Courseiva

Certified in Risk and Information Systems Control CRISC (CRISC) — Questions 601–675

1062 questions total · 15pages · All types, answers revealed

Page 8

Page 9 of 15

Page 10
601
Multi-Selecthard

An organization is implementing a quantitative risk assessment for its customer database. Which TWO elements are essential for calculating the annualized loss expectancy (ALE)?

Select 2 answers
A.Annualized rate of occurrence (ARO)
B.Control effectiveness rating
C.Asset value (AV)
D.Inherent risk score
E.Risk appetite threshold
AnswersA, C

ALE is derived by multiplying the single loss expectancy by how often the loss occurs each year. The annualised rate of occurrence supplies that frequency figure, so without it the expected yearly loss cannot be quantified for the customer database scenario.

Why this answer

The ALE formula is ALE = SLE × ARO, where SLE (single loss expectancy) = AV × EF (exposure factor). Option A, annualized rate of occurrence (ARO), is essential because it estimates how many times per year a threat is expected to materialize, directly multiplying the per-incident loss. Option C, asset value (AV), is essential because it feeds into the SLE calculation (AV × EF), representing the monetary worth of the customer database being protected.

Control effectiveness rating (B) is not part of the ALE formula; it may inform residual risk but is not a required input. Inherent risk score (D) is a qualitative/derived measure, not a component of ALE. Risk appetite threshold (E) is a governance tolerance used to compare against risk, not a calculation input for ALE.

Exam trap

The trap here is that candidates often confuse the components of SLE (AV and EF) with the ALE formula itself, mistakenly thinking control effectiveness or inherent risk scores are direct multipliers in the ALE calculation, when in fact they are separate risk assessment inputs.

602
MCQhard

An organization has a risk culture where employees are hesitant to report security incidents due to fear of blame. Which of the following initiatives would MOST effectively promote a risk-aware culture?

A.Increase the frequency of security awareness training
B.Establish a confidential incident reporting system with a no-blame policy
C.Conduct more frequent audits to detect unreported incidents
D.Discipline employees who fail to report incidents
AnswerB

A confidential reporting channel combined with a no-blame policy removes the fear of reprisal that suppresses incident reporting, directly addressing the cultural barrier described. Employees report near misses and incidents earlier, improving detection and organisational learning.

Why this answer

Establishing a confidential incident reporting system with a no-blame policy directly addresses the root cause — fear of blame — by removing the deterrent to reporting. This creates psychological safety, which is a prerequisite for a healthy risk-aware culture where employees surface issues early.

Exam trap

The trap is choosing a control-based or punitive response (training, audits, discipline) when the scenario describes a cultural problem — CRISC tests whether candidates address root causes rather than symptoms.

How to eliminate wrong answers

Option A is wrong because more frequent training does not address the fear of blame; employees may still withhold incidents despite knowing better. Option C is wrong because more audits are a detective control that may catch unreported incidents but does not encourage voluntary reporting or fix the cultural problem. Option D is wrong because disciplining employees who fail to report increases fear and further suppresses reporting, worsening the culture.

603
MCQmedium

A financial services firm has completed its annual IT risk assessment. The chief risk officer asks the IT risk analyst to classify each identified risk according to the organization's risk taxonomy before any response decisions are made. Which activity should the analyst perform FIRST?

A.Recalculate the annualized loss expectancy for every risk using the latest asset valuation data.
B.Immediately transfer the highest-rated risks to the cyber insurance carrier to cap the firm's exposure.
C.Publish the complete risk register to the board risk committee for formal acceptance of all identified risks.
D.Map each risk to the relevant business process and asset owner, and assign a consistent risk category and owner.
AnswerD

Structuring risks by business process, asset owner, and consistent taxonomy category creates the traceability needed before any response decision. Without this alignment, the CRO cannot compare risks, delegate ownership, or aggregate exposure across the enterprise, so classification and ownership assignment must precede selecting treatments, calculating residual scores, or reporting to the board.

Why this answer

Classification and ownership assignment come first because every downstream activity, including quantification, treatment selection, transfer, and governance reporting, depends on knowing what each risk is, who owns it, and how it maps to business processes. Establishing a consistent taxonomy and accountable owner creates the structure required for aggregation and defensible risk acceptance at the enterprise level.

Exam trap

The trap here is assuming the most visible or financially quantifiable activity, such as insurance transfer or ALE recalculation, must come first when the foundational step is actually structuring and assigning the risk.

604
MCQeasy

A company is identifying risks associated with a new cloud-based CRM. Which of the following is the MOST effective method for identifying potential threats?

A.Threat modeling workshops with stakeholders
B.Reviewing industry standards only
C.Conducting penetration testing alone
D.Analyzing historical security incidents from similar organizations
AnswerA

Threat modelling workshops systematically enumerate threats against the CRM's architecture, data flows and trust boundaries, drawing on stakeholder knowledge of misuse cases and attack surfaces. This structured decomposition surfaces cloud-specific risks such as tenant isolation and API exposure that generic checklists or vulnerability scans would miss.

Why this answer

Threat modeling workshops with stakeholders are the most effective method because they leverage diverse expertise to systematically identify threats specific to the cloud-based CRM architecture, including misconfigurations in IAM roles, API vulnerabilities, and data residency issues. This collaborative approach aligns with the CRISC focus on proactive risk identification by considering business context, technical constraints, and regulatory requirements early in the lifecycle.

Exam trap

The trap here is that candidates often choose penetration testing (Option C) because it is a familiar technical activity, but the question asks for the 'most effective method for identifying potential threats' in a new system, where proactive collaboration (threat modeling) outperforms reactive testing.

How to eliminate wrong answers

Option B is wrong because reviewing industry standards only provides a baseline of known controls but fails to capture organization-specific threats, such as custom CRM integrations or unique data flows. Option C is wrong because conducting penetration testing alone is a reactive, point-in-time validation that may miss logical threats (e.g., privilege escalation via business logic flaws) and does not involve stakeholder input for comprehensive threat enumeration. Option D is wrong because analyzing historical security incidents from similar organizations offers hindsight but cannot predict novel attack vectors or misconfigurations unique to the company's cloud deployment model (e.g., SaaS vs.

PaaS).

605
MCQmedium

Which standard is specifically designed for industrial automation and control systems security and provides a framework for addressing security in IACS?

A.ISO 27001
B.NERC CIP
C.IEC 62443
D.NIST SP 800-53
AnswerC

IEC 62443 is the only standard written specifically for industrial automation and control systems, defining security requirements across zones and conduits. It directly satisfies the stem's demand for an IACS-specific framework, unlike generic IT standards such as ISO 27001, which lack operational technology controls.

Why this answer

IEC 62443 is the international standard series specifically designed for industrial automation and control systems (IACS) security. It provides a framework for securing IACS across the entire lifecycle, including risk assessment, system design, and operational security, with roles defined for asset owners, system integrators, and product suppliers. It is the de facto standard for OT/ICS security.

Exam trap

CRISC often tests the difference between general IT security standards (ISO 27001, NIST SP 800-53) and sector-specific or OT-specific standards (IEC 62443, NERC CIP), so candidates pick a well-known general standard instead of the IACS-specific one.

How to eliminate wrong answers

Option A is wrong because ISO 27001 is a general information security management system (ISMS) standard applicable to all industries; it does not provide IACS-specific security requirements or control system guidance. Option B is wrong because NERC CIP is a North American regulatory standard specifically for the bulk electric system (power grid) in the US and Canada; it is not a general IACS framework and applies only to registered entities in the electric sector. Option D is wrong because NIST SP 800-53 is a broad catalog of security and privacy controls for US federal information systems; while it can be applied to OT, it is not specifically designed for industrial automation and control systems.

606
MCQeasy

A risk analyst has completed a control self-assessment and found that a key preventive control failed testing in two consecutive quarters. The risk owner asks the analyst to update the risk register. Which action BEST reflects an appropriate risk response?

A.Close the finding because the control is preventive and failures are expected to occur occasionally in any environment.
B.Record the control failure, reassess the inherent and residual risk ratings, and initiate a remediation plan with a target date.
C.Increase the residual risk rating to the maximum and immediately report the organization as non-compliant to regulators.
D.Delete the original control from the register and replace it with a new control entry showing a passing test result.
AnswerB

Repeated control failure means the residual risk assumption is no longer valid, so the register must reflect the failure and the risk must be re-rated. Pairing that with a remediation plan and target date converts the finding into an actionable response and gives the risk owner a basis for deciding whether interim compensating controls or acceptance is warranted while remediation proceeds.

Why this answer

A repeat control failure invalidates prior residual risk assumptions, so the correct response is to record the failure, re-rate inherent and residual risk, and launch a dated remediation plan. Closing the finding, maximizing the rating without analysis, or overwriting the record all distort the risk picture and remove the accountability that drives correction.

Exam trap

The trap here is treating a repeated control failure as routine operational noise rather than as evidence that the recorded residual risk is understated.

607
MCQmedium

An organization has a policy requiring all sensitive data to be encrypted at rest. During an audit, it is found that encryption keys are stored in plaintext on the same server. Which risk response is MOST appropriate?

A.Avoid by removing the data
B.Mitigate by encrypting the key file
C.Accept the risk because encryption is still applied
D.Transfer the risk to a cloud provider
AnswerB

Encrypting the keys protects them, reducing the risk of unauthorized decryption.

Why this answer

Storing encryption keys in plaintext on the same server as the encrypted data defeats the purpose of encryption, as an attacker who gains access to the server can easily decrypt the data. The most appropriate risk response is to mitigate by encrypting the key file itself, typically using a key-encryption key (KEK) or a hardware security module (HSM), which protects the keys even if the server is compromised. This directly addresses the vulnerability without removing the data or transferring the risk.

Exam trap

The trap here is that candidates mistakenly believe that simply having encryption applied (option C) is sufficient, overlooking the critical requirement that encryption keys must be protected separately from the data they encrypt—a fundamental principle of cryptographic security.

How to eliminate wrong answers

Option A is wrong because removing the data is an extreme measure that disrupts business operations and is unnecessary when a simpler, less costly mitigation (encrypting the key file) exists. Option C is wrong because accepting the risk ignores the fact that plaintext keys on the same server render the encryption ineffective, creating a high-likelihood, high-impact vulnerability that violates the organization's policy. Option D is wrong because transferring the risk to a cloud provider does not inherently solve the problem—if the keys remain in plaintext on the same server, the same vulnerability persists regardless of who manages the infrastructure.

608
Multi-Selecthard

A risk assessment team is calculating the Annual Loss Expectancy (ALE) for a critical server. The Single Loss Expectancy (SLE) is $50,000 and the Annual Rate of Occurrence (ARO) is estimated to be 2. The team is considering implementing a new backup solution costing $40,000 per year. Which TWO of the following statements are true regarding the cost-benefit analysis? (Select TWO.)

Select 2 answers
A.The net benefit of the backup is $60,000 per year.
B.The backup is cost-effective if the ALE reduction exceeds the annual cost.
C.The ALE after implementing the backup is $100,000 minus the backup cost.
D.The payback period for the backup is one year.
E.The current ALE without backup is $100,000.
AnswersB, E

Cost-benefit compares the annual cost of the control against the reduction in ALE it delivers. The backup is justified only when that ALE reduction exceeds $40,000 per year; otherwise the control costs more than the risk it mitigates.

Why this answer

Option E is correct because ALE is calculated as SLE × ARO, so $50,000 × 2 = $100,000, which is the current annualized loss exposure before any control is applied. Option B is correct because a safeguard is justified when its annual cost is less than the ALE reduction it produces; the backup costs $40,000 per year, so it is cost-effective only if it lowers the ALE by more than that amount. Option A is not correct because the net benefit cannot be stated as $60,000 without knowing the reduced ALE after the backup; $100,000 minus $40,000 is not the net benefit.

Option C is not correct because the post-control ALE is the residual SLE × ARO after mitigation, not the original ALE minus the backup cost. Option D is not correct because no payback period can be determined from the given data; it would require the actual loss reduction and possibly the initial versus recurring cost structure.

Exam trap

The trap here is that candidates mistakenly assume the backup cost is subtracted directly from the current ALE to get a net benefit, ignoring that the control reduces but does not eliminate the risk, and that the payback period requires knowing the actual annual benefit.

609
MCQmedium

A retail company is assessing risk for a new customer loyalty application. The risk team determines that the inherent risk is high, then evaluates existing controls and finds that the residual risk is within the organization's risk appetite. The CIO asks what the residual risk rating represents. Which statement BEST describes residual risk in this context?

A.The risk that the implemented controls themselves will fail to operate as designed.
B.The risk that remains after existing controls are applied and their effectiveness is considered.
C.The total risk exposure before any controls are implemented.
D.The maximum plausible loss the organization could suffer from a single risk event.
AnswerB

Residual risk is precisely the exposure left after controls are applied, accounting for how well those controls actually work. In this scenario, the loyalty application's high inherent risk is reduced by current controls to a level within appetite. This rating is what the organization actually carries and is the basis for deciding whether further treatment is needed.

Why this answer

Residual risk is the exposure that remains once existing controls are applied and their effectiveness is factored in. Because the loyalty application's controls reduce the high inherent risk to a level inside the stated appetite, the residual rating is what the organization actually carries. It drives the decision to accept, mitigate further, transfer, or avoid the risk.

Exam trap

The trap here is conflating residual risk with inherent risk or with control risk, when residual risk specifically means post-control exposure adjusted for control effectiveness.

