Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 226–300

1062 questions total · 15pages · All types, answers revealed

Page 3

Page 4 of 15

Page 5
226
MCQhard

A risk practitioner is estimating the likelihood of a ransomware event affecting a manufacturing firm's operational technology environment. Historical incident data is sparse, so the practitioner convenes plant engineers, security staff, and the insurance broker to elicit calibrated estimates and combine them into a reasoned likelihood. Which technique is being used?

A.Delphi technique with structured expert elicitation.
B.Bayesian updating of the prior incident frequency.
C.Monte Carlo simulation of the plant's loss distribution.
D.Fault tree analysis of the ransomware attack path.
AnswerA

The Delphi technique gathers anonymous, iterative expert judgments and converges them toward a calibrated consensus, which fits sparse-data situations perfectly. By combining engineers, security, and the broker, the practitioner draws on operational, technical, and actuarial perspectives. Structured elicitation reduces anchoring and groupthink, producing a reasoned likelihood estimate where historical incident data alone cannot support one.

Why this answer

When incident data is too sparse to support statistical estimation, structured expert elicitation such as the Delphi technique is the appropriate way to generate calibrated likelihood estimates. It pools diverse expertise, uses anonymity and iteration to reduce bias, and converges on a defensible consensus. The resulting estimate can later feed quantitative models if data improves, keeping the analysis honest about its uncertainty.

Exam trap

The trap here is reaching for a quantitative model like Monte Carlo or Bayesian updating when the real problem is that no data exists yet to parameterize those models.

227
MCQhard

A risk practitioner is assessing the security of a new software-defined wide area network (SD-WAN) deployment that will carry regulated traffic between branch offices and a cloud environment. The vendor's controller is managed by a third party. Which of the following risks should the practitioner identify as the MOST significant?

A.The SD-WAN controller could be compromised through the third-party management interface, allowing policy manipulation and traffic redirection.
B.Branch office staff may bypass the SD-WAN by using personal mobile hotspots for internet access.
C.The organization may lose visibility into application performance across the SD-WAN fabric.
D.SD-WAN appliances may not support the organization's existing network access control (NAC) solution.
AnswerA

The SD-WAN controller is the central policy and orchestration point; if an attacker gains control through the third-party management plane, they can alter routing, disable encryption, or redirect regulated traffic. This represents a high-impact, high-likelihood risk given the external dependency. It directly threatens confidentiality and integrity of regulated data, making it the most significant risk.

Why this answer

In SD-WAN architectures, the controller is a high-value target because it defines and enforces forwarding, segmentation, and encryption policies across all sites. When that controller is managed by a third party, the organization inherits supply-chain and access-control risk. A compromise there can bypass many perimeter defenses and affect every branch simultaneously, so it warrants the greatest attention in a risk assessment of regulated traffic.

Exam trap

The trap here is focusing on endpoint or operational issues while overlooking that the centralized controller, especially when third-party managed, is the most consequential single point of failure.

228
MCQmedium

During a risk assessment for a cloud migration project, the IT risk manager identifies that the organization lacks visibility into the cloud provider's security controls. Which approach should the risk manager recommend to address this risk?

A.Obtain a third-party audit report (e.g., SOC 2 Type II).
B.Request the provider to self-attest their controls.
C.Accept the risk based on the provider's reputation.
D.Conduct a penetration test on the provider's infrastructure.
AnswerA

A SOC 2 Type II report provides independent attestation over the cloud provider's security controls across an observation period, directly closing the visibility gap identified in the stem. It evidences control design and operating effectiveness, letting the risk manager assess residual risk without relying on vendor self-assessment.

Why this answer

A SOC 2 Type II report provides an independent, third-party assessment of a cloud provider's controls over a period of time, directly addressing the lack of visibility by offering verifiable evidence of control effectiveness. This is the standard approach for gaining assurance over a provider's security posture without relying on internal access or self-reporting.

Exam trap

The trap here is that candidates may choose penetration testing (D) as a direct technical solution, not realizing that cloud providers typically restrict such testing and that a SOC 2 report is the established, non-invasive method for gaining visibility into a provider's controls.

How to eliminate wrong answers

Option B is wrong because self-attestation lacks independent verification and is inherently biased, providing no reliable assurance to the risk manager. Option C is wrong because accepting risk based solely on reputation ignores the specific control environment and does not provide any evidence or visibility into actual security practices. Option D is wrong because conducting a penetration test on the provider's infrastructure is typically prohibited by the provider's terms of service and would not be feasible or authorized without a contractual agreement, nor does it replace the need for ongoing control assurance.

229
MCQhard

A multinational retailer operates in 14 countries and must report IT risk to its board quarterly. The CISO wants the reporting to drive decisions rather than merely satisfy auditors. Which of the following is the MOST important characteristic of the quarterly IT risk report?

A.It links IT risk exposure to business objectives and states the residual risk against the board-approved risk appetite.
B.It reports the percentage of controls tested and the number of audit findings closed during the quarter.
C.It includes a complete inventory of every vulnerability detected during the quarter, ranked by CVSS score.
D.It compares the organization's risk scores with those of industry peers using a published benchmark.
AnswerA

Board-level reporting is effective only when it connects technology risk to the business outcomes the board cares about and expresses exposure relative to the approved risk appetite. This lets directors judge whether risk is within tolerance and where to direct resources. Raw technical metrics or control counts do not support that judgment, so business-aligned residual risk reporting is the most important characteristic in this scenario.

Why this answer

Effective board reporting translates IT risk into business terms and states residual risk relative to the board-approved risk appetite, enabling directors to make informed decisions about resource allocation and tolerance. Technical inventories, compliance activity metrics, and peer benchmarks may supplement the report but do not by themselves show whether the organization is operating within acceptable risk limits, which is the primary purpose of quarterly risk reporting to the board.

Exam trap

The trap here is equating volume of technical detail or compliance activity with decision-useful risk reporting, when boards need business-aligned residual risk against appetite.

230
MCQeasy

During a control self-assessment, an operational manager reports that a manual review control is performed quarterly instead of monthly as documented. What should the risk practitioner do?

A.Accept the change without documentation since risk level is unchanged
B.Escalate the deviation to senior management for disciplinary action
C.Update the control frequency in the risk register and assess residual risk
D.Require the manager to resume monthly reviews immediately
AnswerC

The documented frequency no longer reflects actual practise, so the risk register entry is inaccurate. Recording the quarterly frequency and reassessing residual risk restores alignment between documented controls and operational reality, giving management a true view of the risk exposure created by reduced review cadence.

Why this answer

The risk practitioner must update the control frequency in the risk register to reflect the actual operating reality (quarterly instead of monthly) and then reassess the residual risk. This ensures the risk register remains accurate and the risk exposure is properly evaluated based on the current control effectiveness. Simply accepting the change without documentation (A) or forcing immediate resumption (D) ignores the need for risk reassessment, while escalating for disciplinary action (B) is premature and not the primary risk management action.

Exam trap

The trap here is that candidates assume any deviation from documented controls must be immediately corrected or punished, rather than recognizing that the risk practitioner's primary duty is to update the risk register and reassess residual risk based on the actual control state.

How to eliminate wrong answers

Option A is wrong because accepting the change without documentation violates the principle of maintaining an accurate risk register; even if the risk level appears unchanged, the deviation must be formally recorded and the residual risk reassessed. Option B is wrong because escalating for disciplinary action is an overreaction and not the immediate risk management step; the focus should be on understanding the impact on risk exposure, not punishing the manager. Option D is wrong because requiring the manager to resume monthly reviews immediately ignores the possibility that the quarterly frequency may still be adequate after reassessment, and it bypasses the proper risk analysis and documentation process.

231
MCQeasy

A risk assessment reveals that a data center is located in a flood-prone area. The organization decides to build a secondary data center in a different region and replicate critical data between both sites. This is an example of which risk response?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerB

Building a secondary data centre in a different region directly reduces the likelihood and impact of flood disruption, satisfying the risk-assessment finding. Risk mitigation lowers risk through controls or redundancy, unlike avoidance (eliminating the activity), transfer (insurance), or acceptance. Replicating critical data to a separate site is a concrete mitigating control.

Why this answer

Building a secondary data center in a different region and replicating critical data between both sites reduces the likelihood and impact of a flood-related outage. This is a classic risk mitigation response because it implements controls (geographic redundancy, data replication) to lower residual risk to an acceptable level, without eliminating the original flood risk entirely.

Exam trap

The trap here is confusing risk mitigation (reducing impact via redundancy) with risk avoidance (eliminating the threat by moving), leading candidates to incorrectly select risk avoidance when the primary site is not decommissioned.

How to eliminate wrong answers

Option A is wrong because risk acceptance would involve acknowledging the flood risk and taking no proactive action, which is not the case here. Option C is wrong because risk avoidance would require relocating the primary data center away from the flood-prone area entirely, not building a secondary site while keeping the original operational. Option D is wrong because risk transfer would involve shifting the financial impact of a flood to a third party (e.g., via insurance or outsourcing), not deploying technical redundancy controls.

232
MCQmedium

Which of the following is the best example of a Key Control Indicator (KCI) for a firewall rule review process?

A.Number of firewall breaches per quarter
B.Percentage of firewall rules reviewed within the defined period
C.Number of firewall administrators
D.Time since last firewall software update
AnswerB

A Key Control Indicator measures control performance, and the percentage of firewall rules reviewed within the defined period quantifies how consistently the review process operates. This satisfies the stem's requirement for a KCI by providing a measurable, time-bound metric rather than a qualitative statement.

Why this answer

A Key Control Indicator (KCI) measures the effectiveness of a control by tracking its operational performance. For a firewall rule review process, the percentage of rules reviewed within the defined period directly indicates whether the control (periodic review) is being executed as intended, ensuring that stale or overly permissive rules are identified and remediated on schedule.

Exam trap

The CRISC exam often tests the distinction between KCIs (control performance) and KRIs (risk outcomes), so the trap here is confusing a lagging outcome metric (breaches) with a leading process metric (review completion).

How to eliminate wrong answers

Option A is wrong because the number of firewall breaches per quarter is a Key Risk Indicator (KRI), not a KCI; it measures the outcome of control failure rather than the performance of the control itself. Option C is wrong because the number of firewall administrators is a staffing metric unrelated to the operational effectiveness of the rule review process; it does not indicate whether reviews are completed on time. Option D is wrong because the time since the last firewall software update measures patch management hygiene, not the adherence to a rule review schedule; it is a separate control indicator for vulnerability management.

233
MCQmedium

A financial services firm is performing an IT risk assessment on its legacy 3270-based transaction processing system. The system has no vendor support, no documentation, and only two remaining staff members who understand its internals. The risk committee asks the risk analyst to determine the MOST appropriate way to characterize the risk associated with this asset. Which of the following should the analyst do FIRST?

A.Immediately migrate the workload to a modern platform to eliminate the unsupported technology exposure.
B.Quantify the asset's replacement cost and depreciated book value to express risk in monetary terms.
C.Purchase cyber insurance covering business interruption losses from system outages.
D.Identify and document the threats, vulnerabilities, and business impact specific to the legacy environment.
AnswerD

Risk characterization begins with identifying the relevant threats (hardware failure, loss of key personnel), vulnerabilities (no vendor patches, no documentation), and business impact (transaction outages, reconciliation errors). Only after these elements are articulated can the firm assess likelihood and impact and select a treatment. Jumping to quantification or control selection before identification would leave critical exposure drivers unexamined and produce an incomplete risk picture.

Why this answer

Characterizing risk requires first identifying the threats, vulnerabilities, and business impacts associated with the asset, because likelihood and impact assessment depend on those inputs. Legacy platforms with no vendor support and concentrated tribal knowledge present availability and knowledge-loss exposures that must be articulated before any treatment decision. Quantifying value, migrating, or buying insurance are downstream activities that presume the risk has already been understood and documented.

Exam trap

The trap here is treating risk characterization as a financial valuation exercise or jumping straight to a treatment, when the foundational step is identifying threats, vulnerabilities, and business impact.

234
MCQhard

A multinational corporation is deploying a new IoT-based inventory management system across its warehouses. The risk practitioner identifies that the IoT devices use default administrative credentials and unencrypted communication protocols. The vendor states that a firmware update to address these issues will not be available for six months. The business cannot delay the deployment due to competitive pressures. Which risk response strategy is MOST appropriate in this situation?

A.Accept the risk and proceed with deployment, documenting the decision and implementing compensating controls such as network segmentation and monitoring.
B.Transfer the risk by purchasing cyber insurance that covers IoT-related breaches.
C.Avoid the risk by canceling the IoT deployment and continuing with the existing manual inventory process.
D.Mitigate the risk by immediately replacing the IoT devices with a different vendor's products that have better security features.
AnswerA

When a risk cannot be avoided or mitigated immediately due to business constraints, acceptance with compensating controls is appropriate. Network segmentation and monitoring reduce the likelihood and impact of exploitation. Documenting the decision ensures accountability and provides a basis for future risk reassessment once the firmware update is available.

Why this answer

Given the business imperative to deploy and the unavailability of a timely patch, risk acceptance with compensating controls is the most appropriate response. This approach acknowledges the residual risk while reducing it through segmentation and monitoring. It also documents the decision for future review, aligning with CRISC principles of balancing risk and business objectives.

Exam trap

The trap here is assuming that risk transfer through insurance or avoidance is always preferable, when in fact business constraints often necessitate risk acceptance with compensating controls.

