Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 526–600

1062 questions total · 15pages · All types, answers revealed

Page 7

Page 8 of 15

Page 9
526
MCQmedium

When identifying vulnerabilities, which of the following is the BEST source for configuration-related vulnerabilities in operating systems?

A.NVD
B.CVE database
C.OWASP Top 10
D.CIS Benchmarks
AnswerD

CIS Benchmarks provide prescriptive, platform-specific secure configuration baselines for operating systems, mapping directly to configuration weaknesses. They satisfy the stem's configuration focus by detailing exact settings, registry values and service states to compare against, unlike vulnerability scanners that detect missing patches or generic threat feeds lacking hardening guidance.

Why this answer

CIS Benchmarks are industry-recognized configuration guidelines that help identify and remediate configuration-related vulnerabilities in operating systems. Unlike NVD or CVE which catalog known vulnerabilities, CIS Benchmarks provide actionable hardening steps for system configurations.

527
Multi-Selectmedium

A risk practitioner at a software company is reviewing external sources to identify emerging IT risks that could affect the organization's cloud-hosted products. The practitioner wants to use sources that provide structured, timely information about newly disclosed software weaknesses. Which TWO of the following sources BEST meet this need? (Choose two.)

Select 2 answers
A.Prior-year internal audit findings
B.National Vulnerability Database (NVD) records
C.Common Vulnerabilities and Exposures (CVE) listings
D.Internal employee satisfaction survey results
E.Facilities maintenance work order logs
AnswersB, C

The NVD enriches CVE identifiers with severity scoring, affected product mappings, and references, making it a structured and timely source for prioritizing newly disclosed weaknesses. It allows the practitioner to filter and rank vulnerabilities relevant to the cloud products in scope. Because it is maintained as a public reference with consistent data fields, it directly supports emerging-risk identification and comparison across many software components.

Why this answer

Emerging IT risk identification benefits from external, structured, and current sources that describe newly disclosed weaknesses. CVE listings supply standardized identifiers for disclosed vulnerabilities, and NVD records add severity scoring and product mappings that let the practitioner prioritize. Together they provide the timeliness and structure needed.

Internal surveys, past audit findings, and facilities logs are either retrospective, unrelated to software weaknesses, or both, so they cannot fulfill the same purpose.

Exam trap

The trap here is treating any internal record as a valid risk identification source, when the requirement specifically calls for structured and timely external information about newly disclosed software weaknesses.

528
MCQhard

A multinational corporation is deploying a new enterprise resource planning (ERP) system across 30 countries. The risk manager identifies that data residency laws in several countries require customer data to remain within national borders. The project team proposes using a single global cloud region for simplicity. Which risk response strategy is MOST appropriate for the risk manager to recommend?

A.Accept the risk because the cloud provider's global presence ensures compliance.
B.Mitigate the risk by implementing data localization controls, such as regional data centers or data residency zones.
C.Avoid the risk by canceling the ERP deployment in countries with strict data residency laws.
D.Transfer the risk by outsourcing data management to a third-party provider.
AnswerB

Mitigation through data localization controls directly addresses the legal requirement by ensuring data remains within required jurisdictions. This allows the ERP deployment to proceed while complying with laws. It is the most appropriate response because it reduces risk to an acceptable level without abandoning the business initiative.

Why this answer

The correct answer is to mitigate the risk by implementing data localization controls. This approach directly addresses the legal requirement while allowing the ERP deployment to continue. Risk mitigation is appropriate when the risk can be reduced to an acceptable level through controls, and it balances business needs with compliance obligations.

Exam trap

The trap here is assuming that using a global cloud region automatically satisfies data residency laws, or that transferring the risk to a third party absolves the organization of legal responsibility.

529
MCQhard

The policy requiring TLS 1.2 or higher for all data transmissions is intended to enforce what security control?

A.Data classification
B.Access control
C.Encryption at rest
D.Encryption in transit
AnswerD

TLS 1.2 or higher encrypts data while moving between systems, directly satisfying the policy's requirement for protecting transmissions. This is encryption in transit, distinct from encryption at rest, which protects stored data. The policy's scope — all data transmissions — maps precisely to data in motion, making this the control being enforced.

Why this answer

The policy explicitly requires TLS 1.2 or higher for all data transmissions, which enforces encryption in transit. This ensures that data is protected from interception or tampering while moving across networks, as opposed to being stored (at rest) or managed via classification or access rules.

Exam trap

The trap here is that candidates confuse 'encryption in transit' with 'encryption at rest' because both involve encryption, but the policy's focus on transmission protocols (TLS) clearly distinguishes it as a network-layer control.

How to eliminate wrong answers

Option A is wrong because data classification involves labeling data based on sensitivity, not enforcing encryption during transmission. Option B is wrong because access control governs who can view or modify data, not how data is encrypted while moving. Option C is wrong because encryption at rest protects stored data on disk or in databases, not data in transit over a network.

530
MCQeasy

Which of the following is the PRIMARY purpose of a risk register?

A.To track the status of risk remediation actions
B.To document identified risks, their analysis, and planned responses
C.To provide real-time alerts for risk events
D.To satisfy regulatory compliance requirements
AnswerB

A risk register serves as the central record capturing each identified risk alongside its assessed likelihood and impact, plus the agreed response owner and action. This directly fulfils the register's primary purpose: maintaining a structured, auditable repository that supports ongoing risk monitoring and informed decision-making throughout the risk management lifecycle.

Why this answer

The risk register is the central repository for documenting identified risks, their analysis (including likelihood and impact), and the planned responses. While it can be used to track remediation actions, its primary purpose is to serve as the authoritative record of risk information, enabling informed decision-making and ongoing risk management.

Exam trap

The trap here is that candidates confuse the risk register's primary purpose (documentation and analysis) with its secondary uses (tracking remediation or compliance), leading them to select a plausible but incorrect option like A or D.

How to eliminate wrong answers

Option A is wrong because tracking the status of risk remediation actions is a secondary function of the risk register, not its primary purpose; that tracking is often managed via action plans or issue logs. Option C is wrong because a risk register is a static or periodically updated document, not a real-time alerting system; real-time alerts are provided by monitoring tools, SIEMs, or automated risk dashboards. Option D is wrong because while a risk register may help satisfy regulatory compliance requirements, that is a beneficial outcome, not the primary purpose; the core purpose is to document and manage risks, not to meet compliance obligations.

531
MCQeasy

A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?

A.IT strategy
B.Risk management policy
C.Business continuity plan
D.Risk register
AnswerB

A risk management policy is the governing document that mandates the organization's approach to risk assessment, treatment, and reporting, satisfying the stem's requirement for a primary source. It establishes authority, scope, and responsibilities, unlike frameworks or procedures, which support implementation rather than define the overarching programme.

Why this answer

The risk management policy is the authoritative document that establishes the organization's overall approach to risk management, including the principles, roles, responsibilities, and processes for risk assessment, treatment, and reporting. It sets the governance framework and mandates how risk activities must be conducted across the IT environment, ensuring consistency and alignment with business objectives.

Exam trap

The trap here is that candidates often confuse the risk register (a tactical tool) with the risk management policy (a strategic governance document), mistakenly thinking the register defines the process rather than just recording the outputs.

How to eliminate wrong answers

Option A is wrong because the IT strategy defines the long-term technology direction and investment priorities, not the specific procedures for risk assessment, treatment, and reporting. Option C is wrong because the business continuity plan focuses on maintaining or restoring operations after a disruption, not on the ongoing risk management process of identifying, analyzing, and treating risks. Option D is wrong because the risk register is a living document that records identified risks, their assessments, and treatment plans, but it does not define the overarching methodology or governance for risk management.

532
MCQhard

Based on the exhibit, what control monitoring deficiency is evident in the DLP policy?

A.The policy does not monitor or block credit card data exfiltration via cloud storage applications (e.g., Dropbox, OneDrive).
B.Alerts are not sent to the appropriate team.
C.Log retention is insufficient for forensic analysis.
D.The rules are too broadly defined and may cause false positives.
AnswerA

The DLP policy inspects email and endpoint channels but omits cloud storage applications, so credit card data can leave via Dropbox or OneDrive undetected. That coverage gap is the monitoring deficiency, since exfiltration through those sanctioned apps is neither blocked nor logged.

Why this answer

The DLP policy shown in the exhibit only includes rules for monitoring and blocking credit card data exfiltration via webmail (Gmail, Yahoo Mail) and FTP. It completely omits any rule for cloud storage applications such as Dropbox or OneDrive, which are common vectors for data exfiltration. This is a control monitoring deficiency because the policy fails to cover a significant risk surface, leaving the organization blind to unauthorized transfers of sensitive data through these channels.

Exam trap

The trap here is that candidates may assume the DLP policy is comprehensive because it covers webmail and FTP, but they fail to notice the omission of cloud storage applications, which is a classic control monitoring deficiency tested in CRISC.

How to eliminate wrong answers

Option B is wrong because the exhibit does not provide any information about alert routing or notification configuration; the deficiency is about missing monitoring coverage, not alert delivery. Option C is wrong because log retention policies are not addressed in the exhibit; the issue is the absence of a rule for cloud storage, not the duration logs are kept. Option D is wrong because the rules shown are specific to webmail and FTP, not broadly defined; the problem is under-coverage (missing cloud storage), not over-broad rules that would cause false positives.

533
MCQeasy

An organization is updating its asset inventory to improve IT risk identification. Which of the following asset attributes is MOST critical for assessing cybersecurity risk?

A.Criticality rating based on business impact
B.IP address and location
C.Asset owner contact information
D.Software vendor name
AnswerA

Criticality rating based on business impact links each asset to the processes it supports, letting risk assessors prioritise threats by potential operational and financial consequence. Other attributes such as location or owner inform exposure but do not directly quantify risk severity.

Why this answer

For assessing cybersecurity risk, the most critical attribute is the criticality rating based on business impact because it directly quantifies the potential harm from a security incident. Without knowing which assets are most vital to business operations, risk prioritization becomes arbitrary, leading to misallocated security controls. This aligns with the CRISC focus on risk-based decision-making, where impact drives the urgency of mitigation.

Exam trap

The trap here is that candidates often confuse operational attributes (like IP address or owner) with risk attributes, assuming that knowing where an asset is or who owns it is sufficient for risk assessment, when in fact business impact is the primary driver of risk prioritization.

How to eliminate wrong answers

Option B is wrong because IP address and location are operational attributes that help with network mapping and incident response, but they do not indicate the asset's importance or the severity of risk if compromised. Option C is wrong because asset owner contact information is useful for accountability and notification, but it does not influence the inherent risk level of the asset itself. Option D is wrong because the software vendor name alone provides no insight into the asset's business value or the specific vulnerabilities that could be exploited; it is merely a procurement detail.

534
MCQeasy

A retail company has a risk register that includes a risk of inventory shrinkage due to employee theft. The risk manager decides to implement a new surveillance system and conduct background checks on all new hires. Which risk response strategy is being applied?

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerD

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Surveillance systems deter theft and increase detection, while background checks reduce the likelihood of hiring individuals prone to theft. These actions directly lower the risk of inventory shrinkage, making this a clear example of mitigation.

Why this answer

Implementing surveillance and background checks are preventive controls that reduce the likelihood of employee theft. This is a classic risk mitigation strategy, as the company is taking direct action to lower the risk rather than accepting, avoiding, or transferring it. Mitigation is appropriate when the risk is significant and controls can cost-effectively reduce it.

Exam trap

The trap here is confusing mitigation with transfer, assuming that any action involving insurance or external parties is transfer, but these internal controls are clearly mitigation.

535
MCQhard

A software development team is adopting Agile methodology and wants to integrate risk identification into their sprints. Which approach BEST aligns with Agile principles while ensuring effective risk identification?

A.Conduct a risk workshop at the start of the project only
B.Assign risk identification solely to the product owner
C.Perform an annual risk assessment
D.Incorporate a risk identification task in each sprint backlog and review risks during sprint retrospectives
AnswerD

Adding a risk identification task to each sprint backlog and reviewing risks in retrospectives embeds risk work into existing Agile ceremonies, keeping it iterative and continuous. This satisfies the stem's requirement to align with Agile principles while ensuring risks are identified every sprint.

Why this answer

Agile emphasizes iterative, continuous improvement, and integrating risk identification into each sprint backlog ensures risks are identified and addressed as the project evolves. Reviewing risks during sprint retrospectives aligns with the Agile principle of inspecting and adapting, making risk management a recurring, team-driven activity rather than a one-time event. This approach is effective because it captures risks that emerge from changing requirements, technical debt, or integration issues during development.

Exam trap

The trap here is that candidates may think risk identification is a one-time planning activity (Option A) or a single role's responsibility (Option B), but CRISC emphasizes that risk identification must be continuous and collaborative in Agile environments to be effective.