610
MCQmedium

A risk practitioner at a healthcare insurance company is building the risk register entry for ransomware affecting its claims-processing platform. The practitioner must document the loss event type, the asset at risk, and the expected loss magnitude in the organization's risk taxonomy. Which of the following BEST describes the risk component that represents the expected loss magnitude?

A.The likelihood that a ransomware actor will attempt to compromise the claims-processing platform within the next twelve months.
B.The inherent risk level assigned to the claims-processing platform before any controls are applied.
C.The business impact, expressed in financial terms, if the ransomware event actually occurs and disrupts claims processing.
D.The control effectiveness rating of the endpoint detection and backup controls protecting the claims-processing platform.
AnswerC

Business impact in financial terms is the expected loss magnitude component of a risk scenario. It captures the monetary consequence if the ransomware event materializes against the claims-processing platform. This aligns with ISACA risk scenario anatomy, where impact answers how much loss would result. Documenting this value supports risk ranking, treatment decisions, and comparison against the organization's risk appetite.

Why this answer

Expected loss magnitude is captured as business impact expressed in financial terms, answering how much the organization would lose if the ransomware event disrupted claims processing. Likelihood, inherent risk, and control effectiveness are distinct components that feed into risk analysis but do not themselves quantify the consequence. Documenting financial impact enables meaningful comparison against risk appetite and supports prioritization of treatment options.

Exam trap

The trap here is confusing likelihood or inherent risk level with expected loss magnitude, when only the financially expressed business impact represents the magnitude component of the risk scenario.

611
MCQmedium

A risk practitioner at a healthcare insurer is mapping the organization's IT risk register to the NIST Cybersecurity Framework (CSF) 2.0. Executive leadership wants assurance that the organization understands which assets and business processes depend on which systems before any risk treatment decisions are made. Which CSF 2.0 function and category BEST addresses this requirement?

A.IDENTIFY (ID) — Asset Management (ID.AM)
B.DETECT (DE) — Continuous Monitoring (DE.CM)
C.GOVERN (GV) — Risk Management Strategy (GV.RM)
D.PROTECT (PR) — Identity Management, Authentication, and Access Control (PR.AA)
AnswerA

ID.AM requires the organization to inventory hardware, software, services, and systems and to map them to business functions and processes. For the healthcare insurer, this directly produces the asset-to-business-process dependency view leadership is asking for, making it the correct foundation before any risk response or treatment decision is taken.

Why this answer

The insurer needs to know which systems support which business processes before deciding on treatment, and that dependency mapping is the core purpose of the IDENTIFY function's Asset Management category. Governance sets direction, PROTECT enforces controls, and DETECT finds events, but none of those produces the asset-to-process inventory that leadership explicitly requested.

Exam trap

The trap here is assuming that any governance or risk strategy category satisfies an executive request for asset visibility, when dependency mapping is really an IDENTIFY function activity.

612
Multi-Selectmedium

Which TWO of the following are primary factors that determine how often a risk assessment should be performed?

Select 2 answers
A.Available risk assessment budget
B.Rate of change in the IT environment
C.Number of IT employees
D.Inherent risk level of critical assets
E.Number of past security incidents
AnswersB, D

A rapidly changing IT environment invalidates prior assessments quickly, so the interval must shorten to keep risk pictures current. This directly determines assessment frequency, unlike static factors such as organisational size or historical loss data.

Why this answer

Option B is correct because the rate of change in the IT environment directly drives how quickly risk exposure can shift — new systems, cloud migrations, software updates, and architecture changes can invalidate a prior assessment, so faster change demands more frequent reassessment. Option D is correct because the inherent risk level of critical assets determines the potential impact and likelihood of loss; high-inherent-risk assets (e.g., those processing sensitive data or supporting critical services) warrant more frequent risk assessments than low-risk assets. Option A is not a primary factor — budget is a constraint on how assessments are executed, not a driver of the required frequency.

Option C is not a primary factor — headcount does not by itself change the risk landscape or the need for reassessment. Option E is not a primary factor — past incidents may inform risk ratings, but the frequency of assessment is driven by change and inherent risk, not by a historical incident count.

Exam trap

The trap here is that candidates confuse operational constraints (budget, staff count) or reactive metrics (past incidents) with the proactive, risk-driven factors that ISACA emphasizes for determining assessment frequency, leading them to select budget or incident count instead of change rate and inherent risk.

613
MCQmedium

A healthcare organization is subject to strict regulatory requirements regarding patient data privacy. The organization has a control that requires all access to patient records to be logged and reviewed weekly by the compliance team. The review is currently performed manually by sampling 10% of the logs. The compliance team reports that the review takes 20 hours per week and they are often unable to complete it on time. As a result, some suspicious access patterns are detected weeks after they occur. The risk manager needs to propose an improvement to the monitoring process. The organization's risk appetite for undetected unauthorized access is very low. Which of the following is the MOST effective recommendation?

A.Reduce the review frequency to bi-weekly to free up time.
B.Hire additional staff to perform the manual reviews.
C.Deploy user behavior analytics (UBA) tools for automated anomaly detection.
D.Increase the sample size to 50% of logs for better coverage.
AnswerC

User behaviour analytics continuously baselines access patterns and flags anomalies automatically, replacing 10% manual sampling with full coverage and near-real-time detection. This directly satisfies the very low risk appetite for undetected unauthorised access, which delayed weekly reviews cannot meet.

Why this answer

The most effective recommendation because deploying user behavior analytics (UBA) tools automates the detection of anomalous access patterns, enabling real-time or near-real-time monitoring. This reduces manual effort, improves detection speed, and aligns with the organization's low risk appetite for undetected unauthorized access. Option A is wrong because reducing review frequency to bi-weekly would further delay detection, increasing risk.

Option B is wrong because hiring additional staff only addresses the workload issue temporarily and does not improve detection timeliness or scalability. Option D is wrong because increasing the sample size to 50% would increase manual effort and still result in delayed detection due to the manual review bottleneck.

614
MCQmedium

A large e-commerce company uses several key risk indicators (KRIs) to monitor credit card fraud. The risk committee noticed that one KRI has been trending above the threshold for three consecutive months, yet no risk response was initiated. Which of the following is the MOST likely root cause?

A.The KRI was not validated for accuracy
B.The risk response workflow was not triggered automatically
C.The KRI threshold was set too lenient
D.The monitoring tool failed to capture data
AnswerB

A KRI breaching its threshold for three months without any response indicates the escalation path depends on manual intervention that never occurred. Automating the risk response workflow so threshold breaches trigger action directly addresses this control gap.

Why this answer

The most likely root cause is that the risk response workflow was not triggered automatically. In a mature risk monitoring environment, KRIs should be linked to automated workflows that initiate a response when thresholds are breached. Since the KRI has been above threshold for three consecutive months without any action, it indicates a failure in the automated triggering mechanism, not in the KRI's accuracy or the threshold's leniency.

Exam trap

The trap here is that candidates may focus on data quality or threshold settings (options A, C, D) instead of recognizing that the core issue is the failure of the automated response mechanism, which is a process/control design flaw, not a data or measurement problem.

How to eliminate wrong answers

Option A is wrong because if the KRI were not validated for accuracy, the data might be unreliable, but the question states the KRI has been trending above the threshold, implying the data is consistent and likely accurate; the issue is the lack of response, not data quality. Option C is wrong because a threshold set too lenient would mean the KRI rarely or never triggers, but here it has been above threshold for three months, indicating the threshold is actually being breached; the problem is the absence of a response, not the threshold's strictness. Option D is wrong because if the monitoring tool failed to capture data, the KRI would not show a trend at all, but the question explicitly states the KRI has been trending above the threshold, meaning data capture is functioning correctly.

615
MCQmedium

A risk assessment team is evaluating the effectiveness of existing controls for a critical application. Which of the following approaches best determines whether controls are operating as intended?

A.Interviewing the control owner
B.Reviewing control documentation
C.Conducting a walkthrough and testing the controls
D.Analyzing historical audit findings
AnswerC

Walkthroughs confirm the control design is actually implemented as described, while testing provides evidence it operates effectively during the review period. This combination directly satisfies the stem's requirement to determine whether controls are operating as intended, not merely whether they exist on paper.

Why this answer

Walkthroughs and testing provide direct, empirical evidence that controls are functioning as designed. For a critical application, this approach validates actual control execution (e.g., verifying that an automated access control list (ACL) on a database server actually blocks unauthorized queries), rather than relying on secondhand accounts or static documentation. Testing confirms operational effectiveness in real-time, which is essential for accurate risk assessment.

Exam trap

The trap here is that candidates often confuse 'design effectiveness' (confirmed by documentation and interviews) with 'operating effectiveness' (confirmed only by walkthroughs and testing), leading them to choose Option B or A when the question explicitly asks whether controls are operating as intended.

How to eliminate wrong answers

Option A is wrong because interviewing the control owner only yields subjective, self-reported information about how controls are supposed to work, not objective proof of actual operation; control owners may overstate effectiveness or omit failures. Option B is wrong because reviewing control documentation (e.g., policy documents, configuration guides) shows intended design but cannot reveal whether controls are consistently applied or have degraded over time (e.g., a documented firewall rule may have been inadvertently disabled). Option D is wrong because analyzing historical audit findings provides evidence of past issues but does not confirm current control operation; controls may have been remediated or new gaps may have emerged since the last audit.

616
MCQhard

An organization is reviewing its enterprise architecture to identify risks. In which IT architecture layer would a risk related to data classification and data sovereignty be primarily addressed?

A.Application architecture layer
B.Business architecture layer
C.Data architecture layer
D.Infrastructure/Technology architecture layer
AnswerC

Data classification and data sovereignty govern how information is categorised, stored and transferred across jurisdictions, which are concerns defined within the data architecture layer. This layer specifies data entities, ownership and residency rules, so the risk is primarily addressed there rather than in application, technology or business architecture.

Why this answer

Data classification and data sovereignty are concerns about how data is categorized, where it resides, and which legal/regulatory jurisdictions govern it — all of which are addressed in the data architecture layer. This layer defines data models, ownership, retention, classification schemes, and cross-border data flow rules. Risk related to sovereignty (e.g., GDPR data residency) is fundamentally a data architecture design issue.

Exam trap

The trap is assuming that because data physically resides on infrastructure, sovereignty and classification belong to the infrastructure layer — CRISC tests whether you understand that data governance policy is defined at the data architecture layer, with infrastructure merely implementing it.

How to eliminate wrong answers

Option A is wrong because application architecture deals with how software components are structured and integrated, not data residency or classification policy. Option B is wrong because business architecture covers business processes, capabilities, and organizational structure — it may inform data policy but does not primarily address classification/sovereignty controls. Option D is wrong because infrastructure/technology architecture concerns servers, networks, and platforms; while data physically resides there, sovereignty and classification are governed at the data layer, not the hardware layer.

617
MCQeasy

Which of the following best describes the purpose of a risk heat map in an IT risk report?

A.To list the top risks in order of priority
B.To illustrate the relationship between risks and controls
C.To provide a visual representation of the likelihood and impact of risks
D.To show the cost of controls
AnswerC

A risk heat map plots risks on a matrix whose axes are likelihood and impact, giving stakeholders a visual picture of relative exposure. This graphical representation satisfies the stem's requirement to describe the heat map's purpose in an IT risk report.

Why this answer

A risk heat map is a visual tool that plots risks on a grid using likelihood (probability) on one axis and impact (consequence) on the other, typically with color coding (green/yellow/red) to indicate severity. Its primary purpose is to give decision-makers an at-a-glance view of which risks fall into high, medium, or low severity zones. This visual representation supports prioritization and communication, but the visualization itself — not the ranking — is the defining purpose.

Exam trap

CRISC often tests the distinction between a heat map (visual likelihood/impact representation) and a risk register or prioritized list — candidates confuse the visualization tool with the ranking or control-mapping artifacts.

How to eliminate wrong answers

Option A is wrong because listing risks in priority order is a ranked risk register or prioritized risk list, not a heat map; a heat map may inform prioritization but does not inherently order items. Option B is wrong because mapping risks to controls is the purpose of a control matrix or risk-control mapping, not a heat map. Option D is wrong because showing control costs is a cost-benefit or budget analysis, which is unrelated to the likelihood/impact visualization a heat map provides.

618
Drag & Dropmedium

Sequence the steps for implementing a new control based on risk assessment findings.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Control implementation involves design, procurement/build, testing, deployment, and monitoring.

619
MCQhard

A hospital's risk practitioner is assessing a new telehealth platform that stores protected health information. During risk identification, she maps threats to the platform. Which of the following BEST illustrates a threat to this platform rather than a vulnerability or a control weakness?

A.A ransomware group known to target healthcare providers is actively scanning for exposed telehealth endpoints
B.The platform's session tokens are generated with insufficient randomness and can be predicted by an attacker
C.The hospital has not yet completed a SOC 2 Type II assessment for the telehealth vendor
D.The platform's video-conferencing component has not been patched against a recently published remote code execution flaw
AnswerA

This describes an external actor with intent and capability to cause harm to the platform, which is the definition of a threat. The scanning activity shows both motivation and reach against healthcare providers, making it the threat element in the scenario. It is distinct from any internal weakness the platform may have.

