CRISC Risk Response and Reporting Practice Question
An IT risk manager is developing KRIs for a critical application. Which TWO of the following are leading indicators that the risk level may be increasing? (Select TWO)
⚠ Common exam trap
CRISC often tests the distinction between leading and lagging indicators, and candidates frequently select incident counts or audit findings because they sound risk-related, missing that these are backward-looking outcomes rather than predictive signals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Average patch lag time increasing
Option A (Average patch lag time increasing) is correct because a growing delay between patch release and deployment is a leading indicator: it signals accumulating unpatched vulnerabilities and weakening patch management before any exploit or incident occurs. Option B (Failed authentication spike) is correct because a sudden rise in failed logons is a leading indicator of credential-stuffing, brute-force, or password-spraying activity, which precedes a potential account compromise. Option C is a lagging indicator because audit findings document control deficiencies that already exist, reflecting past state rather than predicting future risk increase. Option D is a lagging indicator since successful intrusions are realized events that have already occurred. Option E is also lagging because counting past security incidents measures historical impact, not forward-looking risk trajectory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Average patch lag time increasing
Why this is correct
Patch lag measures exposure duration before remediation, so lengthening lag signals accumulating unpatched vulnerabilities and rising likelihood of exploitation. It is a leading indicator because it predicts future incidents rather than reporting past losses, satisfying the KRI requirement for forward-looking risk trend data.
- ✓
Failed authentication spike
Why this is correct
Failed authentication spikes indicate attempted credential attacks or brute-force activity, preceding potential account compromise. This forward-looking signal predicts elevated breach likelihood, satisfying the KRI criterion for a leading indicator of increasing risk rather than a lagging record of realised incidents.
- ✗
Audit findings of control deficiencies
Why it's wrong here
Audit findings of control deficiencies are discovered through retrospective assessment, so they report existing weakness rather than forecast increasing risk. They attract attention because deficiencies correlate with exposure, but they are lagging indicators; leading KRIs track precursor conditions such as control failure rates or vulnerability ageing.
- ✗
Number of successful intrusions
Why it's wrong here
Successful intrusions are recorded after a threat event has already defeated controls, making this a lagging indicator of realised loss. It is tempting because intrusion counts clearly signal danger, but they belong in post-incident reporting rather than predicting rising risk exposure.
- ✗
Number of security incidents in the past month
Why it's wrong here
Incidents counted over the past month describe events that have already occurred, so they measure outcomes rather than forward-looking exposure. The metric appeals because incident volume feels predictive, yet it is a lagging indicator used for trend review after the fact.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.