Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 376–450

1062 questions total · 15pages · All types, answers revealed

Page 5

Page 6 of 15

Page 7
376
MCQmedium

A company is implementing a new cloud-based customer relationship management (CRM) system. The IT risk manager needs to assess the risk of data exfiltration by a malicious insider at the cloud provider. Which risk assessment approach is most appropriate for this scenario?

A.Quantitative risk assessment using ALE and SLE
B.Application of the COSO ERM framework
C.Scenario analysis with a focus on likelihood and impact
D.Control self-assessment (CSA) against ISO 27001
AnswerC

Scenario analysis directly models the malicious-insider threat at the cloud provider, assessing how plausible exfiltration is and the resulting business impact. It satisfies the stem's requirement to evaluate a specific, low-frequency, high-consequence risk that quantitative historical data cannot reliably support, unlike generic control checklists or compliance audits.

Why this answer

Scenario analysis is most appropriate because the risk of data exfiltration by a malicious insider at the cloud provider is a complex, low-frequency, high-impact threat that is difficult to quantify with historical data. This approach allows the risk manager to systematically evaluate specific attack paths (e.g., an insider with database access copying customer records) by focusing on likelihood and impact, which aligns with the qualitative nature of insider threat assessment in a cloud environment.

Exam trap

The trap here is that candidates often choose quantitative risk assessment (A) because it seems more rigorous, but they fail to recognize that insider threats at a cloud provider lack the historical data needed for ALE/SLE calculations, making scenario analysis the practical and most appropriate approach per CRISC best practices.

How to eliminate wrong answers

Option A is wrong because quantitative risk assessment using ALE and SLE requires reliable historical data on frequency and loss magnitude, which is typically unavailable for malicious insider threats at a cloud provider due to the rarity and variability of such events. Option B is wrong because the COSO ERM framework is an enterprise-level governance and internal control framework, not a specific risk assessment methodology for analyzing a discrete technical threat like data exfiltration by a cloud provider insider. Option D is wrong because control self-assessment (CSA) against ISO 27001 evaluates the effectiveness of existing controls against a standard, but it does not directly assess the likelihood and impact of a specific threat scenario like malicious insider data exfiltration.

377
MCQhard

A power utility company is required to comply with NERC CIP standards. The risk manager is assessing the impact of connecting a remote substation's OT network to the corporate WAN. Which of the following is the MOST significant risk that must be addressed to comply with NERC CIP?

A.Violation of electronic security perimeter (ESP) requirements
B.Latency issues affecting real-time control
C.Increased bandwidth costs for WAN connectivity
D.Incompatibility with legacy serial protocols
AnswerA

Connecting OT to the corporate WAN crosses an electronic security perimeter, so NERC CIP ESP controls—firewalls, access control, monitoring at every boundary—are directly triggered. This is the most significant compliance risk because unsecured routable paths between trusted and untrusted networks breach the standard's core requirement.

Why this answer

The [CORRECT] answer is A. NERC CIP standards (specifically CIP-005) mandate the establishment and protection of Electronic Security Perimeters (ESPs) around critical cyber assets. Connecting a remote substation's OT network to the corporate WAN inherently crosses an ESP boundary, requiring strict controls such as firewalls, access control lists, and monitored electronic access points.

Failure to properly define and secure the ESP is a direct compliance violation and the most significant risk because it exposes critical infrastructure to cyber threats.

Exam trap

The trap is selecting an operational or financial concern (latency, bandwidth, legacy protocols) over the regulatory compliance requirement; candidates must remember that NERC CIP is about security controls, and ESP is the foundational control for network connections.

How to eliminate wrong answers

Option B is wrong because latency, while a legitimate operational concern for real-time control, is not a NERC CIP compliance requirement—CIP focuses on security, not performance. Option C is wrong because bandwidth cost is a business/financial consideration, not a regulatory compliance risk under NERC CIP. Option D is wrong because legacy serial protocol incompatibility is a technical integration challenge, not a NERC CIP compliance risk; CIP does not mandate protocol modernization, though it does require protection of those communications.

378
MCQmedium

A risk practitioner is analyzing the risk of insider threat in a software development company. The practitioner wants to assess the likelihood of a developer exfiltrating source code. Which of the following factors would MOST directly increase the likelihood of this risk?

A.The developer has elevated access privileges to the source code repository.
B.The company's security awareness training is conducted annually.
C.The company has a high turnover rate among developers.
D.The source code repository is hosted in a third-party cloud environment.
AnswerA

Elevated access privileges directly increase the opportunity for a developer to exfiltrate source code. Even if motivation exists, without access the threat cannot be realized. In insider threat analysis, opportunity is a key likelihood factor, and privileged access is a common enabler. This makes it the most direct factor increasing likelihood in this scenario.

Why this answer

The likelihood of an insider threat depends on motivation, opportunity, and capability. Elevated access privileges provide the opportunity for a developer to exfiltrate source code, making it the most direct factor increasing likelihood. Other factors like turnover or training frequency may influence the environment but do not directly enable the theft.

Access control is therefore a critical control point.

Exam trap

The trap here is selecting indirect organizational factors, such as turnover or training frequency, instead of the direct enabler of opportunity that privileged access provides.

379
MCQeasy

Which of the following is the BEST indicator that a control is effective in mitigating a risk?

A.Regular testing shows the control consistently reduces the risk to the desired level
B.The control is automated and runs daily
C.The control is documented in a policy
D.The cost of the control is lower than the potential loss
AnswerA

Consistent risk reduction to the desired level, verified through regular testing, demonstrates the control operates as intended against the specific risk. This evidence-based outcome is stronger than design documentation or one-off assessments, confirming sustained mitigation effectiveness.

Why this answer

The effectiveness of a control is ultimately measured by its ability to consistently reduce residual risk to the organization's defined risk appetite. Regular testing provides empirical evidence that the control is operating as intended and achieving the desired risk mitigation outcome, which is the primary goal of risk treatment.

Exam trap

The trap here is that candidates often confuse control attributes (automation, documentation, cost) with direct evidence of effectiveness, but only regular testing provides the empirical proof that the control is actually reducing risk to the desired level.

How to eliminate wrong answers

Option B is wrong because automation and frequency of execution do not guarantee that the control is actually reducing risk to the desired level; a control can run daily but still be misconfigured or ineffective. Option C is wrong because documentation in a policy only indicates intent or design, not operational effectiveness; a control may be well-documented yet never implemented or poorly executed. Option D is wrong because cost-benefit analysis (cost of control vs. potential loss) is a factor in control selection and justification, not a direct measure of its effectiveness in mitigating risk; a low-cost control can still be ineffective.

380
MCQhard

A power utility must comply with NERC CIP standards. Which of the following is a key requirement under these standards?

A.Implementing IEC 62443 for all control systems
B.Identifying and securing Critical Cyber Assets (CCAs)
C.Deploying AI for threat detection
D.Using only air-gapped networks
AnswerB

NERC CIP requires utilities to identify and protect Critical Cyber Assets supporting the bulk electric system, forming the basis for subsequent controls. This directly satisfies the standard's core obligation to catalogue and secure assets whose compromise could disrupt reliable power delivery.

Why this answer

NERC CIP (Critical Infrastructure Protection) standards require utilities to identify and protect Critical Cyber Assets (CCAs) — later evolved into BES Cyber Systems — that support the reliable operation of the Bulk Electric System. Identification, categorization, and implementation of security controls for these assets is a foundational requirement across the CIP standards (CIP-002 through CIP-014).

Exam trap

The trap is selecting a well-known OT standard (IEC 62443) or a trendy technology (AI) as a NERC CIP requirement — candidates must recognize that NERC CIP is a prescriptive, region-specific regulatory framework with its own defined controls.

How to eliminate wrong answers

Option A is wrong because IEC 62443 is an ISA/IEC industrial cybersecurity standard used broadly in OT environments, but it is not a NERC CIP requirement — NERC CIP has its own control framework. Option C is wrong because deploying AI for threat detection is not mandated by NERC CIP; the standards are prescriptive about controls, not specific technologies. Option D is wrong because NERC CIP does not require air-gapped networks — it mandates Electronic Security Perimeters, access controls, and monitoring, which can be met without full air-gapping.

381
MCQmedium

A risk analyst is reviewing the organization's identity and access management (IAM) processes after a recent audit finding. The finding states that terminated employees retained active directory accounts for up to 30 days. Which control should the analyst recommend to BEST address this risk?

A.Require managers to submit a ticket to the IT help desk within 24 hours of an employee's termination.
B.Enforce mandatory password changes every 30 days for all employees, including terminated ones.
C.Conduct quarterly access reviews to identify and disable accounts of terminated employees.
D.Implement automated deprovisioning integrated with the HR system to disable accounts immediately upon termination.
AnswerD

Automated deprovisioning tied to the HR system ensures that account disablement occurs as soon as a termination is recorded, eliminating the 30-day window. This directly addresses the audit finding by reducing the risk of unauthorized access by former employees. It is a preventive control that is both efficient and auditable, and it aligns with least privilege and timely access revocation principles.

Why this answer

The audit finding highlights a delay between termination and account disablement, creating a window for unauthorized access. An automated deprovisioning process integrated with the HR system is the most effective preventive control because it removes human latency and ensures accounts are disabled immediately upon termination. Manual tickets and periodic reviews are detective or delayed, and password expiration does not deactivate accounts.

Exam trap

The trap here is choosing a manual or detective control, such as a help desk ticket or quarterly review, when the finding demands immediate, automated revocation.

382
Multi-Selecthard

An organization is deploying IoT devices for environmental monitoring in a manufacturing facility. Which THREE of the following are significant security risks that should be addressed? (Select THREE.)

Select 3 answers
A.Expanded attack surface due to numerous connected devices
B.Vendor lock-in due to proprietary protocols
C.Lack of firmware update capabilities for security patches
D.Data sovereignty issues for sensor data
E.Use of legacy components with known vulnerabilities
AnswersA, C, E

Each connected IoT device adds a potential entry point, so the sheer number of endpoints materially widens the attack surface an adversary can probe. This directly satisfies the scenario's environmental-monitoring deployment, where many low-power sensors often lack hardening, patching or monitoring, multiplying exploitable weaknesses.

Why this answer

Option A is correct because deploying many IoT sensors multiplies entry points (each device's network services, management interfaces, and APIs), greatly expanding the attack surface an adversary can probe or exploit. Option C is correct because IoT devices without a secure firmware update mechanism cannot receive patches for newly disclosed CVEs, leaving them permanently vulnerable to exploitation. Option E is correct because legacy components often run outdated firmware or unsupported OS/protocol stacks with publicly known vulnerabilities that attackers can leverage.

Option B is not a direct security risk but a business/procurement concern, and Option D concerns legal/regulatory data residency rather than a technical security vulnerability.

Exam trap

CRISC often tests the distinction between security risks and non-security concerns such as vendor lock-in or data sovereignty; candidates who select B or D confuse business/compliance issues with technical security exposure.

383
MCQmedium

An access control policy includes a default deny rule (DenyAll) and an explicit allow rule. During a monitoring review, the risk practitioner notices that the DenyAll rule is never evaluated because the explicit allow matches first. What is the MOST likely monitoring gap?

A.No KRI is defined for unauthorized access attempts
B.Server-side encryption is not enabled
C.No automated test validates that the DenyAll policy is effective
D.User access reviews are not performed quarterly
AnswerC

Without automated testing, the effectiveness of the DenyAll policy is not verified, leaving a monitoring gap.

Why this answer

The default deny rule is overridden by the explicit allow rule, making the deny ineffective. Without an automated test to validate that the deny rule is actually enforced, the monitoring gap is that the control is assumed to work but is not verified. This is a classic control monitoring failure where the existence of a policy is confused with its effectiveness.

Exam trap

The trap is that candidates assume a deny-all rule is always effective because it is present, but they overlook that policy evaluation order and first-match semantics can cause an allow rule to be evaluated first, making the deny-all rule inert unless its effectiveness is validated through testing.

How to eliminate wrong answers

Option A is wrong because the question focuses on a policy evaluation order issue, not on the absence of a KRI for unauthorized access; even if a KRI existed, it would not detect the policy misconfiguration. Option B is wrong because server-side encryption is a separate data-at-rest control unrelated to the IAM policy evaluation logic that causes the DenyAll to be skipped. Option D is wrong because user access reviews address who has permissions, not whether a specific deny statement is being bypassed due to evaluation order.

384
MCQhard

An organization is implementing continuous monitoring of its network using SIEM rules. Which of the following is the PRIMARY benefit of this approach over periodic manual testing?

A.Reduces the need for security staff
B.Is less expensive than periodic testing
C.Eliminates all false positives
D.Provides real-time detection of security events
AnswerD

SIEM rules correlate log and event data continuously, alerting as activity occurs rather than at scheduled test intervals. This satisfies the stem's continuous monitoring requirement by shrinking detection latency, so threats are identified in real time instead of after periodic manual testing.

Why this answer

Continuous monitoring via SIEM rules provides real-time detection of security events, enabling immediate identification and response to threats as they occur. This is the primary benefit over periodic manual testing, which only identifies issues at discrete intervals and cannot catch events that happen between tests.