Why this answer

A threat is an actor or event with the potential to cause harm, while a vulnerability is a weakness that a threat can exploit. The ransomware group targeting healthcare providers is an external threat source with demonstrated intent and capability. Unpatched components, predictable tokens, and missing assessments are internal weaknesses or control gaps that a threat could exploit, not threats themselves.

Exam trap

The trap here is conflating a vulnerability or control gap with a threat, since both appear in the same risk statement.

620
MCQeasy

A company uses a third-party SaaS application for payroll processing. What is the most important activity to identify IT risks associated with this service?

A.Conducting a vendor risk assessment
B.Performing penetration testing on the SaaS application
C.Reviewing the service-level agreement (SLA)
D.Implementing multi-factor authentication (MFA)
AnswerA

Conducting a vendor risk assessment directly addresses the third-party SaaS constraint by evaluating the provider's security controls, data handling, subcontractors and compliance posture. It identifies risks the organisation inherits but cannot inspect, such as multi-tenant isolation, breach notification and service continuity, satisfying the stem's requirement to identify IT risks associated with the payroll service.

Why this answer

A vendor risk assessment is the most important activity because it systematically evaluates the third-party SaaS provider's security controls, compliance posture, and operational resilience before and during service use. For a payroll SaaS, this includes reviewing data protection measures for sensitive employee PII, understanding the provider's SOC 2 Type II report, and assessing their incident response capabilities. Without this assessment, the organization cannot identify inherent risks like unauthorized data access, service downtime, or regulatory non-compliance specific to the third-party environment.

Exam trap

The trap here is that candidates confuse risk identification activities (like vendor assessments) with risk mitigation controls (like MFA) or contractual reviews (like SLAs), leading them to select a control or document review instead of the foundational assessment needed to uncover risks.

How to eliminate wrong answers

Option B is wrong because penetration testing on the SaaS application is typically prohibited by the provider's terms of service and would require explicit contractual permission; it is a technical control validation step, not a risk identification activity. Option C is wrong because reviewing the SLA identifies contractual remedies and uptime guarantees but does not uncover underlying security vulnerabilities, data handling practices, or third-party dependencies that constitute IT risks. Option D is wrong because implementing MFA is a risk mitigation control, not a risk identification activity; it reduces the likelihood of unauthorized access but does not help identify what risks exist in the first place.

621
Multi-Selecthard

A financial services firm has completed a risk assessment and determined that the residual risk for its online banking platform exceeds the board-approved risk appetite. The CISO must recommend risk response options to the risk committee. Which TWO of the following are appropriate risk response actions? (Choose two.)

Select 2 answers
A.Implement additional compensating controls to reduce the residual risk to within appetite
B.Remove the platform from the risk register so it no longer appears as an exception in committee reporting
C.Transfer a portion of the exposure through a cyber insurance policy and document the retained risk
D.Recalculate the annualized loss expectancy using a lower single loss expectancy to bring the rating within tolerance
E.Accept the residual risk without further action because the platform generates significant revenue
AnswersA, C

Applying additional compensating controls is the risk mitigation response, directly lowering likelihood or impact so residual risk falls back within the approved appetite. Since the committee has already determined the exposure is unacceptable, reducing it through controls is the primary and most defensible action. It also preserves the business capability while bringing exposure into alignment with the tolerance the board has formally set.

Why this answer

When residual risk exceeds appetite, the risk owner must choose from the recognized response set: mitigate, transfer, avoid, or accept with proper authority. Applying compensating controls reduces the exposure, and transferring part of the financial consequence through insurance addresses what remains. Accepting without authority, recalculating assumptions to change the rating, and deleting the risk from the register are not legitimate responses because they alter the record rather than the risk.

Exam trap

The trap here is treating risk acceptance as a default when exposure exceeds appetite, when acceptance above tolerance requires explicit authority the risk owner does not hold.

622
MCQhard

A risk practitioner is developing a risk scenario for a potential ransomware attack. Using the ISACA risk scenario template, which element describes the entity that initiates the attack?

A.Event
B.Threat type
C.Actor
D.Asset/Resource
AnswerC

The ISACA risk scenario template separates threat actor, threat event, asset, and consequence. The actor element names the party initiating the attack, such as an external ransomware group, distinguishing it from the event or impact fields.

Why this answer

In the ISACA risk scenario template, the 'Actor' element specifically identifies the entity that initiates or perpetrates the attack. For a ransomware attack, the actor could be an external hacker, a malicious insider, or a cybercriminal group, making option C the correct choice.

Exam trap

The trap here is confusing 'Actor' with 'Threat type' because both relate to the threat, but the Actor is the who (initiator) while Threat type is the what (category of threat).

How to eliminate wrong answers

Option A is wrong because 'Event' describes the specific incident or occurrence (e.g., ransomware encryption of files), not the initiating entity. Option B is wrong because 'Threat type' categorizes the nature of the threat (e.g., malware, social engineering), not the actor behind it. Option D is wrong because 'Asset/Resource' refers to the target or affected component (e.g., database, server), not the entity that launches the attack.

623
MCQeasy

Which of the following is a key component of the NIST Cybersecurity Framework's 'Identify' function?

A.Recovery planning
B.Response planning
C.Anomalies and events detection
D.Risk assessment
AnswerD

Risk assessment underpins the Identify function, establishing organisational understanding of cybersecurity risk to systems, assets and data. It inventories assets and evaluates threats and vulnerabilities, directly satisfying the framework's requirement to identify risk before protective controls are selected.

Why this answer

The NIST Cybersecurity Framework's Identify function includes categories such as Asset Management, Business Environment, Governance, Risk Assessment, and Risk Management Strategy. Risk assessment is explicitly a key component of Identify because understanding organizational risk is foundational to prioritizing cybersecurity activities. It is listed under ID.RA in the framework core.

Exam trap

The trap is mixing up the five CSF functions — candidates often associate 'risk assessment' with governance or protection, but CRISC tests that risk assessment is an Identify function, while recovery and response planning belong to Recover and Respond respectively.

How to eliminate wrong answers

Option A is wrong because recovery planning belongs to the Recover function (RC.RP), not Identify. Option B is wrong because response planning belongs to the Respond function (RS.RP). Option C is wrong because anomalies and events detection belongs to the Detect function (DE.AE).

624
MCQmedium

A company is adopting a DevSecOps approach and wants to conduct threat modeling early in the development lifecycle. Which threat modeling methodology is BEST suited for this environment due to its focus on agile and continuous integration?

A.TRIKE
B.VAST
C.STRIDE
D.PASTA
AnswerB

VAST's Visual, Agile and Simple Threat modelling integrates into agile workflows and CI pipelines, producing scalable, automation-friendly outputs. This suits DevSecOps, where threat modelling must recur each sprint rather than as a one-off design-phase exercise.

Why this answer

VAST (Visual, Agile, and Simple Threat modeling) is the only methodology explicitly designed for agile and DevSecOps environments, integrating threat modeling into CI/CD pipelines and scaling across large development teams. It uses two model types — application threat models for developers and operational threat models for infrastructure — making it suitable for continuous delivery. This agile-native design is why VAST is the best fit when threat modeling must occur early and iteratively in the SDLC.

Exam trap

CRISC often tests the distinction between threat modeling methodologies by pairing an agile/DevSecOps keyword with the methodology that was purpose-built for that context — candidates who default to the more famous STRIDE or PASTA miss that VAST is the agile-native answer.

How to eliminate wrong answers

Option A is wrong because TRIKE is a risk-based, requirements-driven threat modeling framework focused on satisfying security auditing needs, not on agile or CI/CD integration. Option C is wrong because STRIDE is a Microsoft-developed classification model for identifying spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege — it categorizes threats but is not a full agile-oriented methodology. Option D is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a seven-stage, attacker-centric, risk-centric methodology that is heavyweight and better suited to mature, waterfall-style or high-assurance projects rather than fast agile sprints.

625
MCQhard

After a control self-assessment (CSA) workshop, business units reported that 80% of controls are operating effectively. However, internal audit's recent testing indicates a 30% control failure rate. What is the BEST explanation for this discrepancy?

A.The audit was conducted three months after the CSA, and controls may have degraded.
B.CSA participants may have a biased perception of control effectiveness, while audit uses objective evidence.
C.CSA participants lacked adequate training on what constitutes a control failure.
D.The CSA covered a different scope of controls than the audit.
AnswerB

CSA workshops rely on business units self-reporting, which introduces optimism bias and limited sampling, whereas internal audit tests controls against objective evidence such as transaction logs. That difference in evidence quality, not control design, explains the 80% versus 30% gap.

Why this answer

The most likely explanation for the gap between CSA self-reported effectiveness (80%) and audit-observed failure (30%) is that CSA participants assess controls subjectively and may overestimate effectiveness due to familiarity, optimism, or lack of objectivity, whereas internal audit tests controls using independent, evidence-based procedures. This perception bias is a well-documented limitation of self-assessment. The other options introduce speculative factors (timing, training, scope) that are not supported by the scenario.

Exam trap

The trap is selecting a plausible-sounding but speculative cause (timing, training, scope) instead of the fundamental methodological difference — CSA is subjective self-reporting, audit is objective evidence-based testing — which is the best explanation for systematic over-reporting.

How to eliminate wrong answers

Option A is wrong because while control degradation over three months is possible, it is speculative and does not explain a 50-percentage-point gap as well as the inherent bias of self-assessment. Option C is wrong because lack of training is a plausible but secondary factor; the core issue is the subjective nature of CSA versus objective audit evidence, and the scenario does not indicate a training deficiency. Option D is wrong because the scenario does not state that scopes differed; assuming a scope mismatch is an unsupported leap when the more fundamental explanation (bias vs. evidence) is available.

626
MCQhard

An organization uses a third-party vendor for critical data processing. The vendor has experienced two minor security incidents in the past year with no data loss. The risk manager is updating the vendor risk assessment. Which approach best aligns with ISACA's guidance?

A.Initiate a formal reassessment of the vendor's security controls and contractual protections.
B.Increase the frequency of vendor audits to quarterly.
C.Request a copy of the vendor's SOC 2 report from last year.
D.Accept the risk because the incidents did not result in data loss.
AnswerA

Repeated incidents, even minor ones without data loss, signal control weaknesses at a critical vendor. ISACA guidance requires reassessing the vendor's security controls and contractual protections rather than waiting for a scheduled review or accepting the risk based on absence of loss.

Why this answer

ISACA's guidance emphasizes that even minor security incidents without data loss indicate potential control weaknesses that require reassessment. A formal reassessment (A) ensures the vendor's security controls and contractual protections are re-evaluated to address underlying risks, aligning with the principle of continuous risk monitoring and response.

Exam trap

The trap here is that candidates assume no data loss means no risk, but ISACA requires proactive reassessment of controls after any incident to prevent escalation, not passive acceptance or superficial monitoring.

How to eliminate wrong answers

Option B is wrong because increasing audit frequency to quarterly does not address the root cause of the incidents; it only increases oversight without reassessing the effectiveness of existing controls. Option C is wrong because a SOC 2 report from last year is historical and may not reflect current control effectiveness after two incidents; it provides a point-in-time assessment rather than a dynamic response. Option D is wrong because accepting risk solely because no data loss occurred ignores the potential for future incidents with more severe consequences; ISACA requires risk treatment based on likelihood and impact, not just past outcomes.

627
MCQeasy

An organization is implementing a bring your own device (BYOD) program. The risk practitioner is asked to identify the control that BEST reduces the risk of data leakage from lost or stolen mobile devices.

A.Require complex passwords on all BYOD devices.
B.Conduct annual security awareness training for BYOD users.
C.Implement mobile device management (MDM) with remote wipe and encryption enforcement.
D.Prohibit storing any corporate data on BYOD devices.
AnswerC

MDM allows the organization to enforce encryption, require screen locks, and remotely wipe corporate data if a device is lost or stolen. This directly mitigates the risk of data leakage by ensuring data is encrypted at rest and can be erased. It is the most effective control for the stated scenario.

Why this answer

The most effective way to reduce data leakage from lost or stolen BYOD devices is to enforce encryption and enable remote wipe through MDM. This ensures that even if the device is compromised, the data remains protected or can be erased. Other controls are helpful but do not provide the same direct technical mitigation.

Exam trap

The trap here is choosing a policy or awareness control when the question asks for the control that best reduces data leakage from a lost device, which requires technical enforcement.

628
MCQhard

An organization has recently suffered a ransomware attack that encrypted critical files. During the post-incident review, the risk team is identifying key risk indicators (KRIs) to improve early detection. Which of the following KRIs would be MOST effective in detecting similar attacks in the future?

A.Frequency of antivirus signature updates.
B.Number of unauthorized remote access attempts.
C.Percentage of employees who completed security awareness training.
D.Time to patch critical vulnerabilities.
AnswerB

Unauthorised remote access attempts are a leading indicator: ransomware actors typically gain initial entry through remote access, so a rising count signals intrusion attempts before encryption occurs, enabling earlier detection than lagging indicators such as encrypted file counts.

Why this answer

A KRI must be a measurable, leading indicator that provides early warning of an emerging risk. A spike in unauthorized remote access attempts is a direct precursor to ransomware intrusion (which typically begins with credential abuse or RDP exploitation), so monitoring this metric can trigger early detection before encryption occurs. It is behavioral, actionable, and tied to the attack chain.

Exam trap

CRISC often tests the KRI vs. KPI distinction — candidates pick compliance or hygiene metrics (training completion, patch time) that feel security-related but are lagging indicators, rather than behavioral signals that actually precede an attack.

