Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 376450

983 questions total · 14pages · All types, answers revealed

Page 5

Page 6 of 14

Page 7
376
Multi-Selectmedium

Which THREE of the following are characteristics of leading key risk indicators (KRIs)?

Select 3 answers
A.They are predictive in nature.
B.They are based on historical data.
C.They measure past events and losses.
D.They provide early warning of potential risk events.
E.They enable proactive risk mitigation.
AnswersA, D, E

Leading indicators predict future risk levels.

Why this answer

Leading key risk indicators (KRIs) are predictive in nature because they track forward-looking metrics that signal potential future risk events before they occur. Unlike lagging indicators that measure past outcomes, leading KRIs use trend analysis and threshold monitoring to forecast changes in risk exposure, enabling organizations to anticipate and address issues proactively.

Exam trap

The trap here is that candidates often confuse leading KRIs with lagging indicators, mistakenly selecting options that describe historical or past-event measurements because they think all KRIs are backward-looking, but CRISC emphasizes that leading KRIs are forward-looking and predictive.

377
MCQmedium

During a vendor risk assessment, a prospective vendor for critical services cannot provide a SOC 2 Type II report. According to the organization's vendor risk appetite, which action should be taken?

A.Lower the vendor's tier to reduce requirements
B.Accept the vendor's self-assessment instead
C.Reject the vendor or request a formal risk acceptance
D.Onboard the vendor with additional monitoring
AnswerC

This aligns with risk appetite; if risk is accepted, it must be formally documented.

Why this answer

A SOC 2 Type II report provides independent assurance over a service organization's controls over a period of time. When a prospective vendor for critical services cannot provide this report, and the organization's risk appetite is defined, the appropriate action is to reject the vendor or require a formal risk acceptance from the risk owner. This ensures that any deviation from the required control evidence is explicitly acknowledged and approved, rather than bypassing the requirement.

Exam trap

The trap here is that candidates may assume 'additional monitoring' (Option D) is a valid compensating control, but the CRISC exam emphasizes that for critical services, independent assurance (like SOC 2) is a non-negotiable baseline, and monitoring is a detective control, not a preventive or directive control that replaces the need for formal risk acceptance.

How to eliminate wrong answers

Option A is wrong because lowering the vendor's tier to reduce requirements would arbitrarily weaken the control baseline for a critical service, which contradicts the principle of aligning controls with risk criticality. Option B is wrong because accepting a vendor's self-assessment instead of a SOC 2 Type II report removes independent verification, introducing a conflict of interest and potentially hiding control weaknesses. Option D is wrong because onboarding the vendor with additional monitoring does not address the lack of foundational control assurance; monitoring can detect issues but cannot replace the need for pre-contract evidence of control effectiveness.

378
MCQmedium

A new web application is being developed using several open-source libraries. Which risk identification method is most effective for identifying vulnerabilities in these libraries?

A.Static application security testing (SAST)
B.Software composition analysis (SCA)
C.Dynamic application security testing (DAST)
D.Manual code review
AnswerB

SCA scans dependencies and matches them against vulnerability databases, ideal for open-source risk identification.

Why this answer

Software Composition Analysis (SCA) is specifically designed to identify known vulnerabilities in open-source libraries by analyzing dependency manifests (e.g., pom.xml, package.json) and correlating them against vulnerability databases like the National Vulnerability Database (NVD). For a web application built with multiple open-source components, SCA automates the detection of outdated or vulnerable libraries, which is the most effective method for this risk identification scenario.

Exam trap

The trap here is that candidates confuse SAST (which finds code-level bugs) with SCA (which finds library vulnerabilities), assuming any security testing tool can identify open-source risks, but only SCA is designed to inventory and assess third-party components against known CVEs.

How to eliminate wrong answers

Option A is wrong because Static Application Security Testing (SAST) analyzes source code for security flaws in custom application logic (e.g., SQL injection, buffer overflows), but it does not scan or track third-party library dependencies or their known vulnerabilities. Option C is wrong because Dynamic Application Security Testing (DAST) tests the running application for runtime vulnerabilities (e.g., XSS, CSRF) by sending malicious payloads, but it cannot identify vulnerabilities embedded in library versions that are not actively exploited during the test. Option D is wrong because Manual code review, while thorough for custom code, is impractical for large open-source libraries and cannot efficiently cross-reference thousands of library versions against vulnerability databases like SCA does.

379
Multi-Selecteasy

A SIEM generates alerts for the following events. Which TWO events should be considered potential emerging risks? (Select exactly 2.)

Select 2 answers
A.Scheduled backup completed successfully
B.Software update installed on server
C.High number of failed authentication attempts from a single IP
D.Low disk space alert on a file server
E.Unusual increase in outbound traffic from a database server
AnswersC, E

Indicates a brute-force attack attempt.

Why this answer

A high number of failed authentication attempts from a single IP (C) is a classic indicator of a brute-force or password-spraying attack. This represents an emerging risk because it signals active reconnaissance or attempted unauthorized access, which could lead to account compromise or lateral movement if successful.

Exam trap

The trap here is that candidates confuse operational alerts (like low disk space or successful backups) with security risks, failing to recognize that emerging risks must involve active threat indicators such as reconnaissance or anomalous traffic patterns.

380
MCQhard

Based on the exhibit, which of the following poses the HIGHEST risk to the environment?

A.The web servers are in a public subnet
B.The communication between web and application servers is encrypted via HTTPS
C.The application servers use embedded credentials to access the database
D.The database has a direct SSH connection from the internet
AnswerD

Direct internet access to the database, even from a single IP, exposes a critical asset to external threats.

Why this answer

A direct SSH connection from the internet to the database server bypasses all network segmentation and firewall controls, exposing the database to brute-force attacks, credential theft, and unauthorized remote access. SSH is a management protocol, not an application protocol, and its exposure on the internet creates a direct attack surface on the most sensitive data tier, which is the highest risk to the environment.

Exam trap

ISACA often tests the misconception that 'encryption always reduces risk' or that 'public subnets are inherently dangerous,' when in reality the highest risk is exposing management interfaces (like SSH) directly to the internet, not the application-layer exposure of web servers.

How to eliminate wrong answers

Option A is wrong because web servers are typically placed in a public subnet to serve traffic to users; this is a standard architectural design and not inherently high risk as long as proper security groups and WAFs are in place. Option B is wrong because HTTPS encryption between web and application servers protects data in transit from eavesdropping and tampering, which actually reduces risk rather than posing a risk. Option C is wrong because while embedded credentials are a security concern (they can be extracted from code), they do not expose the database to direct internet-based attacks and are a lower risk compared to an open SSH management channel from the internet.

381
Multi-Selecteasy

A risk manager is designing monthly risk reports for senior management. Which THREE of the following should be included in an effective risk report? (Choose three.)

Select 3 answers
A.Names of individual employees responsible for control failures.
B.Changes in the risk landscape.
C.Key risk indicators (KRIs) and their trends.
D.Detailed control test results for every control.
E.Status of risk treatment plans.
AnswersB, C, E

Keeps management informed of external and internal changes.

Why this answer

An effective risk report must communicate changes in the risk landscape, such as new threats, regulatory shifts, or emerging vulnerabilities, to enable senior management to make informed strategic decisions. This ensures the report remains relevant and actionable, reflecting the dynamic nature of risk.

Exam trap

The trap here is that candidates confuse operational detail (like individual blame or exhaustive control results) with strategic reporting, forgetting that senior management needs aggregated, trend-based insights rather than granular data.

382
MCQmedium

In a qualitative risk assessment, a risk owner argues that the likelihood of a cyberattack is low because the organization has strong perimeter defenses. However, the analyst notes that the impact would be catastrophic. Which limitation of qualitative analysis is most relevant?

A.It relies on subjective judgments
B.It is not comparable across organizations
C.It is time-consuming and data-intensive
D.It does not produce financial values
AnswerA

Correct; subjective interpretation of likelihood and impact can vary.

Why this answer

Qualitative analysis is subjective; different stakeholders may interpret likelihood and impact differently based on their perspectives. The risk owner's judgment may be biased by existing controls.

383
MCQhard

A multinational corporation is migrating its customer relationship management (CRM) system to a public cloud provider. The data includes personally identifiable information (PII) from multiple jurisdictions. Which risk should be considered most critical during the cloud architecture review?

A.Multi-tenancy isolation failures
B.Data sovereignty and cross-border data transfer restrictions
C.Shared responsibility model gaps for patching
D.Vendor lock-in due to proprietary APIs
AnswerB

Correct. Data sovereignty is a critical legal risk that must be addressed before migration.

Why this answer

The CRM migration involves PII from multiple jurisdictions, making data sovereignty and cross-border data transfer restrictions the most critical risk. Regulations like GDPR (EU) and local data localization laws (e.g., Russia, China) can impose fines or block transfers if data leaves approved regions. This risk directly impacts legal compliance and operational continuity, outweighing technical concerns like isolation or patching.

Exam trap

The trap here is that candidates confuse technical risks like multi-tenancy or patching with the overriding legal and regulatory risk of data sovereignty, which is the most critical for multinational PII migrations.

How to eliminate wrong answers

Option A is wrong because multi-tenancy isolation failures are a general cloud risk but less critical here; the CRM data is PII, but the primary legal risk is jurisdictional, not technical co-mingling. Option C is wrong because shared responsibility model gaps for patching are operational risks that can be mitigated via SLAs and automated patching, not the most critical for cross-jurisdiction PII. Option D is wrong because vendor lock-in due to proprietary APIs is a long-term strategic risk, not an immediate compliance or legal threat during migration of regulated data.

