Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 151225

983 questions total · 14pages · All types, answers revealed

Page 2

Page 3 of 14

Page 4
151
MCQeasy

A global manufacturing company is implementing a new ERP system across multiple regions. The project manager has identified a risk that data migration from legacy systems may cause data corruption, leading to production delays. The risk owner proposes conducting a full data reconciliation after migration. However, the IT director argues that this would be too time-consuming and suggests only sampling data for verification. The risk manager must decide on the risk response. The project timeline is tight, and the company has a low tolerance for data integrity issues. Which of the following is the BEST course of action?

A.Accept the risk and proceed with data sampling to save time
B.Avoid the risk by postponing the ERP implementation
C.Implement the full data reconciliation as proposed by the risk owner
D.Transfer the risk by purchasing insurance for data corruption
AnswerC

Full reconciliation directly addresses the risk and aligns with low tolerance for data integrity issues.

Why this answer

Full data reconciliation is the correct risk response because the company has a low tolerance for data integrity issues and the risk of data corruption could cause production delays. While time-consuming, this approach directly mitigates the identified risk by ensuring all migrated data is verified, aligning with the risk appetite. Sampling would leave a margin of error unacceptable for a low-tolerance environment, and the other options either fail to address the risk or are impractical.

Exam trap

The trap here is that candidates may choose data sampling (Option A) as a compromise to save time, overlooking that the company's low tolerance for data integrity issues demands full verification, not a statistical shortcut.

How to eliminate wrong answers

Option A is wrong because accepting the risk with data sampling ignores the company's low tolerance for data integrity issues and could leave undetected corruption that causes production delays. Option B is wrong because avoiding the risk by postponing the ERP implementation is an extreme overreaction that does not address the immediate need for migration and would cause significant business disruption. Option D is wrong because transferring the risk via insurance does not prevent data corruption or production delays; it only provides financial compensation after the fact, which does not meet the requirement for data integrity.

152
Multi-Selectmedium

Which TWO of the following are recognized techniques for identifying IT risks? (Select exactly 2.)

Select 2 answers
A.ROI calculation
B.Brainstorming sessions
C.Benchmarking against industry peers
D.Threat modeling
E.SWOT analysis
AnswersB, D

Brainstorming with stakeholders generates risk ideas.

Why this answer

Brainstorming sessions (B) are a recognized technique for IT risk identification because they leverage the collective expertise of stakeholders to surface potential threats, vulnerabilities, and risk scenarios in a structured or unstructured group setting. This method is specifically cited in ISACA's CRISC Review Manual as a qualitative risk identification approach, often used during the early stages of risk assessment to generate a comprehensive list of risks without requiring quantitative data.

Exam trap

The trap here is that candidates often confuse strategic or financial analysis tools (like SWOT or ROI) with risk identification techniques, but CRISC specifically requires methods that directly uncover threats and vulnerabilities, such as brainstorming and threat modeling, rather than high-level planning or performance metrics.

153
MCQeasy

During an IT risk assessment, the risk owner decides to accept a risk that falls within the organization's risk appetite. Which of the following actions is most appropriate for the risk owner to take?

A.Document the risk and obtain formal sign-off from the risk owner.
B.Eliminate the business process that creates the risk.
C.Transfer the risk to a third party via insurance.
D.Implement additional controls to reduce the risk to zero.
AnswerA

Correct. Acceptance requires documentation and sign-off.

Why this answer

When a risk falls within the organization's risk appetite, the most appropriate action is to formally accept it. The risk owner must document the risk and obtain formal sign-off to ensure accountability and auditability, as required by the risk management framework. This aligns with the principle that risks within appetite do not require additional treatment beyond formal acceptance.

Exam trap

The trap here is that candidates often confuse risk acceptance with risk treatment, assuming that any risk must be mitigated or transferred, but the CRISC exam emphasizes that risks within appetite can be formally accepted without further action.

How to eliminate wrong answers

Option B is wrong because eliminating the business process that creates the risk is a risk avoidance strategy, which is excessive and unnecessary when the risk is within the organization's risk appetite. Option C is wrong because transferring the risk via insurance is a risk treatment option typically reserved for risks that exceed the risk appetite or tolerance, not for those already within acceptable levels. Option D is wrong because implementing additional controls to reduce the risk to zero is impractical and violates the concept of residual risk; risk can rarely be reduced to zero, and doing so would be cost-prohibitive and unnecessary for an accepted risk.

154
MCQhard

A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?

A.Standardize industrial control protocols
B.Reduce energy consumption
C.Ensure interoperability between IT and OT systems
D.Protect the reliability of the bulk electric system
AnswerD

NERC CIP focuses on reliability and security of the electric grid.

Why this answer

NERC CIP standards aim to protect the reliability of the bulk electric system by securing critical cyber assets.

155
MCQhard

Refer to the exhibit. What is the PRIMARY risk identified from this policy?

A.Unrestricted public read access to confidential data
B.Inadequate logging
C.Lack of encryption for data at rest
D.Missing versioning
AnswerA

This is correct because unrestricted public read access directly exposes confidential data.

Why this answer

The policy statement 'All cloud storage buckets must be private by default' directly addresses the risk of public read access to confidential data. If a bucket is misconfigured as public, anyone on the internet can read its objects without authentication, leading to a data breach. This is the primary risk because the policy explicitly targets preventing unauthorized public exposure.

Exam trap

The trap here is that candidates may confuse the primary risk (public read access to data) with secondary risks like logging or encryption, but the policy's explicit focus on 'private by default' directly targets unauthorized public exposure.

How to eliminate wrong answers

Option B is wrong because inadequate logging is a separate operational risk (e.g., missing CloudTrail or S3 server access logs), not the primary risk from a bucket being public. Option C is wrong because lack of encryption for data at rest (e.g., SSE-S3 vs. SSE-KMS) is a different security control; a private bucket with no encryption still prevents public read access.

Option D is wrong because missing versioning (e.g., S3 Versioning disabled) is a data protection and recovery risk, not directly related to public read access.

156
MCQmedium

During a quarterly control effectiveness test, an internal auditor discovers that a key preventive control has a 10% exception rate. The control is designed to prevent unauthorized transactions. Which Key Control Indicator (KCI) is being measured?

A.Key Risk Indicator (KRI)
B.Test result pass rate
C.Control deficiency rate
D.Exception rate
AnswerD

Exception rate is a KCI that measures the frequency of control failures or deviations.

Why this answer

KCIs measure control performance. The exception rate is a KCI that indicates how often the control fails to operate as intended.

157
MCQeasy

Which type of control is designed to reduce the likelihood of a risk event occurring?

A.Corrective
B.Compensating
C.Preventive
D.Detective
AnswerC

Preventive controls reduce the likelihood of occurrence.

Why this answer

Preventive controls are designed to stop a risk event from occurring in the first place. For example, implementing a firewall rule to block unauthorized inbound traffic reduces the likelihood of a network intrusion. This aligns with the CRISC definition of preventive controls as proactive measures that reduce the probability of a risk scenario.

Exam trap

The trap here is that candidates often confuse preventive controls with detective controls, mistakenly thinking that monitoring or alerting (detective) reduces the likelihood of an event, when in fact it only reduces the impact or detection time after the event has occurred.

How to eliminate wrong answers

Option A is wrong because corrective controls are designed to remediate or restore operations after a risk event has occurred, such as restoring data from backup after a ransomware attack, not to reduce the likelihood of the event. Option B is wrong because compensating controls are alternative measures that provide equivalent protection when a primary control is not feasible, such as using additional logging when encryption cannot be applied, but they do not directly reduce the likelihood of the original risk event. Option D is wrong because detective controls are designed to identify and report risk events after they have happened, such as intrusion detection systems (IDS) that alert on malicious traffic, not to prevent the event from occurring.

158
MCQeasy

Which of the following is an example of a corrective control?

A.Firewall blocking unauthorized traffic
B.Intrusion detection system alerting on suspicious activity
C.Log monitoring to identify unauthorized access
D.Restoring data from backup after a ransomware attack
AnswerD

Correct. This corrects the impact of the incident.

Why this answer

Corrective controls are designed to remediate or reverse the effects of an incident after it has occurred. Restoring data from backup after a ransomware attack directly addresses the damage by recovering lost or encrypted data, making it a classic corrective control. In contrast, preventive controls (like firewalls) block incidents before they happen, and detective controls (like IDS alerts or log monitoring) identify incidents after they occur but do not fix the damage.

Exam trap

The trap here is confusing detective controls (which identify incidents) with corrective controls (which fix the damage), leading candidates to pick IDS alerts or log monitoring as corrective actions when they only provide visibility, not remediation.

How to eliminate wrong answers

Option A is wrong because a firewall blocking unauthorized traffic is a preventive control—it stops threats before they reach the network, not after an incident. Option B is wrong because an intrusion detection system (IDS) alerting on suspicious activity is a detective control—it identifies potential incidents but does not take action to correct them. Option C is wrong because log monitoring to identify unauthorized access is also a detective control—it detects breaches after they happen but does not restore or repair the affected systems or data.

159
Multi-Selectmedium

A company has a critical production system with a known vulnerability. Due to the system's age, the vendor no longer supports it. The company decides to implement network segmentation and purchase cyber insurance to cover potential losses. Which TWO risk response options are they applying?

Select 2 answers
A.Accept
B.Transfer
C.Avoid
D.Ignore
E.Mitigate
AnswersB, E

Insurance transfers financial risk.

Why this answer

Network segmentation reduces the attack surface by isolating the vulnerable system, which is a classic risk mitigation technique. Purchasing cyber insurance transfers the financial risk of residual losses to a third party, making 'Transfer' the correct second option. Together, these actions address the risk without removing the vulnerability.

Exam trap

The trap here is that candidates confuse 'transfer' with 'mitigate' because insurance is a financial transfer, while segmentation is a technical mitigation, and the question expects you to recognize both as distinct, simultaneous responses.

160
MCQhard

A multinational corporation is evaluating a new vendor for cloud services. The vendor's data centers are located in a country with weak data protection laws. The corporation's data includes personal information of EU citizens subject to GDPR. What is the MOST appropriate risk response?

A.Avoid by choosing a vendor in a country with strong data protection laws
B.Require the vendor to sign standard contractual clauses and encrypt all data
C.Accept the risk because the vendor offers the best price
D.Purchase cyber insurance to cover potential fines
AnswerB

This mitigates risk to an acceptable level under GDPR.

Why this answer

Standard Contractual Clauses (SCCs) are a GDPR-approved transfer mechanism that legally binds the vendor to EU data protection standards, even in a weak-law jurisdiction. Combined with encryption of all data at rest and in transit, this provides both a legal and technical safeguard, reducing the risk of non-compliance to an acceptable level without abandoning the vendor.

Exam trap

The trap here is that candidates often choose 'avoid' (Option A) as the safest response, but the CRISC exam expects you to recognize that risk can be mitigated to an acceptable level using legal and technical controls, rather than automatically avoiding the risk.

