Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 451–525

1062 questions total · 15pages · All types, answers revealed

Page 6

Page 7 of 15

Page 8
451
Multi-Selectmedium

A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?

Select 2 answers
A.Risk heat map
B.Individual employee performance metrics
C.Detailed technical logs
D.Top risks and their status
E.List of all IT assets
AnswersA, D

A risk heat map gives the committee an aggregated, visual view of likelihood and impact across the portfolio, enabling prioritisation and comparison of exposures. This satisfies the stem's requirement for the most important content in a quarterly IT risk committee report.

Why this answer

A risk heat map (A) is essential because it visually prioritizes risks by likelihood and impact, allowing the IT risk committee to quickly identify and compare exposure across the risk portfolio. Top risks and their status (D) must be included so the committee can focus on the most significant threats, track mitigation progress, and make informed governance decisions. Individual employee performance metrics (B) are an HR concern and do not reflect organizational risk posture.

Detailed technical logs (C) are too granular and operational for a quarterly executive-level risk report. A list of all IT assets (E) is an inventory artifact, not a risk report element, and would overwhelm the committee without risk context.

Exam trap

The trap here is that candidates confuse operational data (like logs or asset lists) with strategic risk reporting content, failing to recognize that the committee needs summarized, decision-supporting visuals (heat map) and prioritized risk status, not raw technical details.

452
MCQmedium

A healthcare organization has identified that its patient portal has a vulnerability that could expose sensitive data. The risk owner decides to implement multifactor authentication (MFA) for all users. After implementation, the risk practitioner conducts a follow-up assessment and finds that some users are sharing credentials, potentially bypassing MFA. The risk practitioner should FIRST:

A.Report the control failure to the risk owner and reassess the residual risk.
B.Recommend additional security awareness training for all users.
C.Implement technical controls to prevent credential sharing, such as device fingerprinting.
D.Accept the residual risk because MFA is still partially effective.
AnswerA

The risk practitioner's first step is to inform the risk owner that the implemented control (MFA) is not fully effective due to credential sharing. This triggers a reassessment of the residual risk, as the control may no longer reduce risk to an acceptable level. The practitioner should gather evidence, quantify the impact, and present findings to the risk owner so that a decision can be made on additional risk responses, such as stricter enforcement or alternative controls.

Why this answer

When a control is found to be ineffective or circumvented, the risk practitioner must first report the control failure to the risk owner and reassess the residual risk. This ensures that the risk owner is aware of the changed risk landscape and can make an informed decision on whether to accept, mitigate, or transfer the risk. The reassessment should consider the extent of credential sharing, its impact on the MFA control's effectiveness, and any additional vulnerabilities.

Only after this reassessment should further actions, such as training or technical controls, be considered.

Exam trap

The trap here is jumping to a solution like training or new controls without first reassessing the risk and informing the risk owner.

453
MCQmedium

An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?

A.Vendor lock-in to proprietary protocols
B.Expanded attack surface with unpatched devices
C.Insufficient bandwidth for data transmission
D.Data integrity issues from sensor malfunction
AnswerB

Unpatchable, low-power IoT sensors each expose services that attackers can reach, so every added device widens the exploitable footprint. Prioritising this expanded attack surface with unpatched devices addresses the constraint that firmware cannot be remediated easily across the remote facility.

Why this answer

IoT sensors with limited processing power that cannot be easily patched represent a classic expanded attack surface with unpatched devices. Each unpatched sensor is a potential entry point into the network, and the sheer number of devices multiplies the risk. Because patching is infeasible, compensating controls (network segmentation, monitoring, least privilege) become critical, making this the priority risk for the risk manager.

Exam trap

CRISC often tests prioritization of security risk over operational or strategic risk, so candidates who pick vendor lock-in or bandwidth issues mistake business/performance concerns for the most pressing security exposure.

How to eliminate wrong answers

Option A is wrong because vendor lock-in to proprietary protocols is a strategic/business continuity concern, not the most immediate security risk; it affects flexibility and cost, not the likelihood of compromise. Option C is wrong because insufficient bandwidth is an availability/performance issue that can be addressed with network upgrades or edge processing, and it does not represent a security threat vector. Option D is wrong because data integrity issues from sensor malfunction are a reliability/data-quality concern; while relevant, they are typically addressed through calibration and redundancy and do not carry the same adversarial risk as an unpatched, network-exposed device.

454
Multi-Selecthard

A risk practitioner is performing risk identification for a manufacturing firm that relies on industrial control systems (ICS) to operate assembly lines. The practitioner is cataloging vulnerabilities that could be exploited to disrupt production. Which TWO of the following represent vulnerabilities rather than threats? (Choose two.)

Select 2 answers
A.Flat network architecture that allows engineering workstations to reach production PLCs without segmentation.
B.A severe storm causing extended power loss to the manufacturing plant.
C.A nation-state group conducting reconnaissance against critical manufacturing infrastructure.
D.Ransomware operators targeting industrial organizations for extortion payments.
E.Unpatched programmable logic controllers (PLCs) running firmware with known remote code execution flaws.
AnswersA, E

A flat network that permits engineering workstations to directly reach production PLCs is an architectural weakness. It increases the likelihood that a compromised workstation can pivot to control systems. This is a vulnerability because it is a condition of the environment that can be remediated through segmentation, firewalls, and access controls. It is a classic ICS risk finding, and its identification supports design changes that reduce the blast radius of an incident.

Why this answer

Vulnerabilities are internal weaknesses or conditions that a threat can exploit, such as unpatched PLCs with known flaws and flat network architecture exposing production systems. Threat actors and natural events exist independently and are classified as threats. Correctly separating the two is essential because treatment differs: vulnerabilities are remediated through patching, segmentation, and configuration, while threats are addressed by reducing exposure and improving detection and response.

Exam trap

The trap here is labeling threat actors or natural hazard events as vulnerabilities, which misdirects treatment toward controlling the attacker or the weather instead of fixing internal weaknesses.

455
MCQhard

A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?

A.Multi-tenancy isolation vulnerabilities
B.Vendor lock-in due to proprietary APIs
C.Shared responsibility model gaps
D.Data sovereignty and cross-border data transfer restrictions
AnswerD

Data residency laws restrict where customer data may be stored and transferred, so a cloud analytics platform spanning jurisdictions risks unlawful cross-border movement of sensitive records. This legal constraint, not generic breach exposure, creates the greatest compliance risk for the institution.

Why this answer

Data sovereignty issues arise when data is stored in jurisdictions with conflicting or unknown legal frameworks, posing significant compliance risk.

456
Multi-Selecthard

An organization is implementing continuous monitoring for its critical systems. Which TWO of the following are examples of continuous monitoring techniques? (Select TWO)

Select 2 answers
A.Continuous vulnerability scanning
B.Weekly review of access logs by a manager
C.Automated SIEM rules to detect anomalies
D.Annual penetration testing
E.Quarterly control testing by internal audit
AnswersA, C

Continuous vulnerability scanning automatically and repeatedly identifies new weaknesses across critical systems, providing the ongoing, real-time assurance that continuous monitoring demands. Periodic manual reviews or annual assessments lack the automation and frequency the technique requires.

Why this answer

Option A (Continuous vulnerability scanning) is correct because it is an automated, ongoing process that repeatedly identifies new vulnerabilities as systems and threat data change, which is a core continuous monitoring technique. Option C (Automated SIEM rules to detect anomalies) is correct because SIEM correlation rules and alerting run continuously against real-time log and event streams, providing ongoing detection rather than point-in-time assessment. Option B (Weekly review of access logs by a manager) is a periodic, manual review, so it is not continuous.

Option D (Annual penetration testing) is a point-in-time, typically yearly assessment, not continuous monitoring. Option E (Quarterly control testing by internal audit) is periodic assurance performed on a quarterly cycle, not continuous monitoring.

457
Drag & Dropmedium

Order the steps for change management in an IT environment.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Change management includes request, approval, testing, implementation, and review.

458
MCQmedium

The exhibit shows a control monitoring configuration in JSON format. Which of the following is the MOST critical gap in this monitoring setup?

A.The control was last tested over a month ago
B.The data source 'transaction_log' is not specific enough
C.The monitoring frequency is set to daily, which may miss real-time breaches
D.There is no action defined for when the threshold is first breached
AnswerD

A threshold without a defined breach action means the monitoring configuration detects the condition but triggers nothing, leaving the control purely observational. Defining the response, such as alerting or blocking, is what converts detection into an effective control, making this the most critical gap.

Why this answer

The JSON configuration defines a threshold but lacks any corresponding action (e.g., alert, ticket, or automated response) to be triggered when the threshold is first breached. Without an action, the monitoring setup cannot notify or initiate a response, rendering the threshold definition useless for risk mitigation. This is the most critical gap as it directly undermines the control's ability to detect and react to risk events in a timely manner.

Exam trap

The trap here is that candidates focus on operational details like frequency or data source specificity, but the CRISC exam emphasizes that a monitoring setup is incomplete without a defined response action to trigger on threshold breach.

How to eliminate wrong answers

Option A is wrong because the 'lastTested' field indicates the control was tested over a month ago, but testing frequency is separate from monitoring configuration; the JSON defines monitoring parameters, not testing schedules, so this is not a gap in the monitoring setup itself. Option B is wrong because 'transaction_log' as a data source is sufficiently specific for monitoring purposes; the JSON does not require a more granular source like a table name, and the data source can be refined at the query level. Option C is wrong because daily monitoring frequency is appropriate for many risk scenarios, and the JSON does not specify a requirement for real-time monitoring; the critical gap is the missing action, not the frequency.

459
Multi-Selectmedium

Which TWO of the following are appropriate actions when a control deficiency is identified during monitoring? (Select exactly two.)

Select 2 answers
A.Increase the risk appetite
B.Document the deficiency and its impact
C.Assign a remediation plan with deadlines
D.Ignore if the deficiency is minor
E.Immediately terminate the control owner
AnswersB, C

Proper documentation is essential.

Why this answer

Documenting the deficiency and its impact is a fundamental step in the risk and control monitoring process. It ensures that the nature, severity, and potential consequences of the control failure are formally recorded, which is essential for risk assessment, reporting, and audit trails. Without this documentation, the organization cannot properly evaluate the risk exposure or justify remediation efforts.

Exam trap

The trap here is that candidates may confuse 'immediate termination' (Option E) with accountability, but CRISC emphasizes corrective and preventive actions over punitive measures, and ignoring minor deficiencies (Option D) violates the principle of continuous monitoring.

460
MCQeasy

A small logistics company has no formal risk assessment process. The new IT manager wants to introduce a simple, repeatable method to identify and evaluate IT risks. Which action should the manager take FIRST?

A.Commission a full penetration test of all external systems.
B.Outsource all risk decisions to an external consulting firm.
C.Define risk criteria and a common likelihood and impact scale for the organization.
D.Purchase an automated governance, risk, and compliance tool.
AnswerC

Establishing risk criteria and shared scales gives everyone a consistent basis for rating and comparing risks. It is the foundation on which identification, analysis, and evaluation depend, and it can be documented simply without expensive tooling. Once criteria exist, the company can repeat the process, track changes, and prioritize treatment. This is the logical first step for building a formal program.

Why this answer

A repeatable risk process depends on agreed criteria and consistent rating scales. Defining these first allows the company to identify, analyze, and evaluate risks in a uniform way, and it makes later tooling or testing meaningful. Purchasing tools, testing systems, or outsourcing decisions before establishing criteria puts technology and activity ahead of methodology.

Exam trap

The trap here is jumping to tools or testing as the first step, when a repeatable process actually begins with agreed risk criteria and rating scales.

461
MCQmedium

An organization is implementing a new access control system. The project manager is concerned about delays due to user training requirements. Which of the following should the risk practitioner prioritize to ensure effective control implementation?

A.Accelerate the deployment to meet the project deadline
B.Implement a compensating control to reduce training requirements
C.Delay the entire project until training can be completed
D.Ensure user training is completed before go-live
AnswerD

Completing user training before go-live ensures staff can operate the access control system correctly from day one. Untrained users generate misconfigurations, workarounds and access errors that undermine the control, so sequencing training ahead of launch directly prevents the delays and control failures the project manager fears.

Why this answer

User training is a critical success factor for access control systems because misconfigured or improperly used controls can lead to security gaps. Ensuring training is completed before go-live (Option D) aligns with the principle that a control is only effective if users understand how to operate it correctly, preventing human error that could bypass the control's intended protections.

Exam trap

The trap here is that candidates may choose Option B (compensating control) thinking it is a valid risk treatment, but the question asks for what ensures effective control implementation, not just risk reduction—training is non-negotiable for the primary control to work as designed.