Exam trap

The trap here is that candidates may confuse 'continuous monitoring' with 'automated response' or assume it reduces staffing needs, but the CRISC exam emphasizes that the primary benefit is real-time detection, not cost savings or elimination of human oversight.

How to eliminate wrong answers

Option A is wrong because continuous monitoring does not eliminate the need for security staff; it augments their capabilities but still requires analysts to investigate alerts, tune rules, and respond to incidents. Option B is wrong because continuous monitoring often involves higher upfront and ongoing costs for SIEM infrastructure, licensing, and staffing compared to periodic manual testing. Option C is wrong because SIEM rules can produce false positives due to misconfigurations, noisy data sources, or overly broad rule logic; they do not eliminate all false positives.

385
MCQhard

An organization is evaluating threat intelligence feeds to improve IT risk identification. Which of the following criteria should be given the HIGHEST priority when selecting a feed?

A.Relevance to the organization's industry and technology stack
B.Ease of integration with existing security tools
C.The feed's update frequency
D.The number of indicators provided per day
AnswerA

Relevance to the organisation's industry and technology stack ensures the feed addresses threats and vulnerabilities actually applicable to its environment, maximising risk identification value. Feeds lacking this alignment waste resources on irrelevant indicators, so relevance outranks cost, volume or format.

Why this answer

Relevance to the organization's industry and technology stack is the highest priority because threat intelligence that does not align with the specific attack surface, software versions, and threat actors targeting that industry will generate excessive false positives and irrelevant alerts. For example, a healthcare organization using Epic EHR would prioritize feeds covering healthcare-specific ransomware (e.g., Ryuk) and medical device vulnerabilities over generic indicators, ensuring risk identification is actionable and contextually accurate.

Exam trap

The trap here is that candidates prioritize operational metrics like integration ease or update frequency over the strategic requirement of contextual relevance, confusing efficiency with effectiveness in risk identification.

How to eliminate wrong answers

Option B is wrong because ease of integration, while operationally convenient, does not address the core requirement of improving risk identification; a feed that integrates easily but provides irrelevant data will not reduce risk. Option C is wrong because update frequency alone is meaningless if the indicators are not relevant; a feed updated every 5 minutes with generic IPs from unrelated sectors adds noise and degrades detection fidelity. Option D is wrong because the number of indicators per day is a vanity metric; high volume often includes low-quality or outdated indicators (e.g., stale C2 IPs) that increase false positives without improving risk identification accuracy.

386
Drag & Dropmedium

Order the steps for implementing a risk treatment plan.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk treatment starts with selecting response, planning, approval, implementation, and monitoring.

387
MCQmedium

An organization is developing an IT risk universe. Which of the following is the PRIMARY purpose of creating a comprehensive IT risk universe?

A.To ensure all potential IT risks are considered and documented
B.To prioritize risks based on their financial impact
C.To assign risk owners to each identified risk
D.To calculate the aggregated risk exposure for the organization
AnswerA

A comprehensive IT risk universe ensures no material risk is omitted from scoping, so every potential IT risk is identified and documented before assessment. This completeness underpins later risk evaluation, appetite setting and treatment, preventing blind spots that would otherwise distort the organisation's overall IT risk profile.

Why this answer

The IT risk universe is a comprehensive inventory of all plausible IT-related risks an organization faces, organized by category (e.g., infrastructure, applications, data, third parties, people). Its primary purpose is to ensure completeness — that all potential IT risks are considered and documented — so that subsequent risk assessment, prioritization, and treatment are built on a complete foundation. Without completeness, later steps may overlook material risks.

Exam trap

CRISC often tests the sequence of risk management activities — candidates confuse the purpose of the risk universe (completeness of identification) with downstream activities like prioritization, ownership assignment, or exposure aggregation.

How to eliminate wrong answers

Option B is wrong because prioritizing risks by financial impact is a subsequent step performed after the risk universe is populated; prioritization is not the purpose of creating the universe. Option C is wrong because assigning risk owners is a downstream governance activity that occurs once risks are identified and assessed, not the reason for building the universe. Option D is wrong because calculating aggregated risk exposure is an analytical output that depends on the universe existing first; it is a use of the universe, not its primary purpose.

388
MCQmedium

A company has identified a risk of data exfiltration through an outdated encryption protocol. The risk assessment team determines that the likelihood is low, but the impact is very high. The company decides to update the encryption protocol. This risk response is an example of:

A.Risk transfer
B.Risk acceptance
C.Risk mitigation
D.Risk avoidance
AnswerC

Updating the encryption protocol directly reduces the vulnerability that enables exfiltration, satisfying the high-impact constraint while accepting the low likelihood. This is risk mitigation: treating the risk by applying controls to lower impact or likelihood, rather than avoiding, transferring or accepting it.

Why this answer

Updating the encryption protocol directly reduces the vulnerability that could lead to data exfiltration, thereby lowering the likelihood or impact of the risk. This is the definition of risk mitigation, where controls are applied to reduce risk to an acceptable level. The action does not transfer, accept, or avoid the risk; it actively addresses the root cause.

Exam trap

The trap here is confusing risk mitigation with risk avoidance: candidates often think that updating a protocol 'avoids' the risk, but avoidance requires ceasing the risky activity entirely, whereas mitigation reduces the risk while continuing the activity.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial burden of a loss to a third party (e.g., cyber insurance or outsourcing), not updating a technical control like an encryption protocol. Option B is wrong because risk acceptance means formally acknowledging the risk and choosing to take no action, which contradicts the decision to update the protocol. Option D is wrong because risk avoidance would mean eliminating the activity that introduces the risk (e.g., discontinuing the use of the system or data transmission entirely), not updating the encryption to make it secure.

389
MCQeasy

An organization is performing a risk assessment for its new customer relationship management (CRM) system. Which of the following is the BEST way to identify threats to the CRM?

A.Perform a vulnerability scan on the CRM server.
B.Conduct a threat modeling workshop with the development team.
C.Run a penetration test against the CRM application.
D.Review the business impact analysis for the CRM.
AnswerB

Threat modelling workshops systematically enumerate threat sources and attack paths against the CRM's architecture, data flows and trust boundaries. This satisfies the stem's need to identify threats, whereas vulnerability scanning or control testing only detects existing weaknesses after threats are already known.

Why this answer

Threat modeling is a proactive, structured approach that identifies potential threats by analyzing the CRM's design, data flows, and trust boundaries. Unlike vulnerability scanning or penetration testing, which find existing weaknesses, threat modeling uncovers threats early in the lifecycle, such as SQL injection via customer input fields or privilege escalation in role-based access controls. This aligns with the CRISC focus on risk identification before controls are implemented.

Exam trap

ISACA often tests the distinction between threat identification (proactive, design-focused) and vulnerability assessment (reactive, implementation-focused), leading candidates to choose a technical test like a penetration test over a collaborative workshop.

How to eliminate wrong answers

Option A is wrong because a vulnerability scan only identifies known technical weaknesses (e.g., missing patches, misconfigurations) on the CRM server, not the broader set of threats like business logic flaws, insider threats, or data leakage through API endpoints. Option C is wrong because penetration testing validates exploitability of existing vulnerabilities but is a reactive, point-in-time test that misses threats not yet present in the code or configuration. Option D is wrong because a business impact analysis (BIA) assesses the consequences of disruption (e.g., financial loss, reputational damage) but does not identify specific threat sources or threat events targeting the CRM.

390
MCQeasy

A vulnerability scan of the internal network reveals a critical vulnerability in a legacy application that cannot be patched immediately. What is the FIRST step the risk practitioner should take?

A.Document the vulnerability and assess the associated risk in the risk register
B.Apply a virtual patch via an intrusion prevention system
C.Isolate the application from the network
D.Notify the application owner and request an emergency patch
AnswerA

Documenting the vulnerability and assessing its risk in the risk register satisfies the immediate need to evaluate likelihood and impact against existing controls, given the constraint that patching is impossible. This establishes a traceable risk record, enabling prioritised treatment decisions such as compensating controls, rather than premature remediation or acceptance.

Why this answer

The first step is to document the vulnerability and assess the associated risk in the risk register because risk identification and assessment must precede any remediation decision. Without a formal risk assessment, the practitioner cannot determine whether compensating controls (like a virtual patch or isolation) are appropriate or whether the residual risk is acceptable to the business. This aligns with the CRISC framework's emphasis on risk-based decision-making before implementing technical controls.

Exam trap

The trap here is that candidates often jump to a technical control (like applying a virtual patch or isolating the application) because it seems immediate and effective, but the CRISC exam consistently tests that risk assessment and documentation must come first before any control implementation.

How to eliminate wrong answers

Option B is wrong because applying a virtual patch via an intrusion prevention system (IPS) is a compensating control that should only be selected after the risk has been assessed and documented; jumping to a technical fix without risk evaluation bypasses the risk management process. Option C is wrong because isolating the application from the network is a drastic technical control that may disrupt business operations and should be considered only after the risk assessment determines that the vulnerability's impact exceeds the organization's risk appetite. Option D is wrong because notifying the application owner and requesting an emergency patch is a reactive step that assumes a patch is feasible, but the scenario explicitly states the application cannot be patched immediately, making this action premature and potentially futile without first assessing the risk.

391
MCQeasy

Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA) during the IT risk assessment process?

A.To determine the criticality and recovery time objectives of business processes
B.To identify vulnerabilities in IT systems
C.To identify potential threat actors
D.To inventory all IT assets
AnswerA

A BIA identifies which business processes are most critical and how quickly each must resume after disruption, producing recovery time objectives that then drive IT risk prioritisation. This directly satisfies the stem's requirement to establish criticality and RTOs, which no other risk assessment activity delivers.

Why this answer

The primary purpose of a business impact analysis (BIA) is to identify critical business processes, determine their recovery priorities, and establish recovery time objectives (RTOs) and recovery point objectives (RPOs). Option B is incorrect because identifying vulnerabilities is part of a vulnerability assessment, not a BIA. Option C is incorrect because identifying potential threat actors is part of threat modeling.

Option D is incorrect because inventorying IT assets is part of asset management, not the primary goal of a BIA.

392
Multi-Selectmedium

Which TWO of the following are examples of risk avoidance?

Select 2 answers
A.Implementing a firewall
B.Purchasing cyber insurance
C.Accepting the risk
D.Migrating to a different technology platform
E.Discontinuing a high-risk business process
AnswersD, E

Migrating to a different technology platform eliminates the exposure entirely by removing the vulnerable or high-risk technology from the environment, rather than mitigating, transferring or accepting it. This makes it a genuine example of risk avoidance, as the risk source ceases to exist.

Why this answer

Risk avoidance means eliminating the activity or exposure that creates the risk entirely, rather than mitigating, transferring, or accepting it. Option D (Migrating to a different technology platform) is correct because replacing a vulnerable or risky platform removes the exposure associated with the original technology, thereby avoiding the risk rather than merely reducing it. Option E (Discontinuing a high-risk business process) is correct because ceasing the process altogether eliminates the risk source, which is the defining characteristic of risk avoidance.

Option A (Implementing a firewall) is incorrect because a firewall is a risk mitigation control that reduces likelihood or impact while the underlying activity continues. Option B (Purchasing cyber insurance) is incorrect because it transfers financial risk to an insurer, not avoids it. Option C (Accepting the risk) is incorrect because acceptance means retaining the risk with no action to eliminate it, which is the opposite of avoidance.

Exam trap

The trap here is that candidates confuse risk mitigation (e.g., implementing controls like firewalls) with risk avoidance, failing to recognize that avoidance requires completely eliminating the risk source, not just reducing it.

393
MCQmedium

A risk manager decides to accept a risk because the cost of controls exceeds the potential loss. Which of the following is required for this risk treatment option?

A.Elimination of the business process
B.Transfer of risk via insurance
C.Implementation of compensating controls
D.Formal sign-off by the risk owner
AnswerD

Risk acceptance demands documented accountability, so formal sign-off by the risk owner satisfies the stem's requirement. The owner holds authority over the affected asset and bears residual loss, making their approval the control that legitimises accepting the risk rather than treating it. Without that signature, acceptance is unowned and unenforceable.

Why this answer

When a risk manager decides to accept a risk because the cost of controls exceeds the potential loss, the risk treatment option is risk acceptance. This requires formal acknowledgment and sign-off by the risk owner, who is accountable for the risk and must document the decision, typically in a risk register, to ensure governance and auditability.

Exam trap

The trap here is that candidates confuse risk acceptance with risk mitigation or transfer, assuming that any decision involving cost analysis must lead to controls or insurance, but the question explicitly states the cost of controls exceeds the potential loss, making formal acceptance the correct treatment option.

How to eliminate wrong answers

Option A is wrong because elimination of the business process is a risk avoidance strategy, not acceptance; it would remove the risk entirely by discontinuing the activity, which is a different treatment option. Option B is wrong because transfer of risk via insurance shifts the financial impact to a third party, but the question specifies acceptance due to cost-benefit analysis, not transfer. Option C is wrong because implementation of compensating controls is a risk mitigation strategy that reduces risk to an acceptable level, whereas acceptance involves no additional controls and relies on the existing risk level being tolerated.