How to eliminate wrong answers

Option A is wrong because it represents risk avoidance, which is overly restrictive and may not be feasible if no suitable vendor exists in strong-law countries; it also ignores that SCCs and encryption can adequately mitigate the risk. Option C is wrong because accepting risk solely based on cost violates the fundamental principle of risk management—financial benefit does not justify exposing EU personal data to inadequate legal protections, and GDPR fines can far exceed any cost savings. Option D is wrong because cyber insurance only transfers the financial impact of a fine, not the legal liability or reputational damage; it does not address the root cause of non-compliance with GDPR transfer restrictions.

161
MCQmedium

During a vulnerability assessment, a risk practitioner identifies that a web application is vulnerable to SQL injection, which is listed in the OWASP Top 10. Which type of vulnerability identification technique MOST likely discovered this issue?

A.SAST (Static Application Security Testing)
B.CIS Benchmarks comparison
C.DAST (Dynamic Application Security Testing)
D.DISA STIG scanning
AnswerC

Why this answer

DAST (Dynamic Application Security Testing) tests the running application for vulnerabilities like SQL injection by simulating attacks. SAST is static code analysis, IAST is interactive testing.

162
MCQmedium

An organization has implemented a continuous monitoring solution for its critical applications. The IT team reports that the monitoring tool generates a high volume of false positives. What is the BEST course of action?

A.Refine the monitoring rules and thresholds to reduce false positives.
B.Disable the monitoring for applications that generate the most false positives.
C.Increase the size of the monitoring team to handle the alerts.
D.Implement additional detective controls for all false positive alerts.
AnswerA

Tuning the tool reduces noise and enhances monitoring effectiveness.

Why this answer

Refining monitoring rules and thresholds directly addresses the root cause of false positives by tuning the detection logic to better match actual risk conditions. This aligns with the CRISC principle of optimizing control efficiency rather than accepting or compensating for excessive noise. For example, adjusting anomaly detection thresholds in a SIEM like Splunk or QRadar can reduce alert volume without sacrificing coverage of genuine threats.

Exam trap

The CRISC exam often tests the misconception that increasing resources (team size) or adding more controls is the best response to monitoring inefficiency, when in fact tuning existing controls is the most effective and risk-appropriate action.

How to eliminate wrong answers

Option B is wrong because disabling monitoring for applications that generate false positives eliminates visibility into those systems, creating a blind spot that could allow real incidents to go undetected. Option C is wrong because increasing team size treats the symptom (alert volume) rather than the cause, and is unsustainable if false positives continue to grow. Option D is wrong because implementing additional detective controls for false positive alerts adds unnecessary complexity and cost without fixing the underlying rule misconfiguration, and may even increase noise further.

163
MCQeasy

Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?

A.Business interruption
B.Ransomware attacks
C.Social engineering fraud
D.Acts of war
AnswerD

Correct. Acts of war are commonly excluded.

Why this answer

Cyber insurance policies often exclude acts of war, including state-sponsored cyber attacks. This is a critical exclusion that can leave organizations unprotected against nation-state threats.

164
MCQhard

You are the IT risk manager for a multinational corporation with a hybrid cloud environment. The company uses AWS for its primary infrastructure and maintains an on-premises data center for legacy applications. Recently, the security team detected that a contractor's credentials were used to access an S3 bucket containing personally identifiable information (PII) of European customers. The contractor had been granted access to this bucket six months ago for a data migration project that has since been completed. The access was not revoked. The security team has implemented an automated process to review and revoke access for contractors after project completion, but this process has not been applied retroactively. The company is subject to GDPR. Which of the following is the BEST course of action to address the immediate risk?

A.Conduct a forensic investigation to determine if any data was exfiltrated, then update the incident response plan.
B.Immediately revoke the contractor's access and initiate a review of all contractor accounts to revoke any unnecessary permissions.
C.Manually review access rights for all contractors and revoke those not needed, starting with the most sensitive systems.
D.Update the automated access review process to include all existing contractor accounts and schedule it to run weekly.
AnswerB

This directly mitigates the immediate risk of unauthorized access.

Why this answer

The immediate risk is that the contractor still has active access to an S3 bucket containing PII, which violates GDPR's principle of data minimization and access control (Article 5(1)(f)). Revoking the contractor's access now stops any ongoing unauthorized access, and initiating a review of all contractor accounts addresses the systemic failure to apply the automated process retroactively. This directly mitigates the risk of further data exposure without delay.

Exam trap

The trap here is that candidates may choose a forensic or process-improvement option (A or D) because they seem thorough, but the question asks for the BEST course of action to address the immediate risk, which is to stop the active unauthorized access first before investigating or improving long-term processes.

How to eliminate wrong answers

Option A is wrong because conducting a forensic investigation first delays the immediate action needed to stop ongoing unauthorized access; while forensics may be needed later, the priority is to revoke access to prevent further potential data exfiltration. Option C is wrong because manually reviewing all contractors starting with the most sensitive systems is slower and less efficient than immediately revoking the known risky access and then performing a broader review; it also fails to address the fact that the automated process should be applied retroactively. Option D is wrong because updating the automated process to include existing accounts and scheduling it weekly does not address the immediate risk of the contractor's current active access; it only prevents future occurrences, leaving the current vulnerability open.

165
MCQhard

Based on the exhibit, which risk should be treated first according to the risk rating?

A.R003, because the likelihood is highest
B.R002, because the impact is highest
C.All three should be treated simultaneously
D.R001, because it has the highest risk level
AnswerD

R001 has level 15, the highest.

Why this answer

Risk treatment priority is determined by the risk level, which is a function of both likelihood and impact. In the exhibit, R001 has the highest risk level (e.g., 16), calculated as likelihood × impact, making it the most critical to address first. This aligns with the CRISC principle of prioritizing risks with the highest residual risk rating.

Exam trap

The trap here is that candidates often confuse 'highest likelihood' or 'highest impact' with 'highest risk level,' but CRISC emphasizes that risk level is the product of both factors, not any single component.

How to eliminate wrong answers

Option A is wrong because R003 has the highest likelihood but not the highest risk level; risk treatment prioritizes risk level, not likelihood alone. Option B is wrong because R002 has the highest impact but not the highest risk level; impact alone does not determine priority without considering likelihood. Option C is wrong because simultaneous treatment is inefficient and contradicts the risk management principle of prioritizing based on risk level; resources should be allocated to the highest-rated risk first.

166
MCQmedium

An organization has implemented a new control that requires manual approval for all high-value transactions. The control owner is responsible for ensuring approvals are obtained. Which control ownership aspect is demonstrated?

A.Control implementation plan
B.Cost-benefit analysis
C.Control ownership
D.Resource requirements
AnswerC

The control owner is accountable for the control's operation and effectiveness.

Why this answer

The scenario explicitly states that the control owner is responsible for ensuring approvals are obtained, which directly demonstrates the concept of control ownership. Control ownership refers to the assignment of accountability for the implementation, operation, and maintenance of a specific control, such as manual approval for high-value transactions. This is a core principle in risk response, where a named individual is accountable for the control's effectiveness, not just its implementation or cost.

Exam trap

The trap here is that candidates confuse 'control ownership' with 'control implementation' or 'resource allocation,' but the question specifically tests the distinction between accountability for ongoing operation versus planning or resourcing.

How to eliminate wrong answers

Option A is wrong because a control implementation plan is a project roadmap detailing steps, timelines, and resources to deploy a control, not the assignment of ongoing accountability for its operation. Option B is wrong because cost-benefit analysis is a financial evaluation used to justify a control's selection, not the demonstration of ownership or responsibility for its execution. Option D is wrong because resource requirements define the personnel, technology, or budget needed to operate a control, but they do not assign the specific accountability for ensuring approvals are obtained.

167
MCQhard

After implementing security controls, a risk assessment shows a residual risk of data exfiltration with a probability of 5% and potential loss of $10 million. The organization's risk appetite allows a maximum acceptable risk level of 3% probability for such impact. The cost of further mitigation is $1 million. What is the best risk response?

A.Implement additional controls to reduce probability to 2%
B.Accept the residual risk
C.Purchase cybersecurity insurance
D.Discontinue the process
AnswerA

Further mitigation brings risk within appetite.

Why this answer

The residual risk has a probability of 5% and a potential loss of $10 million, resulting in an expected loss of $500,000. The organization's risk appetite allows a maximum probability of 3% for such an impact, so the current risk exceeds the acceptable threshold. Implementing additional controls for $1 million to reduce the probability to 2% brings the risk within the risk appetite (expected loss of $200,000) and is cost-effective because the reduction in expected loss ($300,000) is less than the control cost, but the primary driver is compliance with risk appetite, not pure cost-benefit.

Exam trap

The trap here is that candidates focus on the cost-benefit analysis (mitigation cost vs. reduced expected loss) and incorrectly conclude that acceptance is cheaper, ignoring that risk appetite is a binding constraint that overrides pure financial calculations.

How to eliminate wrong answers

Option B is wrong because accepting the residual risk would violate the organization's risk appetite, which explicitly caps probability at 3% for this impact level; acceptance is only valid when risk is within tolerance. Option C is wrong because purchasing cybersecurity insurance transfers financial risk but does not reduce the probability of data exfiltration; it would still leave the probability at 5%, exceeding the risk appetite threshold, and insurance premiums often require residual risk to be within appetite. Option D is wrong because discontinuing the process is an extreme risk avoidance response that would eliminate the business function entirely, which is disproportionate when a cost-effective mitigation exists to bring risk within appetite.

168
MCQmedium

A risk manager is identifying risks for an organization that uses a hybrid cloud environment. The organization stores sensitive data on-premises and in the cloud. Which of the following is the MOST effective method for identifying risks related to data residency and compliance?

A.Conduct a penetration test of the cloud environment
B.Review data flow diagrams and legal requirements for each jurisdiction
C.Perform a configuration review of cloud security settings
D.Review the cloud provider's SOC 2 report
AnswerB

This identifies data movement and regulatory compliance risks.

Why this answer

Reviewing data flow diagrams alongside legal requirements for each jurisdiction is the most effective method because it directly maps where sensitive data resides, transits, and is processed across on-premises and cloud environments, enabling precise identification of residency and compliance gaps. This approach aligns with CRISC's emphasis on risk identification through understanding data lineage and regulatory obligations, rather than relying on post-deployment security tests or generic reports.

Exam trap

The trap here is that candidates confuse security testing (penetration tests, configuration reviews) with compliance risk identification, overlooking that data residency and legal requirements demand a process-oriented review of data flows and jurisdictional rules, not just technical controls.

How to eliminate wrong answers

Option A is wrong because a penetration test assesses security vulnerabilities (e.g., misconfigurations, exploit paths) but does not evaluate data residency or compliance with jurisdictional laws like GDPR or CCPA. Option C is wrong because a configuration review of cloud security settings checks for technical controls (e.g., encryption, IAM policies) but cannot reveal whether data storage locations violate specific residency requirements. Option D is wrong because a SOC 2 report provides assurance on a cloud provider's controls (e.g., security, availability) but does not detail data flow paths or legal compliance for each jurisdiction where data resides.

