CRISC Risk Response and Reporting Practice Question
An organization’s continuous monitoring program includes automated vulnerability scanning and log review. Which of the following is a Key Risk Indicator (KRI) that would BEST signal an increasing risk of a successful network breach?
⚠ Common exam trap
CRISC often tests the distinction between KRIs (leading, risk-signaling metrics) and KPIs (performance/coverage metrics) — candidates frequently pick control-effectiveness metrics like patch time or AV coverage instead of threat-activity indicators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spike in failed authentication attempts from external IPs
A Key Risk Indicator (KRI) is a forward-looking metric that signals changes in risk exposure. A spike in failed authentication attempts from external IPs is a leading indicator of attempted unauthorized access — such as brute-force or credential-stuffing attacks — and directly signals increasing likelihood of a successful network breach. It is actionable and tied to a specific threat vector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Average time to patch critical vulnerabilities
Why it's wrong here
Average time to patch critical vulnerabilities is a lagging remediation metric describing past performance, not a forward-looking indicator of increasing breach risk. It is tempting because patching is central to vulnerability management, but the KRI should track the volume and severity of unpatched exposures trending upward.
- ✓
Spike in failed authentication attempts from external IPs
Why this is correct
Failed external authentication attempts are a leading indicator: they rise before a breach succeeds, revealing active credential-guessing or brute-force activity against exposed services. Unlike lagging measures such as confirmed incidents, this spike gives continuous monitoring data that signals escalating likelihood, directly satisfying the KRI requirement for early warning.
- ✗
Number of firewall rule changes per month
Why it's wrong here
Firewall rule change volume measures operational churn, not risk exposure; many changes may be routine and few may be reckless. It is tempting because change activity can precede misconfiguration, but as a KRI it lacks a defined risk direction. Patch latency and vulnerability counts directly indicate exploitable exposure.
- ✗
Percentage of systems with up-to-date antivirus signatures
Why it's wrong here
Antivirus signature currency is a control-effectiveness metric, not a risk indicator; high coverage signals good hygiene and does not trend toward breach likelihood. It is tempting because it is measurable and security-related, but KRIs must reflect changing risk exposure, which patch latency and vulnerability counts do.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.