How to eliminate wrong answers

Option A is wrong because accelerating deployment to meet a deadline sacrifices control effectiveness; a rushed rollout without user training increases the risk of misconfiguration and security incidents. Option B is wrong because implementing a compensating control to reduce training requirements does not address the root cause—users must still understand the primary access control system to avoid errors that the compensating control cannot fully mitigate. Option C is wrong because delaying the entire project is unnecessarily disruptive; training can be completed in parallel with other project phases, and a full delay may introduce new risks from prolonged use of legacy systems.

462
MCQhard

During a vendor risk tiering exercise, a vendor that stores the organization's customer PII and is critical for daily operations should be classified as which tier?

A.Critical
B.Medium
C.High
D.Low
AnswerA

Handling customer PII plus daily operational dependency means a vendor outage or breach causes regulatory, financial and continuity impact simultaneously. That combination of data sensitivity and operational criticality places the vendor in the critical tier, matching the stem's tiering criteria.

Why this answer

Vendors with access to sensitive data and high service criticality are typically classified as critical (highest tier).

463
MCQmedium

An organization maintains a risk register. Which of the following updates should be made on an ongoing basis?

A.Continuously add new risks as they are identified
B.Update controls only when an incident occurs
C.Revise risk levels only after an internal audit
D.Update the register only during the annual risk assessment
AnswerA

A risk register is a living document; newly identified risks must be captured as they emerge so that assessment, ownership and treatment stay current. Continuous addition satisfies the ongoing-update requirement, unlike periodic reviews of existing entries alone.

Why this answer

A risk register is a living document that must be updated continuously to reflect the current threat landscape. New risks can emerge from changes in technology, business processes, or external threats, and failing to capture them promptly leaves the organization exposed to unmitigated vulnerabilities.

Exam trap

The trap here is that candidates often assume risk registers are updated only during formal assessment cycles, but the CRISC exam emphasizes that risk management is a continuous process requiring real-time updates as new risks are identified.

How to eliminate wrong answers

Option B is wrong because controls should be reviewed and updated proactively based on risk changes, not only reactively after an incident occurs. Option C is wrong because risk levels should be revised whenever new information or changes in the environment affect the likelihood or impact, not only after an internal audit. Option D is wrong because an annual update cycle is too infrequent; risks can emerge or change significantly within a year, and the register must be maintained on an ongoing basis to remain relevant.

464
MCQmedium

A retail bank's risk practitioner is building a risk scenario for its online banking platform. He needs to estimate how frequently an attacker could realistically succeed in exploiting the platform's unpatched web tier. Which of the following provides the MOST quantitative basis for this estimate?

A.Historical loss-event data from the bank's own incident and fraud systems for comparable attack types
B.The Common Vulnerability Scoring System (CVSS) base score of each unpatched vulnerability on the web tier
C.The mean time to remediate critical vulnerabilities reported by the bank's vulnerability management team
D.The annualized rate of new vulnerabilities published in the National Vulnerability Database (NVD) for web servers
AnswerA

Historical internal loss-event data reflects how often comparable attacks actually succeeded against this bank's environment, including its existing controls and threat exposure. This makes it the most defensible quantitative input for frequency estimation in the risk scenario, since it is grounded in observed events rather than theoretical severity or generic external statistics.

Why this answer

Frequency estimation in a risk scenario should be grounded in data that reflects how often the event actually occurs in the organization's own environment. Internal loss-event and incident data capture real attack attempts that succeeded despite existing controls. CVSS scores, industry vulnerability publication rates, and remediation timeliness describe severity or process performance rather than the expected rate of successful exploitation.

Exam trap

The trap here is treating a severity metric such as CVSS as if it were a frequency metric for the risk scenario.

465
MCQmedium

A retail company recently deployed a point-of-sale (POS) system that processes credit card transactions. The system is connected to the corporate network and transmits transaction data to a payment processor over the internet. During a risk assessment, the IT risk manager identifies that the POS system is vulnerable to malware injection via unvalidated input from barcode scanners. Which of the following is the MOST appropriate risk mitigation strategy?

A.Encrypt all transaction data in transit using TLS 1.2.
B.Install a next-generation firewall at the internet boundary.
C.Implement network segmentation to isolate the POS system from the corporate network.
D.Deploy application-layer input validation and sanitization for barcode scanner inputs.
AnswerD

Application-layer input validation and sanitisation directly neutralises the unvalidated barcode scanner input that enables malware injection, addressing the vulnerability at its source rather than merely detecting or containing it. Because the flaw is an application coding weakness, correcting the parsing logic satisfies the stem's specific constraint, unlike network or endpoint controls that leave the injection path open.

Why this answer

The most appropriate risk mitigation strategy because the vulnerability is specifically malware injection via unvalidated input from barcode scanners. Application-layer input validation and sanitization directly addresses the root cause by ensuring that only expected, safe data is processed by the POS system, preventing injection attacks at the point of entry.

Exam trap

The trap here is that candidates often choose network-level controls like firewalls or encryption, overlooking that the vulnerability originates from local input that never traverses the network boundary.

How to eliminate wrong answers

Option A is wrong because encrypting transaction data in transit with TLS 1.2 protects data confidentiality during transmission but does not prevent malware injection through barcode scanner input. Option B is wrong because a next-generation firewall at the internet boundary inspects traffic leaving or entering the network, but it cannot validate input from a local barcode scanner connected directly to the POS system. Option C is wrong because network segmentation isolates the POS system from the corporate network, which limits lateral movement but does not prevent the initial injection of malware via unvalidated barcode scanner input.

466
Matchingmedium

Match each control type to its example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Firewall blocking unauthorized traffic

Intrusion detection system alerts

Backup restoration after data loss

Security warning banners

Why these pairings

Controls are categorized by their function: Preventive controls aim to prevent incidents, Detective controls identify incidents in progress, Corrective controls restore after an incident, and Deterrent controls discourage malicious behavior. Common confusions include swapping preventive with corrective or detective actions.

467
MCQmedium

A risk practitioner is helping a mid-sized healthcare organization update its IT risk register after migrating patient scheduling to a SaaS platform. The vendor's SOC 2 Type II report shows no exceptions, but the contract omits breach notification timelines and data deletion commitments. Which action BEST addresses the residual risk?

A.Accept the risk because the SOC 2 Type II report confirms the vendor's controls are operating effectively.
B.Transfer the risk by purchasing a cyber insurance policy that covers third-party data breaches.
C.Amend the contract to include specific breach notification timelines, data deletion rights, and audit rights, then reassess the residual risk.
D.Perform a penetration test against the SaaS platform to validate the vendor's security controls.
AnswerC

The SOC 2 report addresses the vendor's internal controls, but the missing contractual terms represent unmitigated legal and compliance risk. Amending the contract to add breach notification timelines, data deletion commitments, and audit rights directly addresses those gaps. Reassessing residual risk afterward ensures the risk register reflects the improved control environment and the organization's reduced exposure.

Why this answer

The vendor's SOC 2 Type II report gives assurance over controls, but it does not replace contractual protections. Missing breach notification timelines and data deletion commitments create legal, regulatory, and reputational risk that the organization must address. Amending the contract to include these terms, along with audit rights, directly mitigates the gap and allows the risk practitioner to reassess residual risk accurately.

Exam trap

The trap here is assuming that a clean SOC 2 Type II report eliminates the need to address contractual gaps such as breach notification and data deletion terms.

468
MCQhard

In the FAIR framework, which of the following correctly represents the calculation of Loss Event Frequency (LEF)?

A.LEF = Threat Event Frequency × Vulnerability
B.LEF = Threat Event Frequency + Vulnerability
C.LEF = Asset Value × Vulnerability
D.LEF = Annualized Rate of Occurrence × Single Loss Expectancy
AnswerA

LEF combines how often a threat agent acts with how often those actions succeed. Multiplying Threat Event Frequency by Vulnerability (the probability a threat event becomes a loss event) satisfies FAIR's requirement to express frequency as a rate, not a monetary value or control strength.

Why this answer

In the FAIR (Factor Analysis of Information Risk) framework, Loss Event Frequency (LEF) is calculated as the product of Threat Event Frequency (TEF) and Vulnerability (Vuln). This reflects that the frequency of loss events depends on how often a threat event occurs and the probability that the threat event will result in a loss, which is the vulnerability component. The multiplication captures the dependency: even if threats are frequent, low vulnerability reduces LEF, and vice versa.

Exam trap

The trap here is that candidates often confuse LEF with ALE or mistakenly think vulnerability is additive, leading them to choose Option B or D, but FAIR explicitly defines LEF as a product of TEF and vulnerability, not a sum or a monetary metric.

How to eliminate wrong answers

Option B is wrong because LEF is not a sum of Threat Event Frequency and Vulnerability; addition would incorrectly imply that vulnerability adds to frequency rather than acting as a probabilistic multiplier. Option C is wrong because Asset Value is not part of LEF calculation; it is used in Loss Magnitude (LM) to compute risk, not in frequency estimation. Option D is wrong because Annualized Rate of Occurrence (ARO) × Single Loss Expectancy (SLE) is the formula for Annualized Loss Expectancy (ALE) in quantitative risk analysis, not LEF in FAIR; LEF is a frequency metric, not a monetary loss calculation.

469
MCQeasy

Which type of control is designed to stop an undesirable event from occurring?

A.Corrective control
B.Preventive control
C.Directive control
D.Detective control
AnswerB

Preventive controls act before or during an event, blocking it from occurring through mechanisms such as access restrictions, segregation of duties or input validation. Detective controls only identify events after the fact, and corrective controls restore operations afterwards, so prevention uniquely satisfies stopping the undesirable event.

Why this answer

Preventive control is designed to stop an undesirable event from occurring by enforcing policies or technical barriers before the event happens. For example, a firewall rule that blocks inbound traffic on port 23 (Telnet) prevents unauthorized remote access attempts, directly reducing the likelihood of a security incident.

Exam trap

The trap here is that candidates often confuse preventive controls with detective controls, mistakenly thinking that monitoring or alerting (detective) can stop an event, when in fact prevention requires proactive blocking mechanisms like access control lists (ACLs) or input validation.

How to eliminate wrong answers

Option A is wrong because corrective control is applied after an undesirable event has occurred, aiming to restore normal operations (e.g., restoring data from backup after a ransomware attack). Option C is wrong because directive control guides behavior through policies or procedures but does not physically or technically stop an event (e.g., a password policy requiring complex passwords does not prevent a brute-force attack by itself). Option D is wrong because detective control identifies that an undesirable event has occurred or is occurring, such as an intrusion detection system (IDS) alerting on suspicious traffic, but it does not stop the event.

470
Multi-Selectmedium

A risk practitioner is assessing the security of an organization's software development lifecycle (SDLC). The organization wants to integrate security early to reduce the cost and impact of fixing vulnerabilities. Which TWO of the following practices are MOST effective for achieving this goal? (Choose two.)

Select 2 answers
A.Performing penetration testing just before production release.
B.Training developers on secure coding practices.
C.Using a web application firewall (WAF) to block attacks in production.
D.Conducting a security audit after the application is deployed.
E.Conducting static application security testing (SAST) during the coding phase.
AnswersB, E

Secure coding training equips developers with the knowledge to avoid common vulnerabilities such as injection and cross-site scripting. When developers understand security principles, they can write more secure code from the start, reducing the need for later fixes. This is a foundational shift-left practice that embeds security into the development process and directly reduces the cost of remediation.

Why this answer

Integrating security early in the SDLC means identifying and fixing vulnerabilities during development rather than after deployment. Static application security testing (SAST) and secure coding training are both shift-left practices that enable developers to find and prevent flaws early, reducing remediation costs. Penetration testing, post-deployment audits, and WAFs are later-stage or runtime controls that do not achieve early integration.

Exam trap

The trap here is selecting later-stage controls like penetration testing or WAFs as effective for early integration, when they actually address vulnerabilities after code is written or deployed.

471
Multi-Selecthard

In the context of IT risk reporting to the board, which THREE elements should be included to effectively communicate risk?

Select 3 answers
A.Detailed technical logs
B.Top risks and status
C.Risk heat map
D.Employee performance reviews
E.Risk trend analysis
AnswersB, C, E

Top risks and status give the board a prioritised view of the most significant exposures and whether mitigation is on track, satisfying the need for concise, decision-useful reporting. Raw technical logs or exhaustive registers would obscure the strategic picture the board requires.

Why this answer

Option B (Top risks and status) is correct because board-level reporting must prioritize the most significant risks and their current mitigation status, giving directors a concise view of what threatens organizational objectives and how management is responding. Option C (Risk heat map) is correct because a heat map visually plots risks by likelihood and impact, enabling the board to quickly grasp relative exposure and prioritize attention without wading through technical detail. Option E (Risk trend analysis) is correct because showing how risk levels change over time (e.g., increasing, stable, or decreasing) demonstrates whether risk management is effective and supports forward-looking governance decisions.

