Courseiva

CRISC Information Technology and Security Practice Question

An organization is planning to adopt post-quantum cryptography. Which TWO considerations are MOST important for migration planning?

⚠ Common exam trap

CRISC often tests the distinction between strategic risk-planning considerations (crypto agility, data lifetime) and tactical or irrelevant distractors (buying hardware, training on physics) — candidates who pick the 'most action-oriented' answer instead of the 'most risk-relevant' answer get it wrong.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess the cryptographic agility of current systems

Option B is correct because cryptographic agility—the ability of systems to swap algorithms, keys, and protocols without major redesign—is essential for migrating to post-quantum cryptography (PQC), since standards such as ML-KEM (FIPS 203) and ML-DSA (FIPS 204) will continue to evolve and hybrid deployments (e.g., X25519+ML-KEM) must be supported during transition. Option C is correct because systems protecting data with long confidentiality lifetimes (classified, health, financial records) are exposed to 'harvest now, decrypt later' attacks, so migration priority must be driven by how long the data must remain secret versus when a cryptographically relevant quantum computer (CRQC) is expected. Option A is not a migration-planning consideration because the cost of quantum computers is irrelevant to an organization's own cryptographic inventory and transition roadmap. Option D is unnecessary because adopting PQC requires cryptographic and IT expertise, not training staff in quantum physics. Option E is premature because standardized PQC algorithms run on existing classical hardware via software/firmware updates, so buying 'quantum-resistant hardware' immediately is neither required nor a sound first step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Evaluate the cost of quantum computers

    Why it's wrong here

    Evaluating quantum computer costs is irrelevant to migration planning, because organisations adopt post-quantum algorithms regardless of whether they own quantum hardware. It is tempting since quantum computing underpins the threat, but the real considerations are cryptographic discovery, data shelf-life and hybrid transition timelines.

  • ✓

    Assess the cryptographic agility of current systems

    Why this is correct

    Cryptographic agility determines how quickly algorithms can be swapped without redesigning applications or protocols. Assessing it exposes hard-coded cryptography and vendor dependencies, so migration planning can schedule remediation of inflexible systems before post-quantum standards are mandated.

  • ✓

    Identify systems that need long-term confidentiality (e.g., classified data)

    Why this is correct

    Data requiring long-term confidentiality is exposed to harvest-now-decrypt-later attacks, so it dictates migration priority. Identifying these systems lets the organisation sequence post-quantum adoption where cryptographic risk is greatest, rather than treating all assets equally during migration planning.

  • ✗

    Train employees on quantum physics

    Why it's wrong here

    Training employees on quantum physics does not support post-quantum migration, which needs cryptographic inventory, algorithm agility and vendor readiness. It is tempting because awareness programmes accompany major technology shifts, yet staff need guidance on identifying vulnerable algorithms and certificates, not theoretical quantum mechanics.

  • ✗

    Purchase quantum-resistant hardware immediately

    Why it's wrong here

    Buying quantum-resistant hardware immediately ignores that post-quantum migration is primarily cryptographic inventory and algorithm agility, since standards and vendor support are still maturing. It is tempting because hardware refresh cycles feel concrete and actionable, but premature procurement risks locking in unsupported implementations before interoperability is settled.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.