How to eliminate wrong answers

Option A is wrong because conducting a risk workshop only at the start of the project violates the Agile principle of continuous feedback and adaptation; risks that emerge later in development (e.g., from new dependencies or scope changes) would be missed. Option B is wrong because assigning risk identification solely to the product owner contradicts the Agile principle of cross-functional team ownership and collaboration; risk identification is a shared responsibility that benefits from diverse technical perspectives. Option C is wrong because performing an annual risk assessment is too infrequent for Agile sprints, which typically last 1-4 weeks; this approach would fail to identify rapidly emerging risks such as security vulnerabilities introduced by new code or third-party library updates.

536
MCQhard

A large enterprise uses a risk matrix with impact categories (very low, low, medium, high, very high) and likelihood (rare, unlikely, possible, likely, almost certain). A risk identified has a 'likely' likelihood and 'high' impact. According to the matrix, risks with this combination are classified as 'high' risk. The risk appetite statement requires that all high risks have a response plan within 30 days. However, the risk owner argues that due to effective compensating controls, the residual risk is only 'medium'. Which of the following is the BEST course of action?

A.Formalize the risk treatment plan and include the compensating controls in the risk register.
B.Implement additional controls to ensure the residual risk becomes low.
C.Accept the risk as is, since controls reduce it to acceptable level.
D.Document the residual risk as medium and extend the response deadline beyond 30 days.
AnswerA

Formalizing the risk treatment plan and including the compensating controls in the risk register is the best action. It documents the residual risk as medium and satisfies the requirement for a response plan within 30 days.

Why this answer

The risk appetite statement mandates that all high risks have a response plan within 30 days. Even if the risk owner argues residual risk is medium due to compensating controls, the initial risk classification is high, so a formal risk treatment plan must be created and the compensating controls documented in the risk register. This ensures compliance with policy and provides a clear record.

Exam trap

CRISC often tests the misconception that effective compensating controls can bypass policy requirements for high risks, leading candidates to choose acceptance or deadline extension instead of formalizing the required response plan.

How to eliminate wrong answers

Option B is wrong because implementing additional controls to reduce residual risk to low is not required by the policy; the policy only requires a response plan for high risks, and the current controls may be sufficient. Option C is wrong because accepting the risk as is without a formal plan violates the risk appetite statement's requirement for a response plan within 30 days. Option D is wrong because extending the deadline beyond 30 days is not allowed by the policy, and documenting residual risk as medium does not negate the need for a response plan for the inherent high risk.

537
MCQeasy

Which of the following is the BEST indicator that a risk assessment should be performed outside the normal cycle?

A.A new regulation is proposed
B.An employee leaves the company
C.A major IT infrastructure change
D.The annual budget is approved
AnswerC

A major IT infrastructure change alters the threat landscape, vulnerabilities and control environment, invalidating prior assessment assumptions. This triggers an out-of-cycle assessment because the existing risk profile no longer reflects the operating environment, satisfying the stem's need for the strongest trigger indicator.

Why this answer

A major IT infrastructure change introduces new or altered assets, data flows, and threat surfaces that were not considered in the previous risk assessment cycle. This change can invalidate existing control assumptions and risk ratings, making an ad-hoc assessment necessary to identify and evaluate emerging risks before they materialize.

Exam trap

The trap here is confusing routine operational events (like employee turnover or budget cycles) with events that fundamentally change the risk profile, leading candidates to overlook the necessity of an ad-hoc assessment triggered by a significant technical change.

How to eliminate wrong answers

Option A is wrong because a proposed regulation is not yet enacted; risk assessments are triggered by compliance requirements only after the regulation is finalized and effective. Option B is wrong because an employee departure is a personnel event that typically triggers an access review or segregation-of-duties check, not a full risk assessment outside the normal cycle. Option D is wrong because budget approval is a financial planning event that does not directly alter the risk landscape; it may enable risk treatment actions but does not itself require a new risk assessment.

538
Multi-Selecteasy

A risk manager is designing a monitoring and reporting framework. Which THREE of the following are essential components of an effective risk and control monitoring program?

Select 3 answers
A.Control self-assessments (CSAs)
B.Key performance indicators (KPIs)
C.Risk reporting dashboards
D.Key risk indicators (KRIs)
E.Risk response plans
AnswersA, C, D

CSAs involve business owners evaluating control effectiveness, which is essential for monitoring.

Why this answer

Control self-assessments (CSAs) are essential because they empower process owners to evaluate the design and operating effectiveness of internal controls, providing firsthand evidence for the monitoring program. This bottom-up approach complements top-down testing by identifying control gaps and remediation needs directly from those who execute the controls, which is critical for a comprehensive risk and control monitoring framework.

Exam trap

ISACA often tests the distinction between KPIs and KRIs, where candidates mistakenly select KPIs because they confuse operational performance metrics with risk indicators, but KPIs do not directly measure risk exposure or control effectiveness.

539
MCQmedium

An employee with access to sensitive financial data has been observed accessing systems outside of normal working hours and exhibiting erratic behavior. The IT risk manager suspects insider threat. What is the most appropriate risk response?

A.Terminate the employee immediately
B.Implement additional monitoring and restrictions
C.Accept the risk as the employee is trusted
D.Transfer via fidelity insurance
AnswerB

Insider threat involving privileged financial access cannot be proven immediately, so additional monitoring and restrictions contain the risk while evidence is gathered. This satisfies the need for a proportionate response that limits exposure without prematurely accusing or removing the employee.

Why this answer

Implementing additional monitoring and restrictions (Option B) is the most appropriate risk response because it allows the organization to gather more evidence of the suspected insider threat while immediately reducing the attack surface. This aligns with the risk mitigation strategy, as it directly addresses the observed anomalous behavior—accessing systems outside normal hours—without prematurely escalating the situation. In a financial data environment, this could involve enabling enhanced audit logging, restricting access to specific IP ranges or times, and deploying user and entity behavior analytics (UEBA) to detect deviations from baseline activity.

Exam trap

A common mistake in the CRISC exam is assuming that immediate termination (Option A) is the best response to insider threats, but the trap here is that termination is a punitive action, not a risk response—it fails to preserve evidence and may violate due process, whereas monitoring and restriction is a proper mitigation that balances security with operational continuity.

How to eliminate wrong answers

Option A is wrong because immediate termination without a full investigation could destroy critical forensic evidence, violate employment or data privacy laws, and does not address the root cause of the behavior; it is a reactive, punitive measure rather than a controlled risk response. Option C is wrong because accepting the risk based solely on the employee being 'trusted' ignores the clear indicators of potential malicious activity (erratic behavior, off-hours access) and violates the principle of least privilege and continuous monitoring required for sensitive financial data. Option D is wrong because transferring the risk via fidelity insurance only covers financial loss after an incident occurs, not the ongoing threat; it does nothing to prevent the insider from exfiltrating data or causing harm in the immediate term.

540
MCQmedium

An organization is deploying IoT sensors in a manufacturing plant. Which of the following is the MOST significant security risk associated with these devices?

A.Interference with radio frequency signals
B.Limited data storage capacity
C.High power consumption leading to operational costs
D.Inability to apply security patches due to legacy firmware
AnswerD

Legacy firmware often cannot accept vendor patches, leaving known vulnerabilities permanently exploitable on plant-floor sensors with long service lives. This satisfies the stem's constraint of identifying the most significant risk, since unpatchable devices sustain exposure that segmentation or monitoring alone cannot remediate.

Why this answer

IoT devices often have limited security features and may lack the ability to receive firmware updates, making them vulnerable and expanding the attack surface.

541
MCQhard

An organization has implemented a firewall (preventive), intrusion detection system (detective), and a backup restoration plan (corrective) to address a specific risk. The risk manager assesses the control effectiveness as follows: design adequacy is strong, but operating effectiveness is weak due to inconsistent patching. Which of the following best describes the residual risk?

A.Residual risk cannot be determined without a quantitative analysis
B.Residual risk is negligible because multiple controls are in place
C.Residual risk is lower than inherent risk but still significant due to weak operating effectiveness
D.Residual risk is equal to inherent risk because controls are ineffective
AnswerC

Residual risk falls below inherent risk because preventive, detective, and corrective controls are all designed adequately, yet weak operating effectiveness from inconsistent patching leaves meaningful exposure unaddressed. Design adequacy alone cannot reduce risk to acceptable levels; the controls must actually function as intended, so significant residual risk persists.

Why this answer

Residual risk is lower than inherent risk because the three controls (preventive, detective, corrective) do reduce the risk, but it remains significant because weak operating effectiveness — inconsistent patching — means the controls are not functioning as designed. Design adequacy alone does not guarantee risk reduction; actual operating effectiveness determines the true residual level.

Exam trap

The trap here is conflating design adequacy with operating effectiveness — candidates see 'strong design' and 'multiple controls' and assume residual risk is negligible, ignoring that weak operating effectiveness keeps residual risk significant.

How to eliminate wrong answers

Option A is wrong because residual risk can be assessed qualitatively or semi-quantitatively; quantitative analysis is not a prerequisite for determining that residual risk exists and is significant. Option B is wrong because multiple controls do not make residual risk negligible when operating effectiveness is weak — layered controls with poor execution still leave material exposure. Option D is wrong because residual risk equals inherent risk only if controls provide zero risk reduction; here the controls do reduce risk, just not to an acceptable level, so residual is lower than inherent.

542
MCQmedium

During a vendor risk assessment, a third-party vendor is classified as "critical" because it has access to sensitive customer data. According to the organization's risk appetite, what minimum security requirement should be mandated for this vendor?

A.SOC 2 Type II report
B.General liability insurance certificate
C.Penetration test results from the vendor
D.Self-assessment questionnaire only
AnswerA

A SOC 2 Type II report independently attests that controls over security, availability and confidentiality operated effectively across a review period, giving assurance proportionate to the critical vendor's access to sensitive customer data and satisfying the risk-appetite requirement for validated third-party control evidence.

Why this answer

A SOC 2 Type II report is the minimum security requirement for a critical vendor with access to sensitive customer data because it provides an independent, audited assessment of the vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time. This aligns with the organization's risk appetite by ensuring that the vendor has demonstrated effective controls in place to protect sensitive data, rather than relying on a point-in-time test or self-reported information.

Exam trap

The trap here is that candidates often choose penetration test results (Option C) because they seem technically rigorous, but they fail to recognize that a point-in-time test does not provide the ongoing assurance of control effectiveness required for a critical vendor with access to sensitive customer data.

How to eliminate wrong answers

Option B is wrong because a general liability insurance certificate covers financial losses from incidents like property damage or bodily injury, not the technical security controls required to protect sensitive customer data. Option C is wrong because penetration test results provide only a point-in-time snapshot of vulnerabilities and do not demonstrate ongoing control effectiveness or compliance with security frameworks. Option D is wrong because a self-assessment questionnaire alone is insufficient for a critical vendor, as it relies on unverified self-reported information and lacks independent validation of security controls.

543
MCQmedium

A financial services company's risk register shows that a critical vulnerability in its online banking application has a high likelihood of exploitation and a high impact. The risk owner decides to implement a web application firewall (WAF) and conduct monthly penetration tests. Which risk response strategy is being applied?

A.Risk acceptance
B.Risk avoidance
C.Risk mitigation
D.Risk transfer
AnswerC

Risk mitigation reduces the likelihood or impact of a risk through controls. Implementing a WAF and conducting penetration tests are detective and preventive controls that lower the probability of exploitation and the potential damage, aligning with mitigation.

Why this answer

The organization is reducing the likelihood and impact of the vulnerability by adding a WAF and performing regular penetration tests. These actions are classic risk mitigation controls that lower residual risk. Avoidance would mean discontinuing the online banking service, transfer would involve insurance, and acceptance would mean no action.

Exam trap

The trap here is confusing mitigation with avoidance because both involve taking action, but avoidance eliminates the risk source entirely.

544
MCQhard

A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time data analytics. Which of the following represents the MOST significant risk introduced by this convergence?

A.Increased complexity in managing network bandwidth
B.Potential for increased data redundancy
C.Expansion of the attack surface from IT to OT environments
D.Higher licensing costs for security software
AnswerC

Bridging IT and OT dissolves the air gap that previously isolated industrial control systems. Each newly reachable OT device, protocol and service becomes an additional entry point, so the attack surface expands from enterprise IT into operational technology, exposing safety-critical processes to IT-borne threats.

Why this answer

Connecting ICS to the corporate network expands the attack surface, allowing threats from the IT network to reach OT systems, potentially leading to safety incidents.

545
MCQeasy

Which risk treatment option involves purchasing cyber insurance?