235
MCQeasy

A retail company has identified that its point-of-sale (POS) terminals are running an outdated operating system that no longer receives security patches. The risk practitioner recommends upgrading the terminals to a supported OS. The cost of the upgrade is $500,000, while the estimated annual loss from a potential breach is $2,000,000 with a 30% likelihood. Which risk response strategy is being recommended?

A.Risk avoidance
B.Risk acceptance
C.Risk mitigation
D.Risk transfer
AnswerC

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Upgrading the POS terminals to a supported OS reduces the likelihood of exploitation of unpatched vulnerabilities. This is a classic example of mitigation, as the action directly addresses the vulnerability and lowers the risk to an acceptable level.

Why this answer

Upgrading the POS terminals to a supported operating system is a mitigation strategy because it reduces the likelihood of a breach by addressing the unpatched vulnerability. The cost-benefit analysis ($500,000 upgrade vs. $600,000 expected annual loss) supports this action. Mitigation is appropriate when controls can reduce risk to an acceptable level.

Exam trap

The trap here is confusing mitigation with avoidance or transfer. Mitigation reduces risk through controls, while avoidance eliminates the activity and transfer shifts financial impact.

236
MCQmedium

An organization is evaluating risks and decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk treatment option does this represent?

A.Transfer
B.Accept
C.Mitigate
D.Avoid
AnswerA

Purchasing cyber insurance shifts the financial consequence of a breach to an insurer for a premium, which is risk transfer. This satisfies the stem because the organisation retains the threat but not the loss burden, distinguishing transfer from mitigation, avoidance or acceptance.

Why this answer

Transfer involves shifting risk to a third party, such as through insurance or outsourcing with liability transfer.

237
MCQhard

A company uses a dashboard to monitor KRIs. One KRI shows a warning level, but the data is two months old. What is the primary concern?

A.The KRI is not relevant.
B.The dashboard is not user-friendly.
C.The threshold is too low.
D.The monitoring is not timely.
AnswerD

A KRI warning based on two-month-old data cannot reflect current risk exposure, so the primary concern is that monitoring is not timely. Stale indicators defeat the purpose of key risk indicators, which must trigger prompt action.

Why this answer

The primary concern with a KRI showing a warning level based on data that is two months old is that the monitoring is not timely. Timeliness is a critical attribute of effective Key Risk Indicators (KRIs) because risk conditions can change rapidly; stale data renders the warning obsolete and may lead to incorrect risk decisions. Without current data, the organization cannot respond to emerging threats or control failures in a relevant timeframe, undermining the entire monitoring process.

Exam trap

The trap here is that candidates may focus on the 'warning level' and assume the threshold is too low (Option C), but the real issue is the latency of the data, not the threshold's calibration.

How to eliminate wrong answers

Option A is wrong because the KRI's relevance is not determined by data age; a KRI can be perfectly relevant to the risk but still fail if the data is not current. Option B is wrong because the dashboard's user-friendliness is a usability concern, not the core issue when the underlying data is stale; even a highly intuitive dashboard cannot compensate for outdated information. Option C is wrong because the threshold being too low would cause frequent warnings, but the problem here is the delay in data collection, not the sensitivity of the threshold.

238
MCQeasy

A healthcare organization is required by law to retain patient records for seven years. The IT department proposes storing backups on tapes that are kept in an on-site vault. The risk manager notes that the on-site vault is in a flood zone. Which risk response strategy is being applied if the organization decides to move the tapes to a secure off-site facility in a different geographic region?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerA

Moving backups to an off-site facility in a different geographic region reduces the risk of loss from a flood. This is a mitigation strategy because it implements a control (geographic separation) to lower the likelihood or impact of a disaster. The organization still retains records but with reduced risk.

Why this answer

The correct answer is risk mitigation. By moving backups to an off-site facility, the organization implements a control that reduces the risk of flood damage. This is a classic example of mitigation, where the goal is to lower the probability or impact of a threat, rather than avoiding the activity or transferring the risk.

Exam trap

The trap here is confusing mitigation with avoidance; moving data to a safer location reduces risk but does not eliminate the activity that creates the risk.

239
MCQeasy

Which of the following is a threat intelligence source that provides information about known exploited vulnerabilities, maintained by a government agency?

A.OSINT
B.NVD
C.CISA KEV
D.ISACs
AnswerC

The CISA Known Exploited Vulnerabilities catalogue is maintained by the US Cybersecurity and Infrastructure Security Agency and lists vulnerabilities with confirmed in-the-wild exploitation, satisfying the stem's government-maintained, known-exploited requirement. Other sources, such as vendor advisories or commercial feeds, lack that specific provenance.

Why this answer

The CISA Known Exploited Vulnerabilities (KEV) catalog is maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and lists vulnerabilities that have been exploited in the wild. It is a government-maintained threat intelligence source specifically focused on known exploited vulnerabilities.

Exam trap

The trap is confusing the NVD with the CISA KEV catalog; both are government-related vulnerability databases, but only KEV specifically lists vulnerabilities known to be exploited in the wild.

How to eliminate wrong answers

Option A is wrong because OSINT (Open Source Intelligence) is a broad category of publicly available information, not a specific government-maintained catalog of exploited vulnerabilities. Option B is wrong because the NVD (National Vulnerability Database) is a repository of vulnerability data maintained by NIST, but it does not exclusively list exploited vulnerabilities; it includes all published CVEs. Option D is wrong because ISACs (Information Sharing and Analysis Centers) are industry-specific information sharing organizations, not government-maintained catalogs of exploited vulnerabilities.

240
MCQeasy

Which type of threat actor is characterized by having significant resources, advanced skills, and often state-sponsored objectives?

A.Script kiddies
B.Organized crime
C.Nation-state APTs
D.Hacktivists
AnswerC

Nation-state advanced persistent threats combine government funding, elite technical capability and geopolitical objectives, enabling prolonged intrusion campaigns that outmatch criminal or insider actors. This matches the stem's significant resources, advanced skills and state-sponsored objectives precisely.

Why this answer

Nation-state advanced persistent threats (APTs) are characterized by significant resources, advanced technical skills, and objectives aligned with state interests, such as espionage, sabotage, or influence operations. They are typically well-funded and persistent.

Exam trap

The trap is equating 'significant resources and advanced skills' with organized crime; however, organized crime is financially motivated, while state-sponsored objectives are the key differentiator for nation-state APTs.

How to eliminate wrong answers

Option A is wrong because script kiddies are unskilled attackers who use existing tools and have limited resources. Option B is wrong because organized crime groups are motivated by financial gain and may have resources, but they are not typically state-sponsored and their objectives are profit-driven. Option D is wrong because hacktivists are ideologically motivated and usually have limited resources and skills compared to nation-state actors.

241
MCQhard

A multinational organization is assessing the risk of a new cloud service that stores data across multiple geographic regions. The service provider offers standard contractual terms and does not commit to specific data residency requirements. What is the primary risk that should be evaluated?

A.Service availability and uptime commitments.
B.Non-compliance with data protection regulations due to data location uncertainty.
C.Unauthorized access to data by cloud provider employees.
D.Inadequate encryption of data at rest and in transit.
AnswerB

Without contractual data residency commitments, data may be stored or processed in jurisdictions with differing legal requirements, creating regulatory exposure. The primary risk is therefore non-compliance with data protection laws governing cross-border transfers, not availability or performance.

Why this answer

The primary risk is non-compliance with data protection regulations due to uncertain data location (Option B). Because the provider does not commit to specific data residency, the organization cannot guarantee compliance with laws like GDPR that impose strict requirements on where data is stored and processed. This legal exposure outweighs the other options, as it could lead to fines and legal penalties.

242
MCQhard

Refer to the exhibit. What risk is introduced by this IAM policy?

A.Misconfigured encryption
B.Lack of logging
C.Excessive permissions
D.Weak authentication
AnswerC

The policy grants full access to all resources, creating a risk of privilege abuse.

Why this answer

The IAM policy grants `s3:*` actions on all S3 resources (`"Resource": "*"`), which allows any user or service assuming this role to perform any S3 operation, including deleting buckets, modifying permissions, or accessing all objects. This violates the principle of least privilege and introduces the risk of excessive permissions, as the policy does not restrict actions or resources to only what is necessary for the intended function.

Exam trap

The trap here is that candidates may focus on the absence of encryption or logging keywords in the policy, but the core risk is the overly broad action and resource scope, which is a classic excessive permissions vulnerability.

How to eliminate wrong answers

Option A is wrong because the policy does not reference encryption settings, KMS keys, or any condition that would misconfigure encryption; the risk is about authorization scope, not data protection configuration. Option B is wrong because the policy does not disable or omit logging settings; CloudTrail or S3 server access logging are independent of IAM policy statements and are not addressed here. Option D is wrong because the policy does not define authentication mechanisms, password policies, or MFA requirements; it only specifies allowed actions and resources after authentication has already occurred.

243
MCQmedium

After a security incident, a company implements a new control and begins monitoring its effectiveness. Which of the following metrics would BEST indicate that the control is achieving its objective?

A.Decrease in the number of successful attacks.
B.Reduction in the number of vulnerabilities.
C.Number of incidents reported.
D.Time to detect incidents.
AnswerA

A falling count of successful attacks directly evidences that the control is blocking the risk it was introduced to address, rather than merely being deployed. It measures outcome effectiveness, which is what the monitoring objective demands.

Why this answer

A decrease in the number of successful attacks directly measures the control's primary objective: preventing or mitigating actual security breaches. If the control is effective, it should stop or reduce the frequency of attacks that compromise the system, making this the most direct indicator of success.

Exam trap

The trap here is confusing control effectiveness (preventing harm) with control efficiency (reducing vulnerabilities or improving detection speed), leading candidates to pick metrics that measure secondary benefits rather than the primary objective.

How to eliminate wrong answers

Option B is wrong because a reduction in vulnerabilities is a measure of the control's ability to patch or remove weaknesses, not necessarily its effectiveness in preventing attacks; vulnerabilities may exist but not be exploited. Option C is wrong because the number of incidents reported includes both successful and attempted attacks, and a control might reduce successful attacks while incident reports remain high due to increased detection of attempts. Option D is wrong because time to detect incidents measures detection speed, not prevention; a control could be effective at preventing attacks but still have a slow detection time for those that bypass it.

244
MCQmedium

A bank's fraud detection system generates an alert for a transaction, but subsequent investigation finds it false. What should be done?

A.Document the false positive for trend analysis.
B.Report to the board.
C.Ignore future similar alerts.
D.Reduce the sensitivity of the detection system.
AnswerA

Documenting the false positive builds a record for trend analysis, letting the bank tune detection thresholds and reduce recurring noise. This satisfies the need to improve fraud detection accuracy over time rather than treating each alert in isolation.

Why this answer

Documenting false positives enables trend analysis to identify patterns in detection logic errors, such as rule misconfigurations or data quality issues. This aligns with the CRISC domain of risk and control monitoring, where logging and analyzing false alerts improves detection accuracy over time without prematurely adjusting thresholds.

Exam trap

The trap here is that candidates may assume immediate corrective action (reducing sensitivity) is best, but CRISC emphasizes data-driven decision-making and documentation before making control changes.

How to eliminate wrong answers

Option B is wrong because reporting a single false positive to the board is not appropriate; board reporting is reserved for material risk events or systemic control failures, not routine operational noise. Option C is wrong because ignoring future similar alerts would create a blind spot, potentially allowing actual fraud to go undetected if the false positive pattern changes. Option D is wrong because reducing sensitivity without data-driven analysis could increase false negatives, missing genuine fraud; sensitivity should only be adjusted after analyzing false positive trends and impact on detection rates.

245
MCQmedium

An organization wants to identify risks related to third-party vendors. Which approach best supports continuous risk identification?

A.Contractual clauses requiring self-assessment
B.On-site audits every two years
C.Automated monitoring of vendor security controls via a third-party risk platform
D.Annual vendor risk assessments
AnswerC

Automated monitoring via a third-party risk platform provides continuous, near-real-time visibility into vendor security posture, satisfying the stem's requirement for ongoing risk identification rather than periodic assessments. Unlike manual reviews, it detects control degradation as it occurs, enabling timely risk register updates and remediation before exposures escalate.

Why this answer

Automated monitoring via a third-party risk platform enables continuous, real-time visibility into vendor security controls, such as firewall rule changes, vulnerability scan results, and compliance posture. This approach aligns with the CRISC principle of ongoing risk identification, as it detects changes in risk exposure between formal assessment cycles without relying on periodic snapshots.

Exam trap

The trap here is that candidates often choose periodic assessments (A, B, or D) because they seem thorough, but CRISC emphasizes continuous risk identification over point-in-time reviews, and automated monitoring is the only option that provides real-time, ongoing visibility.

How to eliminate wrong answers

Option A is wrong because contractual clauses requiring self-assessment rely on vendor-reported data, which may be outdated, incomplete, or biased, and do not provide continuous or independent verification. Option B is wrong because on-site audits every two years are infrequent, static snapshots that miss interim changes in vendor environments, such as new vulnerabilities or configuration drift. Option D is wrong because annual vendor risk assessments are periodic and cannot capture risks that emerge between assessments, such as zero-day exploits or rapid cloud infrastructure changes.