Option A (Detailed technical logs) does not belong because raw logs are operational artifacts for IT staff, not strategic governance information, and would overwhelm the board with irrelevant granularity. Option D (Employee performance reviews) does not belong because individual HR performance data is unrelated to enterprise risk communication and would be inappropriate to present in a board risk report.

Exam trap

CRISC often tests the distinction between operational/technical detail and strategic risk communication, tempting candidates to select detailed technical logs because they seem data-rich, when the board requires aggregated, business-oriented views like top risks, heat maps, and trends.

472
MCQmedium

A financial services firm's risk register shows that a critical trading application has a high inherent risk of unauthorized access. The risk owner decides to implement multifactor authentication (MFA) and role-based access controls (RBAC). After implementation, the residual risk score decreases but remains above the risk appetite. Which of the following should the risk practitioner recommend NEXT?

A.Perform additional risk response to further reduce the residual risk to within appetite.
B.Accept the residual risk because the controls have reduced it significantly.
C.Remove the existing controls and reassess the inherent risk.
D.Transfer the entire risk to a third party through insurance.
AnswerA

When residual risk remains above the risk appetite after implementing controls, the risk practitioner should recommend further risk response, such as additional controls, risk transfer, or avoidance. This aligns with the CRISC principle of continuous risk treatment until risk is within acceptable levels, ensuring alignment with organizational objectives.

Why this answer

The correct answer is to perform additional risk response because residual risk still exceeds the risk appetite. CRISC emphasizes that risk treatment is iterative: after controls are applied, if residual risk is not within appetite, further action is needed. This could include additional controls, risk avoidance, or transfer, but the key is to continue treatment until risk is acceptable.

Exam trap

The trap here is assuming that any reduction in risk after implementing controls is sufficient, even if residual risk remains above the risk appetite.

473
MCQmedium

A bank implements a new transaction monitoring system to detect fraudulent activities. After six months, the system has a high false positive rate, causing analysts to miss real threats. Which of the following is the BEST way to address this risk?

A.Accept the false positives as a cost of doing business
B.Tune the system to reduce false positives
C.Remove the monitoring system to focus on other controls
D.Hire additional analysts to review all alerts
AnswerB

Tuning thresholds and rules reduces false positives, restoring analyst capacity to investigate genuine alerts. This addresses the stated risk that excessive false positives cause real threats to be missed, rather than replacing or ignoring the monitoring system.

Why this answer

B is correct because tuning the system involves adjusting detection thresholds, rules, or machine learning models to reduce false positives while maintaining sensitivity to actual fraud. This directly addresses the root cause—poorly calibrated detection logic—without sacrificing the system's primary function or incurring unsustainable costs.

Exam trap

The trap here is that candidates may choose D (hire more analysts) because it seems like a direct solution to alert overload, but it fails to address the system's inefficiency and is not a sustainable risk response per CRISC principles.

How to eliminate wrong answers

Option A is wrong because accepting false positives as a cost of doing business ignores the operational risk that analysts miss real threats, leading to potential financial and regulatory damage. Option C is wrong because removing the monitoring system eliminates the primary detective control for fraud, leaving the bank exposed to undetected fraudulent transactions. Option D is wrong because hiring additional analysts does not fix the underlying system misconfiguration; it only masks the symptom with increased headcount, which is not scalable and still risks alert fatigue.

474
MCQmedium

A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?

A.Model bias
B.Adversarial attacks
C.Explainability requirements
D.Data privacy in AI training
AnswerA

Model bias is the AI/ML risk where training data or algorithm design produces systematically unfair outcomes for particular demographic groups. It directly matches the stem's concern about biased credit-scoring decisions against protected groups, distinguishing it from other risks such as drift, opacity or overfitting.

Why this answer

Model bias occurs when an AI/ML model produces systematically unfair outcomes against certain demographic groups, often because training data reflects historical discrimination or underrepresentation. In credit scoring, if the model learns from historical lending data that excluded or disadvantaged certain groups, it will replicate and even amplify that bias. This is the risk most directly associated with biased outcomes.

Exam trap

CRISC often tests the distinction between AI/ML risk categories (bias, adversarial attacks, explainability, privacy), so candidates who pick explainability or privacy miss that the question is about unfair outcomes, which is bias.

How to eliminate wrong answers

Option B is wrong because adversarial attacks involve malicious actors deliberately manipulating inputs to cause the model to misclassify (e.g., evasion, poisoning), not unintentional bias against demographic groups. Option C is wrong because explainability requirements concern the ability to understand and articulate how a model reaches a decision — a related but distinct governance concern, not the bias itself. Option D is wrong because data privacy in AI training concerns the handling of personal data used to train models (e.g., consent, GDPR), not the fairness of model outputs.

475
MCQhard

A company's control monitoring shows that a detective control has been 100% effective for the past year. However, a recent incident revealed that a data breach went undetected for three months. What is the MOST likely cause?

A.The control failure occurred but was not recorded.
B.The monitoring frequency was insufficient to detect the breach.
C.The control was not designed to detect the type of breach that occurred.
D.The control monitoring logs were tampered with.
AnswerC

A detective control can operate exactly as designed yet still miss a breach if its detection logic does not cover that attack vector. The three-month gap indicates a design scope limitation, not control failure or monitoring error, so the breach type fell outside the control's intended coverage.

Why this answer

The detective control was 100% effective based on monitoring data, but it failed to detect a data breach for three months. This indicates the control was not designed to detect the specific type of breach that occurred, such as an exfiltration via an encrypted tunnel or a non-standard protocol. A control can be perfectly effective against known patterns while being blind to novel or out-of-scope attack vectors, which is why option C is correct.

Exam trap

The trap here is that candidates confuse 'control effectiveness' (how often it works when triggered) with 'control coverage' (whether it is designed to detect the relevant risk), leading them to incorrectly choose monitoring frequency or log tampering instead of recognizing the design gap.

How to eliminate wrong answers

Option A is wrong because if the control failure occurred but was not recorded, the monitoring logs would still show the control as effective for recorded events, but the breach would have been detected if the control was designed for that attack type; the issue is design, not recording. Option B is wrong because monitoring frequency (e.g., log review every 24 hours) would affect detection latency, but a three-month undetected breach implies the control never triggered, not that it triggered but was missed between reviews. Option D is wrong because tampered logs would likely show gaps or anomalies in the monitoring data, but the scenario states the control was 100% effective based on monitoring, implying logs were intact and consistent.

476
Multi-Selecthard

Which TWO of the following are characteristics of quantitative risk analysis compared to qualitative risk analysis? (Select 2)

Select 2 answers
A.It is always easier to communicate to non-technical stakeholders
B.It produces results in monetary values or percentages
C.It supports cost-benefit analysis of controls
D.It requires less specialized expertise to perform
E.It relies solely on expert judgment without numerical data
AnswersB, C

Quantitative analysis expresses likelihood and impact numerically, yielding monetary values or percentages, which satisfies the stem's requirement for a defining characteristic. Unlike qualitative methods that rank risks descriptively (high/medium/low), this numeric output enables direct cost-benefit comparison and expected loss calculation, supporting the financial justification CRISC expects.

Why this answer

Option B is correct because quantitative risk analysis expresses risk in numerical terms such as monetary values (e.g., annualized loss expectancy, ALE = SLE × ARO) or percentages (e.g., probability of occurrence), which is the defining characteristic that distinguishes it from qualitative analysis. Option C is correct because these monetary outputs directly enable cost-benefit analysis of controls, allowing an organization to compare a control's cost against the expected risk reduction in financial terms. Options A and D are incorrect because quantitative analysis is generally harder to communicate to non-technical stakeholders and requires more specialized expertise (statistics, financial modeling) than qualitative methods.

Option E is incorrect because quantitative analysis depends on numerical data and probabilistic estimates, not solely on expert judgment, which is more characteristic of qualitative approaches.

Exam trap

The trap here is that candidates often confuse 'easier to communicate' with quantitative analysis because numbers seem objective, but in reality, qualitative ratings are usually simpler for non-technical audiences to grasp without specialized training.

477
MCQhard

An organization uses a KRI that tracks the average time to patch critical vulnerabilities. The metric has been increasing over the past three months. What does this indicate from a risk perspective?

A.The control effectiveness is improving
B.The risk of exploitation is increasing
C.The risk appetite has been reduced
D.The risk of exploitation is decreasing
AnswerB

Longer patch times leave critical vulnerabilities exposed for extended windows, so the likelihood that an attacker exploits a known flaw rises. The KRI measures exposure duration, and a sustained upward trend signals deteriorating risk posture requiring escalation or remediation.

Why this answer

An increasing average time to patch critical vulnerabilities indicates that the organization is taking longer to remediate known security weaknesses. From a risk perspective, this directly increases the window of exposure, making it more likely that an attacker will exploit a vulnerability before a patch is applied. Therefore, the risk of exploitation is increasing.

Exam trap

The trap here is that candidates may confuse a rising KRI metric with improved security posture, failing to recognize that longer remediation times increase exposure and risk of exploitation.

How to eliminate wrong answers

Option A is wrong because an increasing patch time indicates control effectiveness is deteriorating, not improving; effective controls would show decreasing or stable patch times. Option C is wrong because risk appetite is a strategic decision about acceptable risk levels, not a metric derived from patch timeliness; a reduced risk appetite would typically drive faster patching, not slower. Option D is wrong because it is the direct opposite of the correct interpretation; increasing patch time means the risk of exploitation is increasing, not decreasing.

478
Multi-Selecteasy

When performing a risk assessment, which TWO of the following are components of inherent risk?

Select 2 answers
A.Residual risk level
B.Impact of the risk event
C.Control effectiveness
D.Likelihood of a threat event
E.Cost-benefit analysis of controls
AnswersB, D

Inherent risk is assessed before controls, and impact measures the potential magnitude of loss or harm should the risk event occur. It forms one of the two components, alongside likelihood, that together express inherent risk exposure in the absence of mitigation.

Why this answer

Inherent risk considers likelihood and impact without controls.

479
MCQmedium

During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?

A.Accept the risk owner's decision
B.Document the deficiency and move on
C.Communicate the risk exposure to senior management
D.Escalate directly to the board
AnswerC

Escalating the exposure to senior management is the first step because the risk owner's budget refusal leaves the practitioner without authority to accept or fund the risk. Senior management owns risk acceptance at the organisational level, so they must decide whether to accept, mitigate or transfer the exposure.

Why this answer

The risk practitioner's primary duty is to ensure that senior management is aware of material risk exposures that could impact business objectives. When a key control for a high-risk process is ineffective and the risk owner refuses to remediate due to budget constraints, the practitioner must communicate the residual risk exposure to senior management, who have the authority to allocate resources and make strategic risk acceptance decisions. This aligns with the CRISC framework's emphasis on escalating risk information to the appropriate decision-making level when the risk owner's response is inadequate.

Exam trap

The trap here is that candidates confuse 'documenting the deficiency' (Option B) with completing the risk management process, but CRISC requires active communication of risk exposure to the appropriate authority, not just passive recording.

How to eliminate wrong answers

Option A is wrong because accepting the risk owner's decision without further action would violate the risk practitioner's responsibility to ensure that risk acceptance is based on complete and accurate information; the risk owner's budget-driven refusal does not constitute a valid risk acceptance decision without senior management's informed consent. Option B is wrong because simply documenting the deficiency and moving on fails to address the material risk exposure; documentation is necessary but not sufficient—the practitioner must actively communicate the risk to those who can authorize additional controls or formally accept the risk. Option D is wrong because escalating directly to the board bypasses the proper escalation chain; the board should only be involved for strategic-level risks or after senior management has been informed and has failed to act, not as a first step.

480
MCQhard

A financial services firm is completing its annual IT risk assessment. The CISO wants to compare the relative severity of 40 identified risks across different business units and prioritize which ones to treat first. The risk team has limited quantitative data and needs a consistent, repeatable method that reflects both likelihood and impact. Which approach BEST meets this need?

A.Calculate the annualized loss expectancy for each risk using historical loss data.
B.Rank the risks by the total number of identified vulnerabilities associated with each.
C.Assign each risk to the business unit that owns the affected asset and treat them independently.
D.Score each risk on defined likelihood and impact scales and plot them on a risk matrix.
AnswerD

A risk matrix with defined likelihood and impact scales gives a consistent, repeatable way to rank many risks when quantitative data is limited. It reflects both dimensions the CISO cares about and produces comparable severity ratings across business units, enabling defensible prioritization. This qualitative approach is the standard method for relative ranking during an enterprise IT risk assessment.

