Courseiva

CCNA Information Technology and Security Questions

75 of 152 questions · Page 1/3 · Information Technology and Security · Answers revealed

1
MCQeasy

A risk practitioner is evaluating the effectiveness of the organization's IT change management process. Which of the following metrics would BEST indicate that the process is effectively reducing risk?

A.Number of changes implemented per month.
B.Percentage of changes that are rolled back due to failures.
C.Percentage of changes that are tested in a non-production environment before deployment.
D.Average time to implement a change.
AnswerC

Testing changes in a non-production environment before deployment is a key preventive control in change management. A high percentage of changes tested indicates that the process is effectively identifying and mitigating potential issues before they affect production. This directly reduces the risk of service disruptions, data corruption, and security vulnerabilities introduced by changes.

Why this answer

The percentage of changes tested in a non-production environment is a leading indicator of effective change management. It shows that the organization is proactively identifying and mitigating risks before changes reach production. This directly reduces the likelihood of incidents caused by changes, making it the best metric for assessing risk reduction.

Exam trap

The trap here is focusing on efficiency metrics like speed or volume, which do not necessarily correlate with reduced risk, instead of a control adherence metric like testing coverage.

2
MCQmedium

A risk practitioner is reviewing the organization's identity and access management (IAM) processes. The organization wants to reduce the risk of excessive access rights for employees who change roles internally. Which of the following controls is MOST effective for this risk?

A.Enforcing least privilege at the database level only.
B.Implementing mandatory vacation policies for all employees.
C.Automating role-based access revocation and provisioning upon HR role changes.
D.Conducting periodic user access reviews by managers.
AnswerC

Automating access revocation and provisioning based on HR role changes ensures that when an employee moves to a new role, their old access is immediately removed and new access is granted according to the new role. This event-driven approach directly mitigates the risk of excessive access rights, providing timely and consistent enforcement without relying on manual reviews.

Why this answer

The most effective control to reduce excessive access rights from internal role changes is automated role-based access revocation and provisioning triggered by HR events. This ensures immediate removal of old access and assignment of new access, directly addressing the risk. Other controls like vacation policies, periodic reviews, or database-level least privilege are either indirect or incomplete.

Exam trap

The trap here is assuming that periodic access reviews or least privilege at a single layer are sufficient, when timely, automated revocation upon role change is the most direct mitigation.

3
MCQmedium

A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time production monitoring. Which risk is most directly introduced by this convergence?

A.Higher licensing costs for industrial software
B.Expanded attack path from IT to OT systems
C.Increased complexity of data analytics
D.Reduced operational efficiency due to network latency
AnswerB

Converging ICS with corporate IT dissolves the air gap, letting compromised enterprise credentials or lateral movement reach operational technology. This expanded attack path directly satisfies the stem's convergence scenario, where IT-borne threats can now pivot into production systems, escalating impact from data loss to physical process disruption.

Why this answer

The convergence of IT and OT networks creates a bridge between two environments that were traditionally air-gapped. This bridge allows threats that compromise the corporate IT network to pivot into the industrial control systems (ICS), expanding the attack surface and providing adversaries with a direct path to operational technology (OT). Unlike licensing costs or analytics complexity, this is a direct security risk that can lead to physical consequences, making it the most critical risk introduced by such integration.

Exam trap

CRISC often tests the ability to distinguish between direct security risks and secondary business impacts; candidates may incorrectly focus on operational or financial outcomes rather than the immediate security risk of expanded attack paths.

How to eliminate wrong answers

Option A is wrong because licensing costs are a financial consideration, not a direct risk introduced by network convergence; they may change but are not the primary risk. Option C is wrong because increased complexity of data analytics is an operational challenge, not a security risk, and may even be mitigated by integration. Option D is wrong because reduced operational efficiency due to network latency is a performance concern, not a risk; in fact, integration often aims to improve efficiency, and latency can be managed with proper design.

4
MCQmedium

An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?

A.Risk assessment methodology
B.Risk treatment process
C.Risk management policy
D.Risk register
AnswerA

A defined risk assessment methodology supplies common criteria, scales and scoring, so different business units identify and evaluate risks consistently. Without it, assessments vary by assessor and cannot be aggregated, failing the stem's requirement for enterprise-wide consistency in identification and assessment.