A.Avoid
B.Transfer
C.Mitigate
D.Accept
AnswerB

Transfer shifts the financial consequence of a risk to a third party. Cyber insurance does exactly this: the insurer absorbs covered losses in exchange for premiums, leaving the organisation's residual exposure reduced rather than retained, avoided, or mitigated.

Why this answer

Cyber insurance is a form of risk transfer, where the financial impact of a loss is shifted to the insurer.

546
MCQeasy

Which threat actor is most likely motivated by political ideology and may target government systems?

A.Organized crime
B.Nation-state APT
C.Hacktivist
D.Script kiddie
AnswerC

Hacktivists are driven by political, ideological or social agendas, and they frequently deface or disrupt government, military and activist-related systems to publicise their cause. Unlike financially motivated cybercriminals or state-sponsored actors, their primary motivation is ideological, matching the stem's political-ideology and government-target criteria.

Why this answer

Hacktivists are threat actors whose primary motivation is political ideology, social activism, or protest. They often target government systems to disrupt operations, deface websites, or leak sensitive information in order to advance their political agenda, making option C correct.

Exam trap

The trap here is confusing nation-state APTs with hacktivists because both may target government systems, but the key differentiator is motivation: nation-state APTs act for geopolitical or espionage reasons, while hacktivists are driven by political ideology and often seek public visibility.

How to eliminate wrong answers

Option A is wrong because organized crime is motivated by financial gain, not political ideology, and typically targets financial institutions or data for resale. Option B is wrong because nation-state APTs are state-sponsored actors focused on espionage, geopolitical advantage, or strategic disruption, not primarily political ideology or public protest. Option D is wrong because script kiddies are unskilled attackers using pre-made tools for notoriety or fun, lacking the ideological motivation to specifically target government systems.

547
MCQeasy

A mid-sized retail company processes over 1 million credit card transactions daily. It uses an automated monitoring system with static thresholds to flag potential fraud. Recently, the fraud detection team has been overwhelmed by a 40% increase in false positive alerts, causing legitimate transactions to be delayed and customer service complaints to rise. The risk manager is tasked with improving the situation. After reviewing the alert logs, it is clear that the thresholds have not been updated in 18 months, and transaction patterns have shifted due to seasonal promotions and new payment methods. The team has limited resources and cannot handle the current alert volume. What should the risk manager recommend as the most effective course of action?

A.Perform a root cause analysis on the false positives to refine the detection rules and thresholds.
B.Deploy an additional monitoring tool with machine learning capabilities.
C.Engage an external fraud detection consultant to review the system.
D.Immediately increase the alert thresholds to reduce the volume of alerts.
AnswerA

Static thresholds left unchanged for 18 months no longer reflect shifted transaction patterns, so the alerts themselves are mis-calibrated. Root cause analysis identifies which rules and thresholds generate the false positives, letting the team recalibrate detection precisely rather than adding headcount it does not have.

Why this answer

Performing a root cause analysis to refine detection rules and thresholds (Option A) directly addresses the outdated thresholds that caused the increase in false positives. This approach is systematic and can be tailored to the current transaction patterns without requiring additional resources or tools. Option B (deploying a machine learning tool) introduces new complexity and costs without fixing the underlying threshold issue, and the team's limited resources may hinder implementation.

Option C (hiring an external consultant) is costly and slow, and may not be sustainable. Option D (increasing thresholds immediately) could reduce alert volume but risks missing true positives, making it a temporary fix rather than a long-term solution.

548
Multi-Selectmedium

A risk practitioner at a regional bank is compiling a list of internal threat sources for the enterprise risk assessment. Which TWO of the following are internal threat sources that should be included? (Choose two.)

Select 2 answers
A.A nation-state actor conducting espionage against financial regulators
B.A terminated employee who retained a VPN credential
C.A contractor with privileged access to the core banking platform
D.An organized crime group running ransomware campaigns
E.A hacktivist group targeting the bank's public website
AnswersB, C

A former employee who still holds valid access is an internal threat source because the actor has or had trusted access to bank systems. Insider threats include malicious, negligent, and compromised insiders, and the terminated employee with a live credential fits the malicious or negligent insider category. This directly affects the likelihood assessment for unauthorized access scenarios.

Why this answer

Internal threat sources are actors who operate within or with trusted access to the organization, including current and former employees, contractors, and other insiders with authorized privileges. The terminated employee with a retained credential and the contractor with privileged platform access both meet that definition. Hacktivists, nation-state actors, and organized crime groups are external sources even when they target the bank.

Exam trap

The trap here is assuming that any actor who attacks the bank is an internal source, when internal classification depends on trusted access rather than on intent or target.

549
MCQmedium

An organization is selecting a control to reduce the risk of unauthorized data exfiltration. The annual loss expectancy (ALE) for this risk is currently $500,000. The proposed control costs $80,000 annually and is expected to reduce the ALE by 60%. What is the net benefit (reduction in risk exposure minus control cost) of implementing this control?

A.$220,000
B.$420,000
C.$300,000
D.$120,000
AnswerA

A 60% reduction on the $500,000 ALE yields $300,000 in avoided loss. Subtracting the $80,000 annual control cost gives a net benefit of $220,000, satisfying the stem's requirement to quantify risk reduction minus control cost.

Why this answer

The current ALE is $500,000. A 60% reduction lowers the ALE by $300,000 (0.60 × $500,000). The net benefit is the reduction in risk exposure ($300,000) minus the annual control cost ($80,000), resulting in $220,000.

This calculation directly measures the residual risk reduction against the cost of the control, a key concept in cost-benefit analysis for risk response.

Exam trap

The trap here is that candidates often forget to subtract the control cost from the risk reduction, mistakenly selecting the reduction amount ($300,000) as the net benefit, or they incorrectly apply the percentage to the wrong base value, such as subtracting the cost from the original ALE.

How to eliminate wrong answers

Option B ($420,000) is wrong because it incorrectly subtracts the control cost from the original ALE ($500,000 - $80,000), ignoring the 60% reduction factor. Option C ($300,000) is wrong because it represents only the reduction in ALE (60% of $500,000) without subtracting the control cost, failing to account for the expense of implementation. Option D ($120,000) is wrong because it mistakenly calculates the net benefit as the control cost ($80,000) subtracted from the remaining ALE after reduction ($200,000), which confuses residual risk with net benefit.

550
Multi-Selecteasy

Which TWO of the following are types of insider threats?

Select 2 answers
A.Malicious
B.Nation-state
C.Hacktivist
D.Negligent
E.Script kiddie
AnswersA, D

Malicious insiders act with deliberate intent to steal data, sabotage systems or abuse privileged access for gain. This satisfies the stem's requirement for an insider threat type, contrasting premeditated action with accidental or coerced behaviour.

Why this answer

Insider threats can be malicious (intentional harm) or negligent (unintentional mistakes).

551
MCQeasy

Which of the following is a Key Risk Indicator (KRI) that provides leading indication of increasing vulnerability risk?

A.Control deficiency rate
B.Patch lag metric
C.Mean time to detect (MTTD)
D.Number of security incidents
AnswerB

Patch lag measures elapsed time between patch release and deployment, rising before exploitation occurs, so it leads vulnerability risk rather than reporting it afterwards. This satisfies the KRI requirement for a leading indication, unlike lagging metrics such as confirmed exploit counts.

Why this answer

Patch lag metric is a leading KRI because it measures the time between patch availability and deployment, directly indicating how exposed systems are to known vulnerabilities before exploitation occurs. A growing patch lag signals increasing vulnerability risk before incidents materialize.

Exam trap

CRISC often tests leading versus lagging indicators by offering metrics like incident counts or MTTD that sound risk-related but are actually lagging, tempting candidates to misclassify them as leading KRIs.

How to eliminate wrong answers

Option A is wrong because control deficiency rate is a lagging indicator — it reflects deficiencies already identified, not future vulnerability risk. Option C is wrong because mean time to detect (MTTD) is a detective performance metric that measures response capability after an event, not a leading indicator of increasing vulnerability. Option D is wrong because the number of security incidents is a lagging indicator that counts events that have already occurred, not a forward-looking vulnerability signal.

552
MCQmedium

After implementing a set of controls, the risk owner calculates the residual risk. Which of the following is true about residual risk?

A.It is the risk that remains after controls are applied
B.It is not considered in risk treatment decisions
C.It is always higher than inherent risk
D.It is the risk before any controls are implemented
AnswerA

Residual risk is the exposure remaining once implemented controls have reduced inherent risk, so it directly satisfies the stem's scenario of a risk owner calculating exposure after controls. It reflects control effectiveness rather than the untreated threat, and must be compared against the risk appetite to decide whether further treatment is required.

Why this answer

Residual risk is by definition the risk that remains after controls have been applied and risk treatment has occurred. It represents the exposure the organization accepts or must further mitigate after existing safeguards are considered.

Exam trap

The trap is confusing residual risk with inherent risk — candidates may select 'risk before controls' or assume residual risk can exceed inherent risk, misunderstanding the fundamental relationship between the two.

How to eliminate wrong answers

Option B is wrong because residual risk is central to risk treatment decisions — it determines whether additional controls are needed or whether the risk is acceptable. Option C is wrong because residual risk is always less than or equal to inherent risk, never higher, since controls can only reduce (or leave unchanged) the original risk. Option D is wrong because risk before controls is inherent risk, not residual risk; the two are distinct concepts in the CRISC framework.

553
Multi-Selectmedium

Which THREE of the following are key components of a risk assessment report?

Select 3 answers
A.Risk register with identified risks
B.Copies of vendor contracts
C.Recommended risk response actions
D.Network topology diagram
E.Risk analysis (likelihood and impact)
AnswersA, C, E

The risk register catalogues each identified risk with its owner, likelihood, impact and response, forming the evidentiary core that the rest of the report analyses. Without it, findings cannot be traced or tracked, so it satisfies the stem's key-component requirement.

Why this answer

A risk assessment report must document the identified risks in a structured format, so option A (Risk register with identified risks) is correct because the risk register is the core artifact that catalogs each risk, its owner, and its status. Option C (Recommended risk response actions) is correct because the report must translate findings into actionable treatment options such as mitigate, transfer, avoid, or accept, guiding decision-makers on next steps. Option E (Risk analysis (likelihood and impact)) is correct because quantifying or qualifying each risk by its probability and potential impact is the analytical heart of the assessment, typically expressed as a risk score (e.g., likelihood × impact).

Options B (Copies of vendor contracts) and D (Network topology diagram) are supporting evidence or technical artifacts that may inform the assessment but are not key components of the risk assessment report itself.

Exam trap

The trap here is that candidates confuse supporting artifacts (like network diagrams or contracts) with mandatory report components, but the CRISC exam specifically tests that the risk assessment report must include the risk register, risk analysis, and risk response recommendations as its key deliverables.

554
Multi-Selectmedium

Which TWO of the following are examples of risk avoidance? (Select TWO.)

Select 2 answers
A.Accepting the risk
B.Installing a firewall
C.Deciding not to enter a new market
D.Purchasing insurance
E.Discontinuing a risky product line
AnswersC, E

Declining to enter a new market eliminates the exposure entirely rather than reducing or transferring it, satisfying the stem's requirement for risk avoidance. Unlike mitigation, which lowers likelihood or impact, or acceptance, which retains the risk, avoidance removes the underlying activity generating the threat.

Why this answer

Risk avoidance involves taking action to eliminate the risk entirely by not engaging in the activity that introduces it. Option C, 'Deciding not to enter a new market,' avoids all associated market, regulatory, and competitive risks by simply not pursuing that business opportunity. Option E, 'Discontinuing a risky product line,' removes the risk by ceasing the activity that generates it, such as halting production of a product with known safety or compliance issues.

Exam trap

The trap here is that candidates often confuse risk avoidance with risk mitigation or transfer, mistakenly selecting options like 'installing a firewall' (mitigation) or 'purchasing insurance' (transfer) as examples of avoidance, when avoidance requires ceasing or not starting the risk-generating activity.

555
MCQmedium

A company is evaluating the cost-benefit of a new control that reduces the annualized loss expectancy (ALE) from $500,000 to $100,000. The control has an annual cost of $150,000. What is the net benefit of implementing this control?

A.$350,000
B.$250,000
C.$400,000
D.$50,000
AnswerB

The control lowers annualised loss expectancy by $400,000 ($500,000 − $100,000), then subtracts its $150,000 annual cost, giving a net benefit of $250,000. This satisfies the stem's cost-benefit constraint by quantifying residual risk reduction against control expenditure, confirming the investment yields positive value.

Why this answer

The net benefit of implementing a control is calculated as the reduction in Annualized Loss Expectancy (ALE) minus the annual cost of the control. The ALE reduction is $500,000 - $100,000 = $400,000. Subtracting the annual control cost of $150,000 yields a net benefit of $250,000, making option B correct.