Why this answer

When quantitative data is scarce but consistent comparison across many risks is required, a risk matrix with defined likelihood and impact scales is the appropriate tool. It normalizes judgments, reflects both dimensions of risk, and yields repeatable severity ratings that support prioritization across business units. This aligns with standard IT risk assessment practice for relative risk ranking.

Exam trap

The trap here is assuming annualized loss expectancy is always superior, when limited data and the need for consistent relative ranking actually favor a defined qualitative risk matrix.

481
MCQeasy

A manufacturing company uses an industrial control system (ICS) that is connected to the corporate network for monitoring. The risk manager is identifying risks related to this connectivity. Which of the following is the MOST significant risk?

A.Compromise of ICS causing physical damage to manufacturing equipment.
B.Malware infection spreading from corporate to ICS network.
C.Network congestion due to ICS traffic affecting corporate users.
D.Unauthorized access to corporate data through the ICS connection.
AnswerA

Corporate network connectivity exposes the ICS to lateral movement from compromised business systems, allowing attackers to manipulate controllers and cause physical harm to equipment or personnel. This safety and availability impact outweighs data confidentiality or reputational concerns, making it the most significant risk.

Why this answer

The most significant risk is that a compromise of the ICS could lead to physical damage, such as equipment destruction, safety hazards, or environmental release. Unlike IT systems where data loss is the primary concern, ICS failures directly impact the physical world, making safety and operational integrity the top priority in risk identification.

Exam trap

The trap here is that candidates often focus on the most common IT risk (data breach or malware) and overlook the unique ICS risk of physical damage, which is the defining characteristic of operational technology risk management.

How to eliminate wrong answers

Option B is wrong because while malware spreading from corporate to ICS is a real threat, it is a means to an end; the ultimate impact (physical damage) is more significant than the infection itself. Option C is wrong because network congestion is a performance issue, not a safety or integrity risk, and ICS traffic is typically low-bandwidth and predictable. Option D is wrong because unauthorized access to corporate data is a confidentiality risk, which is secondary to the safety and availability risks posed by ICS compromise.

482
MCQmedium

A risk practitioner is designing an IT risk management programme. Which of the following is the BEST sequence of components to establish?

A.Risk register, risk assessment methodology, risk treatment process, risk reporting, risk management policy
B.Risk assessment methodology, risk register, risk treatment process, risk management policy, risk reporting
C.Risk reporting, risk management policy, risk assessment methodology, risk register, risk treatment process
D.Risk management policy, risk assessment methodology, risk register, risk treatment process, risk reporting
AnswerD

Establishing the policy first sets risk appetite and governance, then methodology standardises assessment, the register records findings, treatment addresses them, and reporting communicates results. This order ensures each component builds on approved direction rather than ad hoc activity.

Why this answer

The best sequence starts with a risk management policy, which provides the mandate and framework. Then a risk assessment methodology defines how risks are identified and evaluated. Next, a risk register captures the risks.

Then a risk treatment process defines how to respond. Finally, risk reporting communicates to stakeholders. This logical order ensures that each component builds on the previous one.

Exam trap

CRISC often tests the logical sequence of establishing risk management components, and candidates may incorrectly place reporting or register before policy and methodology.

How to eliminate wrong answers

Option A is wrong because it starts with a risk register before establishing a methodology or policy, which is illogical. Option B is wrong because it places risk management policy after risk treatment, but policy should come first to guide the entire process. Option C is wrong because it starts with risk reporting before any assessment or policy, which is backwards.

483
MCQmedium

An organization has implemented a new key risk indicator (KRI) for vendor management that measures the percentage of vendors without a signed contract. The current value is 15%, exceeding the risk appetite threshold of 10%. The risk owner wants to know the most appropriate action to take based on this KRI. What should the risk practitioner recommend?

A.Increase the frequency of KRI reporting from monthly to weekly to monitor the trend.
B.Update the risk appetite threshold to 15% to align with the current value.
C.Immediately communicate the KRI breach to the board of directors.
D.Analyze the root cause of the high percentage and develop a remediation plan.
AnswerD

A KRI exceeding the 10% appetite threshold signals the control gap needs investigation, not immediate escalation or acceptance. Root cause analysis identifies why vendors lack signed contracts, enabling a targeted remediation plan that brings the metric back within tolerance.

Why this answer

When a KRI exceeds the risk appetite threshold, the immediate priority is to understand why the breach occurred and to implement corrective actions. Analyzing the root cause and developing a remediation plan directly addresses the underlying issue—vendors without signed contracts—rather than merely monitoring or adjusting thresholds. This aligns with the CRISC principle that KRIs are leading indicators that should trigger risk response, not just reporting changes.

Exam trap

The trap here is that candidates often confuse monitoring actions (like increasing reporting frequency) with risk response actions, or they mistakenly believe that adjusting the threshold to match the current value is a valid risk treatment instead of recognizing it as risk acceptance without proper analysis.

How to eliminate wrong answers

Option A is wrong because increasing reporting frequency from monthly to weekly only monitors the trend without addressing the root cause or reducing the percentage; it is a monitoring action, not a risk treatment action. Option B is wrong because updating the risk appetite threshold to match the current value eliminates the KRI's purpose as an early warning indicator and effectively accepts the risk without analysis or remediation. Option C is wrong because immediate communication to the board is premature before root cause analysis and remediation planning; escalation is appropriate only after the risk owner has assessed the situation and determined the severity.

484
Matchingmedium

Match each risk response strategy to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Eliminate the activity that causes the risk

Reduce the likelihood or impact of the risk

Shift the risk to a third party, e.g., insurance

Acknowledge the risk and take no further action

Why these pairings

The correct matches are: Avoid – decision to not perform the activity; Accept – formal acceptance of risk; Mitigate – reduce likelihood/impact; Transfer – shift to another party. Common confusions include mixing transfer with avoidance and acceptance with mitigation.

485
MCQeasy

A retail company is assessing the risk of a point-of-sale (POS) system compromise. The risk team estimates that a successful attack would cost $500,000 in fines, remediation, and lost sales. The likelihood of such an attack in the next year is estimated at 20%. What is the annualized loss expectancy (ALE) for this risk scenario?

A.$20,000
B.$100,000
C.$500,000
D.$2,500,000
AnswerB

ALE is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, the single loss is $500,000 and the likelihood or ARO is 0.20, yielding an ALE of $100,000. This quantitative value represents the expected average annual loss and is used to compare risk treatment options against their costs.

Why this answer

The annualized loss expectancy is computed by multiplying the single loss expectancy by the annualized rate of occurrence. With a $500,000 impact and a 20% annual likelihood, the expected annual loss is $100,000. This quantitative result allows the organization to compare the cost of potential controls against the expected loss and to prioritize the POS risk against other risks in the risk register.

Exam trap

The trap here is confusing single loss expectancy with annualized loss expectancy, or dividing instead of multiplying impact by likelihood.

486
Multi-Selecthard

During risk identification, a risk manager is reviewing threat intelligence sources. Which THREE of the following are considered legitimate sources of threat intelligence? (Choose three.)

Select 3 answers
A.Government advisories such as CISA Known Exploited Vulnerabilities (KEV) catalog
B.Unverified social media rumors
C.OSINT (Open-Source Intelligence) feeds
D.Information Sharing and Analysis Centers (ISACs)
E.Vendor sales presentations
AnswersA, C, D

Government advisories such as the CISA KEV catalog are authoritative, vetted sources listing vulnerabilities known to be actively exploited. They provide reliable, actionable intelligence for risk identification, satisfying the requirement for legitimate threat intelligence sources rather than unverified or vendor-marketing material.

Why this answer

OSINT (open-source intelligence), ISACs (sector-specific sharing), and government advisories (e.g., CISA KEV) are established threat intelligence sources. Social media rumor and vendor sales pitches are not reliable.

487
MCQmedium

A risk officer is evaluating the effectiveness of a control that prevents unauthorized changes to configuration files. The control has not detected any unauthorized changes in the past year. What does this indicate?

A.The control is unnecessary because no changes occurred.
B.The control is not configured correctly to detect changes.
C.The control is operating effectively and no violations occurred.
D.Further testing is needed to determine control effectiveness.
AnswerD

Zero detected changes may reflect a genuinely effective control or simply a lack of testing rigour, so absence of findings alone proves nothing. Additional testing, such as simulated unauthorised changes, is required to confirm the control actually functions.

Why this answer

The absence of detected unauthorized changes does not automatically confirm control effectiveness; it could also indicate that the control is not properly configured to detect changes (e.g., missing file integrity monitoring rules, incorrect baseline, or disabled logging). Further testing—such as manually introducing a test change or reviewing audit logs—is required to verify that the control can actually detect violations. This aligns with CRISC best practices for validating control effectiveness through testing rather than relying solely on absence of alerts.

Exam trap

The trap here is that candidates assume 'no detected violations' equals 'control is effective,' but CRISC emphasizes that absence of evidence is not evidence of absence—further testing is required to rule out detection failures.

How to eliminate wrong answers

Option A is wrong because the control's purpose is to detect unauthorized changes, and the fact that no changes were detected does not prove no changes occurred—it could mean the control missed them. Option B is wrong because while misconfiguration is a possible cause, it is not the only explanation; the control could be correctly configured but simply not have been triggered due to a lack of violations, so concluding misconfiguration without evidence is premature. Option C is wrong because the absence of detected violations does not confirm control effectiveness; it only indicates that no violations were recorded, which could be due to the control failing to detect them (e.g., a false negative scenario).

488
MCQhard

A risk practitioner is analyzing the results of a phishing simulation. The simulation had a 15% click rate on a test email targeting finance department staff. Which of the following conclusions is MOST valid regarding IT risk identification?

A.The email filtering system is ineffective
B.There is an increased risk of successful targeted phishing attacks against finance staff
C.This is an effective red team exercise
D.The organization has a low risk of credential theft
AnswerB

A 15% click rate among finance staff demonstrates that this group is susceptible to phishing lures, directly evidencing elevated likelihood of a successful targeted attack against them. The simulation result identifies a real human-factor risk, not merely a theoretical one.

Why this answer

A 15% click rate on a targeted phishing simulation indicates that a significant portion of finance staff are susceptible to social engineering, which directly increases the risk of a successful targeted phishing attack. This finding is a key input for IT risk identification because it reveals a control weakness (user awareness) that could be exploited by attackers to gain unauthorized access or initiate fraudulent transactions. The click rate itself is a risk indicator, not a definitive measure of control effectiveness like email filtering.

Exam trap

The trap here is that candidates may confuse a user awareness test result with a direct assessment of technical controls like email filtering, when in fact the simulation is designed to bypass those controls to measure human risk.

How to eliminate wrong answers

Option A is wrong because a 15% click rate does not directly measure the effectiveness of the email filtering system; the simulation email was deliberately allowed through to test user behavior, so filtering bypass is irrelevant to this conclusion. Option C is wrong because the simulation is a test of user awareness, not a red team exercise; red team exercises involve broader adversarial simulation including multiple attack vectors, not just a single phishing email. Option D is wrong because a 15% click rate indicates a non-trivial risk of credential theft, as clicking a phishing link can lead to credential harvesting or malware installation, so the risk is not low.

489
MCQmedium

A risk practitioner at a regional hospital is building a risk register entry for the loss of availability of its electronic health record (EHR) system. The practitioner wants to express the risk in a way that supports later quantification and treatment decisions. Which of the following BEST describes how the risk should be documented in the register?

A.As a paired statement of the event, its cause, and its business impact, such as 'EHR outage caused by ransomware exploitation of an unpatched server, leading to delayed clinical care and regulatory reporting failure'.
B.As a list of all unpatched servers and their IP addresses across the clinical network.
C.As a statement of the threat source only, such as 'ransomware gang targeting healthcare'.
D.As an accepted risk with no further detail because the EHR vendor holds a Business Associate Agreement.
AnswerA

A well-formed risk statement pairs a cause (unpatched server) with an event (ransomware-driven EHR outage) and a business consequence (delayed care, reporting failure). This structure lets the practitioner assess likelihood and impact, assign inherent and residual ratings, and choose treatment. It also aligns the register entry with ISACA guidance that risks be expressed in business-relevant terms so leadership can compare and fund responses.

Why this answer

Expressing risk as a cause-event-impact triplet gives the practitioner the components needed to estimate likelihood and magnitude and to select treatment. It also links technical conditions to business outcomes, which is what the register is for. The other choices capture only an actor, only a vulnerability inventory, or an unsupported acceptance decision, none of which supports quantification or comparison across the risk portfolio.