How to eliminate wrong answers

Option A is wrong because antivirus signature update frequency is a hygiene/operational metric, not a leading indicator of an attack — it measures process compliance, not threat activity. Option C is wrong because security awareness training completion is a lagging, one-time compliance metric that does not detect active attacks. Option D is wrong because time-to-patch is a vulnerability management metric that reflects exposure reduction over time, but it is not a real-time detection indicator for an in-progress ransomware attack.

629
Multi-Selecteasy

Which THREE of the following are indicators of potential IT risk in an organization? (Select exactly THREE.)

Select 3 answers
A.Strong password policy
B.Regular patching cycles
C.High employee turnover in IT
D.Frequent changes to firewall rules
E.Increasing number of help desk tickets
AnswersC, D, E

Leads to loss of institutional knowledge and potential operational gaps.

Why this answer

High employee turnover in IT is a risk indicator because it can lead to loss of institutional knowledge, inconsistent security practices, and increased likelihood of misconfigurations or unpatched systems. When experienced staff leave, remaining or new employees may lack the context to properly manage firewall rules, access controls, or incident response, creating vulnerabilities.

Exam trap

The trap here is confusing risk indicators (conditions that signal potential risk) with risk controls (actions that reduce risk), leading candidates to select strong password policies or patching cycles as risk indicators instead of recognizing them as mitigations.

630
MCQhard

A risk practitioner is mapping identified IT risks to the organization's risk taxonomy. A risk has been logged for 'unauthorized access to the HR system resulting from excessive user privileges.' Under which risk category should this be classified?

A.Operational risk, because it arises from inadequate internal processes and access controls.
B.Financial risk, because a data breach could result in monetary losses and fines.
C.Strategic risk, because workforce data supports long-term talent planning.
D.Compliance risk, because HR data is subject to privacy regulations.
AnswerA

Operational risk covers losses from failed or inadequate internal processes, people, and systems. Excessive user privileges represent a control design or enforcement failure within the HR system's access management process. This categorization correctly directs treatment toward entitlement reviews, least-privilege enforcement, and segregation-of-duties controls rather than toward regulatory or strategic responses.

Why this answer

Risk categorization should reflect the root cause of the risk event. Excessive user privileges are a failure of internal access management processes, which places the risk in the operational risk category. This classification drives treatment toward entitlement reviews, least-privilege enforcement, and segregation-of-duties controls.

Compliance and financial consequences may follow, but they are impacts, not the originating category.

Exam trap

The trap here is categorizing by downstream impact such as a potential fine rather than by the root cause of the risk event.

631
MCQhard

A global organization is consolidating risk data from multiple business units into a single enterprise risk management (ERM) system. The risk practitioner notices that KRIs for the same risk type (e.g., cybersecurity) are calculated differently across units. What is the BEST approach to ensure consistent and reliable risk monitoring and reporting?

A.Require all units to adopt a common set of key performance indicators for their control environment.
B.Allow each business unit to maintain its own KRI definitions but report explanations for variances.
C.Establish a common definition and calculation methodology for each KRI across all business units.
D.Implement automated data feeds from each unit's system to the ERM system without changing the KRI definitions.
AnswerC

A single enterprise-wide definition and calculation methodology removes unit-level variation, so KRIs for the same risk type become directly comparable and aggregatable. This satisfies the consolidation constraint, enabling reliable enterprise risk monitoring and reporting across all business units.

Why this answer

Consistent risk monitoring and reporting requires a standardized definition and calculation methodology for each KRI across all business units. Without this common baseline, the aggregated risk data in the ERM system will be incomparable and unreliable, leading to flawed decision-making. Establishing common definitions ensures that the same risk type (e.g., cybersecurity) is measured uniformly, enabling accurate trend analysis and risk aggregation.

Exam trap

The trap here is that candidates often confuse KRIs with KPIs (option A) or believe that automated data feeds (option D) solve consistency issues, when in fact the core problem is the lack of a standardized measurement definition, not the data collection method.

How to eliminate wrong answers

Option A is wrong because key performance indicators (KPIs) measure control effectiveness, not risk levels; requiring KPIs does not address the inconsistency in KRI calculations, which are the direct inputs for risk monitoring. Option B is wrong because allowing each unit to maintain its own KRI definitions with variance explanations introduces subjectivity and makes it impossible to aggregate risk data consistently across the enterprise; the explanations do not resolve the underlying calculation differences. Option D is wrong because implementing automated data feeds without changing KRI definitions merely accelerates the ingestion of inconsistent data into the ERM system, perpetuating the problem of unreliable risk reporting.

632
MCQeasy

During a risk assessment, the risk manager identifies a vulnerability in a web application that could allow SQL injection. The development team states they will fix it in the next release, which is six months away. What should the risk manager do?

A.Implement a web application firewall (WAF) as a compensating control.
B.Accept the risk due to the low likelihood of exploitation.
C.Document the risk and defer action to the next assessment.
D.Request an immediate emergency patch deployment.
AnswerA

A WAF filters and blocks SQL injection patterns at the application boundary, reducing exploitability while the code fix waits six months. This compensating control addresses the vulnerability's interim exposure, satisfying the risk manager's duty to mitigate accepted remediation delay.

Why this answer

A web application firewall (WAF) is the appropriate compensating control because it can inspect and block SQL injection payloads at the HTTP/HTTPS layer without modifying the application code. This provides immediate risk reduction while the development team works on the permanent fix, aligning with the principle of defense-in-depth and the risk manager's responsibility to treat unacceptable risk during the remediation window.

Exam trap

The trap here is that candidates may assume accepting risk (Option B) is valid because the fix is scheduled, but CRISC emphasizes that risk acceptance requires formal sign-off and cannot be used as a default for unmitigated critical vulnerabilities; the correct response is to implement a compensating control to reduce residual risk to an acceptable level.

How to eliminate wrong answers

Option B is wrong because the risk manager cannot simply accept the risk based on an unsubstantiated assumption of low likelihood; SQL injection is a well-known, actively exploited vulnerability with high impact, and acceptance requires formal approval and documented justification. Option C is wrong because deferring action to the next assessment ignores the current exposure and violates the risk treatment requirement to address identified vulnerabilities in a timely manner, especially when a compensating control like a WAF is available. Option D is wrong because requesting an immediate emergency patch deployment is impractical for a six-month release cycle and may introduce instability; the development team has already committed to a scheduled fix, and the risk manager should implement a temporary control rather than demand an unrealistic patch.

633
MCQeasy

A retail bank is documenting its risk appetite for IT risk. The board states that the bank will accept only minimal risk of unauthorized disclosure of customer payment data, but is willing to accept moderate availability risk in internal reporting systems. A risk practitioner is asked to translate this statement into operational terms. Which action BEST reflects establishing risk tolerance in this context?

A.Defining measurable thresholds, such as a maximum acceptable number of payment data records exposed per year, for each risk category
B.Documenting the inherent risk rating of the payment data system in the risk register
C.Purchasing cyber insurance to transfer the financial impact of a payment data breach
D.Conducting a penetration test of the payment card processing environment
AnswerA

Risk tolerance operationalizes risk appetite by expressing it as measurable limits that can be monitored and enforced. Translating the board statement into thresholds such as a maximum number of exposed payment records per year gives objective boundaries for the payment data category and separate, looser limits for internal reporting availability, making the appetite actionable across the two stated risk categories.

Why this answer

Risk appetite is the amount of risk an organization is willing to accept in pursuit of value, while risk tolerance translates that appetite into measurable, monitorable limits. Expressing the board's statement as maximum acceptable exposure counts for payment data and separate downtime limits for internal reporting systems makes the appetite operational. The other choices are response or assessment activities that do not establish the quantitative boundaries the board's differentiated statement requires.

Exam trap

The trap here is treating risk appetite as a qualitative slogan that is satisfied by any control or insurance purchase, rather than recognizing that tolerance requires measurable thresholds tied to each risk category.

634
MCQmedium

A risk assessment report includes both inherent and residual risk ratings. The inherent risk for a process is rated as 'high' based on a 5×5 heat map. After applying a set of controls, the residual risk is rated as 'medium'. What does this indicate about the control effectiveness?

A.Controls increased the risk level.
B.Controls are fully effective and eliminate all risk.
C.Controls are not effective at all.
D.Controls are partially effective in reducing risk.
AnswerD

Residual risk dropping from high to medium shows controls reduced likelihood or impact but did not eliminate exposure. Partial effectiveness is the precise reading: inherent risk measures exposure before controls, residual after, and medium remains above the low threshold.

Why this answer

The reduction from high to medium indicates that controls are partially effective in reducing risk, but not completely.

635
Multi-Selecthard

A risk manager is designing a third-party risk management program. Which THREE factors should be considered when determining the risk tier of a vendor?

Select 3 answers
A.The vendor's physical location
B.The type of data the vendor will access
C.The vendor's annual revenue
D.The vendor's security certifications and audit results
E.The criticality of the service provided
AnswersB, D, E

Data sensitivity drives inherent risk: vendors accessing confidential, personal or regulated data create higher exposure from breach or misuse. This determines the depth of due diligence and contractual controls applied, directly informing the vendor's risk tier.

Why this answer

Option B is correct because the type of data the vendor will access directly determines the potential impact of a breach — vendors handling regulated data such as PII, PHI, or cardholder data (PCI DSS scope) warrant a higher risk tier than those with no data access. Option D is correct because a vendor's security certifications and audit results (e.g., SOC 2 Type II, ISO/IEC 27001, PCI DSS AOC) provide objective evidence of the maturity and effectiveness of its control environment, which is a core input to tiering. Option E is correct because the criticality of the service provided reflects business impact — an outage or compromise of a vendor supporting a critical business process or system causes far greater operational and financial harm than a non-essential service.

Option A does not belong because a vendor's physical location alone is not a primary tiering factor; geography may inform jurisdictional or regulatory considerations but does not by itself indicate risk level. Option C does not belong because annual revenue is a financial size indicator, not a measure of the risk the vendor poses to the organization's data, systems, or operations.

636
MCQmedium

An organization is implementing a new cloud-based CRM system. The risk manager is reviewing the solution architecture for security risks. Which architectural layer should be evaluated to ensure data encryption at rest and in transit?

A.Application architecture
B.Data architecture
C.Infrastructure architecture
D.Business architecture
AnswerB

Data architecture defines how data is stored, classified and protected, encompassing encryption at rest in databases and in transit across networks. Evaluating this layer directly verifies that the CRM's encryption controls satisfy the stem's security requirement.

Why this answer

Data architecture defines how data is stored, processed, and transmitted, including encryption policies. To ensure data encryption at rest (e.g., AES-256 for stored CRM records) and in transit (e.g., TLS 1.2/1.3 for API calls), the risk manager must evaluate the data architecture layer, which specifies encryption standards, key management, and data flow controls.

Exam trap

The trap here is that candidates often confuse 'infrastructure architecture' with data security controls, but encryption policies and data flow protections are explicitly part of the data architecture layer, not the underlying hardware or network layer.

How to eliminate wrong answers

Option A is wrong because application architecture focuses on software components, APIs, and business logic, not on encryption mechanisms for data at rest or in transit. Option C is wrong because infrastructure architecture covers hardware, networks, and virtualization layers, but encryption policies and data flow security are defined at the data architecture level. Option D is wrong because business architecture addresses organizational goals, processes, and governance, not technical encryption controls.

637
Multi-Selectmedium

Which THREE of the following are common consequences in an IT risk scenario?

Select 3 answers
A.Financial loss
B.Increased market share
C.Employee satisfaction
D.Regulatory penalty
E.Reputational damage
AnswersA, D, E

Financial loss is a standard business consequence recorded when an IT risk materialises, directly satisfying the stem's requirement for common risk outcomes. It captures monetary impact from downtime, remediation, regulatory penalties or lost revenue, and is a core input to CRISC risk analysis and response decisions.

Why this answer

In IT risk scenarios, a common consequence is financial loss (A), because incidents such as data breaches, downtime, or fraud directly incur remediation costs, lost revenue, and legal fees. A regulatory penalty (D) is also a standard consequence, since failures to comply with laws or standards like GDPR, HIPAA, or PCI DSS can result in fines and sanctions. Reputational damage (E) is likewise a typical consequence, as publicized security or availability failures erode customer trust and brand value.

By contrast, increased market share (B) and employee satisfaction (C) are generally positive business outcomes, not consequences of risk events, so they do not belong in this list.

Exam trap

The trap here is that candidates see plausible-sounding business terms like 'increased market share' and 'employee satisfaction' and select them because they sound like outcomes — but CRISC requires recognizing that risk consequences must be negative impacts, not benefits or neutral metrics.

638
Multi-Selectmedium

A risk manager is integrating risk management with IT governance. Which of the following are key elements of an IT risk management programme design? (Choose TWO.)

Select 2 answers
A.Risk assessment methodology
B.Incident response plan
C.Business continuity plan
D.Vendor management policy
E.Risk register
AnswersA, E

A defined risk assessment methodology is essential because it establishes consistent likelihood and impact criteria, enabling risks to be identified, analysed and prioritised against the organisation's risk appetite. This directly satisfies the stem's requirement for governance integration, since IT governance depends on repeatable, comparable risk evaluations feeding escalation and oversight processes.