394
Multi-Selectmedium

A risk practitioner is assessing the security of the organization's software development lifecycle (SDLC). The organization wants to integrate security controls to reduce the risk of introducing vulnerabilities into production. Which TWO of the following are the MOST effective preventive controls to implement during the development phase? (Choose two.)

Select 2 answers
A.Conduct static application security testing (SAST) on source code before code is merged into the main branch.
B.Require developers to complete secure coding training and adhere to a secure coding standard.
C.Implement a web application firewall (WAF) in front of the production application to block malicious traffic.
D.Perform dynamic application security testing (DAST) on applications in the production environment after deployment.
E.Conduct a penetration test on the application after it is deployed to production.
AnswersA, B

SAST analyzes source code for security flaws without executing the program, allowing developers to identify and fix vulnerabilities early in the development phase. Integrating SAST into the CI/CD pipeline before merge ensures that insecure code does not progress to later stages. This is a preventive control that reduces the cost and effort of remediation compared to finding issues in production.

Why this answer

The most effective preventive controls during development are those that stop vulnerabilities from being introduced in the first place. Static application security testing (SAST) analyzes code before it is merged, catching flaws early. Secure coding training and standards give developers the skills to write safer code.

Both are proactive measures integrated into the development phase, unlike DAST, WAF, or penetration testing, which are detective or perimeter controls applied later.

Exam trap

The trap here is confusing detective controls like DAST or penetration testing with preventive controls that belong earlier in the development lifecycle.

395
MCQeasy

You are the risk manager at a financial institution that processes online transactions. The organization relies on a legacy system for transaction authorization, which is monitored via manual log reviews performed weekly by a junior analyst. Recently, the internal audit team identified that several unauthorized transactions were not detected for over two weeks. The logs showed that the authorization control failed intermittently due to a known software bug, but the bug had been documented in the risk register with a low residual risk rating. The CRO asks you to recommend the most effective improvement to the control monitoring process. Which of the following would be the BEST course of action?

A.Implement an automated real-time monitoring tool that alerts on authorization failures.
B.Increase the frequency of log reviews to daily.
C.Update the risk register to increase the residual risk rating for the bug.
D.Retrain the junior analyst on log analysis techniques.
AnswerA

Automated real-time monitoring replaces weekly manual log reviews, detecting intermittent authorization failures immediately rather than after two weeks. This directly addresses the control-monitoring weakness and corrects the understated low residual risk rating in the register.

Why this answer

Implementing an automated real-time monitoring tool that alerts on authorization failures directly addresses the root cause: the detection delay caused by manual weekly log reviews. Unlike manual reviews, automated monitoring provides immediate notification of control failures, enabling rapid response to intermittent software bugs and reducing the window of exposure for unauthorized transactions.

Exam trap

The trap here is that candidates often choose to increase review frequency (Option B) because it seems like a direct improvement, but they fail to recognize that manual reviews, regardless of frequency, still suffer from human delay and cannot match the immediacy of automated monitoring for intermittent control failures.

How to eliminate wrong answers

Option B is wrong because increasing log review frequency to daily still relies on manual analysis, which introduces human latency and potential oversight; it does not eliminate the detection gap for intermittent failures that occur between reviews. Option C is wrong because updating the risk register to increase the residual risk rating is a documentation change that does not improve the actual monitoring or detection capability; it merely acknowledges the problem without fixing it. Option D is wrong because retraining the junior analyst on log analysis techniques does not address the fundamental issue of manual review latency and the inability to detect failures in near real-time; even a highly skilled analyst cannot overcome the delay inherent in periodic manual checks.

396
MCQhard

A risk practitioner is using the Delphi technique to estimate the likelihood of a sophisticated ransomware attack against a hospital network. The first round of expert opinions produced widely divergent estimates. Which of the following is the MOST appropriate next step in the Delphi process?

A.Replace the expert panel with a quantitative Monte Carlo simulation to model the ransomware likelihood.
B.Provide a statistical summary of the first-round estimates to the experts and ask them to revise their estimates in a second anonymous round.
C.Discard the highest and lowest estimates and average the remaining responses to produce a single likelihood value.
D.Convene a face-to-face meeting where experts debate their estimates until a unanimous consensus is reached.
AnswerB

The Delphi method involves iterative rounds where experts receive anonymized feedback, such as the median and interquartile range, and then revise their estimates. This controlled feedback helps converge toward consensus without direct confrontation. In this scenario, the divergent first-round estimates should be summarized and returned to the experts for a second round. This is the standard next step in the Delphi process.

Why this answer

The Delphi technique is an iterative, anonymous expert elicitation method. After the first round, the facilitator provides a statistical summary of the responses, such as the median and range, to the experts. The experts then revise their estimates in a second anonymous round.

This process repeats until consensus or stability is achieved. Providing feedback and allowing revision is the defining characteristic of Delphi, making the second anonymous round the correct next step.

Exam trap

The trap here is thinking that averaging or face-to-face debate is part of Delphi, when in fact anonymity and iterative feedback are essential.

397
Multi-Selecteasy

In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?

Select 2 answers
A.Likelihood
B.Impact
C.Risk appetite
D.Cost of mitigation
E.Control effectiveness
AnswersA, B

Likelihood is one of the two axes in a qualitative risk assessment, paired with impact, to derive the overall risk rating. It expresses the probability that a given threat will exploit a vulnerability, directly satisfying the stem's requirement for the elements used to determine that rating.

Why this answer

In a qualitative risk assessment, risk rating is determined by combining the likelihood of a threat occurring with the impact of that threat on business objectives. Likelihood (A) and impact (B) are the two fundamental elements used in a risk matrix to assign a qualitative rating such as high, medium, or low. This approach relies on subjective judgment rather than numerical data, making it suitable for scenarios where precise quantification is not feasible.

Exam trap

The trap here is that candidates often confuse the inputs for inherent risk rating (likelihood and impact) with factors used in residual risk calculation or risk treatment decisions, such as control effectiveness or cost of mitigation.

398
Multi-Selectmedium

A risk practitioner is facilitating a risk assessment workshop for a new cloud-based HR system. The team is identifying threats. Which TWO of the following are examples of threat events that should be considered? (Choose two.)

Select 2 answers
A.An unpatched web server software vulnerability
B.A natural disaster causing a cloud data center outage
C.A malicious insider exfiltrating employee personal data
D.Lack of encryption for data at rest
E.Inadequate security awareness training for employees
AnswersB, C

A natural disaster causing a data center outage is a threat event. It can lead to loss of availability of the HR system. Even though the cloud provider may have controls, the organization should consider this threat as part of its risk assessment, especially for critical systems. It is an external event with potential business impact.

Why this answer

Threat events are occurrences or actions that can cause harm, such as a malicious insider exfiltrating data or a natural disaster causing an outage. Vulnerabilities like unpatched software, lack of encryption, or inadequate training are conditions that threats may exploit. Distinguishing between threats and vulnerabilities is essential for accurate risk scenarios.

Exam trap

The trap here is listing vulnerabilities as threats, which confuses the two and leads to incomplete risk scenarios.

399
MCQmedium

During a risk assessment, an organization identifies that its primary data center is located in a flood-prone area. Which risk treatment option would best address this risk?

A.Purchase business interruption insurance
B.Move all operations to a cloud provider
C.Implement flood barriers and redundant cooling systems
D.Accept the risk and document it in the risk register
AnswerC

Flood barriers directly mitigate the flood threat at the data centre, while redundant cooling systems address the consequential overheating risk. Together they reduce likelihood and impact without relocating operations, satisfying the risk treatment requirement within the existing facility constraint.

Why this answer

Implementing flood barriers and redundant cooling systems directly reduces the likelihood and impact of a flood event on the data center's physical infrastructure. This is a risk mitigation strategy that proactively addresses the root cause of the risk (flooding) by hardening the facility, which is the most effective treatment for a high-probability, high-impact physical threat.

Exam trap

The trap here is that candidates often confuse risk transfer (insurance) with risk mitigation, failing to recognize that insurance does not prevent operational downtime or data loss, whereas physical controls directly reduce the risk's likelihood and impact.

How to eliminate wrong answers

Option A is wrong because purchasing business interruption insurance is a risk transfer strategy that only compensates for financial loss after an incident, but does not reduce the probability or impact of the flood itself; it leaves the organization's operations vulnerable to downtime. Option B is wrong because moving all operations to a cloud provider is a risk avoidance strategy that may be overly drastic and costly, and it does not address the underlying risk assessment of the existing data center; it also introduces new risks such as vendor lock-in and data sovereignty issues. Option D is wrong because accepting the risk without any active controls is inappropriate for a flood-prone location with high potential for catastrophic damage; risk acceptance is typically reserved for low-impact or low-probability risks, not for a clearly identified physical threat that can be mitigated.

400
MCQhard

A risk practitioner is quantifying the potential loss from a ransomware scenario affecting a hospital's electronic health record (EHR) platform. Historical data shows an average of two disruptive malware incidents per year, a 30% probability that any single incident escalates to full EHR encryption, and an estimated $4,000,000 business impact when the EHR is unavailable for a full day. What is the annualized loss expectancy (ALE) for this scenario?

A.$12,000,000
B.$2,400,000
C.$1,200,000
D.$8,000,000
AnswerB

Annualized loss expectancy equals single loss expectancy multiplied by annualized rate of occurrence. The single loss expectancy is $4,000,000 times 30%, or $1,200,000 per disruptive incident. Multiplying by two incidents per year yields $2,400,000. This figure gives leadership a defensible annual expected loss that can be compared directly against the annual cost of proposed controls when prioritizing risk treatment decisions.

Why this answer

Annualized loss expectancy is derived by first computing single loss expectancy, which is the impact of $4,000,000 multiplied by the 30% probability of escalation, giving $1,200,000. Multiplying that by the annualized rate of occurrence of two incidents per year produces $2,400,000. This expected annual loss can be weighed directly against the yearly cost of controls such as immutable backups, segmentation, and detection tooling.

Exam trap

The trap here is multiplying the raw impact by the annual incident count and forgetting to weight the impact by the probability that an incident escalates into full EHR encryption.

401
MCQhard

A multinational retailer's risk register shows a high inherent risk rating for its third-party payment processor. The processor has since obtained an independent SOC 2 Type II report with no exceptions, and the retailer's contract includes a right-to-audit clause. The risk owner proposes lowering the residual risk rating to low. Which factor is MOST important for the risk practitioner to consider before approving the revised rating?

A.Whether the SOC 2 report's scope and testing period cover the specific services, systems, and controls the retailer relies on.
B.Whether the retailer has exercised its right-to-audit clause at least once in the past three years.
C.Whether the processor's SOC 2 report was issued by a well-known audit firm with a strong market reputation.
D.Whether the processor has publicly announced any data breaches during the current fiscal year.
AnswerA

A SOC 2 Type II report only provides assurance over the systems, services, and controls within its stated scope and testing period. If the processor's report excludes the payment application or the relevant control objectives, the no-exceptions opinion does not support lowering residual risk. Confirming scope alignment is therefore the most important step before accepting the revised rating.

Why this answer

Before reducing residual risk based on third-party assurance, the practitioner must confirm that the assurance actually covers the systems, services, and control objectives the organization relies upon. Scope and period alignment determines whether the SOC 2 Type II opinion is relevant evidence. Auditor reputation, audit clause usage, and public breach history may inform judgment but cannot substitute for verifying that the report addresses the specific risk under review.

Exam trap

The trap here is accepting a clean third-party assurance report at face value without confirming that its scope and testing period cover the services the organization actually depends on.

402
MCQmedium

A software development company is adopting a DevOps model and wants to accelerate deployments. The risk manager is concerned that rapid changes could introduce security vulnerabilities. The team proposes implementing automated security testing in the CI/CD pipeline. Which of the following BEST describes the risk response strategy being applied?

A.Risk mitigation
B.Risk avoidance
C.Risk acceptance
D.Risk transfer
AnswerA

Automated security testing in the CI/CD pipeline is a mitigation control because it reduces the likelihood of security vulnerabilities being introduced into production. It addresses the risk by integrating security checks early and continuously, thus lowering the probability of a breach.

Why this answer

The correct answer is risk mitigation. By integrating automated security testing into the CI/CD pipeline, the company is implementing a control that reduces the likelihood of vulnerabilities reaching production. This is a proactive mitigation strategy that aligns with CRISC's emphasis on embedding risk management into business processes.

Exam trap

The trap here is thinking that adding security testing to a fast-paced process is avoidance or acceptance; it is mitigation because it reduces risk while allowing the business activity to continue.

403
Multi-Selectmedium

During a risk identification workshop, the team identifies several vulnerabilities. Which TWO of the following are examples of operational vulnerability identification? (Select two.)

Select 2 answers
A.Inadequate access control review process
B.Outdated firewall firmware
C.Missing security patches on servers
D.Weak password policy enforcement
E.SQL injection vulnerability in the web application
AnswersA, D

An inadequate access control review process is an operational vulnerability: a weakness in the ongoing procedures that govern how access rights are checked and recertified. It satisfies the stem's requirement for operational identification, since it arises from day-to-day process execution rather than project or architectural design.