Why this answer

A risk assessment methodology provides a standardized approach for identifying, analyzing, and evaluating risks. It ensures that all business units use consistent criteria, scales, and processes, which is essential for comparing and aggregating risks across the enterprise. Without a common methodology, risk assessments become subjective and inconsistent, undermining the risk management program.

Exam trap

CRISC often tests the distinction between governance elements (policy) and operational elements (methodology, process, register); candidates may incorrectly choose the policy because it sounds foundational, but the question asks for the component ensuring consistent identification and assessment, which is the methodology.

How to eliminate wrong answers

Option B is wrong because the risk treatment process focuses on selecting and implementing controls after risks are assessed; it does not ensure consistent identification and assessment. Option C is wrong because the risk management policy sets high-level direction and objectives but does not provide the detailed procedures needed for consistent risk identification and assessment. Option D is wrong because the risk register is a tool for recording and tracking risks; it depends on the methodology to populate it consistently and does not itself ensure consistency.

5
MCQhard

A risk manager is evaluating the potential impact of quantum computing on the organization's encryption infrastructure. The organization uses RSA-2048 for key exchanges and digital signatures. According to current quantum computing projections, what is the MOST urgent risk management action to take?

A.Immediately replace all RSA-2048 keys with symmetric encryption
B.Begin a cryptographic inventory and develop a migration plan to post-quantum cryptography
C.Purchase cyber insurance to cover potential losses from quantum attacks
D.Increase the RSA key length to 4096 bits
AnswerB

RSA-2048 is vulnerable to Shor's algorithm, so a cryptographic inventory identifying where RSA is used, followed by migration planning toward post-quantum algorithms, addresses the harvest-now-decrypt-later threat. This satisfies the stem's urgency requirement, since long-lived encrypted data can be captured today and decrypted later.

Why this answer

Quantum computers capable of breaking RSA-2048 are not imminent but expected within 10-20 years. The most urgent action is to start planning for post-quantum cryptography migration, as it requires long lead times for assessment and implementation.

6
Multi-Selectmedium

A risk practitioner is reviewing the organization's cryptographic key management practices after an audit finding. Which TWO of the following practices are MOST important to protect the confidentiality and integrity of cryptographic keys throughout their lifecycle? (Choose two.)

Select 2 answers
A.Document key custodians in the configuration management database and review the list annually.
B.Define and enforce a cryptoperiod for each key type with scheduled rotation and retirement.
C.Use the same master key across all environments to simplify key management and reduce operational cost.
D.Email encrypted key backups to the security team's shared mailbox for disaster recovery availability.
E.Store keys in a hardware security module (HSM) or managed key vault with strict access controls.
AnswersB, E

A defined cryptoperiod limits the volume of data protected by a single key and bounds the damage if a key is compromised. Scheduled rotation, rekeying, and secure retirement ensure keys do not outlive their intended use, satisfying lifecycle governance requirements and reducing exposure from undetected key compromise.

Why this answer

Protecting keys across their lifecycle requires both a secure execution and storage environment and disciplined lifecycle governance. Hardware security modules or managed vaults keep key material confidential and enforce access, while a defined cryptoperiod with rotation and retirement limits how much data any single key protects. Email distribution of backups, shared master keys across environments, and custodian documentation do not provide these protections.

Exam trap

The trap here is selecting administrative documentation or convenience-driven practices as if they protected the key material itself.

7
Multi-Selecthard

A risk manager is assessing the security posture of a containerized application deployment in a public cloud. The organization uses Kubernetes for orchestration. Which TWO of the following are the MOST significant risks specific to this environment? (Choose two.)