Exam trap

The trap here is treating a vulnerability finding or a threat actor profile as if it were a risk, when a risk requires an event tied to a business impact.

490
MCQhard

During a risk analysis, the risk team finds that a legacy inventory system has a single point of failure: one administrator holds the only credentials for the backup restoration process. The system supports regulatory filings with a hard deadline. Management proposes documenting the situation in the risk register and revisiting it next year. Which action should the risk practitioner take?

A.Transfer the risk by purchasing additional cyber insurance for the inventory system.
B.Agree, because the risk is documented and the system still functions today.
C.Escalate the concentration risk and recommend immediate interim controls such as credential escrow or a second trained administrator.
D.Remove the administrator's access until a permanent solution is approved.
AnswerC

The finding combines high impact with a low-cost remedy, which justifies prompt action rather than annual review. Credential escrow or a cross-trained backup administrator reduces both availability and integrity exposure quickly. Escalating also places the decision with the accountable owner, ensuring the regulatory deadline risk is weighed against the effort of remediation now.

Why this answer

A single point of failure tied to a hard regulatory deadline and held by one person warrants prompt treatment, especially when low-cost interim measures exist. Escalating with a recommendation to escrow credentials or train a second administrator addresses availability and fraud exposure immediately while a permanent solution is designed. Deferring, blocking access, or relying solely on insurance leaves the operational and compliance risk intact.

Exam trap

The trap here is believing that logging a risk in the register and scheduling a future review constitutes an adequate risk response.

491
Multi-Selecthard

Which THREE of the following are effective risk identification techniques for a cloud migration project? (Select exactly THREE.)

Select 3 answers
A.Vendor lock-in analysis
B.User acceptance testing (UAT)
C.Cloud security assessment
D.Data classification
E.Network scanning of on-premises infrastructure
AnswersA, C, D

Vendor lock-in analysis identifies risks arising from proprietary cloud services, non-portable data formats and contractual exit barriers. It is effective for cloud migration because dependency on a single provider constrains future flexibility, a risk absent from traditional on-premises hosting.

Why this answer

Vendor lock-in analysis (A) is a valid risk identification technique because it surfaces strategic and exit risks tied to proprietary APIs, managed services, and data egress costs that can constrain future portability during a cloud migration. Cloud security assessment (C) is correct because it identifies threats and control gaps in the shared responsibility model, including IAM misconfigurations, encryption coverage, and compliance exposure specific to the target cloud. Data classification (D) is correct because it reveals which datasets are sensitive, regulated, or business-critical, driving risks around residency, sovereignty, access control, and migration sequencing.

User acceptance testing (B) is a validation activity performed after implementation to confirm the solution meets business needs, not a technique for identifying risks up front. Network scanning of on-premises infrastructure (E) is a technical discovery or vulnerability assessment activity; while it may feed risk data, it is not itself a risk identification technique for the migration project.

Exam trap

The trap here is confusing post-migration validation activities (UAT) or on-premises-focused scans with proactive risk identification techniques that are specifically designed to uncover cloud migration risks.

492
MCQeasy

An organization wants to promote a risk-aware culture. Which of the following actions is most effective in encouraging employees to report incidents without fear?

A.Establishing a non-punitive incident reporting policy
B.Conducting annual security awareness training
C.Publishing risk metrics on the intranet
D.Providing incentives for risk identification
AnswerA

A non-punitive reporting policy removes the fear of disciplinary consequences, which is the primary barrier to incident disclosure. By guaranteeing that honest reporters are not blamed, it directly satisfies the stem's constraint of encouraging employees to report incidents without fear, increasing early detection.

Why this answer

A non-punitive incident reporting policy is the most effective action because it directly removes the fear of retaliation or blame, which is the primary psychological barrier to reporting security incidents. By guaranteeing that employees will not face disciplinary action for reporting their own mistakes or observed issues, the organization fosters psychological safety and encourages timely disclosure. This aligns with the CRISC principle that a risk-aware culture requires trust and openness, which cannot be achieved through training or metrics alone if fear persists.

Exam trap

The trap here is that candidates often choose 'Conducting annual security awareness training' because they equate awareness with culture change, but the question specifically targets the barrier of fear, which training alone cannot remove.

How to eliminate wrong answers

Option B is wrong because annual security awareness training, while important for knowledge, does not address the emotional or cultural barrier of fear; employees may still hide incidents if they believe reporting will lead to punishment. Option C is wrong because publishing risk metrics on the intranet is a communication tactic that informs but does not create a safe reporting environment; it may even increase anxiety if metrics highlight failures without a supportive policy. Option D is wrong because providing incentives for risk identification can inadvertently encourage gaming the system or reporting only low-risk items, and it does not eliminate the fear of consequences for reporting one's own errors or serious incidents.

493
MCQhard

A risk practitioner is assessing a new e-commerce platform. The business owner insists that the platform must be available 24/7. The practitioner identifies that a distributed denial-of-service (DDoS) attack could cause an outage. Which of the following BEST describes the risk scenario?

A.A risk that is inherent to the e-commerce platform and cannot be mitigated, so it must be accepted
B.A control failure (lack of DDoS protection) that directly causes a financial loss without any threat event
C.A vulnerability (DDoS attack) causing a threat event (inadequate DDoS protection) resulting in a loss of confidentiality
D.A threat event (DDoS attack) exploiting a vulnerability (inadequate DDoS protection) leading to an impact (loss of availability)
AnswerD

This option correctly structures the risk as a threat event exploiting a vulnerability to cause an impact on a business objective. In CRISC, risk scenarios should link threat, vulnerability, and impact. The DDoS attack is the threat event, the inadequate protection is the vulnerability, and the loss of availability of the e-commerce platform is the impact, which aligns with the business owner's availability requirement.

Why this answer

A well-formed risk scenario describes a threat event exploiting a vulnerability to produce an impact on business objectives. The DDoS attack is the threat, inadequate DDoS protection is the vulnerability, and loss of availability is the impact. This structure supports consistent risk assessment and treatment planning, and it directly connects to the business owner's availability requirement.

Exam trap

The trap here is reversing threat and vulnerability roles or focusing only on the control failure without identifying the threat event and impact.

494
MCQhard

A risk practitioner is using the ISACA risk scenario development approach to articulate a risk related to a third-party payment processor. The practitioner wants to ensure the scenario includes all key components. Which of the following components is MOST critical to include to enable effective risk analysis and treatment?

A.The asset, threat, vulnerability, and potential impact
B.The name of the specific threat actor group
C.The regulatory requirements applicable to the payment processor
D.The cost of the third-party processor's service
AnswerA

The core components of a risk scenario are the asset at risk, the threat that could affect it, the vulnerability that could be exploited, and the potential impact. These elements enable the practitioner to assess likelihood and impact, and to determine appropriate risk treatment. Without them, the scenario is incomplete and cannot be effectively analyzed or managed.

Why this answer

A well-structured risk scenario includes the asset, threat, vulnerability, and impact. These components allow the practitioner to assess the probability and consequence of the risk and to design appropriate responses. Other details like threat actor names, costs, or regulations are secondary and do not replace the fundamental elements needed for risk analysis and treatment.

Exam trap

The trap here is focusing on contextual details like the threat actor's name or regulatory requirements, which are not the core components that enable risk analysis and treatment.

495
MCQmedium

A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?

A.Threat event frequency
B.Loss magnitude
C.Vulnerability severity score
D.Annualized rate of occurrence
AnswerB

FAIR quantifies risk as loss event frequency multiplied by loss magnitude. Loss magnitude estimates the probable financial impact of a breach, covering primary and secondary response, replacement and reputational costs, which is exactly the factor needed for the impact calculation.

Why this answer

In the FAIR (Factor Analysis of Information Risk) model, risk is quantified as the probable frequency and probable magnitude of future loss. To calculate the probable financial impact of a data breach, the practitioner must estimate Loss Magnitude — the monetary value of the loss event, typically broken down into primary loss (response, replacement, fines) and secondary loss (reputation, legal, competitive advantage). Threat event frequency drives the probability side of the equation, not the impact side.

Exam trap

CRISC often tests the distinction between frequency factors (TEF, ARO) and magnitude factors (Loss Magnitude, SLE) in quantitative risk models — candidates who see 'financial impact' and grab a familiar acronym like ARO or a severity score like CVSS fall into the trap.

How to eliminate wrong answers

Option A is wrong because Threat Event Frequency (TEF) is a frequency/likelihood factor in FAIR that estimates how often threat agents act against the asset — it feeds the probability of loss, not the financial magnitude. Option C is wrong because Vulnerability Severity Score (e.g., CVSS) is a technical severity metric, not a FAIR financial loss variable, and FAIR deliberately avoids severity scores in favor of calibrated probability and loss estimates. Option D is wrong because Annualized Rate of Occurrence (ARO) is a classic quantitative risk formula input (SLE × ARO = ALE), not a FAIR loss magnitude factor, and it measures frequency, not impact.

496
Multi-Selectmedium

An organization is designing a vendor risk assessment process for critical vendors. Which THREE of the following should be included in the initial onboarding assessment?

Select 3 answers
A.Security questionnaires
B.Continuous monitoring via shared intelligence platforms
C.Contract compliance review
D.Annual reassessment
E.SOC 2 report review
AnswersA, C, E

Security questionnaires elicit the vendor's control environment, certifications and data-handling practises at onboarding, providing the baseline evidence needed to assess inherent risk before a critical vendor is engaged or granted access to systems and data.

Why this answer

Security questionnaires (A) are a core onboarding artifact because they elicit the vendor's controls, data handling, and security posture directly from the vendor before any data or access is granted. Contract compliance review (C) is essential at onboarding to verify that the agreement contains required security, privacy, breach-notification, and data-return/retention clauses before the relationship begins. SOC 2 report review (E) is appropriate during initial assessment because it provides independent third-party attestation over the vendor's security, availability, confidentiality, or privacy controls under the Trust Services Criteria.

Continuous monitoring via shared intelligence platforms (B) and annual reassessment (D) are ongoing or periodic post-onboarding activities, not initial onboarding assessment steps, so they do not belong in this phase.

Exam trap

The trap here is confusing ongoing monitoring activities (like continuous monitoring or annual reassessments) with the discrete, upfront steps required during the initial vendor onboarding assessment.

497
Multi-Selectmedium

Which TWO methods are commonly used for continuous monitoring of IT controls?

Select 2 answers
A.SIEM rules for automated testing
B.Board risk review
C.Annual control self-assessment
D.Vulnerability scanning
E.Quarterly internal audit
AnswersA, D

SIEM rules continuously correlate log events against defined conditions, automatically testing control effectiveness in near real time. This satisfies the stem's continuous monitoring requirement by detecting anomalies and control failures without waiting for periodic manual review or point-in-time assessment.

Why this answer

SIEM rules for automated testing (A) are correct because SIEM platforms continuously correlate and analyze log and event data against detection rules, providing real-time, automated monitoring of IT controls such as access violations, configuration changes, and policy breaches. Vulnerability scanning (D) is correct because it is run on a recurring, often automated schedule to continuously identify weaknesses in systems and applications, feeding ongoing control-monitoring and remediation processes. Board risk review (B) is not continuous monitoring; it is a periodic governance activity conducted at scheduled intervals.

Annual control self-assessment (C) is a point-in-time, yearly exercise and therefore not continuous. Quarterly internal audit (E) is a periodic assurance activity performed at defined intervals, not real-time or continuous monitoring.

Exam trap

CRISC often tests the distinction between continuous monitoring (automated, real-time) and periodic assessment (manual, scheduled), so candidates may incorrectly select annual or quarterly activities as continuous.

498
MCQeasy

An organization uses control self-assessments (CSAs) as part of its monitoring program. The results from the latest CSA show that the majority of controls are rated as effective, but an internal audit reveals several control failures in those same areas. What is the MOST likely reason for this discrepancy?

A.The CSA scope was narrower than the audit scope
B.The CSA questionnaire contained documentation errors
C.The inherent risk level of the processes decreased after the CSA
D.CSA respondents may have a bias toward reporting favorable results
AnswerD

Control self-assessments rely on control owners evaluating their own controls, which introduces a self-assessment bias toward favourable ratings. Respondents may under-report or rationalise weaknesses, so CSA results rate controls effective while independent internal audit testing identifies the actual control failures in those same areas.

Why this answer

Control self-assessments (CSAs) rely on the subjective judgment of process owners and operators, who may have a natural tendency to report favorable results to avoid scrutiny or additional work. This self-reporting bias is a well-known limitation of CSAs, leading to an overstatement of control effectiveness. The internal audit, being independent and objective, is more likely to uncover actual control failures, explaining the discrepancy.