169
MCQmedium

A company outsourced its payroll processing to a third-party vendor. During the risk assessment, it was found that the vendor's data centers are in a country with weak data protection laws. What is the BEST way to treat this risk?

A.Terminate the contract and bring payroll in-house
B.Purchase cyber insurance to cover potential losses
C.Require contractual clauses and verify compliance
D.Accept the risk because the vendor has never had a breach
AnswerC

Contractual obligations with verification help manage the risk while maintaining operations.

Why this answer

The best way to treat this risk is to implement contractual controls that require the vendor to adhere to data protection standards equivalent to the company's requirements, and to verify compliance through audits or certifications. This directly addresses the root cause—weak local data protection laws—by imposing enforceable obligations on the vendor, rather than transferring, avoiding, or accepting the risk without mitigation. Contractual clauses with compliance verification are a recognized risk mitigation technique in third-party risk management, as they create a legal framework for data protection regardless of the vendor's jurisdiction.

Exam trap

The trap here is that candidates often confuse risk treatment options—mistaking risk transfer (insurance) or risk avoidance (termination) for the most appropriate response, when the question specifically asks for the 'best way to treat' a risk that can be mitigated through contractual and compliance controls.

How to eliminate wrong answers

Option A is wrong because terminating the contract and bringing payroll in-house may not be feasible or cost-effective, and it does not address the risk assessment's finding that the vendor's location has weak data protection laws—it avoids the risk rather than treating it with a balanced, business-aligned response. Option B is wrong because purchasing cyber insurance transfers the financial impact of a breach but does not reduce the likelihood or severity of the data protection risk; it is a risk transfer technique, not a risk treatment that addresses the underlying control weakness. Option D is wrong because accepting the risk based solely on the vendor's historical lack of breaches ignores the inherent risk from weak data protection laws and violates the principle of due care; risk acceptance requires a formal decision with documented justification, not passive reliance on past performance.

170
Multi-Selectmedium

Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)

Select 3 answers
A.Exclusions for acts of war or state-sponsored attacks
B.Incident response prerequisites such as mandatory use of approved vendors
C.Coverage scope for different incident types
D.Company's stock price volatility
E.Office location and building security
AnswersA, B, C

Many policies exclude nation-state attacks, which is a significant gap.

Why this answer

Cyber insurance policies have specific coverage scopes, exclusions (e.g., war, negligence), and prerequisites (e.g., multi-factor authentication). Premium factors like security controls also affect cost.

171
MCQhard

A multinational organization uses multiple risk management systems that do not integrate with each other. The risk team manually consolidates data into a spreadsheet for reporting. This process is error-prone and time-consuming. Which of the following is the BEST long-term solution to improve risk monitoring and reporting?

A.Standardize the spreadsheet format across all departments
B.Implement a centralized governance, risk, and compliance (GRC) platform with automated data feeds
C.Train risk owners on how to better manually report risks
D.Assign dedicated staff to perform additional manual reviews of the spreadsheet
AnswerB

A centralized GRC platform with automated data feeds integrates all risk management systems, reducing errors and improving efficiency.

Why this answer

Implementing a centralized GRC platform with data feeds from all systems automates integration and reduces errors. Option A is wrong because standardizing spreadsheets still requires manual consolidation. Option C is wrong because training does not address the system integration issue.

Option D is wrong because simply adding more manual reviews increases overhead.

172
MCQmedium

During a qualitative risk assessment, the risk owner rates the likelihood of a threat as 'high' and the impact as 'medium'. According to standard risk matrices, what is the resulting risk level?

A.Low
B.High
C.Medium
D.Critical
AnswerB

High likelihood and medium impact yields high risk.

Why this answer

In a standard 3x3 or 5x5 risk matrix, a 'high' likelihood combined with a 'medium' impact typically maps to a 'high' risk level. This is because the risk level is determined by the intersection of likelihood and impact, and the product or matrix cell for these two ratings falls into the high category, indicating a significant risk that requires management attention.

Exam trap

The trap here is that candidates often confuse 'medium' impact with a 'medium' overall risk level, failing to account for the multiplicative or matrix-based escalation when likelihood is high.

How to eliminate wrong answers

Option A (Low) is wrong because a 'high' likelihood with a 'medium' impact does not produce a low risk level; low risk would require both likelihood and impact to be low. Option C (Medium) is wrong because while 'medium' impact is present, the 'high' likelihood elevates the overall risk above medium in standard matrices. Option D (Critical) is wrong because critical risk typically requires both likelihood and impact to be 'high' or 'very high', not a mix of 'high' and 'medium'.

173
MCQhard

A financial institution uses a quantitative risk assessment for a core banking system. The annual loss expectancy (ALE) is calculated as $500,000 with a single loss expectancy (SLE) of $2,500,000. What is the annualized rate of occurrence (ARO)?

A.5.0
B.2.0
C.0.5
D.0.2
AnswerD

ARO = ALE / SLE = 0.2.

Why this answer

The annualized rate of occurrence (ARO) is derived from the formula ALE = SLE × ARO. Given ALE = $500,000 and SLE = $2,500,000, solving for ARO yields $500,000 / $2,500,000 = 0.2. This means the core banking system is expected to experience a loss event once every five years on average.

Exam trap

The trap here is that candidates often mistakenly invert the formula, dividing SLE by ALE to get 5.0, or confuse ARO with a percentage, leading to 0.5, instead of correctly applying ALE = SLE × ARO to solve for ARO.

How to eliminate wrong answers

Option A is wrong because 5.0 would result from incorrectly dividing SLE by ALE (2,500,000 / 500,000), which reverses the formula. Option B is wrong because 2.0 would come from dividing ALE by a misapplied factor or confusing ARO with a multiplier. Option C is wrong because 0.5 would arise from misplacing the decimal or assuming a 50% chance per year, which does not match the calculated ratio.

174
MCQhard

When developing IT risk scenarios, connecting them to business impact is critical. Which of the following BEST describes how a risk practitioner should link a technical scenario to business impact?

A.Assign a likelihood rating and an inherent risk score
B.Quantify the impact in terms of financial loss, regulatory penalty, and operational disruption
C.Describe the technical steps of the attack in detail
D.Reference industry benchmarks for similar scenarios
AnswerB

Correct. This directly links the scenario to business-relevant consequences.

Why this answer

The correct approach is to map the technical scenario to specific business outcomes such as financial loss, regulatory penalties, or reputational damage, allowing management to understand the significance.

175
MCQmedium

Refer to the exhibit. The SIEM alert triggered, but the security team did not respond because they were investigating another incident. What is the BEST way to prevent such monitoring gaps in the future?

A.Implement a ticketing system to track alert handling.
B.Hire additional security analysts to handle peak loads.
C.Increase the threshold to reduce false positives.
D.Configure automatic escalation to a secondary response team if the alert is not acknowledged within a set time.
AnswerD

Ensures alerts are not ignored.

Why this answer

It directly addresses the monitoring gap caused by analyst unavailability. By configuring automatic escalation to a secondary response team if an alert is not acknowledged within a set time, the organization ensures that no alert is left unattended even when the primary team is occupied. This is a standard operational resilience control in SIEM workflows, often implemented via playbook automation or SOAR integration.

Exam trap

The trap here is that candidates often choose 'Hire additional security analysts' (Option B) as a capacity solution, but the question specifically tests the concept of operational resilience through automated failover, not just staffing levels.

How to eliminate wrong answers

Option A is wrong because a ticketing system tracks alert handling but does not automatically reassign or escalate unacknowledged alerts; it only logs the event, leaving the gap unaddressed. Option B is wrong because hiring additional analysts increases capacity but does not guarantee coverage during peak loads or when the team is already engaged; it is a scaling solution, not a failover mechanism. Option C is wrong because increasing the threshold to reduce false positives may suppress legitimate alerts, increasing the risk of missing real incidents; it does not solve the problem of unacknowledged alerts.

176
MCQmedium

Which of the following best describes the purpose of tactical risk reporting?

A.To satisfy regulatory compliance requirements
B.To inform the board of directors about strategic risk exposure
C.To provide daily operational metrics to system administrators
D.To enable the CISO to make informed decisions about risk mitigation priorities
AnswerD

Tactical reporting supports management decisions.

Why this answer

Tactical risk reporting is designed to provide mid-level management, such as the CISO, with actionable insights to prioritize risk mitigation activities. It focuses on operational risk decisions, not strategic oversight or daily metrics, enabling informed choices about resource allocation and remediation timelines.

Exam trap

The trap here is confusing the audience and time horizon of reporting levels—candidates often mistake tactical reporting for operational metrics (Option C) because both involve technical details, but tactical reporting is decision-focused for management, not daily task execution.

How to eliminate wrong answers

Option A is wrong because tactical risk reporting is not primarily for regulatory compliance; compliance reporting is a separate function that addresses specific legal or contractual requirements. Option B is wrong because informing the board about strategic risk exposure is the purpose of strategic risk reporting, which covers high-level, long-term risk posture. Option C is wrong because providing daily operational metrics to system administrators is the role of operational or technical reporting, not tactical reporting, which targets management decisions.

177
MCQmedium

An IT risk report for the board of directors should primarily focus on:

A.Specific control failures with root cause analysis
B.Detailed technical vulnerability scan results
C.Operational incident counts
D.Top risks, trends, and control performance metrics
AnswerD

These provide a strategic overview for the board.

Why this answer

Strategic risk reporting to the board should highlight top risks, trends, and high-level metrics in business terms, avoiding excessive technical detail.

178
Multi-Selectmedium

A risk assessment identifies that a critical application has a vulnerability with a high likelihood of exploitation. The risk owner proposes to implement a web application firewall (WAF) as a mitigating control. Which TWO of the following are likely benefits of this control?

Select 2 answers
A.Reduces the likelihood of successful exploitation
B.Transfers the risk to the vendor
C.Eliminates the need for other controls
D.Eliminates all residual risk
E.Provides detective capabilities by logging blocked attacks
AnswersA, E

WAF blocks malicious traffic, reducing likelihood.

Why this answer

A WAF reduces the likelihood of successful exploitation by inspecting and filtering HTTP/HTTPS traffic for common attack patterns such as SQL injection and cross-site scripting (XSS). It blocks malicious payloads before they reach the application, directly lowering the probability that a vulnerability will be exploited. This aligns with the risk mitigation strategy of reducing threat exposure.

Exam trap

The CRISC exam often tests the misconception that a WAF is a silver bullet that eliminates all risk or replaces other controls, when in fact it is a layered defense that reduces likelihood but does not transfer, eliminate, or remove the need for complementary security measures.

179
Multi-Selectmedium

Which TWO of the following are examples of continuous monitoring activities? (Select TWO.)

Select 2 answers
A.Continuous vulnerability scanning
B.Annual penetration testing
C.Quarterly user access reviews
D.Automated SIEM rule-based alerts for suspicious activity
E.Monthly review of audit logs
AnswersA, D

Correct. Continuous scanning is ongoing.