Select 2 answers
A.Container images may contain vulnerable dependencies that are not patched regularly.
B.Container orchestration platforms automatically enforce network segmentation, eliminating the risk of lateral movement.
C.The cloud provider's shared responsibility model means the organization is not responsible for the security of the underlying nodes.
D.Kubernetes secrets are stored unencrypted by default in etcd, allowing attackers with access to etcd to retrieve sensitive data.
E.Kubernetes RBAC is enabled by default and cannot be misconfigured, so access control risks are minimal.
AnswersA, D

Container images often include third-party libraries and base images that may have known vulnerabilities. If not scanned and patched regularly, these vulnerabilities can be exploited to compromise the container and potentially the host. This is a significant risk in containerized environments because images are immutable and may be reused across deployments, propagating vulnerabilities.

Why this answer

The most significant risks are vulnerable container images and unencrypted Kubernetes secrets in etcd. Vulnerable images can introduce exploitable flaws, while unencrypted secrets can be read by attackers with etcd access. Both are specific to containerized Kubernetes environments and require proactive controls such as image scanning and etcd encryption.

The other options describe misconceptions or false assumptions that do not represent the primary risks.

Exam trap

The trap here is being misled by statements that assume automatic security controls, such as automatic network segmentation or default RBAC, rather than recognizing the actual risks of unpatched images and unencrypted secrets.

8
MCQeasy

Which of the following is a key component of an IT risk management programme design?

A.Incident response playbooks
B.Risk assessment methodology
C.Vendor security assessment reports
D.Network topology diagrams
AnswerB

A risk assessment methodology defines how risks are identified, analysed, evaluated and prioritised, forming the foundation on which the entire IT risk management programme operates. Without it, consistent scoring and treatment decisions across the organisation are impossible.

Why this answer

A risk assessment methodology defines the process for identifying, analyzing, and evaluating risks, which is a core component of any risk management programme.

9
MCQmedium

A risk practitioner is evaluating the effectiveness of the organization's security awareness training program. The practitioner wants to determine whether the training is reducing the risk of phishing attacks. Which of the following metrics would be MOST indicative of the program's effectiveness?

A.The number of phishing emails reported by employees to the security team.
B.The percentage of employees who completed the annual security awareness training.
C.The number of phishing incidents that resulted in a data breach.
D.The click-through rate on simulated phishing campaigns over time.
AnswerD

The click-through rate on simulated phishing campaigns directly measures employee behavior when faced with a phishing attempt. A decreasing trend over time indicates that employees are becoming better at recognizing and avoiding phishing emails, which directly correlates with reduced risk. This metric provides actionable insight into the effectiveness of the training program in changing behavior.

Why this answer

The click-through rate on simulated phishing campaigns is the most indicative metric because it directly measures employee behavior in response to phishing attempts. A declining click-through rate over time demonstrates that employees are learning to recognize and avoid phishing, which reduces the risk of successful attacks. Other metrics like completion rates or breach counts are either indirect or influenced by external factors.

Exam trap

The trap here is choosing a metric that measures activity or outcomes (like training completion or breach counts) rather than a behavioral metric that directly reflects the likelihood of falling for a phishing attack.

10
MCQeasy

Which of the following is a primary goal of the 'Protect' function in the NIST Cybersecurity Framework?

A.Develop and implement appropriate activities to identify the occurrence of a cybersecurity event
B.Develop and implement appropriate safeguards to ensure delivery of critical services
C.Develop and implement appropriate activities to take action regarding a detected cybersecurity event
D.Develop and implement appropriate activities to maintain plans for resilience
AnswerB

The Protect function covers safeguards that limit or contain the impact of a cybersecurity event, directly supporting delivery of critical services. It spans identity management, access control, awareness training, data security and protective technology, matching the goal of implementing appropriate safeguards.

Why this answer

The NIST Cybersecurity Framework's Protect function (PR) is defined as developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services. It covers areas like access control, awareness training, data security, and protective technology — all aimed at limiting or containing the impact of a potential cybersecurity event.

Exam trap

CRISC often tests the distinction between the five CSF functions, especially Protect vs. Detect vs. Respond, by using similar phrasing ('develop and implement appropriate activities to...') for each.

How to eliminate wrong answers

Option A is wrong because identifying the occurrence of a cybersecurity event describes the Detect function (DE), not Protect. Option C is wrong because taking action regarding a detected event describes the Respond function (RS). Option D is wrong because maintaining plans for resilience describes the Recover function (RC).

