Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 301–375

1062 questions total · 15pages · All types, answers revealed

Page 4

Page 5 of 15

Page 6
301
MCQhard

An organization is considering moving from periodic control testing to continuous monitoring for its critical financial controls. What is the PRIMARY benefit of this transition?

A.Simplification of the control environment.
B.Reduction in monitoring costs.
C.Faster identification of control failures.
D.Elimination of all control failures.
AnswerC

Continuous monitoring evaluates controls automatically and near-continuously rather than at periodic intervals, so deviations surface within hours instead of at the next test cycle. This shortens the window in which a failed financial control operates undetected, enabling faster remediation.

Why this answer

Continuous monitoring provides real-time or near-real-time visibility into control performance, enabling the organization to detect control failures as soon as they occur. This is a primary benefit over periodic testing, which only identifies failures at discrete intervals, potentially allowing issues to persist undetected for longer periods.

Exam trap

The trap here is that candidates may confuse 'continuous monitoring' with 'continuous auditing' or assume it always reduces costs, but the primary benefit is improved detection speed, not cost reduction or failure elimination.

How to eliminate wrong answers

Option A is wrong because continuous monitoring typically adds complexity to the control environment (e.g., implementing automated tools, configuring alerts, and managing data streams) rather than simplifying it. Option B is wrong because continuous monitoring often increases costs due to the need for specialized software, infrastructure, and ongoing maintenance, though it can reduce long-term costs by preventing larger failures. Option D is wrong because no monitoring approach can eliminate all control failures; continuous monitoring improves detection speed but does not prevent failures from occurring in the first place.

302
MCQhard

A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk team has identified that the organization performs daily incremental backups and weekly full backups, but the backups are stored on the same network share as the EHR data. The risk owner argues that the backup strategy reduces the impact of a ransomware attack. Which statement BEST describes the residual risk after considering this control?

A.The residual risk is unchanged from the inherent risk because backups are a preventive control.
B.The residual risk is medium because the weekly full backup provides a fallback if incremental backups fail.
C.The residual risk is low because daily backups ensure data can be restored with minimal loss.
D.The residual risk is high because the backups are not isolated and could be encrypted along with the primary data.
AnswerD

Storing backups on the same network share as the primary data means ransomware can encrypt both, eliminating the recovery benefit. The control is not effective in reducing impact. Thus, the residual risk remains high. This is a common pitfall in backup strategies; best practice is to keep offline or immutable backups. The risk practitioner should identify this as a control weakness and recommend remediation.

Why this answer

The backup strategy is ineffective against ransomware because the backups reside on the same network share as the primary EHR data. Ransomware can encrypt both, so the organization may lose both primary and backup data. Therefore, the residual risk remains high.

The risk practitioner should recognize this control weakness and recommend isolating backups, such as using offline or immutable storage. This is a critical aspect of IT risk assessment: evaluating control effectiveness, not just existence.

Exam trap

The trap here is assuming that any backup strategy reduces risk, without considering whether the backups are isolated from the threat.

303
Multi-Selecteasy

An organization is performing a business impact analysis (BIA) for its critical applications. Which TWO of the following are primary objectives of a BIA?

Select 2 answers
A.Prioritize recovery of business processes based on criticality.
B.Determine the likelihood of each threat event.
C.Identify the maximum acceptable outage (MAO) for each process.
D.Calculate the annualized loss expectancy (ALE).
E.Select appropriate risk response strategies.
AnswersA, C

A BIA determines which business processes are most critical by assessing disruption impact over time, so recovery sequencing follows business dependency rather than technical convenience. Prioritising process recovery by criticality is therefore a primary BIA objective, directly satisfying the stem's requirement.

Why this answer

Option A is correct because a core purpose of the BIA is to rank business processes and their supporting applications by criticality, so that recovery efforts and resources are directed to the most essential functions first. Option C is correct because the BIA establishes the maximum acceptable outage (MAO), also expressed as maximum tolerable downtime (MTD), which defines how long a process can be unavailable before unacceptable impact occurs and drives the RTO/RPO targets. Option B is not a BIA objective; threat likelihood estimation belongs to risk assessment, not impact analysis.

Option D is not a BIA objective; ALE is a quantitative risk calculation (SLE × ARO) performed during risk analysis. Option E is not a BIA objective; selecting risk response strategies (avoid, mitigate, transfer, accept) is part of risk treatment, which follows the assessment.

Exam trap

The trap here is that candidates confuse the BIA with the broader risk assessment process, mistakenly selecting options like determining threat likelihood or calculating ALE, which are distinct activities performed after the BIA is complete.

304
MCQmedium

Refer to the exhibit. What is the most appropriate immediate action for the control failure?

A.Ignore as it was followed by a pass.
B.Escalate to the board.
C.Accept the control failure due to subsequent pass.
D.Investigate the root cause of the failure because it occurred before the pass.
AnswerD

The failure occurred before the pass, so the control operated as intended at the point of testing; investigating why it failed beforehand establishes whether the exception was genuine or a false positive before any remediation or reporting decision.

Why this answer

The most appropriate immediate action for a control failure is to investigate the root cause, regardless of a subsequent pass. A control failure indicates a breakdown in the control environment that could recur or have other implications. The fact that a later test passed does not negate the need to understand why the failure occurred, as it may point to systemic issues, process gaps, or human error that require corrective action.

Immediate investigation aligns with risk management principles of identifying and addressing root causes to prevent future failures.

Exam trap

CRISC often tests the misconception that a subsequent pass negates the need to investigate a control failure, but the correct approach is always to investigate the root cause to prevent recurrence.

How to eliminate wrong answers

Option A is wrong because ignoring a control failure is never acceptable; even if a subsequent test passes, the failure indicates a potential weakness that must be examined. Option B is wrong because escalating to the board is not an immediate action for a single control failure; escalation should follow established incident response procedures and typically only after initial investigation and assessment. Option C is wrong because accepting the control failure due to a subsequent pass is inappropriate; acceptance implies tolerating the risk without action, which is not justified without understanding the failure's cause and impact.

305
MCQmedium

A risk assessment identifies a high-likelihood, high-impact risk associated with a legacy system. The business owner decides to decommission the system to eliminate the risk. Which risk treatment option is being applied?

A.Mitigate
B.Accept
C.Transfer
D.Avoid
AnswerD

Decommissioning the legacy system removes the risk's source entirely, so no residual likelihood or impact remains. Avoidance is the only treatment that eliminates exposure rather than reducing or transferring it, satisfying the stem's high-likelihood, high-impact constraint.

Why this answer

Avoidance involves eliminating the activity that creates the risk, such as decommissioning a system.

306
MCQmedium

In a risk report presented to the board of directors, which of the following elements is most appropriate to include?

A.Vendor security assessment scores for all vendors
B.Detailed weekly firewall log analysis
C.List of all IT incidents from the past month
D.Risk heat map with top risks and status
AnswerD

A risk heat map with top risks and status translates complex risk data into a visual, prioritised format that boards can act on. It satisfies the stem's board-level audience constraint by focusing on material exposures and treatment progress, rather than operational detail, enabling informed governance decisions without requiring technical depth.

Why this answer

A risk report to the board of directors should be strategic and concise, focusing on top risks and their status. A risk heat map with top risks and status provides an executive-level view that supports governance and decision-making without overwhelming the board with operational detail. This is the most appropriate element for a board audience.

Exam trap

CRISC often tests the audience-appropriateness of risk reporting — candidates pick detailed operational data when the board needs strategic, aggregated risk views.

How to eliminate wrong answers

Option A is wrong because vendor security assessment scores for all vendors is too granular and operational for a board report. Option B is wrong because detailed weekly firewall log analysis is a technical operational artifact, not board-level information. Option C is wrong because a list of all IT incidents from the past month is tactical and lacks the risk context the board needs.

307
MCQmedium

A security operations center (SOC) uses a Security Information and Event Management (SIEM) system to continuously monitor for suspicious activities. Which type of monitoring is being performed?

A.Periodic control testing
B.Compliance audit
C.Vulnerability scanning
D.Continuous monitoring
AnswerD

A SIEM ingesting and correlating event data around the clock to detect suspicious activity is performing continuous monitoring, the ongoing, automated observation of systems and controls. This satisfies the stem's requirement for uninterrupted surveillance rather than periodic or ad hoc review.

Why this answer

The SOC is using a SIEM system to continuously monitor for suspicious activities, which aligns with continuous monitoring. Continuous monitoring involves real-time or near-real-time collection and analysis of security events to detect threats as they occur, rather than at scheduled intervals. SIEM systems aggregate logs and alerts from various sources to provide ongoing visibility into the security posture.

Exam trap

The trap here is that candidates confuse continuous monitoring with vulnerability scanning or periodic testing, but the key differentiator is the real-time, event-driven nature of SIEM-based monitoring versus scheduled or point-in-time assessments.

How to eliminate wrong answers

Option A is wrong because periodic control testing involves scheduled assessments (e.g., quarterly penetration tests) to verify control effectiveness, not real-time monitoring. Option B is wrong because a compliance audit is a point-in-time evaluation against regulatory standards (e.g., PCI DSS), not ongoing surveillance. Option C is wrong because vulnerability scanning is a periodic or scheduled process to identify known vulnerabilities (e.g., using Nessus or Qualys), not continuous monitoring of suspicious activities.

308
MCQmedium

A business continuity manager wants to identify risks that could disrupt critical business processes. Which source of information would be MOST valuable for identifying such risks?

A.Organizational charts
B.Industry benchmarks on downtime
C.Business impact analysis (BIA) documentation
D.Historical incident reports
AnswerC

A BIA identifies and prioritises critical business processes and their dependencies, including the resources, systems and single points of failure whose disruption halts those processes. This directly supplies the risk scenarios a continuity manager needs, unlike asset inventories or audit findings that lack process-level impact context.

Why this answer

The Business Impact Analysis (BIA) documentation is the most valuable source because it systematically identifies critical business processes, their dependencies (e.g., specific servers, databases, network links), and the maximum tolerable downtime (MTD) for each. This directly pinpoints which risks would cause unacceptable disruption, making it the foundational input for risk identification in continuity planning.

Exam trap

The trap here is that candidates often choose historical incident reports (D) thinking past failures are the best predictor, but CRISC emphasizes proactive identification of all risks—including those never experienced—which only a BIA can systematically uncover by analyzing process criticality and dependencies.

How to eliminate wrong answers

Option A is wrong because organizational charts show reporting structures and roles, not the technical dependencies or recovery time objectives (RTOs) of critical processes. Option B is wrong because industry benchmarks on downtime provide generic statistics (e.g., average cost per hour) but do not identify specific risks to an organization's unique processes or infrastructure. Option D is wrong because historical incident reports only capture past failures, missing emerging threats, single points of failure not yet realized, or risks that have never materialized.

309
MCQhard

A software development company uses a DevOps pipeline with automated code deployment. Recently, a developer accidentally pushed a configuration file containing database credentials to a public repository. The credentials were changed within an hour, but the file remained public for a few hours. The risk team is now identifying risks in the CI/CD process. The security team has proposed adding static code analysis to detect secrets in code. The development team objects, citing false positives. The risk manager must identify the most significant risk that could lead to a data breach. Which risk should be prioritized?

A.Insufficient training on secure coding practices for developers.
B.Over-reliance on manual code reviews which are error-prone.
C.Lack of pre-commit hooks or automated scanning to prevent secrets from being committed.
D.Inadequate incident response procedures for exposed credentials.
AnswerC

Automated pre-commit hooks or secret scanning would have blocked the credential file before it entered the repository, directly addressing the CI/CD control gap that allowed exposure. Static analysis alone, run later, leaves the commit window open; prevention at commit time satisfies the pipeline constraint the stem describes.

Why this answer

The root cause of the incident was the absence of automated, pre-commit scanning to detect secrets before they are pushed to a repository. Pre-commit hooks (e.g., using tools like git-secrets or Talisman) or server-side scanning (e.g., GitHub secret scanning) can block credentials from being committed in the first place, directly preventing exposure. Without this control, the CI/CD pipeline lacks a critical preventive layer, making data breaches more likely despite post-commit remediation.

Exam trap

The trap here is that candidates focus on the incident response or training aspects (options A and D) because they seem like common root causes, but the question specifically asks for the most significant risk that could lead to a data breach, which is the lack of a preventive control (pre-commit scanning) that directly stops secrets from entering the repository.

How to eliminate wrong answers

Option A is wrong because insufficient training on secure coding practices, while valuable, does not address the immediate technical gap that allowed the secret to be committed; training alone cannot prevent accidental pushes without automated enforcement. Option B is wrong because over-reliance on manual code reviews is a secondary concern; the incident occurred due to a lack of automated scanning, not because manual reviews were bypassed or failed. Option D is wrong because inadequate incident response procedures for exposed credentials are a reactive control; the most significant risk is the preventive failure that allowed the secret to be pushed, not the speed of response after exposure.

310
MCQeasy

A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?

A.Corrective control
B.Preventive control
C.Detective control
D.Directive control
AnswerB

Preventive controls block unauthorised access attempts before they reach the critical database, matching the stem's objective to prevent rather than detect. Authentication, authorisation and network filtering deny intrusion at entry, whereas detective controls only identify breaches after they occur.

Why this answer

A preventive control is designed to stop an incident before it occurs — access controls, authentication, encryption, and firewalls are classic examples. Preventing unauthorized database access is definitionally a preventive objective, so a preventive control (e.g., RBAC, MFA, network segmentation) is the correct category.