Exam trap

The trap here is that candidates often forget to subtract the annual control cost from the ALE reduction, mistakenly selecting the gross reduction ($400,000) as the net benefit, or they incorrectly subtract the residual ALE instead of the control cost.

How to eliminate wrong answers

Option A is wrong because $350,000 represents the ALE reduction ($400,000) minus only the residual ALE ($100,000) instead of the control cost, a common miscalculation. Option C is wrong because $400,000 is the gross reduction in ALE before subtracting the control's annual cost, ignoring the expense side of cost-benefit analysis. Option D is wrong because $50,000 incorrectly subtracts the control cost from the residual ALE ($100,000 - $150,000 = -$50,000) or misapplies the formula, yielding a negative or minimal value that does not reflect the actual net benefit.

556
MCQmedium

A risk practitioner is reviewing the organization's risk register and notes that a critical web application has a high inherent risk of SQL injection. The development team proposes implementing a web application firewall (WAF) with virtual patching. The risk practitioner's primary responsibility in this scenario is to:

A.Immediately implement the WAF and virtual patching to address the vulnerability before any exploitation occurs.
B.Transfer the risk by purchasing cyber insurance that covers SQL injection attacks, since the WAF may not be fully effective.
C.Accept the risk because the WAF will eventually be deployed and the residual risk will be managed by the IT team.
D.Evaluate whether the proposed control reduces risk to an acceptable level within the organization's risk appetite.
AnswerD

The risk practitioner's role is to assess whether the proposed risk response (WAF with virtual patching) effectively mitigates the identified risk to a level that aligns with the organization's risk appetite. This involves analyzing the control's expected effectiveness, cost, and impact on residual risk. The practitioner does not implement controls or accept risk unilaterally; rather, they provide guidance to ensure the response is appropriate and aligned with business objectives.

Why this answer

The risk practitioner's core duty is to evaluate risk responses, not to implement them or accept risk. In this scenario, the proposed WAF with virtual patching is a mitigation control. The practitioner must assess whether it reduces the SQL injection risk to a level consistent with the organization's risk appetite.

This involves considering control effectiveness, potential residual risk, and cost-benefit. Only after this evaluation can the risk owner make an informed decision.

Exam trap

The trap here is confusing the risk practitioner's advisory role with hands-on implementation or risk acceptance authority.

557
MCQmedium

A company has implemented a key risk indicator (KRI) for system availability, with a threshold of 99.5%. The monitoring team observes that availability has dropped to 99.2% for two consecutive months. What is the most appropriate next step?

A.Implement additional redundancy to improve availability.
B.Increase the threshold to 99.0% to avoid false alarms.
C.Notify the risk owner and initiate a root cause analysis.
D.Escalate immediately to the board of directors.
AnswerC

Availability at 99.2% breaches the 99.5% KRI threshold for two consecutive months, so the indicator has been triggered. Escalating to the risk owner and performing root cause analysis converts the breach into assessed, actionable risk response rather than passive monitoring.

Why this answer

A sustained breach of a KRI threshold (99.2% vs. 99.5%) for two consecutive months indicates a systemic issue that requires formal risk management action. The risk owner must be notified to assess the impact, and a root cause analysis (RCA) should be initiated to identify underlying failures—such as network congestion, hardware faults, or software bugs—before any remediation is planned.

Exam trap

The trap here is that candidates often jump to immediate remediation (Option A) or threshold adjustment (Option B), failing to recognize that the CRISC framework mandates a structured risk response starting with notification and analysis before any control changes.

How to eliminate wrong answers

Option A is wrong because implementing additional redundancy without first understanding the root cause could waste resources on the wrong fix (e.g., adding servers when the issue is a misconfigured load balancer or a DDoS attack). Option B is wrong because lowering the threshold to 99.0% is a form of risk acceptance without analysis, which violates the principle of maintaining objective KRIs and could mask a deteriorating service level agreement (SLA). Option D is wrong because immediate escalation to the board is premature; the board should be informed only after the risk owner has assessed the situation and determined that the risk exceeds the enterprise risk appetite, not for a single KRI breach.

558
MCQmedium

A risk practitioner has completed a quantitative risk analysis for a customer-facing payment platform. The analysis shows an inherent annualized loss expectancy (ALE) of $2.4 million. Management wants to fund a tokenization control that reduces the ALE to $600,000, but the control costs $1.9 million per year to operate. Which action should the risk practitioner recommend?

A.Reject the tokenization control because its annual cost exceeds the reduction in ALE, and document the accepted residual risk.
B.Defer the decision indefinitely until the inherent ALE increases enough to justify the control cost.
C.Implement the tokenization control because it reduces the ALE by $1.8 million.
D.Implement the tokenization control and offset the shortfall by reducing the scope of the annual penetration test.
AnswerA

The control costs $1.9 million but only reduces expected loss by $1.8 million, producing a negative net benefit of $100,000 per year. Spending more than the expected loss avoided is not cost-justified, so the practitioner should advise against funding it and ensure the $600,000 residual ALE is formally accepted by the appropriate risk owner with documented rationale.

Why this answer

Cost-benefit analysis compares the control's annual cost against the reduction in expected loss it produces. Here the $1.9 million cost exceeds the $1.8 million ALE reduction, so the control is not economically justified. The correct response is to advise against funding it while ensuring the remaining $600,000 residual risk is explicitly accepted and documented by the accountable risk owner.

Exam trap

The trap here is treating the gross reduction in ALE as the benefit and never subtracting the control's ongoing cost.

559
MCQeasy

A retail company's risk register lists 'unauthorized access to the customer loyalty database' with a likelihood of 4 and an impact of 5 on a 1-5 scale. The CISO asks the risk practitioner to reduce the risk to an acceptable level. Which action BEST represents risk treatment in this situation?

A.Report the risk to the board risk committee and request a decision on acceptance.
B.Recalculate the likelihood and impact scores with the database team and update the risk register.
C.Deploy database activity monitoring and enforce least-privilege access to the loyalty database.
D.Purchase a cyber insurance policy that covers privacy breach response costs.
AnswerC

Risk treatment is the deliberate selection and implementation of controls that modify likelihood or impact. Database activity monitoring detects anomalous access while least-privilege enforcement reduces the chance that compromised accounts can reach sensitive records, directly lowering the likelihood component of the registered risk. This is a concrete, targeted control response rather than documentation or measurement activity.

Why this answer

Risk treatment means selecting and applying controls that change the likelihood or impact of an identified risk. Enforcing least privilege and monitoring database activity directly reduce the chance of unauthorized access, which is the likelihood dimension in the register. Re-scoring, escalation and insurance are assessment, governance and transfer activities that leave the underlying exposure unchanged.

Exam trap

The trap here is confusing activities that document, escalate or transfer risk with activities that actually modify the risk itself.

560
MCQeasy

An organization decides to outsource its data center operations to a third party. This is an example of which risk response?

A.Risk reduction
B.Risk transfer
C.Risk acceptance
D.Risk avoidance
AnswerB

Outsourcing shifts the financial impact of data centre failures to the third party, satisfying the stem's need to reallocate risk ownership. Unlike risk avoidance, which eliminates the activity, or mitigation, which reduces likelihood, transfer moves the consequence to another party via contract.

Why this answer

Outsourcing data center operations transfers the financial and operational risks associated with managing the infrastructure to a third-party provider. This is a classic risk transfer response because the organization retains ownership of the data and business accountability but shifts the liability for physical security, hardware maintenance, and uptime to the vendor via contractual agreements, such as SLAs with penalty clauses.

Exam trap

The trap here is that candidates confuse risk transfer with risk reduction, mistakenly thinking that outsourcing reduces the risk of hardware failure, when in fact it only shifts the financial liability for that failure, not the operational impact on the business.

How to eliminate wrong answers

Option A is wrong because risk reduction involves implementing controls to lower the likelihood or impact of a risk, such as deploying redundant power supplies or fire suppression systems, not outsourcing operations. Option C is wrong because risk acceptance means formally acknowledging the risk and choosing to bear it without additional action, which contradicts the active decision to engage a third party. Option D is wrong because risk avoidance would mean ceasing the activity that generates the risk, such as shutting down the data center entirely, rather than transferring its management to another entity.

561
MCQmedium

A risk practitioner at a regional bank is building a threat landscape for its new mobile payment platform. A recently published report from a national CERT indicates that a loosely organized group has been targeting payment APIs across the region, exploiting known authentication weaknesses. The practitioner wants to determine whether this group should be treated as a relevant threat source in the risk register. Which of the following is the MOST appropriate FIRST step?

A.Immediately add the group to the risk register as a high-rated threat because it appears in a national CERT report.
B.Implement additional authentication controls on the mobile payment APIs to mitigate the reported weaknesses.
C.Subscribe to additional commercial threat intelligence feeds to obtain more detail on the group's activities.
D.Assess the group's capability, intent, and opportunity against the bank's specific mobile payment assets.
AnswerD

Risk identification requires evaluating threat sources in terms of capability, intent, and opportunity relative to the organization's own assets. The CERT report establishes general activity, but relevance to the bank depends on whether the group can realistically reach and exploit the mobile payment APIs. This asset-centric assessment determines if the threat is material and warrants entry into the risk register.

Why this answer

Threat sources become relevant only when evaluated against the organization's own assets through capability, intent, and opportunity. A CERT report signals activity in the sector, but the bank must determine whether the group can realistically reach and exploit its mobile payment APIs. That asset-centric analysis is the first step before the threat is entered into the risk register or any control is selected.

Exam trap

The trap here is treating external threat intelligence as a direct input to the risk register without first assessing the threat source against the organization's specific assets.

562
MCQeasy

An organization is considering migrating its customer database to a public cloud provider. Which of the following is the PRIMARY risk identification technique that should be used to identify potential data exposure risks?

A.Vulnerability scanning
B.Threat modeling
C.Penetration testing
D.Business impact analysis
AnswerB

Threat modelling systematically enumerates threats, attack vectors and weaknesses against the database's architecture and data flows, exposing data-exposure scenarios before migration. It satisfies the stem's requirement for a primary risk identification technique by revealing threats that generic checklists would miss.

Why this answer

Threat modeling is the primary risk identification technique for proactively identifying potential data exposure risks during a cloud migration. It systematically analyzes the system architecture, data flows, and trust boundaries to uncover threats such as misconfigured access controls, insecure APIs, or data leakage between tenants. Unlike reactive techniques, threat modeling focuses on design-level vulnerabilities before they are exploited.

Exam trap

The trap here is that candidates confuse vulnerability scanning (a reactive, point-in-time check) with proactive risk identification, but threat modeling is the only technique that addresses design-level data exposure risks before migration.

How to eliminate wrong answers

Option A is wrong because vulnerability scanning identifies known software flaws (e.g., CVEs) in running systems but does not assess architectural risks like data exposure from shared cloud storage or improper IAM policies. Option C is wrong because penetration testing validates exploitability of existing vulnerabilities after deployment, not the proactive identification of data exposure risks during migration planning. Option D is wrong because business impact analysis prioritizes critical assets and recovery objectives, not the technical identification of data exposure threats.

563
MCQmedium

An organization is designing a risk and control monitoring program for a new cloud-based application. Which of the following is the MOST important factor to consider when selecting Key Risk Indicators (KRIs)?

A.Historical loss data availability.
B.Ease of automated data collection.
C.Industry best practices.
D.Alignment with strategic objectives.
AnswerD

KRIs tied to strategic objectives ensure monitoring reflects risks that actually threaten the organisation's goals, rather than isolated technical metrics. This alignment keeps the cloud programme's risk reporting meaningful to leadership and drives relevant control decisions.

Why this answer

Alignment with strategic objectives is the most important factor because KRIs must directly measure risks that could impede the organization's business goals and strategic initiatives. For a new cloud-based application, KRIs tied to strategic objectives ensure monitoring focuses on risks that matter most to the business, such as data breaches affecting customer trust or service downtime impacting revenue, rather than irrelevant metrics.

Exam trap

The trap here is that candidates often prioritize ease of automation or industry benchmarks over strategic alignment, forgetting that KRIs must be tailored to the organization's specific risk profile and business objectives to be effective.

How to eliminate wrong answers

Option A is wrong because historical loss data may not exist for a new cloud application, and KRIs should be forward-looking indicators of risk exposure, not backward-looking loss metrics. Option B is wrong because ease of automated data collection is a practical consideration but not the primary factor; a KRI that is easy to collect but irrelevant to strategic risk is useless. Option C is wrong because industry best practices provide generic guidance but may not reflect the organization's unique risk appetite, cloud architecture, or strategic priorities, leading to misaligned monitoring.