Exam trap

The trap here is that candidates may assume a technical or procedural cause (like scope or documentation errors) rather than recognizing the inherent human bias in self-assessment, which is a classic CRISC concept in the Risk and Control Monitoring and Reporting domain.

How to eliminate wrong answers

Option A is wrong because a narrower CSA scope would typically result in fewer controls being assessed, not a systematic overstatement of effectiveness; the discrepancy is about accuracy, not coverage breadth. Option B is wrong because documentation errors in the questionnaire could cause confusion but would not consistently produce favorable ratings across multiple respondents; such errors are random, not directional. Option C is wrong because a decrease in inherent risk after the CSA would not cause the CSA to rate controls as effective when they are actually failing; risk level changes affect the likelihood or impact, not the direct assessment of control operation.

499
MCQmedium

A company is updating its risk register. Which of the following is the primary purpose of a risk register?

A.To define risk appetite
B.To record and track identified risks and their treatment
C.To store threat intelligence feeds
D.To document all IT assets
AnswerB

The risk register is the central repository capturing each identified risk, its owner, likelihood, impact and agreed treatment, enabling ongoing tracking and review. This satisfies the stem's requirement to update the register with identified risks and their treatment.

Why this answer

A risk register's primary purpose is to serve as the central repository that records identified risks, their owners, likelihood/impact ratings, and treatment decisions (mitigate, transfer, accept, avoid), enabling ongoing tracking and reporting. It is a living document used by risk managers to monitor status over time. Defining risk appetite is a governance activity that precedes and informs the register, not its purpose.

Exam trap

CRISC often tests the distinction between governance artifacts — candidates confuse the risk register (a tracking tool) with risk appetite (a policy decision) or with asset/threat inventories (data sources).

How to eliminate wrong answers

Option A is wrong because risk appetite is set by senior management/board as a policy statement about how much risk the organization is willing to accept; it is an input to the register, not the register's purpose. Option C is wrong because threat intelligence feeds are external data sources that may inform risk identification, but the register stores risk entries, not raw feeds. Option D is wrong because IT asset inventory is maintained in a CMDB or asset management system; while assets may be referenced in risk entries, documenting all assets is not the register's function.

500
MCQhard

A company's risk management team is evaluating the effectiveness of its control monitoring program. They find that many controls are tested at the same time each year, leading to a resource bottleneck. Which of the following approaches would BEST address this issue?

A.Increase the testing team size
B.Stagger testing cycles across the year
C.Implement continuous monitoring automation
D.Reduce the number of controls tested
AnswerB

Staggering testing cycles distributes control assessments across the calendar year, directly relieving the annual resource bottleneck identified in the stem. Continuous monitoring becomes feasible because testing effort is levelled rather than concentrated, sustaining coverage without requiring additional headcount or reducing the scope of controls assessed.

Why this answer

Staggering testing cycles across the year distributes the workload evenly, preventing the resource bottleneck caused by testing all controls simultaneously. This approach optimizes resource utilization without increasing headcount or reducing coverage, directly addressing the root cause of the scheduling conflict.

Exam trap

The trap here is that candidates often choose 'Implement continuous monitoring automation' (Option C) because it sounds modern and efficient, but the question specifically asks for the BEST approach to address a resource bottleneck caused by timing, not the method of testing.

How to eliminate wrong answers

Option A is wrong because increasing the testing team size only adds more resources to the same peak period, failing to resolve the underlying scheduling inefficiency and potentially increasing costs without improving process design. Option C is wrong because implementing continuous monitoring automation changes the testing methodology rather than addressing the scheduling bottleneck; while automation can reduce manual effort, it does not inherently fix the problem of all controls being tested at the same time each year. Option D is wrong because reducing the number of controls tested weakens the control environment and increases residual risk, which is not a valid risk management approach to solve a resource scheduling issue.

501
MCQhard

During a quantitative risk analysis, the risk practitioner determines that the single loss expectancy (SLE) for a ransomware attack is $500,000 and the annualized rate of occurrence (ARO) is 0.4. The organization has a risk appetite that accepts annual losses up to $150,000. What is the recommended action?

A.Purchase insurance to cover the potential loss
B.Accept the risk because it is within the organization's risk appetite
C.Reassess using qualitative analysis because the ARO is not precise
D.Implement controls to reduce the likelihood or impact until ALE is below $150,000
AnswerD

ALE equals SLE multiplied by ARO, giving $200,000, which exceeds the $150,000 appetite. Reducing likelihood or impact lowers ALE beneath that threshold, satisfying the stem's quantitative constraint rather than accepting, transferring or ignoring the residual risk.

Why this answer

The annualized loss expectancy (ALE) is SLE × ARO = $500,000 × 0.4 = $200,000, which exceeds the organization's risk appetite of $150,000. Since the risk is above appetite, the recommended action is to implement controls that reduce likelihood or impact until the ALE falls below the $150,000 threshold, aligning residual risk with appetite.

Exam trap

CRISC often tests whether candidates calculate ALE correctly and compare it to appetite — the trap is picking 'accept' or 'insurance' without doing the math, or assuming insurance fully addresses risk when it only transfers financial impact.

How to eliminate wrong answers

Option A is wrong because purchasing insurance transfers part of the financial impact but does not by itself reduce the ALE below appetite unless the coverage and deductible are explicitly modeled — and the question asks for the recommended action to bring risk within appetite, which is control implementation. Option B is wrong because $200,000 ALE is greater than the $150,000 appetite, so the risk is not acceptable as-is. Option C is wrong because reassessing qualitatively does not change the quantitative result and is not a risk treatment action; the ARO precision is adequate for the calculation.

502
MCQmedium

After a risk assessment, the risk owner decides to mitigate a high-risk finding by implementing additional access controls. What should the risk manager do NEXT?

A.Update the risk register with the mitigation actions taken.
B.Accept the residual risk on behalf of the organization.
C.Reassess the residual risk level after controls are implemented.
D.Close the risk issue and move to the next priority.
AnswerC

Mitigation changes the risk picture, so the risk manager must re-evaluate the finding's likelihood and impact with the new controls in place, confirming the residual risk falls within tolerance. Only then can the risk be formally accepted, transferred, or escalated.

Why this answer

After mitigation controls are implemented, the risk manager must reassess the residual risk level to determine whether the controls have effectively reduced the risk to an acceptable level. This step ensures that the risk treatment decision is validated and that any remaining exposure is understood before updating the risk register or closing the issue.

Exam trap

The trap here is that candidates often confuse the order of risk management steps, assuming the risk register update (Option A) is the immediate next action, when in fact the residual risk reassessment must occur first to ensure the mitigation was effective.

How to eliminate wrong answers

Option A is wrong because updating the risk register with mitigation actions should occur after the residual risk has been reassessed, not before; the register must reflect the validated post-control risk level. Option B is wrong because accepting residual risk is a decision made by the risk owner, not the risk manager, and it should only occur after the residual risk has been reassessed and found to be within the organization's risk appetite. Option D is wrong because closing the risk issue without reassessing the residual risk ignores the possibility that the implemented controls may be ineffective or introduce new risks, violating the principle of continuous risk monitoring.

503
MCQmedium

A company's risk assessment identifies that a threat actor has high capability and motivation to exploit a vulnerability. Which factor does this relate to?

A.Likelihood assessment
B.Risk appetite
C.Control effectiveness
D.Impact assessment
AnswerA

High capability and motivation directly increase the probability that a threat actor will attempt and succeed in exploiting the vulnerability, which is precisely what likelihood assessment evaluates. Threat capability and motivation are core likelihood inputs, distinct from impact, which measures consequence severity rather than the chance of exploitation occurring.

Why this answer

Threat actor capability and motivation are factors in likelihood assessment.

504
MCQeasy

A multinational corporation is conducting a risk assessment for its new online payment platform. The platform processes transactions in multiple currencies and stores sensitive customer financial data. The risk team has identified that the encryption algorithm used for data at rest is outdated and could be vulnerable to advanced attacks. The company's risk appetite is low for data breaches. The security team recommends upgrading the encryption to a modern standard, but the upgrade will require a 48-hour downtime impacting all global transactions. The business unit is concerned about revenue loss during the downtime. As the risk practitioner, what is the BEST course of action to balance security and business continuity?

A.Accept the risk and delay the upgrade until the next scheduled maintenance window in three months.
B.Plan the upgrade during a low-traffic period and implement compensating controls such as additional monitoring during the downtime.
C.Outsource the payment processing to a third-party vendor that already uses modern encryption.
D.Implement the upgrade immediately to mitigate the vulnerability, accepting the revenue loss.
AnswerB

Scheduling during low traffic minimises revenue impact while compensating controls maintain detection during the 48-hour window, satisfying both the low breach risk appetite and business continuity constraint. This balances the outdated encryption remediation against the downtime the business unit flagged.

Why this answer

The best course of action because it balances the need to mitigate a high-risk encryption vulnerability with business continuity. By scheduling the upgrade during a low-traffic period and implementing compensating controls (e.g., enhanced monitoring and intrusion detection), the organization reduces the likelihood of exploitation during the 48-hour downtime while minimizing revenue loss. This aligns with the low risk appetite for data breaches and demonstrates a risk-based decision that treats the vulnerability without accepting unacceptable exposure.

Exam trap

The trap here is that candidates often choose immediate remediation (Option D) without considering business impact, failing to recognize that risk management requires balancing security with operational continuity through compensating controls and scheduling.

How to eliminate wrong answers

Option A is wrong because delaying the upgrade for three months while the encryption algorithm is known to be vulnerable to advanced attacks directly contradicts the company's low risk appetite for data breaches; it effectively accepts a high residual risk that could lead to a catastrophic data breach. Option C is wrong because outsourcing payment processing introduces new risks, such as loss of direct control over sensitive customer financial data, potential compliance issues (e.g., GDPR, PCI DSS), and the complexity of vendor risk management, which does not inherently resolve the immediate vulnerability in the existing platform. Option D is wrong because implementing the upgrade immediately without considering traffic patterns or compensating controls would cause significant revenue loss from a 48-hour global transaction halt, which is not a balanced approach; it ignores the business impact and fails to apply risk treatment options like mitigation through scheduling and compensating controls.

505
MCQhard

A risk manager is assessing the risk of a distributed denial-of-service (DDoS) attack on a critical online service. The service has a service-level agreement (SLA) that requires 99.9% uptime. The manager has identified that the likelihood of a DDoS attack is high, but the impact is considered low because the service can fail over to a backup data center. Which of the following should the risk manager do NEXT?

A.Validate the effectiveness of the failover mechanism under a DDoS attack.
B.Transfer the risk by purchasing cyber insurance for DDoS attacks.
C.Mitigate the risk by implementing a DDoS protection service.
D.Accept the risk because the impact is low and the SLA can be met.
AnswerA

The risk manager assumed low impact based on failover, but that assumption must be validated. Failover may not work under a DDoS attack if the backup data center is also targeted or if failover triggers are not met. Validating the control ensures the impact assessment is accurate and the risk is properly understood.

Why this answer

The risk manager's impact assessment relies on the failover mechanism working during a DDoS attack. Before proceeding, the manager must validate that the failover can handle a DDoS scenario. If it cannot, the impact may be higher than assumed.

Validating the control ensures the risk assessment is accurate and informs subsequent risk response decisions.

Exam trap

The trap here is accepting the impact assessment at face value without verifying the underlying control, which could lead to underestimating risk.

506
MCQeasy

Refer to the exhibit. Based on the KRI data for the current week, what action should the risk manager take FIRST?

A.Adjust the KRI threshold to 15 per day to reduce false positives.
B.Continue monitoring as all days are within Green or Amber.
C.Investigate Wednesday and Thursday spikes as they are above the Green threshold.
D.Escalate to the risk committee because the threshold was breached.
AnswerC

Wednesday and Thursday breaches exceed the Green threshold, so the KRI demands immediate investigation before escalation or reporting. Threshold breaches signal control drift, and the risk manager must first establish cause and impact. Investigating these spikes satisfies the stem's requirement to act on current-week KRI data exceeding defined tolerance.

Why this answer

In KRI monitoring, values above the Green threshold but below the Red threshold (Amber zone) indicate a potential emerging risk that warrants investigation before escalation. Wednesday and Thursday spikes exceed the Green threshold, so the risk manager should first investigate these anomalies to determine if they are false positives or early signs of a real issue. This aligns with the CRISC principle of proactive risk monitoring and timely response.

Exam trap

The trap is treating any threshold breach as requiring immediate escalation, when in fact Amber breaches typically call for investigation first, and Red breaches trigger escalation.

