Which TWO methods are commonly used for continuous monitoring of IT controls?
Continuously analyzes logs for anomalies.
Why this answer
Automated SIEM rules and vulnerability scanning are typical continuous monitoring techniques.
983 questions total · 14pages · All types, answers revealed
Which TWO methods are commonly used for continuous monitoring of IT controls?
Continuously analyzes logs for anomalies.
Why this answer
Automated SIEM rules and vulnerability scanning are typical continuous monitoring techniques.
A medium-sized e-commerce company recently experienced a denial-of-service (DoS) attack that took down its website for two hours. The incident response team quickly mitigated the attack by blocking the source IPs. In the aftermath, the risk manager is tasked with identifying risks to prevent recurrence. The company relies heavily on a single internet service provider (ISP) and has no DDoS protection service. The IT director suggests purchasing additional server capacity to absorb future attacks. The CEO is concerned about the cost. The risk team has identified that the likelihood of a similar attack is high based on recent industry trends, and the impact includes lost revenue and customer trust. What is the MOST effective risk identification action the risk team should take next?
Proper documentation and evaluation are core to risk identification.
Why this answer
The risk team's primary role during risk identification is to document the risk and evaluate alternative mitigation options before committing to a specific solution. Diversifying ISPs addresses the single point of failure in the network architecture, which is a root cause of the DoS vulnerability, and aligns with the principle of defense in depth. Simply blocking source IPs is reactive, and the IT director's suggestion of adding server capacity is a costly and potentially ineffective absorption strategy against volumetric attacks.
Exam trap
The trap here is that candidates confuse risk identification with risk treatment, selecting a specific solution (like a WAF or DDoS protection) instead of first documenting the risk and evaluating all possible options, which is the correct next step in the risk management process.
How to eliminate wrong answers
Option A is wrong because implementing a WAF is a control for application-layer attacks (e.g., SQL injection, XSS) and does not effectively mitigate volumetric or network-layer DoS attacks that saturate bandwidth. Option B is wrong because recommending a specific vendor solution (cloud-based DDoS protection) is a risk treatment decision, not a risk identification action; the risk team must first document and evaluate all options. Option C is wrong because accepting the risk is premature without first documenting the risk and evaluating alternative mitigations; the cost of mitigation may not exceed expected loss when considering reputational damage and customer trust, which are difficult to quantify.
An organization uses control self-assessments (CSAs) as part of its monitoring program. The results from the latest CSA show that the majority of controls are rated as effective, but an internal audit reveals several control failures in those same areas. What is the MOST likely reason for this discrepancy?
Self-assessment can lead to overly optimistic ratings.
Why this answer
Control self-assessments (CSAs) rely on the subjective judgment of process owners and operators, who may have a natural tendency to report favorable results to avoid scrutiny or additional work. This self-reporting bias is a well-known limitation of CSAs, leading to an overstatement of control effectiveness. The internal audit, being independent and objective, is more likely to uncover actual control failures, explaining the discrepancy.
Exam trap
The trap here is that candidates may assume a technical or procedural cause (like scope or documentation errors) rather than recognizing the inherent human bias in self-assessment, which is a classic CRISC concept in the Risk and Control Monitoring and Reporting domain.
How to eliminate wrong answers
Option A is wrong because a narrower CSA scope would typically result in fewer controls being assessed, not a systematic overstatement of effectiveness; the discrepancy is about accuracy, not coverage breadth. Option B is wrong because documentation errors in the questionnaire could cause confusion but would not consistently produce favorable ratings across multiple respondents; such errors are random, not directional. Option C is wrong because a decrease in inherent risk after the CSA would not cause the CSA to rate controls as effective when they are actually failing; risk level changes affect the likelihood or impact, not the direct assessment of control operation.
A company is updating its risk register. Which of the following is the primary purpose of a risk register?
This is the main purpose of a risk register.
Why this answer
The risk register centralizes identified risks, their analysis, and treatment plans.
An IAM policy grants an external auditor user permission to read objects from a sensitive data bucket, with no location restrictions. What risk does this indicate?
No IP restriction on the auditor's access.
Why this answer
The IAM policy's second statement allows the external-auditor user to perform GetObject on the corporate-data bucket without any IP address condition. This means the auditor can access sensitive data from any location, posing a risk of unauthorized access outside the internal network. Option B is incorrect because there is no unrestricted public access; the policy specifically allows only the external-auditor user.
Option C is incorrect because listing operations (ListBucket) are not allowed; only GetObject is permitted. Option D is incorrect because the policy does not address encryption; the risk is about location-based access.
A company's risk management team is evaluating the effectiveness of its control monitoring program. They find that many controls are tested at the same time each year, leading to a resource bottleneck. Which of the following approaches would BEST address this issue?
Spreading testing evenly throughout the year reduces peak loads and optimizes resource use.
Why this answer
Staggering testing cycles across the year distributes the workload evenly, preventing the resource bottleneck caused by testing all controls simultaneously. This approach optimizes resource utilization without increasing headcount or reducing coverage, directly addressing the root cause of the scheduling conflict.
Exam trap
The trap here is that candidates often choose 'Implement continuous monitoring automation' (Option C) because it sounds modern and efficient, but the question specifically asks for the BEST approach to address a resource bottleneck caused by timing, not the method of testing.
How to eliminate wrong answers
Option A is wrong because increasing the testing team size only adds more resources to the same peak period, failing to resolve the underlying scheduling inefficiency and potentially increasing costs without improving process design. Option C is wrong because implementing continuous monitoring automation changes the testing methodology rather than addressing the scheduling bottleneck; while automation can reduce manual effort, it does not inherently fix the problem of all controls being tested at the same time each year. Option D is wrong because reducing the number of controls tested weakens the control environment and increases residual risk, which is not a valid risk management approach to solve a resource scheduling issue.
During a quantitative risk analysis, the risk practitioner determines that the single loss expectancy (SLE) for a ransomware attack is $500,000 and the annualized rate of occurrence (ARO) is 0.4. The organization has a risk appetite that accepts annual losses up to $150,000. What is the recommended action?
Since ALE exceeds appetite, controls are necessary to bring residual risk within tolerance.
Why this answer
The ALE is $500,000 * 0.4 = $200,000, which exceeds the organization's risk appetite of $150,000 per year. Therefore, the risk is not acceptable, and controls must be implemented to reduce either the SLE (impact) or ARO (likelihood) until the ALE falls below the risk appetite threshold. Option A is incorrect because purchasing insurance may transfer risk but does not address the need to bring ALE within appetite; the organization must first attempt to reduce risk cost-effectively.
Option B is incorrect because the ALE exceeds the risk appetite, so acceptance is not justified. Option C is unnecessary; quantitative analysis already provides actionable data. Option D is the appropriate action as it aims to lower the risk to an acceptable level.
After a risk assessment, the risk owner decides to mitigate a high-risk finding by implementing additional access controls. What should the risk manager do NEXT?
Ensures the mitigation is effective and risk is within tolerance.
Why this answer
After mitigation controls are implemented, the risk manager must reassess the residual risk level to determine whether the controls have effectively reduced the risk to an acceptable level. This step ensures that the risk treatment decision is validated and that any remaining exposure is understood before updating the risk register or closing the issue.
Exam trap
The trap here is that candidates often confuse the order of risk management steps, assuming the risk register update (Option A) is the immediate next action, when in fact the residual risk reassessment must occur first to ensure the mitigation was effective.
How to eliminate wrong answers
Option A is wrong because updating the risk register with mitigation actions should occur after the residual risk has been reassessed, not before; the register must reflect the validated post-control risk level. Option B is wrong because accepting residual risk is a decision made by the risk owner, not the risk manager, and it should only occur after the residual risk has been reassessed and found to be within the organization's risk appetite. Option D is wrong because closing the risk issue without reassessing the residual risk ignores the possibility that the implemented controls may be ineffective or introduce new risks, violating the principle of continuous risk monitoring.
A company's risk assessment identifies that a threat actor has high capability and motivation to exploit a vulnerability. Which factor does this relate to?
Threat actor characteristics influence how likely an attack is.
Why this answer
Threat actor capability and motivation are factors in likelihood assessment.