564
Multi-Selectmedium

An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?

Select 2 answers
A.Model bias causing discriminatory outcomes
B.Model explainability for regulatory compliance
C.Data privacy in AI training
D.High computational cost of model retraining
E.Adversarial attacks on the training data
AnswersA, B

Discriminatory outcomes breach fair-lending legislation and expose the organisation to enforcement action and litigation. Bias arises from unrepresentative training data or proxy variables, so testing for disparate impact across protected groups is a governance control that directly addresses the stem's regulatory oversight constraint.

Why this answer

Option A (Model bias causing discriminatory outcomes) is correct because credit approval is a legally regulated decision domain where biased models can produce discriminatory lending practices, violating fair-lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act, exposing the organization to enforcement actions and reputational harm. Option B (Model explainability for regulatory compliance) is correct because regulators in credit decisions require the ability to understand and justify adverse action reasons, typically under regulations like the Equal Credit Opportunity Act (ECOA) and the Fair Credit Reporting Act (FCRA), making explainability essential for compliance and auditability. Options C, D, and E, while relevant to AI/ML generally, are not the most significant risk considerations in this specific regulated credit-approval scenario: data privacy (C) matters but is secondary to fairness and explainability in lending regulation, high computational cost (D) is an operational efficiency concern rather than a regulatory risk, and adversarial attacks on training data (E) are a security concern that is less directly tied to the regulatory oversight governing credit decisions.

Exam trap

CRISC often tests whether candidates can distinguish the most significant regulatory risks from general operational or security risks, so the trap is selecting data privacy or compute cost when the question is specifically about a regulated credit decision where bias and explainability are the legally material concerns.

565
MCQeasy

A risk practitioner is reviewing the organization's risk response plan for a database containing personally identifiable information (PII). The plan states that the database will be encrypted at rest, access will be restricted to authorized personnel, and regular backups will be performed. Which risk response strategy is being applied?

A.Risk mitigation
B.Risk transfer
C.Risk avoidance
D.Risk acceptance
AnswerA

The plan includes encryption, access restrictions, and backups, all of which are controls designed to reduce the likelihood and impact of a data breach. These actions are characteristic of risk mitigation, where the organization takes steps to lower risk to an acceptable level while continuing the business activity. The strategy is clearly mitigation.

Why this answer

Implementing encryption, access controls, and backups are all mitigation actions that reduce the likelihood or impact of a breach. The organization is actively managing the risk rather than avoiding, transferring, or accepting it. Therefore, the risk response strategy is mitigation.

Exam trap

The trap here is overthinking and selecting risk transfer because backups might seem like insurance, but they are actually a mitigation control.

566
MCQmedium

An organization is evaluating a new security control that costs $50,000 annually to implement and maintain. The current annualized loss expectancy (ALE) for a related risk is $200,000. The control is expected to reduce the ALE by 85%. Using cost-benefit analysis, what is the net benefit of implementing this control?

A.$120,000
B.$30,000
C.$170,000
D.$150,000
AnswerA

The control reduces the $200,000 ALE by 85%, giving a mitigated ALE of $30,000 and an $170,000 loss reduction. Subtracting the $50,000 annual cost yields a net benefit of $120,000, satisfying the cost-benefit comparison the stem requires.

Why this answer

The reduction in ALE is 85% of $200,000 = $170,000. The annual control cost is $50,000. Net benefit = $170,000 - $50,000 = $120,000.

567
MCQhard

A multinational manufacturer has completed a quantitative risk analysis for a ransomware scenario affecting its primary ERP system. The analysis shows an annualized loss expectancy (ALE) of $2.4 million. A proposed endpoint detection and response (EDR) solution would cost $600,000 annually and is projected to reduce the ALE by 60%. The CFO asks the risk practitioner to justify the investment. Which of the following is the BEST response?

A.The EDR solution should be approved because any control that reduces risk by more than half automatically satisfies the cost-benefit test.
B.The EDR solution delivers a net risk reduction benefit of $840,000 annually, so it should be approved.
C.The EDR solution costs 25% of the ALE, which is within the accepted industry benchmark for control spending.
D.The EDR solution should be rejected because the residual ALE of $960,000 remains above the organization's risk appetite.
AnswerB

A 60% reduction of the $2.4 million ALE equals $1.44 million in avoided loss. Subtracting the $600,000 annual cost yields a net benefit of $840,000, which is positive and therefore economically justified. This quantitative comparison directly answers the CFO's request for justification and supports approval.

Why this answer

The control reduces the $2.4 million ALE by 60%, avoiding $1.44 million in expected annual loss, and costs $600,000 per year. The net benefit of $840,000 is positive, so the investment is economically justified. The other responses either invoke unsupported benchmarks, assume an unstated appetite threshold, or rely on the percentage reduction without considering cost.

Exam trap

The trap here is treating a large percentage risk reduction as sufficient justification without subtracting the control's annual cost from the avoided loss.

568
MCQeasy

An organization's risk register shows that a critical database containing customer records has a high inherent risk rating. Management installs database activity monitoring, enforces encryption at rest, and implements quarterly access reviews. After these actions, the risk is re-rated as medium. Which risk concept does the re-rated medium value BEST represent?

A.Risk appetite
B.Control risk
C.Residual risk
D.Inherent risk
AnswerC

Residual risk is what remains after controls are designed and operating. Installing database activity monitoring, encryption at rest, and quarterly access reviews reduced the likelihood and impact of the identified threat, so the re-rated medium value reflects the remaining exposure. CRISC practitioners use residual risk, not inherent risk, to judge whether the response brings the risk within the organization's stated tolerance.

Why this answer

Residual risk is the exposure that remains after controls are applied, and it is the figure decision makers should compare against tolerance. The database started with a high inherent rating; monitoring, encryption, and periodic access reviews lowered the likelihood and impact, producing a medium residual rating. Reporting residual risk keeps the risk register meaningful and prevents the organization from funding controls for exposure that has already been mitigated.

Exam trap

The trap here is reading a post-control rating as inherent risk or as a statement of risk appetite rather than as residual risk.

569
MCQmedium

A logistics firm relies on a third-party cloud provider to host its shipment tracking system. The provider's latest SOC 2 report includes a qualified opinion noting that access review controls were not operating effectively during part of the audit period. The firm's risk practitioner must determine the appropriate risk response. Which of the following is the MOST appropriate action?

A.Terminate the contract immediately and migrate the shipment tracking system to a different provider.
B.Assess the impact of the access review exception on the firm's data and implement compensating controls while the provider remediates.
C.Request the provider's remediation plan and take no further action until the next annual SOC 2 report is issued.
D.Accept the risk because the provider holds a SOC 2 report, which demonstrates an adequate control environment.
AnswerB

The qualified opinion signals a specific control weakness, so the practitioner should evaluate how that weakness affects the logistics firm's data and systems. Implementing compensating controls, such as additional monitoring or restricting privileged access, reduces exposure while the provider addresses the root cause. This response is proportionate, risk-based, and maintains service continuity while holding the provider accountable.

Why this answer

A qualified SOC 2 opinion identifies a real control failure at the provider, so the firm cannot simply accept the risk or wait a year for the next report. The practitioner should assess how the access review weakness affects the shipment tracking data and deploy compensating controls during remediation. This protects the firm while preserving the vendor relationship and allows for a proportionate, evidence-based response.

Exam trap

The trap here is treating the existence of a SOC 2 report as assurance of effective controls, when a qualified opinion specifically documents a control failure that requires its own risk response.

570
MCQhard

You are the IT risk manager for a mid-sized e-commerce company. The company processes credit card payments and stores customer data. Recently, the company experienced a security incident where an attacker exploited a SQL injection vulnerability in the web application, exfiltrating a database of customer records. The vulnerability was introduced three months ago during a feature upgrade. The development team claims they followed secure coding guidelines, but the vulnerability was missed due to insufficient testing. The company's risk appetite is moderate, and they have a risk management policy that requires risks to be treated within 30 days of identification. The CISO wants to know the most effective way to reduce the likelihood of similar incidents. You have assessed that the current risk score for web application vulnerabilities is 16 (High). The company has a bug bounty program, but it has not been effective. Which of the following courses of action would BEST address the root cause and reduce the risk?

A.Increase the frequency of vulnerability scanning and patch management.
B.Deploy a web application firewall (WAF) to block SQL injection attempts.
C.Increase the reward amounts in the bug bounty program to attract more researchers.
D.Implement a secure software development lifecycle (SSDLC) with mandatory security training, code reviews, and automated security testing.
AnswerD

An SSDLC embeds security training, mandatory code reviews and automated security testing into development, catching flaws like SQL injection before release. This treats the root cause of the missed vulnerability, reducing likelihood within the 30-day policy.

Why this answer

The root cause of the incident is a failure in the development process: secure coding guidelines were followed but insufficient testing allowed a SQL injection vulnerability to be introduced. Implementing a Secure Software Development Lifecycle (SSDLC) with mandatory security training, code reviews, and automated security testing directly addresses this root cause by embedding security controls into every phase of development, preventing vulnerabilities from being introduced in the first place. This is the most effective way to reduce the likelihood of similar incidents, as it proactively fixes the process rather than relying on reactive measures.

Exam trap

The trap here is that candidates often choose a compensating control (like a WAF or vulnerability scanning) because it seems faster or more familiar, but the question asks for the BEST way to reduce likelihood by addressing the root cause, which requires a preventive, process-level change like SSDLC.

How to eliminate wrong answers

Option A is wrong because increasing vulnerability scanning and patch management is a reactive measure that detects vulnerabilities after deployment, not preventing them from being introduced during development; it does not address the root cause of insufficient testing in the SDLC. Option B is wrong because deploying a WAF is a compensating control that can block some SQL injection attempts, but it does not fix the underlying insecure coding practices and can be bypassed by sophisticated attackers or misconfigurations; it reduces impact but not likelihood. Option C is wrong because increasing bug bounty rewards may attract more researchers, but the program has already been ineffective, and relying on external researchers to find vulnerabilities after release is reactive and does not prevent the introduction of vulnerabilities during development.

571
MCQhard

A multinational corporation is migrating critical applications to a public cloud provider. The IT risk manager needs to design a risk assessment approach that addresses shared responsibility. Which of the following is the MOST appropriate approach?

A.Assess only the cloud provider's security controls
B.Assume that the provider's controls cover all risks
C.Perform a data leakage risk assessment for each application
D.Map controls to the shared responsibility model and assess both sides
AnswerD

The shared responsibility model splits security duties between provider and customer, so assessing only one side leaves gaps. Mapping controls to each party's obligations and evaluating both ensures coverage of the actual division of accountability in the public cloud.

Why this answer

In a public cloud shared responsibility model, the cloud provider secures the infrastructure (e.g., physical security, hypervisor), while the customer secures their data, configurations, and access controls. Option D is correct because it requires mapping each control to the specific party responsible (customer vs. provider) and assessing both sides, ensuring no gaps in coverage. This approach aligns with the CSA Cloud Controls Matrix and NIST SP 800-146, which mandate joint accountability.

Exam trap

The trap here is that candidates assume the cloud provider is fully responsible for all security, overlooking the customer's contractual and operational obligations under the shared responsibility model, which is a core CRISC concept for cloud risk assessments.

How to eliminate wrong answers

Option A is wrong because assessing only the provider's controls ignores customer-side responsibilities like IAM policies, encryption key management, and application-layer security, leading to unmitigated risks. Option B is wrong because assuming the provider covers all risks violates the shared responsibility model; the provider explicitly disclaims responsibility for customer data and configurations in their SLA (e.g., AWS Shared Responsibility Model). Option C is wrong because a data leakage risk assessment is too narrow; it omits other critical risks such as misconfigured network ACLs, insecure APIs, and compliance violations (e.g., GDPR data residency).

572
MCQeasy

A risk practitioner is reviewing the organization's risk register and notices that a risk related to outdated encryption protocols on a file server has been assigned an owner. According to CRISC principles, what is the PRIMARY responsibility of the risk owner?

A.To implement the technical controls necessary to mitigate the risk to an acceptable level.
B.To ensure that the risk is managed appropriately and that decisions regarding its treatment are made and documented.
C.To perform periodic vulnerability scans and penetration tests to identify changes in the risk profile.
D.To approve the organization's overall risk appetite statement and communicate it to the board of directors.
AnswerB

The risk owner is accountable for the overall management of a specific risk, including making decisions about risk treatment, ensuring controls are in place, and monitoring the risk over time. In this scenario, the risk owner for the outdated encryption risk must decide whether to accept, mitigate, transfer, or avoid the risk and ensure that decision is documented. This aligns with CRISC's emphasis on clear ownership and accountability.