384
MCQeasy

A retail company is establishing an IT risk universe. Which of the following should be included as a primary category of IT risk?

A.Market risk
B.Third-party risk
C.Inflation risk
D.Interest rate risk
AnswerB

Third-party risk is a core IT risk category.

Why this answer

The IT risk universe should include all potential IT risks, and third-party risks are a key category due to reliance on vendors.

385
MCQhard

A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?

A.Establishment of an electronic security perimeter around critical cyber assets
B.Adoption of a cloud-based backup solution
C.Use of quantum-resistant encryption for all communications
D.Implementation of IEC 62443 security levels
AnswerA

NERC CIP requires defining and securing electronic security perimeters.

Why this answer

NERC CIP standards require identification and protection of critical cyber assets, including clear boundaries (electronic security perimeters) to control access.

386
MCQmedium

A company is implementing a new continuous monitoring tool for its network security controls. Which of the following is the MOST important step to ensure the tool provides meaningful risk information?

A.Configure the tool to generate real-time alerts for all events.
B.Provide training to all users on how to interpret the tool's output.
C.Ensure the tool is integrated with the existing SIEM system.
D.Align the tool's monitoring parameters with key risk indicators and critical controls.
AnswerD

Alignment ensures the tool focuses on what matters for risk management.

Why this answer

A continuous monitoring tool only delivers meaningful risk information when its monitoring parameters are directly aligned with key risk indicators (KRIs) and critical controls. Without this alignment, the tool may generate noise or miss high-severity events, failing to support risk-based decision-making.

Exam trap

The trap here is that candidates confuse operational efficiency (integration with SIEM) or user training with the risk-focused requirement of aligning monitoring to KRIs, which is the core of risk-based monitoring and reporting.

How to eliminate wrong answers

Option A is wrong because configuring the tool to generate real-time alerts for all events would overwhelm analysts with false positives and alert fatigue, obscuring genuine risk signals. Option B is wrong while user training is valuable, it does not address the fundamental need for the tool to monitor the right parameters; training on interpreting output is useless if the data itself is irrelevant. Option C is wrong because integration with a SIEM system is a technical convenience for log aggregation, but it does not ensure that the monitored data corresponds to KRIs or critical controls; the tool could still produce meaningless data even if integrated.

387
MCQhard

During a VAST threat modeling session for a DevSecOps pipeline, the team focuses on threats that align with agile development. Which of the following is a key advantage of VAST?

A.It requires detailed system architecture upfront
B.It replaces the need for vulnerability scanning
C.It is tailored for use in agile and DevOps environments
D.It focuses on compliance requirements only
AnswerC

VAST supports iterative development.

Why this answer

VAST is designed to integrate with agile and DevOps, providing continuous threat modeling.

388
MCQmedium

A risk practitioner is reviewing the monitoring reports for a critical business process. The report shows that a key control has a 95% effectiveness rate, but the risk appetite for the associated risk is 98%. What should the practitioner do?

A.Accept the current effectiveness as it is close to the target.
B.Immediately escalate to senior management.
C.Recommend enhancements to the control to improve effectiveness.
D.Reduce the risk appetite to 95%.
AnswerC

Aligns control with risk appetite.

Why this answer

The control effectiveness (95%) is below the risk appetite threshold (98%), meaning the residual risk exceeds the acceptable level. The practitioner should recommend enhancements to close this gap, as accepting the current state would violate risk appetite. This aligns with the principle that controls must be improved when monitoring shows performance below the defined tolerance.

Exam trap

The trap here is that candidates may think 'close enough' (Option A) is acceptable, but CRISC requires strict adherence to risk appetite thresholds, not approximations.

How to eliminate wrong answers

Option A is wrong because accepting a 95% effectiveness when the risk appetite is 98% means the residual risk is above the acceptable threshold, which is not permissible; 'close to the target' is not sufficient in risk management. Option B is wrong because immediate escalation to senior management is premature; the practitioner should first analyze the gap and recommend control improvements, as escalation is reserved for critical failures or when remediation is beyond the practitioner's authority. Option D is wrong because reducing the risk appetite to match the current control performance is a reactive and inappropriate approach; risk appetite is set by the board and should drive control improvement, not be lowered to accommodate weak controls.

389
Multi-Selectmedium

An organization is evaluating risk treatment options for a critical vulnerability. Which TWO options would be considered risk mitigation?

Select 2 answers
A.Purchase cyber insurance
B.Accept the risk with formal sign-off
C.Discontinue the vulnerable service
D.Deploy an intrusion prevention system
E.Implement a security patch
AnswersD, E

IPS reduces likelihood of successful attack.

Why this answer

Deploying an intrusion prevention system (IPS) is a risk mitigation measure because it actively monitors and blocks malicious traffic targeting the vulnerability, reducing the likelihood of exploitation. Implementing a security patch directly removes the vulnerability, thereby reducing both the likelihood and impact of a potential attack. Both actions modify the risk by applying technical controls to lower the residual risk level.

Exam trap

The trap here is confusing risk mitigation (reducing likelihood/impact through controls) with risk transfer (insurance), risk acceptance (formal sign-off), or risk avoidance (discontinuing the service), which are distinct treatment options in the CRISC risk response framework.

390
MCQhard

A risk manager discovers that a business unit has been using an unapproved software-as-a-service (SaaS) application for three months. The application stores customer PII. Which of the following risk identification techniques should the risk manager use to understand the full extent of the risk?

A.Run an automated data discovery tool across the network
B.Interview the business unit head about the application's use and data stored
C.Request an independent audit of the SaaS provider
D.Review network logs to identify data transfers to the SaaS provider
AnswerB

Interview provides context on what data is stored and why, critical for risk identification.

Why this answer

Interviewing the business unit head is the most direct and effective technique to understand the full extent of the risk. The risk manager needs to know the specific business processes, the types and volume of PII stored, the purpose of the application, and how data flows into and out of the SaaS application. Automated tools or logs can only provide technical evidence of usage, but they cannot capture the business context, data classification, or the actual data handling practices that define the risk's scope.

Exam trap

The trap here is that candidates often choose an automated or technical option (like A or D) because they seem objective and efficient, but the question specifically asks for a technique to 'understand the full extent of the risk,' which requires human insight into business context and data handling, not just technical detection.

How to eliminate wrong answers

Option A is wrong because running an automated data discovery tool across the network can identify the presence of the SaaS application and data transfers, but it cannot determine the business purpose, the exact PII fields stored, or the data handling procedures, which are essential for understanding the full risk extent. Option C is wrong because requesting an independent audit of the SaaS provider is a reactive and external step that assumes the provider will cooperate and that the risk manager already knows the scope of data shared; it does not help the risk manager initially understand the internal usage and data stored. Option D is wrong because reviewing network logs can show data transfers to the SaaS provider, but logs alone cannot reveal the specific PII content, the business justification, or the data lifecycle within the application, leaving significant gaps in risk understanding.

391
MCQeasy

Which risk treatment option is being used when an organization decides to stop a business activity that creates a high-risk exposure?

A.Avoid
B.Accept
C.Mitigate
D.Transfer
AnswerA

Correct; avoidance eliminates the risk by discontinuing the activity.

Why this answer

When an organization stops a business activity that creates high-risk exposure, it is applying the risk avoidance treatment option. This is a deliberate decision to eliminate the risk entirely by discontinuing the associated process, system, or operation, rather than attempting to reduce or transfer the residual risk. In IT risk management, avoidance is often chosen when the cost or impact of mitigation exceeds the benefit of the activity, or when the risk level is intolerable under any control scenario.

Exam trap

The trap here is that candidates often confuse 'avoid' with 'mitigate,' thinking that any action to reduce risk is avoidance, but CRISC specifically tests that avoidance means completely eliminating the risk by discontinuing the activity, not just applying controls to lower it.

How to eliminate wrong answers

Option B (Accept) is wrong because risk acceptance involves acknowledging the risk and its potential impact without taking action to reduce it, which is the opposite of stopping the activity. Option C (Mitigate) is wrong because mitigation involves implementing controls to reduce the likelihood or impact of the risk while continuing the activity, not ceasing it entirely. Option D (Transfer) is wrong because risk transfer shifts the financial burden of the risk to a third party (e.g., via insurance or outsourcing) but does not stop the underlying business activity or eliminate the operational exposure.

392
Multi-Selectmedium

A risk assessment for a financial trading platform has identified a high-risk vulnerability in the order matching engine. The risk owner has recommended implementing compensating controls rather than fixing the underlying code. Which TWO of the following are valid compensating controls? (Choose two.)

Select 2 answers
A.Rewrite the order matching engine in a memory-safe language
B.Deploy a Web Application Firewall (WAF) to block malicious payloads
C.Enable detailed logging for all order matching transactions
D.Require manual approval for all orders above a threshold
E.Implement rate limiting on order submissions
AnswersD, E

Manual approval adds a human verification step, reducing the impact of a potential exploit.

Why this answer

Requiring manual approval for orders above a threshold directly reduces the impact of a successful exploit by preventing large-scale financial loss, even if the underlying code vulnerability remains unpatched. This compensating control shifts the risk acceptance decision to a human operator, effectively adding a business logic layer that can catch anomalous or malicious order matching attempts. Option E is correct because rate limiting on order submissions mitigates the risk of an attacker exploiting the vulnerability to submit a high volume of malicious orders, thereby limiting the blast radius and preventing denial-of-service or market manipulation scenarios.