A multinational corporation is conducting a risk assessment for its new online payment platform. The platform processes transactions in multiple currencies and stores sensitive customer financial data. The risk team has identified that the encryption algorithm used for data at rest is outdated and could be vulnerable to advanced attacks. The company's risk appetite is low for data breaches. The security team recommends upgrading the encryption to a modern standard, but the upgrade will require a 48-hour downtime impacting all global transactions. The business unit is concerned about revenue loss during the downtime. As the risk practitioner, what is the BEST course of action to balance security and business continuity?
This reduces risk while minimizing business disruption.
Why this answer
The best course of action because it balances the need to mitigate a high-risk encryption vulnerability with business continuity. By scheduling the upgrade during a low-traffic period and implementing compensating controls (e.g., enhanced monitoring and intrusion detection), the organization reduces the likelihood of exploitation during the 48-hour downtime while minimizing revenue loss. This aligns with the low risk appetite for data breaches and demonstrates a risk-based decision that treats the vulnerability without accepting unacceptable exposure.
Exam trap
The trap here is that candidates often choose immediate remediation (Option D) without considering business impact, failing to recognize that risk management requires balancing security with operational continuity through compensating controls and scheduling.
How to eliminate wrong answers
Option A is wrong because delaying the upgrade for three months while the encryption algorithm is known to be vulnerable to advanced attacks directly contradicts the company's low risk appetite for data breaches; it effectively accepts a high residual risk that could lead to a catastrophic data breach. Option C is wrong because outsourcing payment processing introduces new risks, such as loss of direct control over sensitive customer financial data, potential compliance issues (e.g., GDPR, PCI DSS), and the complexity of vendor risk management, which does not inherently resolve the immediate vulnerability in the existing platform. Option D is wrong because implementing the upgrade immediately without considering traffic patterns or compensating controls would cause significant revenue loss from a 48-hour global transaction halt, which is not a balanced approach; it ignores the business impact and fails to apply risk treatment options like mitigation through scheduling and compensating controls.
Refer to the exhibit. Based on the KRI data for the current week, what action should the risk manager take FIRST?
Amber days should be analyzed to understand root causes and prevent escalation to Red.
Why this answer
Wednesday (12) and Thursday (15) are in the Amber zone (10-20), indicating a need for investigation. Option A is premature because the threshold for Red (>20) was not breached. Option B ignores the amber days.
Option D suggests adjusting the threshold without understanding the cause of the spikes.
Refer to the exhibit. Given the organization's risk appetite is Low, which risk response is most appropriate?
Correct: This aligns with the low risk appetite by reducing residual risk to an acceptable level.
Why this answer
With a Low risk appetite, the organization requires residual risk to be Low. Option D proposes implementing additional monitoring to reduce the Medium residual risk to Low, which aligns with the risk appetite. This is a corrective response that mitigates the risk without unnecessary business disruption.
Exam trap
ISACA often tests the misconception that transferring risk (e.g., insurance) eliminates the risk itself, when in fact it only covers financial loss, leaving the operational risk level unchanged.
How to eliminate wrong answers
Option A is wrong because accepting a Medium residual risk violates the organization's Low risk appetite; acceptance is only appropriate when residual risk is within appetite. Option B is wrong because avoiding the risk by discontinuing operations is an extreme and disproportionate response that unnecessarily halts business functions when a less drastic mitigation (like monitoring) can achieve the required risk level. Option C is wrong because transferring risk via insurance does not reduce the inherent or residual risk level; it only shifts financial impact, leaving the operational risk still at Medium, which still violates the Low risk appetite.
During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?
Encryption mitigates the risk of data exposure effectively.
Why this answer
The risk of data exposure can be mitigated by implementing encryption, such as TLS, to protect data in transit.
Order the steps for incident response handling.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Why this order
Incident response follows preparation, detection, containment/eradication/recovery, lessons learned, and reporting.
An organization is designing a control monitoring program. Which THREE of the following are types of control monitoring activities that should be included?
Internal audits provide independent assurance on control effectiveness.
Why this answer
Periodic internal audits of control processes (Option A) are a formal, independent review of control design and effectiveness, providing assurance that controls are operating as intended. This is a detective control monitoring activity that validates the control environment over time, often aligned with frameworks like COSO or COBIT.
Exam trap
The trap here is confusing risk management activities (like defining risk appetite) or point-in-time assessments (like penetration testing) with ongoing control monitoring activities, which must be systematic and recurring to provide assurance over control effectiveness.
How to eliminate wrong answers
Option B is wrong because defining risk appetite statements is a risk governance activity, not a control monitoring activity; it sets the organization's risk tolerance but does not monitor controls. Option D is wrong because penetration testing of critical systems is a specific technical assessment of security vulnerabilities, not a broad control monitoring activity; it is a point-in-time evaluation rather than an ongoing monitoring process.
An IT risk assessment team is using a 5×5 risk matrix with likelihood and impact ratings. A risk scenario is rated as likelihood = 4 (likely) and impact = 5 (catastrophic). According to the typical heat map, what would be the risk rating?
Correct; likelihood 4 × impact 5 = 20, which corresponds to critical risk.
Why this answer
In a 5×5 matrix, likelihood 4 and impact 5 give a product of 20, which is typically in the 'critical' range. Common thresholds: 1-5 low, 6-10 medium, 11-15 high, 16-25 critical.
After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?
The practitioner should collaborate with the risk owner to identify additional controls or modify existing ones.
Why this answer
When residual risk remains above the risk appetite after treatment, the risk practitioner must first re-evaluate the existing risk treatment options with the risk owner. This collaborative review identifies whether additional controls (e.g., stricter input validation, rate limiting, or Web Application Firewall tuning) can further reduce the risk to an acceptable level before considering escalation or acceptance.
Exam trap
The trap here is that candidates often confuse the urgency of residual risk with the need to immediately escalate or accept it, when the correct first step is to revisit treatment options with the risk owner to see if further controls can close the gap.
How to eliminate wrong answers
Option B is wrong because escalating directly to the board bypasses the proper risk management process; the board should only be informed after all feasible treatment options have been exhausted and documented. Option C is wrong because updating the risk register to reflect residual risk is a documentation step that should occur after determining the final risk response, not as the first action. Option D is wrong because accepting residual risk above the risk appetite without first exploring additional mitigation measures violates the principle of risk reduction and could lead to unacceptable exposure.
Which TWO of the following are key outputs of a risk assessment process?
Risk register is a direct output of risk assessment.
Why this answer
The risk register is a key output of the risk assessment process because it formally documents identified risks, their assessed likelihood and impact, risk scores, and ownership. This output serves as the central repository for all risk information generated during the assessment, enabling ongoing risk tracking and reporting.
Exam trap
The trap here is that candidates often confuse the risk treatment plan as a separate post-assessment activity, but CRISC explicitly recognizes it as a key output of the risk assessment process because the assessment directly informs and documents the chosen treatment strategies.
Which of the following is a detective control for an information system?
IDS detects attacks or policy violations.
Why this answer
An intrusion detection system (IDS) is a detective control because it monitors network traffic or system activity for malicious actions or policy violations and generates alerts when such events occur. Unlike preventive controls, an IDS does not block or stop the attack; it detects and reports it after the fact, enabling incident response.
Exam trap
The trap here is confusing detective controls (which identify incidents after they occur) with preventive controls (which stop incidents before they happen), leading candidates to mistakenly classify firewalls or encryption as detective.
How to eliminate wrong answers
Option A is wrong because data backup is a corrective/recovery control, not detective; it restores data after a loss but does not detect ongoing threats. Option B is wrong because encryption is a preventive control that protects data confidentiality by encoding it, but it does not detect unauthorized access or attacks. Option C is wrong because a firewall is a preventive control that enforces access policies by blocking or allowing traffic based on rules, but it does not actively detect or alert on suspicious activity.
Which TWO of the following are characteristics of an effective key risk indicator (KRI)?
A predictive KRI provides early warning of increasing risk.
Why this answer
An effective KRI must be predictive in nature because it provides early warning signs of increasing risk exposure before a loss event occurs. Predictive KRIs allow risk owners to take proactive mitigating actions, whereas lagging indicators only confirm past failures. This forward-looking characteristic is essential for risk monitoring and timely decision-making.