246
MCQeasy

An IT risk analyst is preparing a report for the board risk committee. The committee wants a single view of how much loss the organization could face from IT risks over the next year if no additional controls are implemented. Which metric should the analyst use?

A.Annualized loss expectancy (ALE)
B.Return on security investment (ROSI)
C.Recovery time objective (RTO)
D.Control deficiency rate
AnswerA

ALE expresses the expected annual monetary loss from a risk and is calculated as single loss expectancy multiplied by annualized rate of occurrence. It gives the board a forward-looking, quantified view of potential loss exposure before additional controls, which is exactly what the committee requested. It is the standard metric for comparing and prioritizing IT risks in financial terms.

Why this answer

The board requested a single monetary view of potential annual loss from IT risks with no additional controls, which is precisely what annualized loss expectancy provides. ROSI is a control-investment metric, control deficiency rate measures control performance, and RTO is a time-based recovery target. Only ALE combines likelihood and financial impact into an expected annual loss figure suitable for board-level risk reporting.

Exam trap

The trap here is confusing a control performance indicator, such as deficiency rate, with a quantified loss exposure metric such as ALE.

247
MCQmedium

During a review of third-party vendor risks, the risk team identifies that a cloud service provider's data center is located in a country with unstable political conditions. What should the risk practitioner do FIRST?

A.Document the risk and assess its potential impact.
B.Accept the risk based on the vendor's SLA.
C.Request the vendor to move data to another region.
D.Terminate the contract immediately.
AnswerA

Risk identification precedes evaluation, so the practitioner must first record the geopolitical threat in the risk register, then assess likelihood and impact against the cloud provider's data centre location before recommending any treatment or transfer.

Why this answer

The risk practitioner's first step should be to document the identified risk and assess its potential impact on the organization. This aligns with the CRISC framework's emphasis on risk identification and assessment before any treatment decisions are made. Without a thorough impact assessment, the organization cannot determine whether the risk is acceptable, requires mitigation, or warrants contract termination.

Exam trap

The trap here is that candidates may jump to a risk treatment action (accept, mitigate, or terminate) without first completing the foundational step of documenting and assessing the risk.

How to eliminate wrong answers

Option B is wrong because accepting a risk based solely on a vendor's SLA is premature without first assessing the actual impact and likelihood of the political instability affecting the data center's operations. Option C is wrong because requesting the vendor to move data to another region is a risk mitigation action that should only be considered after the risk has been documented and assessed. Option D is wrong because terminating the contract immediately is an extreme response that bypasses the necessary risk assessment and evaluation of alternative treatments.

248
MCQhard

A financial services firm operates a high-volume transaction processing platform. During a risk assessment, the risk owner determines that the residual risk of database corruption exceeds the risk appetite. The database vendor offers a patch that reduces the vulnerability but requires a 12-hour outage. Business stakeholders refuse the outage. The risk practitioner is asked to recommend a risk response that aligns with the risk appetite without disrupting operations. Which of the following is the BEST recommendation?

A.Avoid the risk by decommissioning the transaction platform and migrating to a new solution.
B.Implement database replication to a secondary node and fail over during a maintenance window, then apply the patch.
C.Accept the residual risk and document it in the risk register with a review date in six months.
D.Transfer the risk by purchasing cyber liability insurance that covers data corruption events.
AnswerB

Replication provides a compensating control that maintains availability while the patch is applied to the primary node, allowing the outage to be absorbed by failover. This reduces the corruption risk to within appetite without a full 12-hour business outage. It is a mitigation strategy that balances technical remediation with business continuity requirements.

Why this answer

The best response reduces residual risk to within appetite while respecting the business constraint against a 12-hour outage. Database replication provides a compensating control that enables patching with minimal downtime, effectively mitigating the vulnerability. Acceptance, transfer, and avoidance either leave risk above appetite or introduce unacceptable business disruption.

Exam trap

The trap here is assuming that because the business refuses downtime, the only options are acceptance or avoidance, ignoring compensating controls that enable mitigation.

249
MCQmedium

A company is planning to migrate to post-quantum cryptography. What is the primary risk that quantum computing poses to current cryptographic systems?

A.Enhancing encryption key generation
B.Breaking widely used public-key cryptographic algorithms
C.Compromising hash functions for integrity
D.Increased speed of brute-force attacks on symmetric keys
AnswerB

Shor's algorithm lets a sufficiently large quantum computer solve integer factorisation and discrete logarithms in polynomial time, undermining RSA, Diffie-Hellman and ECC — the public-key algorithms protecting key exchange and signatures. Symmetric ciphers like AES are weakened only quadratically by Grover, so they are not the primary risk.

Why this answer

Quantum computers using Shor's algorithm can efficiently solve integer factorization and discrete logarithm problems, threatening RSA and ECC.

250
Multi-Selectmedium

A risk practitioner at an insurance company is identifying risks for a newly deployed customer portal that integrates with a third-party identity provider. She wants to document external factors that could increase the likelihood of a data breach. Which TWO of the following are external risk factors she should capture? (Choose two.)

Select 2 answers
A.The identity provider's recent history of service outages and security incidents disclosed in its public trust reports
B.The insurer's internal policy requiring multi-factor authentication for all administrative access to the portal
C.The insurer's internal change management process for deploying portal updates
D.The current regulatory penalties for privacy breaches in the jurisdictions where the insurer operates
E.The number of privileged accounts the insurer's own IT staff hold on the portal's backend systems
AnswersA, D

The provider's incident history is an external factor outside the insurer's direct control that directly affects breach likelihood for the portal. Documenting it supports third-party risk assessment and helps the practitioner set monitoring and contractual expectations. It belongs in the external factor category because it describes the vendor's environment rather than an internal control or process.

Why this answer

External risk factors are conditions outside the organization's direct control that affect the likelihood or impact of a risk event. A third-party identity provider's incident history and changing regulatory penalty regimes both originate outside the insurer and vary independently of its own actions. Internal policies, privileged account counts, and change management processes are internal conditions or controls that the organization itself shapes.

Exam trap

The trap here is assuming any factor that affects breach likelihood is external, when internal controls and processes also qualify as risk factors but are internally controlled.

251
MCQmedium

A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?

A.Reduced network bandwidth for OT operations
B.Expanded attack surface from IT to OT systems
C.Increased data storage costs
D.Loss of proprietary control protocols
AnswerB

Linking ICS to the corporate network exposes operational technology to threats previously confined to IT, expanding the attack surface across both domains. This satisfies the stem's convergence scenario, where compromised corporate endpoints or lateral movement can now reach industrial control systems directly.

Why this answer

The correct answer is B: Expanded attack surface from IT to OT systems. Connecting ICS/OT networks to corporate IT networks creates a bridge that allows threats to move laterally from IT into OT environments. Historically, OT networks were air-gapped or highly segmented, but IT/OT convergence introduces new entry points and attack vectors, significantly increasing the risk of cyberattacks that can disrupt physical industrial processes.

This is the most significant risk because it can lead to safety incidents, production outages, and physical damage.

Exam trap

CRISC often tests the distinction between operational risks (e.g., bandwidth, storage) and strategic risks (e.g., expanded attack surface), and candidates may choose a technical impact over the broader security risk.

How to eliminate wrong answers

Option A is wrong because reduced network bandwidth is a performance concern, not a risk; IT/OT convergence typically involves dedicated network segments or quality-of-service to prioritize OT traffic, and bandwidth can be managed. Option C is wrong because increased data storage costs are a financial consideration, not a risk; storage is relatively cheap and can be scaled, and it does not directly threaten the organization's mission. Option D is wrong because loss of proprietary control protocols is not a risk; protocols remain in use, and convergence often involves protocol translation or encapsulation, not elimination.

252
MCQmedium

Which of the following is the PRIMARY source for identifying known software vulnerabilities in a systematic manner?

A.OSINT feeds from social media
B.CIS Benchmarks
C.National Vulnerability Database (NVD)
D.OWASP Top 10
AnswerC

The National Vulnerability Database provides a systematic, authoritative feed of known vulnerabilities, each mapped to CVE identifiers and enriched with CVSS severity scores. This structured, continuously updated catalogue satisfies the stem's requirement for a primary, repeatable source, unlike vendor advisories or ad hoc threat feeds.

Why this answer

The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, built upon the CVE (Common Vulnerabilities and Exposures) list. It provides a systematic, structured, and continuously updated source of known software vulnerabilities, including CVSS scores, CWE classifications, and affected product configurations. For CRISC, it is the authoritative primary source for identifying vulnerabilities in a repeatable, comprehensive manner, unlike the other options which are either not vulnerability databases or not systematic.

Exam trap

CRISC often tests the distinction between a vulnerability database (NVD) and security guidance or awareness lists (CIS Benchmarks, OWASP Top 10), causing candidates to select a well-known framework instead of the primary systematic source.

How to eliminate wrong answers

Option A is wrong because OSINT feeds from social media are unstructured, unverified, and lack the systematic, standardized vulnerability identifiers and metadata needed for a reliable vulnerability management process. Option B is wrong because CIS Benchmarks are prescriptive configuration hardening guidelines, not a database of known software vulnerabilities; they help prevent exploitation but do not enumerate vulnerabilities. Option D is wrong because the OWASP Top 10 is an awareness document that lists the most critical web application security risks, not a comprehensive, systematic database of known software vulnerabilities.

253
MCQeasy

An organization is selecting a control to prevent unauthorized access to a critical database. Which control type is most appropriate?

A.Detective control
B.Corrective control
C.Directive control
D.Preventive control
AnswerD

Preventive controls stop unauthorised access before it occurs, directly satisfying the stem's requirement to prevent access to the critical database. Detective controls only identify access after the fact, and corrective controls restore service afterwards, so neither blocks the initial intrusion.

Why this answer

Preventive control is the most appropriate because it directly stops unauthorized access before it occurs. For a critical database, this includes mechanisms like database firewalls, access control lists (ACLs), or mandatory access control (MAC) policies that enforce authentication and authorization at the point of entry, such as requiring valid credentials and role-based permissions before any query is processed.

Exam trap

The trap here is that candidates often confuse 'preventive' with 'detective' controls, mistakenly thinking that logging and monitoring (detective) are sufficient to stop unauthorized access, when in fact they only provide visibility after the fact.

How to eliminate wrong answers

Option A is wrong because detective controls, such as audit logs or intrusion detection systems (IDS), only identify unauthorized access after it has happened, not prevent it. Option B is wrong because corrective controls, like restoring from a backup or applying a patch, are used to remediate damage after an incident, not to block initial access. Option C is wrong because directive controls, such as security policies or acceptable use agreements, guide behavior but do not technically enforce or block access to the database.

254
MCQhard

A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk assessment team has identified that the likelihood of an attack is high due to recent industry trends, and the impact would be severe, including patient safety risks and regulatory fines. The organization has a limited budget and wants to implement controls that provide the greatest risk reduction. Which of the following risk response strategies is MOST appropriate in this scenario?

A.Risk acceptance by documenting the risk and taking no action due to budget constraints.
B.Risk mitigation by implementing layered controls such as regular backups, employee training, and endpoint detection and response.
C.Risk transfer by purchasing cyber insurance to cover all potential losses.
D.Risk avoidance by discontinuing the use of the EHR system.
AnswerB

Risk mitigation reduces the likelihood or impact of a risk through controls. For ransomware, layered controls like offline backups, security awareness training, and endpoint detection can significantly reduce the chance of a successful attack and enable rapid recovery. Given the high likelihood and severe impact, mitigation is the most practical strategy to protect patient safety and meet regulatory requirements without halting essential operations.

Why this answer

Risk mitigation is the most appropriate strategy because it reduces both the likelihood and impact of a ransomware attack through layered controls. Given the criticality of the EHR system and the severe consequences, simply transferring or accepting the risk would leave the organization vulnerable. Avoidance is impractical.

Mitigation aligns with the need to protect patient safety and comply with regulations while operating within budget constraints.

Exam trap

The trap here is assuming that cyber insurance (risk transfer) fully addresses the risk, when it only covers financial losses and does not prevent operational disruption or patient harm.

255
MCQeasy

A risk manager uses a 5x5 heat map to plot the likelihood and impact of identified risks. This approach is an example of which type of risk analysis?

A.Qualitative risk analysis
B.Quantitative risk analysis
C.Hybrid risk analysis
D.Semi-quantitative risk analysis
AnswerA

A 5x5 heat map plots likelihood and impact using ordinal rating scales rather than monetary values, which is the defining mechanism of qualitative risk analysis. It satisfies the scenario's constraint of subjective, expert-driven ranking, unlike quantitative analysis, which requires numerical data such as annualised loss expectancy.

Why this answer

A 5x5 heat map is a qualitative risk analysis technique that uses ordinal scales for likelihood and impact to derive risk ratings.

256
MCQhard

A multinational corporation uses commercial threat intelligence feeds and participates in an ISAC. However, they recently missed a critical vulnerability exploited in the wild that was not in their feeds. Which additional source should they incorporate to improve vulnerability identification?

A.CISA KEV catalog
B.NVD database
C.OSINT from social media
D.Vendor advisories only
AnswerA

The CISA Known Exploited Vulnerabilities catalog lists vulnerabilities confirmed as exploited in the wild, including those absent from commercial feeds and ISAC sharing. Incorporating it closes the gap that let the exploited vulnerability go unidentified, directly addressing the missed in-the-wild exploitation described in the stem.