Why this answer

Option A (Risk assessment methodology) is correct because an IT risk management programme must define a consistent, repeatable approach for identifying, analyzing, and evaluating risks — including likelihood, impact, and risk criteria — so that risks can be prioritized and treated consistently across the enterprise. Option E (Risk register) is correct because it is the core record that captures identified risks, their owners, ratings, treatment decisions, and status, enabling ongoing monitoring and reporting that links IT risk to governance objectives. The other options do not belong as key design elements of an IT risk management programme: an incident response plan (B) and a business continuity plan (C) are operational response and recovery capabilities that may be informed by risk assessments but are not themselves risk programme design components, and a vendor management policy (D) is a third-party governance control that addresses only one risk domain rather than the overall programme structure.

Exam trap

The trap is selecting operational security documents (IR plan, BCP, vendor policy) as risk programme design elements — CRISC tests whether you distinguish foundational risk management components (methodology, register) from adjacent operational plans that consume risk outputs.

639
Multi-Selecthard

A risk practitioner is identifying external threats to a retail bank's online transaction platform. The bank wants to understand threats that originate from outside the organization and target customer accounts. Which TWO of the following are external threats relevant to this scenario? (Choose two.)

Select 2 answers
A.Hacktivists defacing the bank's public website to protest its lending practices.
B.A database administrator accidentally deleting transaction records during routine maintenance.
C.A developer introducing a logic flaw into the transaction code during an internal sprint.
D.Organized criminal groups conducting credential stuffing attacks against the login portal.
E.A third-party cloud provider's data center experiencing a power outage.
AnswersA, D

Hacktivists are external actors motivated by ideology, and defacement of a public website is an external attack. It is relevant to the bank's online presence and can damage reputation and customer trust. Even if the primary target is the website rather than transaction accounts, it remains an external threat the practitioner should include in the landscape analysis.

Why this answer

External threats originate outside the organization and involve actors or events that can affect its assets. Organized criminal credential stuffing and hacktivist website defacement both fit because they are externally initiated and target the bank's online presence or customer accounts. Internal errors, developer mistakes, and provider outages are important risks but do not meet the external threat actor criterion for this analysis.

Exam trap

The trap here is treating any adverse event, such as a cloud outage or internal error, as an external threat when it lacks an external adversary.

640
MCQmedium

An architecture review board (ARB) is evaluating a new solution architecture that processes sensitive data. Which of the following should the ARB review to ensure security risks are addressed before implementation?

A.User acceptance test plan
B.Business case and ROI analysis
C.Threat model and security controls
D.Project timeline and budget
AnswerC

A threat model identifies attack vectors and required mitigations for the sensitive data flows, while the security controls demonstrate those risks are actually treated. Reviewing both before implementation satisfies the ARB's mandate to confirm security risks are addressed prior to build, rather than discovered post-deployment.

Why this answer

The ARB must ensure that security risks are identified and mitigated before implementation. A threat model systematically identifies potential threats (e.g., STRIDE) and maps them to security controls, ensuring that sensitive data is protected against attacks like injection, disclosure, or tampering. Without this review, the architecture could be deployed with unaddressed vulnerabilities.

Exam trap

The trap here is that candidates confuse project governance artifacts (UAT plan, business case, timeline) with security-specific risk assessment deliverables, leading them to select a generic project management option instead of the threat model that directly addresses security risks.

How to eliminate wrong answers

Option A is wrong because a user acceptance test plan validates functional requirements and usability, not security risks or threat mitigation. Option B is wrong because the business case and ROI analysis focus on financial justification and cost-benefit, not on identifying or addressing security threats. Option D is wrong because the project timeline and budget are project management artifacts that track schedule and cost, not security risk assessment or control validation.

641
Multi-Selectmedium

A company is prioritizing risk treatment actions. Which THREE factors should be considered when prioritizing risks?

Select 3 answers
A.Industry best practices
B.Cost-benefit analysis of controls
C.Residual risk after control implementation
D.Risk level (inherent or residual)
E.Number of vulnerabilities
AnswersB, C, D

Cost-benefit helps determine which treatments provide the best value.

Why this answer

Cost-benefit analysis ensures that the resources invested in controls are justified by the reduction in risk, which is a core principle of risk management. Without this analysis, an organization might over-invest in low-impact risks or under-invest in high-impact ones, leading to inefficient allocation of budget and effort.

Exam trap

The trap here is that candidates confuse 'number of vulnerabilities' (a technical count) with 'risk level' (which incorporates impact and likelihood), leading them to select Option E instead of recognizing that risk level is the primary driver for prioritization.

642
MCQeasy

When implementing a new access control system, which activity is essential during the change management process?

A.Updating the system documentation and user manuals
B.Removing all legacy controls
C.Assigning control ownership to external vendors
D.Disabling audit logs to save storage
AnswerA

Updating documentation and user manuals preserves the integrity of the change record, satisfying the change management requirement for controlled, auditable transitions. This ensures users and administrators understand altered access procedures, reducing operational risk from misconfiguration. Documentation updates also provide the evidence trail auditors need to verify that the access control change was authorised, tested and communicated before deployment.

Why this answer

Updating system documentation and user manuals is essential during change management because it ensures that the new access control system is accurately reflected in operational procedures, training materials, and compliance artifacts. Without updated documentation, users and auditors operate on stale information, leading to misconfigurations and audit findings. Documentation is a key change management deliverable that supports knowledge transfer and ongoing control effectiveness.

Exam trap

CRISC often tests the misconception that technical implementation alone completes a change; candidates overlook that documentation updates are a mandatory change management activity for control sustainability and audit readiness.

How to eliminate wrong answers

Option B is wrong because removing all legacy controls before the new system is validated creates a control gap and risks unauthorized access during transition. Option C is wrong because assigning control ownership to external vendors dilutes accountability and is not a standard change management requirement; ownership should remain with the organization. Option D is wrong because disabling audit logs to save storage destroys the evidence trail needed for monitoring and compliance, directly undermining the access control system's effectiveness.

643
Multi-Selecthard

Which THREE of the following are key components of an effective risk reporting framework?

Select 3 answers
A.Automated collection of risk data from all sources.
B.Consistent risk metrics across the organization.
C.Clear definition of risk appetite and tolerance levels.
D.Defined escalation paths for exceeding thresholds.
E.Statistical models for predicting future risks.
AnswersB, C, D

Enables aggregation and comparison.

Why this answer

Consistent risk metrics across the organization (Option B) are a key component of an effective risk reporting framework because they ensure that risk data is comparable and aggregated meaningfully across different business units and systems. Without standardized metrics, reports would be inconsistent, making it impossible to assess overall risk posture or identify trends reliably.

Exam trap

The trap here is that candidates often mistake operational enablers (like automated data collection or predictive models) for core framework components, but the CRISC exam emphasizes that the framework must define what is measured, how it is compared, and how responses are triggered, not just how data is gathered or analyzed.

644
MCQmedium

A financial institution is considering adopting a new AI/ML model for credit scoring. The model uses customer demographic data and transaction history. Which of the following risks is MOST likely to cause regulatory penalties if not addressed?

A.Data privacy of training data
B.Model drift due to changing economic conditions
C.Model bias leading to unfair lending practices
D.Adversarial attacks on the model
AnswerC

Model bias producing discriminatory lending outcomes directly violates fair-lending regulations, such as the Equal Credit Opportunity Act, exposing the institution to penalties. Because the model ingests demographic data, protected attributes can proxy into scoring decisions, so bias testing and mitigation are mandatory controls under this scenario's regulatory constraint.

Why this answer

Model bias leading to unfair lending practices is the most likely risk to cause regulatory penalties because credit scoring is heavily regulated under fair lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act. If an AI/ML model uses demographic data and produces disparate impact on protected classes, regulators can impose fines, sanctions, and enforcement actions. Unlike data privacy or model drift, bias directly violates anti-discrimination statutes, making it a legal compliance issue with immediate regulatory consequences.

Exam trap

CRISC often tests the distinction between technical risks (like model drift or adversarial attacks) and compliance risks (like bias), where the latter directly triggers regulatory penalties under fair lending laws.

How to eliminate wrong answers

Option A is wrong because while data privacy violations can lead to penalties under GDPR or CCPA, they are typically addressed through consent and data protection measures, and the question emphasizes regulatory penalties for unfair lending, which is a more direct and severe compliance breach. Option B is wrong because model drift affects model performance and accuracy over time but does not inherently violate regulations; it is a model risk management concern, not a direct legal violation. Option D is wrong because adversarial attacks are a security risk that can cause financial loss or data breaches, but they are not specifically tied to regulatory penalties for credit scoring fairness; they are more about model robustness and cybersecurity.

645
MCQhard

Based on the exhibit, which risk is most likely present and what is the most appropriate risk response?

A.Risk of cost; set a budget alert
B.Risk of data exposure; apply a deny rule to restrict access
C.Risk of availability; implement backup
D.No risk; the policy is standard
AnswerB

The exposed storage configuration permits anonymous or over-broad access, creating data exposure risk. Applying a deny rule restricts that access, satisfying the stem's requirement for a response that directly removes the exposure path rather than merely detecting or transferring the risk.

Why this answer

The exhibit shows a cloud storage access policy that allows public access via a wildcard permission with an allow effect. This directly exposes data to the internet, creating a risk of unauthorized data exposure. The most appropriate risk response is to apply a deny rule to restrict access, such as modifying the policy to remove the wildcard permission or adding conditions to block public access.

Exam trap

The trap here is that candidates may confuse a permissive policy with a standard configuration, overlooking the severe security implication of a wildcard permission that allows public access.

How to eliminate wrong answers

Option A is wrong because the risk is not about cost; setting a budget alert does not address the security vulnerability of public data exposure. Option C is wrong because the risk is not about availability; implementing backup does not mitigate the unauthorized access risk. Option D is wrong because the policy is not standard; allowing public access via a wildcard principal is a well-known misconfiguration that violates the principle of least privilege.

646
MCQeasy

A risk practitioner is reviewing the organization's backup and recovery procedures for critical systems. The organization wants to ensure that backups are protected against ransomware attacks that could encrypt both production data and backups. Which of the following controls is MOST effective for this purpose?

A.Performing daily full backups instead of incremental backups.
B.Encrypting backups with a strong encryption algorithm.
C.Storing backups on the same network as production systems with access controls.
D.Implementing immutable backups that cannot be altered or deleted for a set period.
AnswerD

Immutable backups prevent modification or deletion, even by administrators or attackers with elevated privileges, for a defined retention period. This ensures that a clean copy of data remains available for recovery after a ransomware attack. It directly addresses the risk of backups being encrypted or destroyed, providing a reliable recovery point.

Why this answer

Immutable backups are the most effective control because they cannot be altered or deleted for a set period, ensuring a clean recovery point even if ransomware compromises the network. Other controls like network access controls, encryption, or backup frequency do not prevent backups from being encrypted or deleted by ransomware.

Exam trap

The trap here is assuming that encryption or network access controls alone protect backups, when they do not prevent ransomware from encrypting or deleting backup files.

647
MCQmedium

A credit union's risk committee has approved a risk response for its core banking platform: purchase an insurance policy against ransomware losses and keep the current backup process unchanged. Six months later, a ransomware event encrypts production data and the backup restoration takes four days, breaching regulatory reporting deadlines. Which risk response did the risk committee most likely select, and why did it fail to address the operational impact?

A.Risk transfer, because insurance shifted the financial loss but did not reduce the likelihood or duration of the service outage.
B.Risk mitigation, because the insurance policy reduced the likelihood of a ransomware attack.
C.Risk avoidance, because the committee decided not to invest in additional backup controls.
D.Risk acceptance, because the committee acknowledged the residual risk without purchasing insurance.
AnswerA

Insurance is a classic risk transfer mechanism that compensates for financial loss after an event. It does not alter the underlying likelihood or impact of the operational disruption, so restoration time and regulatory deadlines remained exposed. The committee effectively transferred only the monetary consequence, leaving the availability and compliance risks unmitigated, which is why the four-day outage still occurred.

Why this answer

The committee chose a risk transfer response by buying insurance, which addresses only the financial consequence of a ransomware loss. Because backups and recovery capabilities were left unchanged, the operational and regulatory impacts remained fully exposed, and the four-day restoration breached reporting deadlines. Effective risk response selection must consider whether the chosen treatment addresses the specific impact categories the organization cares about, not just the monetary loss.

Exam trap

The trap here is assuming that any purchased control or policy automatically mitigates operational risk, when insurance transfers only financial loss and leaves availability and compliance exposure intact.

648
MCQhard

A large e-commerce company is assessing the risk of a distributed denial-of-service (DDoS) attack on its web applications. The company has experienced three DDoS attacks in the past year, each causing significant downtime and revenue loss. The current mitigation strategy relies on an on-premise appliance that can handle up to 10 Gbps of attack traffic. Recent industry reports indicate that DDoS attacks are growing in volume and sophistication, with some exceeding 100 Gbps. The company's risk appetite for availability is moderate. The security team has proposed migrating to a cloud-based DDoS protection service that scales to 200 Gbps, but it will increase annual operational costs by 40%. The business is concerned about the cost increase. Which of the following is the BEST risk treatment decision?