Exam trap

The trap is that candidates confuse 'detective' with 'preventive' because monitoring feels proactive — but detection only reveals an event after it happens; only a preventive control stops the unauthorized access itself.

How to eliminate wrong answers

Option A is wrong because corrective controls act after an incident to restore normal operations (e.g., backups, patching, incident response) — they do not stop unauthorized access in the first place. Option C is wrong because detective controls identify that an event occurred (e.g., IDS, log monitoring, SIEM alerts) but do not block it; detection is reactive to the event. Option D is wrong because directive controls establish policy or guidance (e.g., security policies, awareness training, procedures) — they influence behavior but do not technically enforce access restrictions.

311
MCQmedium

A risk assessment reveals that a legacy system has a high vulnerability score but low business criticality. The cost to remediate is high. What is the MOST appropriate risk response?

A.Avoid the risk by decommissioning the system
B.Accept the risk and monitor it
C.Mitigate the vulnerability with a patch
D.Transfer the risk via a managed security service
AnswerB

Low business criticality means the potential impact does not justify the high remediation cost, so accepting the risk and monitoring it is proportionate. Continued monitoring ensures the exposure is revisited if criticality or threat conditions change.

Why this answer

When a vulnerability is high-scoring but the affected system has low business criticality and remediation cost is high, the risk to the organization is low in business-impact terms. The most appropriate response is to accept the risk and monitor it, since the cost of remediation outweighs the potential business impact. Risk acceptance with ongoing monitoring is a legitimate CRISC-aligned response when residual risk is within tolerance.

Exam trap

CRISC often tests the confusion between technical severity (CVSS score) and business risk — candidates pick 'mitigate' because the vulnerability score is high, ignoring that low business criticality makes acceptance the appropriate response.

How to eliminate wrong answers

Option A is wrong because decommissioning a system is a drastic action that may disrupt business operations; it is not warranted when the system is low-criticality and still in use — avoidance is reserved for risks that cannot be otherwise managed. Option C is wrong because patching is mitigation, and the scenario explicitly states remediation cost is high relative to the low business criticality, making mitigation economically unjustified. Option D is wrong because transferring risk via an MSSP does not eliminate the underlying vulnerability and adds cost; it is not the most appropriate response when the risk is already low and acceptance is viable.

312
MCQhard

A risk practitioner is working with the IT team to design controls for a new cloud-based human resources system. The team proposes using encryption for data at rest and in transit, role-based access controls, and regular backups. The risk practitioner notes that these controls address confidentiality, integrity, and availability. Which of the following should the risk practitioner recommend to ensure the controls remain effective over time?

A.Document the controls in the risk register and review them during the next audit.
B.Perform a penetration test after the system goes live and then every two years.
C.Conduct an annual risk assessment to re-evaluate the risks and controls.
D.Implement a continuous monitoring program that includes automated alerts for control failures.
AnswerD

Continuous monitoring ensures that controls remain effective by providing real-time or near-real-time visibility into control performance. Automated alerts can notify the team of failures or deviations, enabling prompt remediation. This is a proactive approach to maintain risk at acceptable levels and is a key recommendation for sustaining control effectiveness in dynamic environments like cloud systems.

Why this answer

Continuous monitoring with automated alerts ensures that controls are consistently effective by detecting failures or deviations quickly. In a cloud environment, where changes are frequent, periodic assessments or audits are insufficient. Continuous monitoring provides ongoing assurance and supports timely risk response, aligning with CRISC best practices for maintaining risk within appetite.

Exam trap

The trap here is opting for periodic assessments like annual risk assessments or audits, which do not provide the timely detection needed for dynamic cloud environments.

313
MCQmedium

An organization is assessing risks related to a new cloud-based CRM system. The risk team is developing a risk scenario. Which of the following is the BEST example of a complete risk scenario following the ISACA template?

A.A DDoS attack on the CRM disrupts service, leading to operational downtime.
B.A hacker exploits a vulnerability in the CRM to steal customer data, resulting in financial loss.
C.An external attacker (actor) performs a SQL injection (threat type) to exfiltrate customer records from the CRM database (event/asset); occurs during off-hours (timing); detected by IDS after 2 hours (detection); leads to regulatory fines and reputational damage (consequence).
D.A disgruntled employee leaks data from the CRM, causing reputational damage.
AnswerC

A complete ISACA risk scenario names the actor, threat type, event and affected asset, timing, detection, and consequence. This option supplies all six elements, describing an external attacker using SQL injection to exfiltrate customer records, with detection delay and resulting regulatory and reputational impact.

Why this answer

ISACA's risk scenario template requires a structured narrative that identifies the threat actor, threat type, event, asset, timing, detection method, and consequence. Option C is the only choice that includes all these elements — actor (external attacker), threat type (SQL injection), event/asset (exfiltration from CRM database), timing (off-hours), detection (IDS after 2 hours), and consequence (regulatory fines and reputational damage). This completeness is what makes it a valid risk scenario rather than a vague risk statement.

Exam trap

CRISC often tests whether candidates can distinguish a complete risk scenario (with actor, threat, asset, timing, detection, consequence) from a simple risk statement that only names a threat and an outcome.

How to eliminate wrong answers

Option A is wrong because it only names a threat (DDoS) and a generic outcome (downtime) without identifying the actor, asset specifics, timing, detection, or quantified consequence — it is a risk statement, not a full scenario. Option B is wrong because although it names a threat actor and outcome, it omits timing, detection method, and asset specificity, and uses vague terms like 'financial loss' without a structured consequence. Option D is wrong because it identifies an insider threat and reputational damage but lacks timing, detection, asset detail, and a structured consequence statement.

314
MCQhard

A third-party vendor's security assessment reveals multiple high-risk findings related to data handling. The vendor is unwilling to remediate, citing cost. The vendor contract includes a clause that requires adherence to security standards. The organization's risk appetite for third-party risk is low. What is the most appropriate risk response?

A.Avoid by terminating the contract
B.Mitigate by reducing data shared
C.Transfer via insurance
D.Accept the risk and monitor
AnswerA

With low third-party risk appetite and a contract clause mandating security standards, the vendor's refusal to remediate leaves the risk above tolerance. Terminating the contract eliminates the exposure entirely, which is avoidance — the only response that removes rather than accepts, transfers or mitigates the risk.

Why this answer

The vendor's refusal to remediate high-risk findings directly violates the contract's security standards clause, and the organization's low risk appetite for third-party risk means that accepting or mitigating the residual risk is unacceptable. Terminating the contract (avoidance) is the only response that eliminates the risk entirely, aligning with the principle that when a third party cannot or will not meet required security controls, the relationship should be severed to prevent potential data breaches or compliance violations.

Exam trap

The trap here is that candidates often choose mitigation (reducing data shared) because it seems like a compromise, but they overlook that the vendor's core data handling processes remain insecure, and the organization's low risk appetite demands complete elimination of the risk, not partial reduction.

How to eliminate wrong answers

Option B is wrong because reducing data shared (mitigation) does not address the vendor's unwillingness to remediate the root cause of the high-risk findings; the vendor's insecure data handling practices would still expose the organization to residual risk exceeding its low appetite. Option C is wrong because transferring risk via insurance does not reduce the likelihood or impact of a data breach; it only provides financial compensation after an incident, which is insufficient when the organization's risk appetite is low and the vendor is non-compliant with contractual security standards. Option D is wrong because accepting the risk and monitoring contradicts the organization's low risk appetite; acceptance is appropriate only when residual risk falls within appetite, but here the high-risk findings and vendor non-compliance create an unacceptable level of exposure.

315
MCQhard

A financial services firm is deploying a new trading platform. The risk committee has approved a risk treatment plan that includes a requirement to implement a circuit breaker that halts trading if losses exceed a predefined threshold. The project manager asks the risk practitioner to verify that the control is designed effectively before go-live. Which activity BEST validates the design of this risk mitigation control?

A.Monitor trading losses for the first month after go-live and confirm that the circuit breaker activates when the threshold is breached.
B.Confirm that the vendor's product documentation states the circuit breaker feature is included in the licensed version.
C.Ask the internal audit team to add the circuit breaker to the annual audit plan and review it during the next audit cycle.
D.Review the control's technical specification and conduct a tabletop walkthrough with the trading and technology teams.
AnswerD

Design effectiveness is evaluated before the control operates in production. Reviewing the technical specification confirms that the circuit breaker logic matches the risk treatment requirement, and a tabletop walkthrough reveals whether the teams understand how the threshold triggers and who is responsible for halting trading. This combination validates the design without waiting for a live trading loss event.

Why this answer

Design effectiveness testing confirms that a control, as planned, will mitigate the identified risk before it is relied upon. Reviewing specifications and walking through scenarios with stakeholders validates the logic, thresholds, and responsibilities. Live monitoring tests operating effectiveness, internal audit provides later assurance, and vendor documentation only confirms feature availability.

The pre-go-live design validation is the most direct and timely way to confirm the circuit breaker will work as intended.

Exam trap

The trap here is confusing design effectiveness with operating effectiveness, and selecting live monitoring as the validation method.

316
MCQhard

A financial institution is assessing the risk of a new real-time payment system. The risk manager calculates that the annualized loss expectancy (ALE) for a potential fraud scenario is $500,000. The cost to implement a fraud detection solution is $200,000 initially with $50,000 annual maintenance. The solution is expected to reduce the ALE by 80%. What is the net benefit of implementing the solution over three years?

A.$1,000,000
B.$950,000
C.$800,000
D.$850,000
AnswerD

The solution cuts the $500,000 ALE by 80%, saving $400,000 annually, or $1,200,000 across three years. Against that, total cost is $200,000 plus three years of $50,000 maintenance, equalling $350,000. Subtracting gives a net benefit of $850,000, satisfying the three-year horizon constraint.

Why this answer

The net benefit over three years is calculated as the reduction in ALE minus the total cost of the solution. The original ALE is $500,000 per year, and an 80% reduction saves $400,000 annually. Over three years, total savings are $1,200,000.

The total cost includes the initial $200,000 plus three years of maintenance at $50,000 each ($150,000), totaling $350,000. Net benefit = $1,200,000 - $350,000 = $850,000.

Exam trap

The trap here is that candidates often forget to include the annual maintenance costs over the full three-year period or mistakenly apply the 80% reduction to the total cost instead of the ALE, leading to incorrect net benefit calculations.

How to eliminate wrong answers

Option A is wrong because it incorrectly assumes the full ALE ($500,000) is saved each year without accounting for the 80% reduction factor, leading to an overestimation of $1,000,000 net benefit. Option B is wrong because it likely miscalculates the total cost or savings, perhaps omitting the initial implementation cost or misapplying the reduction percentage, resulting in $950,000. Option C is wrong because it may only consider the first year's net benefit or incorrectly subtract the total cost from a single year's savings, yielding $800,000.

317
MCQeasy

Which type of control is designed to operate before an event to prevent an undesirable outcome?

A.Preventive control
B.Detective control
C.Corrective control
D.Compensating control
AnswerA

Preventive controls act on the cause before an event occurs, blocking the undesirable outcome rather than detecting it afterwards or compensating for it. This directly satisfies the stem's requirement that the control operates before the event, unlike detective or corrective controls.

Why this answer

A preventive control is designed to operate before an event to stop an undesirable outcome from occurring. In risk management, this includes measures such as firewalls blocking unauthorized traffic before it reaches the internal network, or access control lists (ACLs) preventing unauthorized users from reading sensitive files. These controls proactively enforce security policies to reduce the likelihood of a risk event.

Exam trap

In the ISACA CRISC exam, candidates often confuse preventive controls (e.g., firewalls, access controls) with detective controls (e.g., intrusion detection systems). Remember that preventive controls act before an event, while detective controls identify events that have already occurred.

How to eliminate wrong answers

Option B (Detective control) is wrong because it operates during or after an event to identify that an undesirable outcome has occurred, such as intrusion detection systems (IDS) logging suspicious activity after the fact. Option C (Corrective control) is wrong because it operates after an event to restore normal operations, like applying a patch to fix a vulnerability that was exploited. Option D (Compensating control) is wrong because it is an alternative control used when a primary control is not feasible, not specifically designed to operate before an event.

318
MCQmedium

Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?

A.To reduce the frequency of IT risk reporting
B.To eliminate the need for IT risk assessments
C.To provide a holistic view of risk across the organization
D.To replace IT risk management with ERM
AnswerC

Integrating IT risk reporting into enterprise risk management aggregates technology exposures alongside financial, operational and compliance risks, so leadership sees interconnected exposures rather than a siloed technology list. This holistic aggregation is the primary purpose, enabling consistent prioritisation and comparison against the organisation's overall risk appetite.

Why this answer

Integrating IT risk reporting into the ERM program provides a holistic view of risk across the organization by aligning IT-specific risks with strategic, operational, and compliance risks. This integration ensures that decision-makers can prioritize and respond to risks based on their aggregate impact, rather than treating IT risks in isolation. The primary purpose is to enable a unified risk posture that supports enterprise-wide governance and resource allocation.

Exam trap

ISACA often tests the misconception that ERM integration aims to replace or reduce IT-specific risk management activities, when in fact it seeks to elevate IT risk visibility to the enterprise level without eliminating specialized IT risk processes.