11
MCQeasy

Which component of the NIST Cybersecurity Framework is primarily concerned with developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Detect
B.Identify
C.Recover
D.Protect
AnswerD

The Protect function covers safeguards that limit or contain the impact of a cybersecurity event, securing delivery of critical services. It encompasses identity management, access control, data security and protective technology, directly matching the stem's focus on implementing safeguards.

Why this answer

The NIST Cybersecurity Framework Core consists of five functions: Identify, Protect, Detect, Respond, and Recover. The Protect function is explicitly defined as developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services, covering areas like access control, awareness training, data security, and protective technology. This matches the question's wording exactly, making Protect the correct answer.

Exam trap

CRISC often tests the precise NIST CSF function definitions, and candidates commonly confuse Protect with Detect because both involve security controls — the key discriminator is that Protect is about safeguards implemented before an event, while Detect is about discovering events in progress.

How to eliminate wrong answers

Option A (Detect) is wrong because the Detect function focuses on developing and implementing activities to identify the occurrence of a cybersecurity event, not on implementing safeguards. Option B (Identify) is wrong because Identify concerns understanding the cybersecurity risks to systems, people, assets, data, and capabilities — it is about awareness and asset management, not safeguard implementation. Option C (Recover) is wrong because Recover focuses on developing and implementing activities to restore capabilities or services impaired by a cybersecurity event, not on preventing or protecting against them.

12
MCQeasy

A risk practitioner is reviewing the organization's vulnerability management programme. The vulnerability scan report shows thousands of findings, and remediation teams are overwhelmed. Which of the following is the MOST effective approach to prioritize remediation?

A.Remediate all findings with a Common Vulnerability Scoring System (CVSS) base score of 7.0 or higher within 30 days.
B.Assign every finding to the system owner and require monthly status reporting until all findings are closed.
C.Prioritize using threat intelligence and exploitability data combined with the business criticality of the affected assets.
D.Purchase an additional scanning tool and run scans more frequently to build a complete inventory of findings.
AnswerC

Risk-based prioritization weighs the likelihood of exploitation, drawn from threat intelligence and known exploited vulnerability catalogs, against the business impact of the affected asset. This focuses limited remediation capacity on findings that present real, material risk to the organization, which is the core purpose of vulnerability risk management rather than severity sorting alone.

Why this answer

Vulnerability management fails when severity is confused with risk. The most effective approach combines exploitability signals, such as active exploitation and threat intelligence, with the business criticality of the asset, so remediation effort targets findings that could actually harm the organization. A pure CVSS threshold, blanket assignment, or extra scanning does not answer the prioritization question.

Exam trap

The trap here is equating a high CVSS base score with high organizational risk and prioritizing solely on that number.

13
MCQmedium

A risk practitioner is assessing the risk associated with the organization's use of third-party APIs that integrate with its core banking platform. The practitioner needs to determine the MOST effective way to monitor the risk exposure of these APIs on an ongoing basis. Which of the following approaches BEST addresses this requirement?

A.Use a static risk score assigned to each third-party API at onboarding.
B.Conduct an annual security assessment of each third-party API provider.
C.Implement API gateway logging and monitor for anomalous behavior using predefined risk thresholds.
D.Require third-party API providers to submit monthly compliance reports.
AnswerC

API gateway logging captures all API calls and responses, enabling continuous monitoring. By defining risk thresholds for anomalous behavior, the organization can detect deviations that indicate increased risk exposure. This approach provides ongoing, automated visibility into third-party API activity, aligning with the requirement for continuous risk monitoring and early warning of potential issues.

Why this answer

Continuous monitoring of third-party API risk requires real-time or near-real-time data. API gateway logging with anomaly detection and risk thresholds provides ongoing visibility into API usage and potential threats. Other options like annual assessments, monthly reports, or static scores are point-in-time or retrospective and do not meet the need for continuous monitoring of dynamic risk exposure.

Exam trap

The trap here is assuming that periodic compliance reports or annual assessments provide sufficient ongoing risk monitoring, when they actually leave gaps between reviews.