Why this answer

The CISA KEV catalog specifically lists vulnerabilities that have been confirmed as exploited in the wild, which is exactly the gap described—a critical vulnerability exploited in the wild that was missed by commercial feeds and ISAC participation. Incorporating KEV ensures the organization prioritizes vulnerabilities with known active exploitation, regardless of whether they appear in commercial feeds. This makes it the correct additional source.

Exam trap

CRISC often tests the difference between vulnerability severity (NVD/CVSS) and confirmed exploitation (CISA KEV); the trap is selecting NVD because it is a well-known government vulnerability database, when the question specifically asks about a vulnerability exploited in the wild that was missed by existing feeds.

How to eliminate wrong answers

Option B is wrong because the NVD is a comprehensive vulnerability database that catalogs CVEs with CVSS scores but does not specifically identify which vulnerabilities are known to be exploited in the wild, so it would not have closed the gap described. Option C is wrong because OSINT from social media is unstructured, unverified, and not a reliable or systematic source for identifying exploited vulnerabilities. Option D is wrong because vendor advisories only cover vulnerabilities in that specific vendor's products and would not provide the cross-vendor, exploitation-confirmed coverage that KEV offers.

257
MCQmedium

A company operates a legacy system for which the vendor no longer provides security patches. What is the most critical risk to identify regarding this system?

A.Unpatched vulnerabilities
B.Incompatibility with new systems
C.Lack of vendor support
D.Skill shortage for maintenance
AnswerA

Without vendor patches, known exploits remain permanently exploitable, so unpatched vulnerabilities represent the most critical risk. This directly addresses the stem's constraint that no security patches are available, unlike availability, compliance or obsolescence concerns that follow from, rather than define, that exposure.

Why this answer

Unpatched vulnerabilities are the most critical risk because the legacy system is exposed to known exploits that the vendor no longer addresses. Without security patches, attackers can leverage published CVEs to compromise the system, leading to data breaches or system takeover. This directly threatens the confidentiality, integrity, and availability of the system and its data.

Exam trap

The trap here is that candidates confuse the root cause (lack of vendor support) with the actual risk (unpatched vulnerabilities), leading them to select 'Lack of vendor support' instead of identifying the direct security exposure.

How to eliminate wrong answers

Option B is wrong because incompatibility with new systems is an operational or integration risk, not a security risk, and is less critical than unpatched vulnerabilities. Option C is wrong because lack of vendor support is a contributing factor to the risk, not the risk itself; the core issue is the resulting unpatched vulnerabilities. Option D is wrong because skill shortage for maintenance is a resource risk that affects the ability to manage the system, but it does not directly expose the system to exploitation like unpatched vulnerabilities do.

258
Multi-Selectmedium

A retail company is conducting an IT risk assessment for its point-of-sale (POS) system. The risk team has identified several threats, including malware, insider theft, and denial-of-service (DoS) attacks. The company currently uses antivirus software, firewalls, and role-based access controls. Which TWO of the following are the MOST appropriate risk response actions to address the identified threats? (Choose two.)

Select 2 answers
A.Conduct regular security awareness training for employees handling POS transactions.
B.Outsource POS management to a third-party service provider.
C.Implement network segmentation to isolate the POS system from the corporate network.
D.Increase the backup frequency for POS transaction logs.
E.Purchase cyber insurance to transfer the financial impact of a data breach.
AnswersA, C

Security awareness training helps mitigate insider threats and reduces the likelihood of successful phishing or social engineering attacks, which are common vectors for malware. It is a preventive control that addresses the human factor. For POS systems, training employees on secure practices and threat recognition is essential. This action directly addresses the identified threats, especially insider theft and malware. It complements technical controls.

Why this answer

Network segmentation and security awareness training are the most appropriate risk response actions because they directly mitigate the identified threats. Segmentation reduces the attack surface and limits lateral movement, while training addresses human-related risks like insider theft and phishing. These are preventive controls that reduce likelihood and impact.

The other options either transfer risk without reducing it or focus on recovery rather than addressing the threats themselves.

Exam trap

The trap here is selecting risk transfer or recovery options instead of preventive controls that directly reduce the likelihood or impact of the threats.

259
MCQmedium

A multinational corporation has adopted a risk mitigation strategy for its key suppliers by requiring them to maintain ISO 27001 certification. During an audit, the risk manager discovers that one critical supplier lost its certification six months ago but did not report it, as contractually required. The supplier still has adequate security controls in place, and the relationship is strategically important. The CEO wants to avoid contract termination. What is the MOST appropriate risk response?

A.Issue a corrective action plan requiring the supplier to regain certification within three months, with monthly progress reviews.
B.Transfer the risk to the supplier's cyber liability insurance policy.
C.Accept the risk because the supplier still has effective controls, and update the risk register.
D.Terminate the contract immediately and find an alternative supplier.
AnswerA

A corrective action plan with monthly reviews addresses the contractual breach and certification lapse while preserving the strategic relationship, satisfying the CEO's wish to avoid termination. It imposes measurable remediation deadlines rather than accepting or transferring the supplier risk outright.

Why this answer

The most appropriate risk response is to issue a corrective action plan with a deadline and monitoring, because it directly addresses the control gap (lapsed certification) while preserving the strategic relationship. ISO 27001 certification is a contractual requirement and a key risk mitigation control; its loss increases risk even if other controls exist. A corrective action plan is a targeted risk treatment that restores compliance and provides assurance through monthly reviews, aligning with CRISC's emphasis on balancing risk and business objectives.

Exam trap

CRISC often tests the misconception that risk acceptance is always acceptable if controls are present, but the key is that contractual non-compliance and loss of independent assurance require a formal response; candidates may overlook the need to address the root cause through a corrective action plan.

How to eliminate wrong answers

Option B is wrong because transferring risk via the supplier's insurance does not address the root cause (loss of certification) and may not cover contractual non-compliance; insurance is a financial risk transfer, not a control restoration. Option C is wrong because accepting the risk solely based on existing controls ignores the contractual breach and the fact that certification provides independent assurance; acceptance without treatment may be inappropriate for a critical supplier. Option D is wrong because immediate termination is a disproportionate response that could disrupt operations and damage a strategically important relationship, and it does not consider less disruptive alternatives like corrective action.

260
MCQhard

An organization is implementing a new control to address a high-risk finding. The project manager has scheduled a user training session and updated the relevant policies. Which implementation phase is being addressed?

A.Control monitoring
B.Risk assessment
C.Control implementation
D.Control design
AnswerC

Training and policy updates are execution activities, not design or assessment. Control implementation covers deploying the approved control into operation, which includes enabling people and processes through training and revised policies. This satisfies the stem's requirement to identify the phase where the control is actually put in place.

Why this answer

These activities (training and documentation updates) are part of the control implementation phase, specifically after the control is designed and before going live.

261
MCQeasy

Based on the exhibit, which of the following is the MOST likely risk scenario?

A.A denial-of-service attack on the SSH service
B.A brute-force attack targeting the root account
C.A successful privilege escalation by an insider
D.A misconfigured firewall allowing unauthorized access
AnswerB

Repeated failed authentication attempts against the root account, followed by a successful login from an unfamiliar external address, indicate credential guessing rather than malware or misconfiguration, making brute-force targeting of root the most plausible scenario.

Why this answer

The exhibit shows repeated failed login attempts for the root account, which is a classic indicator of a brute-force attack. SSH logs typically record authentication failures, and a high frequency of 'Failed password for root' entries from a single source IP strongly suggests an automated password guessing attempt. This aligns with the risk scenario of a brute-force attack targeting the root account.

Exam trap

The trap here is that candidates may confuse authentication failure logs with network-level attacks (DoS or firewall misconfiguration) or assume that any failed login implies a successful breach, when in fact the logs only show the attempt, not the outcome.

How to eliminate wrong answers

Option A is wrong because a denial-of-service attack on the SSH service would manifest as connection timeouts, resource exhaustion, or service unavailability, not repeated authentication failure logs. Option C is wrong because a successful privilege escalation by an insider would show evidence of a normal user account gaining elevated privileges (e.g., via sudo or kernel exploit), not repeated root login attempts. Option D is wrong because a misconfigured firewall allowing unauthorized access would result in unexpected network traffic reaching the server, but the logs specifically show authentication failures, not firewall rule violations or allowed connections from unauthorized IPs.

262
MCQeasy

Which risk reporting level is typically provided to the board of directors and focuses on strategic risk posture?

A.Tactical risk reporting
B.Compliance risk reporting
C.Strategic risk reporting
D.Operational risk reporting
AnswerC

Strategic risk reporting addresses enterprise-wide, long-horizon risk posture and aggregated exposure, which is the language and scope a board requires for governance oversight. Operational and tactical reporting deal with day-to-day or function-level detail, not the strategic posture the stem specifies.

Why this answer

Strategic risk reporting is the correct level for the board of directors because it focuses on high-level, long-term risks that could affect the organization's strategic objectives and overall business posture. Unlike tactical or operational reports, strategic reports aggregate risk data into a format that supports governance, risk appetite decisions, and capital allocation at the executive level.

Exam trap

The trap here is that candidates often confuse 'strategic' with 'operational' or 'tactical' because they think the board needs detailed technical data, when in fact the board requires aggregated, high-level information focused on long-term strategy and risk appetite.

How to eliminate wrong answers

Option A is wrong because tactical risk reporting is designed for mid-level management and focuses on specific projects or processes, not the enterprise-wide strategic posture required by the board. Option B is wrong because compliance risk reporting is narrowly scoped to regulatory and legal obligations, such as SOX or GDPR, and does not encompass the broader strategic risk landscape. Option D is wrong because operational risk reporting deals with day-to-day risks like system failures or process errors, which are too granular and short-term for board-level strategic oversight.

263
MCQhard

A company has a control that automatically rejects transactions over $10,000. During a review, it is found that 2% of transactions over $10,000 were approved due to a system glitch. The control owner says the glitch has been fixed. What should the risk practitioner do next?

A.Accept the control owner's assurance and close the finding.
B.Request evidence of the fix and perform a sample test of recent transactions.
C.Recommend a compensating control until the fix is confirmed.
D.Report the issue to the audit committee.
AnswerB

The owner's claim that the glitch is fixed is unverified, so the practitioner must obtain evidence of remediation and test a sample of recent transactions to confirm the control now rejects all transactions above $10,000. Only then can the risk be reassessed.

Why this answer

The risk practitioner must independently verify that the system glitch has been resolved before closing the finding. Requesting evidence of the fix (e.g., change logs, patch notes) and performing a sample test of recent transactions provides objective assurance that the control is now operating effectively. This aligns with the CRISC principle that control owner assurances alone are insufficient without validation, especially for automated controls where residual risk from the glitch could persist.

Exam trap

The trap here is that candidates assume a control owner's assurance is sufficient (Option A) or that a compensating control is always needed (Option C), but CRISC emphasizes independent verification of control fixes before closure.

How to eliminate wrong answers

Option A is wrong because accepting the control owner's assurance without evidence violates the risk practitioner's duty to independently validate control effectiveness; a verbal fix claim does not confirm the system glitch is resolved. Option C is wrong because recommending a compensating control is premature—the fix is already claimed to be implemented, and the practitioner should first verify it before adding compensating controls, which could introduce unnecessary complexity or cost. Option D is wrong because reporting directly to the audit committee bypasses normal escalation and management review; the issue should first be addressed with the control owner and management, and only escalated if the fix is not confirmed or if residual risk remains unacceptable.

264
MCQhard

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The identity team proposes implementing just-in-time (JIT) privileged access with automated approval workflows and session recording. Which risk is MOST effectively mitigated by this approach compared to standing privileged accounts?

A.The risk of a denial-of-service attack saturating the network perimeter during peak business hours.
B.The risk that database administrators can read sensitive data in production without leaving an audit trail.
C.The risk that unused or stale privileged accounts accumulate and are exploited by attackers or insiders.
D.The risk of credential stuffing attacks against the single sign-on portal used by all employees.
AnswerC

Standing privileged accounts persist indefinitely and are often forgotten, creating a large attack surface. JIT access grants privileges only when needed, for a limited time, with approval and session recording, so dormant entitlements no longer exist. This directly reduces the risk of exploitation of stale or unused privileged accounts by both external attackers and malicious insiders.

Why this answer

Standing privileged accounts are a persistent target because they remain valid even when unused. Just-in-time provisioning eliminates standing entitlements, granting elevated rights only for an approved, time-bound session. This shrinks the attack surface, removes dormant accounts that attackers and insiders could exploit, and adds approval and recording as compensating detective controls.

Exam trap

The trap here is confusing the reduction of standing privileges with broader identity threats like credential stuffing, which JIT access does not address.

265
Multi-Selecthard

A multinational manufacturer is migrating its disaster recovery capability for a core ERP system from a warm standby data center to a cloud-based recovery service. The risk practitioner is validating the recovery design. Which TWO of the following should be validated to confirm the recovery time objective can realistically be met? (Choose two.)

Select 2 answers
A.Confirm the actual data replication lag and whether it stays within the recovery point objective during peak transaction periods.
B.Verify that automated failover orchestration and DNS redirection complete within the documented recovery time objective.
C.Confirm the backup retention schedule aligns with the organization's data classification policy.
D.Confirm that the cloud recovery environment is pre-provisioned with sufficient compute, storage and network capacity for peak load.
E.Review the cloud provider's SOC 2 report to confirm its availability commitments.
AnswersB, D

Recovery time objective is about elapsed time until service is restored. Automated failover and DNS cutover are usually the longest sequential steps in a cloud recovery, so measuring their end-to-end duration against the documented objective is the most direct validation that the time target is achievable in practice rather than aspirational.