Why this answer

Automated SIEM monitoring and continuous vulnerability scanning are continuous activities, while annual penetration testing and quarterly access reviews are periodic.

180
MCQhard

Your organization is undergoing a merger and acquisition. The IT risk assessment team is tasked with evaluating the target company's IT environment. During the assessment, you discover that the target company uses a legacy ERP system that is no longer supported by the vendor. They have no disaster recovery plan for this system, and it contains financial data critical to the merged entity. The integration timeline is aggressive, and replacing the system would delay the merger by 18 months. The executive team is reluctant to delay. What is the BEST risk treatment option?

A.Avoid the risk by excluding the legacy system from the merger and migrating data to a new system.
B.Accept the risk because the system has been running for years without issue.
C.Mitigate by developing a disaster recovery plan and implementing compensating controls such as regular backups and manual procedures.
D.Transfer the risk to the target company's previous owners.
AnswerC

Addresses key weaknesses without delaying merger.

Why this answer

The legacy ERP system contains critical financial data and cannot be replaced without an 18-month delay, making risk mitigation the most practical approach. Developing a disaster recovery plan and implementing compensating controls (e.g., regular backups, manual procedures) reduces the likelihood and impact of a system failure while allowing the merger to proceed on schedule. This aligns with the CRISC principle of treating risk by reducing residual risk to an acceptable level without blocking business objectives.

Exam trap

The trap here is that candidates may choose Option B (accept the risk) because the system has been stable historically, but CRISC expects you to recognize that unsupported systems with no DR plan represent an unmanaged risk that requires active mitigation, not passive acceptance.

How to eliminate wrong answers

Option A is wrong because excluding the legacy system and migrating data to a new system would effectively replace it, causing the same 18-month delay the executive team wants to avoid; this is a risk avoidance strategy that is not feasible given the aggressive timeline. Option B is wrong because accepting the risk based solely on historical uptime ignores the fact that the system is unsupported, has no disaster recovery plan, and contains critical financial data—past performance does not guarantee future reliability, especially without vendor patches or support. Option D is wrong because transferring risk to the target company's previous owners is impractical post-acquisition; contractual indemnification may exist, but it does not address the ongoing operational risk of the unsupported system within the merged entity, and such transfer is typically limited to legal liability, not technical risk.

181
MCQhard

An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:

A.Risk transfer
B.Risk acceptance
C.Risk mitigation
D.Risk avoidance
AnswerA

Outsourcing and insurance are examples of risk transfer.

Why this answer

Transfer involves shifting risk to a third party, such as through outsourcing with contractual liability transfer and insurance.

182
MCQmedium

A company is developing risk scenarios for business impact analysis. Which of the following scenario components directly links the risk event to potential financial loss?

A.Vulnerability
B.Threat actor
C.Consequence
D.Asset
AnswerC

Consequence captures the impact, such as financial loss.

Why this answer

The consequence describes the outcome of the risk event, which includes financial loss. Other components describe the cause or context but not the impact.

183
MCQmedium

A risk owner is reviewing a control that has a deficiency rate of 15%. The target deficiency rate is less than 5%. Which of the following is the MOST appropriate immediate action?

A.Investigate the root cause of the high deficiency rate
B.Increase the target deficiency rate to 15%
C.Report the deficiency to the external auditor
D.Accept the risk and document the decision
AnswerA

Root cause analysis is needed to identify why the control is failing.

Why this answer

A deficiency rate of 15% against a target of less than 5% indicates a control failure that requires immediate remediation. Investigating the root cause is the first step in the risk response process to identify why the control is failing and to determine the appropriate corrective action, aligning with the Risk Response and Reporting domain's emphasis on addressing control deficiencies before considering acceptance or reporting.

Exam trap

The trap here is that candidates may choose 'Accept the risk and document the decision' (Option D) because they confuse risk acceptance with a standard response to control deficiencies, but CRISC emphasizes that acceptance is only appropriate after a formal risk assessment and when remediation is not feasible or cost-justified.

How to eliminate wrong answers

Option B is wrong because increasing the target deficiency rate to 15% would lower the control standard without addressing the underlying failure, effectively ignoring the risk and violating the principle of maintaining control effectiveness. Option C is wrong because reporting the deficiency to the external auditor is premature; the immediate action should be internal investigation and remediation, not external disclosure, which occurs after analysis and as part of formal reporting cycles. Option D is wrong because accepting the risk without understanding the root cause or attempting remediation bypasses the risk treatment process; acceptance should be a deliberate decision after evaluating the impact and likelihood, not the first action upon discovering a high deficiency rate.

184
Multi-Selectmedium

A company is considering risk transfer for a new IT project. Which TWO options represent valid risk transfer mechanisms? (Select TWO)

Select 2 answers
A.Accepting the risk with sign-off
B.Purchasing cyber insurance
C.Implementing access controls
D.Discontinuing the project
E.Outsourcing with liability clauses
AnswersB, E

Insurance transfers financial risk.

Why this answer

Cyber insurance and outsourcing with contractual liability transfer are classic examples of risk transfer. Accepting, avoiding, and mitigating are not transfer.

185
Multi-Selecthard

Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)

Select 3 answers
A.Risk trend analysis over time
B.Risk heat map showing current risk levels
C.Names of all third-party vendors with contracts
D.List of top risks and their mitigation status
E.Detailed control deficiency descriptions
AnswersA, B, D

Correct. Shows changes in risk posture.

Why this answer

Risk trend analysis over time (Option A) is essential because it enables senior management to understand whether the organization's risk posture is improving or deteriorating, supporting strategic decision-making. Trend data, such as month-over-month changes in residual risk scores or frequency of high-severity incidents, provides context beyond a static snapshot. This aligns with the CRISC focus on continuous monitoring and reporting of risk response effectiveness.

Exam trap

The trap here is that candidates confuse operational detail (like vendor lists or control descriptions) with strategic reporting content, failing to recognize that senior management needs aggregated, decision-focused information rather than granular technical data.

186
MCQmedium

A company is evaluating the risk of a data breach using the FAIR framework. The threat event frequency is estimated at 10 per year, and the vulnerability is 0.2. The primary loss per event is $50,000 and secondary loss is $20,000. What is the annualized loss expectancy (ALE)?

A.$100,000
B.$140,000
C.$70,000
D.$1,400,000
AnswerB

Correctly computed as described.

Why this answer

The annualized loss expectancy (ALE) is calculated as threat event frequency (TEF) × vulnerability (V) × loss per event. Here, TEF = 10, V = 0.2, primary loss = $50,000, secondary loss = $20,000, so total loss per event = $70,000. ALE = 10 × 0.2 × $70,000 = 10 × $14,000 = $140,000, making option B correct.

Exam trap

ISACA CRISC often tests the candidate's ability to correctly apply the FAIR formula by including both primary and secondary losses, and the trap here is that candidates forget to multiply by vulnerability or omit secondary loss, leading to options A or C.

How to eliminate wrong answers

Option A is wrong because it incorrectly uses only the primary loss ($50,000) and ignores the secondary loss ($20,000), calculating ALE as 10 × 0.2 × $50,000 = $100,000. Option C is wrong because it uses the total loss per event ($70,000) but fails to multiply by vulnerability (0.2), resulting in 10 × $70,000 = $700,000, not $70,000; the stated $70,000 is just the loss per event, not the ALE. Option D is wrong because it multiplies TEF (10) by total loss per event ($70,000) without applying vulnerability (0.2), giving $700,000, and then incorrectly multiplies by 2, or it misplaces the decimal, resulting in $1,400,000.

187
MCQhard

A company has a low risk appetite but high risk tolerance. Which of the following scenarios is consistent with this situation?

A.The company avoid controls and accepts high risk
B.The company invests heavily in cybersecurity controls but accepts some residual risk
C.The company has aggressive growth targets and accepts any IT risk
D.The company invests minimally in controls and has low residual risk
AnswerB

Low appetite drives control investment; high tolerance allows acceptance of remaining risk within bounds.

Why this answer

A low risk appetite means the company is unwilling to accept high levels of risk, while high risk tolerance indicates it can absorb the financial or operational impact of residual risk that remains after controls are applied. Investing heavily in cybersecurity controls reduces inherent risk to a low residual level, aligning with the low appetite, and the acceptance of some residual risk is consistent with the high tolerance. This scenario reflects a balanced approach where controls are prioritized to meet appetite, and tolerance allows for manageable leftover risk.

Exam trap

The trap here is confusing risk appetite (the willingness to take risk) with risk tolerance (the capacity to withstand risk), leading candidates to incorrectly associate high tolerance with accepting high risk, when in fact high tolerance allows for acceptance of residual risk after controls are applied.

How to eliminate wrong answers

Option A is wrong because avoiding controls and accepting high risk directly contradicts a low risk appetite, which demands risk reduction, not acceptance of high risk. Option C is wrong because aggressive growth targets and accepting any IT risk ignore the low risk appetite, which would reject unmitigated high-risk initiatives. Option D is wrong because investing minimally in controls would leave high inherent risk unaddressed, resulting in residual risk that exceeds a low appetite, and low residual risk cannot be achieved without adequate controls.

188
MCQhard

An organization uses the PASTA threat modeling methodology. In which stage would the team identify threat agents and their capabilities?

A.Define objectives
B.Threat analysis
C.Vulnerability analysis
D.Decompose application
AnswerB

Stage 3 analyzes threats, including threat agents.

Why this answer

PASTA's third stage involves profiling threat agents and their capabilities.

189
MCQeasy

A risk practitioner discovers that a critical control deficiency has been open for six months beyond the agreed remediation date. What is the MOST appropriate reporting action?

A.Report the overdue deficiency to senior management for escalation.
B.Notify the control owner and request an updated remediation plan.
C.Accept the delay and extend the remediation date by six months.
D.Update the risk register to reflect the increased residual risk and close out the deficiency.
AnswerA

Timely escalation is key for unresolved critical issues.

Why this answer

A critical control deficiency that remains unresolved six months past its remediation date represents a significant governance failure and an elevated risk exposure that exceeds the organization's risk appetite. The risk practitioner's primary reporting obligation under CRISC principles is to escalate such overdue deficiencies to senior management, who have the authority and accountability to enforce remediation, allocate resources, or accept the risk formally. This aligns with the monitoring and reporting domain, where timely escalation of control failures is essential to maintain the integrity of the risk management process.

Exam trap

The trap here is that candidates often confuse the operational step of notifying the control owner (Option B) with the required reporting action, failing to recognize that after a six-month overdue period, the deficiency has already escalated in severity and must be reported to senior management for formal governance action.

How to eliminate wrong answers

Option B is wrong because notifying the control owner and requesting an updated remediation plan is a tactical, operational step that should have been taken much earlier; after six months of delay, the deficiency has already demonstrated a failure of the remediation process, and the risk practitioner must escalate to a higher authority. Option C is wrong because accepting the delay and extending the remediation date by six months without formal risk acceptance from senior management violates the principle of timely remediation and could lead to unchecked risk accumulation; the risk practitioner cannot unilaterally approve such an extension. Option D is wrong because updating the risk register to reflect increased residual risk and closing out the deficiency would improperly close a control gap that still exists, effectively hiding the unresolved issue from oversight and bypassing the required escalation and remediation tracking.