Why this answer

Operational vulnerability identification focuses on weaknesses in day-to-day processes, procedures, and human/administrative controls rather than specific technical flaws in systems or code. Option A, an inadequate access control review process, is correct because it is a procedural/process weakness—failing to periodically review who has access means operational controls are not being maintained, which is a classic operational vulnerability. Option D, weak password policy enforcement, is correct because it reflects a failure in enforcing an administrative/operational control (e.g., not applying complexity, rotation, or lockout rules), which is a process and governance issue rather than a single technical defect.

By contrast, option B (outdated firewall firmware) and option C (missing security patches on servers) are technical vulnerabilities tied to unpatched software/hardware, and option E (SQL injection in the web application) is a technical application flaw, so they fall under technical rather than operational vulnerability identification.

Exam trap

CRISC often tests the boundary between operational and technical vulnerabilities — candidates pick patch or firmware issues because they sound like 'vulnerabilities,' but the question specifically asks for operational (process/control) weaknesses.

404
MCQeasy

In the NIST Cybersecurity Framework, which function is primarily focused on developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Detect
B.Protect
C.Recover
D.Identify
AnswerB

Protect encompasses the safeguards that limit or contain a cybersecurity event's impact, directly satisfying the stem's requirement to ensure delivery of critical infrastructure services. Its categories cover identity management, access control, awareness training, data security, maintenance and protective technology — the controls that actually secure service delivery.

Why this answer

The Protect function in the NIST Cybersecurity Framework (CSF) covers the safeguards that limit or contain the impact of a cybersecurity event — access control, awareness training, data security, information protection processes, maintenance, and protective technology. It is explicitly defined as developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services. Detect, Identify, and Recover address different phases of the risk lifecycle.

Exam trap

CRISC often tests the exact CSF function definitions — the trap is confusing Protect (safeguards) with Detect (monitoring) or Identify (asset/risk understanding), since all three sound defensive.

How to eliminate wrong answers

Option A is wrong because Detect focuses on developing and implementing activities to identify the occurrence of a cybersecurity event (continuous monitoring, detection processes, anomalies) — it does not implement safeguards. Option C is wrong because Recover focuses on developing and implementing activities to restore capabilities or services impaired by a cybersecurity event (recovery planning, improvements, communications). Option D is wrong because Identify focuses on understanding the cybersecurity risk to systems, people, assets, data, and capabilities (asset management, business environment, governance, risk assessment) — it is foundational but not the safeguard-implementation function.

405
MCQmedium

A multinational e-commerce company has experienced multiple security incidents involving unauthorized access to customer payment data. The incidents originated from different regional offices and exploited misconfigured firewall rules. The risk manager needs to identify the root cause of these risks. Which approach would BEST help in identifying the root cause of the IT risk?

A.Perform a root cause analysis on the firewall misconfigurations to determine underlying process weaknesses.
B.Implement additional logging on all firewall devices to capture configuration changes.
C.Conduct a penetration test targeting all regional office networks to identify vulnerabilities.
D.Update the risk register to include the incidents and assign risk owners.
AnswerA

Root cause analysis examines the firewall misconfigurations to expose the underlying process weaknesses, such as absent change control or review, that allowed them across regions. This addresses the stem's need to identify why the risk occurred, not merely remediate individual rules.

Why this answer

Root cause analysis (RCA) on the firewall misconfigurations directly investigates why the misconfigurations occurred, uncovering underlying process weaknesses such as inadequate change management, lack of configuration standards, or insufficient training. This addresses the root cause rather than symptoms, which is exactly what the risk manager needs to prevent recurrence across regional offices.

Exam trap

CRISC often tests the difference between identifying symptoms/vulnerabilities (logging, pen testing) and determining the underlying cause (RCA) — candidates may choose logging or pen testing because they sound proactive, but they do not answer 'why' the risk exists.

How to eliminate wrong answers

Option B is wrong because additional logging only captures future configuration changes and does not identify why the misconfigurations happened or what process failures allowed them. Option C is wrong because a penetration test identifies vulnerabilities but does not analyze the root cause of the existing misconfigurations or the process weaknesses behind them. Option D is wrong because updating the risk register documents the incidents and assigns ownership but does not investigate or resolve the underlying cause.

406
MCQeasy

According to COBIT 2019, which governance objective is primarily concerned with evaluating, directing, and monitoring the management of IT risk?

A.EDM03 — Ensure Risk Optimization
B.EDM02 — Ensure Benefits Delivery
C.EDM04 — Ensure Resource Optimization
D.EDM01 — Ensure Governance Framework Setting and Maintenance
AnswerA

EDM03 addresses risk optimisation within the Evaluate, Direct and Monitor domain, ensuring IT-related risk is identified, assessed and kept within the enterprise's risk appetite. It satisfies the stem's governance objective because EDM03 specifically covers evaluating, directing and monitoring IT risk management.

Why this answer

EDM03 — Ensure Risk Optimization is the governance objective that focuses on evaluating, directing, and monitoring risk management to ensure the enterprise's risk appetite and risk tolerance are understood and articulated.

407
Multi-Selecthard

Which THREE of the following should be included in a board-level risk report to effectively communicate the organization's risk profile?

Select 3 answers
A.Emerging risks and trend analysis of key risk indicators over the past quarter.
B.A list of the most recent security incidents with root cause analysis.
C.Detailed descriptions of all controls mitigating the top risks.
D.A risk heat map showing the current likelihood and impact of top risks.
E.A summary of current risk exposure relative to the board-approved risk appetite.
AnswersA, D, E

Trends and emerging risks support proactive oversight.

Why this answer

A board-level risk report must include forward-looking information such as emerging risks and trend analysis of key risk indicators (KRIs) over the past quarter. This enables the board to understand not only the current risk posture but also the direction and velocity of risk changes, which is essential for strategic oversight and proactive decision-making.

Exam trap

The trap here is that candidates confuse the operational detail needed for management-level reports (e.g., incident root causes or control descriptions) with the strategic, summarized, and risk-appetite-focused content required for board-level communication.

408
MCQmedium

During a risk assessment, a financial institution identifies that its online banking application uses an outdated encryption protocol. The likelihood of exploitation is high, and the impact is moderate. What should the risk owner do FIRST?

A.Implement a compensating control to mitigate the risk
B.Validate the risk rating with additional data
C.Transfer the risk via cyber insurance
D.Accept the risk as low priority
AnswerB

Before treating the high-likelihood, moderate-impact rating as final, the risk owner should confirm it against further evidence, since the assessment may rest on incomplete or stale data. Validating the rating ensures subsequent treatment decisions target the genuine exposure rather than an unverified estimate.

Why this answer

The risk owner's first responsibility is to ensure the risk assessment is accurate before deciding on a response. Validating the risk rating with additional data (option B) confirms that the high likelihood and moderate impact are correctly assessed, which is a prerequisite for selecting an appropriate treatment. Jumping to implement controls, transfer, or accept the risk without validation could lead to misallocation of resources or inadequate mitigation.

Exam trap

The trap here is that candidates often jump to selecting a risk treatment option (like implementing a control or transferring risk) without recognizing that the risk owner must first validate the risk rating to ensure the assessment is accurate and actionable.

How to eliminate wrong answers

Option A is wrong because implementing a compensating control is a risk treatment decision that should only occur after the risk rating is validated and a response strategy is chosen; acting prematurely may result in unnecessary or ineffective controls. Option C is wrong because transferring risk via cyber insurance is a specific treatment option that requires a validated risk rating to determine if transfer is cost-effective and appropriate; it is not the first step. Option D is wrong because accepting the risk as low priority contradicts the assessment's high likelihood and moderate impact, and acceptance should only be considered after validation confirms the rating and the risk is within the organization's appetite.

409
MCQeasy

A risk practitioner is conducting a risk assessment for a new customer-facing mobile application. The practitioner wants to identify risks by examining how data flows between the mobile client, the API gateway, and the backend database. Which of the following techniques is being applied?

A.Vulnerability scanning
B.Business impact analysis
C.Threat modeling
D.Control self-assessment
AnswerC

Threat modeling examines a system's architecture and data flows to identify where threats could exploit weaknesses. By tracing data between the mobile client, API gateway, and backend database, the practitioner is building the data-flow view that threat modeling uses to find exposure points such as unvalidated input or weak authentication between tiers. This makes it the technique being applied.

Why this answer

Threat modeling is the structured technique for examining system architecture, trust boundaries, and data flows to identify where threats can act. Tracing data between the mobile client, API gateway, and database is exactly the data-flow analysis that threat modeling performs. The other techniques address control evaluation, automated weakness detection, or business process criticality rather than architectural data movement.

Exam trap

The trap here is selecting vulnerability scanning because it also identifies weaknesses, when the distinguishing activity is architectural data-flow analysis rather than automated probing.

410
MCQeasy

Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a firewall?

A.Number of security incidents reported
B.Number of blocked intrusion attempts
C.Average time to patch vulnerabilities
D.Percentage of employees who completed security training
AnswerB

Blocked intrusion attempts measure the firewall's actual defensive effectiveness against real traffic, making it a KCI rather than a configuration metric. Rule counts or patch levels indicate effort or state, not control performance, so this satisfies the stem's requirement for an effectiveness measure.

Why this answer

A KCI measures the performance or effectiveness of a control. The number of blocked intrusion attempts is a direct measure of the firewall's preventive effectiveness.

411
MCQmedium

Which of the following is a key element of promoting a risk-aware culture within an IT department?

A.Establishing an anonymous incident reporting system
B.Outsourcing risk management to a third party
C.Conducting annual performance reviews
D.Requiring employees to sign non-disclosure agreements
AnswerA

An anonymous reporting channel lets staff raise risk concerns and near-misses without fear of reprisal, increasing the volume and honesty of information reaching management. This directly satisfies the cultural requirement by encouraging open, proactive risk communication across the IT department.

Why this answer

An anonymous incident reporting system encourages employees to report risks, errors, and near-misses without fear of retaliation, which is fundamental to building a risk-aware culture where people feel safe to speak up. It directly promotes transparency and proactive risk identification, key elements of a risk-aware culture.

Exam trap

CRISC often tests the confusion between risk culture enablers (like anonymous reporting) and generic HR or legal tools (performance reviews, NDAs) that do not directly promote risk awareness.

How to eliminate wrong answers

Option B is wrong because outsourcing risk management to a third party does not foster internal risk awareness; it may even distance employees from risk ownership. Option C is wrong because annual performance reviews are unrelated to risk culture and may even discourage reporting if tied to punitive measures. Option D is wrong because non-disclosure agreements are legal tools to protect confidentiality, not mechanisms to promote a risk-aware culture; they do not encourage open discussion of risks.

412
MCQhard

A utility company's risk practitioner is defining the scope of a risk identification exercise for a new advanced metering infrastructure. The practitioner must decide which elements to include. Which action BEST ensures the identification exercise covers the full risk landscape?

A.Limit the exercise to the technologies the project team will deploy directly.
B.Base scope on the risk categories already recorded in the enterprise risk register.
C.Defer identification until the infrastructure has been operating for one full billing cycle.
D.Include internal processes, third parties, and dependencies that interact with the new infrastructure.
AnswerD

Advanced metering infrastructure depends on internal billing and outage processes, communications vendors, field operations, and regulatory reporting, so identifying risks across these interactions exposes exposures that a technology-only view misses. This scope supports end-to-end risk scenarios, lets the practitioner trace cascading effects from a meter compromise through to customer billing, and aligns the identification exercise with how the utility actually delivers service.

Why this answer

A complete identification exercise follows the service and data flows rather than the project's technical boundary. For advanced metering infrastructure, that means including internal billing and outage processes, third-party communication providers, field operations, and regulatory dependencies, because risks frequently arise at these interfaces. A technology-only scope, a register-driven scope, or a deferred timeline would all leave material exposures unidentified or identified too late to influence design.

Exam trap

The trap here is equating the project's technical boundary with the risk boundary, when the risk landscape extends across processes, vendors, and dependencies.

413
MCQmedium

A mid-sized hospital is building its IT risk register. The risk practitioner wants to express the organization's tolerance for a ransomware event that would disrupt electronic health records for 24 hours. Which of the following BEST represents a structured way to document this tolerance?

A.A vulnerability assessment report showing unpatched EHR servers.
B.A risk register entry that lists ransomware as a high-likelihood, high-impact risk.
C.A business impact analysis that estimates the financial cost of a 24-hour EHR outage.
D.A documented risk appetite statement that specifies the maximum acceptable downtime and data loss for EHR systems.
AnswerD

A risk appetite statement quantifies how much risk the organization is willing to accept for a specific risk category or system. By stating maximum tolerable downtime and data loss, the hospital creates a measurable threshold that guides decisions on controls, insurance, and response planning. This directly supports IT risk identification by defining the boundary between acceptable and unacceptable risk.

