the risk of a data breach in its cloud-based source code repository. The risk assessment team has identified that the repository contains proprietary algorithms and customer data. The team is considering implementing a control that would encrypt the data at rest. Which of the following BEST describes the impact of this control on the risk?

A.It eliminates the risk of a data breach entirely.
B.It transfers the risk to the cloud provider.
C.It reduces the likelihood of a data breach by making it harder for attackers to access the data.
D.It reduces the impact of a data breach by rendering the data unreadable to unauthorized parties.
AnswerD

Encryption at rest ensures that data stored in the repository is encrypted, so if an attacker gains access, they cannot read the data without the decryption key. This directly reduces the impact of a breach because the confidentiality of the data is preserved. It does not prevent the breach itself, but it mitigates the consequences, such as intellectual property theft or regulatory penalties. This is a classic impact-reducing control.

Why this answer

Encryption at rest is a control that reduces the impact of a data breach by making the data unreadable without the decryption key. It does not reduce the likelihood of an attacker gaining access, nor does it transfer or eliminate the risk. It is an impact-mitigating control that protects confidentiality even if other defenses fail.

This aligns with the principle of defense in depth.

Exam trap

The trap here is assuming that encryption prevents breaches (reduces likelihood) or eliminates risk, when it primarily reduces impact by protecting data confidentiality.

216
Multi-Selecthard

A risk practitioner is identifying risks associated with the decommissioning of a legacy data center. The organization plans to migrate all remaining applications to a cloud environment. Which TWO of the following are the MOST significant risks that should be included in the risk register for this project? (Choose two.)

Select 2 answers
A.Incomplete destruction of sensitive data on decommissioned storage media, leading to unauthorized disclosure.
B.Failure to update the IT service continuity plan to reflect the new cloud architecture.
C.Inability to meet new regulatory requirements for data residency in the cloud environment.
D.Increased cloud subscription costs due to unexpected usage spikes after migration.
E.Loss of institutional knowledge about legacy application dependencies as experienced staff leave or retire.
AnswersA, E

When decommissioning a data center, ensuring that all sensitive data is securely wiped or destroyed from storage media is critical. If not properly handled, residual data could be recovered by unauthorized parties, leading to a data breach. This is a well-known risk in decommissioning projects and must be included in the risk register. It addresses confidentiality and compliance requirements.

Why this answer

The decommissioning of a legacy data center involves unique risks. Loss of institutional knowledge can lead to migration errors and outages, while incomplete data destruction can cause data breaches. These two risks are directly tied to the decommissioning process and should be prioritized in the risk register.

Regulatory data residency, cloud cost spikes, and continuity plan updates are important but are either related to the cloud migration itself or are control activities, not the primary risks of decommissioning.

Exam trap

The trap here is selecting cloud-related risks like data residency or cost, which are not specific to the decommissioning project.

217
MCQhard

A hospital is implementing a new electronic health record (EHR) system. The risk practitioner is concerned about the risk of unauthorized access to patient data by internal staff. Which of the following controls is MOST effective in mitigating this risk?

A.Logging and monitoring of all access to patient records.
B.Role-based access control (RBAC) with least privilege.
C.Encryption of patient data at rest.
D.Annual security awareness training for all staff.
AnswerB

RBAC with least privilege ensures that staff members are granted only the access necessary to perform their job functions. This limits the potential for unauthorized access and reduces the attack surface. It is a preventive control that directly addresses the risk of internal staff accessing patient data they do not need, and it is a fundamental requirement of many healthcare regulations.

Why this answer

RBAC with least privilege is a preventive control that restricts access based on job roles, ensuring staff can only access the patient data necessary for their duties. This directly mitigates the risk of unauthorized internal access. While training, encryption, and monitoring are valuable, they do not prevent an authorized user from accessing data they should not see.

Exam trap

The trap here is confusing detective controls like logging with preventive controls, or assuming encryption at rest protects against all unauthorized access when it only protects data at the storage layer.