Exam trap
The CRISC exam often tests the misconception that KRIs are merely historical metrics, but the trap here is confusing lagging indicators (based on past data) with leading indicators (predictive), causing candidates to incorrectly select 'Based on historical data only' as a valid characteristic.
An organization is implementing the NIST Cybersecurity Framework to manage cyber risk. The risk manager is mapping the 'Detect' function to existing risk management processes. Which of the following activities is MOST directly aligned with the 'Detect' function?
Continuous monitoring enables detection of potential incidents.
Why this answer
The 'Detect' function focuses on identifying cybersecurity events in a timely manner. Continuous security monitoring is a key activity to detect anomalies and incidents.
An organization uses a risk and control monitoring system that generates weekly reports. The reports show a key control as 'effective' for the past three months. However, during a recent audit, a significant control failure was discovered. Which TWO of the following are MOST likely root causes for this discrepancy? (Choose two.)
A non-representative sample can miss failures.
Why this answer
Options D and E are correct. A non-representative test sample (D) would fail to detect failures in parts of the population not sampled, leading to a false 'effective' rating. KRI thresholds set too high (E) would prevent alerts even when control failures occur, masking the true status.
Option A (data integrity issue) is possible but less likely given the system generated consistent reports. Option B (inaccurate reporting by control owner) is plausible but assumes deliberate misrepresentation, which is not indicated as a root cause. Option C (low monitoring frequency) would affect detection, but three months of effective reports suggests frequency alone is not the primary issue.
An organization calculated the inherent risk for a critical system as 'High' using a 5x5 heat map. After implementing controls, the residual risk is assessed as 'Medium'. What does this indicate about the control effectiveness?
The risk dropped from High to Medium, showing partial effectiveness.
Why this answer
The movement from 'High' inherent risk to 'Medium' residual risk indicates that the implemented controls have reduced the risk level by one step on the 5x5 heat map, but have not eliminated it entirely. Since the residual risk is still 'Medium' rather than 'Low' or 'Very Low', the controls are only partially effective—they mitigate some of the risk but do not bring it down to the organization's target risk appetite or tolerance level.
Exam trap
The trap here is that candidates assume any reduction in risk means controls are fully effective and risk is acceptable, but CRISC requires you to compare residual risk against the organization's specific risk appetite and target level, not just the inherent risk baseline.
How to eliminate wrong answers
Option A is wrong because 'fully effective' controls would reduce the risk to the organization's target level (often 'Low' or 'Very Low'), not leave it at 'Medium'; residual risk being 'Medium' means the risk is not yet acceptable unless the target is explicitly 'Medium'. Option B is wrong because 'ineffective' controls would result in residual risk remaining at 'High' or possibly increasing, not dropping to 'Medium'; a reduction in risk level proves some effectiveness. Option D is wrong because if controls are effective, residual risk should be lower than inherent risk, not equal; equal residual risk would mean controls have zero effect, which contradicts the observed reduction from 'High' to 'Medium'.
A risk manager is evaluating the risk associated with a new third-party vendor that will have access to customer data. The vendor has been in business for 10 years and holds ISO 27001 certification. Which factor should be given the MOST weight when determining the vendor's risk level?
Data sensitivity directly impacts risk magnitude.
Why this answer
The sensitivity and volume of data directly determine the potential impact of a breach, which is a core component of inherent risk. Even with strong controls like ISO 27001, the risk level is primarily driven by the value and quantity of the asset at risk (customer data). In IT risk assessment, the asset's criticality and exposure outweigh historical or certification-based indicators when calculating residual risk.
Exam trap
The trap here is that candidates overvalue certifications and tenure as proxies for security, while the CRISC exam emphasizes that risk is fundamentally tied to the asset's value and exposure, not just the vendor's credentials.
How to eliminate wrong answers
Option A is wrong because years in operation are a proxy for stability, not a direct measure of security posture or the specific risk from data access; a mature vendor can still have weak controls for a particular data type. Option B is wrong because ISO 27001 certification indicates a management system is in place, but it does not guarantee that controls are effectively implemented for the specific data sensitivity or volume, nor does it eliminate the need to assess the asset's inherent risk. Option D is wrong because contractual terms are a risk mitigation mechanism, not a primary risk factor; they define remedies and obligations but do not change the inherent risk posed by the data access itself.
An organization is implementing a third-party risk management program. Which TWO are essential components of the initial vendor risk assessment process?
Questionnaires gather information about the vendor's security practices.
Why this answer
Initial vendor assessments typically involve security questionnaires to gather information and review of SOC 2 reports to verify controls. These are foundational due diligence steps.
Which risk assessment method uses a matrix to plot likelihood and impact to determine risk level?
Qualitative assessment uses risk matrices.
Why this answer
The qualitative risk assessment method uses a matrix to plot likelihood and impact, typically with ordinal scales (e.g., high, medium, low) to derive a risk level. This approach is subjective and relies on expert judgment rather than numerical values, making it distinct from quantitative methods.
Exam trap
The trap here is that candidates confuse the qualitative risk matrix with the Delphi technique, which is a consensus-building method, or mistakenly think Annual Loss Expectancy (ALE) is plotted on a matrix, when in fact ALE is a quantitative output.
How to eliminate wrong answers
Option A is wrong because the Delphi technique is a structured communication method for achieving consensus among experts, not a risk assessment method that uses a likelihood-impact matrix. Option B is wrong because Annual Loss Expectancy (ALE) is a quantitative metric calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO), not a matrix-based qualitative approach. Option D is wrong because quantitative risk assessment uses numerical values (e.g., monetary amounts, percentages) and formulas like ALE, not a subjective matrix of likelihood and impact.
An organization uses a third-party vendor for payment processing. The vendor's latest SOC 2 report shows a significant control exception in logical access. What is the BEST way to monitor the effectiveness of the compensating controls the vendor has implemented?
Proactive monitoring of the vendor's corrective actions.
Why this answer
The most effective way to monitor compensating controls is to obtain the vendor's remediation plan and schedule a follow-up assessment. This allows the organization to verify that the compensating controls are operating effectively, which is a key activity in the Risk and Control Monitoring and Reporting domain. Simply accepting risk or adding contractual clauses does not provide ongoing assurance that the controls are working as intended.
Exam trap
The trap here is that candidates may confuse contractual remedies (like liability clauses or penalties) with actual control monitoring, but CRISC emphasizes that monitoring requires direct verification of control effectiveness, not just legal or financial agreements.
How to eliminate wrong answers
Option A is wrong because accepting the risk and applying a monetary penalty does not monitor the effectiveness of compensating controls; it merely transfers financial liability without verifying control operation. Option B is wrong because immediately terminating the contract is a drastic, reactive measure that does not address the need to monitor compensating controls and may disrupt business operations unnecessarily. Option C is wrong because requesting a contractual clause for breach liability does not provide a mechanism for ongoing monitoring or verification of control effectiveness; it only addresses legal recourse after a failure.
An organization is implementing a control to prevent unauthorized access to its critical database. The control must be designed to block access attempts in real time. Which type of control should be selected?
Preventive controls block unauthorized access in real time.
Why this answer
A preventive control is designed to block unauthorized access attempts in real time before they reach the critical database. Technologies such as a database firewall or network access control list (ACL) evaluate each request against a policy and drop the packet or terminate the session immediately, preventing the access from occurring. This aligns with the requirement for real-time blocking, which is the defining characteristic of a preventive control.
Exam trap
The trap here is that candidates often confuse detective controls (like monitoring or logging) with preventive controls, mistakenly thinking that detecting an attempt in real time is the same as blocking it, but detection does not stop the action from occurring.
How to eliminate wrong answers
Option A is wrong because a corrective control acts after an incident has occurred (e.g., restoring a database from backup after a breach), not in real time to block access. Option B is wrong because a detective control identifies and logs unauthorized access attempts (e.g., via audit logs or intrusion detection systems) but does not block them in real time. Option D is wrong because a compensating control is an alternative mechanism used when the primary control is not feasible (e.g., using additional monitoring when encryption cannot be applied), but it is not the first choice for real-time blocking and does not inherently block access in real time.