Why this answer

A risk appetite statement is the formal mechanism for expressing how much risk an organization is willing to accept. It translates broad tolerance into specific, measurable limits such as maximum downtime and data loss. This gives the risk practitioner a clear benchmark for evaluating whether a ransomware risk is within or outside acceptable boundaries, enabling consistent risk response decisions.

Exam trap

The trap here is confusing risk assessment outputs, like a business impact analysis or vulnerability report, with a formal statement of risk appetite that explicitly defines acceptable risk levels.

414
MCQmedium

A financial services firm is deploying a new customer portal on a public cloud. The security team proposes using digital certificates to authenticate the portal to clients and sign sensitive transaction data. The risk manager must evaluate the residual risk after certificate deployment. Which of the following is the MOST significant residual risk related to the certificate lifecycle?

A.The certificate's private key might be stored in a hardware security module (HSM) with weak access controls.
B.The certificate's public key algorithm might be deprecated, requiring reissuance.
C.The certificate authority's root certificate might be compromised, allowing attackers to forge certificates.
D.Certificate revocation lists (CRLs) might become too large to distribute efficiently.
AnswerC

Compromise of a trusted root CA undermines the entire chain of trust, enabling attackers to issue fraudulent certificates that appear legitimate. This is a catastrophic residual risk because it can affect all certificates issued under that root, including those used for authentication and signing. Even with strong internal controls, reliance on a third-party CA introduces this systemic risk that cannot be fully mitigated by the organization.

Why this answer

A root certificate authority compromise is the most significant residual risk because it can invalidate the trust model for all certificates issued under that CA. Unlike internal control gaps or operational issues, this risk is external and can have widespread impact, including forged certificates for the organization's portal. Risk managers must consider third-party dependencies and the potential for cascading effects when evaluating residual risk.

Exam trap

The trap here is focusing on internal certificate management issues like key storage or algorithm deprecation while overlooking the systemic risk of a compromised root CA.

415
Multi-Selectmedium

Which THREE of the following are characteristics of leading key risk indicators (KRIs)?

Select 3 answers
A.They are predictive in nature.
B.They are based on historical data.
C.They measure past events and losses.
D.They provide early warning of potential risk events.
E.They enable proactive risk mitigation.
AnswersA, D, E

Leading KRIs forecast future risk exposure, enabling pre-emptive action before losses materialise. This predictive quality satisfies the stem's requirement for forward-looking characteristics, distinguishing them from lagging indicators that merely report past events. By signalling deteriorating conditions early, they support the proactive risk decisions CRISC expects.

Why this answer

Leading key risk indicators (KRIs) are predictive in nature because they track forward-looking metrics that signal potential future risk events before they occur. Unlike lagging indicators that measure past outcomes, leading KRIs use trend analysis and threshold monitoring to forecast changes in risk exposure, enabling organizations to anticipate and address issues proactively.

Exam trap

The trap here is that candidates often confuse leading KRIs with lagging indicators, mistakenly selecting options that describe historical or past-event measurements because they think all KRIs are backward-looking, but CRISC emphasizes that leading KRIs are forward-looking and predictive.

416
MCQmedium

During a vendor risk assessment, a prospective vendor for critical services cannot provide a SOC 2 Type II report. According to the organization's vendor risk appetite, which action should be taken?

A.Lower the vendor's tier to reduce requirements
B.Accept the vendor's self-assessment instead
C.Reject the vendor or request a formal risk acceptance
D.Onboard the vendor with additional monitoring
AnswerC

Without a SOC 2 Type II report, assurance over the vendor's control operating effectiveness is absent, breaching the stated risk appetite for critical services. Rejecting the vendor or escalating to formal risk acceptance satisfies that constraint, ensuring residual risk is consciously owned rather than silently absorbed.

Why this answer

A SOC 2 Type II report provides independent assurance over a service organization's controls over a period of time. When a prospective vendor for critical services cannot provide this report, and the organization's risk appetite is defined, the appropriate action is to reject the vendor or require a formal risk acceptance from the risk owner. This ensures that any deviation from the required control evidence is explicitly acknowledged and approved, rather than bypassing the requirement.

Exam trap

The trap here is that candidates may assume 'additional monitoring' (Option D) is a valid compensating control, but the CRISC exam emphasizes that for critical services, independent assurance (like SOC 2) is a non-negotiable baseline, and monitoring is a detective control, not a preventive or directive control that replaces the need for formal risk acceptance.

How to eliminate wrong answers

Option A is wrong because lowering the vendor's tier to reduce requirements would arbitrarily weaken the control baseline for a critical service, which contradicts the principle of aligning controls with risk criticality. Option B is wrong because accepting a vendor's self-assessment instead of a SOC 2 Type II report removes independent verification, introducing a conflict of interest and potentially hiding control weaknesses. Option D is wrong because onboarding the vendor with additional monitoring does not address the lack of foundational control assurance; monitoring can detect issues but cannot replace the need for pre-contract evidence of control effectiveness.

417
MCQmedium

A new web application is being developed using several open-source libraries. Which risk identification method is most effective for identifying vulnerabilities in these libraries?

A.Static application security testing (SAST)
B.Software composition analysis (SCA)
C.Dynamic application security testing (DAST)
D.Manual code review
AnswerB

SCA scans dependencies and matches them against vulnerability databases, ideal for open-source risk identification.

Why this answer

Software Composition Analysis (SCA) is specifically designed to identify known vulnerabilities in open-source libraries by analyzing dependency manifests (e.g., pom.xml, package.json) and correlating them against vulnerability databases like the National Vulnerability Database (NVD). For a web application built with multiple open-source components, SCA automates the detection of outdated or vulnerable libraries, which is the most effective method for this risk identification scenario.

Exam trap

The trap here is that candidates confuse SAST (which finds code-level bugs) with SCA (which finds library vulnerabilities), assuming any security testing tool can identify open-source risks, but only SCA is designed to inventory and assess third-party components against known CVEs.

How to eliminate wrong answers

Option A is wrong because Static Application Security Testing (SAST) analyzes source code for security flaws in custom application logic (e.g., SQL injection, buffer overflows), but it does not scan or track third-party library dependencies or their known vulnerabilities. Option C is wrong because Dynamic Application Security Testing (DAST) tests the running application for runtime vulnerabilities (e.g., XSS, CSRF) by sending malicious payloads, but it cannot identify vulnerabilities embedded in library versions that are not actively exploited during the test. Option D is wrong because Manual code review, while thorough for custom code, is impractical for large open-source libraries and cannot efficiently cross-reference thousands of library versions against vulnerability databases like SCA does.

418
Multi-Selecteasy

A SIEM generates alerts for the following events. Which TWO events should be considered potential emerging risks? (Select exactly 2.)

Select 2 answers
A.Scheduled backup completed successfully
B.Software update installed on server
C.High number of failed authentication attempts from a single IP
D.Low disk space alert on a file server
E.Unusual increase in outbound traffic from a database server
AnswersC, E

Repeated failed authentications from one IP indicate brute-force or credential-stuffing activity, directly satisfying the stem's emerging-risk criterion of a novel, escalating attack pattern. Unlike routine policy violations, this signal reflects active adversarial probing against Microsoft Entra ID, warranting threat-intelligence review before it matures into account compromise.

Why this answer

Option C is correct because a high volume of failed authentication attempts from a single IP is a classic indicator of a brute-force or password-spraying attack, representing an emerging risk that could lead to unauthorized access. Option E is correct because an unusual increase in outbound traffic from a database server may indicate data exfiltration, command-and-control communication, or a compromised host, all of which are emerging threats. Option A does not belong because a successful scheduled backup is a normal, expected operational event with no risk implication.

Option B does not belong because a routine software update installation is a planned maintenance activity, not an emerging risk. Option D does not belong because low disk space on a file server is a capacity or availability issue, not an emerging security risk.

Exam trap

The trap here is that candidates confuse operational alerts (like low disk space or successful backups) with security risks, failing to recognize that emerging risks must involve active threat indicators such as reconnaissance or anomalous traffic patterns.

419
MCQhard

Based on the exhibit, which of the following poses the HIGHEST risk to the environment?

A.The web servers are in a public subnet
B.The communication between web and application servers is encrypted via HTTPS
C.The application servers use embedded credentials to access the database
D.The database has a direct SSH connection from the internet
AnswerD

Direct SSH exposure from the internet places the database's administrative access on a publicly reachable port, enabling brute-force, credential-stuffing and exploit attempts against a Tier-1 asset. Other findings require an internal foothold first, so this offers the shortest path to compromise.

Why this answer

A direct SSH connection from the internet to the database server bypasses all network segmentation and firewall controls, exposing the database to brute-force attacks, credential theft, and unauthorized remote access. SSH is a management protocol, not an application protocol, and its exposure on the internet creates a direct attack surface on the most sensitive data tier, which is the highest risk to the environment.

Exam trap

ISACA often tests the misconception that 'encryption always reduces risk' or that 'public subnets are inherently dangerous,' when in reality the highest risk is exposing management interfaces (like SSH) directly to the internet, not the application-layer exposure of web servers.

How to eliminate wrong answers

Option A is wrong because web servers are typically placed in a public subnet to serve traffic to users; this is a standard architectural design and not inherently high risk as long as proper security groups and WAFs are in place. Option B is wrong because HTTPS encryption between web and application servers protects data in transit from eavesdropping and tampering, which actually reduces risk rather than posing a risk. Option C is wrong because while embedded credentials are a security concern (they can be extracted from code), they do not expose the database to direct internet-based attacks and are a lower risk compared to an open SSH management channel from the internet.

420
MCQhard

A multinational bank has a risk appetite that allows for a maximum of 5% downtime for its online banking platform per quarter. The platform currently experiences 8% downtime due to frequent distributed denial-of-service (DDoS) attacks. The risk owner proposes investing in a cloud-based DDoS mitigation service. Which of the following should be the risk practitioner's PRIMARY consideration when evaluating this proposed risk response?

A.The total cost of the service compared to the potential financial losses from downtime.
B.The service provider's reputation and market share in the DDoS mitigation industry.
C.The expected reduction in downtime and whether it brings residual risk within the bank's risk appetite.
D.The service provider's ability to integrate with the bank's existing incident response plan.
AnswerC

The primary consideration is whether the proposed DDoS mitigation service will reduce the downtime from 8% to 5% or below, aligning with the bank's risk appetite. The risk practitioner must evaluate the control's effectiveness in mitigating the risk to an acceptable level. This involves analyzing the service's capabilities, historical performance, and any residual risk after implementation. Cost and integration are secondary to this fundamental risk-reduction assessment.

Why this answer

The risk practitioner's primary role is to evaluate whether a proposed risk response will bring residual risk within the organization's risk appetite. Here, the bank's risk appetite for downtime is 5%, but current downtime is 8%. The proposed DDoS mitigation service must be assessed for its ability to reduce downtime to 5% or less.

This assessment should consider the service's effectiveness, reliability, and any residual risk. Cost, integration, and vendor reputation are secondary factors that inform the decision but do not replace the core risk-reduction evaluation.

Exam trap

The trap here is prioritizing cost or vendor reputation over the fundamental question of whether the control actually reduces risk to within appetite.

421
Multi-Selecteasy

A risk manager is designing monthly risk reports for senior management. Which THREE of the following should be included in an effective risk report? (Choose three.)

Select 3 answers
A.Names of individual employees responsible for control failures.
B.Changes in the risk landscape.
C.Key risk indicators (KRIs) and their trends.
D.Detailed control test results for every control.
E.Status of risk treatment plans.
AnswersB, C, E

Keeps management informed of external and internal changes.

Why this answer

An effective risk report must communicate changes in the risk landscape, such as new threats, regulatory shifts, or emerging vulnerabilities, to enable senior management to make informed strategic decisions. This ensures the report remains relevant and actionable, reflecting the dynamic nature of risk.

Exam trap

The trap here is that candidates confuse operational detail (like individual blame or exhaustive control results) with strategic reporting, forgetting that senior management needs aggregated, trend-based insights rather than granular data.

422
MCQmedium

In a qualitative risk assessment, a risk owner argues that the likelihood of a cyberattack is low because the organization has strong perimeter defenses. However, the analyst notes that the impact would be catastrophic. Which limitation of qualitative analysis is most relevant?

A.It relies on subjective judgments
B.It is not comparable across organizations
C.It is time-consuming and data-intensive
D.It does not produce financial values
AnswerA

Qualitative assessment rates likelihood and impact using judgement-based scales rather than measurable frequencies, so the owner's confidence in perimeter defences becomes an unverified subjective input. This subjectivity is the limitation, since no objective data validates the low-likelihood claim despite the catastrophic impact.

Why this answer

Qualitative risk assessment relies on subjective judgments, such as the risk owner's belief that strong perimeter defenses make an attack unlikely, despite the analyst's view that impact would be catastrophic. This subjectivity can lead to inconsistent or biased risk ratings. The scenario highlights how personal opinion can skew likelihood estimates, which is a core limitation of qualitative analysis.

Exam trap

CRISC often tests the limitation of qualitative analysis as subjectivity, but candidates may confuse it with lack of financial values or comparability, which are also limitations but not the most relevant in a scenario about conflicting expert opinions.