190
MCQeasy

A risk practitioner is using a 5×5 heat map to assess IT risks. Which of the following is the primary advantage of this qualitative approach?

A.Produces financially meaningful loss estimates
B.Requires less data and time to implement
C.Provides objective and comparable risk scores across organizations
D.Eliminates subjectivity in risk ratings
AnswerB

Qualitative methods like heat maps are quick and require less data compared to quantitative methods.

Why this answer

A 5×5 heat map is a qualitative risk assessment tool that uses ordinal scales (e.g., low, medium, high) for likelihood and impact. Its primary advantage is that it requires less data and time to implement compared to quantitative methods, which demand detailed financial data and complex calculations. This makes it practical for rapid, high-level IT risk prioritization when precise data is unavailable.

Exam trap

The trap here is that candidates often confuse 'qualitative' with 'objective' or 'comparable,' but qualitative methods are inherently subjective and context-dependent, unlike quantitative methods that produce numeric, comparable outputs.

How to eliminate wrong answers

Option A is wrong because qualitative heat maps do not produce financially meaningful loss estimates; they use subjective ordinal scales (e.g., 'high impact') rather than monetary values, which is a key limitation. Option C is wrong because qualitative scores are subjective and depend on the assessor's judgment, making them not objectively comparable across different organizations or even different teams within the same organization. Option D is wrong because the approach does not eliminate subjectivity; in fact, it relies on expert judgment to assign ratings, which introduces inherent bias and variability.

191
MCQeasy

A risk manager notices that a key risk indicator (KRI) for system downtime has exceeded the threshold for two consecutive months. What is the MOST appropriate immediate action?

A.Revise the KRI threshold to a higher value.
B.Archive the current KRI and define a new one.
C.Update the risk register with the new KRI value.
D.Escalate to the risk owner for investigation.
AnswerD

The risk owner should assess the situation and determine corrective actions.

Why this answer

When a KRI exceeds its threshold for two consecutive months, the immediate priority is to investigate the root cause and assess whether the risk is materializing. Escalating to the risk owner ensures that the appropriate subject matter expert analyzes the situation, determines if controls are failing, and decides on corrective actions. Revising the threshold or replacing the KRI without investigation would bypass the monitoring and response process, potentially masking a real risk event.

Exam trap

The trap here is that candidates assume a breached KRI automatically means the threshold is wrong, leading them to choose threshold revision (Option A) instead of recognizing that the immediate action must be investigation to determine if the risk is materializing.

How to eliminate wrong answers

Option A is wrong because revising the KRI threshold to a higher value without investigation would arbitrarily reduce sensitivity and could hide a genuine increase in risk exposure, violating the principle that KRIs should be objective and aligned with risk appetite. Option B is wrong because archiving the current KRI and defining a new one without understanding why the threshold was breached discards valuable monitoring data and fails to address the underlying risk condition. Option C is wrong because updating the risk register with the new KRI value is a documentation step that should follow investigation and remediation, not be the immediate action when a threshold breach indicates a potential risk event.

192
MCQeasy

A company implements a new automated control to monitor user access rights. The control sends a daily report of any users with excessive privileges. What is the PRIMARY benefit of this control?

A.Enables timely remediation of access violations
B.Reduces the number of user access reviews
C.Eliminates the need for manual checks
D.Provides real-time alerts for critical changes
AnswerA

Daily reports allow prompt action to reduce risk.

Why this answer

The primary benefit of an automated control that sends a daily report of users with excessive privileges is that it enables timely remediation of access violations. By providing a regular, scheduled summary of privilege anomalies, the control allows the IT security team to investigate and revoke unauthorized access within a defined timeframe (e.g., 24 hours), reducing the window of exposure. This aligns with the principle of continuous monitoring and rapid response, which is critical for minimizing risk from privilege creep or misconfigured roles.

Exam trap

The trap here is that candidates confuse 'automated reporting' with 'real-time alerting' or assume that automation completely replaces manual processes, but the question specifically describes a daily report, which is a detective control focused on timely (not immediate) remediation, not a preventive or real-time control.

How to eliminate wrong answers

Option B is wrong because the control does not reduce the number of user access reviews; it automates the detection of excessive privileges, but periodic manual reviews (e.g., quarterly recertifications) are still required by compliance frameworks like SOX or PCI DSS to validate that access is appropriate. Option C is wrong because the control does not eliminate the need for manual checks; it only automates the reporting of excessive privileges, but manual verification of the report's accuracy, investigation of false positives, and remediation actions are still necessary. Option D is wrong because the control sends a daily report, not real-time alerts; real-time alerts would require a different mechanism (e.g., SIEM correlation rules or syslog triggers) that immediately notify on privilege changes, whereas this control is batch-oriented and designed for periodic review.

193
MCQeasy

Which of the following is the BEST indicator that an organization's IT risk assessment process is effective?

A.The risk register contains a large number of risks
B.Risk appetite statements are clearly defined
C.Risk assessments are performed annually
D.Risk treatment plans are implemented within agreed timelines
AnswerD

Implementation shows action.

Why this answer

The effectiveness of an IT risk assessment process is ultimately measured by whether identified risks are actually treated within agreed timelines. Option D directly demonstrates that the organization moves from risk identification to remediation, closing the risk management loop. Without timely implementation of treatment plans, even the most thorough risk assessments provide no reduction in actual risk exposure.

Exam trap

The trap here is that candidates confuse inputs or prerequisites (like risk appetite or scheduled assessments) with the output-based evidence of effectiveness, which is the actual closure of risk treatment actions within agreed timelines.

How to eliminate wrong answers

Option A is wrong because a large number of risks in the register does not indicate effectiveness; it may indicate poor risk aggregation, excessive risk tolerance, or failure to treat risks. Option B is wrong because clearly defined risk appetite statements are a prerequisite for effective risk assessment, not a measure of the assessment process itself. Option C is wrong because performing risk assessments annually only indicates compliance with a schedule, not that the assessments are accurate, actionable, or lead to risk reduction.

194
MCQhard

An organization's risk committee reviews a risk heat map showing that a key IT risk has moved from the "high" to "medium" category. However, the associated control's effectiveness has decreased from 95% to 85%. What is the most likely explanation?

A.The control testing frequency was increased.
B.The inherent risk has decreased due to external factors.
C.The risk assessment methodology was changed.
D.The control owner has implemented additional compensating controls.
AnswerB

A decrease in inherent risk can lower overall risk even if control effectiveness drops.

Why this answer

The risk heat map shows a reduction in residual risk from high to medium, yet the control effectiveness dropped from 95% to 85%. This apparent contradiction is best explained by a decrease in inherent risk—the risk before controls are applied. If inherent risk falls (e.g., due to external factors like new regulations or reduced threat activity), the residual risk can decrease even if the control becomes less effective, because the starting risk level is lower.

Exam trap

The trap here is that candidates assume a decrease in control effectiveness must always increase residual risk, ignoring that a simultaneous decrease in inherent risk can more than compensate, leading to a net reduction in residual risk.

How to eliminate wrong answers

Option A is wrong because increasing control testing frequency typically improves control effectiveness or detects failures earlier, not decreases it; it would not cause effectiveness to drop from 95% to 85%. Option C is wrong because changing the risk assessment methodology could alter how risk is categorized, but the question states the control's effectiveness has measurably decreased, which is a factual change in control performance, not a methodological reclassification. Option D is wrong because implementing additional compensating controls would generally increase overall control effectiveness or at least maintain it, not reduce it from 95% to 85%.

195
MCQmedium

A healthcare organization is implementing a new electronic health records (EHR) system. During the risk assessment, the risk practitioner discovers that the system's access control mechanism allows any authenticated user to view patient records without additional authorization checks. This violates the principle of least privilege and could lead to unauthorized disclosure of protected health information (PHI). The IT team proposes implementing role-based access control (RBAC), but it will require significant changes to the system configuration and user training. The project manager is concerned about delays to the go-live date. The organization has a moderate risk appetite but must comply with HIPAA regulations. Which of the following actions should the risk practitioner recommend FIRST?

A.Accept the risk because the likelihood of unauthorized access is low.
B.Implement a temporary compensating control, such as logging and monitoring all accesses to patient records, and proceed with go-live while RBAC is developed.
C.Proceed with the go-live as scheduled and plan to implement RBAC in a future upgrade.
D.Delay the go-live until RBAC is fully implemented to ensure compliance.
AnswerB

Compensating controls reduce risk while avoiding delays.

Why this answer

It balances the immediate need to go live with the critical requirement to protect PHI. Logging and monitoring all accesses acts as a detective compensating control, providing visibility into unauthorized disclosures while the more robust RBAC preventive control is developed. This approach aligns with the organization's moderate risk appetite and HIPAA compliance obligations by not accepting the risk outright, but also not delaying the project unnecessarily.

Exam trap

The trap here is that candidates often choose 'accept the risk' (A) or 'delay go-live' (D) because they focus on either risk appetite or compliance in isolation, failing to recognize that compensating controls can bridge the gap between operational urgency and regulatory requirements.

How to eliminate wrong answers

Option A is wrong because accepting the risk of unauthorized PHI disclosure violates HIPAA's requirement for appropriate administrative, physical, and technical safeguards, and the likelihood of unauthorized access is not low given that any authenticated user can view records. Option C is wrong because proceeding with go-live without any compensating control and planning RBAC for a future upgrade leaves a known high-risk vulnerability unaddressed, which is not acceptable under HIPAA's 'addressable' implementation specifications. Option D is wrong because delaying go-live until RBAC is fully implemented, while technically compliant, is overly conservative for an organization with a moderate risk appetite and ignores the possibility of using compensating controls to mitigate the risk in the interim.

196
Multi-Selecthard

A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?

Select 3 answers
A.The impact of the risk on operational productivity
B.The likelihood of the threat event occurring
C.The cost of the insurance premium relative to the expected loss
D.The residual risk after insurance is applied
E.The extent of coverage and exclusions in the policy
AnswersC, D, E

Cost-benefit analysis ensures the transfer is economically justified.

Why this answer

Risk transfer effectiveness depends on policy coverage, residual risk after transfer, and cost-benefit. Likelihood reduction is not directly applicable as transfer does not reduce likelihood.

197
MCQhard

An organization uses AI/ML for credit scoring decisions. The risk manager is concerned about regulatory compliance if the model cannot explain its decisions. Which AI risk is most directly addressed by requiring explainability?

A.Data privacy in AI training
B.Vendor lock-in
C.Adversarial attacks
D.Model bias
AnswerD

Explainability helps identify and mitigate bias in AI decisions.

Why this answer

Requiring explainability in an AI/ML credit scoring model directly addresses model bias because it forces the model to reveal which input features (e.g., income, zip code) drive its decisions. Without explainability, the organization cannot detect or prove that the model is not discriminating against protected groups, violating regulations like the Equal Credit Opportunity Act (ECOA) or GDPR's right to explanation. Explainability is the primary technical control to audit and mitigate bias in automated decision-making.