Exam trap

The trap here is that candidates confuse detective controls (logging) or remediation (rewriting code) with compensating controls, failing to recognize that a compensating control must actively reduce risk without fixing the original vulnerability.

393
Multi-Selecthard

A company's IT risk team is conducting a risk identification exercise for a new blockchain-based supply chain solution. Which THREE risks are MOST specific to this technology?

Select 3 answers
A.51% attack on the underlying consensus mechanism.
B.Incompatibility with legacy database systems.
C.High electricity consumption of mining nodes.
D.Smart contract vulnerabilities leading to unintended execution.
E.Cryptographic key management failures.
AnswersA, D, E

Consensus attacks are specific to blockchain.

Why this answer

A 51% attack is a specific risk to blockchain consensus mechanisms where a single entity or group gains majority hashing power, allowing them to reverse transactions or prevent new blocks from being confirmed. This directly undermines the integrity and immutability that blockchain promises for the supply chain solution.

Exam trap

ISACA often tests the distinction between generic IT risks and technology-specific risks, so candidates mistakenly select 'high electricity consumption' without considering that many blockchain implementations (especially in enterprise supply chains) do not use energy-intensive proof-of-work.

394
Multi-Selecteasy

Which TWO of the following are primary sources of risk identification for IT projects? (Select exactly 2.)

Select 2 answers
A.Security baseline
B.Project documentation
C.Risk treatment plan
D.Firewall logs
E.Lessons learned from previous projects
AnswersB, E

Requirements, design, and architecture documents contain information to identify risks.

Why this answer

Project documentation (Option B) is a primary source of risk identification because it contains the project scope, schedule, requirements, and assumptions that directly reveal potential risks such as resource constraints or scope creep. Lessons learned from previous projects (Option E) provide empirical data on actual risks encountered, mitigation effectiveness, and failure patterns, making them a critical input for identifying risks in new IT projects. Both sources are explicitly cited in the CRISC Review Manual as foundational inputs for the risk identification process.

Exam trap

The trap here is that candidates confuse operational artifacts (like firewall logs or security baselines) with project-level risk identification sources, or mistakenly think the risk treatment plan is an input rather than an output of the risk identification process.

395
MCQhard

During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?

A.The degree to which the risk affects strategic business objectives
B.The ease of implementing mitigating controls
C.The likelihood that the threat will be exploited
D.The financial impact calculated in monetary terms
AnswerA

Risks that impact strategic objectives are of highest priority.

Why this answer

In CRISC, risk prioritization is fundamentally driven by alignment with strategic business objectives because IT risk management exists to protect the enterprise’s mission and goals. Even a high-likelihood or high-financial-impact risk may be deprioritized if it does not materially affect the organization’s strategic objectives, as the risk treatment decision must support business value and continuity. This weighting ensures that resources are allocated to risks that most threaten the enterprise’s ability to achieve its core mission.

Exam trap

ISACA often tests the misconception that financial impact or likelihood should be the primary weighting factor, but CRISC emphasizes that strategic alignment is the overriding criterion because risk treatment must support the enterprise’s overall business goals, not just minimize cost or probability.

How to eliminate wrong answers

Option B is wrong because the ease of implementing mitigating controls is a tactical implementation consideration, not a primary risk prioritization factor; prioritizing based on ease can lead to treating low-impact risks while ignoring critical strategic threats. Option C is wrong because likelihood alone is insufficient—a threat with high likelihood but negligible business impact should not be weighted more heavily than a lower-likelihood risk that could cripple strategic objectives. Option D is wrong because financial impact in isolation ignores non-monetary strategic factors such as reputational damage, regulatory compliance, or competitive advantage, which may be more critical to the enterprise’s survival than a simple dollar figure.

396
MCQmedium

Based on the exhibit, what is the primary risk to the organization?

A.Unauthorized modification of customer data
B.Data loss due to accidental deletion
C.Unauthorized disclosure of sensitive customer data
D.Denial of service due to excessive read requests
AnswerC

Public access exposes data to anyone on the internet.

Why this answer

The exhibit shows a database server with customer data accessible via a web application that uses unencrypted HTTP (port 80) and has direct internet exposure. This configuration allows an attacker to intercept traffic or exploit the lack of encryption to read sensitive customer data in transit, making unauthorized disclosure the primary risk. The core reasoning is that unencrypted HTTP exposes data to eavesdropping and man-in-the-middle attacks, directly violating confidentiality requirements for sensitive customer information.

Exam trap

The trap here is that candidates often focus on the database server's role (e.g., modification or deletion risks) instead of recognizing that the unencrypted HTTP exposure directly enables unauthorized disclosure of data in transit, which is the most immediate and severe risk to confidentiality.

How to eliminate wrong answers

Option A is wrong because unauthorized modification of customer data requires write access or injection vulnerabilities (e.g., SQL injection), but the exhibit only shows read access via HTTP without any indication of write capabilities or input validation flaws. Option B is wrong because data loss due to accidental deletion typically involves lack of backups or improper access controls on delete operations, whereas the exhibit highlights unencrypted read access and internet exposure, not deletion risks. Option D is wrong because denial of service due to excessive read requests would require a resource exhaustion scenario (e.g., lack of rate limiting or DDoS protection), but the primary risk from unencrypted HTTP is data exposure, not availability.

397
Multi-Selecthard

Which THREE of the following are best practices for reporting risk and control monitoring results to stakeholders?

Select 3 answers
A.Tailor the report to the audience's level of understanding.
B.Include trend analysis and comparisons to thresholds.
C.Include detailed technical logs for each control.
D.Provide reports only when issues occur.
E.Highlight changes in risk exposure and control effectiveness.
AnswersA, B, E

Customization improves comprehension.

Why this answer

Risk and control monitoring reports must be tailored to the audience's level of understanding to ensure that stakeholders can effectively interpret the information. For example, an executive summary should focus on high-level risk exposure and strategic impacts, while detailed reports for control owners may include operational metrics. This practice aligns with the principle of communicating risk information in a manner that supports informed decision-making.

Exam trap

The trap here is that candidates may mistakenly think that providing detailed technical logs (Option C) demonstrates thoroughness, when in fact it undermines the goal of clear, actionable reporting by overwhelming the audience with irrelevant data.

398
MCQhard

A government agency is migrating its critical applications to a public cloud infrastructure. The risk assessment reveals that the cloud provider uses shared tenancy, and the agency's sensitive data will be stored alongside other customers' data. The agency has a very low risk appetite for data leakage and must comply with strict data sovereignty laws. The cloud provider offers data encryption at rest and in transit, as well as dedicated hardware security modules (HSMs) for key management. However, the provider's physical datacenters are located in another country with different legal frameworks. As the risk practitioner, which of the following should be the PRIMARY risk response?

A.Avoid the risk by keeping sensitive data on-premises and using the cloud only for non-sensitive workloads.
B.Reduce the risk by negotiating a contract that includes specific data handling clauses and audit rights.
C.Transfer the risk by requiring the provider to maintain a large cyber insurance policy.
D.Accept the risk after verifying the provider's compliance certifications.
AnswerA

Avoidance is appropriate given low risk appetite.

Why this answer

The agency's very low risk appetite for data leakage and strict data sovereignty laws cannot be adequately mitigated by encryption or contractual measures when the physical datacenters are in a foreign jurisdiction with different legal frameworks. Shared tenancy in a public cloud inherently increases the attack surface for side-channel attacks and misconfiguration risks, and even with encryption at rest (e.g., AES-256) and in transit (e.g., TLS 1.3), the cloud provider's staff or foreign legal authorities could potentially access decryption keys or compel key disclosure. Avoiding the risk by keeping sensitive data on-premises eliminates the exposure to foreign legal frameworks and shared tenancy, directly aligning with the agency's risk appetite.

Exam trap

The trap here is that candidates often overestimate the effectiveness of encryption and contractual controls, failing to recognize that physical jurisdiction and shared tenancy introduce residual risks that cannot be fully mitigated, making avoidance the only appropriate response for a very low risk appetite.

How to eliminate wrong answers

Option B is wrong because negotiating data handling clauses and audit rights reduces but does not eliminate the risk; the provider's physical location in another country means local laws (e.g., the US CLOUD Act or EU GDPR cross-border transfer restrictions) could override contractual terms, and shared tenancy still exposes the data to potential side-channel attacks or misconfiguration by other tenants. Option C is wrong because transferring risk via cyber insurance does not prevent data leakage or address sovereignty laws; insurance only provides financial compensation after a breach, which is unacceptable for an agency with a very low risk appetite for data leakage. Option D is wrong because accepting the risk after verifying compliance certifications (e.g., ISO 27001, SOC 2) is insufficient; certifications attest to controls at a point in time but do not guarantee protection against foreign legal compulsion or shared tenancy vulnerabilities, and acceptance contradicts the stated very low risk appetite.

399
MCQhard

When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:

A.Reporting IT risks only to the CIO
B.Eliminating IT risk reporting to the board
C.Mapping IT risks to enterprise risk categories
D.Using separate risk scoring for IT risks
AnswerC

Mapping ensures IT risks are included in the enterprise risk taxonomy.

Why this answer

IT risk should be treated as a component of broader operational risk to ensure alignment with enterprise-level risk appetite and reporting.

400
MCQmedium

An organization is considering purchasing cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?

A.Accept
B.Transfer
C.Avoid
D.Mitigate
AnswerB

Correct; insurance transfers financial risk to the insurer.

Why this answer

Transferring risk to a third party, such as an insurance company, is a risk transfer strategy. The insurance company assumes the financial risk in exchange for premiums.