How to eliminate wrong answers

Option A is wrong because the purpose of integration is not to reduce the frequency of reporting but to enhance the quality and context of risk information; frequency is determined by risk velocity and materiality, not by integration alone. Option B is wrong because integrating IT risk reporting into ERM does not eliminate the need for IT risk assessments; IT risk assessments remain essential for identifying, analyzing, and evaluating specific technical threats, vulnerabilities, and controls. Option D is wrong because ERM does not replace IT risk management; rather, it subsumes IT risk as a component of the overall risk portfolio, requiring continued specialized IT risk management practices.

319
Multi-Selectmedium

A risk manager is developing risk scenarios to present to the board. Which TWO elements are essential for connecting a risk scenario to business impact?

Select 2 answers
A.Threat actor motivation
B.Vulnerability score
C.Detection time
D.Consequence (e.g., financial loss)
E.Business impact statement
AnswersD, E

Consequence quantifies what happens to the organisation if the risk eventuates — financial loss, regulatory penalty or service disruption. It is the causal link translating a risk scenario into measurable business impact, giving the board a basis for comparing scenarios against risk appetite.

Why this answer

Option D, consequence such as financial loss, is essential because it translates a technical or threat event into measurable business outcomes (e.g., revenue loss, regulatory fines, recovery cost), which is exactly what connects the scenario to business impact. Option E, a business impact statement, is essential because it formally articulates how the scenario affects business objectives, operations, or stakeholders, providing the board with a clear linkage between risk and organizational impact. Together, consequence and the business impact statement bridge the gap between risk scenarios and business-level decision-making.

Option A, threat actor motivation, is useful for threat modeling but does not by itself quantify or express business impact. Option B, vulnerability score, is a technical severity metric (e.g., CVSS) that does not directly map to business consequences. Option C, detection time, is an operational metric that influences exposure but is not an essential element for connecting a scenario to business impact.

Exam trap

CRISC often tests the confusion between technical severity metrics (vulnerability score, detection time) and business-facing elements (consequence, business impact statement) when linking risk scenarios to organizational impact.

320
MCQmedium

A risk practitioner is facilitating a workshop to identify risks for a new customer-facing payment portal. The CISO wants the exercise to capture risks arising from both internal process weaknesses and external threat sources without producing an unmanageable list. Which approach is MOST appropriate for structuring the risk identification effort?

A.Use a structured technique such as scenario analysis that pairs threat sources with affected assets and business processes.
B.Conduct a penetration test of the portal and register only the findings that result in successful exploitation.
C.Ask each workshop participant to submit an unrestricted list of every concern they have about the portal.
D.Adopt the vendor's standard risk register template and record the categories the vendor already populated.
AnswerA

Scenario analysis systematically combines plausible threat sources with the assets and business processes they could affect, producing a structured set of risk statements that spans internal weaknesses and external actors. This disciplined pairing keeps the list focused on credible combinations rather than an exhaustive inventory, and it aligns directly with the risk scenario structure used in ISACA guidance, making the outputs suitable for subsequent assessment and treatment.

Why this answer

Structured scenario analysis pairs credible threat sources with the assets and business processes they could affect, producing a comprehensive yet bounded set of risk statements. This technique captures internal weaknesses such as process gaps and external sources such as criminal actors in a consistent format, supports later likelihood and impact assessment, and keeps the register manageable. Testing, unrestricted brainstorming, and vendor templates each fall short on coverage, consistency, or relevance.

Exam trap

The trap here is equating thorough risk identification with either technical testing or open-ended brainstorming, when the real requirement is a structured pairing of threat sources with assets and processes.

321
MCQhard

A risk manager is evaluating the risk of a distributed denial-of-service (DDoS) attack against the organization's public-facing web application. The organization has a 1 Gbps internet connection and no DDoS mitigation service. Which of the following is the MOST important factor in determining the potential impact of a volumetric DDoS attack?

A.The geographic location of the attackers launching the DDoS attack.
B.The number of users who will be unable to access the application during the attack.
C.The type of web server software used to host the application.
D.The bandwidth of the organization's internet connection compared to the attack traffic volume.
AnswerD

A volumetric DDoS attack aims to saturate the network link. If the attack traffic exceeds the 1 Gbps connection capacity, the link becomes congested, and legitimate traffic cannot pass, causing an outage. The impact is directly determined by whether the attack volume overwhelms the available bandwidth. This makes the connection bandwidth the most important factor in assessing the potential impact.

Why this answer

In a volumetric DDoS attack, the attacker floods the target with a high volume of traffic to exhaust network bandwidth. The potential impact is primarily determined by whether the attack traffic exceeds the organization's internet connection capacity. If the attack volume is greater than 1 Gbps, the link will be saturated, causing an outage.

Thus, the bandwidth of the connection relative to the attack volume is the most critical factor in assessing impact.

Exam trap

The trap here is focusing on downstream consequences like number of users affected or server software, rather than the direct capacity constraint that determines whether a volumetric attack succeeds.

322
MCQeasy

A newly appointed risk owner is reviewing a risk register entry for an aging payroll application. The entry shows a likelihood rating, an impact rating, an inherent risk score, and a residual risk score, but no owner signature or review date. Which action should the risk practitioner take FIRST to strengthen the register's usefulness for IT risk assessment?

A.Confirm the accountable risk owner and establish a review date so the entry has clear ownership and currency.
B.Escalate the entry to the audit committee as an unowned high risk requiring immediate remediation funding.
C.Recompute the inherent and residual scores using a different likelihood and impact scale.
D.Remove the inherent risk score and retain only the residual risk score to simplify reporting.
AnswerA

A risk register entry without an accountable owner or review date cannot support monitoring, treatment decisions, or escalation, because no one is responsible and the data may be stale. Confirming ownership and setting a review cadence is the foundational fix that makes every other register attribute usable. This directly matches the missing fields described in the scenario.

Why this answer

A register entry is only actionable when someone is accountable and the data is kept current. Confirming the risk owner and setting a review date converts a static record into a managed risk with monitoring and escalation paths. Scoring adjustments, escalations, or field deletions do not remedy the underlying governance gap that the scenario describes.

Exam trap

The trap here is treating a missing owner as a documentation nuisance rather than the accountability failure that blocks all downstream risk management.

323
Multi-Selecthard

A risk practitioner is cataloging external factors that could create IT risk for a logistics firm expanding into a new country. Which TWO of the following are external factors that should be included in the risk identification effort? (Choose two.)

Select 2 answers
A.The organization's chosen encryption standard for data at rest.
B.The firm's internal security awareness training completion rate.
C.New data residency and privacy regulations in the target country.
D.The maturity of the local telecommunications and power infrastructure.
E.The technical skill level of the firm's current IT staff.
AnswersC, D

Data residency and privacy laws are external, environmental factors outside the firm's control that can create compliance and operational risk. They influence where data may be stored and processed, affecting architecture and vendor choices. Capturing them during identification ensures the expansion plan accounts for legal constraints before systems are deployed, rather than discovering violations after the fact.

Why this answer

External factors are conditions outside the organization's control that shape its risk landscape. New data residency and privacy regulations and the maturity of local telecom and power infrastructure both originate in the target country's legal and physical environment, so they must be identified during expansion planning. Internal items such as staff skills, training rates, and encryption choices are capability and control decisions the firm governs itself.

Exam trap

The trap here is listing internal control weaknesses or capability gaps as external factors, when external factors must originate outside the organization's own control.

324
MCQmedium

A risk analyst at a regional bank is assessing the risk to its core banking platform. The analyst finds that the platform has a known vulnerability with a high exploitability score, but the platform is isolated on a segmented network with no external connectivity and strict change control. The analyst must determine the PRIMARY factor that reduces the likelihood of exploitation. Which factor should the analyst emphasize?

A.The bank's risk appetite statement
B.The strict change control process
C.The vulnerability's high exploitability score
D.The network segmentation and lack of external connectivity
AnswerD

Network segmentation and the absence of external connectivity directly reduce the attack surface and limit the pathways an attacker could use to reach the vulnerable platform. Even with a high exploitability score, the likelihood of exploitation drops because the threat actor cannot easily access the asset. This is the primary factor that lowers likelihood in this scenario.

Why this answer

The likelihood of exploitation depends on both the vulnerability's characteristics and the threat actor's ability to reach the asset. Network segmentation and lack of external connectivity create a barrier that prevents or severely limits access, making exploitation unlikely even if the vulnerability is severe. The other factors either increase concern or provide indirect governance benefits but do not directly reduce the likelihood of a successful attack.

Exam trap

The trap here is assuming that a high exploitability score always dominates the risk assessment, ignoring compensating controls like network isolation that directly reduce the likelihood of exploitation.

325
MCQhard

A global retailer's risk committee is reviewing a proposal to transfer the financial impact of payment card fraud to an insurer through a cyber insurance policy. The policy has a $2 million retention and excludes losses caused by unencrypted cardholder data at rest. The organization's cardholder database is currently unencrypted. Which of the following is the MOST significant limitation the risk manager should highlight?

A.Cyber insurance cannot be used as a risk response because it does not reduce the likelihood of a fraud event.
B.The exclusion for unencrypted cardholder data means the transfer will not respond to a loss from the current database configuration.
C.The insurer, not the risk committee, will now own the risk and control decisions for the payment environment.
D.The retention amount is too low to provide meaningful financial protection for a global retailer.
AnswerB

Risk transfer only works when the transferred event falls within the policy's coverage. Because the cardholder database is unencrypted and the policy excludes losses from unencrypted data at rest, a breach of that database would fall outside coverage, leaving the organization to bear the full financial impact. This is the material limitation the committee must weigh before treating insurance as the response.

Why this answer

Transferring risk through insurance is effective only when the loss event is actually covered. An exclusion for unencrypted cardholder data at rest directly conflicts with the current state of the cardholder database, so a breach of that database would not be indemnified. The risk manager must flag this gap so the committee understands that the proposed transfer does not address the organization's most likely fraud loss scenario, and that encryption or another response is needed.

Exam trap

The trap here is assuming that purchasing a cyber insurance policy automatically transfers the relevant fraud risk without checking policy exclusions against the actual control state.

326
MCQhard

A risk practitioner is reviewing the results of a control self-assessment (CSA) and finds that the control owner rated a control as 'effective' but an independent audit found control weaknesses. What is the BEST explanation for this discrepancy?

A.The control owner may have a biased perception of control effectiveness.
B.The CSA was conducted too long ago.
C.The control owner did not understand the control objectives.
D.The audit used a different definition of 'effective'.
AnswerA

Self-assessment is inherently subjective: the control owner who designed or operates the control may overestimate its effectiveness, producing a rating that independent audit evidence contradicts. This perceptual bias, rather than control design, explains the discrepancy between the CSA result and the audit finding.

Why this answer

The control owner's self-assessment is inherently subjective and may be influenced by personal bias, lack of objectivity, or a desire to report favorable results. An independent audit provides an objective, evidence-based evaluation, so a discrepancy where the owner rates a control as 'effective' while the audit finds weaknesses strongly suggests the owner's perception is skewed. This is the most direct and common explanation for such a conflict in control self-assessment (CSA) results.

Exam trap

The trap here is that candidates may choose Option D (different definition of 'effective') because it seems like a logical technical reason, but the question asks for the 'BEST' explanation, and bias is a more common and fundamental cause of CSA-audit discrepancies than definitional differences.

How to eliminate wrong answers

Option B is wrong because the question does not provide any information about the timing of the CSA relative to the audit; even if the CSA was conducted recently, the discrepancy could still exist due to bias. Option C is wrong because while a control owner might misunderstand objectives, the more fundamental issue is that the owner's rating is a subjective judgment, not a technical misunderstanding of the control's purpose. Option D is wrong because while different definitions could cause a discrepancy, the audit and CSA typically use the same organizational standard for 'effective'; the more likely root cause is the owner's biased perception rather than a definitional mismatch.

327
Multi-Selecthard

A risk practitioner is defining key risk indicators (KRIs) for the organization's third-party risk program after several supplier outages disrupted operations. Which TWO characteristics are essential for these KRIs to be effective for the risk committee? (Choose two.)

Select 2 answers
A.Each indicator reflects the total number of suppliers onboarded during the reporting period.
B.Each indicator is reviewed only during the annual enterprise risk assessment cycle.
C.Each indicator is measurable from data that can be collected reliably and repeatedly.
D.Each indicator is tied to a defined risk threshold that triggers a specific escalation or response.
E.Each indicator is expressed as a qualitative rating assigned by the relationship manager.
AnswersC, D

A KRI is only useful if it can be calculated consistently from dependable sources; otherwise trends and thresholds are meaningless. Reliable, repeatable measurement lets the risk committee compare periods, detect deterioration, and trust the signal. Indicators built on anecdotal data or manual estimates that vary by analyst introduce noise and erode confidence, defeating the purpose of monitoring third-party risk over time.

Why this answer

Effective KRIs are measurable from reliable, repeatable data and are linked to thresholds that trigger defined action. Those two properties turn a metric into a decision-support tool for the risk committee. Activity counts, subjective ratings, and annual-only reviews lack the objectivity, relevance, and timeliness needed to warn about third-party disruption before it affects operations.

Exam trap

The trap here is selecting indicators that are easy to collect, such as supplier counts, instead of ones that actually signal risk exposure.