Exam trap

The trap here is that candidates confuse 'model bias' with 'data privacy' or 'adversarial attacks,' but the question specifically ties explainability to regulatory compliance, which is fundamentally about detecting and proving fairness (bias), not about data protection or input manipulation.

How to eliminate wrong answers

Option A is wrong because data privacy in AI training concerns how personal data is collected, stored, and used during model training (e.g., GDPR Article 5), not the model's ability to explain its outputs. Option B is wrong because vendor lock-in refers to dependency on a single vendor's proprietary platform or tools, which is unrelated to the model's interpretability or regulatory compliance. Option C is wrong because adversarial attacks involve manipulating input data to fool the model (e.g., adding noise to evade detection), which is a security risk, not a compliance risk addressed by explainability.

198
MCQmedium

An organization's risk register contains a risk with a very high impact but very low likelihood. The risk response strategy should be:

A.Mitigate
B.Avoid
C.Transfer
D.Accept
AnswerD

Acceptance is common for low-likelihood, high-impact risks.

Why this answer

When a risk has very high impact but very low likelihood, the most cost-effective response is often acceptance, because the probability of occurrence is so low that the cost of mitigation, avoidance, or transfer would exceed the expected benefit. Accepting the risk means the organization formally acknowledges it and monitors it, but does not allocate resources to reduce or transfer it. This aligns with the principle of risk appetite and cost-benefit analysis in IT risk management.

Exam trap

The trap here is that candidates mistakenly choose 'Mitigate' or 'Transfer' for any high-impact risk, failing to weigh the low likelihood against the cost of the response, which is a core concept in risk treatment decisions.

How to eliminate wrong answers

Option A is wrong because mitigation involves reducing the likelihood or impact through controls, which would incur ongoing costs that are not justified for a risk with very low likelihood. Option B is wrong because avoidance means eliminating the risk entirely by discontinuing the activity, which is an extreme measure that would likely disrupt business operations unnecessarily for a low-probability event. Option C is wrong because transfer (e.g., insurance or outsourcing) typically involves premium payments or contractual costs that are not warranted when the likelihood of the risk materializing is negligible.

199
MCQeasy

An organization is implementing a new identity and access management (IAM) system. The risk manager is tasked with identifying risks associated with the migration from legacy authentication to single sign-on (SSO). Which of the following is the GREATEST risk during this migration?

A.Users may reuse strong passwords across multiple systems.
B.Users may experience increased convenience, leading to reduced security awareness.
C.Legacy authentication accounts may remain active, creating orphan accounts.
D.Help desk call volumes may increase due to SSO authentication failures.
AnswerC

Orphan accounts are a high-risk security issue if not disabled.

Why this answer

Legacy accounts that are not disabled after migration become unmanaged orphan accounts, which can be exploited by attackers, posing a significant security risk. Option A is less severe because password reuse, while a risk, is not unique to this migration and is generally mitigated by SSO policies. Option B is incorrect because increased convenience does not inherently reduce security awareness; in fact, SSO can improve security by reducing password fatigue.

Option D is incorrect because while help desk call volumes may initially rise, this is an operational issue, not a security risk, and is typically temporary.

200
MCQmedium

An organization identifies a risk that is within its risk appetite. The risk owner decides to formally document the risk and accept it without implementing additional controls. Which of the following is required for this risk acceptance?

A.Avoidance of the business process
B.Transfer of risk to an insurance provider
C.Formal sign-off by the risk owner
D.Implementation of compensating controls
AnswerC

Acceptance requires documented acknowledgment and approval from the risk owner.

Why this answer

Acceptance requires formal documentation and sign-off by the risk owner, acknowledging the risk within appetite.

201
Multi-Selecthard

Which THREE of the following are typical components of a risk scenario?

Select 3 answers
A.Impact
B.Threat source
C.Probability
D.Vulnerability
E.Control
AnswersA, B, D

Describes the consequence of the event.

Why this answer

Impact is a typical component of a risk scenario because it defines the magnitude of harm to assets or business objectives if a threat exploits a vulnerability. In IT risk assessment, impact is quantified in terms of financial loss, reputational damage, or operational disruption, and it directly influences risk level calculations. Without impact, a risk scenario would lack the consequence necessary for prioritization and decision-making.

Exam trap

The trap here is that candidates confuse the components of a risk scenario (threat source, vulnerability, impact) with the elements of risk analysis (probability, control effectiveness), leading them to incorrectly select Probability or Control as scenario components.

202
Multi-Selectmedium

An organization is assessing control effectiveness for a key process. Which TWO aspects should be evaluated to determine if a control is effective?

Select 2 answers
A.Operating effectiveness
B.Compliance with industry standards
C.Number of control owners
D.Design adequacy
E.Cost of implementation
AnswersA, D

The control must operate as designed in practice.

Why this answer

Control effectiveness is assessed based on design adequacy (whether the control is properly designed) and operating effectiveness (whether it works as intended).

203
MCQmedium

Which of the following is a leading Key Risk Indicator (KRI) for the risk of a data breach?

A.Average time to detect a breach
B.Number of data breaches in the past quarter
C.Percentage of systems with unpatched critical vulnerabilities
D.Number of security incidents closed
AnswerC

This is a leading indicator; a high percentage suggests increased risk of future breaches.

Why this answer

A leading KRI predicts future risk events. The percentage of systems with unpatched critical vulnerabilities directly indicates an increasing attack surface and likelihood of exploitation, making it a leading indicator for a data breach. In contrast, lagging indicators like detection time or breach count measure past incidents.

Exam trap

The trap here is that candidates confuse lagging indicators (like breach count or detection time) with leading indicators, failing to recognize that a leading KRI must predict future risk, not measure past events.

How to eliminate wrong answers

Option A is wrong because average time to detect a breach (Mean Time to Detect, MTTD) is a lagging indicator that measures the effectiveness of detection controls after a breach has occurred, not a predictor of future breaches. Option B is wrong because the number of data breaches in the past quarter is a lagging indicator that reports historical incidents, providing no forward-looking insight into the likelihood of a future breach. Option D is wrong because the number of security incidents closed is a lagging operational metric reflecting past remediation activity, not a leading indicator of breach risk.

204
MCQhard

A large financial services firm recently deployed a new security information and event management (SIEM) system to monitor thousands of servers, network devices, and applications. The system is generating over 1,000 alerts per hour, of which 80% are false positives. The security operations center (SOC) team is overwhelmed and has started ignoring all but the most critical alerts. As a result, a real attack recently went undetected for 48 hours. The risk manager is asked to recommend improvements. The SOC team has 12 analysts working in shifts. The SIEM is properly configured but the correlation rules are broad and noisy. The firm cannot add more staff due to budget freeze. What should the risk manager prioritize?

A.Disable all low-priority alerts to reduce volume immediately.
B.Implement a machine learning algorithm to automatically classify alerts.
C.Tune the alerting rules and adopt risk-based prioritization to filter out known false positives.
D.Request budget to hire five additional SOC analysts.
AnswerC

Tuning alerting rules with risk-based prioritization directly reduces noise and ensures the SOC focuses on true positives; this is the most feasible and effective improvement.

Why this answer

Tuning alerting rules with risk-based prioritization reduces noise and ensures the SOC focuses on true positives. Disabling low-priority alerts (A) may cause missing important events; hiring (D) is not feasible due to budget freeze; machine learning (B) is complex and still needs tuning.

205
MCQhard

An organization is assessing the risk of a ransomware attack. The threat actor capability is high, but vulnerability is low due to strong patching. However, the business impact is severe. According to FAIR, which factor most directly influences Loss Event Frequency (LEF)?

A.Vulnerability severity
B.Threat actor capability and motivation
C.Control effectiveness
D.Business impact severity
AnswerA

Vulnerability directly multiplies TEF to determine LEF.

Why this answer

In FAIR, Loss Event Frequency (LEF) is directly influenced by the probability that a threat actor will successfully exploit a vulnerability. Vulnerability severity (how easily a vulnerability can be exploited) is a key component of the 'Vulnerability' factor in FAIR's decomposition, which feeds into LEF. Even with high threat capability and severe impact, if vulnerability is low (strong patching), LEF remains low because the attack is unlikely to succeed.

Exam trap

The ISACA CRISC exam often tests the distinction between factors that affect LEF (vulnerability and threat event frequency) versus factors that affect loss magnitude (impact), so candidates mistakenly pick 'business impact severity' because it seems most urgent, but it does not influence how often an attack succeeds.

How to eliminate wrong answers

Option B is wrong because threat actor capability and motivation influence the 'Threat Event Frequency' (TEF), not directly LEF; LEF is the product of TEF and the probability of successful exploitation (vulnerability). Option C is wrong because control effectiveness is an input that reduces either vulnerability or threat frequency, but it is not the direct factor; FAIR decomposes LEF into 'Threat Event Frequency' and 'Vulnerability' (which includes control strength). Option D is wrong because business impact severity influences 'Loss Magnitude', not LEF; LEF is about how often losses occur, not their size.

206
MCQhard

During a risk assessment, an organization identifies that its remote workforce uses personal devices for work. The risk manager is concerned about data leakage. The organization has a risk appetite that is 'moderate' and wants to treat the risk. Which of the following is the MOST effective risk treatment option?

A.Implement a VPN for remote access
B.Require full disk encryption on all personal devices
C.Implement a Mobile Device Management (MDM) policy with containerization
D.Ban the use of personal devices for work
AnswerC

MDM with containerization provides a secure work environment on personal devices.

Why this answer

The most effective because MDM with containerization creates a separate, encrypted work profile on the personal device, isolating corporate data from personal apps and data. This directly addresses data leakage by enforcing security policies (e.g., remote wipe of the work container only) without requiring full control over the entire device, aligning with a 'moderate' risk appetite that seeks a balance between security and usability.

Exam trap

The trap here is that candidates often confuse 'encryption' (Option B) with 'data leakage prevention'—full disk encryption protects data at rest but does not control data flow between apps or enable selective wipe, making it less effective than containerization for a moderate risk appetite where usability and privacy are key considerations.

How to eliminate wrong answers

Option A is wrong because a VPN only encrypts data in transit between the device and the corporate network; it does not protect data at rest on the device, so if the device is lost or compromised, stored corporate data remains vulnerable to leakage. Option B is wrong because requiring full disk encryption on all personal devices is overly invasive for a moderate risk appetite—it encrypts the entire device, including personal data, and does not provide granular control over corporate data (e.g., selective wipe), potentially violating user privacy and causing resistance. Option D is wrong because banning personal devices outright is a risk avoidance strategy, not a treatment; it may reduce productivity and employee satisfaction, and it fails to address the organization's need to support a remote workforce while managing risk at an acceptable level.

207
Multi-Selecteasy

Which TWO of the following are key elements that should be included in an IT risk assessment report?