401
MCQmedium

A retail company uses a third-party vendor for payment processing. The vendor's service level agreement (SLA) requires 99.9% uptime. Recently, there were two incidents of downtime totaling 0.2% in a month, still within the SLA. However, the company's internal risk monitoring detected a pattern of increasing minor incidents. The vendor insists the SLA is met. The risk manager must decide on monitoring and reporting. The company's board wants to understand the risk. What is the best course of action?

A.Request a root cause analysis from the vendor and monitor trend more closely, reporting to board if trend worsens.
B.Terminate the vendor contract.
C.Increase the SLA penalty.
D.Accept the vendor's assurance as SLA is met.
AnswerA

Proactive management of increasing incidents aligns with risk monitoring best practices.

Why this answer

The increasing trend of incidents indicates potential risk even though the SLA is met. Requesting a root cause analysis and monitoring the trend closely allows proactive risk management and escalation to the board if the trend worsens. This aligns with best practices for risk monitoring and reporting.

Terminating the contract (B) is too drastic for minor incidents. Increasing the SLA penalty (C) may not address the underlying pattern. Accepting the vendor's assurance (D) ignores the emerging risk.

402
MCQeasy

A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?

A.EDM03 — Ensure Risk Optimization
B.EDM04 — Ensure Resource Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM01 — Ensure Governance Framework Setting and Maintenance
AnswerA

EDM03 directly addresses risk optimization through evaluation, direction, and monitoring.

Why this answer

COBIT 2019's EDM03 (Ensure Risk Optimization) is the governance objective that directs the evaluation, direction, and monitoring of risk management to align with enterprise risk appetite.

403
MCQmedium

During a vendor risk assessment, an organization discovers that a critical vendor has not performed a security assessment in two years. The vendor is tiered as 'medium risk'. According to best practices, what should the risk practitioner recommend?

A.Request a current SOC 2 report or equivalent assessment
B.Downgrade the vendor to low risk to reduce monitoring frequency
C.Accept the risk because the vendor is only medium risk
D.Terminate the relationship immediately
AnswerA

This ensures the organization has up-to-date information on the vendor's controls.

Why this answer

A SOC 2 report (or equivalent, such as an ISO 27001 certification or a SIG assessment) provides independent assurance over a vendor's controls, including security monitoring and assessment cadence. Since the vendor is tiered as 'medium risk' and has not performed a security assessment in two years, the risk practitioner should request current evidence of control effectiveness rather than accept, ignore, or escalate the risk prematurely. This aligns with the CRISC principle of verifying control status before making risk response decisions.

Exam trap

The trap here is that candidates may assume 'medium risk' automatically justifies risk acceptance (Option C), but CRISC requires that acceptance be based on current control evidence, not just the risk tier label.

How to eliminate wrong answers

Option B is wrong because downgrading a vendor's risk tier to reduce monitoring frequency would violate the risk assessment's integrity; the vendor's lack of assessment indicates a control gap, not a lower inherent risk. Option C is wrong because accepting risk without understanding the current control state (i.e., without a recent assessment) is premature and contradicts the risk response process, which requires informed acceptance based on evidence. Option D is wrong because terminating the relationship immediately is an extreme response that ignores the possibility of obtaining a current assessment or remediation plan; it fails to consider business continuity and the vendor's criticality.

404
MCQeasy

An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?

A.Threat Event Frequency
B.Annualized Loss Expectancy
C.Primary Loss
D.Secondary Loss
AnswerA

Threat Event Frequency is a factor in LEF.

Why this answer

In FAIR, Loss Event Frequency = Threat Event Frequency × Vulnerability.

405
Multi-Selecthard

Which TWO of the following are valid techniques for identifying risk in IT risk assessment?

Select 2 answers
A.SWOT analysis
B.Brainstorming sessions
C.Residual risk assessment
D.Risk aggregation
E.Monte Carlo simulation
AnswersA, B

SWOT helps identify strengths, weaknesses, opportunities, and threats.

Why this answer

SWOT analysis (Strengths, Weaknesses, Opportunities, Threats) is a structured technique used to identify both internal and external risk factors during IT risk assessment. It helps uncover threats that could exploit weaknesses, as well as opportunities that might mitigate risks, making it a valid identification method.

Exam trap

The trap here is confusing risk identification techniques (like SWOT and brainstorming) with risk analysis or evaluation techniques (like residual risk assessment, risk aggregation, and Monte Carlo simulation), which are applied after risks have already been identified.

406
MCQeasy

When implementing a new control, which of the following is the most important factor in ensuring its long-term effectiveness?

A.Selecting a control owner
B.Updating documentation
C.Conducting user training
D.Performing cost-benefit analysis
AnswerB

Documentation supports proper operation, training, and auditability, which are key to long-term effectiveness.

Why this answer

Documentation updates ensure that the control operates correctly and can be maintained, audited, and improved over time.

407
Multi-Selectmedium

A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?

Select 2 answers
A.Risk heat map
B.Individual employee performance metrics
C.Detailed technical logs
D.Top risks and their status
E.List of all IT assets
AnswersA, D

Provides a visual overview of risk levels.

Why this answer

A risk heat map is a critical visual tool for risk reporting because it provides a concise, at-a-glance view of the likelihood and impact of identified risks, enabling the IT risk committee to quickly prioritize and make informed decisions. It directly supports the Risk Response and Reporting domain by summarizing complex risk data into actionable insights, which is essential for quarterly governance meetings.

Exam trap

The trap here is that candidates confuse operational data (like logs or asset lists) with strategic risk reporting content, failing to recognize that the committee needs summarized, decision-supporting visuals (heat map) and prioritized risk status, not raw technical details.

408
MCQhard

An organization's risk register contains a scenario: 'A nation-state actor exploits an unpatched vulnerability in a public-facing web application, leading to data exfiltration of customer PII.' According to ISACA's risk scenario template, which element is MISSING from this description?

A.Detection
B.Timing
C.Consequence
D.Vulnerability
AnswerB

Correct. The scenario does not specify when the exploit occurs (e.g., during business hours, after hours, or over a period).

Why this answer

ISACA's risk scenario template includes: actor, threat type, event, asset/resource, timing, detection, and response. The scenario lacks timing (when the event occurs or duration).

409
Multi-Selectmedium

An organization is reviewing its IT risk management program and identifies that the risk register is not being updated after project changes. Which TWO components of the risk management program are most likely deficient?

Select 2 answers
A.Risk register
B.Risk management policy
C.Risk reporting
D.Risk assessment methodology
E.Risk treatment process
AnswersB, C

The policy should mandate regular updates; its absence leads to outdated registers.

Why this answer

The risk management policy (B) is deficient because it should mandate periodic updates to the risk register after project changes, ensuring alignment with the organization's risk appetite and tolerance. Without a policy that explicitly requires post-change risk reassessment, the process lacks governance and accountability. Risk reporting (C) is also deficient because it fails to communicate the updated risk status to stakeholders, which is critical for informed decision-making and maintaining an accurate risk posture.

Exam trap

The trap here is that candidates see the risk register is not being updated and immediately select it as deficient, but the question asks for the components of the program that are most likely deficient—the register is the output, not the process component; the deficiency is in the policy that mandates updates and the reporting that communicates changes.

410
MCQmedium

An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?

A.Vendor lock-in to proprietary protocols
B.Expanded attack surface with unpatched devices
C.Insufficient bandwidth for data transmission
D.Data integrity issues from sensor malfunction
AnswerB

Correct. Many unpatched IoT devices create a large attack surface.

Why this answer

IoT devices often lack security updates, making them vulnerable to exploitation. The expanded attack surface from many devices compounds this risk.

411
MCQmedium

During an IT risk assessment, the risk team calculates the Annualized Loss Expectancy (ALE) for a critical application. Which quantitative risk analysis framework is most commonly used for this calculation?

A.NIST SP 800-30
B.FAIR
C.ISO 31000
D.COBIT 5
AnswerB

FAIR is a quantitative framework that models risk as a function of Loss Event Frequency and Loss Magnitude, used to compute ALE.

Why this answer

The Factor Analysis of Information Risk (FAIR) framework is the most commonly used quantitative risk analysis framework for calculating Annualized Loss Expectancy (ALE) because it provides a structured, probabilistic approach to decompose risk into loss event frequency and loss magnitude. Unlike qualitative frameworks, FAIR enables precise ALE computation by modeling threat event frequency, vulnerability, and probable loss, making it the standard for quantitative IT risk assessments in the CRISC domain.

Exam trap

The trap here is that candidates often confuse NIST SP 800-30 as the standard for quantitative ALE calculation because it is widely used for risk assessments, but it is primarily qualitative and does not provide the specific quantitative decomposition that FAIR does.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-30 is primarily a qualitative risk assessment framework that provides guidelines for conducting risk assessments but does not define the specific quantitative formulas (like ALE = SLE × ARO) or the probabilistic decomposition required for ALE calculation. Option C is wrong because ISO 31000 is a generic risk management standard that outlines principles and processes for any organization, but it does not prescribe a specific quantitative methodology or formula for calculating ALE. Option D is wrong because COBIT 5 is a governance and management framework for enterprise IT that focuses on control objectives and process maturity, not on quantitative risk analysis calculations like ALE.

412
MCQeasy

Which of the following is the PRIMARY purpose of a risk register?

A.To calculate the organization's risk appetite
B.To report risks to regulatory authorities
C.To track the status of risk treatment plans
D.To document and manage identified risks throughout their lifecycle
AnswerD

This is the primary purpose of a risk register.