Why this answer

Validating a recovery time objective requires measuring the steps that consume restoration time and confirming the target environment can carry production load. Failover orchestration and DNS cutover are typically the longest sequential activities, and pre-provisioned capacity determines whether the restored service can actually run. Replication lag addresses data loss, while assurance reports and retention schedules address different objectives.

Exam trap

The trap here is conflating recovery point objective evidence such as replication lag with recovery time objective evidence about how fast service actually returns.

266
MCQhard

A risk manager is reviewing the control monitoring reports and finds that a key control's effectiveness rating has dropped from 'effective' to 'partially effective' due to increased errors in manual data entry. Which of the following is the BEST course of action?

A.Conduct a root cause analysis to identify why errors increased.
B.Immediately implement an automated data entry solution.
C.Increase the frequency of monitoring to detect errors sooner.
D.Assign additional staff to double-check data entries.
AnswerA

A drop to 'partially effective' signals the control no longer mitigates risk as designed, so the manager must first understand the cause of the increased manual entry errors before selecting remediation. Root cause analysis pinpoints whether training, workload or process design drives the degradation, directing an effective response.

Why this answer

A root cause analysis (RCA) is the best course of action because it systematically identifies the underlying reasons for the increased manual data entry errors, such as inadequate training, unclear procedures, or system interface issues. Without understanding the root cause, any corrective action (like automation or additional staff) may address symptoms rather than the actual problem, leading to wasted resources or recurring control failures. This aligns with the CRISC principle that control effectiveness must be restored by addressing the fundamental cause of degradation, not just the symptoms.

Exam trap

The trap here is that candidates often choose immediate automation (Option B) because it seems like a modern, efficient fix, but the CRISC exam emphasizes that risk treatment must be based on root cause analysis to avoid ineffective or counterproductive controls.

How to eliminate wrong answers

Option B is wrong because immediately implementing an automated data entry solution without first conducting a root cause analysis may introduce new risks (e.g., integration issues, cost overruns, or data mapping errors) and does not address why manual errors increased—automation might not be necessary if the root cause is, for example, a training gap. Option C is wrong because increasing monitoring frequency only detects errors sooner but does not prevent them or fix the underlying cause; it is a detective control, not a corrective one, and may increase monitoring costs without improving control effectiveness. Option D is wrong because assigning additional staff to double-check data entries is a compensating control that adds cost and potential for human error, but it does not address why the original errors increased—it merely adds a layer of review without resolving the root cause.

267
MCQmedium

A financial services firm is conducting an IT risk assessment on a legacy trading application. The assessment team wants to prioritize risks based on the combination of the likelihood of a threat event and the magnitude of its impact. The firm has limited resources and needs to focus on the most significant risks first. Which of the following BEST describes the purpose of using a risk map (heat map) in this context?

A.To provide a visual representation of risks based on their likelihood and impact, helping to prioritize risk response efforts.
B.To calculate the exact annualized loss expectancy (ALE) for each identified risk.
C.To eliminate the need for a detailed risk assessment by providing a quick overview.
D.To determine the effectiveness of existing controls by comparing inherent and residual risk.
AnswerA

A risk map (heat map) plots risks on a matrix of likelihood and impact, enabling the firm to visually identify which risks fall into high-priority zones. This helps allocate limited resources to the most significant risks first, aligning with the goal of prioritizing risk response. It does not quantify exact losses or replace detailed analysis, but it is a key tool for communicating and prioritizing risk.

Why this answer

A risk map (heat map) is a qualitative tool that plots risks on a matrix of likelihood and impact, enabling the firm to visually identify and prioritize the most significant risks. This is particularly useful when resources are limited, as it helps focus attention on high-priority areas. It does not calculate exact losses, replace detailed assessment, or directly measure control effectiveness, but it supports communication and prioritization.

Exam trap

The trap here is assuming that a risk map provides quantitative precision or replaces the need for detailed risk analysis, when it is actually a qualitative prioritization aid.

268
MCQeasy

Which of the following is the BEST example of a key risk indicator (KRI) for the risk of unauthorized access to sensitive data?

A.Average server uptime
B.Number of firewalls deployed
C.Percentage of users with access to sensitive data
D.Number of security awareness trainings completed
AnswerC

Counting the proportion of users holding access to sensitive data directly measures exposure to the unauthorised-access risk, since excessive permissions are the principal driver. It is quantifiable and trackable over time, satisfying the KRI requirement for a forward-looking metric rather than a lagging incident count.

Why this answer

A KRI must directly measure the likelihood or impact of a specific risk. The percentage of users with access to sensitive data is a direct indicator of the attack surface for unauthorized access; a higher percentage increases the probability that an unauthorized user could gain access, making it a leading indicator for that risk.

Exam trap

The trap here is confusing a control metric (e.g., number of firewalls or training completions) with a risk indicator; candidates often pick options that sound security-related but fail to directly measure the risk event's likelihood or impact.

How to eliminate wrong answers

Option A is wrong because average server uptime is an operational metric for availability, not a risk indicator for unauthorized access; it does not measure who can access data or how access controls are configured. Option B is wrong because the number of firewalls deployed is a control metric (a count of security devices), not a KRI; it does not indicate the effectiveness of access controls or the actual exposure of sensitive data. Option D is wrong because the number of security awareness trainings completed is a compliance or activity metric; it measures training completion, not the actual risk of unauthorized access, and does not reflect whether users are following access policies.

269
MCQmedium

An organization is evaluating cyber insurance to mitigate financial risk from potential data breaches. Which factor would most likely increase the insurance premium?

A.Implementation of multi-factor authentication
B.Adoption of a cybersecurity framework
C.Regular penetration testing
D.History of previous security incidents
AnswerD

A documented history of previous security incidents directly raises the insurer's assessed loss frequency, increasing the premium. Underwriters price cyber cover on actuarial loss experience, so prior breaches signal elevated recurrence risk and weaker controls, satisfying the stem's requirement to identify the factor that most likely increases the premium charged.

Why this answer

A history of previous security incidents most likely increases the insurance premium because it indicates a higher risk profile to the insurer. Insurers assess past claims and incident frequency as a key factor in determining the likelihood of future breaches, leading to higher premiums or even denial of coverage.

Exam trap

CRISC often tests risk factors for insurance; candidates may assume that any security investment lowers premiums, but the question asks what increases premiums, and past incidents are a clear negative indicator.

How to eliminate wrong answers

Option A is wrong because implementing multi-factor authentication reduces risk and would likely lower premiums, not increase them. Option B is wrong because adopting a cybersecurity framework demonstrates a mature security posture, which insurers view favorably and may result in premium discounts. Option C is wrong because regular penetration testing is a proactive security measure that identifies and remediates vulnerabilities, reducing risk and potentially lowering premiums.

270
MCQmedium

An insurance company is assessing the risk of a distributed denial-of-service (DDoS) attack against its customer portal. The risk team estimates that a threat actor group has both the capability and the intent to launch such an attack, and that the portal has an unpatched vulnerability that could be exploited to amplify the attack. Which factor does the unpatched vulnerability PRIMARILY represent in this risk scenario?

A.Impact
B.Threat
C.Risk appetite
D.Vulnerability
AnswerD

This is correct because the unpatched weakness in the portal is a flaw or gap that a threat actor could exploit. In risk assessment, vulnerability represents the internal weakness that, combined with a threat and its potential impact, creates risk. It is the condition that enables the threat actor's capability and intent to translate into a successful DDoS amplification against the customer portal.

Why this answer

In risk assessment, vulnerability is the internal weakness or gap that a threat can exploit. The threat actor group provides capability and intent, while impact describes the resulting harm. The unpatched portal flaw is the vulnerability that enables the DDoS amplification, so it is the factor the risk team should prioritize for remediation.

Exam trap

The trap here is conflating the threat actor's capability and intent with the vulnerability, when the unpatched flaw is the exploitable weakness rather than the threat itself.

271
MCQhard

During a quantitative risk analysis, the risk team calculates the loss event frequency (LEF) using the FAIR framework. If the threat event frequency (TEF) is 10 per year and the vulnerability (V) is 0.3, what is the LEF?

A.10.3 per year
B.30 per year
C.0.3 per year
D.3 per year
AnswerD

In FAIR, loss event frequency derives from threat event frequency multiplied by vulnerability, so 10 × 0.3 yields 3 loss events per year. This satisfies the stem's quantitative requirement, converting ten annual threat events into the subset that actually becomes losses given the 0.3 vulnerability rate.

Why this answer

In the FAIR framework, loss event frequency (LEF) is calculated as the product of threat event frequency (TEF) and vulnerability (V). Given TEF = 10 per year and V = 0.3, LEF = 10 × 0.3 = 3 per year. This represents the expected number of loss events per year, accounting for the probability that a threat event will actually result in a loss.

Exam trap

The trap here is that candidates may confuse the multiplicative relationship in FAIR with additive or divisive operations, or mistakenly treat vulnerability as the final frequency rather than a probability multiplier.

How to eliminate wrong answers

Option A is wrong because 10.3 per year results from incorrectly adding TEF and V (10 + 0.3), but LEF is a multiplicative product, not a sum. Option B is wrong because 30 per year results from dividing TEF by V (10 / 0.3 ≈ 33.3) or multiplying by the reciprocal, which misapplies the FAIR formula. Option C is wrong because 0.3 per year treats V as the LEF itself, ignoring TEF entirely; LEF must incorporate both TEF and V multiplicatively.

272
MCQeasy

A manufacturing company's board of directors receives a monthly risk report. Which key performance indicator (KPI) is MOST relevant for the board to assess the effectiveness of internal controls?

A.Number of audit findings per business unit.
B.Number of risk assessments completed this month.
C.Percentage of employees completing annual compliance training.
D.Percentage of control tests passed within the reporting period.
AnswerD

Control test pass rates measure whether internal controls operate as designed, giving the board direct evidence of control effectiveness. Other metrics, such as incident counts or risk exposure, reflect outcomes rather than control performance itself.

Why this answer

The percentage of control tests passed within the reporting period directly measures the operational effectiveness of internal controls, which is the board's primary concern for risk mitigation. This KPI provides a quantifiable, trendable metric that reflects whether controls are functioning as designed to reduce residual risk to an acceptable level.

Exam trap

The trap here is that candidates confuse activity-based metrics (like number of assessments or training completion) with outcome-based metrics that directly measure control effectiveness, leading them to select options that sound relevant but do not answer the board's specific need for control performance assurance.

How to eliminate wrong answers

Option A is wrong because the number of audit findings per business unit is a lagging indicator of control failures, not a direct measure of control effectiveness; it reflects past issues rather than current control performance. Option B is wrong because the number of risk assessments completed this month measures process activity (volume of assessments), not the quality or effectiveness of controls themselves. Option C is wrong because the percentage of employees completing annual compliance training measures awareness and training completion, not whether the controls themselves are operating effectively; training is a preventive control, but its completion does not guarantee control effectiveness.

273
MCQmedium

A retail company is prioritizing risks for the coming year. Management wants to focus resources where the potential financial loss is greatest, but the risk team has only ordinal likelihood and impact ratings. Which approach BEST supports this prioritization?

A.Ask each department head to vote on which risks feel most urgent.
B.Convert the ordinal ratings into a single composite score by multiplying likelihood rank by impact rank.
C.Rank risks alphabetically by asset name to ensure consistent ordering.
D.Estimate a monetary loss range and annual frequency for each risk, then calculate expected annual loss.
AnswerD

Expected annual loss combines an estimated loss magnitude with an estimated frequency, producing a monetary value that can be compared and summed across risks. Even rough ranges give management a defensible basis for ranking by financial exposure. This directly answers the goal of focusing resources where potential loss is greatest, and it aligns with quantitative risk analysis techniques used in CRISC.

Why this answer

To prioritize by greatest potential financial loss, the team needs a monetary measure. Estimating loss ranges and annual frequencies yields expected annual loss, which can be compared across risks and aggregated. Ordinal multiplication, alphabetical ordering, and subjective voting do not produce a reliable financial ranking, so they cannot guide resource allocation as effectively.

Exam trap

The trap here is believing that multiplying ordinal likelihood and impact ranks creates a valid financial measure, when ordinal scales lack equal intervals.

274
MCQeasy

An IT risk manager is facilitating a brainstorming session to identify threats. Which technique is BEST suited for identifying a wide range of potential threats?

A.Conduct a facilitated workshop with cross-functional stakeholders
B.Use a standard threat checklist
C.Review historical incident logs
D.Interview the heads of each department individually
AnswerA

Cross-functional stakeholders bring varied perspectives across technology, operations, compliance and business domains, surfacing a broader threat landscape than any single group. This directly satisfies the stem's requirement for identifying a wide range of potential threats during brainstorming.

Why this answer

A facilitated workshop with cross-functional stakeholders is best suited for brainstorming because it leverages diverse perspectives from IT, business, legal, and operations teams to identify a wide range of threats, including emerging and non-obvious ones. This collaborative approach aligns with the CRISC emphasis on qualitative risk assessment techniques that surface unknown unknowns, which static checklists or historical data cannot capture.