14
MCQhard

A risk manager at a retail bank is reviewing the security architecture of an internal API that moves funds between customer accounts. The API is reachable only from the bank's private network, and developers argue that mutual TLS and OAuth 2.0 token validation are unnecessary because external attackers cannot reach it. Which risk principle should the risk manager apply to challenge this reasoning?

A.Defense in depth, because internal network reachability does not eliminate the need for authentication and encryption on sensitive transaction paths.
B.Single loss expectancy, because the bank should quantify the cost of one unauthorized transaction before adding controls.
C.Risk acceptance, because the residual risk of an internal-only API falls within the bank's stated risk appetite for network-perimeter controls.
D.Risk transference, because the bank can purchase cyber insurance to cover unauthorized internal transactions.
AnswerA

Defense in depth assumes the perimeter will eventually be crossed, whether by a compromised workstation, a malicious insider, or lateral movement after a phishing incident. Requiring mutual TLS and token validation on the funds-transfer API ensures that even an attacker already inside the private network cannot invoke transactions without valid credentials and an encrypted channel.

Why this answer

The developers are treating private network reachability as a substitute for authentication, which contradicts defense in depth. Because attackers routinely gain internal footholds and move laterally, a funds-transfer API must require mutual authentication and token validation so that network location alone never authorizes a transaction. The other choices address financial treatment or measurement rather than the architectural control gap.

Exam trap

The trap here is accepting the premise that an internal-only network path is inherently trusted, when defense in depth treats internal reachability as one layer rather than a substitute for authentication.

15
MCQhard

A risk manager at a multinational bank is assessing the risk of a new third-party SaaS provider that will process customer transaction data. The provider stores data in a country with different data protection laws. Which of the following is the MOST critical risk factor to evaluate FIRST?

A.The provider's financial stability and ability to remain in business for the contract duration.
B.The legal and regulatory requirements for cross-border data transfers and the provider's compliance with them.
C.The provider's service level agreements and uptime guarantees for transaction processing.
D.The technical security controls implemented by the provider, such as encryption and access management.
AnswerB

When customer data is processed in a foreign jurisdiction, the most critical initial risk is whether the transfer and storage comply with applicable data protection and privacy regulations, such as GDPR or local banking laws. Non-compliance can result in significant fines, reputational damage, and legal injunctions, making this the primary risk to evaluate before other factors.

Why this answer

Cross-border data transfers introduce legal and regulatory risks that can override operational and financial considerations. The bank must first determine whether the transfer is lawful under applicable data protection laws and whether the provider meets those requirements. Technical controls and SLAs are important but secondary to the fundamental question of legality.

Exam trap

The trap here is focusing on technical security or financial stability while overlooking the legal permissibility of transferring customer data to a foreign jurisdiction.

16
MCQmedium

An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?

A.Data sovereignty of sensor data stored in the cloud
B.Inability to patch vulnerabilities in legacy IoT devices
C.Interoperability issues between different sensor protocols
D.High energy consumption of sensors
AnswerB

Limited firmware update capability means discovered vulnerabilities cannot be remediated, leaving flaws exploitable indefinitely across many vendor devices. This unpatched exposure is the primary risk, since other concerns such as physical tampering or data volume are secondary to permanently unpatchable attack surface.

Why this answer

IoT devices with limited or no firmware update capability represent an unpatched, persistent attack surface that cannot be remediated through normal vulnerability management — this is the primary risk because it is both high-likelihood and difficult to mitigate. Unlike interoperability or power issues, unpatchable firmware means known CVEs remain exploitable for the device's entire lifecycle, and IoT devices are frequently recruited into botnets (e.g., Mirai). For a risk manager, the inability to patch is the foundational risk that amplifies all others.

Exam trap

CRISC often tests the distinction between a security risk (unpatchable vulnerabilities) and operational/compliance concerns (interoperability, sovereignty, power) — candidates pick the most visible issue rather than the one with the greatest residual risk.