Why this answer

The risk register is a central repository for documenting identified risks, their analysis, and planned responses, enabling ongoing monitoring and management.

413
MCQhard

A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?

A.Multi-tenancy isolation vulnerabilities
B.Vendor lock-in due to proprietary APIs
C.Shared responsibility model gaps
D.Data sovereignty and cross-border data transfer restrictions
AnswerD

Data residency laws can conflict, leading to non-compliance if data is stored in an unauthorized location.

Why this answer

Data sovereignty issues arise when data is stored in jurisdictions with conflicting or unknown legal frameworks, posing significant compliance risk.

414
Multi-Selecthard

An organization is implementing continuous monitoring for its critical systems. Which TWO of the following are examples of continuous monitoring techniques? (Select TWO)

Select 2 answers
A.Continuous vulnerability scanning
B.Weekly review of access logs by a manager
C.Automated SIEM rules to detect anomalies
D.Annual penetration testing
E.Quarterly control testing by internal audit
AnswersA, C

Automated scanning can run continuously to detect new vulnerabilities.

Why this answer

Continuous monitoring involves automated, ongoing checks. SIEM rules continuously analyze logs for threats, and vulnerability scanning can be automated to run continuously or frequently.

415
Drag & Dropmedium

Order the steps for change management in an IT environment.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Change management includes request, approval, testing, implementation, and review.

416
Multi-Selectmedium

A financial services company is implementing a new control to mitigate the risk of unauthorized access to customer data. Which TWO of the following are key factors to consider during the control design phase?

Select 2 answers
A.Assigning control ownership to a specific individual or team
B.Conducting a cost-benefit analysis comparing annual control cost to ALE reduction
C.Performing user training on the new control
D.Developing a detailed control implementation plan
E.Selecting the control type (preventive, detective, or corrective)
AnswersB, E

Cost-benefit analysis ensures the control is economically justified.

Why this answer

A cost-benefit analysis comparing the annualized cost of the control to the reduction in Annualized Loss Expectancy (ALE) is a key factor during control design because it ensures the control is economically justified. This aligns with the risk response principle that the cost of mitigation should not exceed the risk reduction benefit, a core tenet of quantitative risk analysis in CRISC.

Exam trap

CRISC often tests the distinction between design-phase activities (like selecting control type and cost-benefit analysis) versus implementation or operational activities (like assigning ownership or training), leading candidates to confuse 'what to design' with 'how to run' the control.

417
MCQmedium

The exhibit shows a control monitoring configuration in JSON format. Which of the following is the MOST critical gap in this monitoring setup?

A.The control was last tested over a month ago
B.The data source 'transaction_log' is not specific enough
C.The monitoring frequency is set to daily, which may miss real-time breaches
D.There is no action defined for when the threshold is first breached
AnswerD

The escalation levels only trigger after 1 and 4 hours, but no action on initial breach.

Why this answer

The JSON configuration defines a threshold but lacks any corresponding action (e.g., alert, ticket, or automated response) to be triggered when the threshold is first breached. Without an action, the monitoring setup cannot notify or initiate a response, rendering the threshold definition useless for risk mitigation. This is the most critical gap as it directly undermines the control's ability to detect and react to risk events in a timely manner.

Exam trap

The trap here is that candidates focus on operational details like frequency or data source specificity, but the CRISC exam emphasizes that a monitoring setup is incomplete without a defined response action to trigger on threshold breach.

How to eliminate wrong answers

Option A is wrong because the 'lastTested' field indicates the control was tested over a month ago, but testing frequency is separate from monitoring configuration; the JSON defines monitoring parameters, not testing schedules, so this is not a gap in the monitoring setup itself. Option B is wrong because 'transaction_log' as a data source is sufficiently specific for monitoring purposes; the JSON does not require a more granular source like a table name, and the data source can be refined at the query level. Option C is wrong because daily monitoring frequency is appropriate for many risk scenarios, and the JSON does not specify a requirement for real-time monitoring; the critical gap is the missing action, not the frequency.

418
Multi-Selectmedium

Which TWO of the following are appropriate actions when a control deficiency is identified during monitoring? (Select exactly two.)

Select 2 answers
A.Increase the risk appetite
B.Document the deficiency and its impact
C.Assign a remediation plan with deadlines
D.Ignore if the deficiency is minor
E.Immediately terminate the control owner
AnswersB, C

Proper documentation is essential.

Why this answer

Documenting the deficiency and its impact is a fundamental step in the risk and control monitoring process. It ensures that the nature, severity, and potential consequences of the control failure are formally recorded, which is essential for risk assessment, reporting, and audit trails. Without this documentation, the organization cannot properly evaluate the risk exposure or justify remediation efforts.

Exam trap

The trap here is that candidates may confuse 'immediate termination' (Option E) with accountability, but CRISC emphasizes corrective and preventive actions over punitive measures, and ignoring minor deficiencies (Option D) violates the principle of continuous monitoring.

419
MCQmedium

An organization is implementing a new access control system. The project manager is concerned about delays due to user training requirements. Which of the following should the risk practitioner prioritize to ensure effective control implementation?

A.Accelerate the deployment to meet the project deadline
B.Implement a compensating control to reduce training requirements
C.Delay the entire project until training can be completed
D.Ensure user training is completed before go-live
AnswerD

Training is essential for users to understand and follow the new access control procedures.

Why this answer

User training is a critical success factor for access control systems because misconfigured or improperly used controls can lead to security gaps. Ensuring training is completed before go-live (Option D) aligns with the principle that a control is only effective if users understand how to operate it correctly, preventing human error that could bypass the control's intended protections.

Exam trap

The trap here is that candidates may choose Option B (compensating control) thinking it is a valid risk treatment, but the question asks for what ensures effective control implementation, not just risk reduction—training is non-negotiable for the primary control to work as designed.

How to eliminate wrong answers

Option A is wrong because accelerating deployment to meet a deadline sacrifices control effectiveness; a rushed rollout without user training increases the risk of misconfiguration and security incidents. Option B is wrong because implementing a compensating control to reduce training requirements does not address the root cause—users must still understand the primary access control system to avoid errors that the compensating control cannot fully mitigate. Option C is wrong because delaying the entire project is unnecessarily disruptive; training can be completed in parallel with other project phases, and a full delay may introduce new risks from prolonged use of legacy systems.

420
MCQhard

During a vendor risk tiering exercise, a vendor that stores the organization's customer PII and is critical for daily operations should be classified as which tier?

A.Critical
B.Medium
C.High
D.Low
AnswerA

Critical tier applies to vendors with sensitive data and essential services.

Why this answer

Vendors with access to sensitive data and high service criticality are typically classified as critical (highest tier).

421
MCQmedium

An organization maintains a risk register. Which of the following updates should be made on an ongoing basis?

A.Continuously add new risks as they are identified
B.Update controls only when an incident occurs
C.Revise risk levels only after an internal audit
D.Update the register only during the annual risk assessment
AnswerA

An effective risk register is a living document updated whenever new risks arise.

Why this answer

A risk register is a living document that must be updated continuously to reflect the current threat landscape. New risks can emerge from changes in technology, business processes, or external threats, and failing to capture them promptly leaves the organization exposed to unmitigated vulnerabilities.

Exam trap

The trap here is that candidates often assume risk registers are updated only during formal assessment cycles, but the CRISC exam emphasizes that risk management is a continuous process requiring real-time updates as new risks are identified.

How to eliminate wrong answers

Option B is wrong because controls should be reviewed and updated proactively based on risk changes, not only reactively after an incident occurs. Option C is wrong because risk levels should be revised whenever new information or changes in the environment affect the likelihood or impact, not only after an internal audit. Option D is wrong because an annual update cycle is too infrequent; risks can emerge or change significantly within a year, and the register must be maintained on an ongoing basis to remain relevant.

422
Multi-Selectmedium

A risk analyst is performing a quantitative risk analysis using the FAIR framework. Which TWO factors are multiplied to calculate Loss Event Frequency (LEF)?

Select 2 answers
A.Loss Magnitude
B.Annualized Rate of Occurrence
C.Threat Event Frequency
D.Single Loss Expectancy
E.Vulnerability
AnswersC, E

TEF is one component of LEF.

Why this answer

LEF = Threat Event Frequency (TEF) × Vulnerability (V).

423
MCQmedium

A retail company recently deployed a point-of-sale (POS) system that processes credit card transactions. The system is connected to the corporate network and transmits transaction data to a payment processor over the internet. During a risk assessment, the IT risk manager identifies that the POS system is vulnerable to malware injection via unvalidated input from barcode scanners. Which of the following is the MOST appropriate risk mitigation strategy?

A.Encrypt all transaction data in transit using TLS 1.2.
B.Install a next-generation firewall at the internet boundary.
C.Implement network segmentation to isolate the POS system from the corporate network.
D.Deploy application-layer input validation and sanitization for barcode scanner inputs.
AnswerD

Input validation directly prevents injection attacks.

Why this answer

The most appropriate risk mitigation strategy because the vulnerability is specifically malware injection via unvalidated input from barcode scanners. Application-layer input validation and sanitization directly addresses the root cause by ensuring that only expected, safe data is processed by the POS system, preventing injection attacks at the point of entry.

Exam trap

The trap here is that candidates often choose network-level controls like firewalls or encryption, overlooking that the vulnerability originates from local input that never traverses the network boundary.