Exam trap

The trap here is that candidates often choose a standard threat checklist (Option B) because it seems systematic and comprehensive, but the question asks for the technique BEST suited for identifying a wide range of potential threats, which requires creative, collaborative exploration beyond predefined lists.

How to eliminate wrong answers

Option B is wrong because a standard threat checklist is inherently limited to predefined threats and cannot identify novel or context-specific threats that emerge from the unique environment or technology stack. Option C is wrong because reviewing historical incident logs only reveals threats that have already materialized, missing latent or future-oriented threats that have not yet occurred. Option D is wrong because interviewing department heads individually lacks the synergistic cross-pollination of ideas that occurs in a group workshop, often resulting in siloed perspectives and missed interdependencies.

275
MCQeasy

A hospital's risk practitioner is identifying risks for a new telehealth platform. The IT director asks which source would be MOST useful for identifying vulnerabilities specific to the platform's underlying commercial software components. Which of the following should the practitioner use?

A.A business impact analysis (BIA) questionnaire.
B.The IT balanced scorecard and service level reports.
C.The Common Vulnerabilities and Exposures (CVE) database.
D.The organization's incident response postmortem reports.
AnswerC

CVE is a publicly maintained catalog of known vulnerabilities in commercial and open-source software, each with a unique identifier. Because the telehealth platform relies on commercial components, searching CVE entries for those products surfaces specific, documented weaknesses that can feed the risk register. It directly addresses vulnerability identification for known software, which is exactly the task described.

Why this answer

CVE is the standard reference catalog for publicly known vulnerabilities in commercial and open-source products, making it the most direct source for identifying weaknesses in the telehealth platform's software components. The other sources address incidents, business impact, or service performance rather than the technical vulnerabilities present in the commercial software itself.

Exam trap

The trap here is choosing an internal document that sounds security-related, such as postmortems, when the question asks specifically about identifying vulnerabilities in commercial software components.

276
MCQhard

During a risk assessment, the risk team identifies that a legacy system has multiple known vulnerabilities that cannot be patched. The system is critical for operations. Which of the following risk treatment options is MOST appropriate?

A.Accept the risk and monitor
B.Remediate by applying patches from the vendor
C.Avoid the risk by decommissioning the system
D.Mitigate by implementing compensating controls
AnswerD

Compensating controls such as network segmentation, enhanced monitoring and strict access restrictions reduce the likelihood or impact of exploitation while the legacy system remains unpatched, matching the constraint that patching is impossible for a critical system.

Why this answer

Since the legacy system cannot be patched (Option B is impossible) and is critical for operations (decommissioning would disrupt the business, making Option C too drastic), the most appropriate treatment is to implement compensating controls. These controls, such as network segmentation, strict access controls, or an application-layer firewall, reduce the likelihood or impact of exploitation without modifying the vulnerable system itself, aligning with the risk mitigation strategy.

Exam trap

The trap here is that candidates often choose 'Accept the risk and monitor' (Option A) because they confuse 'acceptance' with a valid risk response for unpatched systems, failing to recognize that acceptance requires a formal decision and compensating controls when vulnerabilities are known and exploitable on critical assets.

How to eliminate wrong answers

Option A is wrong because accepting the risk without active monitoring or compensating controls is inappropriate when known, exploitable vulnerabilities exist on a critical system; passive acceptance increases exposure unnecessarily. Option B is wrong because the scenario explicitly states the system cannot be patched, making remediation via vendor patches technically infeasible. Option C is wrong because decommissioning a critical system would avoid the risk but at the cost of severe operational disruption, which is not the most appropriate response when compensating controls can reduce risk while maintaining operations.

277
MCQmedium

A risk practitioner at a regional hospital is building a risk register for its new electronic health record (EHR) system. The system stores protected health information (PHI) and is subject to HIPAA. The practitioner wants to ensure that the risk register captures the potential for unauthorized disclosure of PHI. Which of the following should the practitioner PRIMARILY use to identify the relevant threats and vulnerabilities for this system?

A.A review of the vendor's SOC 2 Type II report
B.A control self-assessment (CSA) workshop with clinical staff
C.A business impact analysis (BIA) focused on recovery time objectives
D.A vulnerability assessment combined with a threat modeling exercise
AnswerD

A vulnerability assessment scans the EHR system for known technical weaknesses (e.g., missing patches, misconfigurations), while threat modeling systematically identifies how threats could exploit those weaknesses to cause unauthorized disclosure. Together they provide a structured, evidence-based inventory of threats and vulnerabilities. This is the primary approach for identifying relevant risks in a new system handling sensitive data.

Why this answer

Threat modeling and vulnerability assessment are complementary techniques that together provide a comprehensive identification of threats and vulnerabilities. Threat modeling explores how threat agents could exploit weaknesses, while vulnerability assessment discovers actual technical flaws. This combination ensures the risk register is grounded in both design-level and operational weaknesses, which is essential for a system holding PHI.

Other methods either focus on control effectiveness or impact, not identification.

Exam trap

The trap here is assuming that a compliance report or control assessment satisfies the need to identify threats and vulnerabilities, when in fact those activities evaluate controls rather than discover new weaknesses.

278
Multi-Selecthard

A multinational manufacturer is consolidating IT risk data from business units into a single enterprise risk report for the board. The risk manager must ensure the report supports effective risk-based decision making. Which TWO of the following characteristics are MOST important for the consolidated report to include? (Choose two.)

Select 2 answers
A.Consistent risk rating criteria and definitions applied across all business units.
B.A complete inventory of every IT asset and its configured technical settings.
C.A forecast of IT budget spend for the next three fiscal years.
D.Detailed descriptions of every control deficiency identified during the reporting period.
E.Comparison of residual risk against approved risk tolerance for each material risk.
AnswersA, E

Consolidating data from multiple units is meaningless if each unit rates likelihood and impact differently. Common criteria and definitions make ratings comparable, allow aggregation without distortion, and let the board see a true enterprise view. This consistency also supports trend analysis over time and fair prioritization across regions and functions, which is essential when resources are limited and trade-offs must be justified.

Why this answer

An enterprise risk report earns its value by enabling decisions, which requires two things: comparability and relevance to tolerance. Consistent rating criteria and definitions across business units make aggregated data trustworthy, while showing residual risk against approved tolerance tells the board where intervention is needed. Together they convert disparate unit-level data into a coherent enterprise view that supports prioritization, resource allocation, and formal risk acceptance decisions.

Exam trap

The trap here is selecting exhaustive operational detail, such as full asset inventories or every control deficiency, instead of the comparability and tolerance context that make a consolidated report decision-useful.

279
MCQhard

A risk practitioner is assessing the likelihood of a distributed denial-of-service (DDoS) attack against an online retailer's checkout service during peak shopping season. Which of the following factors would MOST increase the assessed likelihood of this event?

A.The checkout service uses a content delivery network with DDoS mitigation
B.The organization has no documented incident response plan for availability attacks
C.The checkout service is hosted in a single data center region
D.Peer retailers experienced a surge in DDoS attacks during the same peak period last year
AnswerD

Observed attacks against comparable organizations in the same seasonal window indicate an active, capable threat community targeting this sector. That external threat activity directly raises the probability that the retailer's checkout service will be attacked during the upcoming peak. Threat intelligence and peer incident data are core inputs to likelihood estimation in a risk assessment.

Why this answer

Likelihood reflects the probability that a threat will act against an exposed asset, so evidence of an active threat community targeting similar retailers in the same season is the strongest driver. Mitigating controls such as CDN-based DDoS protection lower likelihood, while resilience gaps and missing response plans primarily affect impact and recovery. Peer incident data is a standard threat intelligence input for likelihood estimation.

Exam trap

The trap here is selecting an architectural weakness such as single-region hosting, which affects the severity of an outage rather than the probability that an attack will occur.

280
MCQhard

A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?

A.Increase key lengths for all symmetric encryption to 256 bits
B.Ignore the risk until quantum computers are commercially available
C.Begin post-quantum cryptography migration planning and crypto-agility assessment
D.Replace all existing cryptographic algorithms with post-quantum algorithms immediately
AnswerC

Harvest-now-decrypt-later exposure means encrypted data captured today is at risk once quantum advantage arrives, so migration planning and crypto-agility assessment must start immediately. This satisfies the stem's immediate-action constraint, since inventorying algorithms and enabling rapid substitution takes years.

Why this answer

Beginning post-quantum cryptography (PQC) migration planning and crypto-agility assessment is the most appropriate immediate action because it addresses the long-term risk without premature disruption. Crypto-agility ensures systems can quickly switch algorithms, and planning allows for a smooth transition as standards mature. This proactive approach aligns with risk management principles.

Exam trap

CRISC often tests risk response timing; candidates may choose extreme actions (ignore or immediate replacement) instead of a balanced, proactive approach like planning and agility assessment.

How to eliminate wrong answers

Option A is wrong because increasing symmetric key lengths to 256 bits does not address the quantum threat to asymmetric algorithms (e.g., RSA, ECC), which are vulnerable to Shor's algorithm; symmetric keys are already relatively safe with 256 bits against Grover's algorithm. Option B is wrong because ignoring the risk until quantum computers are available is negligent; migration takes years, and data harvested now could be decrypted later (harvest now, decrypt later). Option D is wrong because immediately replacing all algorithms with post-quantum ones is impractical; PQC standards are still evolving, and many systems lack support, leading to interoperability and performance issues.

281
MCQmedium

A risk practitioner at a healthcare payer is reviewing the organization's identity and access management (IAM) controls. The practitioner discovers that several terminated employees still have active single sign-on (SSO) sessions and directory accounts. Which of the following is the MOST effective control to address this risk?

A.Implement an automated joiner-mover-leaver (JML) process integrated with the HR system to disable accounts and revoke sessions upon termination.
B.Enforce a policy that terminated employees must return their laptops and badges before their final paycheck is issued.
C.Require managers to submit a ticket to the service desk within 24 hours of an employee's termination to request account deactivation.
D.Conduct quarterly user access reviews to identify and remove accounts belonging to terminated employees.
AnswerA

An automated JML process integrated with HR ensures that account disabling and session revocation occur promptly and consistently when an employee leaves. It reduces the window of exposure caused by manual delays and human error, directly mitigating the risk of unauthorized access by terminated employees. This is the most effective preventive and detective control for the described scenario.

Why this answer

The most effective control is an automated JML process integrated with HR, as it ensures timely and consistent deactivation of accounts and revocation of sessions upon termination. Manual or periodic reviews introduce delays that can be exploited. By automating the leaver process, the organization reduces the risk of unauthorized access and aligns with CRISC principles of implementing preventive controls to mitigate IT risk.

Exam trap

The trap here is assuming that manual or periodic reviews, such as quarterly access reviews or ticket-based deactivation, are sufficient to manage the risk of terminated employees retaining access, when in fact they leave significant windows of exposure.

282
Multi-Selectmedium

A risk assessment team is prioritizing risks for treatment using inherent risk ratings. Which TWO factors should be considered when deciding which risks to treat first?

Select 2 answers
A.The asset's replacement value
B.Cost-benefit analysis of potential controls
C.Risk ranking by inherent risk score
D.The risk owner's department budget
E.The number of controls already in place
AnswersB, C

Cost-benefit analysis weighs each control's implementation expense against the risk reduction it delivers, revealing where treatment gives the greatest return. This satisfies the stem's prioritisation requirement by ensuring resources target risks where mitigation is economically justified rather than merely highest-scoring.

Why this answer

Option B (Cost-benefit analysis of potential controls) is correct because risk treatment decisions must weigh the cost of implementing a control against the expected reduction in loss exposure; a control is only justified when its benefit (risk reduction) exceeds its cost, ensuring resources are allocated efficiently. Option C (Risk ranking by inherent risk score) is correct because inherent risk ratings—likelihood and impact assessed before controls—establish the priority order; risks with the highest inherent scores represent the greatest potential exposure and should generally be treated first. Option A is not a prioritization factor by itself, since replacement value is only one input into impact and does not account for likelihood or existing controls.

Option D is incorrect because a department's budget is an organizational constraint, not a risk-based criterion for prioritization. Option E is incorrect because the number of controls already in place relates to residual risk and control effectiveness, not to ranking inherent risk for treatment priority.

Exam trap

CRISC often tests the confusion between inherent and residual risk — candidates pick 'number of controls already in place' which relates to residual risk, not inherent prioritization.

283
MCQhard

A change to a critical application is being implemented without updating the associated security controls. This is most likely a failure in which process?

A.Control design
B.Change management
C.Project management
D.User training
AnswerB

Change management governs modifications to production systems, ensuring security controls are assessed and updated alongside application changes. This scenario's failure to update associated controls during implementation directly violates that process, making it the correct answer over risk assessment or control monitoring.

Why this answer

A change to a critical application that bypasses updating security controls is a direct failure of the change management process. Change management requires that all changes, including security controls, be reviewed, approved, and documented before implementation to maintain the risk posture. Without this process, the organization loses visibility and control over the security implications of the change, leading to potential vulnerabilities.

Exam trap

The trap here is that candidates confuse 'control design' (the initial architecture of controls) with the ongoing governance process of 'change management' that ensures controls are kept in sync with system modifications.

How to eliminate wrong answers

Option A is wrong because control design refers to the initial creation or selection of controls, not the process of ensuring they are updated when a change occurs. Option C is wrong because project management focuses on delivering a project's scope, schedule, and budget, not specifically on the procedural requirement to update security controls during operational changes. Option D is wrong because user training addresses end-user competency, not the procedural governance of change implementation and security control alignment.