328
MCQhard

In the FAIR model, 'Loss Event Frequency' is calculated as:

A.Threat Event Frequency × Asset Value
B.Threat Event Frequency × Vulnerability
C.Threat Event Frequency × Loss Magnitude
D.Annualized Rate of Occurrence × Single Loss Expectancy
AnswerB

FAIR derives Loss Event Frequency from how often threat agents act against the asset, multiplied by the probability those actions succeed given existing controls. Vulnerability here is the percentage of threat events that become loss events, not a separate control rating.

Why this answer

In the FAIR model, Loss Event Frequency (LEF) is the product of Threat Event Frequency (TEF) and Vulnerability (Vuln). This represents how often a threat agent successfully exploits a weakness, making option B correct. The formula is LEF = TEF × Vuln, where Vulnerability is the probability that a threat event will result in a loss.

Exam trap

The trap here is that candidates confuse the FAIR model's Loss Event Frequency with the traditional quantitative risk formula ARO × SLE, leading them to select option D, but FAIR separates frequency from magnitude and uses Vulnerability as a probability factor rather than a direct loss value.

How to eliminate wrong answers

Option A is wrong because Asset Value is used in calculating Loss Magnitude, not Loss Event Frequency; multiplying Threat Event Frequency by Asset Value conflates frequency with impact. Option C is wrong because Loss Magnitude is a separate component in the FAIR model used to derive risk, not a factor in Loss Event Frequency; multiplying TEF by Loss Magnitude would incorrectly combine frequency and impact into a single metric. Option D is wrong because Annualized Rate of Occurrence (ARO) × Single Loss Expectancy (SLE) is the formula for Annualized Loss Expectancy (ALE) in quantitative risk analysis, not Loss Event Frequency in FAIR.

329
MCQhard

A company is integrating its IT risk management program with the enterprise risk management (ERM) program. What is the primary benefit of this integration?

A.It allows IT to operate independently from business units.
B.It eliminates the requirement for a separate IT risk register.
C.It provides a holistic view of risk across the organization.
D.It reduces the need for IT-specific risk assessments.
AnswerC

Integration aggregates IT risk with operational, financial and strategic risk registers, giving leadership a consolidated enterprise-wide view rather than isolated silos. This holistic perspective improves prioritisation and capital allocation, ensuring IT risk is evaluated against overall organisational risk appetite during decision-making.

Why this answer

Integration ensures that IT risks are considered in the context of overall organizational objectives and that risk responses are aligned across the enterprise.

330
Multi-Selecthard

An organization is conducting a risk assessment and finds that the inherent risk for a critical asset is very high due to a high threat event frequency and high vulnerability. The current controls are assessed as adequate in design but not operating effectively. Which THREE of the following should be considered when calculating residual risk?

Select 3 answers
A.Inherent risk score
B.Control design adequacy
C.Cost-benefit analysis of controls
D.Control operating effectiveness
E.Risk appetite statement
AnswersA, B, D

Residual risk is based on inherent risk reduced by controls.

Why this answer

Inherent risk score (A) is correct because residual risk is calculated by considering the inherent risk level and the effectiveness of controls in reducing that risk. Since the inherent risk is very high due to high threat frequency and vulnerability, this baseline score must be factored into the residual risk calculation to determine the remaining risk after controls are applied.

Exam trap

The trap here is that candidates often confuse risk appetite (E) as a direct input to residual risk calculation, when it is actually a threshold for evaluating residual risk, not a component of its calculation.

331
MCQhard

An organization uses a risk appetite statement that limits operational losses to $2 million per quarter. A new risk reporting dashboard shows that current operational losses are $1.8 million with two weeks remaining in the quarter. The head of risk management wants to ensure that losses remain within appetite. Which of the following control monitoring reports would be MOST useful for proactive decision-making?

A.A projected loss report based on current trends and remaining period
B.A report on current loss amounts per business unit
C.A summary of historical operational losses by month
D.A detailed KRI report showing loss frequency by category
AnswerA

A projected loss report extrapolates the current $1.8 million run rate across the two remaining weeks, forecasting whether quarterly operational losses will breach the $2 million appetite threshold. This forward-looking view satisfies the proactive decision-making constraint, enabling intervention before the limit is exceeded, unlike backward-looking actuals reporting.

Why this answer

A projected loss report based on current trends and remaining period is most useful for proactive decision-making because it uses historical and current data to forecast whether losses will exceed the $2 million appetite by quarter-end. This allows the risk manager to take corrective actions now, rather than waiting for actual losses to materialize. The other options are either backward-looking or lack the predictive element needed for proactive control.

Exam trap

The trap here is that candidates confuse descriptive reports (like current loss amounts or historical summaries) with predictive reports, failing to recognize that proactive decision-making requires forward-looking projections rather than backward-looking data.

How to eliminate wrong answers

Option B is wrong because a report on current loss amounts per business unit provides only a static snapshot of past losses, not a forward-looking projection to assess future appetite compliance. Option C is wrong because a summary of historical operational losses by month is purely retrospective and does not incorporate the remaining two-week period or current trends. Option D is wrong because a detailed KRI report showing loss frequency by category, while useful for identifying patterns, does not project total losses against the $2 million threshold over the remaining timeframe.

332
MCQmedium

A financial services firm maintains a risk register that lists inherent risk ratings for its core banking platform. During an internal audit, the CIO notes that the register has not been updated to reflect the controls implemented over the past 18 months. Which of the following should the risk practitioner do FIRST to address this gap?

A.Remove the affected entries from the register until a complete enterprise risk assessment can be scheduled.
B.Reclassify all entries from inherent to residual risk so the register aligns with the audit terminology.
C.Reassess the residual risk for each entry by evaluating the effectiveness of the implemented controls.
D.Escalate the finding to the board risk committee and request additional budget for a full risk assessment.
AnswerC

The register reflects inherent risk but ignores control effectiveness, so the residual risk is misstated. Reassessing residual risk by evaluating the controls already implemented directly corrects the outdated ratings and restores the register's accuracy. This is the logical first step because the identified gap is precisely the failure to reflect controls in the risk position.

Why this answer

The register captured inherent risk but never reflected the controls deployed over 18 months, so the residual risk position is stale. The practitioner must evaluate control effectiveness and recalculate residual risk for each affected entry. Escalation, deletion, or relabeling do not correct the data and would leave decision-makers with a misleading view of the firm's actual risk exposure.

Exam trap

The trap here is assuming the register is wrong because risks were never identified, when the actual gap is that implemented controls were never reflected in the residual ratings.

333
MCQmedium

A risk analyst is evaluating a critical customer database. The asset value is $2,000,000; the exposure factor if the database is compromised is 40%. The annualized rate of occurrence (ARO) for a successful breach is estimated at 0.25. What is the annualized loss expectancy (ALE)?

A.$800,000
B.$200,000
C.$2,000,000
D.$500,000
AnswerB

SLE is $2,000,000 × 0.40 = $800,000. ALE = SLE × ARO = $800,000 × 0.25 = $200,000. This represents the expected annual loss from this specific risk before any controls are applied, which is the correct quantitative output for prioritizing the risk against other assessed risks.

Why this answer

ALE is calculated as SLE × ARO. Here SLE = $2,000,000 × 0.40 = $800,000, and ARO = 0.25, so ALE = $800,000 × 0.25 = $200,000. This quantitative metric helps the risk practitioner compare the expected annual loss of this risk against other risks and against the cost of potential controls.

Exam trap

The trap here is confusing SLE with ALE and stopping the calculation before applying the annualized rate of occurrence.

334
MCQeasy

Which enterprise architecture layer is most directly responsible for managing the storage and processing of data, and for which data classification and encryption controls are critical?

A.Application architecture
B.Data architecture
C.Technology architecture
D.Business architecture
AnswerB

Data architecture defines how data is stored, processed, and moved across the enterprise. Because it governs data at rest and in motion, classification and encryption controls belong at this layer, directly addressing the storage and processing responsibility in the stem.

Why this answer

Data architecture is the enterprise architecture layer that defines how data is stored, managed, and processed, including data models, data flows, and storage structures. Data classification and encryption controls are critical at this layer because they directly protect the confidentiality and integrity of data at rest and in transit, ensuring compliance with policies and regulations.

Exam trap

The trap here is that candidates often confuse data architecture with technology architecture, mistakenly thinking that hardware or infrastructure layers are responsible for data classification and encryption, when in fact these controls are defined and managed at the data layer itself.

How to eliminate wrong answers

Option A is wrong because application architecture focuses on the design and interaction of software applications, not on the underlying storage and processing of data, and while applications may implement encryption, the primary responsibility for data classification and encryption controls lies with the data architecture. Option C is wrong because technology architecture deals with the hardware and software infrastructure (e.g., servers, networks, databases) that supports data processing, but it does not define how data is classified or encrypted; those controls are applied to the data itself, which is the domain of data architecture. Option D is wrong because business architecture describes business strategy, processes, and goals, and it does not directly manage data storage, processing, or technical controls like encryption.

335
MCQeasy

During a risk assessment, the risk owner identifies that the residual risk level is higher than the risk appetite. Which of the following actions should the risk owner take FIRST?

A.Update the risk register
B.Escalate to senior management
C.Implement additional controls
D.Reduce the risk appetite
AnswerB

Residual risk exceeding appetite sits outside the risk owner's delegated authority, so the owner cannot accept it unilaterally. Escalation to senior management is the required first step, since only they can authorise additional treatment or formally accept the elevated exposure.

Why this answer

When residual risk exceeds risk appetite, the risk owner must escalate to senior management because they have the authority to accept the risk or allocate resources for additional controls. This aligns with the CRISC framework's principle that risk acceptance decisions beyond appetite are a management responsibility, not the risk owner's alone.

Exam trap

The trap here is that candidates confuse the risk owner's authority with senior management's authority, assuming the risk owner can independently implement controls or adjust appetite without escalation.

How to eliminate wrong answers

Option A is wrong because updating the risk register is a documentation step that should occur after the decision is made, not the first action when risk exceeds appetite. Option C is wrong because implementing additional controls is a potential remediation step, but it requires senior management approval or direction first, as the risk owner cannot unilaterally decide to spend resources. Option D is wrong because reducing risk appetite is a strategic decision made by the board or senior management, not the risk owner, and changing appetite to match residual risk violates the purpose of having a defined appetite.

336
MCQmedium

An organization uses the FAIR framework to calculate annualized loss expectancy (ALE) for a specific risk. Given that the single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2, what is the ALE?

A.$250,000
B.$100,000
C.$10,000
D.$50,000
AnswerC

Multiplying SLE by ARO yields the annualised loss expectancy: $50,000 × 0.2 = $10,000. This satisfies the stem's requirement to quantify expected yearly loss for the risk, giving decision-makers the cost baseline needed to compare against control costs during risk response prioritisation.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Given SLE = $50,000 and ARO = 0.2, the ALE is $50,000 × 0.2 = $10,000. This aligns with the FAIR framework's quantitative risk analysis formula.

Exam trap

The trap here is that candidates often confuse the ALE formula with the SLE formula or misplace the decimal point in ARO (0.2 vs. 2.0), leading to inflated values like $100,000 or $250,000.

How to eliminate wrong answers

Option A ($250,000) is wrong because it incorrectly divides SLE by ARO ($50,000 / 0.2) instead of multiplying, a common arithmetic reversal. Option B ($100,000) is wrong because it multiplies SLE by 2 (a misinterpretation of ARO as 2.0) rather than by the correct factor of 0.2. Option D ($50,000) is wrong because it assumes ARO = 1.0, ignoring the given 0.2 frequency and treating the loss as occurring once per year.

337
Multi-Selecteasy

Which TWO of the following are examples of risk mitigation controls?

Select 2 answers
A.Implementing a firewall
B.Purchasing cyber insurance
C.Accepting the risk
D.Encrypting sensitive data
E.Discontinuing a high-risk service
AnswersA, D

Mitigation reduces risk through preventive controls.

Why this answer

Implementing a firewall is a risk mitigation control because it reduces the likelihood and impact of unauthorized network access by enforcing access control policies based on source/destination IP addresses, ports, and protocols. Firewalls operate at Layers 3 and 4 (and sometimes Layer 7) of the OSI model to filter traffic, thereby directly reducing the attack surface and preventing exploitation of vulnerabilities.

Exam trap

The CRISC exam often tests the distinction between risk mitigation (reducing likelihood/impact) and risk transfer (e.g., insurance) or risk avoidance (e.g., discontinuing a service), so candidates mistakenly classify insurance or service discontinuation as mitigation when they are separate risk response strategies.

338
Multi-Selecthard

A financial services firm is performing an IT risk assessment on a legacy trading platform. The risk team has identified several weaknesses in the platform's patch management process. Which TWO of the following are examples of vulnerabilities that should be recorded in the risk register? (Choose two.)

Select 2 answers
A.The firm's cyber insurance policy excludes losses from unpatched systems.
B.Patch deployment requires manual approval by a single administrator.
C.The trading platform processes approximately 40 percent of the firm's revenue.
D.A hacker collective has publicly announced targeting of trading firms.
E.The platform runs an operating system version no longer supported by the vendor.
AnswersB, E

A manual, single-person approval bottleneck is a process vulnerability because it creates delay, human error, and a single point of failure in patch deployment. This weakness exists in the organization's procedures and can be exploited indirectly by attackers who rely on slow patching windows. Recording it enables the risk team to recommend automation, segregation of duties, and service-level targets for patch cycles.

