Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?
This is a leading indicator of potential future exploits.
Why this answer
A leading Key Risk Indicator (KRI) predicts future risk events by measuring conditions that precede incidents. Missing critical patches on systems directly indicate a higher likelihood of exploitation, making it a leading indicator. In contrast, lagging KRIs like incident counts or costs measure outcomes after the fact.
Exam trap
The trap here is confusing leading indicators (which predict risk) with lagging indicators (which measure past events), leading candidates to pick options like the number of security incidents or audit findings resolved, which are reactive rather than predictive.
How to eliminate wrong answers
Option B is wrong because the number of audit findings resolved is a lagging indicator that measures remediation activity after issues have been identified, not a predictor of future risk. Option C is wrong because the number of security incidents this quarter is a lagging KRI that reports past events, not a leading indicator of impending risk. Option D is wrong because the total cost of security incidents is a lagging financial metric that quantifies damage after incidents occur, offering no forward-looking risk prediction.