Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

An organization’s continuous monitoring program includes automated vulnerability scanning and log review. Which of the following is a Key Risk Indicator (KRI) that would BEST signal an increasing risk of a successful network breach?

⚠ Common exam trap

CRISC often tests the distinction between KRIs (leading, risk-signaling metrics) and KPIs (performance/coverage metrics) — candidates frequently pick control-effectiveness metrics like patch time or AV coverage instead of threat-activity indicators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spike in failed authentication attempts from external IPs

A Key Risk Indicator (KRI) is a forward-looking metric that signals changes in risk exposure. A spike in failed authentication attempts from external IPs is a leading indicator of attempted unauthorized access — such as brute-force or credential-stuffing attacks — and directly signals increasing likelihood of a successful network breach. It is actionable and tied to a specific threat vector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Average time to patch critical vulnerabilities

    Why it's wrong here

    Average time to patch critical vulnerabilities is a lagging remediation metric describing past performance, not a forward-looking indicator of increasing breach risk. It is tempting because patching is central to vulnerability management, but the KRI should track the volume and severity of unpatched exposures trending upward.

  • ✓

    Spike in failed authentication attempts from external IPs

    Why this is correct

    Failed external authentication attempts are a leading indicator: they rise before a breach succeeds, revealing active credential-guessing or brute-force activity against exposed services. Unlike lagging measures such as confirmed incidents, this spike gives continuous monitoring data that signals escalating likelihood, directly satisfying the KRI requirement for early warning.

  • ✗

    Number of firewall rule changes per month

    Why it's wrong here

    Firewall rule change volume measures operational churn, not risk exposure; many changes may be routine and few may be reckless. It is tempting because change activity can precede misconfiguration, but as a KRI it lacks a defined risk direction. Patch latency and vulnerability counts directly indicate exploitable exposure.

  • ✗

    Percentage of systems with up-to-date antivirus signatures

    Why it's wrong here

    Antivirus signature currency is a control-effectiveness metric, not a risk indicator; high coverage signals good hygiene and does not trend toward breach likelihood. It is tempting because it is measurable and security-related, but KRIs must reflect changing risk exposure, which patch latency and vulnerability counts do.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.