Why this answer

Vulnerabilities are internal weaknesses in people, processes, or technology that a threat can exploit. An unsupported operating system and a manual single-administrator patch approval process both qualify because they exist inside the environment and degrade the firm's ability to prevent exploitation. The hacker announcement is a threat source, the revenue figure is business criticality, and the insurance exclusion is a risk financing condition, so none belong in the vulnerability field of the register.

Exam trap

The trap here is treating a threat source such as an announced attacker campaign as a vulnerability simply because both appear in the same risk discussion.

339
Multi-Selecteasy

Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)

Select 2 answers
A.Ensures all cyber attacks are prevented
B.Helps align cybersecurity activities with business objectives
C.Provides a prescriptive set of controls for all organizations
D.Provides a common language for communicating cybersecurity risk
E.Replaces the need for a separate risk appetite statement
AnswersB, D

Mapping Framework outcomes to enterprise risk processes ties security spending and controls to stated business objectives, letting leadership prioritise investment by impact. This satisfies the integration benefit of aligning cybersecurity activities with what the organisation is trying to achieve.

Why this answer

Option B is correct because the NIST Cybersecurity Framework (CSF) is designed to be integrated with enterprise risk management so that cybersecurity investments and activities are prioritized according to business objectives, mission needs, and organizational risk tolerances, rather than treated as a purely technical concern. Option D is correct because the CSF Core's Functions, Categories, and Subcategories (Identify, Protect, Detect, Respond, Recover, and Govern in CSF 2.0) establish a standardized taxonomy that gives technical and business stakeholders a common language for describing, discussing, and communicating cybersecurity risk. Option A is incorrect because no framework can guarantee prevention of all cyber attacks; the CSF is risk-based and assumes some incidents will occur, emphasizing detection, response, and recovery.

Option C is incorrect because the CSF is outcome-based and voluntary, not a prescriptive checklist of mandatory controls for every organization. Option E is incorrect because the CSF complements, rather than replaces, an organization's risk appetite statement, which is a governance input used to guide risk-based decisions.

Exam trap

CRISC often tests the difference between a framework's actual benefits (alignment, common language) and overstated claims (prevention, prescriptive controls, replacing governance artifacts), so candidates who pick 'prescriptive controls' or 'replaces risk appetite' misunderstand CSF's voluntary, outcome-based nature.

340
MCQeasy

Which of the following is an example of a leading indicator?

A.Number of security incidents.
B.Percentage of employees trained.
C.Audit findings count.
D.Loss amount from fraud.
AnswerB

Percentage of employees trained measures a preventive control's coverage before incidents occur, making it a leading indicator. It satisfies the stem's requirement by predicting future risk exposure rather than reporting past outcomes, unlike lagging metrics such as incident counts or breach losses, which only confirm events already realised.

Why this answer

A leading indicator is a proactive metric that predicts future risk events or control effectiveness. The percentage of employees trained is a leading indicator because it measures a preventive control (security awareness) that reduces the likelihood of future incidents, such as phishing or data breaches. In contrast, lagging indicators like incident counts or loss amounts reflect past events.

Exam trap

ISACA's CRISC exam often tests the distinction between leading and lagging indicators by presenting lagging metrics (like incident counts or audit findings) as plausible answers, trapping candidates who confuse reactive measures with proactive predictors.

How to eliminate wrong answers

Option A is wrong because the number of security incidents is a lagging indicator—it measures events that have already occurred, not predictive of future risk. Option C is wrong because audit findings count is a lagging indicator that reports on past compliance gaps or control failures, not forward-looking risk. Option D is wrong because loss amount from fraud is a lagging indicator that quantifies realized financial impact after an event, not a proactive measure.

341
MCQmedium

During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control is expected to reduce the ALE by 80% and will cost $150,000 per year. What is the net benefit of implementing the control?

A.$100,000
B.$250,000
C.$400,000
D.$350,000
AnswerB

The control reduces the $500,000 ALE by 80%, a $400,000 saving, against a $150,000 annual cost. Subtracting that cost gives a net benefit of $250,000. The calculation uses the ALE reduction minus the control's yearly expense, matching the stated figures exactly.

Why this answer

The current annual loss expectancy (ALE) is $500,000. An 80% reduction means the control saves $400,000 per year. Subtracting the annual control cost of $150,000 yields a net benefit of $250,000.

This is calculated as (ALE × reduction percentage) – control cost.

Exam trap

The trap here is that candidates often forget to subtract the annual control cost from the gross savings, mistakenly selecting the gross savings ($400,000) as the net benefit.

How to eliminate wrong answers

Option A ($100,000) is wrong because it incorrectly subtracts the control cost from the reduced ALE ($100,000 = $100,000 – $0?) or miscalculates the savings as 20% of ALE. Option C ($400,000) is wrong because it represents the gross savings (80% of $500,000) without subtracting the $150,000 annual control cost. Option D ($350,000) is wrong because it likely results from subtracting the control cost from the original ALE ($500,000 – $150,000) and ignoring the 80% reduction factor.

342
MCQmedium

During a quarterly risk review, a risk owner reports that a critical trading application has exceeded its residual risk tolerance for the second consecutive quarter despite remediation efforts. The risk owner proposes to continue remediation and report again next quarter. Which of the following should the risk manager do?

A.Accept the risk owner's proposal because remediation is already underway and progress is being made.
B.Escalate the tolerance breach to the risk committee and recommend a formal risk response decision, such as acceptance, additional mitigation, or avoidance.
C.Re-rate the application's residual risk to within tolerance to reflect the remediation work already completed.
D.Direct the risk owner to implement additional controls immediately without involving the risk committee.
AnswerB

When residual risk remains above tolerance across reporting periods despite remediation, the decision exceeds the risk owner's authority. The risk manager should escalate to the risk committee with the evidence and options so a formal response decision can be made and documented. This preserves accountability, ensures the breach is visible to those empowered to accept it, and prevents uncontrolled drift in the organization's risk profile.

Why this answer

A residual risk that stays above tolerance across multiple reporting periods is a governance event, not a routine remediation update. The risk manager's role is to make the breach visible, present the evidence and available response options, and let the risk committee decide whether to accept, mitigate further, transfer, or avoid. Documenting that decision maintains accountability and keeps the organization's risk profile aligned with its stated tolerance.

Exam trap

The trap here is treating continued remediation effort as equivalent to an approved decision to accept the ongoing tolerance breach.

343
MCQhard

An organization is implementing a new cloud-based customer relationship management (CRM) system. The risk practitioner is designing the control monitoring plan. Which approach BEST ensures continuous monitoring of controls across both the application and infrastructure layers?

A.Implement a generic Security Information and Event Management (SIEM) system with standard rules.
B.Deploy an automated monitoring tool that ingests audit logs from the CRM and cloud infrastructure APIs to trigger alerts on anomalies.
C.Rely on the CRM vendor's SOC 2 Type II report for control assurance.
D.Schedule quarterly manual reviews of user access logs and system configurations.
AnswerB

Ingesting audit logs from both the CRM and cloud infrastructure APIs gives continuous, cross-layer visibility that manual reviews cannot sustain. Automated anomaly alerting satisfies the stem's requirement for ongoing control monitoring across application and infrastructure simultaneously, rather than point-in-time assessment of a single layer.

Why this answer

It establishes a continuous, automated monitoring feedback loop by ingesting audit logs from both the CRM application (e.g., user activity logs) and cloud infrastructure APIs (e.g., AWS CloudTrail, Azure Monitor). This approach enables real-time anomaly detection and alerting, which is essential for maintaining control effectiveness across the entire stack without manual intervention.

Exam trap

The trap here is that candidates often confuse point-in-time assurance (SOC 2 reports) with continuous monitoring, or they assume a generic SIEM is sufficient without considering the need for application-specific log ingestion and correlation.

How to eliminate wrong answers

Option A is wrong because a generic SIEM with standard rules lacks the tailored log sources and correlation logic needed to monitor the specific CRM application and cloud infrastructure layers, leading to high false-positive rates and missed anomalies. Option C is wrong because a SOC 2 Type II report provides only a point-in-time assurance of the vendor's controls, not continuous monitoring of the organization's own control environment. Option D is wrong because quarterly manual reviews introduce significant latency and cannot detect control failures or security incidents in near real-time, violating the principle of continuous monitoring.

344
MCQhard

An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?

A.Accept the risk
B.Implement compensating controls
C.Transfer via insurance
D.Avoid by decommissioning
AnswerB

Compensating controls reduce risk when patching is impossible, such as network segmentation, strict access controls or enhanced monitoring around the legacy system. This response accepts the system's continued operation while lowering likelihood or impact, matching the board's decision to retain it.

Why this answer

When a legacy system cannot be patched and the risk is high, compensating controls are the most appropriate response to reduce the residual risk to an acceptable level. Compensating controls, such as network segmentation, strict access controls, or an application-layer firewall, mitigate the exploitation vector without decommissioning the critical system. The board's decision to keep the system operational means avoidance is not an option, and acceptance alone would leave the organization exposed to an unacceptable risk level.

Exam trap

The trap here is that candidates often choose 'Accept the risk' because they misunderstand risk acceptance as a passive decision, but in CRISC, acceptance is only valid when the risk is within the risk appetite, not when the likelihood and impact are both high and the system is critical.

How to eliminate wrong answers

Option A is wrong because accepting the risk without any mitigation would leave the organization exposed to a high-likelihood, high-impact threat, which is typically unacceptable for a core business function; acceptance is only appropriate when the residual risk is within the organization's risk appetite. Option C is wrong because transferring via insurance does not reduce the likelihood or impact of a security incident; it only provides financial compensation after a loss, and for a legacy system with a high exploitation likelihood, the operational disruption and reputational damage are not fully transferable. Option D is wrong because avoiding by decommissioning contradicts the board's explicit decision to keep the system operational due to its criticality, and it would disrupt the core business function.

345
MCQeasy

A risk manager is using a 5x5 heat map to assess IT risks. Which of the following best describes the primary limitation of this qualitative risk analysis approach?

A.It requires extensive historical data to be accurate.
B.It is time-consuming and complex to implement.
C.It is subjective and not comparable across organizations.
D.It provides objective, financially meaningful results.
AnswerC

A 5x5 heat map relies on ordinal scales whose labels and thresholds each organisation defines differently, so ratings reflect assessor judgement rather than calibrated measurement. This satisfies the stem's focus on the primary limitation: scores cannot be meaningfully benchmarked across organisations, undermining consistent enterprise-wide risk comparison.

Why this answer

A 5x5 heat map is a qualitative technique: likelihood and impact are assigned ordinal ratings (e.g., 1–5) based on expert judgment rather than measured data. Because the scales are defined locally and the ratings are subjective, results are not directly comparable across organizations or even across business units with different risk appetites. This subjectivity is the primary limitation.

Exam trap

The trap is that candidates associate 'risk analysis' with data and rigor, so they pick the answer about needing historical data — but that describes quantitative analysis, while heat maps are deliberately qualitative and subjective.

How to eliminate wrong answers

Option A is wrong because qualitative heat maps explicitly do not require extensive historical data — that is a characteristic of quantitative analysis (e.g., Monte Carlo, FAIR). Option B is wrong because heat maps are valued for being fast and simple to implement; complexity and time consumption are criticisms of quantitative methods, not qualitative ones. Option D is wrong because heat maps produce ordinal, not financially meaningful, results — expressing risk in monetary terms requires quantitative techniques like annualized loss expectancy (ALE).

346
Multi-Selecthard

Which THREE of the following are effective risk treatment strategies?

Select 3 answers
A.Accept the risk without any analysis
B.Avoid the risk by discontinuing the activity
C.Ignore the risk if it has not materialized yet
D.Implement compensating controls to reduce risk
E.Transfer the risk through outsourcing
AnswersB, D, E

Discontinuing the activity eliminates the underlying exposure entirely, so no residual risk remains to be managed. This satisfies the stem's requirement for a genuine risk treatment strategy, since avoidance removes both the likelihood and impact rather than merely transferring or tolerating them.

Why this answer

Option B is correct because risk avoidance is a recognized treatment strategy in which the organization eliminates the risk entirely by discontinuing the activity or process that generates it. Option D is correct because implementing compensating controls is a form of risk mitigation/reduction, lowering the likelihood or impact of a threat to an acceptable level. Option E is correct because risk transfer shifts the financial or operational impact of a risk to a third party, such as through outsourcing, insurance, or contractual agreements.

Option A is not a valid treatment because accepting a risk must be a deliberate, informed decision based on analysis, not done blindly without assessment. Option C is not a valid treatment because ignoring a risk simply leaves it unmanaged and does not constitute an accepted risk-management strategy.

Exam trap

The trap here is confusing 'ignoring' or 'uninformed acceptance' with the legitimate risk acceptance strategy, which requires documented analysis and approval, and assuming that risks that have not yet materialized can be safely disregarded.

347
MCQmedium

Which of the following best describes the primary limitation of qualitative risk analysis?

A.It requires extensive historical data
B.It is subjective and not comparable across organizations
C.It cannot produce financial loss estimates
D.It is time-consuming and complex
AnswerB

Subjectivity and lack of comparability are key limitations.

Why this answer

Qualitative risk analysis relies on expert judgment, ordinal scales (e.g., high/medium/low), and subjective ratings rather than numerical data. Its primary limitation is that these ratings are subjective and organization-specific, making them difficult to compare across different organizations or even across teams using different scales. This lack of standardization and comparability is the core weakness.