A.Transfer the risk by purchasing business interruption insurance that covers revenue loss during outages.
B.Accept the risk because the company has survived previous attacks and the cost of mitigation is high.
C.Reduce the risk by implementing the cloud-based DDoS protection service, accepting the cost increase.
D.Reduce the risk by upgrading the on-premise appliance to handle up to 50 Gbps, which is within budget.
AnswerC

The on-premise appliance caps at 10 Gbps, far below the 100+ Gbps attacks reported, so residual availability risk exceeds the moderate appetite. The cloud service scales to 200 Gbps, reducing risk to an acceptable level; the 40% cost rise is justified given repeated revenue loss.

Why this answer

The current on-premise appliance (10 Gbps capacity) is insufficient against modern DDoS attacks that can exceed 100 Gbps, as noted in industry reports. Migrating to a cloud-based DDoS protection service that scales to 200 Gbps directly reduces the risk to a level aligned with the company's moderate risk appetite for availability, despite the 40% cost increase. The business concern about cost is secondary to the necessity of mitigating a risk that could cause catastrophic revenue loss, and the cloud service provides elastic scalability that an on-premise upgrade cannot match.

Exam trap

The trap here is that candidates may choose Option D (upgrading to 50 Gbps) because it appears to be a cost-effective risk reduction, but they overlook that it still leaves the organization exposed to attacks exceeding 50 Gbps, which is a common scenario given the trend toward 100+ Gbps attacks, and fails to meet the moderate risk appetite for availability.

How to eliminate wrong answers

Option A is wrong because transferring risk via business interruption insurance does not prevent downtime or revenue loss; it only provides financial compensation after the fact, which does not address the company's moderate risk appetite for availability or the operational impact of repeated outages. Option B is wrong because accepting the risk ignores the clear trend of increasing attack volumes (up to 100+ Gbps) and the fact that the company has already suffered significant downtime and revenue loss from three attacks; the high cost of mitigation does not justify continued exposure when the risk exceeds the risk appetite. Option D is wrong because upgrading the on-premise appliance to 50 Gbps is still far below the 100+ Gbps attack volumes reported, leaving the company vulnerable to larger attacks; it also lacks the elastic scaling and global scrubbing capacity of a cloud-based service, making it an inadequate risk reduction measure.

649
MCQmedium

A company has identified a risk of data breach due to weak encryption. The current controls include encryption at rest but not in transit. The risk assessment team calculates inherent risk as high and residual risk as high. What should the team recommend FIRST?

A.Implement encryption in transit to reduce likelihood
B.Transfer the risk by purchasing cyber insurance
C.Avoid the risk by discontinuing data transmission
D.Accept the risk because it is already high
AnswerA

Implementing encryption in transit directly addresses the missing control identified in the stem, reducing the likelihood component of inherent risk. Since encryption at rest already exists, adding transport-layer protection (TLS) closes the gap that keeps residual risk high, lowering it below the organisation's risk appetite before considering transfer or avoidance.

Why this answer

The risk assessment team should first recommend implementing encryption in transit because the current controls only address data at rest, leaving data vulnerable during transmission. Since both inherent and residual risks are high, the most direct and effective control to reduce likelihood is to apply a technical safeguard like TLS 1.3 for data in transit, which directly addresses the identified gap.

Exam trap

The trap here is that candidates may think accepting high residual risk is acceptable if inherent risk is also high, but CRISC emphasizes that risk should be reduced to an acceptable level using controls before considering acceptance or transfer.

How to eliminate wrong answers

Option B is wrong because transferring risk via cyber insurance does not reduce the likelihood or impact of a data breach; it only provides financial compensation after an incident, which is not a first-line recommendation when a technical control is missing. Option C is wrong because avoiding the risk by discontinuing data transmission is an extreme measure that would halt business operations, and it is not the first recommendation when a feasible technical control (encryption in transit) exists. Option D is wrong because accepting a high residual risk when a cost-effective control is available violates the principle of risk reduction; acceptance should only be considered after all reasonable mitigation options have been evaluated.

650
Multi-Selectmedium

An organization recently experienced a significant security incident that was not detected by existing monitoring controls. The risk team is reviewing the effectiveness of the control monitoring framework. Which THREE of the following are key factors that should be evaluated to improve detection capabilities?

Select 3 answers
A.The correlation rules between different monitoring tools
B.The existence of an incident response plan
C.The timeliness of data collection from sources
D.The level of automation in incident response
E.The coverage of monitoring across all high-risk assets
AnswersA, C, E

Correlation reduces false positives and identifies complex patterns.

Why this answer

Correlation rules between different monitoring tools (Option A) are critical because they define how alerts from disparate sources (e.g., SIEM, IDS/IPS, endpoint detection) are combined to identify complex attack patterns. Without well-tuned correlation rules, the organization may miss multi-stage attacks that span multiple systems, as no single tool alone provides the full picture. Evaluating and refining these rules directly improves the detection of incidents that existing controls failed to catch.

Exam trap

ISACA often tests the distinction between detection improvement and response improvement; the trap here is that candidates confuse the incident response plan (Option B) or automation (Option D) with detection capabilities, when they are actually post-detection activities that do not address why the incident was missed in the first place.

651
Multi-Selectmedium

An organization is evaluating whether to accept a risk. Which TWO conditions must be met for risk acceptance to be appropriate?

Select 2 answers
A.The risk can be transferred to an insurer
B.The risk owner formally documents and accepts the risk
C.The risk is high but unavoidable
D.A cost-effective control is available
E.The risk is within the organization's risk appetite
AnswersB, E

Formal documentation by the risk owner creates the accountability trail that risk acceptance demands: the owner with authority over the affected asset acknowledges the residual risk in writing. This satisfies the stem's requirement that acceptance be a deliberate, authorised decision rather than an unrecorded default, enabling later audit and review.

Why this answer

Risk acceptance is only appropriate when the risk owner formally documents and accepts the risk (B), because accountability for the residual risk must be explicitly acknowledged by the party who owns it, ensuring the decision is authorized and auditable. It is also required that the risk falls within the organization's risk appetite (E), since accepting a risk that exceeds the defined tolerance would violate the risk management framework and require treatment instead. Options A, C, and D do not justify acceptance: transferring risk to an insurer (A) is risk transference, not acceptance; a high but unavoidable risk (C) still needs to be within appetite and formally accepted, and 'unavoidable' alone is not a valid criterion; and having a cost-effective control available (D) argues for risk mitigation rather than acceptance.

Exam trap

CRISC often tests the confusion between risk acceptance and risk transference — candidates see 'insurer' and think it's part of acceptance, but insurance is a separate treatment option that shifts financial impact.

652
MCQmedium

A risk practitioner at a healthcare payer is reviewing the organization's disaster recovery (DR) strategy for its core claims adjudication system. The business owner has stated that the maximum tolerable downtime is 4 hours, but the current DR plan relies on restoring from nightly tape backups, which would take at least 30 hours. Which of the following is the MOST appropriate action for the risk practitioner to take FIRST?

A.Perform a full business impact analysis to determine whether the 4-hour maximum tolerable downtime is still valid.
B.Document the gap between the recovery time objective and the achievable recovery time, and escalate it to the business owner and IT leadership for a risk decision.
C.Update the DR plan to state that the recovery time objective is 30 hours, because that is what the current infrastructure can achieve.
D.Immediately purchase a real-time replication solution to meet the 4-hour requirement and inform the business owner after implementation.
AnswerB

The practitioner's role is to identify and communicate the misalignment between the stated maximum tolerable downtime and the actual recovery capability, then escalate for a formal risk decision. Documenting and escalating ensures the business owner understands the residual risk and can approve, mitigate, or transfer it, which is the core of risk governance.

Why this answer

The core issue is a mismatch between the business-required recovery time objective and what the current DR strategy can deliver. The risk practitioner must first document and escalate this gap so the business owner can make an informed risk decision. Directly purchasing technology or rewriting the objective without approval would circumvent governance.

Exam trap

The trap here is assuming the risk practitioner should immediately fix the technical shortfall or adjust the objective, rather than escalate the risk for a business decision.

653
MCQmedium

A retail company's risk practitioner is reviewing how risks flow between the enterprise risk management function and the IT risk function. The CISO argues that IT risks should be reported only within IT, while the CRO wants material IT risks elevated to the enterprise register. Which CRISC principle BEST resolves this disagreement?

A.Both registers should be maintained independently and reconciled only during the annual external audit.
B.IT risk is a subset of enterprise risk and material IT risks should be integrated into enterprise risk reporting.
C.IT risks should remain under the CISO because only technical staff can interpret their likelihood.
D.The CRO should take over all IT risk analysis to ensure consistent methodology across the enterprise.
AnswerB

CRISC treats IT risk as a component of enterprise risk, not a separate silo. Risks that threaten business objectives must flow into enterprise reporting so leadership sees the full exposure picture. Keeping material IT risks inside IT hides their business impact from the board and breaks the linkage between technology failures and strategic outcomes, which undermines integrated risk management.

Why this answer

The correct principle is that IT risk is a subset of enterprise risk and material IT risks belong in enterprise reporting. This ensures business leadership sees how technology exposures affect objectives and can allocate resources and set tolerance accordingly. IT still performs the technical analysis, but the results flow upward so governance and strategy reflect the full risk landscape rather than a fragmented view.

Exam trap

The trap here is treating IT risk as a separate discipline owned solely by security, when CRISC frames it as an integral part of enterprise risk that must be reported at the business level.

654
Drag & Dropmedium

Put the steps for developing an information security policy in order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Policy development starts with gap analysis, drafting, stakeholder review, approval, and communication.

655
Multi-Selectmedium

A hospital network is selecting key risk indicators (KRIs) for its electronic health record (EHR) availability risk. The risk committee wants indicators that will provide early warning before an outage affects patient care. Which TWO of the following are the most appropriate KRIs for this purpose? (Choose two.)

Select 2 answers
A.Total number of change requests submitted for the EHR environment during the past quarter
B.Percentage of critical EHR servers whose monitoring alerts were unacknowledged beyond the response threshold
C.Mean time between failures (MTBF) of the EHR application servers over the trailing twelve months
D.Percentage of EHR database replication lag exceeding the defined threshold over the past 24 hours
E.Number of EHR downtime minutes recorded during the previous quarter
AnswersB, D

Unacknowledged critical alerts indicate that the operations team is not responding to emerging failures within the agreed time. This is a leading indicator because it predicts that a real incident may go undetected or untreated long enough to cause downtime. Measuring the percentage beyond threshold gives a normalized, trendable KRI that directly reflects operational readiness to protect EHR availability.

Why this answer

Replication lag exceeding threshold and unacknowledged critical alerts are leading indicators that measure current degradation of resilience and response capability, giving the risk committee time to intervene before patients are affected. Downtime minutes, long-term MTBF, and raw change volume describe past events or activity levels without predictive value for imminent EHR availability risk, so they do not serve as early-warning KRIs.

Exam trap

The trap here is choosing familiar operational metrics such as downtime minutes or change counts, which are lagging or activity-based, instead of forward-looking indicators of degrading resilience.

656
Multi-Selectmedium

A risk manager is evaluating IoT device risks for a smart building project. Which TWO of the following are significant IoT security risks?

Select 2 answers
A.Data sovereignty compliance
B.Quantum computing threat to cryptography
C.Vendor lock-in
D.Firmware update challenges
E.Expanded attack surface due to many connected devices
AnswersD, E

Many IoT devices lack automated update mechanisms, and firmware patches are often manual, intermittent or unsupported once vendors end lifecycles. Unpatched firmware leaves known vulnerabilities exploitable for years, a structural weakness distinct from conventional IT patching.

Why this answer

Option D is correct because IoT devices often lack a reliable mechanism for secure firmware updates: many have limited processing power, no signed-update verification, or no supported update channel, leaving known vulnerabilities unpatched and devices exploitable over their lifetime. Option E is correct because a smart building connects potentially thousands of heterogeneous sensors, actuators, and controllers, each exposing network interfaces and services, which dramatically expands the attack surface and gives adversaries more entry points and lateral-movement paths. The remaining options do not belong: data sovereignty compliance (A) is a legal/regulatory concern rather than a technical IoT security risk, quantum computing (B) is a long-term cryptographic threat affecting all IT rather than a significant near-term IoT-specific risk, and vendor lock-in (C) is a business/procurement issue, not a security vulnerability.

Exam trap

The trap is selecting broad governance or emerging-technology risks (data sovereignty, quantum threat, vendor lock-in) as IoT-specific security risks — CRISC tests whether you can distinguish inherent technical IoT vulnerabilities (firmware updates, attack surface) from general enterprise risks that apply to any technology.

657
MCQhard

A large bank has implemented a sophisticated risk and control monitoring system with multiple dashboards and automated reporting for key risk indicators (KRIs). However, the board of directors has been receiving conflicting KRI reports from different business units (e.g., retail banking, corporate lending, and wealth management). For example, the fraud KRI shows a high risk in retail but low risk in wealth management, yet both units use the same underlying data source. The chief risk officer (CRO) is concerned that the board is losing confidence in the risk reporting. An investigation reveals that each business unit defines and calculates KRIs differently, uses different thresholds, and reports on different schedules. What is the most likely root cause and the best remediation?

A.The reporting frequency is inadequate; monthly reports should be weekly.
B.The data sources for KRIs are inconsistent across business units.
C.The board members are misinterpreting the KRI reports due to lack of training.
D.The KRI definitions and calculation methods are not standardized across business units.
AnswerD

Divergent KRI definitions, calculation methods, thresholds and reporting schedules across business units produce inconsistent figures from identical source data, destroying board confidence. Standardising definitions, formulas and thresholds centrally, with a unified reporting cadence, restores comparability and credibility of enterprise risk reporting.