How to eliminate wrong answers

Option B is wrong because while qualitative assessments may be hard to compare across organizations, the scenario does not involve cross-organizational comparison. Option C is wrong because qualitative analysis is typically less time-consuming and data-intensive than quantitative analysis. Option D is wrong because although qualitative analysis does not produce financial values, the scenario focuses on subjective likelihood judgment, not the lack of monetary impact.

423
MCQhard

A multinational corporation is migrating its customer relationship management (CRM) system to a public cloud provider. The data includes personally identifiable information (PII) from multiple jurisdictions. Which risk should be considered most critical during the cloud architecture review?

A.Multi-tenancy isolation failures
B.Data sovereignty and cross-border data transfer restrictions
C.Shared responsibility model gaps for patching
D.Vendor lock-in due to proprietary APIs
AnswerB

PII from multiple jurisdictions triggers conflicting legal requirements about where data may reside and when it may cross borders. Data sovereignty and transfer restrictions therefore dominate the architecture review, since violating them creates regulatory and contractual exposure that other cloud risks do not.

Why this answer

The CRM migration involves PII from multiple jurisdictions, making data sovereignty and cross-border data transfer restrictions the most critical risk. Regulations like GDPR (EU) and local data localization laws (e.g., Russia, China) can impose fines or block transfers if data leaves approved regions. This risk directly impacts legal compliance and operational continuity, outweighing technical concerns like isolation or patching.

Exam trap

The trap here is that candidates confuse technical risks like multi-tenancy or patching with the overriding legal and regulatory risk of data sovereignty, which is the most critical for multinational PII migrations.

How to eliminate wrong answers

Option A is wrong because multi-tenancy isolation failures are a general cloud risk but less critical here; the CRM data is PII, but the primary legal risk is jurisdictional, not technical co-mingling. Option C is wrong because shared responsibility model gaps for patching are operational risks that can be mitigated via SLAs and automated patching, not the most critical for cross-jurisdiction PII. Option D is wrong because vendor lock-in due to proprietary APIs is a long-term strategic risk, not an immediate compliance or legal threat during migration of regulated data.

424
MCQmedium

A hospital's radiology department wants to replace its on-premises PACS archive (DICOM images) with a vendor-hosted SaaS platform. The vendor stores images in its own multitenant cloud and provides a web viewer. Before signing, the risk practitioner must confirm which control MOST directly addresses the risk that a vendor-side compromise could expose patient images to other tenants.

A.Require the vendor to publish a SOC 2 Type II report covering the last twelve months.
B.Require annual penetration testing of the hospital's own internal network by an external firm.
C.Confirm the contract includes a right-to-audit clause allowing the hospital to inspect the vendor's data center.
D.Verify the vendor enforces strict tenant isolation and encryption key separation in the multitenant storage layer.
AnswerD

In a multitenant SaaS PACS, the dominant exposure is logical separation failure, so confirming that tenant isolation is enforced and that each tenant's encryption keys are segregated directly mitigates cross-tenant image disclosure. This control targets the actual mechanism by which one customer could read another customer's DICOM objects, making it the most direct risk response for the stated scenario.

Why this answer

Because the images would reside in a shared multitenant platform, the risk that matters most is logical separation failure between customers. Confirming enforced tenant isolation with segregated encryption keys directly addresses that failure mode. Audit reports, right-to-audit clauses and internal penetration tests provide valuable assurance and leverage but do not specifically prevent one tenant from accessing another tenant's DICOM data.

Exam trap

The trap here is treating vendor assurance artifacts such as SOC 2 reports or right-to-audit clauses as equivalent to evidence that tenant isolation is actually enforced.

425
MCQhard

An organization's risk committee is reviewing key risk indicators (KRIs) for its customer-facing web applications. The KRI for average patch latency has breached its threshold for two consecutive quarters, yet the risk register still lists the associated risk as medium with no treatment plan. Which action should the risk practitioner recommend FIRST?

A.Escalate the KRI breach to the risk owner and require reassessment of the risk rating and treatment plan.
B.Immediately raise the risk rating to high in the risk register without consulting the risk owner.
C.Wait until the next scheduled quarterly risk committee meeting to present the KRI trend for discussion.
D.Recommend purchasing additional cyber insurance to cover the potential loss from unpatched applications.
AnswerA

A sustained KRI breach indicates that the risk environment has changed and the existing rating may no longer be valid. The practitioner's first step is to escalate to the accountable risk owner so the risk can be reassessed and a treatment decision documented. This maintains the integrity of the risk register and ensures reporting reflects actual conditions rather than stale assessments.

Why this answer

A KRI that breaches its threshold for two consecutive quarters signals that the underlying risk profile has deteriorated, yet the register still shows a stale medium rating without treatment. The practitioner should escalate to the accountable risk owner so the risk can be reassessed and a documented treatment decision made. Unilateral rating changes, premature insurance recommendations, and deferred discussion all bypass the owner's accountability and delay necessary action.

Exam trap

The trap here is assuming the practitioner should directly modify the risk register, when the correct first step is escalation to the risk owner for reassessment.

426
MCQeasy

A retail company is establishing an IT risk universe. Which of the following should be included as a primary category of IT risk?

A.Market risk
B.Third-party risk
C.Inflation risk
D.Interest rate risk
AnswerB

Third-party risk is a primary IT risk category because vendors and partners introduce exposure through shared data, integrated systems and outsourced processes. Including it in the risk universe ensures supplier dependencies are assessed alongside internal threats.

Why this answer

Third-party risk is a primary IT risk category because organizations increasingly depend on vendors, cloud providers, and service integrators whose failures, breaches, or non-compliance directly affect the organization's IT risk posture. It belongs in the IT risk universe alongside categories such as cybersecurity, availability, data integrity, and compliance risk. Market, inflation, and interest rate risks are financial/market risks, not IT risk categories.

Exam trap

CRISC often tests whether candidates can distinguish IT risk categories from financial/market risk categories, so the trap is selecting a familiar-sounding financial risk (market, inflation, interest rate) instead of the IT-relevant third-party risk.

How to eliminate wrong answers

Option A is wrong because market risk is a financial risk category (price movements, demand shifts) and is not a primary IT risk category in an IT risk universe. Option C is wrong because inflation risk is a macroeconomic/financial risk, not an IT risk. Option D is wrong because interest rate risk is a treasury/financial risk and does not describe technology-related exposure.

427
MCQhard

A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?

A.Establishment of an electronic security perimeter around critical cyber assets
B.Adoption of a cloud-based backup solution
C.Use of quantum-resistant encryption for all communications
D.Implementation of IEC 62443 security levels
AnswerA

NERC CIP requires responsible entities to define and protect an Electronic Security Perimeter enclosing critical cyber assets, controlling all electronic access points into the bulk electric system environment. This is a mandated CIP-005 control, unlike generic measures such as encryption or patching, which are not perimeter-specific.

Why this answer

NERC CIP standards require identification and protection of critical cyber assets, including clear boundaries (electronic security perimeters) to control access.

428
MCQmedium

A company is implementing a new continuous monitoring tool for its network security controls. Which of the following is the MOST important step to ensure the tool provides meaningful risk information?

A.Configure the tool to generate real-time alerts for all events.
B.Provide training to all users on how to interpret the tool's output.
C.Ensure the tool is integrated with the existing SIEM system.
D.Align the tool's monitoring parameters with key risk indicators and critical controls.
AnswerD

Aligning monitoring parameters with key risk indicators and critical controls ensures collected data reflects actual risk exposure rather than raw technical noise. This satisfies the stem's requirement that the continuous monitoring tool deliver meaningful risk information to decision-makers.

Why this answer

A continuous monitoring tool only delivers meaningful risk information when its monitoring parameters are directly aligned with key risk indicators (KRIs) and critical controls. Without this alignment, the tool may generate noise or miss high-severity events, failing to support risk-based decision-making.

Exam trap

The trap here is that candidates confuse operational efficiency (integration with SIEM) or user training with the risk-focused requirement of aligning monitoring to KRIs, which is the core of risk-based monitoring and reporting.

How to eliminate wrong answers

Option A is wrong because configuring the tool to generate real-time alerts for all events would overwhelm analysts with false positives and alert fatigue, obscuring genuine risk signals. Option B is wrong while user training is valuable, it does not address the fundamental need for the tool to monitor the right parameters; training on interpreting output is useless if the data itself is irrelevant. Option C is wrong because integration with a SIEM system is a technical convenience for log aggregation, but it does not ensure that the monitored data corresponds to KRIs or critical controls; the tool could still produce meaningless data even if integrated.

429
MCQhard

During a VAST threat modeling session for a DevSecOps pipeline, the team focuses on threats that align with agile development. Which of the following is a key advantage of VAST?

A.It requires detailed system architecture upfront
B.It replaces the need for vulnerability scanning
C.It is tailored for use in agile and DevOps environments
D.It focuses on compliance requirements only
AnswerC

VAST's defining advantage is that it was designed specifically for Agile and DevOps delivery, scaling threat modelling across many fast-moving teams and integrating into sprint workflows. This directly satisfies the stem's constraint of aligning threats with agile development during a DevSecOps pipeline session.

Why this answer

VAST is designed to integrate with agile and DevOps, providing continuous threat modeling.

430
Multi-Selectmedium

An organization is evaluating risk treatment options for a critical vulnerability. Which TWO options would be considered risk mitigation?

Select 2 answers
A.Purchase cyber insurance
B.Accept the risk with formal sign-off
C.Discontinue the vulnerable service
D.Deploy an intrusion prevention system
E.Implement a security patch
AnswersD, E

An intrusion prevention system actively blocks detected malicious traffic inline, reducing the likelihood or impact of exploitation. This lowers residual risk while retaining the vulnerability, which is the defining mechanism of risk mitigation rather than avoidance, transfer or acceptance.

Why this answer

Deploying an intrusion prevention system (IPS) is a risk mitigation measure because it actively monitors and blocks malicious traffic targeting the vulnerability, reducing the likelihood of exploitation. Implementing a security patch directly removes the vulnerability, thereby reducing both the likelihood and impact of a potential attack. Both actions modify the risk by applying technical controls to lower the residual risk level.

Exam trap

The trap here is confusing risk mitigation (reducing likelihood/impact through controls) with risk transfer (insurance), risk acceptance (formal sign-off), or risk avoidance (discontinuing the service), which are distinct treatment options in the CRISC risk response framework.

431
MCQhard

A risk manager discovers that a business unit has been using an unapproved software-as-a-service (SaaS) application for three months. The application stores customer PII. Which of the following risk identification techniques should the risk manager use to understand the full extent of the risk?

A.Run an automated data discovery tool across the network
B.Interview the business unit head about the application's use and data stored
C.Request an independent audit of the SaaS provider
D.Review network logs to identify data transfers to the SaaS provider
AnswerB

Interviewing the business unit head establishes what data the SaaS application holds, how many customer records are affected and which controls apply. This directly satisfies the need to determine the full extent of the PII risk, which automated scanning or policy review alone cannot reveal.

Why this answer

Interviewing the business unit head is the most direct and effective technique to understand the full extent of the risk. The risk manager needs to know the specific business processes, the types and volume of PII stored, the purpose of the application, and how data flows into and out of the SaaS application. Automated tools or logs can only provide technical evidence of usage, but they cannot capture the business context, data classification, or the actual data handling practices that define the risk's scope.

Exam trap

The trap here is that candidates often choose an automated or technical option (like A or D) because they seem objective and efficient, but the question specifically asks for a technique to 'understand the full extent of the risk,' which requires human insight into business context and data handling, not just technical detection.

How to eliminate wrong answers

Option A is wrong because running an automated data discovery tool across the network can identify the presence of the SaaS application and data transfers, but it cannot determine the business purpose, the exact PII fields stored, or the data handling procedures, which are essential for understanding the full risk extent. Option C is wrong because requesting an independent audit of the SaaS provider is a reactive and external step that assumes the provider will cooperate and that the risk manager already knows the scope of data shared; it does not help the risk manager initially understand the internal usage and data stored. Option D is wrong because reviewing network logs can show data transfers to the SaaS provider, but logs alone cannot reveal the specific PII content, the business justification, or the data lifecycle within the application, leaving significant gaps in risk understanding.

432
MCQmedium

A financial services firm's risk register shows that a legacy payment gateway has a high inherent risk of SQL injection. The security team proposes deploying a web application firewall (WAF) in front of the gateway. The risk owner must document how this action will be classified in the risk response plan. Which risk response strategy does deploying the WAF represent?

A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerA

Deploying a WAF reduces the likelihood and impact of SQL injection by filtering malicious input before it reaches the payment gateway. In CRISC terms, this is risk mitigation because a control is applied to bring the residual risk within the organization's risk appetite while the underlying asset and threat remain. The risk is not eliminated, transferred, or avoided, so mitigation is the accurate classification.

Why this answer

Applying a web application firewall reduces the likelihood and impact of SQL injection against the legacy payment gateway, which is the definition of risk mitigation. The organization continues to operate the asset and retains the residual risk, so avoidance, transfer, and acceptance do not describe the action. Correct classification matters because the risk register and reporting must reflect the true response strategy and its effect on residual risk.