Exam trap

CRISC often tests the confusion between limitations of qualitative analysis (subjectivity, non-comparability) and characteristics of quantitative analysis (data requirements, complexity, financial estimates).

How to eliminate wrong answers

Option A is wrong because qualitative analysis specifically does not require extensive historical data — that is a characteristic of quantitative analysis, which needs frequency and loss data. Option C is wrong because while qualitative analysis typically does not produce financial loss estimates, that is a characteristic rather than the primary limitation; the deeper issue is subjectivity and non-comparability. Option D is wrong because qualitative analysis is generally faster and simpler than quantitative analysis, not time-consuming and complex — that describes quantitative methods like FAIR or Monte Carlo simulation.

348
Multi-Selecthard

A quantitative risk analysis using FAIR requires estimating which THREE primary factors?

Select 3 answers
A.Risk appetite
B.Vulnerability
C.Loss magnitude
D.Threat event frequency
E.Control cost
AnswersB, C, D

FAIR estimates loss event frequency from threat event frequency and vulnerability, combined with loss magnitude, to quantify risk in monetary terms. Vulnerability is one of the three primary factors, representing the probability a threat event becomes a loss.

Why this answer

In FAIR (Factor Analysis of Information Risk), the primary factors estimated for quantitative risk analysis are threat event frequency (D), vulnerability (B), and loss magnitude (C). Threat event frequency (D) captures how often a threat agent is expected to act against an asset, which drives the likelihood side of the risk equation. Vulnerability (B) is the probability that a threat event becomes a loss event, given the resistance strength of the asset's controls, and it modifies threat event frequency into loss event frequency.

Loss magnitude (C) represents the probable financial impact per loss event, combining primary and secondary loss forms, and it is multiplied by loss event frequency to produce annualized loss exposure. Risk appetite (A) is a governance-level tolerance statement rather than a FAIR-estimated factor, and control cost (E) is an input to cost-benefit analysis of mitigations, not one of the three primary FAIR estimation factors.

Exam trap

CRISC often tests whether candidates can distinguish FAIR's primary estimation factors (threat event frequency, vulnerability, loss magnitude) from contextual elements like risk appetite and control cost.

349
MCQhard

A company monitors key risk indicators (KRIs) using a dashboard. The risk manager notices that a KRI has a green status but the underlying control testing shows a high failure rate. What action should the risk manager take FIRST?

A.Escalate to the risk committee
B.Change the KRI threshold to amber
C.Investigate the KRI calculation methodology
D.Re-test the control
AnswerC

A green KRI conflicting with high control failure rates signals the indicator itself may be miscalculated or misconfigured. Verifying the KRI's calculation methodology first establishes whether the dashboard is misleading before acting on the control findings.

Why this answer

The KRI showing green while the underlying control has a high failure rate indicates a misalignment between the KRI and the actual control effectiveness. The first step is to investigate the KRI calculation methodology to determine if the KRI is measuring the wrong metric, using stale data, or has an incorrect threshold. Only after understanding why the KRI is misleading can the risk manager take appropriate corrective action.

Exam trap

The trap here is that candidates assume a green KRI means the risk is low and immediately focus on fixing the control (Option D) or adjusting the threshold (Option B), rather than recognizing that the KRI itself may be flawed and requires investigation first.

How to eliminate wrong answers

Option A is wrong because escalating to the risk committee without first understanding the root cause of the discrepancy would provide incomplete or misleading information, potentially causing unnecessary alarm or poor decision-making. Option B is wrong because changing the threshold to amber without investigating the calculation methodology is a superficial fix that does not address the underlying issue of why the KRI is green despite control failures. Option D is wrong because re-testing the control assumes the control test results are accurate, but the core problem is that the KRI is not reflecting the control state; re-testing does not resolve the KRI calculation error.

350
MCQmedium

When prioritizing risk treatment actions, which of the following should be the primary consideration?

A.Ease of implementation
B.Compliance requirements only
C.Risk level and cost-benefit analysis
D.Risk owner preference
AnswerC

Risk level and cost-benefit analysis directly satisfy the prioritisation constraint by ranking treatments against both exposure magnitude and the economics of mitigation. Residual risk reduction per unit of spend determines sequencing, ensuring limited resources target the highest-impact exposures first rather than addressing every identified risk equally.

Why this answer

Risk treatment prioritization should be driven by the level of risk (likelihood and impact) combined with a cost-benefit analysis of the treatment options. This ensures that resources are allocated to the most significant risks where the treatment provides the greatest reduction in risk relative to its cost, aligning with business objectives and risk appetite.

Exam trap

CRISC often tests the misconception that ease of implementation or compliance alone should drive risk treatment prioritization, when the primary consideration is risk level combined with cost-benefit analysis.

How to eliminate wrong answers

Option A is wrong because ease of implementation is a secondary factor — a low-risk issue that is easy to fix should not be prioritized over a high-risk issue that is harder to address. Option B is wrong because compliance requirements are one input but not the sole consideration; focusing only on compliance can leave significant non-regulatory risks untreated. Option D is wrong because risk owner preference is subjective and may not align with organizational risk priorities or cost-benefit outcomes.

351
MCQhard

An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is an example of:

A.Periodic control testing
B.Continuous monitoring
C.Access review
D.Vulnerability scanning
AnswerB

SIEM rules that alert when failed logins exceed a threshold constitute continuous monitoring: automated, ongoing collection and analysis of event data against defined criteria. This matches the stem exactly, distinguishing it from periodic assessments or manual review, and satisfies the requirement for real-time anomaly detection.

Why this answer

This scenario describes continuous monitoring because the SIEM is configured with rules that automatically and perpetually analyze login events in real time, generating alerts when the count of failed logins surpasses a predefined threshold. Unlike periodic or manual checks, this process operates 24/7 without human intervention, directly detecting anomalies as they occur.

Exam trap

The trap here is that candidates confuse 'continuous monitoring' with 'continuous auditing' or assume any automated activity is 'vulnerability scanning,' but the key differentiator is the real-time, rule-based detection of operational anomalies versus scheduled scans for configuration weaknesses.

How to eliminate wrong answers

Option A is wrong because periodic control testing involves scheduled, manual or automated assessments of controls at fixed intervals (e.g., quarterly reviews), whereas the SIEM rule runs continuously without a schedule. Option C is wrong because an access review is a manual or semi-automated process that examines user permissions and entitlements against policy, not real-time detection of failed login anomalies. Option D is wrong because vulnerability scanning identifies known software vulnerabilities (e.g., missing patches, misconfigurations) by probing systems, not by monitoring authentication failure patterns.

352
Multi-Selecteasy

A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose two.)

Select 2 answers
A.Implementing firewalls to protect the network perimeter.
B.Conducting regular vulnerability assessments and patching.
C.Avoiding the risk by discontinuing the vulnerable activity.
D.Accepting the risk because the cost of mitigation exceeds the potential loss.
E.Purchasing cyber insurance to cover potential losses.
AnswersA, B

Correct: Firewalls reduce the likelihood of network-based attacks, which is a mitigation technique.

Why this answer

Implementing firewalls to protect the network perimeter is a risk mitigation technique because it reduces the likelihood of unauthorized access by filtering traffic based on security rules. Firewalls operate at layers 3 and 4 (and sometimes layer 7) of the OSI model, using stateful inspection or application-layer filtering to block malicious packets. This directly lowers the probability of a successful attack on the high-value asset, which is the essence of mitigation.

Exam trap

The trap here is that candidates often confuse risk mitigation with risk transfer (insurance) or risk acceptance, failing to recognize that mitigation involves active controls (like firewalls and patching) that reduce the risk level, not just financial compensation or inaction.

353
MCQhard

An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?

A.The probable financial impact of a cyber incident
B.The cost of implementing security controls
C.The number of records compromised in a data breach
D.The probability that a threat event will occur
AnswerA

Loss Magnitude in FAIR represents the total monetary loss an organisation would incur from a single loss event, combining primary and secondary loss forms. It satisfies the stem's quantification constraint by expressing impact in financial terms, distinct from probability or frequency. This makes it the probable financial impact of a cyber incident.

Why this answer

In FAIR, Loss Magnitude represents the probable financial impact resulting from a loss event — it quantifies how much money an organization would lose if a threat event materializes into a loss. It is one of the two primary factors (alongside Loss Event Frequency) that combine to produce risk. It encompasses primary and secondary loss forms across productivity, response, replacement, fines, and reputation.

Exam trap

The trap is conflating Loss Magnitude with Loss Event Frequency — candidates often pick the probability-based answer because both are core FAIR terms, but only LM describes financial impact.

How to eliminate wrong answers

Option B is wrong because the cost of implementing security controls is a risk-mitigation expense, not a loss magnitude — FAIR measures loss from realized events, not control spend. Option C is wrong because the number of compromised records is a unit of exposure/volume, not a financial magnitude; record count feeds into loss estimation but is not itself Loss Magnitude. Option D is wrong because the probability a threat event occurs is Loss Event Frequency (LEF), the other half of the FAIR risk equation, not Loss Magnitude.

354
MCQhard

A risk practitioner is assessing the organization's backup and recovery controls for a critical on-premises database. The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is fifteen minutes. The current design replicates backups nightly to an offsite tape vault. Which finding is MOST significant?

A.Tape media have a limited shelf life and may degrade before they are needed for restoration.
B.The recovery time objective of four hours may be unachievable without a documented disaster recovery test.
C.Nightly backups cannot satisfy the fifteen-minute recovery point objective, so up to a day of data could be lost.
D.The backup media are stored offsite, which introduces a delay in retrieving them during a recovery.
AnswerC

The RPO defines the maximum tolerable data loss. A nightly backup means the organization could lose up to twenty-four hours of transactions, far exceeding the fifteen-minute RPO. This is the most significant finding because the design fundamentally cannot meet the stated business requirement, exposing the organization to unacceptable data loss in a recovery scenario.

Why this answer

The RPO of fifteen minutes requires that no more than fifteen minutes of data can be lost, which demands frequent replication or continuous data protection. Nightly backups leave up to a full day of transactions at risk, so the design cannot meet the business requirement. This mismatch is the most significant finding and must drive a redesign toward more frequent replication.

Exam trap

The trap here is focusing on operational details like tape shelf life or offsite retrieval delay, when the decisive issue is that nightly backups cannot meet a fifteen-minute RPO.

355
Multi-Selectmedium

A risk analyst is assessing the impact of a potential ransomware attack. Which THREE categories of business impact should be considered?

Select 3 answers
A.Geographic diversity
B.Operational downtime
C.Financial losses (direct and indirect)
D.Technical complexity
E.Regulatory fines
AnswersB, C, E

Correct; operational impact affects productivity.

Why this answer

Operational downtime (B) is a direct consequence of a ransomware attack, as encryption of critical systems halts business processes, leading to lost productivity and revenue. This category is essential for impact assessment because it quantifies the duration and scope of service disruption, which directly affects operational continuity.

Exam trap

The trap here is confusing risk factors (like technical complexity or geographic diversity) with impact categories, leading candidates to select options that describe the attack's nature or mitigation rather than its direct business consequences.

356
MCQhard

A healthcare payer's risk committee is deciding how to respond to a risk that its cloud-hosted claims processing platform could become unavailable for more than 24 hours. The platform is critical, the provider offers a financially backed 99.95% availability commitment, and the organization lacks the internal capability to run a secondary environment. Which risk response is MOST appropriate?

A.Transfer the financial consequence through contract terms and insurance while implementing a tested recovery capability with the provider.
B.Avoid the risk entirely by terminating the cloud contract and rebuilding the claims platform in an internally managed data center.
C.Accept the risk and document the decision, relying on the provider's service level agreement as the sole safeguard.
D.Reduce the risk by negotiating a higher availability percentage in the service level agreement without adding recovery arrangements.
AnswerA

Because internal capability is absent, the practical response combines transferring financial exposure via contractual remedies and cyber or business interruption insurance with mitigating operational impact through provider-supported recovery arrangements that are regularly tested. This layered approach addresses both the monetary loss and the service restoration gap, which is what the committee actually needs for a critical platform.

Why this answer

For a critical platform with no internal recovery capability, the realistic response is layered: contractual remedies and insurance transfer the financial loss, while provider-supported recovery arrangements mitigate the operational outage. Pure acceptance leaves patients and regulators exposed, avoidance is disproportionate, and a stronger SLA alone changes expectations without building the capability to restore service.

Exam trap

The trap here is treating a financially backed availability commitment as equivalent to actual recovery capability, when it only compensates loss and does not restore the service.

357
MCQhard

You are the risk manager for a multinational corporation that relies heavily on a cloud-based ERP system. The system is critical for financial reporting and supply chain management. Recently, the company experienced a significant increase in the number of failed user authentication attempts, which were traced to a misconfiguration in the identity management module. The misconfiguration was detected by the security operations center (SOC) through log analysis, but it took three days to identify and resolve. The root cause was a change made by a cloud administrator without following the change management process. The incident resulted in a temporary denial of service for external users. The company's risk appetite for system availability is low, with a tolerance for downtime of no more than one hour per month. The current monitoring controls include quarterly access reviews and SOC monitoring of logs with a 24-hour review cycle. The board has requested a report on the incident and recommendations to prevent recurrence. What is the MOST effective recommendation to improve monitoring and reduce the likelihood of similar incidents?