218
MCQeasy

A healthcare provider has determined that a new telehealth platform introduces risks that exceed its defined risk tolerance. Senior management decides to purchase cyber insurance to cover potential breach costs rather than modify the platform. Which risk response is management applying?

A.Risk transfer
B.Risk avoidance
C.Risk acceptance
D.Risk mitigation
AnswerA

Transfer shifts the financial consequences of a risk to a third party, and insurance is the classic example. By purchasing coverage, management retains the operational risk but moves the monetary impact of a breach to the insurer. This matches the decision to keep the platform while offloading financial exposure.

Why this answer

Insurance shifts the financial burden of a potential breach to the insurer, which is the defining characteristic of risk transfer. The telehealth platform continues to operate, so the risk is not avoided, and no technical control was added, so it is not mitigated. Because management acted rather than simply tolerating the exposure, acceptance does not apply.

Exam trap

The trap here is confusing risk transfer with risk acceptance because the underlying platform risk remains in place even though insurance was purchased.

219
MCQmedium

Which of the following is a leading Key Risk Indicator (KRI) for the risk of a data breach?

A.Average time to detect a breach
B.Number of data breaches in the past quarter
C.Percentage of systems with unpatched critical vulnerabilities
D.Number of security incidents closed
AnswerC

Unpatched critical vulnerabilities represent exposure that attackers can exploit, so the percentage measures conditions preceding a breach rather than breach incidents already suffered. That forward-looking quality makes it a leading indicator, unlike metrics such as confirmed data loss volumes.

Why this answer

A leading KRI predicts future risk events. The percentage of systems with unpatched critical vulnerabilities directly indicates an increasing attack surface and likelihood of exploitation, making it a leading indicator for a data breach. In contrast, lagging indicators like detection time or breach count measure past incidents.

Exam trap

The trap here is that candidates confuse lagging indicators (like breach count or detection time) with leading indicators, failing to recognize that a leading KRI must predict future risk, not measure past events.

How to eliminate wrong answers

Option A is wrong because average time to detect a breach (Mean Time to Detect, MTTD) is a lagging indicator that measures the effectiveness of detection controls after a breach has occurred, not a predictor of future breaches. Option B is wrong because the number of data breaches in the past quarter is a lagging indicator that reports historical incidents, providing no forward-looking insight into the likelihood of a future breach. Option D is wrong because the number of security incidents closed is a lagging operational metric reflecting past remediation activity, not a leading indicator of breach risk.

220
MCQhard

A risk manager is evaluating the security of a new API gateway that will expose internal microservices to external partners. The gateway will handle authentication, rate limiting, and request routing. Which risk is MOST critical to address before go-live?

A.Weak authentication and authorization mechanisms that could allow partners to access unauthorized microservices.
B.Insufficient logging of API requests, which could hinder forensic investigations.
C.Inadequate rate limiting that could allow denial-of-service attacks.
D.Lack of TLS encryption for internal traffic between the gateway and microservices.
AnswerA

The API gateway is the entry point to internal microservices. If authentication or authorization is weak, a partner or attacker could bypass controls and reach services they should not access, leading to data exposure or system compromise. This is a preventive control gap with direct impact on confidentiality and integrity, making it the most critical risk to address before exposing the gateway externally.

Why this answer

The API gateway is the security boundary for external partners. Weak authentication and authorization could allow unauthorized access to internal microservices, directly threatening data confidentiality and integrity. While logging, rate limiting, and internal TLS are important, they are secondary to ensuring that only authorized entities can reach the appropriate services.

Addressing authentication and authorization first prevents the most severe impact.

Exam trap

The trap here is prioritizing availability or detective controls, such as rate limiting or logging, over the preventive control that stops unauthorized access to microservices.

221
MCQhard

A risk manager is evaluating the organization's vulnerability management program. The organization scans its external-facing systems weekly but has no process for prioritizing vulnerabilities based on business impact. Which of the following should the risk manager recommend as the MOST effective improvement?