How to eliminate wrong answers

Option A is wrong because adjusting the KRI threshold to reduce false positives without investigation is premature and could mask genuine risk signals; thresholds should be reviewed based on analysis, not convenience. Option B is wrong because continuing to monitor without action ignores the Amber breaches, which are designed to trigger investigation, not passive observation. Option D is wrong because escalation to the risk committee is typically reserved for Red threshold breaches or after investigation confirms a significant risk; escalating immediately without investigation may be premature and inefficient.

507
MCQmedium

During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?

A.Require encryption (e.g., TLS) for the communication
B.Transfer the risk to a third-party vendor
C.Accept the risk because the legacy system cannot be changed
D.Decommission the legacy system immediately
AnswerA

TLS encrypts data in transit, directly removing the plain-text exposure over the public network that the ARB flagged. Encryption is a preventive control that reduces likelihood, which suits an architectural review where the risk is interception of credentials or sensitive payloads.

Why this answer

Requiring encryption (e.g., TLS) directly mitigates the confidentiality and integrity risk of plaintext transmission over a public network by protecting data in transit. This is the most appropriate risk treatment because it addresses the root cause—unprotected communication—without disrupting the legacy system's functionality. TLS provides encryption, authentication, and integrity checking, which are standard controls for this scenario.

The ARB should mandate this as a condition of approval.

Exam trap

CRISC often tests the misconception that risk transfer (e.g., to a vendor) or acceptance is acceptable when a simple technical control like encryption can mitigate the risk; candidates may overlook that encryption is a direct and feasible treatment.

How to eliminate wrong answers

Option B is wrong because transferring risk to a third-party vendor does not eliminate the vulnerability; the vendor may not accept liability for plaintext transmission, and the organization still retains reputational and regulatory risk. Option C is wrong because accepting the risk is inappropriate when a feasible and cost-effective mitigation (encryption) exists; acceptance should only be considered after all other treatments are evaluated and if the risk is within tolerance. Option D is wrong because decommissioning the legacy system immediately is a drastic, potentially disruptive action that may not be feasible due to business dependencies, and it does not address the immediate need for secure communication.

508
Drag & Dropmedium

Order the steps for incident response handling.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Incident response follows preparation, detection, containment/eradication/recovery, lessons learned, and reporting.

509
MCQhard

A multinational bank is assessing risk for a new mobile banking feature that stores limited customer data on devices. The risk team must decide whether to use a qualitative or quantitative approach. Which of the following is the MOST important factor in making this decision?

A.The number of risks identified in the risk register and the size of the assessment team.
B.The preference of the business unit sponsor and the timeline for the product launch.
C.The regulatory requirement to perform an annual risk assessment and the audit committee's reporting schedule.
D.The availability of reliable historical loss data and the need to express risk in financial terms.
AnswerD

The choice between qualitative and quantitative risk assessment hinges on data availability and the decision-making need. If reliable loss data exists and stakeholders require financial expression for cost-benefit analysis, quantitative methods are appropriate. If data is scarce or decisions are strategic, qualitative methods suffice. This factor directly determines which approach will produce meaningful, defensible results.

Why this answer

Selecting a qualitative or quantitative risk assessment method depends primarily on whether reliable data exists to support quantification and whether decisions require financial expression. When loss data is credible and cost-benefit analysis is needed, quantitative methods add value. When data is sparse or decisions are strategic, qualitative methods are more practical and defensible.

Exam trap

The trap here is letting organizational preferences or timelines dictate methodology instead of the availability of reliable data and the need for financial expression.

510
MCQhard

A financial services company is conducting a risk assessment for a new mobile banking application. The risk team identifies that the application will store sensitive customer data on the device. The team must determine the appropriate risk response. The CISO suggests implementing encryption and tokenization to protect the data. The business sponsor argues that these controls will delay the launch and increase costs. The risk owner must decide how to proceed. Which of the following is the MOST appropriate action for the risk owner to take?

A.Accept the risk because the business sponsor has authority over the project timeline and budget.
B.Document the risk and propose a risk treatment plan that includes the suggested controls, then escalate to senior management for a decision if the business sponsor does not agree.
C.Implement the controls without consulting the business sponsor to avoid further delays.
D.Transfer the risk by purchasing cyber insurance to cover potential data breaches.
AnswerB

The risk owner should ensure that the risk is clearly documented, propose appropriate treatment (encryption and tokenization), and if there is disagreement, escalate to senior management for a risk-based decision. This follows CRISC's principle of aligning risk management with business objectives and ensuring informed decision-making at the appropriate level. It also maintains the risk owner's accountability.

Why this answer

The risk owner must balance business needs with risk mitigation. Documenting the risk, proposing controls, and escalating disagreements to senior management ensures a risk-informed decision. This approach respects the business sponsor's concerns while upholding the risk owner's duty to manage risk within appetite.

It also aligns with CRISC's emphasis on communication and escalation.

Exam trap

The trap here is assuming that the business sponsor's authority automatically justifies accepting the risk without proper escalation or treatment planning.

511
MCQmedium

After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?

A.Re-evaluate risk treatment options with the risk owner
B.Escalate directly to the board
C.Update the risk register to reflect the residual risk
D.Accept the residual risk
AnswerA

Residual risk exceeding appetite means the implemented treatment proved insufficient, so the practitioner must revisit treatment with the risk owner to identify additional or alternative controls. Re-evaluating options directly addresses the gap between current residual exposure and the defined appetite before escalation or acceptance is considered.

Why this answer

When residual risk remains above the risk appetite after treatment, the risk practitioner must first re-evaluate the existing risk treatment options with the risk owner. This collaborative review identifies whether additional controls (e.g., stricter input validation, rate limiting, or Web Application Firewall tuning) can further reduce the risk to an acceptable level before considering escalation or acceptance.

Exam trap

The trap here is that candidates often confuse the urgency of residual risk with the need to immediately escalate or accept it, when the correct first step is to revisit treatment options with the risk owner to see if further controls can close the gap.

How to eliminate wrong answers

Option B is wrong because escalating directly to the board bypasses the proper risk management process; the board should only be informed after all feasible treatment options have been exhausted and documented. Option C is wrong because updating the risk register to reflect residual risk is a documentation step that should occur after determining the final risk response, not as the first action. Option D is wrong because accepting residual risk above the risk appetite without first exploring additional mitigation measures violates the principle of risk reduction and could lead to unacceptable exposure.

512
MCQeasy

Which of the following is a detective control for an information system?

A.Data backup
B.Encryption
C.Firewall
D.Intrusion detection system
AnswerD

An intrusion detection system monitors network or host activity and raises alerts on suspicious patterns, identifying incidents after or during occurrence rather than blocking them. That monitoring-and-alerting function is detective by definition, distinguishing it from preventive controls such as firewalls or encryption.

Why this answer

An intrusion detection system (IDS) is a detective control because it monitors network traffic or system activity for malicious actions or policy violations and generates alerts when such events occur. Unlike preventive controls, an IDS does not block or stop the attack; it detects and reports it after the fact, enabling incident response.

Exam trap

The trap here is confusing detective controls (which identify incidents after they occur) with preventive controls (which stop incidents before they happen), leading candidates to mistakenly classify firewalls or encryption as detective.

How to eliminate wrong answers

Option A is wrong because data backup is a corrective/recovery control, not detective; it restores data after a loss but does not detect ongoing threats. Option B is wrong because encryption is a preventive control that protects data confidentiality by encoding it, but it does not detect unauthorized access or attacks. Option C is wrong because a firewall is a preventive control that enforces access policies by blocking or allowing traffic based on rules, but it does not actively detect or alert on suspicious activity.

513
MCQmedium

An organization is implementing the NIST Cybersecurity Framework to manage cyber risk. The risk manager is mapping the 'Detect' function to existing risk management processes. Which of the following activities is MOST directly aligned with the 'Detect' function?

A.Implementing continuous security monitoring of network traffic
B.Developing an incident response plan
C.Conducting a business impact analysis
D.Establishing a patch management process
AnswerA

Continuous security monitoring of network traffic directly fulfils the Detect function's requirement to identify cybersecurity events as they occur. Unlike Identify or Protect activities, detection demands ongoing visibility, and traffic monitoring provides the timely anomaly discovery the framework expects, satisfying the stem's mapping of Detect to risk management processes.

Why this answer

The NIST Cybersecurity Framework's Detect function (DE) covers activities that identify the occurrence of a cybersecurity event, including continuous security monitoring (DE.CM), anomaly and event detection (DE.AE), and detection processes (DE.DP). Implementing continuous security monitoring of network traffic maps directly to DE.CM-1 (network monitoring) and is the clearest example of a Detect activity. It is about discovering events, not responding to or preventing them.

Exam trap

CRISC often tests function-boundary confusion in the NIST CSF — candidates see 'incident response plan' or 'patch management' and pick them because they sound security-related, missing that Respond and Protect functions are distinct from Detect.

How to eliminate wrong answers

Option B is wrong because developing an incident response plan belongs to the Respond function (RS.RP — response planning), which executes after a detection occurs. Option C is wrong because conducting a business impact analysis is part of risk assessment and business continuity planning, aligned with the Identify function (ID.RA, ID.BE) and not the Detect function. Option D is wrong because establishing a patch management process is a Protect function activity (PR.IP — protective technology and maintenance), aimed at preventing exploitation rather than detecting it.

514
MCQhard

An organization calculated the inherent risk for a critical system as 'High' using a 5x5 heat map. After implementing controls, the residual risk is assessed as 'Medium'. What does this indicate about the control effectiveness?

A.Controls are fully effective and risk is now acceptable
B.Controls are ineffective and need replacement
C.Controls are partially effective, reducing risk but not to the target level
D.Residual risk should equal inherent risk if controls are effective
AnswerC

The drop from High inherent risk to Medium residual risk shows controls are operating but only partially, since risk remains above the organisation's defined tolerance. Residual risk reflects what persists after control implementation, so a Medium rating confirms mitigation occurred without reaching the target level, meaning further treatment or additional controls are required.

Why this answer

The movement from 'High' inherent risk to 'Medium' residual risk indicates that the implemented controls have reduced the risk level by one step on the 5x5 heat map, but have not eliminated it entirely. Since the residual risk is still 'Medium' rather than 'Low' or 'Very Low', the controls are only partially effective—they mitigate some of the risk but do not bring it down to the organization's target risk appetite or tolerance level.

Exam trap

The trap here is that candidates assume any reduction in risk means controls are fully effective and risk is acceptable, but CRISC requires you to compare residual risk against the organization's specific risk appetite and target level, not just the inherent risk baseline.

How to eliminate wrong answers

Option A is wrong because 'fully effective' controls would reduce the risk to the organization's target level (often 'Low' or 'Very Low'), not leave it at 'Medium'; residual risk being 'Medium' means the risk is not yet acceptable unless the target is explicitly 'Medium'. Option B is wrong because 'ineffective' controls would result in residual risk remaining at 'High' or possibly increasing, not dropping to 'Medium'; a reduction in risk level proves some effectiveness. Option D is wrong because if controls are effective, residual risk should be lower than inherent risk, not equal; equal residual risk would mean controls have zero effect, which contradicts the observed reduction from 'High' to 'Medium'.

515
MCQmedium

A risk manager is evaluating the risk associated with a new third-party vendor that will have access to customer data. The vendor has been in business for 10 years and holds ISO 27001 certification. Which factor should be given the MOST weight when determining the vendor's risk level?

A.The vendor's years in operation.
B.The vendor's ISO 27001 certification.
C.The sensitivity and volume of data the vendor will access.
D.The contractual terms for data protection.
AnswerC

Risk severity is driven primarily by the data itself: highly sensitive, high-volume customer data creates greater potential impact if breached. ISO 27001 certification and vendor longevity are assurance factors, but they cannot reduce the inherent risk posed by the data the vendor accesses.

Why this answer

The sensitivity and volume of data directly determine the potential impact of a breach, which is a core component of inherent risk. Even with strong controls like ISO 27001, the risk level is primarily driven by the value and quantity of the asset at risk (customer data). In IT risk assessment, the asset's criticality and exposure outweigh historical or certification-based indicators when calculating residual risk.

Exam trap

The trap here is that candidates overvalue certifications and tenure as proxies for security, while the CRISC exam emphasizes that risk is fundamentally tied to the asset's value and exposure, not just the vendor's credentials.

How to eliminate wrong answers

Option A is wrong because years in operation are a proxy for stability, not a direct measure of security posture or the specific risk from data access; a mature vendor can still have weak controls for a particular data type. Option B is wrong because ISO 27001 certification indicates a management system is in place, but it does not guarantee that controls are effectively implemented for the specific data sensitivity or volume, nor does it eliminate the need to assess the asset's inherent risk. Option D is wrong because contractual terms are a risk mitigation mechanism, not a primary risk factor; they define remedies and obligations but do not change the inherent risk posed by the data access itself.