How to eliminate wrong answers

Option A is wrong because encrypting transaction data in transit with TLS 1.2 protects data confidentiality during transmission but does not prevent malware injection through barcode scanner input. Option B is wrong because a next-generation firewall at the internet boundary inspects traffic leaving or entering the network, but it cannot validate input from a local barcode scanner connected directly to the POS system. Option C is wrong because network segmentation isolates the POS system from the corporate network, which limits lateral movement but does not prevent the initial injection of malware via unvalidated barcode scanner input.

424
Matchingmedium

Match each control type to its example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Firewall blocking unauthorized traffic

Intrusion detection system alerts

Backup restoration after data loss

Security warning banners

Why these pairings

Controls are categorized by their function: Preventive controls aim to prevent incidents, Detective controls identify incidents in progress, Corrective controls restore after an incident, and Deterrent controls discourage malicious behavior. Common confusions include swapping preventive with corrective or detective actions.

425
Multi-Selectmedium

Which TWO of the following are primary techniques for identifying IT risks in an organization? (Choose two.)

Select 2 answers
A.Vulnerability scanning
B.Business impact analysis (BIA)
C.Brainstorming workshops with process owners
D.Control self-assessments
E.Reviewing internal and external audit findings
AnswersC, E

A common qualitative risk identification technique.

Why this answer

The correct answers are C and E. Brainstorming workshops with process owners (C) directly identify risks by leveraging expert knowledge. Reviewing internal and external audit findings (E) identifies risks that have been observed or reported.

Vulnerability scanning (A) identifies technical vulnerabilities, not risks per se. BIA (B) focuses on impact assessment. Control self-assessments (D) evaluate control effectiveness, not identify risks.

426
MCQhard

In the FAIR framework, which of the following correctly represents the calculation of Loss Event Frequency (LEF)?

A.LEF = Threat Event Frequency × Vulnerability
B.LEF = Threat Event Frequency + Vulnerability
C.LEF = Asset Value × Vulnerability
D.LEF = Annualized Rate of Occurrence × Single Loss Expectancy
AnswerA

Correct formula.

Why this answer

In the FAIR (Factor Analysis of Information Risk) framework, Loss Event Frequency (LEF) is calculated as the product of Threat Event Frequency (TEF) and Vulnerability (Vuln). This reflects that the frequency of loss events depends on how often a threat event occurs and the probability that the threat event will result in a loss, which is the vulnerability component. The multiplication captures the dependency: even if threats are frequent, low vulnerability reduces LEF, and vice versa.

Exam trap

The trap here is that candidates often confuse LEF with ALE or mistakenly think vulnerability is additive, leading them to choose Option B or D, but FAIR explicitly defines LEF as a product of TEF and vulnerability, not a sum or a monetary metric.

How to eliminate wrong answers

Option B is wrong because LEF is not a sum of Threat Event Frequency and Vulnerability; addition would incorrectly imply that vulnerability adds to frequency rather than acting as a probabilistic multiplier. Option C is wrong because Asset Value is not part of LEF calculation; it is used in Loss Magnitude (LM) to compute risk, not in frequency estimation. Option D is wrong because Annualized Rate of Occurrence (ARO) × Single Loss Expectancy (SLE) is the formula for Annualized Loss Expectancy (ALE) in quantitative risk analysis, not LEF in FAIR; LEF is a frequency metric, not a monetary loss calculation.

427
MCQeasy

Which type of control is designed to stop an undesirable event from occurring?

A.Corrective control
B.Preventive control
C.Directive control
D.Detective control
AnswerB

Preventive controls aim to stop events from happening.

Why this answer

Preventive control is designed to stop an undesirable event from occurring by enforcing policies or technical barriers before the event happens. For example, a firewall rule that blocks inbound traffic on port 23 (Telnet) prevents unauthorized remote access attempts, directly reducing the likelihood of a security incident.

Exam trap

The trap here is that candidates often confuse preventive controls with detective controls, mistakenly thinking that monitoring or alerting (detective) can stop an event, when in fact prevention requires proactive blocking mechanisms like access control lists (ACLs) or input validation.

How to eliminate wrong answers

Option A is wrong because corrective control is applied after an undesirable event has occurred, aiming to restore normal operations (e.g., restoring data from backup after a ransomware attack). Option C is wrong because directive control guides behavior through policies or procedures but does not physically or technically stop an event (e.g., a password policy requiring complex passwords does not prevent a brute-force attack by itself). Option D is wrong because detective control identifies that an undesirable event has occurred or is occurring, such as an intrusion detection system (IDS) alerting on suspicious traffic, but it does not stop the event.

428
Multi-Selecthard

In the context of IT risk reporting to the board, which THREE elements should be included to effectively communicate risk?

Select 3 answers
A.Detailed technical logs
B.Top risks and status
C.Risk heat map
D.Employee performance reviews
E.Risk trend analysis
AnswersB, C, E

Highlights key concerns and progress.

Why this answer

A risk heat map, top risks and status, and risk trend analysis help the board understand the current and evolving risk landscape.

429
MCQmedium

Based on the exhibit, which risk response should be prioritized?

A.Implement account lockout policy
B.Avoid by taking the server offline
C.Accept the risk because it's only a single server
D.Transfer the risk to a cloud provider
AnswerA

Account lockout reduces the effectiveness of brute-force attacks.

Why this answer

The exhibit indicates a single server with a known vulnerability that could lead to unauthorized access. Implementing an account lockout policy directly mitigates the risk of brute-force attacks by limiting the number of failed login attempts, which is a cost-effective and immediate control. This aligns with the risk response strategy of mitigation, reducing the likelihood of exploitation without the operational impact of taking the server offline.

Exam trap

The trap here is that candidates may choose 'Accept the risk because it's only a single server' (Option C), mistakenly believing that a single server has low impact, but failing to recognize that a compromised server can serve as a pivot point for broader network attacks or data exfiltration.

How to eliminate wrong answers

Option B is wrong because taking the server offline would avoid the risk entirely but is typically a drastic measure that disrupts business operations and is not prioritized unless the vulnerability is critical and cannot be patched immediately. Option C is wrong because accepting the risk for a single server ignores the potential for lateral movement or data breach, and risk acceptance should only be considered after a formal risk assessment and when the cost of mitigation exceeds the potential impact. Option D is wrong because transferring the risk to a cloud provider does not eliminate the underlying vulnerability; the cloud provider may still rely on the same server configuration, and the organization retains residual risk and compliance responsibilities.

430
Multi-Selecthard

A risk practitioner is evaluating the effectiveness of existing risk mitigation controls for a critical financial application. Which THREE of the following are key indicators that controls are operating effectively?

Select 3 answers
A.Control testing results show 95% pass rate over the last quarter.
B.Audit findings for the application have been resolved within the agreed remediation timeline.
C.All control owners have completed annual training on their responsibilities.
D.The application's uptime is 99.9% as per service level agreement.
E.The number of security incidents related to the application has decreased by 30% year-over-year.
AnswersA, B, C

Testing pass rate demonstrates control operation.

Why this answer

A is correct because control testing results showing a 95% pass rate over the last quarter provide direct, quantitative evidence that the controls are functioning as intended. This metric is a primary indicator of control effectiveness in risk management frameworks, as it measures the actual performance of control activities against defined criteria. A pass rate of 95% suggests that the vast majority of control tests met their objectives, indicating reliable operation of the controls for the critical financial application.

Exam trap

The trap here is that candidates often confuse outcome-based metrics (like uptime or incident reduction) with direct control effectiveness indicators, failing to recognize that only control testing results and audit remediation timelines provide direct evidence of control operation and corrective action.

431
MCQmedium

A bank implements a new transaction monitoring system to detect fraudulent activities. After six months, the system has a high false positive rate, causing analysts to miss real threats. Which of the following is the BEST way to address this risk?

A.Accept the false positives as a cost of doing business
B.Tune the system to reduce false positives
C.Remove the monitoring system to focus on other controls
D.Hire additional analysts to review all alerts
AnswerB

Tuning improves detection accuracy.

Why this answer

B is correct because tuning the system involves adjusting detection thresholds, rules, or machine learning models to reduce false positives while maintaining sensitivity to actual fraud. This directly addresses the root cause—poorly calibrated detection logic—without sacrificing the system's primary function or incurring unsustainable costs.

Exam trap

The trap here is that candidates may choose D (hire more analysts) because it seems like a direct solution to alert overload, but it fails to address the system's inefficiency and is not a sustainable risk response per CRISC principles.

How to eliminate wrong answers

Option A is wrong because accepting false positives as a cost of doing business ignores the operational risk that analysts miss real threats, leading to potential financial and regulatory damage. Option C is wrong because removing the monitoring system eliminates the primary detective control for fraud, leaving the bank exposed to undetected fraudulent transactions. Option D is wrong because hiring additional analysts does not fix the underlying system misconfiguration; it only masks the symptom with increased headcount, which is not scalable and still risks alert fatigue.

432
MCQmedium

A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?

A.Model bias
B.Adversarial attacks
C.Explainability requirements
D.Data privacy in AI training
AnswerA

Correct. Model bias leads to unfair outcomes based on demographics.

Why this answer

Model bias occurs when training data or algorithms produce unfair or discriminatory outcomes, directly impacting fairness and regulatory compliance.

433
MCQhard

A company's control monitoring shows that a detective control has been 100% effective for the past year. However, a recent incident revealed that a data breach went undetected for three months. What is the MOST likely cause?

A.The control failure occurred but was not recorded.
B.The monitoring frequency was insufficient to detect the breach.
C.The control was not designed to detect the type of breach that occurred.
D.The control monitoring logs were tampered with.
AnswerC

Control scope may be narrow.