A.Implement a risk-based vulnerability prioritization process that considers asset criticality, threat intelligence, and exploitability.
B.Require all vulnerabilities to be remediated within 30 days regardless of severity to enforce a strict SLA.
C.Outsource vulnerability scanning to a third-party provider to gain access to more comprehensive threat data.
D.Increase the frequency of external scans to daily to catch vulnerabilities faster.
AnswerA

A risk-based prioritization process ensures that remediation efforts focus on vulnerabilities that pose the greatest risk to the business. By factoring in asset criticality, threat intelligence, and exploitability, the organization can allocate resources efficiently and reduce the most significant exposures first. This directly addresses the missing prioritization component and aligns vulnerability management with business risk.

Why this answer

The program lacks a risk-based approach to prioritization. The most effective improvement is to implement a process that ranks vulnerabilities by the risk they pose, considering asset criticality, threat intelligence, and exploitability. This ensures that limited resources are directed to the most significant risks, aligning vulnerability management with business objectives.

Exam trap

The trap here is equating more frequent scanning or stricter deadlines with better risk management, when the real gap is the absence of risk-based prioritization.

222
MCQhard

A large financial services firm recently deployed a new security information and event management (SIEM) system to monitor thousands of servers, network devices, and applications. The system is generating over 1,000 alerts per hour, of which 80% are false positives. The security operations center (SOC) team is overwhelmed and has started ignoring all but the most critical alerts. As a result, a real attack recently went undetected for 48 hours. The risk manager is asked to recommend improvements. The SOC team has 12 analysts working in shifts. The SIEM is properly configured but the correlation rules are broad and noisy. The firm cannot add more staff due to budget freeze. What should the risk manager prioritize?

A.Disable all low-priority alerts to reduce volume immediately.
B.Implement a machine learning algorithm to automatically classify alerts.
C.Tune the alerting rules and adopt risk-based prioritization to filter out known false positives.
D.Request budget to hire five additional SOC analysts.
AnswerC

Tuning correlation rules removes the broad, noisy detections generating 80% false positives, while risk-based prioritisation focuses the 12 analysts on genuine threats. This restores detection capability without additional headcount, satisfying the budget freeze constraint that rules out hiring more staff.

Why this answer

The core issue is that broad correlation rules generate excessive false positives, overwhelming the SOC and causing alert fatigue. Tuning the alerting rules and adopting risk-based prioritization directly addresses the root cause by reducing noise and focusing analyst attention on genuine threats. This is a sustainable, cost-effective improvement that leverages existing staff and tools.

Exam trap

CRISC often tests whether candidates prioritize root-cause remediation (tuning rules) over quick fixes (disabling alerts) or infeasible solutions (hiring staff), so the trap is choosing an option that temporarily reduces volume but increases risk.

How to eliminate wrong answers

Option A is wrong because disabling all low-priority alerts could suppress genuine threats and does not improve detection quality. Option B is wrong because implementing machine learning is a complex, time-consuming project that may not be feasible under a budget freeze and does not address the immediate need for rule tuning. Option D is wrong because the firm cannot add staff due to a budget freeze, making this option infeasible.

223
MCQhard

During a risk assessment, an organization identifies that its remote workforce uses personal devices for work. The risk manager is concerned about data leakage. The organization has a risk appetite that is 'moderate' and wants to treat the risk. Which of the following is the MOST effective risk treatment option?

A.Implement a VPN for remote access
B.Require full disk encryption on all personal devices
C.Implement a Mobile Device Management (MDM) policy with containerization
D.Ban the use of personal devices for work
AnswerC

MDM with containerisation separates corporate data into an encrypted work container, so personal apps cannot access or exfiltrate it, while still permitting BYOD. This treats the leakage risk proportionately, matching the organisation's moderate risk appetite without banning personal devices outright.

Why this answer

The most effective because MDM with containerization creates a separate, encrypted work profile on the personal device, isolating corporate data from personal apps and data. This directly addresses data leakage by enforcing security policies (e.g., remote wipe of the work container only) without requiring full control over the entire device, aligning with a 'moderate' risk appetite that seeks a balance between security and usability.

