mediumMultiple Choice
CRISC Practice Question: Is designing a risk and control monitoring…
An organization is designing a risk and control monitoring program for a new cloud-based application. Which of the following is the MOST important factor to consider when selecting Key Risk Indicators (KRIs)?
⚠ Common exam trap
The trap here is that candidates often prioritize ease of automation or industry benchmarks over strategic alignment, forgetting that KRIs must be tailored to the organization's specific risk profile and business objectives to be effective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alignment with strategic objectives.
Alignment with strategic objectives is the most important factor because KRIs must directly measure risks that could impede the organization's business goals and strategic initiatives. For a new cloud-based application, KRIs tied to strategic objectives ensure monitoring focuses on risks that matter most to the business, such as data breaches affecting customer trust or service downtime impacting revenue, rather than irrelevant metrics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Historical loss data availability.
Why it's wrong here
Historical loss data reflects past incidents and may be sparse for a new cloud application, so it cannot reliably indicate forward-looking exposure. It is tempting because loss records feel objective, but they suit retrospective reporting. KRIs must be predictive of the risks the programme monitors.
- ✗
Ease of automated data collection.
Why it's wrong here
Automated collection addresses measurement convenience, not whether an indicator actually signals risk against an appetite threshold. It is tempting because cloud telemetry is readily harvested, but automation suits high-volume operational metrics. KRIs must first be tied to the risk drivers the programme monitors.
- ✗
Industry best practices.
Why it's wrong here
Industry best practices describe generic peer norms, not the specific risk drivers, thresholds and data sources tied to this application's own threat exposure and control environment. They are tempting as a defensible benchmark, and would suit a maturity assessment or baseline control review, but KRIs must be calibrated to the organisation's own risk appetite.
- ✓
Alignment with strategic objectives.
Why this is correct
KRIs tied to strategic objectives ensure monitoring reflects risks that actually threaten the organisation's goals, rather than isolated technical metrics. This alignment keeps the cloud programme's risk reporting meaningful to leadership and drives relevant control decisions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.