Courseiva

CRISC Risk Response and Reporting Practice Question

An IT risk manager is developing KRIs for a critical application. Which TWO of the following are leading indicators that the risk level may be increasing? (Select TWO)

⚠ Common exam trap

CRISC often tests the distinction between leading and lagging indicators, and candidates frequently select incident counts or audit findings because they sound risk-related, missing that these are backward-looking outcomes rather than predictive signals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Average patch lag time increasing

Option A (Average patch lag time increasing) is correct because a growing delay between patch release and deployment is a leading indicator: it signals accumulating unpatched vulnerabilities and weakening patch management before any exploit or incident occurs. Option B (Failed authentication spike) is correct because a sudden rise in failed logons is a leading indicator of credential-stuffing, brute-force, or password-spraying activity, which precedes a potential account compromise. Option C is a lagging indicator because audit findings document control deficiencies that already exist, reflecting past state rather than predicting future risk increase. Option D is a lagging indicator since successful intrusions are realized events that have already occurred. Option E is also lagging because counting past security incidents measures historical impact, not forward-looking risk trajectory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Average patch lag time increasing

    Why this is correct

    Patch lag measures exposure duration before remediation, so lengthening lag signals accumulating unpatched vulnerabilities and rising likelihood of exploitation. It is a leading indicator because it predicts future incidents rather than reporting past losses, satisfying the KRI requirement for forward-looking risk trend data.

  • ✓

    Failed authentication spike

    Why this is correct

    Failed authentication spikes indicate attempted credential attacks or brute-force activity, preceding potential account compromise. This forward-looking signal predicts elevated breach likelihood, satisfying the KRI criterion for a leading indicator of increasing risk rather than a lagging record of realised incidents.

  • ✗

    Audit findings of control deficiencies

    Why it's wrong here

    Audit findings of control deficiencies are discovered through retrospective assessment, so they report existing weakness rather than forecast increasing risk. They attract attention because deficiencies correlate with exposure, but they are lagging indicators; leading KRIs track precursor conditions such as control failure rates or vulnerability ageing.

  • ✗

    Number of successful intrusions

    Why it's wrong here

    Successful intrusions are recorded after a threat event has already defeated controls, making this a lagging indicator of realised loss. It is tempting because intrusion counts clearly signal danger, but they belong in post-incident reporting rather than predicting rising risk exposure.

  • ✗

    Number of security incidents in the past month

    Why it's wrong here

    Incidents counted over the past month describe events that have already occurred, so they measure outcomes rather than forward-looking exposure. The metric appeals because incident volume feels predictive, yet it is a lagging indicator used for trend review after the fact.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.