Why this answer

The detective control was 100% effective based on monitoring data, but it failed to detect a data breach for three months. This indicates the control was not designed to detect the specific type of breach that occurred, such as an exfiltration via an encrypted tunnel or a non-standard protocol. A control can be perfectly effective against known patterns while being blind to novel or out-of-scope attack vectors, which is why option C is correct.

Exam trap

The trap here is that candidates confuse 'control effectiveness' (how often it works when triggered) with 'control coverage' (whether it is designed to detect the relevant risk), leading them to incorrectly choose monitoring frequency or log tampering instead of recognizing the design gap.

How to eliminate wrong answers

Option A is wrong because if the control failure occurred but was not recorded, the monitoring logs would still show the control as effective for recorded events, but the breach would have been detected if the control was designed for that attack type; the issue is design, not recording. Option B is wrong because monitoring frequency (e.g., log review every 24 hours) would affect detection latency, but a three-month undetected breach implies the control never triggered, not that it triggered but was missed between reviews. Option D is wrong because tampered logs would likely show gaps or anomalies in the monitoring data, but the scenario states the control was 100% effective based on monitoring, implying logs were intact and consistent.

434
Multi-Selecthard

Which TWO of the following are characteristics of quantitative risk analysis compared to qualitative risk analysis? (Select 2)

Select 2 answers
A.It is always easier to communicate to non-technical stakeholders
B.It produces results in monetary values or percentages
C.It supports cost-benefit analysis of controls
D.It requires less specialized expertise to perform
E.It relies solely on expert judgment without numerical data
AnswersB, C

Quantitative outputs are numerical, e.g., ALE, SLE.

Why this answer

Quantitative risk analysis uses numerical data to assign monetary values or percentages to risk components such as asset value, exposure factor, and annualized loss expectancy. This allows for precise, data-driven comparisons and prioritization of risks based on financial impact.

Exam trap

The trap here is that candidates often confuse 'easier to communicate' with quantitative analysis because numbers seem objective, but in reality, qualitative ratings are usually simpler for non-technical audiences to grasp without specialized training.

435
MCQhard

An organization uses a KRI that tracks the average time to patch critical vulnerabilities. The metric has been increasing over the past three months. What does this indicate from a risk perspective?

A.The control effectiveness is improving
B.The risk of exploitation is increasing
C.The risk appetite has been reduced
D.The risk of exploitation is decreasing
AnswerB

Longer patch times increase the window of vulnerability.

Why this answer

An increasing average time to patch critical vulnerabilities indicates that the organization is taking longer to remediate known security weaknesses. From a risk perspective, this directly increases the window of exposure, making it more likely that an attacker will exploit a vulnerability before a patch is applied. Therefore, the risk of exploitation is increasing.

Exam trap

The trap here is that candidates may confuse a rising KRI metric with improved security posture, failing to recognize that longer remediation times increase exposure and risk of exploitation.

How to eliminate wrong answers

Option A is wrong because an increasing patch time indicates control effectiveness is deteriorating, not improving; effective controls would show decreasing or stable patch times. Option C is wrong because risk appetite is a strategic decision about acceptable risk levels, not a metric derived from patch timeliness; a reduced risk appetite would typically drive faster patching, not slower. Option D is wrong because it is the direct opposite of the correct interpretation; increasing patch time means the risk of exploitation is increasing, not decreasing.

436
Multi-Selecteasy

When performing a risk assessment, which TWO of the following are components of inherent risk?

Select 2 answers
A.Residual risk level
B.Impact of the risk event
C.Control effectiveness
D.Likelihood of a threat event
E.Cost-benefit analysis of controls
AnswersB, D

Inherent risk includes impact.

Why this answer

Inherent risk considers likelihood and impact without controls.

437
MCQmedium

During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?

A.Accept the risk owner's decision
B.Document the deficiency and move on
C.Communicate the risk exposure to senior management
D.Escalate directly to the board
AnswerC

Senior management needs to be aware of the risk and decide on additional funding.

Why this answer

The risk practitioner's primary duty is to ensure that senior management is aware of material risk exposures that could impact business objectives. When a key control for a high-risk process is ineffective and the risk owner refuses to remediate due to budget constraints, the practitioner must communicate the residual risk exposure to senior management, who have the authority to allocate resources and make strategic risk acceptance decisions. This aligns with the CRISC framework's emphasis on escalating risk information to the appropriate decision-making level when the risk owner's response is inadequate.

Exam trap

The trap here is that candidates confuse 'documenting the deficiency' (Option B) with completing the risk management process, but CRISC requires active communication of risk exposure to the appropriate authority, not just passive recording.

How to eliminate wrong answers

Option A is wrong because accepting the risk owner's decision without further action would violate the risk practitioner's responsibility to ensure that risk acceptance is based on complete and accurate information; the risk owner's budget-driven refusal does not constitute a valid risk acceptance decision without senior management's informed consent. Option B is wrong because simply documenting the deficiency and moving on fails to address the material risk exposure; documentation is necessary but not sufficient—the practitioner must actively communicate the risk to those who can authorize additional controls or formally accept the risk. Option D is wrong because escalating directly to the board bypasses the proper escalation chain; the board should only be involved for strategic-level risks or after senior management has been informed and has failed to act, not as a first step.

438
MCQhard

During a risk identification workshop, a risk owner proposes a scenario: 'A disgruntled employee with privileged access exfiltrates customer data to a competitor.' In the context of the ISACA risk scenario template, which element is missing if the scenario only includes the actor, threat type, event, and asset?

A.Timing and detection
B.Business impact
C.Consequence
D.Vulnerability
AnswerA

Timing and detection are required by the ISACA template.

Why this answer

A complete risk scenario includes actor, threat type, event, asset/resource, timing, detection, and response. The scenario lacks timing (when the event might occur) and detection/response elements.

439
MCQeasy

A manufacturing company uses an industrial control system (ICS) that is connected to the corporate network for monitoring. The risk manager is identifying risks related to this connectivity. Which of the following is the MOST significant risk?

A.Compromise of ICS causing physical damage to manufacturing equipment.
B.Malware infection spreading from corporate to ICS network.
C.Network congestion due to ICS traffic affecting corporate users.
D.Unauthorized access to corporate data through the ICS connection.
AnswerA

Physical damage can lead to safety incidents, production loss, and high repair costs.

Why this answer

The most significant risk is that a compromise of the ICS could lead to physical damage, such as equipment destruction, safety hazards, or environmental release. Unlike IT systems where data loss is the primary concern, ICS failures directly impact the physical world, making safety and operational integrity the top priority in risk identification.

Exam trap

The trap here is that candidates often focus on the most common IT risk (data breach or malware) and overlook the unique ICS risk of physical damage, which is the defining characteristic of operational technology risk management.

How to eliminate wrong answers

Option B is wrong because while malware spreading from corporate to ICS is a real threat, it is a means to an end; the ultimate impact (physical damage) is more significant than the infection itself. Option C is wrong because network congestion is a performance issue, not a safety or integrity risk, and ICS traffic is typically low-bandwidth and predictable. Option D is wrong because unauthorized access to corporate data is a confidentiality risk, which is secondary to the safety and availability risks posed by ICS compromise.

440
MCQmedium

A risk practitioner is designing an IT risk management programme. Which of the following is the BEST sequence of components to establish?

A.Risk register, risk assessment methodology, risk treatment process, risk reporting, risk management policy
B.Risk assessment methodology, risk register, risk treatment process, risk management policy, risk reporting
C.Risk reporting, risk management policy, risk assessment methodology, risk register, risk treatment process
D.Risk management policy, risk assessment methodology, risk register, risk treatment process, risk reporting
AnswerD

This is the logical sequence: policy first, then methodology, then register, then treatment, then reporting.

Why this answer

A logical order is to first define policy, then methodology, then risk register, then treatment process, and finally reporting. However, the question asks for the best sequence among options. Typically, policy comes first, then methodology, then risk register, then treatment, then reporting.

441
MCQmedium

An organization has implemented a new key risk indicator (KRI) for vendor management that measures the percentage of vendors without a signed contract. The current value is 15%, exceeding the risk appetite threshold of 10%. The risk owner wants to know the most appropriate action to take based on this KRI. What should the risk practitioner recommend?

A.Increase the frequency of KRI reporting from monthly to weekly to monitor the trend.
B.Update the risk appetite threshold to 15% to align with the current value.
C.Immediately communicate the KRI breach to the board of directors.
D.Analyze the root cause of the high percentage and develop a remediation plan.
AnswerD

Root cause analysis and remediation are the correct first steps when a KRI exceeds threshold.

Why this answer

When a KRI exceeds the risk appetite threshold, the immediate priority is to understand why the breach occurred and to implement corrective actions. Analyzing the root cause and developing a remediation plan directly addresses the underlying issue—vendors without signed contracts—rather than merely monitoring or adjusting thresholds. This aligns with the CRISC principle that KRIs are leading indicators that should trigger risk response, not just reporting changes.

Exam trap

The trap here is that candidates often confuse monitoring actions (like increasing reporting frequency) with risk response actions, or they mistakenly believe that adjusting the threshold to match the current value is a valid risk treatment instead of recognizing it as risk acceptance without proper analysis.

How to eliminate wrong answers

Option A is wrong because increasing reporting frequency from monthly to weekly only monitors the trend without addressing the root cause or reducing the percentage; it is a monitoring action, not a risk treatment action. Option B is wrong because updating the risk appetite threshold to match the current value eliminates the KRI's purpose as an early warning indicator and effectively accepts the risk without analysis or remediation. Option C is wrong because immediate communication to the board is premature before root cause analysis and remediation planning; escalation is appropriate only after the risk owner has assessed the situation and determined the severity.