Why this answer

In CRISC, a risk owner is the individual accountable for managing a specific risk. Their primary responsibility is to ensure the risk is managed appropriately, which includes making and documenting decisions about risk treatment (accept, mitigate, transfer, avoid). They do not necessarily implement controls themselves, nor do they perform technical assessments or set organizational risk appetite.

The risk owner ensures that the risk remains within tolerance and that actions are taken to address it.

Exam trap

The trap here is equating the risk owner with the person who implements controls, when actually the risk owner is accountable for decisions and oversight.

573
Multi-Selecteasy

Which TWO outcomes indicate that a risk assessment process is effective?

Select 2 answers
A.All potential risks have been identified.
B.Risk treatment decisions are based on clear, prioritized findings.
C.Residual risk is consistently below the risk appetite.
D.No negative risk events occur after the assessment.
E.The organization achieves full compliance with security standards.
AnswersB, C

Basing risk treatment decisions on clear, prioritised findings demonstrates that assessment outputs actually drive remediation choices, linking identified risk to action. This outcome confirms the process produces usable, ranked information rather than documentation alone, satisfying the stem's effectiveness criterion.

Why this answer

Option B is correct because an effective risk assessment must produce clear, prioritized findings that directly drive risk treatment decisions — prioritization based on likelihood and impact is the core purpose of the process, and if decisions are not traceable to those findings, the assessment is not functioning. Option C is correct because consistently keeping residual risk (the risk remaining after treatment) below the organization's defined risk appetite demonstrates that the assessment and subsequent treatment are actually reducing risk to a tolerable level, which is the measurable goal of risk management. Option A is not correct because identifying 'all' potential risks is neither realistic nor required; risk assessment is iterative and aims to identify relevant, material risks, not achieve completeness.

Option D is not correct because the absence of negative events may reflect luck or effective controls rather than a sound assessment process, and zero incidents is not a valid effectiveness metric. Option E is not correct because compliance with standards is a separate objective from risk assessment effectiveness; an organization can be compliant yet still have poorly prioritized or unmanaged risks.

Exam trap

The trap here is that candidates confuse the goal of risk assessment (producing prioritized, decision-ready findings) with other risk management activities like risk identification (A), risk monitoring (D), or compliance (E), leading them to select options that sound desirable but do not directly measure assessment effectiveness.

574
MCQmedium

An enterprise risk analyst is aggregating risk data from three business units that each used a different likelihood scale: Unit A used a 1-3 scale, Unit B used a 1-5 scale, and Unit C used a 1-10 scale. Before consolidating results into the enterprise risk register, which action BEST ensures the aggregated risk ratings remain meaningful for management reporting?

A.Multiply each unit's likelihood score by its asset count to weight the ratings before consolidation.
B.Recalculate each unit's ratings into a single common likelihood scale and document the normalization criteria used.
C.Discard the two units using narrower scales and report only the unit using the 1-10 scale.
D.Average the raw numeric scores from all three units and report the mean as the enterprise likelihood value.
AnswerB

Normalizing all unit ratings onto one defined scale is the prerequisite for valid aggregation, because ratings expressed on incompatible scales cannot be compared or summed meaningfully. Documenting the conversion criteria preserves traceability and lets reviewers challenge the mapping. This directly addresses the scenario's core problem of three different likelihood scales feeding one enterprise register.

Why this answer

Aggregating risk across business units requires a common measurement basis; otherwise, comparisons and totals are artifacts of differing scales. Mapping each unit's likelihood onto one defined enterprise scale, with documented conversion criteria, produces ratings that are comparable, auditable, and defensible to management and auditors. Averaging or weighting raw incompatible scores does not fix the underlying scale mismatch.

Exam trap

The trap here is assuming that numeric risk scores from different scales can be averaged or summed directly just because they are all numbers.

575
MCQmedium

Which control type is primarily focused on identifying that a risk event has occurred?

A.Compensating
B.Preventive
C.Detective
D.Corrective
AnswerC

Detective controls are designed to discover and flag that a risk event has already happened, through logs, alerts, or monitoring. Unlike preventive controls, which block events before they occur, detective controls satisfy the stem's requirement of identifying that a risk event has taken place.

Why this answer

Detective controls are designed to detect incidents after they happen.

576
MCQhard

A multinational corporation has deployed a centralized log management system that collects security events from all subsidiaries. The CRO notices that the number of critical alerts from the Asia-Pacific region has dropped significantly over the past week. Upon investigation, the log source status shows that 30% of the devices in that region have not sent any logs in 48 hours. What is the MOST likely cause?

A.The security team applied a new log suppression rule that filters out low-severity events.
B.The region experienced a distributed denial-of-service (DDoS) attack that overwhelmed the log collection infrastructure.
C.A configuration change was made to the log forwarder agent on the affected devices, causing it to stop sending logs.
D.The network team recently implemented a segmentation change that blocked log traffic from those devices.
AnswerC

Misconfigured log forwarders are a common cause of log loss.

Why this answer

A configuration change to the log forwarder agent (e.g., syslog-ng, rsyslog, or a proprietary agent) is the most plausible cause for a sudden, sustained drop in log volume from a subset of devices. Unlike network segmentation (Option D), which would affect all traffic, or a DDoS (Option B), which would cause intermittent or total loss, an agent misconfiguration selectively stops log generation while the device remains online. The 48-hour window and 30% device impact align with a staged or partial rollout of a faulty agent configuration.

Exam trap

The trap here is that candidates confuse a reduction in alerts (Option A) with a loss of raw logs, or assume a network change (Option D) is the root cause without considering that a configuration change to the log forwarder agent is a more targeted and common failure mode in centralized logging architectures.

How to eliminate wrong answers

Option A is wrong because a new log suppression rule filtering low-severity events would reduce alert volume but not stop log transmission entirely; the log source status would still show recent heartbeats or connectivity. Option B is wrong because a DDoS attack overwhelming the log collection infrastructure would cause a widespread, not regional, loss of logs, and the log source status would likely show intermittent connectivity or timeouts, not a clean 48-hour gap. Option D is wrong because a network segmentation change blocking log traffic (e.g., UDP 514 or TCP 6514) would affect all devices in the affected subnet, not a specific 30% subset, and would typically be detected by network monitoring tools.

577
Multi-Selectmedium

Which TWO of the following are valid triggers for initiating a risk assessment outside the regular cycle? (Select 2)

Select 2 answers
A.An employee completing annual security awareness training
B.A significant change in the IT infrastructure
C.Introduction of a new regulatory requirement
D.The annual internal audit of financial controls
E.Completion of a routine security patch cycle
AnswersB, C

Changes introduce new risks and require reassessment.

Why this answer

A significant change in IT infrastructure (Option B) is a classic trigger for ad-hoc risk assessment because it introduces new vulnerabilities, alters the attack surface, or changes the effectiveness of existing controls. For example, migrating from on-premises servers to a cloud environment (e.g., AWS, Azure) changes network segmentation, identity management, and data residency, requiring a fresh risk evaluation to identify and treat new threats before they are exploited.

Exam trap

ISACA often tests the distinction between routine, scheduled activities (like training, audits, or patching) and genuine change events that alter the risk profile, tricking candidates into selecting familiar operational tasks as triggers.

578
MCQmedium

During a risk assessment, the risk practitioner discovers that a critical database does not have an active failover solution. The database is used by multiple business applications. Which of the following factors should be given the HIGHEST weight when determining the inherent risk level?

A.The criticality of the database to business operations
B.The number of existing compensating controls
C.The frequency of vulnerability scans
D.The cost to restore the database from backup
AnswerA

Inherent risk reflects impact and likelihood before controls. A database supporting multiple business applications has high business criticality, so its failure causes widespread operational disruption, making this the dominant factor when rating inherent risk, ahead of technical failover gaps.

Why this answer

The inherent risk level is determined by the potential impact and likelihood of a threat exploiting a vulnerability, without considering controls. The criticality of the database to business operations directly drives the impact severity—if the database fails, multiple business applications could be disrupted, leading to significant operational and financial damage. This makes option A the highest-weighted factor because it defines the worst-case consequence, which is the foundation of inherent risk.

Exam trap

The trap here is that candidates confuse inherent risk with residual risk, and incorrectly weigh compensating controls or recovery costs as primary factors for inherent risk, when they only apply after controls are considered.

How to eliminate wrong answers

Option B is wrong because compensating controls are considered when assessing residual risk, not inherent risk; inherent risk assumes no controls are in place. Option C is wrong because the frequency of vulnerability scans is a control activity that reduces risk, not a factor that increases or defines inherent risk. Option D is wrong because the cost to restore from backup is a recovery metric (RTO/RPO) that influences residual risk or risk treatment decisions, not the inherent risk level, which focuses on the raw exposure before any mitigation.

579
Multi-Selectmedium

A risk practitioner is evaluating the organization's identity and access management (IAM) controls as part of an IT risk assessment. The organization has a hybrid environment with on-premises Active Directory and a cloud identity provider. Which TWO of the following are the MOST significant risks that should be prioritized? (Choose two.)

Select 2 answers
A.The organization uses single sign-on (SSO) for cloud applications, which may create a single point of failure.
B.Inconsistent identity synchronization between the on-premises directory and the cloud identity provider, leading to stale or orphaned accounts.
C.Excessive standing privileges assigned to service accounts that are not regularly reviewed.
D.Users are required to change passwords every 90 days without a history check.
E.Some legacy applications do not support multi-factor authentication (MFA).
AnswersB, C

When synchronization fails or is misconfigured, accounts disabled on-premises may remain active in the cloud, and terminated users may retain access. This creates unauthorized access paths to cloud resources. In a hybrid model, synchronization integrity is foundational to access control, making this a high-priority risk that can undermine the entire IAM control set.

Why this answer

In hybrid IAM, the greatest risks arise from controls that grant or preserve broad access without adequate oversight. Excessive standing privileges on service accounts enable attackers to move laterally and persist, while synchronization failures can leave active cloud credentials for users who should no longer have access. Both directly undermine the principle of least privilege and are often missed because they sit between on-premises and cloud governance processes.

Exam trap

The trap here is treating common password policy weaknesses or SSO availability as top risks, while missing that service-account privilege sprawl and synchronization integrity are the systemic issues that enable unauthorized access.

580
Multi-Selecteasy

An organization wants to promote a risk-aware culture. Which TWO of the following initiatives are most effective for achieving this?

Select 2 answers
A.Conducting regular security awareness training for all employees
B.Establishing a 'tone from the top' that emphasizes risk management
C.Implementing a blame-free incident reporting system
D.Offering financial incentives for risk identification
E.Increasing the IT risk team budget
AnswersA, B

Regular security awareness training reaches all employees, embedding risk recognition into daily decisions and behaviours. This directly builds the shared understanding and accountability a risk-aware culture requires, satisfying the initiative's aim of shifting attitudes organisation-wide rather than relying on isolated controls.

Why this answer

Option A is correct because regular security awareness training for all employees builds the knowledge and vigilance needed for staff to recognize and respond to risks, which is the foundation of a risk-aware culture. Option B is correct because a 'tone from the top' that emphasizes risk management signals leadership commitment, sets expectations, and drives risk-conscious behavior throughout the organization. Option C, while valuable for encouraging reporting, addresses incident handling rather than directly cultivating organization-wide risk awareness.

Option D can motivate specific behavior but risks incentivizing quantity over quality and does not by itself build a sustainable culture. Option E, increasing the IT risk team budget, strengthens resources but does not directly engage employees or shape organizational attitudes toward risk.

Exam trap

The trap here is that candidates often mistake a blame-free reporting system or financial incentives as cultural drivers, but the CRISC exam emphasizes that culture is shaped by leadership example and continuous education, not by reactive or transactional mechanisms.

581
MCQmedium

A financial services firm has a critical web application that must remain available 24/7. The risk assessment indicates that a distributed denial-of-service (DDoS) attack could cause significant downtime. The risk owner decides to implement a cloud-based DDoS mitigation service that scrubs traffic before it reaches the application. Which risk response strategy does this represent?

A.Risk avoidance
B.Risk acceptance
C.Risk transference
D.Risk mitigation
AnswerD

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. By deploying a cloud-based DDoS mitigation service, the firm adds a control that scrubs malicious traffic, thereby reducing the chance of downtime and lessening the impact of an attack. This aligns with the definition of risk mitigation, as the risk is still present but its effect is diminished.

Why this answer

Implementing a DDoS mitigation service is a classic example of risk mitigation because it reduces the likelihood or impact of a threat. The risk is not avoided (the service continues), not transferred (the firm retains responsibility), and not accepted (action is taken). Mitigation controls are designed to bring residual risk within the organization's risk appetite.