A.Implement automated real-time monitoring of critical configuration changes with alerts.
B.Require all change requests to be approved by the change advisory board (CAB).
C.Increase the frequency of access reviews to monthly.
D.Provide additional training to cloud administrators on security policies.
AnswerA

Automated real-time monitoring of critical configuration changes detects misconfigurations immediately, replacing the 24-hour log review cycle that let the incident persist three days. This directly reduces likelihood of recurrence and supports the low availability risk appetite, since faster detection shortens the denial-of-service window.

Why this answer

The most effective recommendation is to implement automated real-time monitoring of critical configuration changes with alerts. This directly addresses the root cause: a misconfiguration that went undetected for three days. Real-time monitoring would detect such changes immediately, allowing rapid response and reducing the likelihood of similar incidents.

Other options are less effective: CAB approval is a preventive control but doesn't improve monitoring; increasing access reviews frequency is not directly related to configuration changes; additional training is useful but not as immediate and reliable as automated monitoring.

Exam trap

The trap is choosing preventive controls like CAB approval or training when the question asks for improving monitoring to reduce likelihood of similar incidents.

How to eliminate wrong answers

Option B is wrong because while CAB approval can prevent unauthorized changes, it does not improve monitoring and may not catch misconfigurations that bypass the process. Option C is wrong because access reviews are about user permissions, not configuration changes, and increasing frequency may not detect misconfigurations in real-time. Option D is wrong because training is important but does not provide the real-time detection capability needed to reduce the likelihood of similar incidents.

358
Multi-Selecthard

Which THREE of the following are key considerations when designing a risk reporting framework? (Choose three.)

Select 3 answers
A.Timeliness of the information provided.
B.Including all operational data for completeness.
C.Consistency in definitions and metrics over time.
D.Aligning with industry best practices for risk reporting.
E.Tailoring the report to the target audience.
AnswersA, C, E

Timely information allows management to act promptly.

Why this answer

Timeliness is a key consideration because risk reports must provide current information to enable timely decision-making and response to emerging risks. Stale data can lead to missed opportunities for mitigation or incorrect risk assessments, especially in fast-changing environments like cybersecurity or financial markets.

Exam trap

The trap here is that candidates may confuse 'completeness' (Option B) with 'comprehensiveness' or think that industry best practices (Option D) are mandatory design elements, when in fact risk reporting must be concise and context-specific to be effective.

359
MCQeasy

Which of the following is an example of a detective control in IT risk management?

A.Firewall
B.Data encryption
C.Backup restoration
D.Intrusion Detection System (IDS)
AnswerD

An IDS monitors network traffic and raises alerts on suspicious activity, satisfying the detective control requirement of identifying incidents after they occur. Unlike preventive controls such as firewalls, which block traffic, or corrective controls, it provides visibility and evidence, enabling timely response to potential intrusions.

Why this answer

Detective controls identify risk events after they occur. Intrusion Detection Systems (IDS) monitor network traffic to detect malicious activity.

360
MCQhard

A financial institution has a control that manually reviews all wire transfers over $10,000. During an audit, it was found that the review is completed within 24 hours for 95% of transactions, but the target is 99%. The process owner wants to improve the control's effectiveness. Which of the following would be the MOST effective remediation?

A.Implement a second level of approval for all wire transfers.
B.Automate the review process using an application control.
C.Increase the number of staff performing the reviews.
D.Adjust the target to 95% to reflect current performance.
AnswerB

Automating the review with an application control removes the manual bottleneck causing the 95% timeliness shortfall, enforcing checks consistently within the 24-hour target. This directly addresses the control effectiveness gap the audit identified, rather than adding further manual oversight.

Why this answer

Automating the review process with an application control directly addresses the root cause of the missed target (human delay or error) by enforcing real-time or near-real-time validation of wire transfers over $10,000. This eliminates the dependency on manual throughput and ensures consistent, timely compliance with the 99% target, as the control can be configured to block or flag transactions until automated checks are completed within the required window.

Exam trap

The trap here is that candidates confuse 'adding more people' (Option C) with a process improvement, when in fact automation (Option B) is the only option that removes the bottleneck of human latency and variability, directly targeting the root cause of the missed KPI.

How to eliminate wrong answers

Option A is wrong because adding a second level of approval increases manual steps and latency, likely worsening the timeliness metric rather than improving it. Option C is wrong because increasing staff addresses capacity but not the inherent variability and delay of manual processes; it may improve throughput but cannot guarantee the consistent 99% target without automation. Option D is wrong because adjusting the target to match current performance is a risk acceptance or avoidance tactic, not a remediation that improves control effectiveness; it ignores the underlying deficiency and violates the principle of aligning controls with risk appetite.

361
Multi-Selecthard

Which THREE factors should be considered when determining the likelihood of a threat exploiting a vulnerability?

Select 3 answers
A.Ease of exploitation
B.Regulatory fines
C.Asset value
D.Existing controls
E.Threat actor capability
AnswersA, D, E

Ease of exploitation directly quantifies how readily a threat actor can leverage a weakness, which is a core likelihood input. A vulnerability requiring trivial effort, such as a default credential, raises likelihood; one demanding specialised access or complex chaining lowers it. This satisfies the stem's likelihood determination constraint.

Why this answer

Option A (Ease of exploitation) is correct because the likelihood of a threat exploiting a vulnerability depends heavily on how simple the attack is to execute — for example, whether a public exploit exists, whether it requires authentication, or whether it can be triggered remotely versus requiring local access. Option D (Existing controls) is correct because compensating and preventive controls such as firewalls, EDR, MFA, and patching directly reduce the probability that a vulnerability can be successfully exploited. Option E (Threat actor capability) is correct because likelihood is a function of the adversary's skill, resources, motivation, and tooling — a sophisticated, well-funded actor is far more likely to exploit a given weakness than an unskilled one.

Option B (Regulatory fines) is not a likelihood factor; it is a potential business impact or consequence of a breach, which belongs to the impact side of risk analysis. Option C (Asset value) is also an impact-side consideration, describing how much a compromised asset is worth to the organization, not how probable exploitation is.

Exam trap

The trap here is confusing factors that determine likelihood (probability of occurrence) with factors that determine impact (consequences), leading candidates to incorrectly select asset value or regulatory fines as likelihood inputs.

362
MCQeasy

A risk manager notices that a key risk indicator (KRI) for network downtime has been steadily increasing over the past three months. The current value is 15% above the risk tolerance threshold. Which of the following is the BEST immediate action?

A.Lower the risk tolerance threshold to trigger more frequent alerts
B.Accept the increased risk without further analysis because the trend is gradual
C.Alert the risk owner and initiate a root cause analysis
D.Increase the risk tolerance threshold to match the current level
AnswerC

Alerting the risk owner triggers the governance escalation path, while root cause analysis identifies why the KRI breached tolerance. This satisfies the stem's "immediate action" constraint: the threshold is already exceeded, so the priority is escalation and diagnosis, not re-measuring or revising tolerance thresholds.

Why this answer

The KRI has exceeded the risk tolerance threshold, indicating a potential control failure or emerging threat. The immediate action is to alert the risk owner, who has accountability for the risk, and initiate a root cause analysis to identify why network downtime is increasing. This aligns with the CRISC process of monitoring KRIs and escalating when thresholds are breached.

Exam trap

The trap here is that candidates may confuse adjusting the threshold (a control metric) with managing the risk itself, but CRISC emphasizes that thresholds are set to trigger action, not to be moved to avoid action.

How to eliminate wrong answers

Option A is wrong because lowering the tolerance threshold would increase alert frequency but does not address the underlying cause of the increasing downtime; it merely changes the measurement baseline. Option B is wrong because accepting the risk without analysis violates the principle of proactive risk management; a gradual trend does not justify ignoring a threshold breach, as it may indicate a systemic issue. Option D is wrong because raising the tolerance threshold to match the current level effectively normalizes the breach, eliminating the early warning function of the KRI and masking the problem.

363
MCQeasy

An IT risk manager is facilitating a workshop to identify risks for a new mobile banking application. Which technique is MOST appropriate for generating a comprehensive list of risks?

A.Review risk registers from similar projects
B.Perform a SWOT analysis
C.Conduct a brainstorming session with cross-functional team members
D.Distribute a risk questionnaire to project stakeholders
AnswerC

Cross-functional brainstorming draws on diverse operational, compliance and technical perspectives, surfacing a broader risk list than single-analyst methods. This satisfies the stem's requirement for comprehensive identification during early workshop stages, before quantitative assessment is warranted.

Why this answer

Brainstorming with a cross-functional team (option C) is the most appropriate technique for generating a comprehensive list of risks for a new mobile banking application because it leverages diverse perspectives from development, security, compliance, and business units. This collaborative approach helps uncover unknown or emergent risks specific to the application's architecture, such as API vulnerabilities, session management flaws, or regulatory gaps, which might not be captured by historical data or structured questionnaires.

Exam trap

The trap here is that candidates often choose 'Review risk registers from similar projects' (option A) because it seems efficient and data-driven, but they overlook that historical registers may miss novel risks specific to the new application's technology, such as mobile-specific attack vectors or updated compliance requirements.

How to eliminate wrong answers

Option A is wrong because reviewing risk registers from similar projects relies on historical data that may not account for the unique technology stack, threat landscape, or regulatory requirements of a new mobile banking application, leading to blind spots for novel risks. Option B is wrong because a SWOT analysis focuses on strategic strengths, weaknesses, opportunities, and threats at a high level, but it lacks the depth and specificity needed to identify technical risks like insecure data storage, weak authentication, or third-party SDK vulnerabilities. Option D is wrong because distributing a risk questionnaire to project stakeholders is a passive, one-way method that often yields incomplete or biased responses, missing the interactive discussion needed to surface complex, interdependent risks in a mobile banking context.

364
MCQhard

A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?

A.Implement a unidirectional gateway that enforces one-way data flow
B.Deploy a host-based intrusion detection system on each ICS device
C.Upgrade the ICS to modern protocols with built-in authentication
D.Disconnect the ICS from the corporate network and use manual data transfer
AnswerA

A unidirectional gateway permits data to flow only from the ICS outward to corporate IT, physically preventing inbound commands or protocol exploitation. This isolates the unauthenticated legacy protocols while preserving real-time operational data access, satisfying the availability constraint without modifying the control system.

Why this answer

A unidirectional gateway (data diode) enforces one-way data flow from the ICS to the corporate IT network, preventing any inbound traffic that could exploit the legacy protocols' lack of authentication. This maintains operational availability because the ICS remains isolated from direct network attacks while still providing real-time data access. It is the only option that addresses the authentication gap without disrupting legacy system operations.

Exam trap

The trap here is that candidates often choose upgrading protocols (Option C) as the 'best practice' without considering the operational availability constraints of legacy ICS environments, where a unidirectional gateway provides a non-disruptive security layer.

How to eliminate wrong answers

Option B is wrong because a host-based intrusion detection system (HIDS) on each ICS device can detect attacks but cannot prevent exploitation of unauthenticated legacy protocols; it also adds overhead that may impact real-time control availability. Option C is wrong because upgrading to modern protocols with built-in authentication would require replacing or reconfiguring legacy ICS devices, risking operational downtime and incompatibility with existing field equipment. Option D is wrong because disconnecting the ICS and using manual data transfer eliminates the real-time data access requirement entirely, failing to meet the integration objective and introducing latency and human error.

365
Multi-Selectmedium

An IT risk manager is performing a risk assessment for a new cloud service. Which TWO of the following are key inputs to the risk identification process? (Select TWO.)

Select 2 answers
A.Risk appetite statement
B.Threat intelligence feeds
C.Control testing results
D.Residual risk levels
E.Asset inventory
AnswersB, E

Threat intelligence feeds supply current information on threat actors, tactics and vulnerabilities relevant to the cloud service, directly informing which threats the risk identification process should consider. They are a recognised key input alongside the asset inventory, providing the external threat context that shapes the risk register.

Why this answer

Option B (Threat intelligence feeds) is correct because risk identification requires understanding which threats are relevant to the cloud service, and threat intelligence feeds supply current, actionable information about threat actors, TTPs, and vulnerabilities that could exploit the service's assets. Option E (Asset inventory) is correct because you cannot identify risks without knowing what assets exist; the inventory defines the cloud service's components, data, and dependencies that threats could affect. Option A (Risk appetite statement) is not a key input to risk identification; it is used during risk evaluation and response to determine how much risk is acceptable.

Option C (Control testing results) is not an input to risk identification; it is an output of control assessment used to validate control effectiveness after risks and controls are identified. Option D (Residual risk levels) is not an input to risk identification; residual risk is calculated after risk treatment, so it comes later in the risk management process.

Exam trap

The trap here is that candidates often confuse risk identification inputs with outputs from later phases, such as control testing results (C) or residual risk levels (D), because they are familiar terms in the overall risk management process but are not used at the start of identification.

366
Multi-Selecthard

An organization is deploying IoT devices in a smart building. Which of the following are significant security risks associated with IoT? (Choose THREE.)

Select 3 answers
A.Firmware update challenges due to device diversity
B.Legacy device security gaps from unpatched vulnerabilities
C.Increased power consumption
D.Higher data transmission speeds
E.Expanded attack surface due to many connected devices
AnswersA, B, E

Smart buildings mix devices from many vendors with differing firmware formats and update mechanisms, so no single patching process applies. This diversity makes timely firmware remediation impractical, leaving vulnerabilities unaddressed and directly constituting the update challenge the scenario identifies.