Select 2 answers
A.A list of identified risks and their ratings
B.Recommendations for risk treatment
C.Copies of vendor contracts
D.Network topology diagrams
E.Detailed financial budgets of the IT department
AnswersA, B

Risk inventory is fundamental.

Why this answer

The IT risk assessment report must document all identified risks along with their inherent and residual risk ratings (typically using a qualitative or quantitative scale such as 1-5 for likelihood and impact). This provides a clear, prioritized view of the risk landscape, enabling stakeholders to understand which risks require immediate attention. Without this list and ratings, the report lacks the foundational data needed for decision-making.

Exam trap

The trap here is that candidates confuse supporting documentation (like vendor contracts or network diagrams) with the core required elements of a risk assessment report, which must focus on risk identification, ratings, and treatment recommendations.

208
MCQmedium

A large healthcare organization is implementing a new electronic health record (EHR) system. During the risk identification process, the risk team discovers that the EHR vendor has a history of minor security incidents but has always resolved them quickly. The vendor’s data center is located in a region prone to earthquakes. Additionally, the EHR system will integrate with several legacy systems that have known vulnerabilities. The project sponsor is keen to proceed and believes the vendor is reputable. The risk team needs to ensure all relevant risks are identified and documented. Which of the following should be the PRIORITY for the risk team?

A.Conduct a detailed assessment of the vendor's business continuity and disaster recovery plans, especially regarding natural disasters.
B.Request the vendor to patch the legacy system vulnerabilities before integration.
C.Focus on contractual indemnification clauses to transfer risk.
D.Accept the residual risk after implementing basic controls.
AnswerA

BCP/DR assessment addresses the earthquake risk directly.

Why this answer

The vendor's data center is in an earthquake-prone region, and the vendor has a history of minor security incidents. This creates a significant risk of service disruption that could impact patient safety and data availability. Prioritizing a detailed assessment of the vendor's business continuity and disaster recovery (BC/DR) plans ensures that the organization understands the vendor's ability to maintain operations and recover data in a disaster scenario, which is a fundamental risk identification activity before any mitigation or acceptance decisions.

Exam trap

The trap here is that candidates may focus on the legacy system vulnerabilities (Option B) because they are a known technical issue, but the question specifically prioritizes the vendor's data center risk, which is a higher-level business continuity concern that could render all other controls irrelevant if the vendor's site goes offline.

How to eliminate wrong answers

Option B is wrong because the legacy system vulnerabilities are owned by the healthcare organization, not the vendor; requesting the vendor to patch them is outside the vendor's responsibility and does not address the immediate risk of the vendor's data center location. Option C is wrong because focusing on contractual indemnification clauses is a risk transfer strategy that occurs after risks are fully identified and assessed, not a priority during the risk identification phase. Option D is wrong because accepting residual risk after implementing basic controls is premature; the risk team must first identify and analyze all relevant risks, including the vendor's BC/DR capabilities, before any acceptance decision can be made.

209
MCQmedium

A financial institution uses a third-party cloud service for data analytics. The service has access to non-public personal information (NPI). During a risk assessment, the risk manager discovers that the cloud provider uses subprocessors without notifying the institution. The contract does not require notification of subprocessor changes. What should the risk manager do FIRST?

A.Notify the vendor of the contract breach and request a list of all subprocessors and their compliance certifications.
B.Report the incident to the data protection authority as a breach of contract.
C.Accept the risk since the vendor remains SOC 2 Type II certified.
D.Terminate the contract immediately to mitigate the risk of unauthorized data access.
AnswerA

Immediate termination may disrupt operations; the first step should be to notify the vendor of the breach and request a list of subprocessors to assess risk.

Why this answer

The first step is to notify the vendor of the contract breach and request a list of all subprocessors to assess the risk. Option B is wrong because reporting to the data protection authority before attempting to resolve the issue with the vendor is premature. Option C is wrong because accepting risk without understanding the subprocessors' controls is not prudent; the risk manager should first gather information.

Option D is wrong because immediately terminating the contract could cause significant business disruption and is not the first step.

210
MCQhard

A financial institution is integrating a new cloud-based analytics platform that will process sensitive customer data. The project team is conducting risk identification. Which technique would be MOST effective for identifying risks related to the integration of this platform with existing on-premises systems?

A.Vulnerability scanning of the cloud platform's API endpoints.
B.Brainstorming sessions with the project team.
C.Threat modeling of the integration architecture.
D.SWOT analysis to assess strengths, weaknesses, opportunities, and threats.
AnswerC

Threat modeling systematically identifies threats to the integration points, such as data flow, trust boundaries, and authentication.

Why this answer

Threat modeling of the integration architecture is the most effective technique because it systematically identifies potential security threats, attack vectors, and vulnerabilities specific to the data flows, trust boundaries, and API interactions between the cloud-based analytics platform and existing on-premises systems. Unlike generic methods, threat modeling (e.g., STRIDE or PASTA) focuses on the unique integration points, such as authentication handshakes, data-in-transit encryption (TLS 1.2/1.3), and session management, which are critical for protecting sensitive customer data during integration.

Exam trap

The trap here is that candidates often choose vulnerability scanning (Option A) because they mistakenly believe that scanning API endpoints is sufficient for integration risk identification, but vulnerability scanning only finds known flaws in the API code, not architectural threats like insecure data flows or trust boundary violations that threat modeling uniquely addresses.

How to eliminate wrong answers

Option A is wrong because vulnerability scanning of the cloud platform's API endpoints is a reactive, point-in-time assessment that only identifies known software vulnerabilities (e.g., CVEs) in the API implementation, but it does not proactively analyze the overall integration architecture, data flows, or trust boundaries between cloud and on-premises systems. Option B is wrong because brainstorming sessions with the project team, while useful for generating ideas, lack a structured methodology and can miss subtle, architecture-specific threats like privilege escalation via misconfigured cross-origin resource sharing (CORS) or insecure direct object references (IDOR) in the integration layer. Option D is wrong because SWOT analysis is a high-level strategic planning tool that assesses strengths, weaknesses, opportunities, and threats at a business or project level, but it does not provide the technical depth needed to identify specific integration risks such as API gateway misconfigurations, token replay attacks, or data leakage through logging.

211
MCQmedium

During a risk assessment for a cloud migration project, the IT risk manager identifies that the organization lacks visibility into the cloud provider's security controls. Which approach should the risk manager recommend to address this risk?

A.Obtain a third-party audit report (e.g., SOC 2 Type II).
B.Request the provider to self-attest their controls.
C.Accept the risk based on the provider's reputation.
D.Conduct a penetration test on the provider's infrastructure.
AnswerA

Provides independent assurance of control effectiveness.

Why this answer

A SOC 2 Type II report provides an independent, third-party assessment of a cloud provider's controls over a period of time, directly addressing the lack of visibility by offering verifiable evidence of control effectiveness. This is the standard approach for gaining assurance over a provider's security posture without relying on internal access or self-reporting.

Exam trap

The trap here is that candidates may choose penetration testing (D) as a direct technical solution, not realizing that cloud providers typically restrict such testing and that a SOC 2 report is the established, non-invasive method for gaining visibility into a provider's controls.

How to eliminate wrong answers

Option B is wrong because self-attestation lacks independent verification and is inherently biased, providing no reliable assurance to the risk manager. Option C is wrong because accepting risk based solely on reputation ignores the specific control environment and does not provide any evidence or visibility into actual security practices. Option D is wrong because conducting a penetration test on the provider's infrastructure is typically prohibited by the provider's terms of service and would not be feasible or authorized without a contractual agreement, nor does it replace the need for ongoing control assurance.

212
MCQmedium

In qualitative risk analysis, a risk with a likelihood rating of 'High' and an impact rating of 'High' on a 5×5 heat map would typically be classified as:

A.High
B.Low
C.Critical
D.Medium
AnswerC

The highest combination is often labeled critical.

Why this answer

A 5×5 heat map often uses 'Critical' for the highest risk level (5×5).

213
MCQeasy

During a control self-assessment, an operational manager reports that a manual review control is performed quarterly instead of monthly as documented. What should the risk practitioner do?

A.Accept the change without documentation since risk level is unchanged
B.Escalate the deviation to senior management for disciplinary action
C.Update the control frequency in the risk register and assess residual risk
D.Require the manager to resume monthly reviews immediately
AnswerC

Accurate documentation and risk assessment are key.

Why this answer

The risk practitioner must update the control frequency in the risk register to reflect the actual operating reality (quarterly instead of monthly) and then reassess the residual risk. This ensures the risk register remains accurate and the risk exposure is properly evaluated based on the current control effectiveness. Simply accepting the change without documentation (A) or forcing immediate resumption (D) ignores the need for risk reassessment, while escalating for disciplinary action (B) is premature and not the primary risk management action.

Exam trap

The trap here is that candidates assume any deviation from documented controls must be immediately corrected or punished, rather than recognizing that the risk practitioner's primary duty is to update the risk register and reassess residual risk based on the actual control state.

How to eliminate wrong answers

Option A is wrong because accepting the change without documentation violates the principle of maintaining an accurate risk register; even if the risk level appears unchanged, the deviation must be formally recorded and the residual risk reassessed. Option B is wrong because escalating for disciplinary action is an overreaction and not the immediate risk management step; the focus should be on understanding the impact on risk exposure, not punishing the manager. Option D is wrong because requiring the manager to resume monthly reviews immediately ignores the possibility that the quarterly frequency may still be adequate after reassessment, and it bypasses the proper risk analysis and documentation process.

214
MCQeasy

A risk assessment reveals that a data center is located in a flood-prone area. The organization decides to build a secondary data center in a different region and replicate critical data between both sites. This is an example of which risk response?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerB

Mitigation reduces risk through controls like replication.

Why this answer

Building a secondary data center in a different region and replicating critical data between both sites reduces the likelihood and impact of a flood-related outage. This is a classic risk mitigation response because it implements controls (geographic redundancy, data replication) to lower residual risk to an acceptable level, without eliminating the original flood risk entirely.

Exam trap

The trap here is confusing risk mitigation (reducing impact via redundancy) with risk avoidance (eliminating the threat by moving), leading candidates to incorrectly select risk avoidance when the primary site is not decommissioned.

How to eliminate wrong answers

Option A is wrong because risk acceptance would involve acknowledging the flood risk and taking no proactive action, which is not the case here. Option C is wrong because risk avoidance would require relocating the primary data center away from the flood-prone area entirely, not building a secondary site while keeping the original operational. Option D is wrong because risk transfer would involve shifting the financial impact of a flood to a third party (e.g., via insurance or outsourcing), not deploying technical redundancy controls.

215
Multi-Selectmedium

A risk manager is assessing the risks of an IT/OT convergence project in a chemical plant. Which TWO of the following are the most significant security risks? (Select two.)

Select 2 answers
A.Increased attack surface from IT network to OT systems
B.Increased need for IT support staff
C.Higher bandwidth consumption on OT networks
D.Loss of real-time visibility for operators
E.Inability to apply patches to legacy ICS devices
AnswersA, E

This is a primary risk, as attackers can pivot from IT to OT.