Why this answer

The root cause of conflicting KRI reports is that each business unit defines and calculates KRIs differently, uses different thresholds, and reports on different schedules. This lack of standardization leads to inconsistent risk measurements, even when using the same underlying data source. The best remediation is to standardize KRI definitions, calculation methods, thresholds, and reporting frequencies across all business units to ensure consistent and comparable risk reporting to the board.

Exam trap

CRISC often tests the misconception that reporting frequency or board training is the root cause of inconsistent risk reporting, when the real issue is lack of standardized KRI definitions and calculation methodologies — the exam expects you to identify governance and standardization gaps.

How to eliminate wrong answers

Option A is wrong because increasing reporting frequency from monthly to weekly does not address the inconsistency in definitions and calculations; it would only produce conflicting reports more often. Option B is wrong because the scenario explicitly states that both units use the same underlying data source, so inconsistent data sources are not the issue. Option C is wrong because while board training could help interpretation, the core problem is that the reports themselves are inconsistent due to different definitions, not that the board misunderstands them.

658
MCQmedium

Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?

A.Percentage of systems with missing critical patches
B.Number of audit findings resolved
C.Number of security incidents this quarter
D.Total cost of security incidents
AnswerA

Missing critical patches measure a condition that precedes and predicts future loss events, making them a leading indicator. Lagging KRIs, by contrast, record incidents already realised, such as breach counts or downtime hours, so they cannot drive preventive action.

Why this answer

A leading Key Risk Indicator (KRI) predicts future risk events by measuring conditions that precede incidents. Missing critical patches on systems directly indicate a higher likelihood of exploitation, making it a leading indicator. In contrast, lagging KRIs like incident counts or costs measure outcomes after the fact.

Exam trap

The trap here is confusing leading indicators (which predict risk) with lagging indicators (which measure past events), leading candidates to pick options like the number of security incidents or audit findings resolved, which are reactive rather than predictive.

How to eliminate wrong answers

Option B is wrong because the number of audit findings resolved is a lagging indicator that measures remediation activity after issues have been identified, not a predictor of future risk. Option C is wrong because the number of security incidents this quarter is a lagging KRI that reports past events, not a leading indicator of impending risk. Option D is wrong because the total cost of security incidents is a lagging financial metric that quantifies damage after incidents occur, offering no forward-looking risk prediction.

659
MCQhard

An organization wants to promote a risk-aware culture. Which initiative is most effective in encouraging employees to report security incidents without fear?

A.Conducting annual security awareness training
B.Implementing a no-blame incident reporting policy
C.Increasing penalties for policy violations
D.Publishing names of employees who caused incidents
AnswerB

A no-blame policy removes fear of punitive consequences, directly addressing the psychological barrier that suppresses incident reporting. This encourages early disclosure, giving the organisation faster visibility of events and strengthening its overall risk-aware culture more effectively than awareness campaigns or mandatory training alone.

Why this answer

A no-blame incident reporting policy removes the fear of punishment for reporting mistakes, which is the single most effective cultural lever for increasing incident disclosure. Research (e.g., from aviation safety and DevOps postmortems) shows that psychological safety drives reporting rates, and reporting is the prerequisite for detecting and responding to incidents. This directly addresses the 'without fear' requirement in the question.

Exam trap

CRISC often tests the distinction between awareness (knowledge) and culture (behavior) — candidates pick training because it sounds proactive, but the question specifically asks about removing fear, which only a no-blame policy achieves.

How to eliminate wrong answers

Option A is wrong because annual awareness training improves knowledge but does not address the fear of retaliation that suppresses reporting. Option C is wrong because increasing penalties for policy violations does the opposite — it raises the perceived cost of reporting and drives incidents underground. Option D is wrong because publishing names of employees who caused incidents is a punitive, shaming practice that destroys psychological safety and guarantees under-reporting.

660
Multi-Selectmedium

A retail company is launching a new mobile payment application. The risk practitioner is identifying risk response options for the risk of payment fraud. Which TWO of the following are examples of risk mitigation controls? (Choose two.)

Select 2 answers
A.Tokenization of payment card data
B.Implementing real-time fraud detection algorithms
C.Accepting the risk of fraud and monitoring it quarterly
D.Deciding not to offer mobile payments in certain countries
E.Purchasing cyber insurance to cover fraud losses
AnswersA, B

Tokenization replaces sensitive card data with non-sensitive tokens, reducing the impact of a data breach. It is a preventive control that mitigates the risk of payment fraud by making stolen tokens useless to attackers. This is a classic risk mitigation technique that reduces both likelihood and impact.

Why this answer

Tokenization and real-time fraud detection are both mitigation controls because they actively reduce the risk of payment fraud. Tokenization minimizes the value of stolen data, while fraud detection identifies and blocks suspicious transactions. The other options represent risk transfer, risk avoidance, and risk acceptance, which do not reduce the inherent risk.

Exam trap

The trap here is confusing risk transfer or avoidance with mitigation; controls that reduce likelihood or impact are mitigation, while insurance and avoidance are different strategies.

661
MCQhard

A risk practitioner is connecting a risk scenario to business impact. The scenario involves a ransomware attack that encrypts critical financial systems, resulting in a two-week outage. Which of the following is the MOST appropriate business impact category?

A.Regulatory penalty
B.Reputational damage
C.Operational disruption
D.Financial loss
AnswerC

A two-week outage of critical financial systems halts business processes, making operational disruption the fitting impact category. It captures the inability to execute transactions and services, distinct from financial, compliance or reputational impact, though secondary financial losses may follow.

Why this answer

A two-week outage of critical financial systems directly halts business processes, which is the definition of operational disruption — the inability to execute normal business operations. While financial loss and reputational damage may follow, the primary and most direct business impact category for an outage that stops systems from functioning is operational disruption. CRISC expects the practitioner to map the scenario's immediate effect to the correct impact category.

Exam trap

CRISC often tests the distinction between a direct operational impact and its downstream financial or reputational consequences, so candidates pick 'financial loss' because ransomware sounds costly rather than identifying the immediate operational disruption.

How to eliminate wrong answers

Option A is wrong because a regulatory penalty would require a compliance violation or reporting failure, which is not described in the scenario. Option B is wrong because reputational damage is a secondary, downstream consequence of customer or public perception, not the direct impact of systems being down. Option D is wrong because financial loss is a consequence that may result from the outage, but the scenario's core impact — systems being unavailable for two weeks — is operational, and CRISC distinguishes the direct operational impact from its financial fallout.

662
Multi-Selectmedium

An organization is planning to adopt post-quantum cryptography. Which TWO considerations are MOST important for migration planning?

Select 2 answers
A.Evaluate the cost of quantum computers
B.Assess the cryptographic agility of current systems
C.Identify systems that need long-term confidentiality (e.g., classified data)
D.Train employees on quantum physics
E.Purchase quantum-resistant hardware immediately
AnswersB, C

Cryptographic agility determines how quickly algorithms can be swapped without redesigning applications or protocols. Assessing it exposes hard-coded cryptography and vendor dependencies, so migration planning can schedule remediation of inflexible systems before post-quantum standards are mandated.

Why this answer

Option B is correct because cryptographic agility—the ability of systems to swap algorithms, keys, and protocols without major redesign—is essential for migrating to post-quantum cryptography (PQC), since standards such as ML-KEM (FIPS 203) and ML-DSA (FIPS 204) will continue to evolve and hybrid deployments (e.g., X25519+ML-KEM) must be supported during transition. Option C is correct because systems protecting data with long confidentiality lifetimes (classified, health, financial records) are exposed to 'harvest now, decrypt later' attacks, so migration priority must be driven by how long the data must remain secret versus when a cryptographically relevant quantum computer (CRQC) is expected. Option A is not a migration-planning consideration because the cost of quantum computers is irrelevant to an organization's own cryptographic inventory and transition roadmap.

Option D is unnecessary because adopting PQC requires cryptographic and IT expertise, not training staff in quantum physics. Option E is premature because standardized PQC algorithms run on existing classical hardware via software/firmware updates, so buying 'quantum-resistant hardware' immediately is neither required nor a sound first step.

Exam trap

CRISC often tests the distinction between strategic risk-planning considerations (crypto agility, data lifetime) and tactical or irrelevant distractors (buying hardware, training on physics) — candidates who pick the 'most action-oriented' answer instead of the 'most risk-relevant' answer get it wrong.

663
MCQhard

A risk practitioner is conducting a threat modeling exercise for a new cloud-based application using the STRIDE methodology. Which of the following is the PRIMARY benefit of using STRIDE over a simple checklist?

A.It requires less expertise to perform
B.It automatically quantifies risk levels
C.It ensures consistent application of controls
D.It identifies threats by category, reducing the chance of missing key threat types
AnswerD

STRIDE structures threat discovery around six defined categories — spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege — so analysts systematically cover each, unlike an unstructured checklist that may omit entire threat classes.

Why this answer

The STRIDE methodology categorizes threats into six specific types (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). This structured approach ensures that the threat modeling exercise systematically covers each category, reducing the likelihood of overlooking entire classes of threats that a simple checklist might miss. For a cloud-based application, this is critical because threats like elevation of privilege or information disclosure can manifest in unique ways across shared infrastructure, and STRIDE forces the practitioner to consider each category explicitly.

Exam trap

The trap here is that candidates often confuse a structured methodology like STRIDE with a simple checklist, assuming any structured approach automatically ensures control consistency or risk quantification, when in fact STRIDE's primary benefit is its categorical coverage that reduces blind spots.

How to eliminate wrong answers

Option A is wrong because STRIDE requires a solid understanding of each threat category and how to map them to system components, often demanding more expertise than a simple checklist. Option B is wrong because STRIDE is a qualitative categorization framework and does not automatically quantify risk levels; risk quantification requires separate analysis (e.g., using CVSS scores or likelihood/impact ratings). Option C is wrong because while STRIDE can promote consistency in identifying threat types, it does not ensure consistent application of controls; controls are designed and implemented independently based on the identified threats.

664
MCQmedium

A financial services firm is conducting an IT risk assessment for its customer-facing mobile banking application. The risk team has identified that the application's authentication mechanism relies on a third-party single sign-on (SSO) provider. During a workshop, the risk owner states that the likelihood of a breach is low because the SSO provider has a strong security reputation. However, the risk team notes that no service-level agreement (SLA) exists with the provider. Which risk factor is MOST directly affected by the absence of an SLA, and how should the risk practitioner proceed?

A.The residual risk of the mobile application is unchanged, so the risk practitioner should focus on internal controls only.
B.The inherent risk of the SSO provider is reduced, so the risk practitioner should document the risk as acceptable.
C.The third-party dependency risk is elevated, and the risk practitioner should recommend negotiating an SLA with the SSO provider.
D.The risk appetite for the mobile application is exceeded, so the risk practitioner should immediately terminate the SSO contract.
AnswerC

The lack of an SLA increases third-party dependency risk because there are no contractual obligations for availability, security, or incident response. The risk practitioner should recommend negotiating an SLA to define performance and security requirements, which helps mitigate the risk. This aligns with CRISC practices for vendor risk management. The other options either wrongly accept the risk or misidentify the risk factor.

Why this answer

The absence of an SLA with a critical SSO provider introduces third-party dependency risk because there are no contractual guarantees for security, availability, or incident response. The risk practitioner should recognize this as an elevated risk and recommend negotiating an SLA to establish obligations and controls. This is a key part of IT risk assessment, where third-party relationships must be evaluated and managed.

The correct answer focuses on the specific risk factor and the appropriate next step.

Exam trap

The trap here is assuming that a reputable vendor automatically reduces risk without contractual assurances, overlooking the need for an SLA to manage third-party dependency risk.

665
MCQhard

A company faces a risk of data loss due to untrained staff. They implement mandatory training and quarterly phishing simulations. This is:

A.Risk Avoidance
B.Risk Acceptance
C.Risk Mitigation
D.Risk Transfer
AnswerC

Training and phishing simulations reduce the likelihood of staff falling for attacks, lowering the risk's expected impact rather than avoiding, transferring or accepting it. The controls target the human cause directly, so the treatment is risk mitigation.

Why this answer

Mandatory training and quarterly phishing simulations are proactive controls that reduce the likelihood and impact of data loss from human error. This directly aligns with risk mitigation, which seeks to lower residual risk to an acceptable level without eliminating the activity or transferring the financial burden. The controls target the root cause (untrained staff) by improving security awareness and testing behavioral response.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk avoidance' because they think training eliminates the risk entirely, but mitigation only reduces it, while avoidance would require stopping the use of email or data processing altogether.

How to eliminate wrong answers

Option A is wrong because risk avoidance would mean ceasing the activity that introduces the risk (e.g., not using email or not storing sensitive data), not training staff. Option B is wrong because risk acceptance involves acknowledging the risk and taking no action to reduce it, whereas the company is actively implementing controls. Option D is wrong because risk transfer shifts the financial impact to a third party (e.g., cyber insurance or outsourcing), not internal training and simulations.

666
MCQeasy

A newly hired risk analyst is asked to classify the organization's risk universe before any assessment begins. The analyst lists categories such as strategic, operational, financial, compliance, and reputational. Which of the following BEST explains why this categorization is useful for IT risk identification?