Why this answer

IoT risks include expanded attack surface, legacy device security gaps, and firmware update challenges.

367
MCQmedium

A software company allows developers to push code directly to production using a CI/CD pipeline. A recent post-incident review found that a developer's compromised credentials were used to deploy malicious code that exfiltrated customer data. Which control would MOST effectively reduce the risk of this specific attack path recurring?

A.Increase logging and alerting on production deployments and review alerts weekly.
B.Require multi-factor authentication for all developer accounts and enforce short-lived deployment tokens scoped to individual pipelines.
C.Require developers to complete annual secure coding training and sign an acceptable use policy.
D.Implement static application security testing in the pipeline to scan code before deployment.
AnswerB

The attack relied on a stolen credential being sufficient to deploy code. Multi-factor authentication means a password alone cannot authenticate, and short-lived, pipeline-scoped tokens limit what a captured token can do, directly breaking the specific path used in this incident. This combination is the most targeted reduction of the demonstrated risk.

Why this answer

The incident path was a stolen credential granting deployment rights. Strengthening authentication with multi-factor authentication and constraining deployment tokens to short-lived, pipeline-scoped values removes both the sufficiency of a password and the blast radius of a captured token. Scanning, logging and training are valuable controls but do not close the authentication and authorization gap that enabled this specific attack.

Exam trap

The trap here is selecting detective or awareness controls when the incident path was an authentication and authorization weakness that only preventive identity controls can close.

368
MCQeasy

A risk practitioner is conducting a risk assessment for a new mobile application that will process credit card payments. The practitioner needs to identify relevant threats. Which of the following is the MOST appropriate source for identifying threats specific to this application?

A.The business continuity plan for the payment processing system
B.The IT department's list of approved software vendors
C.A threat intelligence feed that includes mobile and payment card threats
D.The organization's previous audit findings for other applications
AnswerC

Threat intelligence feeds provide current, relevant information about threat actors, tactics, techniques, and procedures (TTPs) targeting mobile payment systems. This is the most appropriate source because it is specific to the technology and industry, enabling the practitioner to identify threats such as credential stuffing, mobile malware, and API abuse. It directly supports the identification of threats for this application.

Why this answer

Threat intelligence feeds are designed to provide up-to-date information on threats relevant to specific technologies and industries. For a mobile payment app, a feed covering mobile and payment card threats will identify threat actors, attack vectors, and emerging TTPs. This enables the risk practitioner to build a realistic threat landscape.

Other sources like audit findings or continuity plans are secondary and do not offer the same breadth or currency.

Exam trap

The trap here is selecting internal documents like audit findings or vendor lists, which are not threat sources, instead of external threat intelligence that is specific to the technology.

369
Multi-Selecteasy

A risk practitioner is identifying risks related to a new API gateway implementation. Which TWO of the following are MOST likely to be significant risks?

Select 2 answers
A.Insufficient logging of API requests.
B.Lack of scalability for peak loads.
C.Insecure direct object references (IDOR) allowing unauthorized data access.
D.Use of outdated programming language.
E.High licensing cost.
AnswersA, C

Insufficient API request logging removes the audit trail needed to detect abuse, trace data exfiltration and evidence compliance, directly undermining the gateway's monitoring and accountability controls. For a new API gateway exposing internal services, this gap is a significant risk because threats such as credential stuffing and injection attacks would go undetected, breaching CRISC's risk-identification expectations.

Why this answer

Option A is correct because an API gateway is a central enforcement and audit point, and insufficient logging of API requests removes the visibility needed to detect abuse, trace incidents, and meet monitoring/compliance requirements, making it a significant risk. Option C is correct because insecure direct object references (IDOR) let an authenticated caller manipulate object identifiers to access resources or data belonging to other users, a common and high-impact API authorization flaw that a gateway implementation must address. The unmarked options are less significant here: lack of scalability (B) is primarily a performance/availability engineering concern rather than a core risk-identification finding, outdated programming language (D) is a generic technical-debt issue not specific to the API gateway scenario, and high licensing cost (E) is a financial/commercial consideration, not a security or operational risk of the gateway itself.

Exam trap

The trap here is that candidates often confuse operational risks (scalability, cost) with security risks, or they incorrectly assume that outdated programming languages are a direct risk to the API gateway itself, when in fact the gateway abstracts away language-specific vulnerabilities.

370
Multi-Selectmedium

Which TWO of the following are examples of detective controls?

Select 2 answers
A.Encryption of data at rest
B.Firewall rules
C.Log monitoring and analysis
D.Intrusion detection system (IDS)
E.Data backup process
AnswersC, D

Log monitoring and analysis examines recorded event data to identify incidents after or during occurrence, which is the defining characteristic of a detective control. It does not prevent events, distinguishing it from preventive controls such as firewalls or access restrictions.

Why this answer

Log monitoring and analysis (C) is a detective control because it continuously reviews and correlates event logs to identify and alert on suspicious or anomalous activity after it occurs, providing visibility into incidents rather than preventing them. An intrusion detection system (IDS) (D) is likewise detective: it passively inspects network or host traffic and raises alerts when it matches known attack signatures or behavioral anomalies, without blocking the traffic itself. By contrast, encryption of data at rest (A) and firewall rules (B) are preventive controls that stop unauthorized access or disclosure before it happens, and a data backup process (E) is a corrective/recovery control that restores data after a loss event, so none of these three are detective controls.

Exam trap

CRISC often tests the preventive-vs-detective distinction by including strong-sounding controls like encryption and firewalls, so candidates must ask 'does this stop an event or detect it?' rather than picking the most security-sounding option.

371
MCQeasy

An organization has a risk indicator that shows the number of failed login attempts per day. The threshold is 100. Last week, the number spiked to 200 on two days. What does this indicate?

A.The system is experiencing a denial-of-service attack.
B.There may be a brute-force attack in progress.
C.The password policy needs to be updated.
D.Users have forgotten their passwords.
AnswerB

Doubling the failed-login threshold on two separate days signals sustained credential-guessing activity against accounts. Such repeated authentication failures concentrated in time are characteristic of a brute-force attack rather than routine user error or isolated lockouts.

Why this answer

A spike in failed login attempts from a baseline of 100 to 200 per day is a classic indicator of a brute-force attack, where an attacker systematically tries multiple username/password combinations. This risk indicator directly measures authentication failures, which are the primary symptom of such an attack. The threshold breach signals that the control (account lockout or rate limiting) may be insufficient or failing.

Exam trap

The trap here is that candidates confuse a spike in failed logins with a DoS attack, but DoS attacks target availability (e.g., SYN flood) rather than authentication failures, which are a confidentiality/integrity concern.

How to eliminate wrong answers

Option A is wrong because a denial-of-service (DoS) attack typically causes a spike in traffic volume or resource exhaustion, not specifically failed login attempts; a DoS would likely overwhelm the entire system, not just authentication. Option C is wrong because a password policy update (e.g., complexity or expiration) would not cause a sudden two-day spike in failed logins; policy changes affect long-term compliance, not immediate authentication failure rates. Option D is wrong because users forgetting passwords would cause a consistent, low-level increase in failed logins, not a sharp spike to 200% of the threshold on only two days; such a pattern is more indicative of automated malicious activity.

372
MCQmedium

You are the IT risk manager for a financial institution. During a routine vulnerability scan, you discover that a critical web application has a high-severity vulnerability that could allow remote code execution. The development team states that a patch is not yet available from the vendor, and the application is business-critical with no acceptable downtime. The risk owner wants to accept the risk. However, the organization's risk appetite is very low for security vulnerabilities. You have been asked to recommend a course of action. Which of the following should you recommend?

A.Transfer the risk by purchasing cyber insurance.
B.Decommission the application immediately.
C.Implement a web application firewall (WAF) with virtual patching to reduce exploitability.
D.Accept the risk as the team will monitor for patches.
AnswerC

A WAF with virtual patching inspects and blocks exploit traffic targeting the known remote code execution vector, reducing exploitability without touching the application or requiring downtime. This compensating control aligns residual risk with the organisation's very low security risk appetite.

Why this answer

Implementing a web application firewall (WAF) with virtual patching provides an immediate, compensating control that reduces the exploitability of the vulnerability without requiring application downtime. This aligns with the organization's low risk appetite by actively mitigating the risk while waiting for an official vendor patch, rather than passively accepting it.

Exam trap

The trap here is that candidates may confuse risk transfer (insurance) with risk mitigation, or assume that accepting risk is always valid when the risk owner agrees, ignoring the organization's stated risk appetite.

How to eliminate wrong answers

Option A is wrong because purchasing cyber insurance transfers financial risk, not technical risk; the vulnerability remains exploitable, and insurance does not prevent a breach or reduce the likelihood of exploitation. Option B is wrong because decommissioning the application immediately would cause unacceptable business downtime, contradicting the requirement that the application is business-critical with no acceptable downtime. Option D is wrong because accepting the risk while monitoring for patches violates the organization's very low risk appetite for security vulnerabilities; passive acceptance without active mitigation is not appropriate when the risk appetite is low.

373
MCQmedium

During a risk assessment for a cloud migration project, the risk team identifies that the new SaaS application has not been tested for interoperability with existing identity management systems. The project manager argues that the integration will be straightforward and asks to remove this from the risk register. Which of the following is the BEST response from the risk practitioner?

A.Remove the risk as it is low priority.
B.Keep the risk in the register with a note that further assessment is needed.
C.Accept the risk but document the decision.
D.Escalate to the project steering committee.
AnswerB

Keeping the risk in the register preserves visibility of an unassessed interoperability exposure until evidence exists, satisfying the requirement that unidentified integration failures remain tracked. Removing it on the project manager's assumption would eliminate the risk before any testing against Microsoft Entra ID confirms compatibility, leaving the residual impact unmanaged.

Why this answer

An untested integration with identity management is a legitimate risk that has not been assessed or quantified, so it must remain in the register with a note that further assessment is required. Removing it based on the project manager's assumption would bypass the risk process and eliminate visibility. The risk practitioner's role is to preserve the risk until evidence supports a formal decision.

Exam trap

CRISC often tests the misconception that a stakeholder's assurance ('it'll be straightforward') justifies removing a risk — the trap is treating opinion as assessment.

How to eliminate wrong answers

Option A is wrong because the risk has not been evaluated — calling it low priority before assessment is unsupported and removes it from governance. Option C is wrong because risk acceptance requires informed decision-making by the appropriate owner after assessment, and no assessment has occurred yet. Option D is wrong because escalation to the steering committee is premature; the immediate correct action is to keep and further assess the risk, not escalate an unquantified item.

374
Multi-Selectmedium

During a third-party risk management review, the organization is tiering its vendors based on risk. Which TWO of the following criteria are most relevant for determining vendor risk tier?

Select 2 answers
A.Criticality of service provided
B.Number of vendor employees
C.Level of data access the vendor has
D.Annual contract value
E.Vendor geographic location
AnswersA, C

Vendor risk tiering hinges on how severely a failure would disrupt the organization, so criticality of the service provided directly drives impact scoring. A vendor supporting a core revenue or safety function warrants a higher tier and deeper due diligence than one supplying peripheral services.

Why this answer

The criticality of the service provided (A) directly determines the potential business impact if the vendor fails, making it a primary factor in risk tiering. Similarly, the level of data access (C) dictates the confidentiality and privacy risks, as vendors handling sensitive or regulated data (e.g., PII, PHI) pose higher inherent risk. Both criteria align with the ISACA risk management framework, which prioritizes impact and data sensitivity over financial or operational metrics.

Exam trap

ISACA often tests the misconception that financial metrics like contract value or vendor size directly correlate with risk, but the CRISC exam emphasizes that risk is driven by data sensitivity and business impact, not cost or scale.

375
MCQeasy

During a risk assessment, a risk owner is unsure about the likelihood rating for a specific threat. Which of the following is the BEST source of information to determine the likelihood?

A.Vendor documentation
B.The risk owner's personal opinion
C.The organization's financial statements
D.Historical incident data from industry reports
AnswerD

Historical incident data from industry reports provides empirical frequency evidence across comparable organisations, giving the risk owner an objective basis for estimating likelihood. Internal opinion or single-source estimates lack that statistical grounding, making external incident history the most reliable input for the rating.

Why this answer

Historical incident data from industry reports provides empirical evidence of threat frequency and impact across similar environments, making it the most objective and reliable source for determining likelihood. Unlike subjective opinions or unrelated financial data, industry reports aggregate real-world occurrences, enabling a data-driven risk assessment that aligns with the organization's threat landscape.

Exam trap

ISACA often tests the misconception that the risk owner's personal experience or vendor claims are sufficient for likelihood determination, but the correct approach relies on objective, historical data from industry sources to avoid bias and ensure repeatable risk scoring.

How to eliminate wrong answers

Option A is wrong because vendor documentation typically focuses on product capabilities, configurations, and known vulnerabilities, not on the frequency or probability of threat events in operational environments. Option B is wrong because the risk owner's personal opinion introduces subjective bias and lacks empirical evidence, which can lead to inaccurate likelihood ratings that do not reflect actual threat patterns. Option C is wrong because the organization's financial statements contain monetary data about assets and losses, but they do not provide historical frequency or probability metrics needed to assess threat likelihood.

Page 4

Page 5 of 15

Page 6