Why this answer

A is correct because IT/OT convergence directly connects corporate IT networks to operational technology (OT) systems, expanding the attack surface. Attackers can pivot from IT to OT via protocols like Modbus/TCP or OPC UA, potentially disrupting critical industrial processes. This is the most significant risk as it introduces new vectors for ransomware or sabotage that were previously isolated by air gaps.

Exam trap

ISACA CRISC often tests the distinction between operational/reliability issues and actual security risks, so candidates mistakenly select 'loss of real-time visibility' or 'higher bandwidth' as security risks when they are not.

216
MCQmedium

An organization is evaluating risks and decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk treatment option does this represent?

A.Transfer
B.Accept
C.Mitigate
D.Avoid
AnswerA

Insurance transfers financial risk to the insurer.

Why this answer

Transfer involves shifting risk to a third party, such as through insurance or outsourcing with liability transfer.

217
MCQhard

A company uses a dashboard to monitor KRIs. One KRI shows a warning level, but the data is two months old. What is the primary concern?

A.The KRI is not relevant.
B.The dashboard is not user-friendly.
C.The threshold is too low.
D.The monitoring is not timely.
AnswerD

Outdated data prevents timely identification and response to risk changes.

Why this answer

The primary concern with a KRI showing a warning level based on data that is two months old is that the monitoring is not timely. Timeliness is a critical attribute of effective Key Risk Indicators (KRIs) because risk conditions can change rapidly; stale data renders the warning obsolete and may lead to incorrect risk decisions. Without current data, the organization cannot respond to emerging threats or control failures in a relevant timeframe, undermining the entire monitoring process.

Exam trap

The trap here is that candidates may focus on the 'warning level' and assume the threshold is too low (Option C), but the real issue is the latency of the data, not the threshold's calibration.

How to eliminate wrong answers

Option A is wrong because the KRI's relevance is not determined by data age; a KRI can be perfectly relevant to the risk but still fail if the data is not current. Option B is wrong because the dashboard's user-friendliness is a usability concern, not the core issue when the underlying data is stale; even a highly intuitive dashboard cannot compensate for outdated information. Option C is wrong because the threshold being too low would cause frequent warnings, but the problem here is the delay in data collection, not the sensitivity of the threshold.

218
MCQeasy

Which of the following is a threat intelligence source that provides information about known exploited vulnerabilities, maintained by a government agency?

A.OSINT
B.NVD
C.CISA KEV
D.ISACs
AnswerC

Why this answer

CISA KEV (Known Exploited Vulnerabilities catalog) is maintained by the U.S. Cybersecurity and Infrastructure Security Agency and provides a list of vulnerabilities that have been exploited in the wild.

219
MCQeasy

Which type of threat actor is characterized by having significant resources, advanced skills, and often state-sponsored objectives?

A.Script kiddies
B.Organized crime
C.Nation-state APTs
D.Hacktivists
AnswerC

Nation-state APTs are highly resourced and state-backed.

Why this answer

Nation-state Advanced Persistent Threats (APTs) are sophisticated, well-funded, and often state-sponsored.

220
MCQhard

A multinational organization is assessing the risk of a new cloud service that stores data across multiple geographic regions. The service provider offers standard contractual terms and does not commit to specific data residency requirements. What is the primary risk that should be evaluated?

A.Service availability and uptime commitments.
B.Non-compliance with data protection regulations due to data location uncertainty.
C.Unauthorized access to data by cloud provider employees.
D.Inadequate encryption of data at rest and in transit.
AnswerB

Without data residency commitments, the organization may violate laws requiring data to stay within certain jurisdictions.

Why this answer

The primary risk is non-compliance with data protection regulations due to uncertain data location (Option B). Because the provider does not commit to specific data residency, the organization cannot guarantee compliance with laws like GDPR that impose strict requirements on where data is stored and processed. This legal exposure outweighs the other options, as it could lead to fines and legal penalties.

221
MCQhard

Refer to the exhibit. What risk is introduced by this IAM policy?

A.Misconfigured encryption
B.Lack of logging
C.Excessive permissions
D.Weak authentication
AnswerC

The policy grants full access to all resources, creating a risk of privilege abuse.

Why this answer

The IAM policy grants `s3:*` actions on all S3 resources (`"Resource": "*"`), which allows any user or service assuming this role to perform any S3 operation, including deleting buckets, modifying permissions, or accessing all objects. This violates the principle of least privilege and introduces the risk of excessive permissions, as the policy does not restrict actions or resources to only what is necessary for the intended function.

Exam trap

The trap here is that candidates may focus on the absence of encryption or logging keywords in the policy, but the core risk is the overly broad action and resource scope, which is a classic excessive permissions vulnerability.

How to eliminate wrong answers

Option A is wrong because the policy does not reference encryption settings, KMS keys, or any condition that would misconfigure encryption; the risk is about authorization scope, not data protection configuration. Option B is wrong because the policy does not disable or omit logging settings; CloudTrail or S3 server access logging are independent of IAM policy statements and are not addressed here. Option D is wrong because the policy does not define authentication mechanisms, password policies, or MFA requirements; it only specifies allowed actions and resources after authentication has already occurred.

222
MCQmedium

After a security incident, a company implements a new control and begins monitoring its effectiveness. Which of the following metrics would BEST indicate that the control is achieving its objective?

A.Decrease in the number of successful attacks.
B.Reduction in the number of vulnerabilities.
C.Number of incidents reported.
D.Time to detect incidents.
AnswerA

Directly reflects the control's ability to prevent or mitigate attacks.

Why this answer

A decrease in the number of successful attacks directly measures the control's primary objective: preventing or mitigating actual security breaches. If the control is effective, it should stop or reduce the frequency of attacks that compromise the system, making this the most direct indicator of success.

Exam trap

The trap here is confusing control effectiveness (preventing harm) with control efficiency (reducing vulnerabilities or improving detection speed), leading candidates to pick metrics that measure secondary benefits rather than the primary objective.

How to eliminate wrong answers

Option B is wrong because a reduction in vulnerabilities is a measure of the control's ability to patch or remove weaknesses, not necessarily its effectiveness in preventing attacks; vulnerabilities may exist but not be exploited. Option C is wrong because the number of incidents reported includes both successful and attempted attacks, and a control might reduce successful attacks while incident reports remain high due to increased detection of attempts. Option D is wrong because time to detect incidents measures detection speed, not prevention; a control could be effective at preventing attacks but still have a slow detection time for those that bypass it.

223
MCQmedium

A bank's fraud detection system generates an alert for a transaction, but subsequent investigation finds it false. What should be done?

A.Document the false positive for trend analysis.
B.Report to the board.
C.Ignore future similar alerts.
D.Reduce the sensitivity of the detection system.
AnswerA

Tracking false positives helps identify patterns and improve the detection logic.

Why this answer

Documenting false positives enables trend analysis to identify patterns in detection logic errors, such as rule misconfigurations or data quality issues. This aligns with the CRISC domain of risk and control monitoring, where logging and analyzing false alerts improves detection accuracy over time without prematurely adjusting thresholds.

Exam trap

The trap here is that candidates may assume immediate corrective action (reducing sensitivity) is best, but CRISC emphasizes data-driven decision-making and documentation before making control changes.

How to eliminate wrong answers

Option B is wrong because reporting a single false positive to the board is not appropriate; board reporting is reserved for material risk events or systemic control failures, not routine operational noise. Option C is wrong because ignoring future similar alerts would create a blind spot, potentially allowing actual fraud to go undetected if the false positive pattern changes. Option D is wrong because reducing sensitivity without data-driven analysis could increase false negatives, missing genuine fraud; sensitivity should only be adjusted after analyzing false positive trends and impact on detection rates.

224
MCQmedium

An organization wants to identify risks related to third-party vendors. Which approach best supports continuous risk identification?

A.Contractual clauses requiring self-assessment
B.On-site audits every two years
C.Automated monitoring of vendor security controls via a third-party risk platform
D.Annual vendor risk assessments
AnswerC

Automated monitoring provides continuous insight into vendor security posture.

Why this answer

Automated monitoring via a third-party risk platform enables continuous, real-time visibility into vendor security controls, such as firewall rule changes, vulnerability scan results, and compliance posture. This approach aligns with the CRISC principle of ongoing risk identification, as it detects changes in risk exposure between formal assessment cycles without relying on periodic snapshots.

Exam trap

The trap here is that candidates often choose periodic assessments (A, B, or D) because they seem thorough, but CRISC emphasizes continuous risk identification over point-in-time reviews, and automated monitoring is the only option that provides real-time, ongoing visibility.

How to eliminate wrong answers

Option A is wrong because contractual clauses requiring self-assessment rely on vendor-reported data, which may be outdated, incomplete, or biased, and do not provide continuous or independent verification. Option B is wrong because on-site audits every two years are infrequent, static snapshots that miss interim changes in vendor environments, such as new vulnerabilities or configuration drift. Option D is wrong because annual vendor risk assessments are periodic and cannot capture risks that emerge between assessments, such as zero-day exploits or rapid cloud infrastructure changes.

225
MCQeasy

Refer to the exhibit. A risk practitioner is reviewing the access control list for a critical server. The ACL is applied inbound on the interface connecting to the internet. Which of the following is the MOST significant risk?

A.The ACL permits all HTTPS and DNS traffic from the subnet, increasing attack surface
B.The ACL has no logging enabled
C.The ACL is missing a permit statement for HTTP
D.The ACL blocks all traffic from the internet
AnswerA

Broad permits may allow unauthorized traffic.

Why this answer

Permitting all HTTPS (TCP/443) and DNS (UDP/53) traffic from any source on the internet to the critical server unnecessarily exposes the server to potential exploitation of vulnerabilities in the web server software (e.g., Apache, Nginx) and DNS resolver services. This broad permit statement increases the attack surface significantly, as HTTPS and DNS are common vectors for attacks such as SQL injection, cross-site scripting, and DNS amplification or tunneling. The risk is heightened because the ACL is applied inbound on the internet-facing interface, meaning all external traffic matching these protocols is allowed without restriction, bypassing any stateful inspection or application-layer filtering.

Exam trap

The trap here is that candidates often focus on missing logging (option B) or missing HTTP (option C) as the most critical issue, but the real risk is the overly permissive ACL that allows all HTTPS and DNS traffic from any source, which dramatically increases the attack surface and is a classic misconfiguration in ACL design.

How to eliminate wrong answers

Option B is wrong because the absence of logging is a monitoring deficiency, not the most significant risk; logging is important for forensic analysis but does not directly increase the attack surface or allow malicious traffic. Option C is wrong because HTTP (TCP/80) is not explicitly permitted, but this is a lesser risk compared to allowing all HTTPS and DNS traffic, as HTTP traffic would be blocked by default (implicit deny) and does not expose the server to the same volume of potential attacks. Option D is wrong because blocking all traffic from the internet would actually reduce risk by preventing external access entirely, though it may break legitimate business functionality; however, the question asks for the most significant risk, and blocking all traffic is a security measure, not a risk.

Page 2

Page 3 of 14

Page 4