Exam trap

The trap here is assuming that any security control automatically means risk avoidance, when avoidance requires eliminating the activity that creates the risk.

433
MCQeasy

Which risk treatment option is being used when an organization decides to stop a business activity that creates a high-risk exposure?

A.Avoid
B.Accept
C.Mitigate
D.Transfer
AnswerA

Risk avoidance eliminates the exposure entirely by discontinuing the activity that generates it, rather than transferring, mitigating or accepting the risk. Stopping the business activity removes both the likelihood and impact, which is the defining characteristic of the avoid treatment option.

Why this answer

When an organization stops a business activity that creates high-risk exposure, it is applying the risk avoidance treatment option. This is a deliberate decision to eliminate the risk entirely by discontinuing the associated process, system, or operation, rather than attempting to reduce or transfer the residual risk. In IT risk management, avoidance is often chosen when the cost or impact of mitigation exceeds the benefit of the activity, or when the risk level is intolerable under any control scenario.

Exam trap

The trap here is that candidates often confuse 'avoid' with 'mitigate,' thinking that any action to reduce risk is avoidance, but CRISC specifically tests that avoidance means completely eliminating the risk by discontinuing the activity, not just applying controls to lower it.

How to eliminate wrong answers

Option B (Accept) is wrong because risk acceptance involves acknowledging the risk and its potential impact without taking action to reduce it, which is the opposite of stopping the activity. Option C (Mitigate) is wrong because mitigation involves implementing controls to reduce the likelihood or impact of the risk while continuing the activity, not ceasing it entirely. Option D (Transfer) is wrong because risk transfer shifts the financial burden of the risk to a third party (e.g., via insurance or outsourcing) but does not stop the underlying business activity or eliminate the operational exposure.

434
Multi-Selecthard

A company's IT risk team is conducting a risk identification exercise for a new blockchain-based supply chain solution. Which THREE risks are MOST specific to this technology?

Select 3 answers
A.51% attack on the underlying consensus mechanism.
B.Incompatibility with legacy database systems.
C.High electricity consumption of mining nodes.
D.Smart contract vulnerabilities leading to unintended execution.
E.Cryptographic key management failures.
AnswersA, D, E

A 51% attack occurs when a single entity controls majority hashing power, enabling transaction reversal or double-spending on the blockchain's consensus mechanism. This satisfies the stem's requirement by naming a risk specific to distributed ledger technology rather than generic IT.

Why this answer

Option A is correct because a 51% attack is a blockchain-specific risk in which an entity controlling a majority of consensus power (hashrate in PoW or stake in PoS) can rewrite transaction history or double-spend, directly threatening the integrity of the distributed ledger. Option D is correct because smart contracts execute automatically on-chain, so coding flaws such as reentrancy, integer overflow, or access-control bugs can cause irreversible unintended transactions and fund loss unique to programmable blockchain logic. Option E is correct because blockchain relies on asymmetric cryptography, and loss or compromise of private keys means irreversible loss of asset control, forged signatures, or unauthorized transactions, a risk intrinsic to decentralized key ownership.

Option B is not specific to blockchain, since incompatibility with legacy database systems is a generic integration challenge faced by many new enterprise platforms. Option C is not the best fit because high electricity consumption applies mainly to proof-of-work mining and is an environmental/cost concern rather than a core risk unique to all blockchain supply chain solutions, especially permissioned or proof-of-stake networks.

Exam trap

ISACA often tests the distinction between generic IT risks and technology-specific risks, so candidates mistakenly select 'high electricity consumption' without considering that many blockchain implementations (especially in enterprise supply chains) do not use energy-intensive proof-of-work.

435
Multi-Selecteasy

Which TWO of the following are primary sources of risk identification for IT projects? (Select exactly 2.)

Select 2 answers
A.Security baseline
B.Project documentation
C.Risk treatment plan
D.Firewall logs
E.Lessons learned from previous projects
AnswersB, E

Project documentation — charters, plans, assumptions and requirements — surfaces risks early by exposing dependencies, scope gaps and constraints. It satisfies the criterion of being a primary, project-specific source rather than an external or generic one.

Why this answer

Option B (Project documentation) is a primary source of risk identification because artifacts such as the project charter, scope statement, WBS, schedule, assumptions log, and stakeholder register expose uncertainties, dependencies, and constraints that can become risks. Option E (Lessons learned from previous projects) is also a primary source, since historical records from comparable projects reveal recurring threats, failure patterns, and effective mitigations that should inform the current risk register. Option A (Security baseline) is a control configuration reference, not a risk identification input; it defines required settings rather than surfacing project risks.

Option C (Risk treatment plan) is an output of the risk management process that documents responses to already-identified risks, so it cannot be a primary source of identification. Option D (Firewall logs) are operational security monitoring data used for detection and incident response, not a standard project risk identification source.

Exam trap

The trap here is that candidates confuse operational artifacts (like firewall logs or security baselines) with project-level risk identification sources, or mistakenly think the risk treatment plan is an input rather than an output of the risk identification process.

436
MCQeasy

An IT risk manager is reviewing the risk register and finds that the same database server appears in three separate risk entries: one for unauthorized access, one for data corruption, and one for denial of service. What is the PRIMARY benefit of structuring the register this way rather than combining all three into a single entry?

A.It reduces the total number of controls that must be implemented.
B.It eliminates the need to reassess the risks during the next assessment cycle.
C.It allows each risk to be assessed and treated based on its distinct threat, vulnerability, and impact.
D.It guarantees that the risk register will align with the organization's risk appetite.
AnswerC

Granular risk entries preserve the unique threat, vulnerability, and impact profile of each scenario. Unauthorized access, data corruption, and denial of service have different causes, likelihoods, and consequences, and they demand different controls. Keeping them separate lets the risk manager assign accurate ratings, target treatment effectively, and track residual risk for each scenario rather than averaging unrelated exposures into a single misleading figure.

Why this answer

Separate risk entries preserve the distinct threat, vulnerability, and impact characteristics of each scenario affecting the database server. This granularity enables accurate likelihood and impact ratings, targeted control selection, and clear ownership. Combining unrelated scenarios into one entry would obscure which threat drives which consequence and would make it difficult to measure whether a specific control reduced the risk it was meant to address.

Exam trap

The trap here is assuming that fewer register entries always mean simpler and better risk management, when granularity actually improves treatment accuracy.

437
MCQhard

During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?

A.The degree to which the risk affects strategic business objectives
B.The ease of implementing mitigating controls
C.The likelihood that the threat will be exploited
D.The financial impact calculated in monetary terms
AnswerA

Strategic alignment determines whether a risk threatens the organisation's core objectives, so it carries the greatest weight when prioritising treatment. Likelihood and financial impact matter, but a risk undermining strategic goals can jeopardise the entire business model, making this characteristic the dominant factor in the assessment.

Why this answer

In CRISC, risk prioritization is fundamentally driven by alignment with strategic business objectives because IT risk management exists to protect the enterprise’s mission and goals. Even a high-likelihood or high-financial-impact risk may be deprioritized if it does not materially affect the organization’s strategic objectives, as the risk treatment decision must support business value and continuity. This weighting ensures that resources are allocated to risks that most threaten the enterprise’s ability to achieve its core mission.

Exam trap

ISACA often tests the misconception that financial impact or likelihood should be the primary weighting factor, but CRISC emphasizes that strategic alignment is the overriding criterion because risk treatment must support the enterprise’s overall business goals, not just minimize cost or probability.

How to eliminate wrong answers

Option B is wrong because the ease of implementing mitigating controls is a tactical implementation consideration, not a primary risk prioritization factor; prioritizing based on ease can lead to treating low-impact risks while ignoring critical strategic threats. Option C is wrong because likelihood alone is insufficient—a threat with high likelihood but negligible business impact should not be weighted more heavily than a lower-likelihood risk that could cripple strategic objectives. Option D is wrong because financial impact in isolation ignores non-monetary strategic factors such as reputational damage, regulatory compliance, or competitive advantage, which may be more critical to the enterprise’s survival than a simple dollar figure.

438
MCQmedium

Based on the exhibit, what is the primary risk to the organization?

A.Unauthorized modification of customer data
B.Data loss due to accidental deletion
C.Unauthorized disclosure of sensitive customer data
D.Denial of service due to excessive read requests
AnswerC

The exhibit exposes sensitive customer records to parties lacking authorisation, so the primary risk is unauthorised disclosure of that data. This directly matches the confidentiality breach scenario the exhibit depicts, rather than integrity or availability concerns.

Why this answer

The exhibit shows a database server with customer data accessible via a web application that uses unencrypted HTTP (port 80) and has direct internet exposure. This configuration allows an attacker to intercept traffic or exploit the lack of encryption to read sensitive customer data in transit, making unauthorized disclosure the primary risk. The core reasoning is that unencrypted HTTP exposes data to eavesdropping and man-in-the-middle attacks, directly violating confidentiality requirements for sensitive customer information.

Exam trap

The trap here is that candidates often focus on the database server's role (e.g., modification or deletion risks) instead of recognizing that the unencrypted HTTP exposure directly enables unauthorized disclosure of data in transit, which is the most immediate and severe risk to confidentiality.

How to eliminate wrong answers

Option A is wrong because unauthorized modification of customer data requires write access or injection vulnerabilities (e.g., SQL injection), but the exhibit only shows read access via HTTP without any indication of write capabilities or input validation flaws. Option B is wrong because data loss due to accidental deletion typically involves lack of backups or improper access controls on delete operations, whereas the exhibit highlights unencrypted read access and internet exposure, not deletion risks. Option D is wrong because denial of service due to excessive read requests would require a resource exhaustion scenario (e.g., lack of rate limiting or DDoS protection), but the primary risk from unencrypted HTTP is data exposure, not availability.

439
MCQhard

A hospital's risk practitioner is evaluating a new telehealth platform that will process protected health information (PHI). The platform will be hosted by a third-party vendor. Which of the following is the MOST critical risk to address during contract negotiations?

A.The vendor's service level agreement (SLA) for platform uptime.
B.The vendor's use of subcontractors to support the platform.
C.The vendor's data breach notification timeline and liability for regulatory penalties.
D.The vendor's geographic location and data residency practices.
AnswerC

Under HIPAA, the covered entity remains responsible for PHI even when a business associate handles it. The contract must define when and how the vendor will notify the hospital of a breach and who bears the cost of regulatory penalties and patient notifications. Without these terms, the hospital faces unmitigated financial and reputational risk.

Why this answer

When a third party processes PHI, the hospital must ensure the business associate agreement clearly assigns responsibility for breach notification and regulatory penalties. This contractual protection is the most critical risk treatment because it directly addresses the hospital's legal and financial exposure under HIPAA. Other concerns like subcontractors, uptime, and data residency are important but secondary to the allocation of liability.

Exam trap

The trap here is focusing on operational issues like uptime or data location, while overlooking the contractual need to transfer or share liability for PHI breaches.

440
Multi-Selecthard

Which THREE of the following are best practices for reporting risk and control monitoring results to stakeholders?

Select 3 answers
A.Tailor the report to the audience's level of understanding.
B.Include trend analysis and comparisons to thresholds.
C.Include detailed technical logs for each control.
D.Provide reports only when issues occur.
E.Highlight changes in risk exposure and control effectiveness.
AnswersA, B, E

Customization improves comprehension.

Why this answer

Risk and control monitoring reports must be tailored to the audience's level of understanding to ensure that stakeholders can effectively interpret the information. For example, an executive summary should focus on high-level risk exposure and strategic impacts, while detailed reports for control owners may include operational metrics. This practice aligns with the principle of communicating risk information in a manner that supports informed decision-making.

Exam trap

The trap here is that candidates may mistakenly think that providing detailed technical logs (Option C) demonstrates thoroughness, when in fact it undermines the goal of clear, actionable reporting by overwhelming the audience with irrelevant data.

441
MCQmedium

A hospital's risk register identifies that a critical medical imaging server runs an unsupported operating system, creating a high likelihood of exploitation. The vendor will not release a patch, and the server cannot be taken offline because it supports active patient care. The CISO asks the risk practitioner to reduce the likelihood of exploitation without disrupting imaging services. Which risk response is MOST appropriate?

A.Accept the risk because the server is essential to patient care and cannot be taken offline for replacement.
B.Isolate the imaging server on a dedicated network segment with strict firewall rules and deploy a host-based intrusion prevention system.
C.Avoid the risk by immediately decommissioning the imaging server and moving all imaging workloads to a cloud provider.
D.Transfer the risk by purchasing cyber insurance that covers medical device downtime and regulatory fines.
AnswerB

Compensating controls such as network segmentation and host-based IPS reduce the likelihood of exploitation while preserving availability for patient care. Because the vendor will not patch the unsupported OS, the risk practitioner must apply layered detective and preventive controls around the asset. This directly addresses the high likelihood of exploitation without requiring downtime or system replacement.

Why this answer

When a critical asset cannot be patched or replaced, compensating controls are the correct mitigation approach. Network segmentation limits lateral movement, and host-based IPS can detect and block exploitation attempts on the unsupported system. These measures reduce likelihood without requiring downtime, unlike acceptance, avoidance, or pure risk transfer, which do not address the technical vulnerability in this operational context.