A risk assessment for a cloud migration project identifies that the cloud provider does not support encryption keys managed by the customer. Which of the following risk scenarios is MOST directly related to this finding?
Directly related to key management control.
Why this answer
When the cloud provider does not support customer-managed encryption keys, the provider retains control over the key material. This means that provider employees with administrative access to the key management system could potentially decrypt and access customer data, leading to unauthorized access. This directly creates a risk scenario of unauthorized access by cloud provider employees, as the customer loses the ability to enforce separation of duties and key sovereignty.
Exam trap
The trap here is that candidates often confuse encryption key management with data residency or misconfiguration risks, but the core issue is that provider-managed keys eliminate the customer's ability to prevent the provider from decrypting their data, directly enabling unauthorized access by provider employees.
How to eliminate wrong answers
Option A is wrong because service availability disruption is typically caused by outages, DDoS attacks, or resource exhaustion, not by the lack of customer-managed encryption keys. Option B is wrong because data loss due to misconfiguration (e.g., public S3 buckets, incorrect retention policies) is a separate risk that can occur regardless of who manages the encryption keys. Option D is wrong because non-compliance with data residency requirements is about where data is stored geographically, not about who controls the encryption keys; even with provider-managed keys, data can be stored in compliant regions.
Which TWO of the following are appropriate criteria for selecting key risk indicators (KRIs)?
Essential for effective monitoring.
Why this answer
Key risk indicators (KRIs) must be quantifiable and reliable to provide objective, measurable data that can be consistently tracked over time. Quantifiable indicators allow for trend analysis and threshold setting, while reliability ensures the data source is accurate and repeatable, which is essential for effective risk monitoring in IT environments such as network security or system availability.
Exam trap
ISACA often tests the distinction between leading and lagging indicators, and the trap here is that candidates confuse historical loss metrics (lagging) with KRIs (leading), or assume that any easy-to-collect metric is automatically a valid KRI.
A technology company has implemented a risk and control monitoring program for its software development lifecycle. The program includes key risk indicators (KRIs) such as number of critical bugs found in production, code review coverage, and time to patch vulnerabilities. After six months, the risk committee noticed that the KRI for code review coverage is consistently green (within threshold), but the number of critical bugs in production remains high. The risk manager suspects a disconnect between the KRI and actual risk. What should the risk manager do FIRST?
The KRI may be measuring review quantity, not quality.
Why this answer
The risk manager must first validate that the KRI for code review coverage is actually measuring the effectiveness of code reviews, not just their completion. If the KRI is green but critical bugs persist, the data source or definition may be flawed—for example, measuring the percentage of code reviewed rather than the quality of reviews. Without this validation, any subsequent action (like adding controls or adjusting thresholds) would be based on unreliable information.
Exam trap
The trap here is that candidates often jump to a corrective action (like adding controls or adjusting thresholds) without first questioning the validity of the KRI itself, which is the foundational step in risk and control monitoring.
How to eliminate wrong answers
Option A is wrong because implementing additional testing controls addresses symptoms (bugs in production) without diagnosing why the existing KRI is misleading; it assumes the KRI is accurate, which is the core issue. Option B is wrong because reducing the code review coverage target lowers the risk appetite without evidence that the current target is inappropriate; it could increase risk exposure if the KRI is already flawed. Option D is wrong because adjusting the threshold to a higher percentage assumes the KRI is correctly defined and merely needs recalibration, but the disconnect suggests the KRI itself may not reflect effective review quality.
Arrange the steps for performing a vulnerability assessment.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Why this order
Vulnerability assessment starts with scope, scanning, analysis, prioritization, and reporting.
Which risk treatment option involves eliminating the activity that creates the risk?
Avoidance eliminates the risk by stopping the activity.
Why this answer
Risk avoidance means avoiding the risk by discontinuing the activity that generates it.
Which TWO of the following are key functions of an Architecture Review Board (ARB) in managing risk?
This is a primary ARB responsibility.
Why this answer
A primary function of an Architecture Review Board (ARB) is to evaluate solution architectures for security risks prior to implementation. This proactive review ensures that security controls are embedded in the design phase, reducing the likelihood of vulnerabilities being introduced into production systems.
Exam trap
The trap here is confusing operational security tasks (like access control, scanning, or incident response) with the strategic, governance-focused role of the ARB, which is to ensure architectural decisions align with risk appetite and security requirements before deployment.
When identifying vulnerabilities, which of the following is the BEST source for configuration-related vulnerabilities in operating systems?
Why this answer
CIS Benchmarks are industry-recognized configuration guidelines that help identify and remediate configuration-related vulnerabilities in operating systems. Unlike NVD or CVE which catalog known vulnerabilities, CIS Benchmarks provide actionable hardening steps for system configurations.
During a quarterly IT risk review, the risk manager presents a risk heat map. Which TWO of the following elements should be included in the report to provide a comprehensive view?
The heat map is a standard visual tool.
Why this answer
A risk heat map visually represents current risk levels based on likelihood and impact, which is essential for a quarterly review to show the organization's present risk posture. Option D is correct because including risk trend analysis over the past quarter provides a dynamic view of how risks have evolved, enabling stakeholders to assess whether risk responses are effective and to identify emerging patterns.
Exam trap
The trap here is that candidates may think a comprehensive risk report must include all possible details (like upcoming events or all risks), but CRISC emphasizes that a quarterly review should focus on current risk posture and trends, not exhaustive lists or forward-looking projections.
The policy requiring TLS 1.2 or higher for all data transmissions is intended to enforce what security control?
aws:SecureTransport enforces HTTPS for data in transit.
Why this answer
How to eliminate wrong answers
Option A is wrong because data classification involves labeling data based on sensitivity, not enforcing encryption during transmission. Option B is wrong because access control governs who can view or modify data, not how data is encrypted while moving. Option C is wrong because encryption at rest protects stored data on disk or in databases, not data in transit over a network.
Which of the following is the PRIMARY purpose of a risk register?
The risk register is the central repository for risk information.
Why this answer
The risk register is the central repository for documenting identified risks, their analysis (including likelihood and impact), and the planned responses. While it can be used to track remediation actions, its primary purpose is to serve as the authoritative record of risk information, enabling informed decision-making and ongoing risk management.
Exam trap
The trap here is that candidates confuse the risk register's primary purpose (documentation and analysis) with its secondary uses (tracking remediation or compliance), leading them to select a plausible but incorrect option like A or D.
How to eliminate wrong answers
Option A is wrong because tracking the status of risk remediation actions is a secondary function of the risk register, not its primary purpose; that tracking is often managed via action plans or issue logs. Option C is wrong because a risk register is a static or periodically updated document, not a real-time alerting system; real-time alerts are provided by monitoring tools, SIEMs, or automated risk dashboards. Option D is wrong because while a risk register may help satisfy regulatory compliance requirements, that is a beneficial outcome, not the primary purpose; the core purpose is to document and manage risks, not to meet compliance obligations.
A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?
Correct. The risk management policy defines the approach to risk management.
Why this answer
The risk management policy is the authoritative document that establishes the organization's overall approach to risk management, including the principles, roles, responsibilities, and processes for risk assessment, treatment, and reporting. It sets the governance framework and mandates how risk activities must be conducted across the IT environment, ensuring consistency and alignment with business objectives.
Exam trap
The trap here is that candidates often confuse the risk register (a tactical tool) with the risk management policy (a strategic governance document), mistakenly thinking the register defines the process rather than just recording the outputs.
How to eliminate wrong answers
Option A is wrong because the IT strategy defines the long-term technology direction and investment priorities, not the specific procedures for risk assessment, treatment, and reporting. Option C is wrong because the business continuity plan focuses on maintaining or restoring operations after a disruption, not on the ongoing risk management process of identifying, analyzing, and treating risks. Option D is wrong because the risk register is a living document that records identified risks, their assessments, and treatment plans, but it does not define the overarching methodology or governance for risk management.
Based on the exhibit, what control monitoring deficiency is evident in the DLP policy?
Missing coverage for common data loss vectors.
