Courseiva
hardMultiple Choice

CRISC Practice Question: Has recently suffered a ransomware attack that…

An organization has recently suffered a ransomware attack that encrypted critical files. During the post-incident review, the risk team is identifying key risk indicators (KRIs) to improve early detection. Which of the following KRIs would be MOST effective in detecting similar attacks in the future?

⚠ Common exam trap

CRISC often tests the KRI vs. KPI distinction — candidates pick compliance or hygiene metrics (training completion, patch time) that feel security-related but are lagging indicators, rather than behavioral signals that actually precede an attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Number of unauthorized remote access attempts.

A KRI must be a measurable, leading indicator that provides early warning of an emerging risk. A spike in unauthorized remote access attempts is a direct precursor to ransomware intrusion (which typically begins with credential abuse or RDP exploitation), so monitoring this metric can trigger early detection before encryption occurs. It is behavioral, actionable, and tied to the attack chain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Frequency of antivirus signature updates.

    Why it's wrong here

    Antivirus signature update frequency reflects maintenance hygiene, not whether encryption is occurring, so it cannot detect an active ransomware event. It is tempting because current signatures improve malware detection generally, making this KRI useful for measuring endpoint control upkeep, but it does not monitor the file-encryption behaviour itself.

  • ✓

    Number of unauthorized remote access attempts.

    Why this is correct

    Unauthorised remote access attempts are a leading indicator: ransomware actors typically gain initial entry through remote access, so a rising count signals intrusion attempts before encryption occurs, enabling earlier detection than lagging indicators such as encrypted file counts.

  • ✗

    Percentage of employees who completed security awareness training.

    Why it's wrong here

    Training completion rates measure human-risk posture over time, not live file-encryption activity, so they cannot flag an unfolding ransomware incident. It is tempting because phishing awareness reduces initial infection likelihood, making this KRI suitable for tracking programme coverage, but it provides no detection signal during an attack.

  • ✗

    Time to patch critical vulnerabilities.

    Why it's wrong here

    Patch latency measures exposure windows, not active encryption behaviour, so it cannot detect an in-progress ransomware event. It is tempting because unpatched vulnerabilities often enable initial access, making this KRI valid for tracking vulnerability management effectiveness, but not for early detection of the attack itself.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.