Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: Has recently suffered a ransomware attack that…

An organization has recently suffered a ransomware attack that encrypted critical files. During the post-incident review, the risk team is identifying key risk indicators (KRIs) to improve early detection. Which of the following KRIs would be MOST effective in detecting similar attacks in the future?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Number of unauthorized remote access attempts.

The most effective KRI for early detection of ransomware because unauthorized remote access attempts are a direct indicator of an ongoing attack or reconnaissance. This metric can signal a breach before encryption occurs. In contrast, Option A (antivirus signature updates) measures a control rather than a risk indicator; Option C (awareness training) is a preventive measure; Option D (patch time) is corrective and not timely for detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Frequency of antivirus signature updates.

    Why it's wrong here

    Updates are preventive, not a real-time detection indicator.

  • Number of unauthorized remote access attempts.

    Why this is correct

    Direct indicator of possible ransomware entry.

  • Percentage of employees who completed security awareness training.

    Why it's wrong here

    Training is preventive, not a direct detection metric.

  • Time to patch critical vulnerabilities.

    Why it's wrong here

    Patching is a corrective control, not a detection KRI.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.