Why this answer
The DLP policy shown in the exhibit only includes rules for monitoring and blocking credit card data exfiltration via webmail (Gmail, Yahoo Mail) and FTP. It completely omits any rule for cloud storage applications such as Dropbox or OneDrive, which are common vectors for data exfiltration. This is a control monitoring deficiency because the policy fails to cover a significant risk surface, leaving the organization blind to unauthorized transfers of sensitive data through these channels.
Exam trap
The trap here is that candidates may assume the DLP policy is comprehensive because it covers webmail and FTP, but they fail to notice the omission of cloud storage applications, which is a classic control monitoring deficiency tested in CRISC.
How to eliminate wrong answers
Option B is wrong because the exhibit does not provide any information about alert routing or notification configuration; the deficiency is about missing monitoring coverage, not alert delivery. Option C is wrong because log retention policies are not addressed in the exhibit; the issue is the absence of a rule for cloud storage, not the duration logs are kept. Option D is wrong because the rules shown are specific to webmail and FTP, not broadly defined; the problem is under-coverage (missing cloud storage), not over-broad rules that would cause false positives.
An organization is updating its asset inventory to improve IT risk identification. Which of the following asset attributes is MOST critical for assessing cybersecurity risk?
Directly feeds into risk calculation.
Why this answer
For assessing cybersecurity risk, the most critical attribute is the criticality rating based on business impact because it directly quantifies the potential harm from a security incident. Without knowing which assets are most vital to business operations, risk prioritization becomes arbitrary, leading to misallocated security controls. This aligns with the CRISC focus on risk-based decision-making, where impact drives the urgency of mitigation.
Exam trap
The trap here is that candidates often confuse operational attributes (like IP address or owner) with risk attributes, assuming that knowing where an asset is or who owns it is sufficient for risk assessment, when in fact business impact is the primary driver of risk prioritization.
How to eliminate wrong answers
Option B is wrong because IP address and location are operational attributes that help with network mapping and incident response, but they do not indicate the asset's importance or the severity of risk if compromised. Option C is wrong because asset owner contact information is useful for accountability and notification, but it does not influence the inherent risk level of the asset itself. Option D is wrong because the software vendor name alone provides no insight into the asset's business value or the specific vulnerabilities that could be exploited; it is merely a procurement detail.
A software development team is adopting Agile methodology and wants to integrate risk identification into their sprints. Which approach BEST aligns with Agile principles while ensuring effective risk identification?
Continuous risk identification fits Agile's iterative nature.
Why this answer
Agile emphasizes iterative, continuous improvement, and integrating risk identification into each sprint backlog ensures risks are identified and addressed as the project evolves. Reviewing risks during sprint retrospectives aligns with the Agile principle of inspecting and adapting, making risk management a recurring, team-driven activity rather than a one-time event. This approach is effective because it captures risks that emerge from changing requirements, technical debt, or integration issues during development.
Exam trap
The trap here is that candidates may think risk identification is a one-time planning activity (Option A) or a single role's responsibility (Option B), but CRISC emphasizes that risk identification must be continuous and collaborative in Agile environments to be effective.
How to eliminate wrong answers
Option A is wrong because conducting a risk workshop only at the start of the project violates the Agile principle of continuous feedback and adaptation; risks that emerge later in development (e.g., from new dependencies or scope changes) would be missed. Option B is wrong because assigning risk identification solely to the product owner contradicts the Agile principle of cross-functional team ownership and collaboration; risk identification is a shared responsibility that benefits from diverse technical perspectives. Option C is wrong because performing an annual risk assessment is too infrequent for Agile sprints, which typically last 1-4 weeks; this approach would fail to identify rapidly emerging risks such as security vulnerabilities introduced by new code or third-party library updates.
A bank is evaluating the impact of a potential system outage. Which of the following is an example of a direct financial cost associated with this impact?
System restoration is a direct cost of the outage.
Why this answer
Direct financial costs include incident response, recovery, and notification costs.
A large enterprise uses a risk matrix with impact categories (very low, low, medium, high, very high) and likelihood (rare, unlikely, possible, likely, almost certain). A risk identified has a 'likely' likelihood and 'high' impact. According to the matrix, risks with this combination are classified as 'high' risk. The risk appetite statement requires that all high risks have a response plan within 30 days. However, the risk owner argues that due to effective compensating controls, the residual risk is only 'medium'. Which of the following is the BEST course of action?
Formalizing the risk treatment plan and including the compensating controls in the risk register is the best action. It documents the residual risk as medium and satisfies the requirement for a response plan within 30 days.
Why this answer
The best course of action is to formalize the risk treatment plan by documenting the compensating controls that reduce the residual risk to medium. This updates the risk register and provides a formal response plan within the required timeframe. Option B is unnecessary because additional controls are not needed if the residual risk is within the risk appetite.
Option C is insufficient as acceptance without formal documentation does not meet the requirement for a response plan. Option D incorrectly suggests extending the deadline; the risk should be reclassified based on residual risk, but a formal plan is still needed.
Which of the following is the BEST indicator that a risk assessment should be performed outside the normal cycle?
Introduces new risks that need assessment.
Why this answer
A major IT infrastructure change introduces new or altered assets, data flows, and threat surfaces that were not considered in the previous risk assessment cycle. This change can invalidate existing control assumptions and risk ratings, making an ad-hoc assessment necessary to identify and evaluate emerging risks before they materialize.
Exam trap
The trap here is confusing routine operational events (like employee turnover or budget cycles) with events that fundamentally change the risk profile, leading candidates to overlook the necessity of an ad-hoc assessment triggered by a significant technical change.
How to eliminate wrong answers
Option A is wrong because a proposed regulation is not yet enacted; risk assessments are triggered by compliance requirements only after the regulation is finalized and effective. Option B is wrong because an employee departure is a personnel event that typically triggers an access review or segregation-of-duties check, not a full risk assessment outside the normal cycle. Option D is wrong because budget approval is a financial planning event that does not directly alter the risk landscape; it may enable risk treatment actions but does not itself require a new risk assessment.
A risk manager is designing a monitoring and reporting framework. Which THREE of the following are essential components of an effective risk and control monitoring program?
CSAs involve business owners evaluating control effectiveness, which is essential for monitoring.
Why this answer
Control self-assessments (CSAs) are essential because they empower process owners to evaluate the design and operating effectiveness of internal controls, providing firsthand evidence for the monitoring program. This bottom-up approach complements top-down testing by identifying control gaps and remediation needs directly from those who execute the controls, which is critical for a comprehensive risk and control monitoring framework.
Exam trap
ISACA often tests the distinction between KPIs and KRIs, where candidates mistakenly select KPIs because they confuse operational performance metrics with risk indicators, but KPIs do not directly measure risk exposure or control effectiveness.
An employee with access to sensitive financial data has been observed accessing systems outside of normal working hours and exhibiting erratic behavior. The IT risk manager suspects insider threat. What is the most appropriate risk response?
Mitigation through controls reduces the risk.
Why this answer
Implementing additional monitoring and restrictions (Option B) is the most appropriate risk response because it allows the organization to gather more evidence of the suspected insider threat while immediately reducing the attack surface. This aligns with the risk mitigation strategy, as it directly addresses the observed anomalous behavior—accessing systems outside normal hours—without prematurely escalating the situation. In a financial data environment, this could involve enabling enhanced audit logging, restricting access to specific IP ranges or times, and deploying user and entity behavior analytics (UEBA) to detect deviations from baseline activity.
Exam trap
A common mistake in the CRISC exam is assuming that immediate termination (Option A) is the best response to insider threats, but the trap here is that termination is a punitive action, not a risk response—it fails to preserve evidence and may violate due process, whereas monitoring and restriction is a proper mitigation that balances security with operational continuity.
How to eliminate wrong answers
Option A is wrong because immediate termination without a full investigation could destroy critical forensic evidence, violate employment or data privacy laws, and does not address the root cause of the behavior; it is a reactive, punitive measure rather than a controlled risk response. Option C is wrong because accepting the risk based solely on the employee being 'trusted' ignores the clear indicators of potential malicious activity (erratic behavior, off-hours access) and violates the principle of least privilege and continuous monitoring required for sensitive financial data. Option D is wrong because transferring the risk via fidelity insurance only covers financial loss after an incident occurs, not the ongoing threat; it does nothing to prevent the insider from exfiltrating data or causing harm in the immediate term.