284
MCQeasy

A risk analyst is reviewing control monitoring results and notices that a detective control has a high false positive rate. What is the BEST action to improve the control's efficiency?

A.Adjust the control's threshold or criteria
B.Accept the false positives as operational tolerance
C.Increase the monitoring frequency
D.Convert the control to a preventive control
AnswerA

A high false positive rate means the detective control flags legitimate activity, wasting investigator effort. Adjusting the threshold or criteria tunes detection sensitivity, reducing noise while preserving genuine alerts, directly improving the control's operational efficiency.

Why this answer

A high false positive rate in a detective control indicates that the control's threshold or criteria are too sensitive, triggering alerts for benign events. Adjusting the threshold (e.g., increasing the baseline or fine-tuning anomaly detection parameters) directly reduces false positives, improving efficiency without sacrificing detection capability. This is the most targeted action to optimize signal-to-noise ratio.

Exam trap

The trap here is that candidates often confuse 'efficiency' with 'frequency' or 'control type,' mistakenly thinking more monitoring or converting to preventive control will solve the false positive issue, when the correct action is to tune the control's sensitivity.

How to eliminate wrong answers

Option B is wrong because accepting false positives as operational tolerance does not improve efficiency; it merely accepts the waste of resources investigating non-events. Option C is wrong because increasing monitoring frequency would generate even more false positives, exacerbating the problem and increasing analyst fatigue. Option D is wrong because converting a detective control to a preventive control is a fundamental design change that may not be feasible or appropriate for the specific risk, and it does not address the root cause of high false positives.

285
MCQmedium

A company is conducting a risk assessment of a critical third-party service provider. Which of the following is the BEST source of information to identify risks associated with the provider's sub-processors?

A.The provider's documented vendor risk management program and audit reports of sub-processors
B.Service level agreements in the contract
C.SOC 2 Type II reports of the primary provider
D.Public announcements of data breaches involving the provider
AnswerA

The provider's vendor risk management programme and sub-processor audit reports give direct, independent evidence of how fourth parties are controlled, satisfying the need to identify risks beyond the provider itself. Audits test actual controls, whereas questionnaires rely on self-reporting, so this source best exposes inherited and concentration risk.

Why this answer

The provider's documented vendor risk management program and audit reports of sub-processors are the best source because they directly detail the controls, security posture, and compliance status of the sub-processors. This information is specific to the sub-processors' operations, unlike general reports or contracts that may not cover their unique risks. It enables the company to assess third-party and fourth-party risks as part of a comprehensive IT risk identification process.

Exam trap

The trap here is that candidates often choose SOC 2 Type II reports of the primary provider (Option C) thinking they cover all downstream risks, but they typically exclude sub-processor controls unless specifically scoped.

How to eliminate wrong answers

Option B is wrong because service level agreements (SLAs) define performance and availability metrics, not the security controls or risk posture of sub-processors; they are contractual, not evidence-based. Option C is wrong because SOC 2 Type II reports of the primary provider cover the primary provider's controls, not those of its sub-processors, and may exclude sub-processor operations entirely. Option D is wrong because public announcements of data breaches are reactive and historical, not a proactive source for identifying current risks associated with sub-processors.

286
Multi-Selectmedium

Which TWO controls are most effective for reducing the risk of data leakage from endpoints in a remote work environment?

Select 2 answers
A.Conduct regular phishing simulation campaigns.
B.Implement Data Loss Prevention (DLP) software.
C.Enforce complex password policies for local accounts.
D.Require full-disk encryption on all laptops.
E.Use a VPN for all remote connections.
AnswersB, D

DLP software inspects endpoint egress content and blocks sensitive data transfers, directly satisfying the remote-work leakage constraint where perimeter controls cannot see off-network traffic. It enforces policy on data in use and in motion regardless of location.

Why this answer

Option B, implementing Data Loss Prevention (DLP) software, is correct because DLP solutions inspect data in use, in motion, and at rest, applying content-aware policies (regex, keywords, file fingerprints) to block or quarantine sensitive data from being exfiltrated via email, USB, cloud uploads, or clipboard on remote endpoints. Option D, requiring full-disk encryption on all laptops, is correct because technologies like BitLocker, FileVault, or LUKS with TPM/PIN protect data at rest, ensuring that if a remote worker's laptop is lost or stolen, the stored data cannot be read without the decryption key, directly reducing leakage risk. Option A, phishing simulations, primarily reduces credential-theft and malware risk through user awareness, not endpoint data exfiltration.

Option C, complex password policies for local accounts, hardens authentication against brute-force but does not prevent a legitimate user or malware from copying data out. Option E, a VPN, encrypts data in transit and hides traffic from local networks, but it does not stop an authorized endpoint from leaking data to unauthorized destinations.

Exam trap

ISACA often tests the misconception that a VPN provides comprehensive data protection, but in reality it only secures data in transit, not data at rest or data in use on the endpoint.

287
Multi-Selectmedium

A retail company is conducting a risk assessment for its point-of-sale (POS) system. The risk team has identified several factors that could affect the likelihood of a data breach. Which TWO factors are considered threat event frequency components that increase the likelihood of a breach? (Choose two.)

Select 2 answers
A.The strength of the encryption used for payment card data
B.The number of attempted intrusions per month
C.The percentage of POS terminals running outdated software
D.The average time to detect a breach
E.The presence of organized crime groups targeting retail payment systems
AnswersB, E

The number of attempted intrusions per month is a direct measure of threat event frequency. A higher number of attempts increases the likelihood that one will succeed, assuming the vulnerability exists. This is a key input in quantitative risk analysis models like FAIR, where threat event frequency is estimated from historical data or industry trends. It directly affects the probability of a breach.

Why this answer

Threat event frequency is the rate at which threat actors attempt to exploit a vulnerability. The number of attempted intrusions per month directly measures this rate. The presence of organized crime groups targeting retail payment systems indicates a higher frequency of attacks because these groups are actively seeking to compromise POS systems.

The other factors relate to vulnerability, detection, or impact, not the frequency of threat events.

Exam trap

The trap here is confusing vulnerability factors, such as outdated software or encryption strength, with threat event frequency, which is about how often attacks are attempted.

288
MCQmedium

A risk practitioner is designing a monitoring dashboard for operational risk. Which of the following is the most important consideration?

A.Automate the generation of reports.
B.Use real-time data feeds.
C.Tailor the information to the needs of the target audience.
D.Include all available risk indicators.
AnswerC

A dashboard only drives action if its audience understands and trusts it. Tailoring metrics, thresholds and granularity to the target audience's decisions ensures operational risk information is relevant and actionable, which matters more than visual polish or data volume.

Why this answer

The primary goal of a monitoring dashboard is to enable effective decision-making. Tailoring information to the target audience ensures that stakeholders receive relevant, actionable data, reducing cognitive load and preventing alert fatigue. Without this alignment, even the most technically sophisticated dashboard fails its core purpose of supporting risk-informed decisions.

Exam trap

The trap here is that candidates confuse technical capability (real-time data, automation, completeness) with the business requirement of relevance, leading them to choose a technically impressive but contextually inappropriate option like B or D.

How to eliminate wrong answers

Option A is wrong because automating report generation addresses efficiency, not the fundamental requirement of relevance; a dashboard can be fully automated yet still present irrelevant or overwhelming data. Option B is wrong because real-time data feeds are not always necessary for operational risk monitoring—latency tolerance varies by risk type, and real-time feeds can introduce noise and false positives without proper context. Option D is wrong because including all available risk indicators violates the principle of materiality; excessive indicators obscure critical signals and violate the 'less is more' heuristic for effective dashboards.

289
MCQmedium

During an IT risk assessment for a new cloud-based customer relationship management (CRM) system, the risk practitioner identifies that the vendor's data center is located in a country with different data protection regulations. Which of the following is the MOST appropriate next step?

A.Conduct a legal review to assess regulatory implications and contractual safeguards.
B.Recommend migrating to a different cloud provider.
C.Implement technical controls to encrypt data in transit and at rest.
D.Accept the risk because the vendor is compliant with industry standards.
AnswerA

Cross-border data flows trigger distinct legal obligations, so a legal review identifies applicable transfer restrictions and whether contractual safeguards such as standard contractual clauses adequately mitigate them. This directly addresses the regulatory divergence constraint before technical or operational controls are considered.

Why this answer

When a cloud vendor's data center is in a jurisdiction with different data protection regulations, the immediate priority is to understand the legal and contractual implications before making any technical or risk acceptance decisions. A legal review will identify specific regulatory conflicts (e.g., GDPR vs. local law) and assess whether existing contractual safeguards (such as Standard Contractual Clauses or Binding Corporate Rules) adequately address the gap. This step ensures that subsequent risk treatment decisions are informed by compliance requirements rather than assumptions.

Exam trap

The trap here is that candidates often jump to technical controls (encryption) as a universal solution, overlooking that regulatory compliance is a legal and contractual issue that cannot be fully resolved by encryption alone.

How to eliminate wrong answers

Option B is wrong because recommending migration to a different cloud provider is premature without first understanding whether the current vendor's legal and contractual framework can be remediated; migration may be unnecessary or more costly than adjusting safeguards. Option C is wrong because implementing technical controls like encryption (e.g., TLS 1.3 for transit, AES-256 for at-rest) addresses data confidentiality but does not resolve regulatory compliance issues such as data residency, lawful access by foreign governments, or cross-border transfer restrictions. Option D is wrong because accepting risk based solely on vendor compliance with industry standards (e.g., ISO 27001) ignores the fact that regulatory requirements are jurisdiction-specific and may impose obligations beyond those standards.

290
MCQhard

An organization uses a risk register that includes inherent risk, control effectiveness, and residual risk. During a quarterly review, the risk owner updates control effectiveness from 'partially effective' to 'effective'. What effect does this have on the residual risk rating?

A.Inherent risk changes
B.Residual risk decreases
C.Residual risk increases
D.Residual risk remains unchanged
AnswerB

Residual risk is derived from inherent risk adjusted by control effectiveness. Upgrading control effectiveness from partially effective to effective strengthens mitigation, so the residual risk rating decreases, reflecting lower remaining exposure after the quarterly review update.

Why this answer

When control effectiveness is updated from 'partially effective' to 'effective', the control is now better at mitigating the inherent risk. Since residual risk is calculated as inherent risk minus the risk reduction provided by controls, improving control effectiveness directly lowers the residual risk rating. The risk register reflects this by showing a decreased residual risk value, assuming inherent risk remains unchanged.

Exam trap

CRISC often tests the misconception that residual risk is static or that inherent risk changes with control improvements, but the key trap here is confusing inherent risk (which is independent of controls) with residual risk (which is dependent on control effectiveness).

How to eliminate wrong answers

Option A is wrong because inherent risk is the risk level before considering controls; it is determined by the nature of the threat and vulnerability, not by control effectiveness, so updating control effectiveness does not change inherent risk. Option C is wrong because improving control effectiveness reduces, not increases, the residual risk; an increase would occur if control effectiveness were downgraded. Option D is wrong because residual risk is directly affected by changes in control effectiveness; it does not remain unchanged when the control's ability to mitigate risk improves.

291
MCQeasy

A control owner reports that a preventive control is operating as designed, but the risk owner is concerned that residual risk remains high. What should the risk practitioner do NEXT?

A.Update the risk register to reflect the high residual risk.
B.Recommend additional compensating controls.
C.Escalate the issue to the risk committee.
D.Perform a control effectiveness test to validate the control.
AnswerD

A control owner's assertion that a preventive control operates as designed is not evidence of effectiveness. Testing validates whether the control actually mitigates the risk, informing whether residual risk is genuinely high or the design is inadequate.

Why this answer

The risk practitioner must first validate the control's effectiveness before taking any further action. Even though the control owner reports the preventive control is operating as designed, the risk owner's concern about high residual risk suggests the control may not be adequately mitigating the risk. Performing a control effectiveness test (D) provides objective evidence to determine whether the control is actually reducing risk to an acceptable level, which is the necessary next step before updating the risk register, recommending compensating controls, or escalating.

Exam trap

The trap here is that candidates assume the control owner's report of 'operating as designed' is sufficient evidence, but CRISC emphasizes that control effectiveness must be independently validated through testing before concluding on residual risk.

How to eliminate wrong answers

Option A is wrong because updating the risk register to reflect high residual risk should only occur after the control's effectiveness has been validated; prematurely updating without evidence could misrepresent the risk posture. Option B is wrong because recommending additional compensating controls is premature without first determining whether the existing control is effective; if the control is effective, compensating controls may be unnecessary and introduce unnecessary cost and complexity. Option C is wrong because escalating to the risk committee is a governance action that should be taken only after the risk practitioner has gathered sufficient evidence through testing; escalation without validation could cause unnecessary alarm or misdirect committee attention.

292
Multi-Selectmedium

Which TWO of the following are leading indicators that could be used as KRIs for information security risk? (Select TWO.)

Select 2 answers
A.Number of security incidents in the past quarter
B.Number of audit findings from the last audit
C.Patch lag (average time to apply critical patches)
D.Spike in failed authentication attempts
E.Percentage of employees who completed security awareness training
AnswersC, D

Patch lag measures how long critical vulnerabilities remain unpatched, exposing the organisation to exploitation. Because it tracks a condition that precedes a potential breach, it functions as a leading indicator, unlike lagging metrics such as incident counts that record harm already realised.