442
MCQmedium

Refer to the exhibit. Based on the risk register, which risk response is applied to the risk with the highest inherent risk?

A.Transfer
B.Avoid
C.Accept
D.Mitigate
AnswerA

Risk-001 uses Transfer.

Why this answer

The risk with the highest inherent risk (Risk A, with a score of 25) involves a critical database server lacking encryption at rest. The risk response chosen is 'Transfer,' which is implemented by purchasing a cyber insurance policy that specifically covers data breach costs and regulatory fines. This shifts the financial impact of the risk to the insurer without altering the technical vulnerability or likelihood of the event.

Exam trap

The trap here is that candidates see a high inherent risk and automatically assume the response must be 'Mitigate' with technical controls, but the question tests the ability to recognize that purchasing insurance is a classic transfer response, not a reduction of the risk itself.

How to eliminate wrong answers

Option B (Avoid) is wrong because avoiding the risk would require decommissioning the database server or discontinuing the service, which is not indicated in the risk register; the response is financial, not operational. Option C (Accept) is wrong because accepting the risk would mean formally acknowledging and budgeting for potential losses without any active treatment, but the purchase of insurance is an active transfer mechanism, not passive acceptance. Option D (Mitigate) is wrong because mitigation would involve implementing technical controls such as enabling Transparent Data Encryption (TDE) or using BitLocker/ LUKS to reduce the likelihood or impact, whereas insurance does not reduce the inherent risk itself.

443
Matchingmedium

Match each risk response strategy to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Eliminate the activity that causes the risk

Reduce the likelihood or impact of the risk

Shift the risk to a third party, e.g., insurance

Acknowledge the risk and take no further action

Why these pairings

The correct matches are: Avoid – decision to not perform the activity; Accept – formal acceptance of risk; Mitigate – reduce likelihood/impact; Transfer – shift to another party. Common confusions include mixing transfer with avoidance and acceptance with mitigation.

444
Multi-Selecthard

During risk identification, a risk manager is reviewing threat intelligence sources. Which THREE of the following are considered legitimate sources of threat intelligence? (Choose three.)

Select 3 answers
A.Government advisories such as CISA Known Exploited Vulnerabilities (KEV) catalog
B.Unverified social media rumors
C.OSINT (Open-Source Intelligence) feeds
D.Information Sharing and Analysis Centers (ISACs)
E.Vendor sales presentations
AnswersA, C, D

Correct. Government advisories are authoritative sources.

Why this answer

OSINT (open-source intelligence), ISACs (sector-specific sharing), and government advisories (e.g., CISA KEV) are established threat intelligence sources. Social media rumor and vendor sales pitches are not reliable.

445
MCQmedium

A risk officer is evaluating the effectiveness of a control that prevents unauthorized changes to configuration files. The control has not detected any unauthorized changes in the past year. What does this indicate?

A.The control is unnecessary because no changes occurred.
B.The control is not configured correctly to detect changes.
C.The control is operating effectively and no violations occurred.
D.Further testing is needed to determine control effectiveness.
AnswerD

Requires validation to confirm.

Why this answer

The absence of detected unauthorized changes does not automatically confirm control effectiveness; it could also indicate that the control is not properly configured to detect changes (e.g., missing file integrity monitoring rules, incorrect baseline, or disabled logging). Further testing—such as manually introducing a test change or reviewing audit logs—is required to verify that the control can actually detect violations. This aligns with CRISC best practices for validating control effectiveness through testing rather than relying solely on absence of alerts.

Exam trap

The trap here is that candidates assume 'no detected violations' equals 'control is effective,' but CRISC emphasizes that absence of evidence is not evidence of absence—further testing is required to rule out detection failures.

How to eliminate wrong answers

Option A is wrong because the control's purpose is to detect unauthorized changes, and the fact that no changes were detected does not prove no changes occurred—it could mean the control missed them. Option B is wrong because while misconfiguration is a possible cause, it is not the only explanation; the control could be correctly configured but simply not have been triggered due to a lack of violations, so concluding misconfiguration without evidence is premature. Option C is wrong because the absence of detected violations does not confirm control effectiveness; it only indicates that no violations were recorded, which could be due to the control failing to detect them (e.g., a false negative scenario).

446
MCQhard

A risk practitioner is analyzing the results of a phishing simulation. The simulation had a 15% click rate on a test email targeting finance department staff. Which of the following conclusions is MOST valid regarding IT risk identification?

A.The email filtering system is ineffective
B.There is an increased risk of successful targeted phishing attacks against finance staff
C.This is an effective red team exercise
D.The organization has a low risk of credential theft
AnswerB

Directly identifies a risk from human factors.

Why this answer

A 15% click rate on a targeted phishing simulation indicates that a significant portion of finance staff are susceptible to social engineering, which directly increases the risk of a successful targeted phishing attack. This finding is a key input for IT risk identification because it reveals a control weakness (user awareness) that could be exploited by attackers to gain unauthorized access or initiate fraudulent transactions. The click rate itself is a risk indicator, not a definitive measure of control effectiveness like email filtering.

Exam trap

The trap here is that candidates may confuse a user awareness test result with a direct assessment of technical controls like email filtering, when in fact the simulation is designed to bypass those controls to measure human risk.

How to eliminate wrong answers

Option A is wrong because a 15% click rate does not directly measure the effectiveness of the email filtering system; the simulation email was deliberately allowed through to test user behavior, so filtering bypass is irrelevant to this conclusion. Option C is wrong because the simulation is a test of user awareness, not a red team exercise; red team exercises involve broader adversarial simulation including multiple attack vectors, not just a single phishing email. Option D is wrong because a 15% click rate indicates a non-trivial risk of credential theft, as clicking a phishing link can lead to credential harvesting or malware installation, so the risk is not low.

447
Multi-Selecthard

Which THREE of the following are effective risk identification techniques for a cloud migration project? (Select exactly THREE.)

Select 3 answers
A.Vendor lock-in analysis
B.User acceptance testing (UAT)
C.Cloud security assessment
D.Data classification
E.Network scanning of on-premises infrastructure
AnswersA, C, D

Evaluates risks related to dependency on a single cloud provider, such as migration difficulty.

Why this answer

Vendor lock-in analysis is an effective risk identification technique for cloud migration because it evaluates the dependency on a specific cloud provider's proprietary services, APIs, or data formats. Identifying this risk early allows the organization to plan for portability, avoid costly migration barriers, and negotiate exit strategies. Without this analysis, the project may face unexpected costs or technical constraints when attempting to switch providers or return to on-premises infrastructure.

Exam trap

The trap here is confusing post-migration validation activities (UAT) or on-premises-focused scans with proactive risk identification techniques that are specifically designed to uncover cloud migration risks.

448
MCQeasy

An organization wants to promote a risk-aware culture. Which of the following actions is most effective in encouraging employees to report incidents without fear?

A.Establishing a non-punitive incident reporting policy
B.Conducting annual security awareness training
C.Publishing risk metrics on the intranet
D.Providing incentives for risk identification
AnswerA

This directly addresses fear of retaliation.

Why this answer

A non-punitive incident reporting policy is the most effective action because it directly removes the fear of retaliation or blame, which is the primary psychological barrier to reporting security incidents. By guaranteeing that employees will not face disciplinary action for reporting their own mistakes or observed issues, the organization fosters psychological safety and encourages timely disclosure. This aligns with the CRISC principle that a risk-aware culture requires trust and openness, which cannot be achieved through training or metrics alone if fear persists.

Exam trap

The trap here is that candidates often choose 'Conducting annual security awareness training' because they equate awareness with culture change, but the question specifically targets the barrier of fear, which training alone cannot remove.

How to eliminate wrong answers

Option B is wrong because annual security awareness training, while important for knowledge, does not address the emotional or cultural barrier of fear; employees may still hide incidents if they believe reporting will lead to punishment. Option C is wrong because publishing risk metrics on the intranet is a communication tactic that informs but does not create a safe reporting environment; it may even increase anxiety if metrics highlight failures without a supportive policy. Option D is wrong because providing incentives for risk identification can inadvertently encourage gaming the system or reporting only low-risk items, and it does not eliminate the fear of consequences for reporting one's own errors or serious incidents.

449
MCQmedium

A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?

A.Threat event frequency
B.Loss magnitude
C.Vulnerability severity score
D.Annualized rate of occurrence
AnswerB

Correct. Loss magnitude estimates the financial impact per event.

Why this answer

In FAIR, the probable financial impact is derived from the loss event frequency and the loss magnitude. Loss magnitude estimates the financial loss per incident.

450
Multi-Selectmedium

An organization is designing a vendor risk assessment process for critical vendors. Which THREE of the following should be included in the initial onboarding assessment?

Select 3 answers
A.Security questionnaires
B.Continuous monitoring via shared intelligence platforms
C.Contract compliance review
D.Annual reassessment
E.SOC 2 report review
AnswersA, C, E

Questionnaires gather vendor security posture information.

Why this answer

Security questionnaires are a foundational tool in initial vendor onboarding because they systematically gather detailed information about the vendor's security controls, policies, and practices. This allows the organization to assess the vendor's baseline security posture against its own requirements before any business relationship begins.

Exam trap

The trap here is confusing ongoing monitoring activities (like continuous monitoring or annual reassessments) with the discrete, upfront steps required during the initial vendor onboarding assessment.

Page 5

Page 6 of 14

Page 7