An organization is deploying IoT sensors in a manufacturing plant. Which of the following is the MOST significant security risk associated with these devices?
Unpatched vulnerabilities in IoT devices are a major security concern.
Why this answer
IoT devices often have limited security features and may lack the ability to receive firmware updates, making them vulnerable and expanding the attack surface.
An organization has implemented a firewall (preventive), intrusion detection system (detective), and a backup restoration plan (corrective) to address a specific risk. The risk manager assesses the control effectiveness as follows: design adequacy is strong, but operating effectiveness is weak due to inconsistent patching. Which of the following best describes the residual risk?
Controls reduce risk but weak operating effectiveness limits the reduction.
Why this answer
Residual risk is inherent risk adjusted for control effectiveness. Weak operating effectiveness means controls are not fully effective, so residual risk remains relatively high.
During a vendor risk assessment, a third-party vendor is classified as "critical" because it has access to sensitive customer data. According to the organization's risk appetite, what minimum security requirement should be mandated for this vendor?
This is a common requirement for critical vendors.
Why this answer
A SOC 2 Type II report is the minimum security requirement for a critical vendor with access to sensitive customer data because it provides an independent, audited assessment of the vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time. This aligns with the organization's risk appetite by ensuring that the vendor has demonstrated effective controls in place to protect sensitive data, rather than relying on a point-in-time test or self-reported information.
Exam trap
The trap here is that candidates often choose penetration test results (Option C) because they seem technically rigorous, but they fail to recognize that a point-in-time test does not provide the ongoing assurance of control effectiveness required for a critical vendor with access to sensitive customer data.
How to eliminate wrong answers
Option B is wrong because a general liability insurance certificate covers financial losses from incidents like property damage or bodily injury, not the technical security controls required to protect sensitive customer data. Option C is wrong because penetration test results provide only a point-in-time snapshot of vulnerabilities and do not demonstrate ongoing control effectiveness or compliance with security frameworks. Option D is wrong because a self-assessment questionnaire alone is insufficient for a critical vendor, as it relies on unverified self-reported information and lacks independent validation of security controls.
A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time data analytics. Which of the following represents the MOST significant risk introduced by this convergence?
This creates new pathways for cyber attacks that can have physical consequences.
Why this answer
Connecting ICS to the corporate network expands the attack surface, allowing threats from the IT network to reach OT systems, potentially leading to safety incidents.
Which risk treatment option involves purchasing cyber insurance?
Insurance transfers the financial risk to a third party.
Why this answer
Cyber insurance is a form of risk transfer, where the financial impact of a loss is shifted to the insurer.
Which threat actor is most likely motivated by political ideology and may target government systems?
Hacktivists are ideologically motivated.
Why this answer
Hacktivists are threat actors whose primary motivation is political ideology, social activism, or protest. They often target government systems to disrupt operations, deface websites, or leak sensitive information in order to advance their political agenda, making option C correct.
Exam trap
The trap here is confusing nation-state APTs with hacktivists because both may target government systems, but the key differentiator is motivation: nation-state APTs act for geopolitical or espionage reasons, while hacktivists are driven by political ideology and often seek public visibility.
How to eliminate wrong answers
Option A is wrong because organized crime is motivated by financial gain, not political ideology, and typically targets financial institutions or data for resale. Option B is wrong because nation-state APTs are state-sponsored actors focused on espionage, geopolitical advantage, or strategic disruption, not primarily political ideology or public protest. Option D is wrong because script kiddies are unskilled attackers using pre-made tools for notoriety or fun, lacking the ideological motivation to specifically target government systems.
A mid-sized retail company processes over 1 million credit card transactions daily. It uses an automated monitoring system with static thresholds to flag potential fraud. Recently, the fraud detection team has been overwhelmed by a 40% increase in false positive alerts, causing legitimate transactions to be delayed and customer service complaints to rise. The risk manager is tasked with improving the situation. After reviewing the alert logs, it is clear that the thresholds have not been updated in 18 months, and transaction patterns have shifted due to seasonal promotions and new payment methods. The team has limited resources and cannot handle the current alert volume. What should the risk manager recommend as the most effective course of action?
This directly addresses why false positives are high and enables data-driven adjustments.
Why this answer
Performing a root cause analysis to refine detection rules and thresholds (Option A) directly addresses the outdated thresholds that caused the increase in false positives. This approach is systematic and can be tailored to the current transaction patterns without requiring additional resources or tools. Option B (deploying a machine learning tool) introduces new complexity and costs without fixing the underlying threshold issue, and the team's limited resources may hinder implementation.
Option C (hiring an external consultant) is costly and slow, and may not be sustainable. Option D (increasing thresholds immediately) could reduce alert volume but risks missing true positives, making it a temporary fix rather than a long-term solution.
An organization is selecting a control to reduce the risk of unauthorized data exfiltration. The annual loss expectancy (ALE) for this risk is currently $500,000. The proposed control costs $80,000 annually and is expected to reduce the ALE by 60%. What is the net benefit (reduction in risk exposure minus control cost) of implementing this control?
Correct: $300,000 reduction minus $80,000 cost = $220,000.
Why this answer
The current ALE is $500,000. A 60% reduction lowers the ALE by $300,000 (0.60 × $500,000). The net benefit is the reduction in risk exposure ($300,000) minus the annual control cost ($80,000), resulting in $220,000.
This calculation directly measures the residual risk reduction against the cost of the control, a key concept in cost-benefit analysis for risk response.
Exam trap
The trap here is that candidates often forget to subtract the control cost from the risk reduction, mistakenly selecting the reduction amount ($300,000) as the net benefit, or they incorrectly apply the percentage to the wrong base value, such as subtracting the cost from the original ALE.
How to eliminate wrong answers
Option B ($420,000) is wrong because it incorrectly subtracts the control cost from the original ALE ($500,000 - $80,000), ignoring the 60% reduction factor. Option C ($300,000) is wrong because it represents only the reduction in ALE (60% of $500,000) without subtracting the control cost, failing to account for the expense of implementation. Option D ($120,000) is wrong because it mistakenly calculates the net benefit as the control cost ($80,000) subtracted from the remaining ALE after reduction ($200,000), which confuses residual risk with net benefit.
Which TWO of the following are types of insider threats?
Intentional harmful actions by insiders.
Why this answer
Insider threats can be malicious (intentional harm) or negligent (unintentional mistakes).
Which TWO of the following are key inputs to a risk assessment?
Identifies what needs to be protected.
Which of the following is a Key Risk Indicator (KRI) that provides leading indication of increasing vulnerability risk?
A high patch lag indicates increased vulnerability risk before exploitation.
Why this answer
Patch lag (time since last patch) is a leading indicator that systems are exposed to known vulnerabilities.
After implementing a set of controls, the risk owner calculates the residual risk. Which of the following is true about residual risk?
Residual risk = inherent risk adjusted for control effectiveness.
Why this answer
Residual risk is the risk remaining after controls are applied, and it should be within the risk appetite.
Which THREE of the following are key components of a risk assessment report?
The risk register lists all identified risks and their attributes.
Why this answer
A risk register is a core component of a risk assessment report because it formally documents each identified risk, its owner, status, and tracking information. This register serves as the authoritative record that links risk identification to subsequent analysis and response activities, ensuring traceability throughout the risk management lifecycle.
Exam trap
The trap here is that candidates confuse supporting artifacts (like network diagrams or contracts) with mandatory report components, but the CRISC exam specifically tests that the risk assessment report must include the risk register, risk analysis, and risk response recommendations as its key deliverables.
Which TWO of the following are examples of risk avoidance? (Select TWO.)
Not entering the market avoids the associated risks.
Why this answer
Risk avoidance involves taking action to eliminate the risk entirely by not engaging in the activity that introduces it. Option C, 'Deciding not to enter a new market,' avoids all associated market, regulatory, and competitive risks by simply not pursuing that business opportunity. Option E, 'Discontinuing a risky product line,' removes the risk by ceasing the activity that generates it, such as halting production of a product with known safety or compliance issues.