Exam trap

The trap here is confusing the use of a third-party service with risk transference, when in fact the service is a mitigation control that reduces risk.

582
MCQeasy

Which of the following threat actors is MOST likely to be motivated by ideology rather than financial gain?

A.Organized crime
B.Nation-state APT
C.Script kiddie
D.Hacktivist
AnswerD

Hacktivists act primarily to advance political, social, or ideological causes, using attacks such as defacement and data leaks for publicity rather than profit. Unlike organised crime or insiders, their motivation is ideological, making them the threat actor most likely driven by ideology instead of financial gain.

Why this answer

Hacktivists are defined by their ideological, political, or social motivations, using cyberattacks to promote a cause, protest, or draw attention to perceived injustices. Their primary goal is message amplification or disruption, not monetary profit. This distinguishes them from financially driven actors such as organized crime.

Exam trap

The trap is conflating 'ideology' with 'political state interest'; nation-state APTs are politically motivated but serve state interests, whereas hacktivists are the classic ideology-driven actor, so candidates must distinguish grassroots ideological motive from state-sponsored geopolitical motive.

How to eliminate wrong answers

Option A is wrong because organized crime is primarily motivated by financial gain through fraud, ransomware, and data theft for resale. Option B is wrong because nation-state APTs are motivated by geopolitical, espionage, or strategic objectives (intelligence collection, disruption of adversaries), which is state interest rather than grassroots ideology. Option C is wrong because script kiddies are typically motivated by curiosity, notoriety, or thrill-seeking, often using ready-made tools without a coherent ideological agenda.

583
MCQmedium

A quantitative risk analysis for a data breach yields an Annualized Loss Expectancy (ALE) of $500,000. The Single Loss Expectancy (SLE) is $100,000. What is the Annualized Rate of Occurrence (ARO)?

A.5
B.50
C.0.2
D.500,000
AnswerA

ARO is derived by dividing ALE by SLE: $500,000 ÷ $100,000 = 5, meaning the loss event is expected five times annually. This satisfies the quantitative relationship ALE = SLE × ARO, so an ARO of 5 reconciles the given figures.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as Single Loss Expectancy (SLE) multiplied by the Annualized Rate of Occurrence (ARO). Given ALE = $500,000 and SLE = $100,000, the ARO is $500,000 / $100,000 = 5. This means the data breach is expected to occur 5 times per year.

Exam trap

The trap here is that candidates often confuse the formula and incorrectly divide SLE by ALE (yielding 0.2) instead of dividing ALE by SLE, or they misplace decimal points when calculating the rate.

How to eliminate wrong answers

Option B (50) is wrong because it would result from incorrectly multiplying SLE by 10 or misplacing a decimal, not from the correct division of ALE by SLE. Option C (0.2) is wrong because it represents the inverse calculation (SLE divided by ALE), which would imply the breach occurs once every 5 years, not 5 times per year. Option D (500,000) is wrong because it simply repeats the ALE value, ignoring the need to divide by SLE to derive the ARO.

584
Multi-Selectmedium

A risk practitioner is identifying risks associated with a new cloud-based customer relationship management (CRM) system. The organization has concerns about data leakage and service availability. Which TWO of the following are examples of vulnerabilities that could lead to these risks? (Choose two.)

Select 2 answers
A.The CRM system lacks encryption for data at rest.
B.A hacktivist group has announced intentions to target cloud providers.
C.The cloud provider's data center is located in a region prone to hurricanes.
D.The organization's risk appetite statement allows for moderate downtime.
E.The cloud provider's service level agreement (SLA) does not include penalties for data breaches.
AnswersA, C

Lack of encryption for data at rest is a technical vulnerability that could lead to data leakage if the storage is compromised. It is a weakness in the system's design or configuration. This directly relates to the risk of unauthorized disclosure of customer data. Therefore, it is a valid vulnerability that the risk practitioner should identify.

Why this answer

Vulnerabilities are weaknesses that can be exploited by threats. The lack of encryption for data at rest is a technical vulnerability that could lead to data leakage. The data center's location in a hurricane-prone region is an environmental vulnerability that could lead to service unavailability.

The other options are threats, governance statements, or contractual issues, not vulnerabilities.

Exam trap

The trap here is confusing threats with vulnerabilities, such as treating a hacktivist group's intentions as a vulnerability, or treating a contractual gap as a technical weakness.

585
MCQhard

A company uses cyber insurance to cover losses from data breaches. This is an example of which risk treatment?

A.Avoid
B.Transfer
C.Mitigate
D.Accept
AnswerB

Cyber insurance shifts the financial impact of breach losses to an insurer, which is risk transfer. The organisation retains the risk itself but compensates losses externally, satisfying the definition of transfer as a risk treatment.

Why this answer

Transfer shifts risk to a third party, such as an insurance company.

586
MCQeasy

An e-commerce company discovers that a third-party payment processor suffered a breach exposing customer card data. The processor contract includes a clause requiring the vendor to indemnify the company for breach-related costs. The risk owner updates the register to show that financial loss from this vendor risk is now borne by the processor. Which risk response strategy has been applied?

A.Risk acceptance
B.Risk transfer
C.Risk avoidance
D.Risk mitigation
AnswerB

The indemnification clause shifts the financial consequence of a breach from the e-commerce company to the payment processor, which is the defining characteristic of risk transfer. The underlying risk of a breach still exists and the company still faces reputational harm, but the monetary loss is contractually assigned to another party. Recording this as transfer correctly reflects the response strategy in the register.

Why this answer

An indemnification clause that makes the payment processor bear breach-related costs shifts the financial consequence of the risk to a third party, which is risk transfer. The breach risk itself and reputational exposure remain with the company, but the monetary loss is contractually reassigned. Mitigation, avoidance, and acceptance do not describe a contractual shifting of financial responsibility, so transfer is the correct classification.

Exam trap

The trap here is confusing contractual risk transfer with mitigation, because both involve doing something about the risk; transfer shifts financial consequence while mitigation reduces likelihood or impact.

587
MCQmedium

A financial services firm has identified that its primary data center is located in a region prone to hurricanes. The risk manager proposes purchasing business interruption insurance to cover potential losses from a catastrophic event. Which risk response strategy does this represent?

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerC

Risk transfer shifts the financial consequences of a risk to a third party, typically through insurance or outsourcing. By purchasing business interruption insurance, the firm transfers the financial loss from a hurricane to the insurer. The risk itself remains, but the financial impact is borne by another party, making this the correct classification.

Why this answer

Purchasing insurance is a classic example of risk transfer, where the financial impact of a risk is shifted to an insurance provider. The risk event (hurricane) still occurs, but the firm is compensated for losses, protecting its financial stability. This strategy is appropriate when the risk is high-impact but low-frequency, and the cost of insurance is justified.

Exam trap

The trap here is confusing risk transfer with risk mitigation, assuming that buying insurance reduces the risk itself rather than just its financial consequences.

588
MCQhard

A software company has a risk appetite statement allowing no more than two hours of downtime per quarter for its customer-facing API. During a quarterly review, the risk practitioner discovers that a single unplanned database failover event caused 90 minutes of downtime, and a separate configuration error caused 45 minutes. Both events were resolved, but no root cause analysis was completed for either. Which of the following should the risk practitioner recommend FIRST?

A.Report to the board that the downtime appetite has been breached and await direction on a response.
B.Initiate a root cause analysis for both incidents to determine whether the downtime events share an underlying control weakness.
C.Revise the risk appetite statement to allow three hours of quarterly downtime, reflecting actual operational reality.
D.Recommend immediate investment in a redundant database cluster to prevent future failover downtime.
AnswerB

The organization has already exceeded its stated downtime appetite, and the absence of root cause analysis means the underlying causes remain unknown. Before changing controls or reporting to the board, the practitioner needs to understand whether the two events stem from a common weakness. Root cause analysis provides that evidence and is the logical first step in determining an appropriate risk response.

Why this answer

The downtime exceeded the stated appetite, and the lack of root cause analysis leaves the reason for the breach unknown. The practitioner's first step should be to investigate both incidents and determine whether a shared control weakness exists. Only with that understanding can a proportionate response be selected, reported accurately, or escalated to governance with meaningful options rather than an unexplained breach.

Exam trap

The trap here is jumping to a technical fix or an appetite revision before establishing why the downtime occurred and whether the incidents share a root cause.

589
MCQhard

A risk manager is reviewing the organization's risk treatment plan for a critical web application. The plan includes implementing a web application firewall (WAF), conducting regular penetration tests, and purchasing cyber insurance. The risk manager notes that the residual risk after these treatments is still above the risk appetite. According to CRISC, what should the risk manager do NEXT?

A.Reassess the risk to ensure the risk assessment is accurate and adjust the risk score accordingly.
B.Update the risk register to reflect the residual risk and continue monitoring.
C.Implement additional controls immediately to reduce the residual risk to an acceptable level.
D.Escalate the residual risk to senior management for a decision on whether to accept, further treat, or avoid the risk.
AnswerD

When residual risk exceeds the risk appetite, it is outside the organization's tolerance. The risk manager should escalate to senior management, who have the authority to decide on further risk response, such as accepting the risk, implementing additional controls, or discontinuing the activity. This aligns with CRISC's emphasis on risk governance and ensuring risk is managed within appetite.

Why this answer

When residual risk exceeds the organization's risk appetite, it must be escalated to senior management, who are responsible for making risk-based decisions. They may choose to accept the risk, allocate resources for further mitigation, or avoid the activity. The risk manager's role is to inform and recommend, not to unilaterally decide or simply monitor.

Exam trap

The trap here is assuming the risk manager should automatically implement more controls, but without management's risk tolerance decision, that could be inappropriate or wasteful.

590
Multi-Selecthard

Which TWO risk identification techniques are most appropriate for identifying emerging risks from new technologies?

Select 2 answers
A.Scenario analysis
B.Historical incident review
C.Delphi technique
D.Peer benchmarking
E.Threat intelligence feeds
AnswersA, E

Scenario analysis explores plausible future states arising from new technologies, exposing risks with no historical data. It directly addresses emerging risks by reasoning about uncertainty rather than extrapolating past incidents, which is the constraint the question imposes.

Why this answer

Scenario analysis (A) is correct because it lets risk teams model plausible future states and 'what-if' situations around new technologies that have little or no historical data, exposing emerging risks such as novel attack paths or unintended AI behavior. Threat intelligence feeds (E) are correct because they continuously deliver current indicators, vulnerability disclosures, and adversary TTPs (e.g., CVEs, IOCs, MITRE ATT&CK techniques) about newly exploited technologies, which is exactly how emerging risks surface before they appear in your own incident history. Historical incident review (B) is not appropriate here because it only reflects risks already experienced, so it cannot reveal risks from technologies with no prior incidents.

The Delphi technique (C) and peer benchmarking (D) can inform risk assessment through expert consensus or comparison with other organizations, but they are slower, opinion- or peer-dependent, and not specifically designed to detect fast-moving emerging technology risks.

Exam trap

The trap here is that candidates often choose historical incident review or peer benchmarking because they seem data-driven, but they fail to recognize that emerging technologies lack the historical data or peer maturity needed for these methods to be effective.

591
Multi-Selecthard

A risk practitioner is performing a risk assessment on an organization's use of a cloud-based payroll platform. The practitioner is identifying the inherent risk factors that exist before any controls are considered. Which TWO of the following are inherent risk factors for this scenario? (Choose two.)

Select 2 answers
A.Payroll processing depends on a single third-party provider with no in-house fallback process.
B.The vendor performs quarterly penetration testing of its external infrastructure.
C.The vendor's most recent SOC 2 Type II report shows no exceptions in its change management controls.
D.The payroll platform stores direct deposit banking details and national identification numbers for all employees.
E.The organization enforces multifactor authentication for all administrator access to the payroll platform.
AnswersA, D

Concentration and lack of redundancy are inherent characteristics of the operating model, not controls. If the provider suffers an outage or fails, payroll cannot run and employees go unpaid, which is a business impact that exists independent of any protective measure. This dependency is therefore an inherent risk factor that must be captured before evaluating the vendor's resiliency controls or the organization's contingency arrangements.

Why this answer

Inherent risk factors describe the exposure that exists by virtue of the assets, data, and dependencies involved, before any protective measures are applied. Sensitive employee data and dependence on a single provider without fallback both raise potential impact and likelihood regardless of controls. Audit reports, multifactor authentication, and penetration testing are control evidence that belongs in the residual risk analysis, not the inherent assessment.

Exam trap

The trap here is counting strong existing controls as inherent risk factors, which reverses the order of inherent and residual risk assessment.

592
MCQeasy

A risk manager is documenting the results of an IT risk assessment. She has identified the risk, analyzed its likelihood and impact, and evaluated existing controls. Which of the following should she do NEXT?