516
Multi-Selectmedium

An organization is implementing a third-party risk management program. Which TWO are essential components of the initial vendor risk assessment process?

Select 2 answers
A.Security questionnaires
B.Contract compliance review
C.Review of SOC 2 Type II report
D.Quarterly vulnerability scans of vendor networks
E.Annual reassessment
AnswersA, C

Security questionnaires elicit each vendor's controls, data handling and compliance posture before onboarding. This standardised evidence supports consistent, comparable risk tiering across the vendor population, which the initial assessment process requires to prioritise due diligence.

Why this answer

Security questionnaires (A) are essential because they elicit the vendor's self-reported controls, data handling practices, and security posture directly from the vendor, forming the foundational data-gathering step of an initial risk assessment. Reviewing a SOC 2 Type II report (C) is also essential because it provides independent auditor attestation that the vendor's controls operated effectively over a period (typically 6–12 months), validating the claims made in questionnaires. Contract compliance review (B) is a legal/procurement activity that occurs around contracting rather than being a core initial risk-assessment component.

Quarterly vulnerability scans of vendor networks (D) are not feasible or appropriate at the initial assessment stage and typically cannot be performed against third-party infrastructure without authorization. Annual reassessment (E) is a recurring post-onboarding activity, not part of the initial vendor risk assessment.

517
MCQeasy

Which risk assessment method uses a matrix to plot likelihood and impact to determine risk level?

A.Delphi technique
B.Annual loss expectancy
C.Qualitative
D.Quantitative
AnswerC

Qualitative assessment plots likelihood against impact on a matrix, assigning descriptive ratings such as high, medium or low to derive an overall risk level. This matrix-based plotting of the two dimensions is precisely what distinguishes it from quantitative methods.

Why this answer

The qualitative risk assessment method uses a matrix to plot likelihood and impact, typically with ordinal scales (e.g., high, medium, low) to derive a risk level. This approach is subjective and relies on expert judgment rather than numerical values, making it distinct from quantitative methods.

Exam trap

The trap here is that candidates confuse the qualitative risk matrix with the Delphi technique, which is a consensus-building method, or mistakenly think Annual Loss Expectancy (ALE) is plotted on a matrix, when in fact ALE is a quantitative output.

How to eliminate wrong answers

Option A is wrong because the Delphi technique is a structured communication method for achieving consensus among experts, not a risk assessment method that uses a likelihood-impact matrix. Option B is wrong because Annual Loss Expectancy (ALE) is a quantitative metric calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO), not a matrix-based qualitative approach. Option D is wrong because quantitative risk assessment uses numerical values (e.g., monetary amounts, percentages) and formulas like ALE, not a subjective matrix of likelihood and impact.

518
MCQmedium

An organization uses a third-party vendor for payment processing. The vendor's latest SOC 2 report shows a significant control exception in logical access. What is the BEST way to monitor the effectiveness of the compensating controls the vendor has implemented?

A.Accept the risk and apply a monetary penalty to the vendor.
B.Immediately terminate the vendor contract and switch to a new payment processor.
C.Request the vendor to include a clause in the contract that holds them liable for any breaches.
D.Obtain the vendor's remediation plan and schedule a follow-up assessment to verify the compensating controls.
AnswerD

Obtaining the remediation plan and scheduling a follow-up assessment directly verifies that the vendor's compensating controls operate effectively after the logical access exception. This tests the controls rather than relying on the vendor's assertions, satisfying ongoing third-party risk monitoring.

Why this answer

The most effective way to monitor compensating controls is to obtain the vendor's remediation plan and schedule a follow-up assessment. This allows the organization to verify that the compensating controls are operating effectively, which is a key activity in the Risk and Control Monitoring and Reporting domain. Simply accepting risk or adding contractual clauses does not provide ongoing assurance that the controls are working as intended.

Exam trap

The trap here is that candidates may confuse contractual remedies (like liability clauses or penalties) with actual control monitoring, but CRISC emphasizes that monitoring requires direct verification of control effectiveness, not just legal or financial agreements.

How to eliminate wrong answers

Option A is wrong because accepting the risk and applying a monetary penalty does not monitor the effectiveness of compensating controls; it merely transfers financial liability without verifying control operation. Option B is wrong because immediately terminating the contract is a drastic, reactive measure that does not address the need to monitor compensating controls and may disrupt business operations unnecessarily. Option C is wrong because requesting a contractual clause for breach liability does not provide a mechanism for ongoing monitoring or verification of control effectiveness; it only addresses legal recourse after a failure.

519
MCQmedium

An organization is implementing a control to prevent unauthorized access to its critical database. The control must be designed to block access attempts in real time. Which type of control should be selected?

A.Corrective control
B.Detective control
C.Preventive control
D.Compensating control
AnswerC

Preventive controls block unauthorised access attempts before they succeed, operating in real time at the point of entry. Detective controls only identify breaches after the fact, and corrective controls respond post-incident, so prevention uniquely satisfies the requirement to stop database access attempts as they occur.

Why this answer

A preventive control is designed to block unauthorized access attempts in real time before they reach the critical database. Technologies such as a database firewall or network access control list (ACL) evaluate each request against a policy and drop the packet or terminate the session immediately, preventing the access from occurring. This aligns with the requirement for real-time blocking, which is the defining characteristic of a preventive control.

Exam trap

The trap here is that candidates often confuse detective controls (like monitoring or logging) with preventive controls, mistakenly thinking that detecting an attempt in real time is the same as blocking it, but detection does not stop the action from occurring.

How to eliminate wrong answers

Option A is wrong because a corrective control acts after an incident has occurred (e.g., restoring a database from backup after a breach), not in real time to block access. Option B is wrong because a detective control identifies and logs unauthorized access attempts (e.g., via audit logs or intrusion detection systems) but does not block them in real time. Option D is wrong because a compensating control is an alternative mechanism used when the primary control is not feasible (e.g., using additional monitoring when encryption cannot be applied), but it is not the first choice for real-time blocking and does not inherently block access in real time.

520
MCQhard

A risk assessment for a cloud migration project identifies that the cloud provider does not support encryption keys managed by the customer. Which of the following risk scenarios is MOST directly related to this finding?

A.Service availability disruption
B.Data loss due to misconfiguration
C.Unauthorized access by cloud provider employees
D.Non-compliance with data residency requirements
AnswerC

Without customer-managed keys, the provider holds and can access the encryption keys, so provider personnel could decrypt stored data. This scenario directly addresses the loss of key custody identified in the finding, making insider access at the provider the most direct consequence.

Why this answer

When the cloud provider does not support customer-managed encryption keys, the provider retains control over the key material. This means that provider employees with administrative access to the key management system could potentially decrypt and access customer data, leading to unauthorized access. This directly creates a risk scenario of unauthorized access by cloud provider employees, as the customer loses the ability to enforce separation of duties and key sovereignty.

Exam trap

The trap here is that candidates often confuse encryption key management with data residency or misconfiguration risks, but the core issue is that provider-managed keys eliminate the customer's ability to prevent the provider from decrypting their data, directly enabling unauthorized access by provider employees.

How to eliminate wrong answers

Option A is wrong because service availability disruption is typically caused by outages, DDoS attacks, or resource exhaustion, not by the lack of customer-managed encryption keys. Option B is wrong because data loss due to misconfiguration (e.g., public S3 buckets, incorrect retention policies) is a separate risk that can occur regardless of who manages the encryption keys. Option D is wrong because non-compliance with data residency requirements is about where data is stored geographically, not about who controls the encryption keys; even with provider-managed keys, data can be stored in compliant regions.

521
Multi-Selectmedium

Which TWO of the following are appropriate criteria for selecting key risk indicators (KRIs)?

Select 2 answers
A.Indicators that are quantifiable and reliable
B.Indicators that only cover financial risks
C.Indicators that provide early warning of potential risk events
D.Indicators that measure historical losses
E.Indicators that are easy to collect regardless of relevance
AnswersA, C

Essential for effective monitoring.

Why this answer

Key risk indicators (KRIs) must be quantifiable and reliable to provide objective, measurable data that can be consistently tracked over time. Quantifiable indicators allow for trend analysis and threshold setting, while reliability ensures the data source is accurate and repeatable, which is essential for effective risk monitoring in IT environments such as network security or system availability.

Exam trap

ISACA often tests the distinction between leading and lagging indicators, and the trap here is that candidates confuse historical loss metrics (lagging) with KRIs (leading), or assume that any easy-to-collect metric is automatically a valid KRI.

522
MCQeasy

A technology company has implemented a risk and control monitoring program for its software development lifecycle. The program includes key risk indicators (KRIs) such as number of critical bugs found in production, code review coverage, and time to patch vulnerabilities. After six months, the risk committee noticed that the KRI for code review coverage is consistently green (within threshold), but the number of critical bugs in production remains high. The risk manager suspects a disconnect between the KRI and actual risk. What should the risk manager do FIRST?

A.Implement additional testing controls to catch bugs before production.
B.Reduce the code review coverage target to lower the risk appetite.
C.Review the KRI definition and data source to ensure it reflects effective code review.
D.Adjust the code review coverage threshold to a higher percentage.
AnswerC

A green KRI coexisting with high production defects indicates the metric may not measure what it claims. Reviewing the KRI definition and its data source first establishes whether code review coverage genuinely reflects effective review before any threshold or control changes are made.

Why this answer

The risk manager must first validate that the KRI for code review coverage is actually measuring the effectiveness of code reviews, not just their completion. If the KRI is green but critical bugs persist, the data source or definition may be flawed—for example, measuring the percentage of code reviewed rather than the quality of reviews. Without this validation, any subsequent action (like adding controls or adjusting thresholds) would be based on unreliable information.

Exam trap

The trap here is that candidates often jump to a corrective action (like adding controls or adjusting thresholds) without first questioning the validity of the KRI itself, which is the foundational step in risk and control monitoring.

How to eliminate wrong answers

Option A is wrong because implementing additional testing controls addresses symptoms (bugs in production) without diagnosing why the existing KRI is misleading; it assumes the KRI is accurate, which is the core issue. Option B is wrong because reducing the code review coverage target lowers the risk appetite without evidence that the current target is inappropriate; it could increase risk exposure if the KRI is already flawed. Option D is wrong because adjusting the threshold to a higher percentage assumes the KRI is correctly defined and merely needs recalibration, but the disconnect suggests the KRI itself may not reflect effective review quality.

523
Drag & Dropmedium

Arrange the steps for performing a vulnerability assessment.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Vulnerability assessment starts with scope, scanning, analysis, prioritization, and reporting.

524
MCQmedium

A global retailer is migrating its point-of-sale (POS) transaction processing to a public cloud provider. The risk practitioner must ensure that the organization's payment card data remains compliant with PCI DSS. Which of the following is the MOST appropriate control to implement FIRST?

A.Implement a web application firewall (WAF) in front of the cloud-based POS application.
B.Require the cloud provider to sign a PCI DSS attestation of compliance (AOC).
C.Encrypt all cardholder data at rest and in transit using strong cryptography.
D.Conduct a data discovery and classification exercise to identify all cardholder data locations.
AnswerD

Before any controls can be effectively applied, the organization must know where cardholder data is stored, processed, and transmitted in the cloud environment. Data discovery and classification define the scope of PCI DSS compliance and ensure that subsequent controls are applied to the correct assets, preventing gaps or unnecessary effort.

Why this answer

The first step in any cloud migration involving cardholder data is to discover and classify that data to define the PCI DSS scope. Without knowing where the data resides, the organization cannot accurately apply encryption, firewalls, or contractual controls. Data discovery ensures that all subsequent risk treatments are targeted and complete, forming the foundation for compliance.

Exam trap

The trap here is assuming that encryption or a WAF is always the first control, when in fact you cannot protect data you have not yet located and classified.

525
Multi-Selecteasy

Which TWO of the following are key functions of an Architecture Review Board (ARB) in managing risk?

Select 2 answers
A.Managing user access controls
B.Performing daily vulnerability scans
C.Reviewing solution architectures for security risks before implementation
D.Responding to security incidents
E.Ensuring architecture alignment with risk appetite
AnswersC, E

This is a primary ARB responsibility.

Why this answer

A primary function of an Architecture Review Board (ARB) is to evaluate solution architectures for security risks prior to implementation. This proactive review ensures that security controls are embedded in the design phase, reducing the likelihood of vulnerabilities being introduced into production systems.

Exam trap

The trap here is confusing operational security tasks (like access control, scanning, or incident response) with the strategic, governance-focused role of the ARB, which is to ensure architectural decisions align with risk appetite and security requirements before deployment.

Page 6

Page 7 of 15

Page 8