Why this answer

Option C (patch lag, the average time to apply critical patches) is a leading indicator because it measures an exposure window that predicts future compromise likelihood — the longer critical patches remain unapplied, the greater the chance an attacker exploits a known CVE — so it signals risk before incidents occur. Option D (a spike in failed authentication attempts) is a leading indicator because it reflects anomalous activity such as brute-force or credential-stuffing attempts that typically precede a breach, giving early warning of an imminent attack. The unmarked options are lagging or outcome metrics: A (number of security incidents in the past quarter) and B (number of audit findings from the last audit) both report events that have already happened, and E (percentage of employees who completed security awareness training) is a compliance/training completion metric rather than a predictive signal of attack activity.

Exam trap

The trap here is that candidates often confuse lagging indicators (like incident counts or audit findings) with leading indicators, failing to recognize that KRIs must be predictive and forward-looking to proactively manage risk rather than merely report on past events.

293
MCQhard

When performing asset-based vulnerability identification, a security analyst uses the Common Vulnerabilities and Exposures (CVE) database along with the National Vulnerability Database (NVD). Which of the following BEST describes the relationship between CVE and NVD?

A.Both databases are identical and maintained by the same organization.
B.CVE is the authoritative source for vulnerability scoring, while NVD assigns identifiers.
C.NVD lists only vulnerabilities that are actively exploited, while CVE lists all known vulnerabilities.
D.CVE provides unique identifiers for vulnerabilities, and NVD provides additional analysis including CVSS scores.
AnswerD

CVE assigns each publicly disclosed vulnerability a unique identifier (CVE-YYYY-NNNN). NVD enriches those CVE records with analysis, including CVSS severity scores, CWE classification and affected product data, so the two are complementary rather than duplicates.

Why this answer

CVE (Common Vulnerabilities and Exposures) is a dictionary that assigns a unique identifier (e.g., CVE-2024-12345) to each publicly disclosed vulnerability, providing a common naming standard. NVD (National Vulnerability Database), maintained by NIST, consumes CVE records and enriches them with CVSS base scores, CWE classifications, CPE applicability statements, and references. So CVE provides the identifier and NVD provides the analysis and scoring.

Exam trap

The trap here is confusing the roles of CVE and NVD — candidates often assume CVE provides scoring or that NVD assigns the CVE IDs, when in fact CVE is the identifier dictionary and NVD is the enrichment/scoring database.

How to eliminate wrong answers

Option A is wrong because CVE is maintained by MITRE (sponsored by CISA) while NVD is maintained by NIST — they are distinct organizations with distinct roles, not identical databases. Option B is wrong because it reverses the roles: CVE assigns identifiers, not scores, and NVD provides CVSS scoring, not identifiers. Option C is wrong because NVD does not limit itself to actively exploited vulnerabilities; it catalogs all CVE entries it enriches, while actively exploited vulnerabilities are tracked separately in CISA's Known Exploited Vulnerabilities (KEV) catalog.

294
MCQeasy

Which of the following best describes residual risk?

A.Risk that is transferred to a third party
B.Risk that is avoided by eliminating the activity
C.Risk without any controls in place
D.Risk after assessing control effectiveness
AnswerD

Residual risk is the exposure that remains after controls have been implemented and their effectiveness assessed. It reflects what is left once mitigation is accounted for, distinguishing it from inherent risk, which exists before any controls are applied.

Why this answer

Residual risk is the risk that remains after management has implemented risk responses and assessed the effectiveness of existing controls. It is calculated by considering the inherent risk (risk without controls) and the risk reduction provided by controls, factoring in control gaps or weaknesses. Option D correctly captures this definition by emphasizing the assessment of control effectiveness.

Exam trap

The trap here is confusing inherent risk (risk with no controls) with residual risk (risk after controls), leading candidates to incorrectly select Option C, especially when the question emphasizes 'risk assessment' without explicitly mentioning control evaluation.

How to eliminate wrong answers

Option A is wrong because transferring risk to a third party (e.g., via insurance or outsourcing) is a risk response strategy, not a measure of remaining risk after controls. Option B is wrong because avoiding risk by eliminating the activity is another risk response (risk avoidance), not the residual risk that persists after controls are applied. Option C is wrong because risk without any controls in place is defined as inherent risk, not residual risk; residual risk explicitly accounts for controls that are in place and their effectiveness.

295
MCQhard

An international bank is expanding its operations into a new country with strict data localization laws. The IT department plans to use a cloud service provider that stores data in neighboring countries but promises compliance. The risk team has identified several potential risks: regulatory fines for non-compliance, data interception during cross-border transmission, and difficulty in auditing the cloud provider. The legal team advises that the contract includes data protection clauses, but these have not been tested. The risk manager must now prioritize risk identification efforts. What is the MOST important risk identification step the risk team should undertake?

A.Review the cloud provider's SOC 2 report.
B.Conduct a thorough legal review of the contract's data handling clauses.
C.Perform a regulatory compliance assessment specific to the new country's laws.
D.Map data flows to ensure all data is properly classified.
AnswerC

Untested contractual clauses cannot demonstrate compliance with the new country's data localization laws, and the provider stores data in neighbouring jurisdictions. A country-specific regulatory compliance assessment establishes the actual legal obligations first, grounding all subsequent risk identification and prioritisation.

Why this answer

The most critical risk identification step when entering a new country with strict data localization laws is to perform a regulatory compliance assessment specific to that country's laws. This ensures the bank understands the exact legal requirements for data storage, processing, and transfer, which directly informs whether the cloud provider's promised compliance is achievable. Without this assessment, the risk team cannot accurately identify the scope and severity of regulatory fines or other legal risks.

Exam trap

The trap here is that candidates often choose Option B (legal review of contract) because they assume contractual clauses are the primary risk mitigation, but the question asks for risk identification, and without first understanding the local law, the contract's adequacy cannot be evaluated.

How to eliminate wrong answers

Option A is wrong because reviewing the cloud provider's SOC 2 report focuses on internal controls and security practices, not on compliance with specific data localization laws of the new country; SOC 2 reports are based on AICPA trust service criteria and do not address jurisdictional legal requirements. Option B is wrong because conducting a thorough legal review of the contract's data handling clauses, while important, assumes the contract is the primary risk control, but the contract clauses have not been tested and may not align with the new country's untested legal interpretations; this step is secondary to understanding the actual regulatory landscape. Option D is wrong because mapping data flows to ensure proper classification is a data governance activity that helps understand where data resides and moves, but it does not directly identify the legal risks of non-compliance with data localization laws; it is a supporting step, not the most critical for risk identification.

296
MCQeasy

An organization uses automated SIEM rules to continuously monitor for unauthorized access attempts. This is an example of which type of monitoring?

A.Periodic control testing
B.Vulnerability scanning
C.Access review
D.Continuous monitoring
AnswerD

Continuous monitoring fits because the SIEM rules run automatically and without interruption, satisfying the stem's requirement for continuous oversight of unauthorised access attempts. Unlike periodic or ad hoc reviews, this provides ongoing, real-time detection aligned with CRISC's definition of continuous monitoring as automated, recurring control assessment.

Why this answer

Continuous monitoring involves the use of automated tools, such as Security Information and Event Management (SIEM) systems, to provide real-time or near-real-time oversight of security events. In this scenario, the SIEM rules are configured to detect unauthorized access attempts as they occur, which aligns directly with the definition of continuous monitoring rather than periodic or point-in-time assessments.

Exam trap

The trap here is that candidates confuse 'continuous monitoring' with 'periodic control testing' or 'access review' because they all involve oversight of access, but only continuous monitoring uses automated, real-time detection of events as they happen, not scheduled checks or static permission audits.

How to eliminate wrong answers

Option A is wrong because periodic control testing refers to scheduled, manual or automated checks performed at set intervals (e.g., quarterly or annually), not the ongoing, real-time analysis provided by SIEM rules. Option B is wrong because vulnerability scanning is a specific type of assessment that identifies known vulnerabilities (e.g., missing patches, misconfigurations) in systems or networks, not the detection of unauthorized access attempts in real time. Option C is wrong because an access review is a periodic or ad-hoc audit of user permissions and entitlements (e.g., reviewing Active Directory group memberships), not the continuous detection of access attempts via SIEM correlation rules.

297
MCQeasy

Which risk identification technique relies on analyzing past incidents to predict future risks?

A.Brainstorming
B.Loss event data analysis
C.SWOT analysis
D.Delphi technique
AnswerB

Loss event data analysis mines historical incident and loss records to identify patterns and frequencies, then extrapolates them into forward-looking risk predictions. This empirical, evidence-based technique distinguishes it from speculative methods such as brainstorming or scenario analysis.

Why this answer

Loss event data analysis (B) is the correct risk identification technique because it systematically examines historical incident records, such as security logs, breach reports, and audit findings, to identify patterns and trends that can predict future risks. This empirical approach leverages past loss events to quantify likelihood and impact, making it distinct from generative or qualitative methods.

Exam trap

The trap here is that candidates confuse 'brainstorming' (a forward-looking ideation method) with data-driven analysis, failing to recognize that only loss event data analysis explicitly relies on historical incident records to predict future risks.

How to eliminate wrong answers

Option A is wrong because brainstorming is a creative, group-based technique that generates ideas without relying on historical data, focusing instead on hypothetical scenarios and expert intuition. Option C is wrong because SWOT analysis evaluates internal strengths/weaknesses and external opportunities/threats in a strategic context, not past incident records for risk prediction. Option D is wrong because the Delphi technique uses iterative anonymous surveys to achieve consensus among experts, not analysis of historical loss events.

298
MCQmedium

A financial services firm has a risk register entry for a core banking application with an inherent risk score of 9 (high). The risk owner implements a new database activity monitoring tool and role-based access reviews. After implementation, the residual risk score is reassessed at 6 (medium). The risk owner now wants to formally document that the risk has been reduced to an acceptable level. Which action should the risk practitioner recommend NEXT?

A.Update the risk register to reflect the new residual risk score and obtain risk owner sign-off.
B.Escalate the residual risk to the board of directors for approval.
C.Initiate a new risk assessment to identify any remaining vulnerabilities.
D.Perform a penetration test to validate the effectiveness of the new controls.
AnswerA

Updating the risk register with the reassessed residual risk score and obtaining formal risk owner acceptance ensures the risk treatment is documented and the risk is owned at the appropriate level. This aligns with CRISC practices for maintaining an accurate risk profile and confirming that residual risk aligns with risk appetite.

Why this answer

After implementing risk mitigation controls, the risk practitioner must ensure the risk register is updated with the new residual risk score and that the risk owner formally accepts the remaining risk. This confirms that the risk treatment has been effective and that the residual risk is within the defined risk appetite. Documentation and sign-off are essential for auditability and governance.

Exam trap

The trap here is assuming that additional technical testing or escalation is always required after control implementation, rather than focusing on the fundamental step of updating the risk register and obtaining risk owner acceptance.

299
MCQmedium

A hospital's risk practitioner is building a risk register entry for a ransomware attack on its electronic health record (EHR) system. The practitioner wants to express the risk in terms of how often the event is expected to occur and how much it would cost if it did. Which of the following BEST describes the two components being quantified?

A.Threat and vulnerability
B.Inherent risk and residual risk
C.Likelihood and impact
D.Risk appetite and risk tolerance
AnswerC

Likelihood expresses how probable the ransomware event is over a defined period, and impact expresses the resulting loss in financial or operational terms. Together they form the two core dimensions used to score a risk register entry. For the EHR scenario, likelihood might be annualized probability and impact could be quantified as recovery cost plus downtime revenue loss.

Why this answer

Quantitative risk analysis expresses each risk event through the probability it will occur and the resulting loss if it does. Likelihood and impact are the standard ISACA dimensions used in a risk register entry, and they can be combined into annualized loss expectancy. Governance thresholds, contributing factors, and control-state comparisons are separate concepts that do not describe the two quantified components.

Exam trap

The trap here is assuming that threat and vulnerability are the quantified components of a risk entry, when they are inputs that shape likelihood and impact rather than the measured dimensions themselves.

300
MCQhard

A multinational corporation has a risk register entry for a potential data breach of customer information. The risk owner has decided to purchase cyber insurance to cover financial losses from a breach. Which of the following BEST describes the residual risk after this risk response?

A.The residual risk remains, but the financial impact is partially transferred to the insurer.
B.The residual risk is reduced to zero because the risk has been transferred.
C.The residual risk is increased because the insurance policy may not cover all breach scenarios.
D.The residual risk is eliminated because the insurance covers all financial losses.
AnswerA

Purchasing cyber insurance is a risk transference strategy that shifts some financial consequences to the insurer. However, the organization still bears residual risk such as reputational harm, loss of customer trust, and any costs exceeding policy limits or not covered. Thus, the residual risk remains but with reduced financial exposure.

Why this answer

Cyber insurance transfers a portion of the financial risk to the insurer, but the organization retains residual risk, including non-financial impacts and any uncovered losses. The residual risk is not eliminated or reduced to zero; it remains but with a lower financial exposure. This is a key concept in risk response: transference does not remove all risk.

Exam trap

The trap here is assuming that insurance eliminates all risk, when in reality it only transfers some financial impact and leaves residual risk.

Page 3

Page 4 of 15

Page 5