Exam trap

The trap here is that candidates often confuse 'encryption' (Option B) with 'data leakage prevention'—full disk encryption protects data at rest but does not control data flow between apps or enable selective wipe, making it less effective than containerization for a moderate risk appetite where usability and privacy are key considerations.

How to eliminate wrong answers

Option A is wrong because a VPN only encrypts data in transit between the device and the corporate network; it does not protect data at rest on the device, so if the device is lost or compromised, stored corporate data remains vulnerable to leakage. Option B is wrong because requiring full disk encryption on all personal devices is overly invasive for a moderate risk appetite—it encrypts the entire device, including personal data, and does not provide granular control over corporate data (e.g., selective wipe), potentially violating user privacy and causing resistance. Option D is wrong because banning personal devices outright is a risk avoidance strategy, not a treatment; it may reduce productivity and employee satisfaction, and it fails to address the organization's need to support a remote workforce while managing risk at an acceptable level.

224
MCQmedium

A healthcare provider has identified a risk that a critical medical imaging system runs on an unsupported operating system. The risk owner determines that the residual risk exceeds the organization's risk appetite, but upgrading the system would cost $2 million and disrupt patient care for several weeks. Which of the following is the MOST appropriate next step?

A.Transfer the risk by purchasing cyber insurance and take no other action.
B.Accept the risk because patient care disruption outweighs the security risk.
C.Escalate the risk to the appropriate governance body with options and recommendations for a risk response decision.
D.Implement a compensating control and close the risk without further reporting.
AnswerC

When residual risk exceeds the risk appetite, the risk owner must escalate it to the governance body authorized to make risk acceptance or funding decisions. Presenting options, such as phased upgrade, compensating controls, or formal acceptance with mitigation, enables informed decision-making. This aligns with CRISC principles of escalation and governance for risks beyond tolerance.

Why this answer

When residual risk exceeds the organization's risk appetite, the risk owner must escalate to the governance body empowered to make risk response decisions. That body can weigh the $2 million upgrade cost and patient care disruption against the security exposure, and choose among options such as phased remediation, compensating controls, or formal risk acceptance. Unilateral acceptance, silent closure, or insurance-only responses bypass required governance.

Exam trap

The trap here is treating a compelling business disruption argument as justification for unilateral risk acceptance, when any risk above appetite must be escalated to the authorized governance body for a formal decision.

225
Multi-Selecteasy

Which TWO of the following are key elements that should be included in an IT risk assessment report?

Select 2 answers
A.A list of identified risks and their ratings
B.Recommendations for risk treatment
C.Copies of vendor contracts
D.Network topology diagrams
E.Detailed financial budgets of the IT department
AnswersA, B

Identified risks with their ratings form the core register that lets management compare exposures and prioritise responses. Without this ranked inventory, the report cannot satisfy its purpose of communicating which risks threaten objectives and where attention should be directed.

Why this answer

Option A is correct because a risk assessment report must document the identified risks along with their assigned ratings (e.g., likelihood and impact scores, or qualitative labels such as high/medium/low), which form the core output of the assessment and enable prioritization. Option B is correct because the report should include recommendations for risk treatment — such as mitigation, transfer, acceptance, or avoidance — so that decision-makers can act on the findings; this is a standard component of risk assessment reporting per frameworks like ISO/IEC 27005 and NIST SP 800-30. Option C is not a key element, since vendor contracts are supporting evidence that may be referenced but are not part of the risk assessment report itself.

Option D is not required, as network topology diagrams are technical artifacts that may inform the assessment but do not constitute a core reporting element. Option E is not relevant, because detailed IT financial budgets fall under financial or budgetary reporting, not IT risk assessment.

Exam trap

The trap here is that candidates confuse supporting documentation (like vendor contracts or network diagrams) with the core required elements of a risk assessment report, which must focus on risk identification, ratings, and treatment recommendations.

Page 2

Page 3 of 15

Page 4