A.Report the inherent risk to the board of directors for acceptance.
B.Conduct a new threat modeling exercise to identify additional threats.
C.Determine the residual risk and compare it to the risk appetite.
D.Implement additional controls to reduce the risk to zero.
AnswerC

After analyzing inherent risk and evaluating controls, the next step is to determine residual risk, which is the risk remaining after controls. Comparing residual risk to the organization's risk appetite informs whether additional treatment is needed. This step is essential for making risk-based decisions and for communicating the risk position to stakeholders.

Why this answer

The risk assessment process moves from identification to analysis to evaluation. After evaluating controls, the risk manager must calculate residual risk and compare it to risk appetite. This comparison determines whether the risk is acceptable or requires further treatment.

It is the basis for risk response decisions and communication to governance bodies.

Exam trap

The trap here is jumping to control implementation or reporting inherent risk without first determining residual risk, which is the output needed for risk-based decisions.

593
MCQmedium

After a security incident, an organization discovers that a critical database was accessed by an unauthorized user due to weak authentication controls. As part of the IT risk assessment process, which step should have identified this vulnerability?

A.Risk treatment
B.Risk monitoring
C.Risk identification
D.Risk evaluation
AnswerC

Risk identification systematically uncovers threats, vulnerabilities and existing controls before incidents occur, so weak authentication on the critical database would have been surfaced here. It satisfies the stem's requirement to determine which assessment step should have detected the vulnerability, preceding risk analysis and evaluation, which merely assess likelihood and impact of already-identified risks.

Why this answer

Risk identification is the step in the IT risk assessment process where potential vulnerabilities, such as weak authentication controls, are systematically discovered and documented. In this scenario, the weak authentication that allowed unauthorized database access should have been identified during risk identification, which involves cataloging assets, threats, and existing controls. This step precedes any treatment, monitoring, or evaluation activities.

Exam trap

The trap here is that candidates confuse risk identification with risk evaluation or risk treatment, mistakenly thinking that evaluating the impact of a weak control or treating it after discovery is the same as initially finding the vulnerability.

How to eliminate wrong answers

Option A is wrong because risk treatment involves selecting and implementing controls to mitigate identified risks, not discovering vulnerabilities; the weak authentication would have already needed to be known before treatment could occur. Option B is wrong because risk monitoring is a continuous process of tracking identified risks and control effectiveness over time, not the initial step to find a vulnerability like weak authentication. Option D is wrong because risk evaluation compares the level of risk against risk criteria to prioritize treatment, but it assumes the vulnerability has already been identified; it does not discover new vulnerabilities.

594
MCQhard

A risk practitioner is selecting a risk analysis technique for a new mobile banking feature. The team has limited historical loss data, the feature involves several interconnected components, and stakeholders disagree about how failures propagate between them. Management wants a technique that structures expert judgment about causal pathways and produces a visual model of how component failures combine to cause the top-level loss event. Which technique BEST meets these requirements?

A.Delphi technique
B.Fault tree analysis
C.Business impact analysis
D.Annualized loss expectancy calculation
AnswerB

Fault tree analysis starts from a defined undesired top event and works backward through logic gates to show how combinations of lower-level failures cause it. With sparse historical data, it structures expert judgment about causal pathways and yields a visual model of how component failures combine, which directly matches the stakeholder need to resolve disagreement about failure propagation in the mobile banking feature.

Why this answer

Fault tree analysis is a deductive technique that begins with a top-level undesired event and uses logic gates to represent combinations of contributing failures, making it ideal when historical data is scarce and causal relationships are disputed. It structures expert judgment and produces a diagram of failure propagation. Annualized loss expectancy quantifies monetary risk but needs data the team lacks, Delphi aggregates opinions without a causal model, and business impact analysis focuses on disruption consequences to business functions.

Exam trap

The trap here is assuming any consensus-building or quantification method satisfies a need for causal modeling, when only a deductive logic-based technique exposes how component failures combine.

595
MCQmedium

A company's risk management policy requires a risk register to be maintained. Which of the following is the primary purpose of a risk register?

A.To assign financial values to all risks
B.To document and track identified risks, assessments, and risk responses
C.To record audit findings
D.To provide a list of all IT assets
AnswerB

A risk register is the central record capturing each identified risk together with its assessment results and chosen responses, enabling tracking and ownership over time. This supports the policy requirement by giving management a single, auditable view of risk status and treatment progress.

Why this answer

The primary purpose of a risk register is to serve as a central repository for documenting and tracking all identified risks, their assessments (including likelihood and impact), and the corresponding risk response strategies. This ensures that risk management activities are transparent, auditable, and actionable throughout the risk lifecycle, aligning with the ISACA CRISC framework.

Exam trap

The trap here is that candidates confuse the risk register with other operational logs (e.g., audit findings or asset inventories) or assume its primary purpose is financial quantification, whereas the CRISC exam emphasizes its role as a comprehensive tracking and documentation tool for the entire risk management process.

How to eliminate wrong answers

Option A is wrong because assigning financial values to risks is a specific activity within risk analysis (e.g., quantitative risk assessment using ALE/SLE), not the primary purpose of the risk register itself; the register may include such values but is not limited to them. Option C is wrong because audit findings are recorded in audit reports or issue logs, not the risk register; the risk register focuses on forward-looking risk identification and treatment, not retrospective audit results. Option D is wrong because a list of all IT assets is typically maintained in an asset inventory or configuration management database (CMDB), not the risk register; the risk register only includes assets relevant to identified risks.

596
MCQeasy

An organization is implementing a new data loss prevention (DLP) solution. The risk manager is identifying potential risks related to the DLP solution itself. Which of the following is a risk that should be considered?

A.The DLP solution may generate a high volume of false positives, causing alert fatigue and missed real incidents.
B.The DLP solution will reduce the risk of data exfiltration.
C.The DLP solution will block all unauthorized data transfers.
D.The DLP solution will automatically encrypt sensitive data in transit.
AnswerA

A DLP solution tuned too broadly flags legitimate activity, producing excessive false positives. Analysts then desensitise to alerts, so genuine data-loss incidents are overlooked — a risk introduced by the control itself, not by the threats it mitigates.

Why this answer

A DLP solution may generate false positives, leading to alert fatigue and missed detections. Option B is a benefit, not a risk. Option C is a control.

Option D is a desired outcome.

597
MCQmedium

A company uses a DevOps approach with a continuous integration/continuous deployment (CI/CD) pipeline. Which risk identification technique is best suited for detecting code vulnerabilities early in the development lifecycle?

A.Quarterly penetration testing
B.Automated security scanning integrated into the pipeline
C.Threat modeling of system architecture
D.Manual code review
AnswerB

Automated security scanning embeds static and dependency analysis directly into the CI/CD pipeline, so vulnerabilities are flagged at commit or build time rather than after deployment. This satisfies the stem's requirement to detect code flaws early in the development lifecycle, before artefacts reach production.

Why this answer

Automated security scanning integrated into the CI/CD pipeline is best suited for detecting code vulnerabilities early because it runs continuously on every code commit, providing immediate feedback to developers. This aligns with the DevOps principle of shifting security left, catching issues like SQL injection or insecure dependencies before they reach production. Unlike periodic tests, this technique ensures vulnerabilities are identified at the moment of introduction, minimizing remediation cost and risk.

Exam trap

The trap here is that candidates may choose threat modeling (Option C) because it is a recognized risk identification technique, but they fail to recognize that it is not designed to detect code-level vulnerabilities early in the development lifecycle, which requires continuous, automated scanning within the pipeline.

How to eliminate wrong answers

Option A is wrong because quarterly penetration testing is a periodic, point-in-time assessment that occurs long after code is deployed, failing to detect vulnerabilities early in the development lifecycle. Option C is wrong because threat modeling of system architecture is a design-phase technique that identifies high-level threats and attack surfaces, not specific code-level vulnerabilities like buffer overflows or injection flaws. Option D is wrong because manual code review, while valuable, is slower, less consistent, and cannot scale to the frequency of commits in a CI/CD pipeline, making it impractical for early and continuous detection.

598
MCQeasy

During a risk assessment of a web application, the risk owner identifies that the application uses outdated encryption algorithms. What is the most appropriate next step?

A.Escalate the issue to senior management for approval to accept the risk.
B.Accept the risk without action because encryption is not critical.
C.Document the finding in the risk register and assign a remediation timeline.
D.Immediately patch the application to use modern encryption without further analysis.
AnswerC

Documenting the outdated encryption algorithms in the risk register with a remediation timeline satisfies the risk owner's obligation to record and track identified risk. The register captures the finding, while the assigned timeline ensures accountability for treating the cryptographic weakness, aligning with CRISC risk response and monitoring practise.

Why this answer

The risk owner has identified a specific vulnerability (outdated encryption algorithms) that must be formally recorded in the risk register. The next step is to document the finding and assign a remediation timeline, which aligns with the risk assessment process of treating identified risks. This ensures the issue is tracked, prioritized, and addressed within the organization's risk management framework, rather than being escalated, ignored, or patched without analysis.

Exam trap

The trap here is that candidates may confuse the immediate need to patch (Option D) with the proper risk management process, which requires documentation and analysis before any remediation action is taken.

How to eliminate wrong answers

Option A is wrong because escalating to senior management for risk acceptance is premature; the risk must first be documented and assessed for impact and likelihood before any acceptance decision. Option B is wrong because accepting the risk without action ignores the fact that outdated encryption algorithms (e.g., DES, RC4, or 3DES) are known to be vulnerable to attacks (e.g., brute force, cryptanalysis) and can lead to data breaches, making encryption critical for confidentiality. Option D is wrong because immediately patching without further analysis bypasses the risk assessment process; a patch could introduce compatibility issues or fail to address the root cause, and a proper change management process is required.

599
Multi-Selectmedium

A risk analyst is evaluating the effectiveness of the organization's existing control environment for a newly identified risk involving unauthorized access to a human resources database. Which TWO of the following activities would BEST help the analyst determine whether the current controls reduce the risk to an acceptable level? (Choose two.)

Select 2 answers
A.Interviewing the HR database administrator about the perceived strength of the database password policy.
B.Mapping the HR database to the organization's risk register and confirming the assigned risk owner.
C.Analyzing security incident logs and access monitoring reports for the HR database over the past year.
D.Reviewing the results of the most recent access control audit and penetration test of the HR database.
E.Calculating the annualized loss expectancy of a hypothetical breach of the HR database.
AnswersC, D

Incident logs and access monitoring reports show how controls performed against real events, including blocked attempts, anomalous access patterns, and detected violations. This operational evidence complements audit and penetration testing by revealing detective and responsive control behavior over time. Trends such as recurring failed logins from unusual locations can indicate control gaps that a point-in-time test might not surface, strengthening the residual risk determination.

Why this answer

Determining whether existing controls reduce risk to an acceptable level requires evidence of both design and operating effectiveness. Audit and penetration test results demonstrate whether safeguards withstand realistic threats, while incident logs and access monitoring reveal how detective and responsive controls perform against actual events over time. Perceptions, financial calculations, and register mapping do not test control performance, so they cannot support a defensible residual risk conclusion.

Exam trap

The trap here is accepting management opinion or a financial calculation as proof of control effectiveness, when only independent testing and operational evidence demonstrate that controls actually work.

600
Multi-Selecthard

A global manufacturer is performing an IT risk assessment for its industrial control systems (ICS). The risk team is evaluating threat sources and wants to identify factors that INCREASE the likelihood of a threat event occurring. Which TWO of the following factors increase the likelihood of a threat event? (Choose two.)

Select 2 answers
A.A well-funded, motivated threat actor targeting the manufacturer's sector.
B.A mature backup and recovery capability with regularly tested restores.
C.A high number of unpatched, internet-facing ICS components.
D.A documented and tested incident response plan for OT environments.
E.Segmentation that isolates the ICS network from the corporate network.
AnswersA, C

Threat capability and motivation are core likelihood drivers. A well-resourced actor with sector-specific intent is more likely to attempt and succeed at exploiting ICS weaknesses. This raises both the frequency of attempts and the probability of success, making it a legitimate factor that increases the likelihood of a threat event in the assessment.

Why this answer

Likelihood of a threat event rises when exposure and adversary pressure increase. Numerous unpatched, internet-facing ICS components create exploitable pathways, and a well-funded, motivated actor targeting the sector raises both attempt frequency and success probability. Response planning, segmentation, and backup capability are controls that reduce impact or exposure, not factors that increase the chance of an event.

Exam trap

The trap here is selecting strong security controls as likelihood drivers, when controls such as segmentation, response planning, and backups reduce likelihood or impact rather than increase it.

Page 7

Page 8 of 15

Page 9