CRISC Risk Response and Reporting Practice Question
An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?
⚠ Common exam trap
The trap is that candidates may rationalize the increase as 'gradual' or compare it to an irrelevant benchmark (60 days) instead of the defined 20-day threshold — CRISC expects you to treat threshold breaches as clear signals requiring management action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vulnerability risk is increasing and requires management attention
The KRI has risen from 15 to 30 days, exceeding the 20-day risk appetite threshold. When a KRI breaches its threshold, it signals that the risk is outside acceptable limits and requires management attention. The correct conclusion is that vulnerability risk is increasing and must be addressed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The patching process is effective because the KRI is still below 60 days
Why it's wrong here
The KRI has risen from 15 to 30 days against a 20-day appetite threshold, so the breach indicates deteriorating patching capability, not effectiveness. It is tempting because 30 days is well under 60 days, but that figure is not the defined risk appetite threshold in this scenario.
- ✗
The KRI should be replaced with a lagging indicator
Why it's wrong here
A KRI breaching its threshold signals that the indicator is working and requires escalation or treatment, not replacement; lagging indicators report past loss events and cannot provide this forward-looking warning. Replacing it would be considered when an indicator no longer correlates with the risk it monitors.
- ✓
The vulnerability risk is increasing and requires management attention
Why this is correct
The KRI has breached the 20-day risk appetite threshold, rising from 15 to 30 days, so vulnerability exposure is worsening. This trend signals that patch management controls are degrading, requiring management attention to remediate the control weakness before the risk exceeds tolerance further.
- ✗
The risk is within appetite because the increase is gradual
Why it's wrong here
A KRI at 30 days has breached the 20-day risk appetite threshold, so the risk cannot be within appetite; gradual drift is irrelevant once the limit is crossed. Trending KRIs are tempting because slow movement can indicate a developing exposure, but breach of a defined threshold triggers escalation regardless of pace.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.