Courseiva

CRISC Information Technology and Security Practice Question

An organization is evaluating cyber insurance to mitigate financial risk from potential data breaches. Which factor would most likely increase the insurance premium?

⚠ Common exam trap

CRISC often tests risk factors for insurance; candidates may assume that any security investment lowers premiums, but the question asks what increases premiums, and past incidents are a clear negative indicator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

History of previous security incidents

A history of previous security incidents most likely increases the insurance premium because it indicates a higher risk profile to the insurer. Insurers assess past claims and incident frequency as a key factor in determining the likelihood of future breaches, leading to higher premiums or even denial of coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementation of multi-factor authentication

    Why it's wrong here

    Multi-factor authentication reduces the likelihood of credential-based compromise, which lowers rather than raises the premium. It is tempting because MFA is a recognised control that insurers reward, and it would be the correct answer if the question asked which factor decreases premiums or improves insurability.

  • ✗

    Adoption of a cybersecurity framework

    Why it's wrong here

    Framework adoption demonstrates mature governance and typically reduces premiums by evidencing lower loss expectancy. It is tempting because frameworks are widely recommended security investments, and this would be correct if the question asked which factor improves underwriting terms rather than which increases cost.

  • ✗

    Regular penetration testing

    Why it's wrong here

    Penetration testing identifies and remediates weaknesses, lowering expected loss and therefore premiums. It is tempting because testing is a proactive control frequently cited in security programmes, and it would be correct if the question asked which activity strengthens an insurance application instead of increasing the premium.

  • ✓

    History of previous security incidents

    Why this is correct

    A documented history of previous security incidents directly raises the insurer's assessed loss frequency, increasing the premium. Underwriters price cyber cover on actuarial loss experience, so prior breaches signal elevated recurrence risk and weaker controls, satisfying the stem's requirement to identify the factor that most likely increases the premium charged.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.