A.It provides a structured lens that helps ensure risks across business functions are surfaced and compared, and it supports consistent ownership and reporting.
B.It replaces the need for a risk register because each category can be tracked in a separate spreadsheet.
C.It lets the analyst assign a single numeric risk score to the entire organization without assessing individual risks.
D.It guarantees that every risk will be assigned to exactly one category, eliminating duplicate register entries.
AnswerA

A defined risk universe gives the practitioner a checklist-like structure so that identification is not limited to whatever area is currently in focus. It enables consistent language, ownership assignment, and aggregation for leadership reporting. ISACA guidance treats the risk universe as the foundation for scoping assessments, so categorizing early reduces the chance that an entire domain, such as third-party or compliance risk, is overlooked until an incident exposes it.

Why this answer

Defining a risk universe by category gives the practitioner a structured way to surface risks from every function, apply consistent terminology, and roll results up for governance. It prevents blind spots and supports ownership and reporting. The alternatives either mistake categories for the register itself, assume unrealistic exclusivity, or skip the underlying assessments that make aggregation meaningful.

Exam trap

The trap here is assuming risk categories are mutually exclusive buckets, when in reality one event commonly spans several categories at once.

667
MCQmedium

An organization is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. Which of the following is the PRIMARY risk introduced by this IT/OT convergence?

A.Reduced availability of OT systems
B.Higher cost of network equipment
C.Expansion of the attack surface to OT systems
D.Increased complexity of data analytics
AnswerC

Connecting ICS to the corporate network exposes OT devices to enterprise-originated threats, expanding the attack surface. Previously isolated industrial protocols and controllers become reachable, enabling lateral movement from compromised corporate endpoints into operational technology, which directly satisfies the stem's IT/OT convergence scenario and its primary risk.

Why this answer

Connecting ICS/OT systems to the corporate IT network exposes previously isolated OT devices to the corporate attack surface, allowing threats that compromise IT to pivot into OT. This expansion of the attack surface is the primary risk of IT/OT convergence because OT systems often lack security controls and cannot be easily patched. The other options are secondary or not risks at all.

Exam trap

The trap is selecting a consequence (reduced availability) or a non-risk (cost, complexity) instead of the root risk — the expansion of the attack surface to OT systems.

How to eliminate wrong answers

Option A is wrong because reduced availability is a potential consequence of a successful attack, not the primary risk introduced by convergence itself; the primary risk is exposure. Option B is wrong because higher equipment cost is a financial consideration, not a security risk, and is not the primary risk of IT/OT convergence. Option D is wrong because increased complexity of data analytics is an operational challenge, not the primary security risk; the question asks for the PRIMARY risk, which is attack surface expansion.

668
MCQhard

An organization's risk committee is reviewing a consolidated IT risk report before a board meeting. The report shows that a critical payment system has a residual risk rating above tolerance, but the remediation project is not scheduled to complete for nine months due to vendor dependencies. The committee must decide how to report this to the board. Which of the following is the MOST appropriate action?

A.Delay the board report until the remediation project completes so the report shows only risks within tolerance.
B.Recommend that the board formally accept the risk above tolerance until remediation completes, documenting the rationale and interim compensating controls.
C.Report the risk as being addressed by the remediation project and omit the completion timeline to avoid alarming the board.
D.Reclassify the residual risk as inherent risk so the rating falls within the board-approved tolerance threshold.
AnswerB

When residual risk exceeds tolerance and cannot be remediated within the desired timeframe, the governing body must formally accept it with documented rationale. Presenting the timeline, the reason for the delay, and any compensating controls gives the board the information needed to make an informed acceptance decision. This preserves transparency and accountability.

Why this answer

Residual risk above tolerance that cannot be remediated promptly requires formal acceptance by the governing body. The committee should present the timeline, the vendor dependency, and any compensating controls so the board can make an informed decision. Concealing the timeline, relabeling the risk, or delaying the report all deprive the board of information it needs and violate reporting integrity.

Exam trap

The trap here is assuming that an active remediation project removes the need for board involvement, when risk above tolerance still requires formal acceptance until the fix is complete.

669
MCQhard

A multinational corporation has a risk register entry for a supplier that provides critical components. The supplier has a history of financial instability, and the risk of supply chain disruption is high. The risk owner decides to dual-source the components from a second supplier. Which risk response strategy does this represent, and what is the primary benefit?

A.Risk transfer, because the risk is shared with the second supplier
B.Risk avoidance, because the organization avoids relying on a single supplier
C.Risk acceptance, because the organization accepts the supplier risk but adds a backup
D.Risk mitigation, because it reduces the likelihood of disruption
AnswerD

Dual-sourcing is a mitigation strategy that reduces the likelihood and impact of a supply chain disruption by ensuring an alternative source is available. It does not eliminate the risk but lowers the probability of a total shutdown if one supplier fails. This is a classic example of risk mitigation through redundancy and diversification.

Why this answer

Dual-sourcing is a risk mitigation technique that reduces the likelihood of supply chain disruption by providing an alternative source. It does not transfer, avoid, or accept the risk; it actively reduces it. The primary benefit is increased resilience and reduced dependency on a single supplier.

Exam trap

The trap here is confusing dual-sourcing with risk transfer because a second supplier is involved, but the risk is not shifted financially.

670
MCQhard

An energy utility is assessing risk to its industrial control system (ICS) network. The risk analyst discovers that the same risk scenario is rated as high risk by the operations team using a qualitative heat map and as low risk by the enterprise risk team using a quantitative model. Both teams used the same underlying data. Which of the following is the MOST likely explanation for the discrepancy?

A.The two methods apply different assumptions about impact magnitude, time horizon, and risk tolerance thresholds.
B.The operations team used an incorrect likelihood scale when rating the scenario.
C.The operations team lacks the technical expertise to assess ICS risk accurately.
D.The enterprise risk team failed to include the control environment in its quantitative model.
AnswerA

Qualitative heat maps rely on ordinal scales and expert judgment, so a scenario with severe but rare consequences may land in a high cell because impact dominates. Quantitative models average frequency and loss over a defined period, which can dilute rare catastrophic events into a lower expected value. Different time horizons and tolerance thresholds compound the gap, so the same data yields divergent ratings without either team being wrong.

Why this answer

Qualitative and quantitative methods process the same data through different lenses. Heat maps use ordinal scales where expert judgment can let a severe impact dominate a low likelihood, producing a high rating. Quantitative models compute expected values over a defined period, which mathematically compresses rare catastrophic events.

Differences in assumed impact magnitude, time horizon, and tolerance thresholds therefore explain the divergence without implying error by either team or a data omission.

Exam trap

The trap here is assuming one team made a mistake, when the divergence is an expected consequence of ordinal judgment versus expected-value mathematics applied to rare, high-consequence events.

671
MCQmedium

In a quantitative risk analysis using FAIR, which of the following best represents Loss Magnitude (LM)?

A.Primary Loss + Secondary Loss
B.Single Loss Expectancy (SLE)
C.Threat Event Frequency × Vulnerability
D.Annualized Loss Expectancy (ALE)
AnswerA

FAIR defines Loss Magnitude as the total impact of a risk event, comprising primary loss (direct costs such as response and replacement) plus secondary loss (consequential costs such as fines, reputation damage and legal fees). Summing both satisfies the stem's requirement for the complete quantitative loss figure.

Why this answer

In FAIR, Loss Magnitude (LM) is the sum of Primary Loss (direct costs) and Secondary Loss (indirect costs) resulting from a loss event.

672
MCQeasy

Which of the following is the primary purpose of a risk and control monitoring program?

A.To identify new risks as they emerge.
B.To provide ongoing assurance that controls are operating effectively.
C.To reduce the frequency of internal audits.
D.To calculate key risk indicators.
AnswerB

Risk and control monitoring delivers continuous, ongoing assurance that controls operate effectively over time, detecting degradation between periodic assessments. This satisfies the stem's primary purpose by focusing on sustained control effectiveness rather than one-off evaluation or risk identification.

Why this answer

The primary purpose of a risk and control monitoring program is to provide ongoing assurance that controls are operating effectively. This is achieved through continuous or periodic testing, observation, and analysis of control activities to confirm they are designed correctly and functioning as intended to mitigate risks. Without this ongoing assurance, an organization cannot reliably know whether its risk responses remain effective over time.

Exam trap

The trap here is that candidates often confuse the primary purpose of a monitoring program (ongoing assurance) with its components or secondary benefits, such as identifying new risks (A) or calculating KRIs (D), leading them to select a narrower or derivative function instead of the core objective.

How to eliminate wrong answers

Option A is wrong because identifying new risks as they emerge is the purpose of a risk identification process or a risk assessment, not the primary goal of a control monitoring program; monitoring focuses on existing controls, not discovering new risks. Option C is wrong because reducing the frequency of internal audits is a potential secondary benefit of a strong monitoring program, but it is not the primary purpose; the core objective is assurance on control effectiveness, not audit reduction. Option D is wrong because calculating key risk indicators (KRIs) is a specific monitoring technique that may be used within a monitoring program, but it is not the primary purpose; the program's goal is broader assurance, not just the calculation of metrics.

673
MCQmedium

An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?

A.The application does not support mobile devices
B.The application development timeline is aggressive
C.The application uses the latest JavaScript framework
D.The application exposes sensitive customer data through APIs without proper authentication
AnswerD

Exposing sensitive customer data through unauthenticated APIs directly threatens confidentiality, the core risk for a customer-facing application. Microsoft Entra ID authentication controls would mitigate this, but the ARB's primary concern is whether the architecture enforces authentication at all, satisfying the stem's focus on identifying the foremost architectural risk.

Why this answer

The primary risk an Architecture Review Board should consider is the exposure of sensitive customer data through unauthenticated APIs, because this represents a direct, high-impact security and compliance risk (data breach, regulatory penalties, reputational damage). ARBs focus on risks that threaten confidentiality, integrity, and availability of critical assets, and unauthenticated API access to sensitive data is a classic OWASP API Security Top 10 issue.

Exam trap

CRISC often tests the distinction between business/functional risks and security/compliance risks; candidates pick timeline or technology-choice options because they sound like 'architecture' concerns, missing that the ARB prioritizes risks to sensitive data and regulatory posture.

How to eliminate wrong answers

Option A is wrong because lack of mobile support is a business/functional limitation, not a primary security or architectural risk, and it does not threaten data confidentiality or regulatory compliance. Option B is wrong because an aggressive timeline is a project-management risk that may affect quality, but it is not the primary architectural risk the ARB should prioritize over a direct data-exposure flaw. Option C is wrong because using the latest JavaScript framework is a technology-choice consideration (potential support/maturity risk) but not a primary risk to sensitive data; it is a preference, not a vulnerability.

674
MCQeasy

For a risk with very low likelihood and low impact, what is the typical risk response?

A.Mitigate
B.Transfer
C.Avoid
D.Accept
AnswerD

Acceptance suits risks whose likelihood and impact both sit at the lowest band, where treatment cost exceeds expected loss. The organisation retains the risk knowingly, monitors it, and allocates no further controls, which is proportionate given the negligible exposure.

Why this answer

When a risk has very low likelihood and low impact, the cost of implementing controls (mitigation, transfer, or avoidance) typically exceeds the potential loss. Accepting the risk is the most cost-effective response, as it acknowledges the residual risk without active treatment. This aligns with the principle that risk acceptance is appropriate for risks below the organization's risk appetite threshold.

Exam trap

The trap here is that candidates mistakenly apply mitigation or transfer to all risks, failing to recognize that acceptance is the default response for low-likelihood, low-impact risks where the cost of treatment exceeds the potential loss.

How to eliminate wrong answers

Option A is wrong because mitigation involves reducing likelihood or impact through controls, which is unnecessary and wasteful for a risk with negligible potential loss. Option B is wrong because transfer (e.g., insurance or outsourcing) incurs premium costs or contractual overhead that outweighs the trivial exposure. Option C is wrong because avoidance (e.g., discontinuing the activity) would eliminate a low-value risk at the cost of losing business functionality or opportunity, which is disproportionate.

675
MCQmedium

An organization is considering cyber insurance to transfer residual risk. Which factor would MOST significantly influence the premium?

A.Industry sector
B.Company revenue
C.Security controls and incident history
D.Number of employees
AnswerC

Insurers price premiums on the likelihood and cost of a claim, so the maturity of implemented security controls and prior incident history directly determine the assessed loss expectancy. Stronger controls and a clean record lower the residual risk being transferred, reducing the premium.

Why this answer

Cyber insurance premiums are most significantly influenced by the organization's security controls and incident history, because insurers underwrite based on the likelihood and severity of a claim. Strong controls (MFA, EDR, backups, segmentation) and a clean incident history reduce perceived risk and lower premiums; poor controls and prior breaches raise them.

Exam trap

CRISC often tests the distinction between factors that affect policy size (revenue, employees) and factors that affect the risk rate (controls, incident history) — candidates who pick revenue or industry as 'most significant' miss that underwriting is fundamentally about control maturity and claims experience.

How to eliminate wrong answers

Option A is wrong because while industry sector affects risk appetite and available coverage, it is a secondary factor — two companies in the same sector can have vastly different premiums based on their controls and claims history. Option B is wrong because company revenue affects the size of the policy (limits) and thus the absolute premium, but not the rate or risk assessment as significantly as controls and incident history. Option D is wrong because the number of employees is a proxy for scale and potential exposure, but it is not the most significant underwriting factor — a small company with no controls can pay more per employee than a large company with mature security.

Page 8

Page 9 of 15

Page 10