Exam trap
The trap here is that candidates often confuse risk avoidance with risk mitigation or transfer, mistakenly selecting options like 'installing a firewall' (mitigation) or 'purchasing insurance' (transfer) as examples of avoidance, when avoidance requires ceasing or not starting the risk-generating activity.
A company is evaluating the cost-benefit of a new control that reduces the annualized loss expectancy (ALE) from $500,000 to $100,000. The control has an annual cost of $150,000. What is the net benefit of implementing this control?
Correct calculation: ALE reduction of $400,000 minus control cost of $150,000 equals $250,000 net benefit.
Why this answer
The net benefit of implementing a control is calculated as the reduction in Annualized Loss Expectancy (ALE) minus the annual cost of the control. The ALE reduction is $500,000 - $100,000 = $400,000. Subtracting the annual control cost of $150,000 yields a net benefit of $250,000, making option B correct.
Exam trap
The trap here is that candidates often forget to subtract the annual control cost from the ALE reduction, mistakenly selecting the gross reduction ($400,000) as the net benefit, or they incorrectly subtract the residual ALE instead of the control cost.
How to eliminate wrong answers
Option A is wrong because $350,000 represents the ALE reduction ($400,000) minus only the residual ALE ($100,000) instead of the control cost, a common miscalculation. Option C is wrong because $400,000 is the gross reduction in ALE before subtracting the control's annual cost, ignoring the expense side of cost-benefit analysis. Option D is wrong because $50,000 incorrectly subtracts the control cost from the residual ALE ($100,000 - $150,000 = -$50,000) or misapplies the formula, yielding a negative or minimal value that does not reflect the actual net benefit.
A vendor is classified as 'critical' based on its access to sensitive data and the criticality of its service. According to best practices, what minimum security requirement should be mandated for this vendor?
SOC 2 Type II provides independent assurance over controls over a period.
Why this answer
For critical vendors, the risk appetite typically requires a SOC 2 Type II report, which provides assurance over controls related to security, availability, processing integrity, confidentiality, and privacy.
A company has implemented a key risk indicator (KRI) for system availability, with a threshold of 99.5%. The monitoring team observes that availability has dropped to 99.2% for two consecutive months. What is the most appropriate next step?
Standard practice for threshold breaches.
Why this answer
A sustained breach of a KRI threshold (99.2% vs. 99.5%) for two consecutive months indicates a systemic issue that requires formal risk management action. The risk owner must be notified to assess the impact, and a root cause analysis (RCA) should be initiated to identify underlying failures—such as network congestion, hardware faults, or software bugs—before any remediation is planned.
Exam trap
The trap here is that candidates often jump to immediate remediation (Option A) or threshold adjustment (Option B), failing to recognize that the CRISC framework mandates a structured risk response starting with notification and analysis before any control changes.
How to eliminate wrong answers
Option A is wrong because implementing additional redundancy without first understanding the root cause could waste resources on the wrong fix (e.g., adding servers when the issue is a misconfigured load balancer or a DDoS attack). Option B is wrong because lowering the threshold to 99.0% is a form of risk acceptance without analysis, which violates the principle of maintaining objective KRIs and could mask a deteriorating service level agreement (SLA). Option D is wrong because immediate escalation to the board is premature; the board should be informed only after the risk owner has assessed the situation and determined that the risk exceeds the enterprise risk appetite, not for a single KRI breach.
A risk manager is evaluating the impact assessment for a potential data breach. Which THREE categories of impact should be considered in a comprehensive business impact analysis?
Operational impact is a key category.
Why this answer
Comprehensive business impact analysis considers various impact categories. For this data breach scenario, the three categories selected are operational (system downtime and productivity loss), regulatory (fines and mandatory remediation), and financial (direct and indirect costs). These three are commonly included in BIA.
Reputational impact is also important but is not among the chosen options.
An organization is considering outsourcing its IT support to a third-party provider. The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements. Which of the following is the BEST risk response strategy?
Avoidance is appropriate when compliance cannot be assured.
Why this answer
The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements, which represents a high-severity compliance risk that cannot be effectively mitigated through monitoring alone. Avoiding the risk by keeping IT support in-house eliminates the exposure entirely, making it the best response when the risk level exceeds the organization's risk appetite and cannot be reduced to an acceptable level through other strategies.
Exam trap
The trap here is that candidates often choose 'mitigate by monitoring' or 'transfer through contract' because they seem proactive, but CRISC expects you to recognize that regulatory compliance risk cannot be effectively transferred or monitored away when the provider's practices are fundamentally non-compliant.
How to eliminate wrong answers
Option A is wrong because regular monitoring does not address the root cause of non-compliance; if the provider's practices violate regulations, monitoring only detects failures without preventing them, and the organization remains liable for regulatory penalties. Option C is wrong because transferring risk through a contract does not absolve the organization of regulatory responsibility; data protection regulations typically hold the data controller (the organization) accountable regardless of contractual indemnities. Option D is wrong because accepting the risk based solely on cost savings ignores the potential for severe regulatory fines, reputational damage, and legal liabilities that far outweigh any financial benefit from cheaper outsourcing.
A SOC analyst observes repeated failed login attempts from an external IP address targeting a user account. What is the best next step in the IT risk identification process?
Checking the IP against threat intelligence helps identify whether this is a known attacker, informing risk assessment.
Why this answer
The first step in the IT risk identification process is to validate whether the observed event represents a genuine threat. Investigating the external IP address against threat intelligence feeds (e.g., VirusTotal, AlienVault OTX) confirms if it is associated with known malicious activity, such as a botnet or brute-force campaign, before taking any action. This aligns with the CRISC risk identification phase, where the goal is to characterize the risk event, not immediately respond or escalate.
Exam trap
ISACA often tests the distinction between risk identification and risk response, trapping candidates who jump to blocking or escalation without first validating the threat through investigation.
How to eliminate wrong answers
Option A is wrong because immediately blocking the IP address is a reactive response that bypasses the risk identification process; the IP could be a legitimate user behind a NAT or a false positive from a misconfigured proxy, and blocking without investigation may disrupt business operations. Option B is wrong because conducting a vulnerability scan of the target system addresses system weaknesses, not the immediate event of failed login attempts; vulnerability scanning is part of risk assessment, not risk identification, and does not confirm if the IP is malicious. Option D is wrong because escalating to the incident response team is premature before confirming the IP is malicious; incident response is triggered after risk identification and validation, not as the first step.
An organization decides to outsource its data center operations to a third party. This is an example of which risk response?
Outsourcing transfers operational risk to the third party.
Why this answer
Outsourcing data center operations transfers the financial and operational risks associated with managing the infrastructure to a third-party provider. This is a classic risk transfer response because the organization retains ownership of the data and business accountability but shifts the liability for physical security, hardware maintenance, and uptime to the vendor via contractual agreements, such as SLAs with penalty clauses.
Exam trap
The trap here is that candidates confuse risk transfer with risk reduction, mistakenly thinking that outsourcing reduces the risk of hardware failure, when in fact it only shifts the financial liability for that failure, not the operational impact on the business.
How to eliminate wrong answers
Option A is wrong because risk reduction involves implementing controls to lower the likelihood or impact of a risk, such as deploying redundant power supplies or fire suppression systems, not outsourcing operations. Option C is wrong because risk acceptance means formally acknowledging the risk and choosing to bear it without additional action, which contradicts the active decision to engage a third party. Option D is wrong because risk avoidance would mean ceasing the activity that generates the risk, such as shutting down the data center entirely, rather than transferring its management to another entity.
An organization is considering migrating its customer database to a public cloud provider. Which of the following is the PRIMARY risk identification technique that should be used to identify potential data exposure risks?
Threat modeling systematically identifies threats relevant to the cloud migration.
Why this answer
Threat modeling is the primary risk identification technique for proactively identifying potential data exposure risks during a cloud migration. It systematically analyzes the system architecture, data flows, and trust boundaries to uncover threats such as misconfigured access controls, insecure APIs, or data leakage between tenants. Unlike reactive techniques, threat modeling focuses on design-level vulnerabilities before they are exploited.