Exam trap

The trap here is assuming that because the system is critical and cannot be replaced, the only remaining choice is to accept the risk.

442
MCQhard

When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:

A.Reporting IT risks only to the CIO
B.Eliminating IT risk reporting to the board
C.Mapping IT risks to enterprise risk categories
D.Using separate risk scoring for IT risks
AnswerC

Mapping IT risks to enterprise risk categories lets IT risk be aggregated, compared and reported alongside other risks within the ERM framework. Without that alignment, IT risk stays siloed and cannot inform enterprise-level risk appetite or reporting, which is the integration's core purpose.

Why this answer

IT risk should be treated as a component of broader operational risk to ensure alignment with enterprise-level risk appetite and reporting.

443
MCQeasy

An organization's data classification policy labels customer payment records as confidential. A risk practitioner is reviewing how the data is protected at rest in a public cloud object storage bucket. Which control BEST ensures that a misconfigured bucket does not expose the data to unauthorized parties?

A.Enable server-side encryption with a customer-managed key for the object storage bucket.
B.Configure versioning and object lock on the bucket to preserve data integrity and prevent deletion.
C.Enforce bucket policies and access control lists that deny public access and apply least privilege to identities.
D.Enable access logging and monitor the bucket for unusual download activity.
AnswerC

The primary cause of cloud storage exposure is permissive bucket policies or ACLs that grant public or broad access. Enforcing deny-public-access settings and least-privilege identity policies directly prevents unauthorized parties from reading the confidential objects, which is the exact exposure scenario. Encryption complements this but does not substitute for correct access control.

Why this answer

Cloud object storage exposure almost always stems from permissive bucket policies or ACLs. Denying public access and applying least-privilege identity policies prevents unauthorized reads at the point of access, directly protecting confidentiality. Encryption, versioning, and logging are useful complementary controls but do not by themselves stop a misconfiguration from granting access.

Exam trap

The trap here is equating encryption at rest with protection against misconfiguration, when encryption does not restrict access granted by a permissive bucket policy.

444
MCQhard

A risk practitioner at a healthcare insurer is identifying risks for a new telehealth platform. The platform integrates with a third-party video vendor, stores protected health information, and must comply with HIPAA. Which of the following is the MOST appropriate FIRST step in identifying IT risk for this platform?

A.Perform a penetration test of the telehealth platform before go-live.
B.Purchase cyber insurance to transfer the financial impact of a breach.
C.Review the third-party video vendor's SOC 2 report and contract terms.
D.Inventory the platform's assets, data flows, and regulatory obligations to define the risk context.
AnswerD

Risk identification begins with understanding the context: what assets exist, how data moves, who touches it, and what legal or contractual requirements apply. For a telehealth platform handling protected health information, this establishes the scope against which threats, vulnerabilities, and impacts can be assessed. Without this foundation, subsequent activities such as vendor review, testing, or control selection lack a reliable basis and may miss critical exposures.

Why this answer

Effective risk identification starts with establishing context: the assets involved, the data flows, the dependencies, and the regulatory environment. Inventorying the telehealth platform's components, protected health information movement, and HIPAA obligations gives the practitioner the basis to enumerate threats and vulnerabilities. Only after this scope is defined do activities such as vendor assurance review, penetration testing, and insurance decisions become targeted and defensible.

Exam trap

The trap here is jumping to a control or treatment activity such as penetration testing or insurance, which feels proactive but actually assumes the risk identification work is already complete.

445
MCQmedium

An organization is considering purchasing cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?

A.Accept
B.Transfer
C.Avoid
D.Mitigate
AnswerB

Purchasing cyber insurance shifts the financial consequence of a breach to a third party, which is risk transfer. The organisation retains the risk itself but compensates for losses through the insurer, rather than avoiding, mitigating or accepting it.

Why this answer

Purchasing cyber insurance transfers the financial consequences of a data breach to an insurer in exchange for premiums, which is the definition of risk transfer. The organization retains some residual risk (deductibles, uncovered losses, reputational damage), but the primary treatment mechanism is transfer. This is distinct from mitigation, which reduces likelihood or impact through controls.

Exam trap

CRISC often tests the distinction between transfer and mitigate, so the trap is assuming that buying insurance reduces the likelihood or impact of a breach rather than simply shifting financial consequences to a third party.

How to eliminate wrong answers

Option A is wrong because acceptance means acknowledging the risk and taking no action to reduce or transfer it, whereas buying insurance is an active treatment. Option C is wrong because avoidance means eliminating the activity or asset that creates the risk (e.g., not collecting PII at all), not insuring it. Option D is wrong because mitigation reduces the probability or impact through controls such as patching, encryption, or MFA, whereas insurance does not reduce the likelihood of a breach — it only compensates for financial loss.

446
MCQmedium

A retail company uses a third-party vendor for payment processing. The vendor's service level agreement (SLA) requires 99.9% uptime. Recently, there were two incidents of downtime totaling 0.2% in a month, still within the SLA. However, the company's internal risk monitoring detected a pattern of increasing minor incidents. The vendor insists the SLA is met. The risk manager must decide on monitoring and reporting. The company's board wants to understand the risk. What is the best course of action?

A.Request a root cause analysis from the vendor and monitor trend more closely, reporting to board if trend worsens.
B.Terminate the vendor contract.
C.Increase the SLA penalty.
D.Accept the vendor's assurance as SLA is met.
AnswerA

An SLA breach threshold alone cannot detect deteriorating stability; rising minor incidents signal systemic weakness that may precede a major outage. Requesting root cause analysis addresses the underlying cause, while trend monitoring provides early warning, with board escalation tied to worsening patterns rather than the SLA figure.

Why this answer

Even though the SLA is technically met, the emerging pattern of minor incidents is a leading indicator of rising operational risk, so the risk manager should request a root cause analysis and tighten monitoring, escalating to the board only if the trend worsens. This balances contractual reality (SLA not breached) with proactive risk management (trend detection). It also gives the board meaningful, evidence-based information rather than alarmist or premature action.

Exam trap

CRISC often tests the difference between contractual compliance and risk posture — the trap is choosing 'SLA is met, so accept' when the question is really about emerging risk that the board needs visibility into.

How to eliminate wrong answers

Option B is wrong because terminating the contract is a disproportionate response when the SLA is being met and no material loss has occurred — it ignores cost, transition risk, and contractual remedies. Option C is wrong because increasing SLA penalties is a contract renegotiation tactic, not a monitoring/reporting action, and it does not address the underlying incident trend. Option D is wrong because passively accepting the vendor's assurance ignores the internal risk signal and fails the risk manager's duty to monitor and report emerging risks.

447
MCQeasy

A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?

A.EDM03 — Ensure Risk Optimization
B.EDM04 — Ensure Resource Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM01 — Ensure Governance Framework Setting and Maintenance
AnswerA

COBIT 2019's EDM03 governance objective sits within the Evaluate, Direct and Monitor domain and explicitly assigns accountability for ensuring risk management is optimised, aligning risk appetite with enterprise objectives. It is the specific objective covering risk optimisation, not risk identification or treatment execution.

Why this answer

COBIT 2019's governance objectives are organized under the EDM (Evaluate, Direct, Monitor) domain. EDM03 — Ensure Risk Optimization is the specific governance objective that ensures enterprise risk is identified, assessed, and managed within the entity's risk appetite, and that risk management activities are optimized. It is the governance-level counterpart to the management-level APO12 (Manage Risk) objective.

Exam trap

CRISC often tests the distinction between the four EDM objectives (EDM01 governance framework, EDM02 benefits delivery, EDM03 risk optimization, EDM04 resource optimization), so candidates who confuse 'risk optimization' with 'resource optimization' pick EDM04.

How to eliminate wrong answers

Option B is wrong because EDM04 — Ensure Resource Optimization focuses on ensuring that adequate and appropriate resources (people, process, technology) are available and optimized, not on risk optimization. Option C is wrong because EDM02 — Ensure Benefits Delivery focuses on optimizing value delivery from investments and services, i.e., benefits realization, not risk. Option D is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance focuses on establishing and maintaining the governance framework (structures, principles, mechanisms), not specifically on optimizing risk.

448
MCQmedium

During a vendor risk assessment, an organization discovers that a critical vendor has not performed a security assessment in two years. The vendor is tiered as 'medium risk'. According to best practices, what should the risk practitioner recommend?

A.Request a current SOC 2 report or equivalent assessment
B.Downgrade the vendor to low risk to reduce monitoring frequency
C.Accept the risk because the vendor is only medium risk
D.Terminate the relationship immediately
AnswerA

A current SOC 2 report provides independent assurance over the vendor's control environment, closing the two-year evidence gap. Requesting it satisfies the assessment requirement proportionately, since medium-tier vendors warrant validated attestation rather than full on-site audits, enabling informed tiering and remediation decisions.

Why this answer

A SOC 2 report (or equivalent, such as an ISO 27001 certification or a SIG assessment) provides independent assurance over a vendor's controls, including security monitoring and assessment cadence. Since the vendor is tiered as 'medium risk' and has not performed a security assessment in two years, the risk practitioner should request current evidence of control effectiveness rather than accept, ignore, or escalate the risk prematurely. This aligns with the CRISC principle of verifying control status before making risk response decisions.

Exam trap

The trap here is that candidates may assume 'medium risk' automatically justifies risk acceptance (Option C), but CRISC requires that acceptance be based on current control evidence, not just the risk tier label.

How to eliminate wrong answers

Option B is wrong because downgrading a vendor's risk tier to reduce monitoring frequency would violate the risk assessment's integrity; the vendor's lack of assessment indicates a control gap, not a lower inherent risk. Option C is wrong because accepting risk without understanding the current control state (i.e., without a recent assessment) is premature and contradicts the risk response process, which requires informed acceptance based on evidence. Option D is wrong because terminating the relationship immediately is an extreme response that ignores the possibility of obtaining a current assessment or remediation plan; it fails to consider business continuity and the vendor's criticality.

449
MCQeasy

An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?

A.Threat Event Frequency
B.Annualized Loss Expectancy
C.Primary Loss
D.Secondary Loss
AnswerA

Loss Event Frequency decomposes into Threat Event Frequency and Vulnerability, so Threat Event Frequency is a direct LEF input. It measures how often threat agents act against the asset, which then combines with vulnerability to yield loss event frequency.

Why this answer

In the FAIR (Factor Analysis of Information Risk) ontology, Loss Event Frequency (LEF) is composed of Threat Event Frequency (TEF) and Vulnerability (the probability that a threat event becomes a loss event). Threat Event Frequency is therefore a direct component of LEF. Annualized Loss Expectancy, Primary Loss, and Secondary Loss belong to the loss magnitude side of the model, not LEF.

Exam trap

CRISC often tests FAIR taxonomy, so the trap is confusing LEF components (Threat Event Frequency, Vulnerability) with Loss Magnitude components (Primary Loss, Secondary Loss) or with derived metrics like ALE.

How to eliminate wrong answers

Option B is wrong because Annualized Loss Expectancy (ALE) is a derived output (ALE = SLE × ARO) and is not a component of FAIR's LEF; it is a separate quantitative risk metric. Option C is wrong because Primary Loss is part of Loss Magnitude (the other half of FAIR), representing direct losses from a loss event. Option D is wrong because Secondary Loss is also part of Loss Magnitude, representing indirect or follow-on losses such as fines, reputation damage, and legal costs.

450
Multi-Selecthard

Which TWO of the following are valid techniques for identifying risk in IT risk assessment?

Select 2 answers
A.SWOT analysis
B.Brainstorming sessions
C.Residual risk assessment
D.Risk aggregation
E.Monte Carlo simulation
AnswersA, B

SWOT analysis systematically surfaces threats and weaknesses across internal and external dimensions, satisfying the requirement for a structured risk identification technique. It exposes adverse conditions before scoring, directly feeding the IT risk assessment process. This makes it a valid identification method rather than an evaluation or treatment tool.

Why this answer

SWOT analysis (A) is a valid risk-identification technique because it systematically examines Strengths, Weaknesses, Opportunities, and Threats, and the Weaknesses and Threats quadrants directly surface internal and external risks to IT assets and processes. Brainstorming sessions (B) are also a recognized identification technique, as they gather subject-matter experts and stakeholders to openly generate potential risk events, threats, and vulnerabilities before any analysis or prioritization occurs. By contrast, residual risk assessment (C) is not an identification method but an evaluation step performed after controls are applied to determine what risk remains.

Risk aggregation (D) is an analysis/reporting activity that combines individual risks into a portfolio or enterprise view, not a way to discover new risks. Monte Carlo simulation (E) is a quantitative risk-analysis technique used to model probability distributions and outcomes, so it belongs to risk evaluation rather than identification.

Exam trap

The trap here is confusing risk identification techniques (like SWOT and brainstorming) with risk analysis or evaluation techniques (like residual risk assessment, risk aggregation, and Monte Carlo simulation), which are applied after risks have already been identified.

Page 5

Page 6 of 15

Page 7