Exam trap
The trap here is that candidates confuse vulnerability scanning (a reactive, point-in-time check) with proactive risk identification, but threat modeling is the only technique that addresses design-level data exposure risks before migration.
How to eliminate wrong answers
Option A is wrong because vulnerability scanning identifies known software flaws (e.g., CVEs) in running systems but does not assess architectural risks like data exposure from shared cloud storage or improper IAM policies. Option C is wrong because penetration testing validates exploitability of existing vulnerabilities after deployment, not the proactive identification of data exposure risks during migration planning. Option D is wrong because business impact analysis prioritizes critical assets and recovery objectives, not the technical identification of data exposure threats.
An organization is designing a risk and control monitoring program for a new cloud-based application. Which of the following is the MOST important factor to consider when selecting Key Risk Indicators (KRIs)?
KRIs should reflect the organization's risk appetite and objectives to be meaningful.
Why this answer
Alignment with strategic objectives is the most important factor because KRIs must directly measure risks that could impede the organization's business goals and strategic initiatives. For a new cloud-based application, KRIs tied to strategic objectives ensure monitoring focuses on risks that matter most to the business, such as data breaches affecting customer trust or service downtime impacting revenue, rather than irrelevant metrics.
Exam trap
The trap here is that candidates often prioritize ease of automation or industry benchmarks over strategic alignment, forgetting that KRIs must be tailored to the organization's specific risk profile and business objectives to be effective.
How to eliminate wrong answers
Option A is wrong because historical loss data may not exist for a new cloud application, and KRIs should be forward-looking indicators of risk exposure, not backward-looking loss metrics. Option B is wrong because ease of automated data collection is a practical consideration but not the primary factor; a KRI that is easy to collect but irrelevant to strategic risk is useless. Option C is wrong because industry best practices provide generic guidance but may not reflect the organization's unique risk appetite, cloud architecture, or strategic priorities, leading to misaligned monitoring.
An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?
Bias can lead to legal and reputational damage.
Why this answer
Regulated decisions require explainability, and model bias can lead to unfair or illegal outcomes. Both are critical risks.
An organization is evaluating a new security control that costs $50,000 annually to implement and maintain. The current annualized loss expectancy (ALE) for a related risk is $200,000. The control is expected to reduce the ALE by 85%. Using cost-benefit analysis, what is the net benefit of implementing this control?
The net benefit is $120,000 per year.
Why this answer
The reduction in ALE is 85% of $200,000 = $170,000. The annual control cost is $50,000. Net benefit = $170,000 - $50,000 = $120,000.
You are the IT risk manager for a mid-sized e-commerce company. The company processes credit card payments and stores customer data. Recently, the company experienced a security incident where an attacker exploited a SQL injection vulnerability in the web application, exfiltrating a database of customer records. The vulnerability was introduced three months ago during a feature upgrade. The development team claims they followed secure coding guidelines, but the vulnerability was missed due to insufficient testing. The company's risk appetite is moderate, and they have a risk management policy that requires risks to be treated within 30 days of identification. The CISO wants to know the most effective way to reduce the likelihood of similar incidents. You have assessed that the current risk score for web application vulnerabilities is 16 (High). The company has a bug bounty program, but it has not been effective. Which of the following courses of action would BEST address the root cause and reduce the risk?
This addresses the root cause by preventing vulnerabilities from being introduced.
Why this answer
The root cause of the incident is a failure in the development process: secure coding guidelines were followed but insufficient testing allowed a SQL injection vulnerability to be introduced. Implementing a Secure Software Development Lifecycle (SSDLC) with mandatory security training, code reviews, and automated security testing directly addresses this root cause by embedding security controls into every phase of development, preventing vulnerabilities from being introduced in the first place. This is the most effective way to reduce the likelihood of similar incidents, as it proactively fixes the process rather than relying on reactive measures.
Exam trap
The trap here is that candidates often choose a compensating control (like a WAF or vulnerability scanning) because it seems faster or more familiar, but the question asks for the BEST way to reduce likelihood by addressing the root cause, which requires a preventive, process-level change like SSDLC.
How to eliminate wrong answers
Option A is wrong because increasing vulnerability scanning and patch management is a reactive measure that detects vulnerabilities after deployment, not preventing them from being introduced during development; it does not address the root cause of insufficient testing in the SDLC. Option B is wrong because deploying a WAF is a compensating control that can block some SQL injection attempts, but it does not fix the underlying insecure coding practices and can be bypassed by sophisticated attackers or misconfigurations; it reduces impact but not likelihood. Option C is wrong because increasing bug bounty rewards may attract more researchers, but the program has already been ineffective, and relying on external researchers to find vulnerabilities after release is reactive and does not prevent the introduction of vulnerabilities during development.
A global financial services firm has implemented a risk monitoring system that aggregates data from 50+ systems across three regions (Americas, EMEA, APAC). The system uses a centralized data lake and provides dashboards to regional risk committees. Recently, the APAC committee reported that their dashboard shows a spike in cyber risk indicators, but the Americas and EMEA dashboards show no change. The data source for the spike is a single system in APAC that tracks failed VPN logins. The risk owner for that system believes the spike is due to a misconfiguration during a recent patch. However, the APAC risk committee is concerned that this indicates a coordinated attack. The Chief Risk Officer (CRO) wants a clear assessment. Which course of action is most appropriate?
Addresses the likely cause directly.
Why this answer
The spike originates from a single system in APAC tracking failed VPN logins, and the risk owner has identified a misconfiguration from a recent patch as the cause. This is a classic false positive scenario where a technical anomaly (e.g., a patch altering authentication timeout or lockout thresholds) generates an alert spike without evidence of lateral movement or other indicators. The CRO needs a clear assessment, and the most appropriate action is to confirm the misconfiguration and fix it, rather than escalating or adding controls prematurely.
Exam trap
The trap here is that candidates may overreact to a spike in risk indicators and choose escalation (Option D) or broad control additions (Option A), failing to recognize that a single-system anomaly with a plausible technical explanation (patch misconfiguration) should first be investigated and confirmed before any further action.
How to eliminate wrong answers
Option A is wrong because implementing additional monitoring controls across all regions would be a reactive, resource-intensive response to a single-system anomaly that is likely a false positive, and it does not address the root cause (the misconfiguration). Option C is wrong because suggesting the APAC committee accept the risk based solely on the system owner's opinion bypasses the need for verification and documentation, which is critical in a regulated financial services environment. Option D is wrong because immediately escalating to the board and activating the incident response team is a severe overreaction to a single-system spike with a known probable cause (patch misconfiguration), and it would waste resources and cause unnecessary alarm.
A multinational corporation is migrating critical applications to a public cloud provider. The IT risk manager needs to design a risk assessment approach that addresses shared responsibility. Which of the following is the MOST appropriate approach?
This ensures all areas are covered according to the provider's model.
Why this answer
In a public cloud shared responsibility model, the cloud provider secures the infrastructure (e.g., physical security, hypervisor), while the customer secures their data, configurations, and access controls. Option D is correct because it requires mapping each control to the specific party responsible (customer vs. provider) and assessing both sides, ensuring no gaps in coverage. This approach aligns with the CSA Cloud Controls Matrix and NIST SP 800-146, which mandate joint accountability.
Exam trap
The trap here is that candidates assume the cloud provider is fully responsible for all security, overlooking the customer's contractual and operational obligations under the shared responsibility model, which is a core CRISC concept for cloud risk assessments.
How to eliminate wrong answers
Option A is wrong because assessing only the provider's controls ignores customer-side responsibilities like IAM policies, encryption key management, and application-layer security, leading to unmitigated risks. Option B is wrong because assuming the provider covers all risks violates the shared responsibility model; the provider explicitly disclaims responsibility for customer data and configurations in their SLA (e.g., AWS Shared Responsibility Model). Option C is wrong because a data leakage risk assessment is too narrow; it omits other critical risks such as misconfigured network ACLs, insecure APIs, and compliance violations (e.g., GDPR data residency).
Practice CRISC by domain
Target a specific domain to shore up weak areas.