How to eliminate wrong answers

Option A is wrong because data sovereignty is a compliance/legal concern that can be addressed contractually and architecturally (region selection, encryption), and is not the primary risk for a fleet of unpatchable devices. Option C is wrong because interoperability issues are an integration and operational concern, typically resolved with protocol gateways or middleware, and do not represent an ongoing exploitable vulnerability. Option D is wrong because high energy consumption is a cost/efficiency issue, not a security or resilience risk, and does not create an attack vector.

17
MCQmedium

A retail company is migrating its customer loyalty application to a cloud provider. During a risk assessment, the risk practitioner notes that the provider's infrastructure is shared across many tenants. Which of the following is the MOST significant risk that this multi-tenancy introduces?

A.A vulnerability in the provider's isolation controls could allow one tenant to access another tenant's data.
B.The cost of cloud services may increase unexpectedly due to provider pricing changes.
C.The organization loses the ability to perform its own vulnerability scanning on the underlying infrastructure.
D.The cloud provider may go out of business, causing an abrupt loss of service.
AnswerA

Multi-tenancy relies on logical isolation mechanisms such as hypervisors, containers, and network segmentation to keep tenants separate. A flaw in these controls can lead to data leakage or cross-tenant attacks, which is a direct and severe risk specific to shared environments. This is the most critical risk because it can compromise confidentiality and integrity of customer data without the organization's direct control.

Why this answer

Multi-tenancy introduces the risk that logical isolation controls may fail, allowing one tenant to access another tenant's data or workloads. This directly threatens confidentiality and integrity and is unique to shared cloud environments. Other risks such as provider failure, loss of scanning, or price changes are important but are not caused by the shared infrastructure model itself.

Exam trap

The trap here is assuming that any risk related to cloud, such as provider insolvency or pricing, is the most significant, rather than focusing on the specific threat introduced by sharing resources.

18
MCQhard

A financial institution is implementing a cloud-based data analytics platform. The data includes personally identifiable information (PII) of customers in multiple jurisdictions. Which of the following is the MOST critical risk consideration?

A.Vendor lock-in due to proprietary APIs
B.Shared responsibility model gaps
C.Data sovereignty and compliance with local regulations
D.Multi-tenancy isolation risks
AnswerC

PII spanning multiple jurisdictions triggers conflicting residency and privacy mandates, so data sovereignty and local regulatory compliance dominate. Where data resides and which laws govern it determine lawful processing, transfer restrictions and breach liability, outweighing other cloud analytics risks.

Why this answer

The most critical risk is data sovereignty and compliance with local regulations because PII from multiple jurisdictions is subject to varying legal requirements (e.g., GDPR in Europe, CCPA in California, LGPD in Brazil). A cloud-based analytics platform processes and stores this data, and failure to comply can result in severe fines, legal action, and reputational damage. Unlike technical risks like vendor lock-in or multi-tenancy, non-compliance is a direct regulatory and business risk that cannot be mitigated by standard cloud controls alone.

Exam trap

The trap here is that candidates often focus on technical risks like shared responsibility or multi-tenancy, but CRISC emphasizes that regulatory compliance (especially with PII across jurisdictions) is the highest-priority risk because it carries direct legal and financial consequences that cannot be overridden by technical controls.

How to eliminate wrong answers

Option A is wrong because vendor lock-in due to proprietary APIs is a strategic risk, not the most critical when PII and regulatory compliance are at stake; it can be mitigated through standard API abstraction or multi-cloud strategies. Option B is wrong because shared responsibility model gaps are important but typically address security controls (e.g., encryption, access management) rather than the fundamental legal obligation to store data within specific geographic boundaries. Option D is wrong because multi-tenancy isolation risks are a security concern but are secondary to the primary risk of violating data residency laws, which can lead to immediate regulatory penalties.

19
MCQhard

An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?

A.Increased number of malware infections
B.Unauthorized access to corporate financial systems
C.Manipulation of operational parameters leading to equipment damage
D.Denial of service affecting IT services
AnswerC

Manipulating operational parameters can drive actuators, valves or turbines beyond safe limits, producing physical destruction or safety incidents rather than mere data loss. That direct kinetic consequence outranks confidentiality or availability risks when integrating IT with OT for real-time monitoring.

Why this answer

When IT and OT networks are integrated, the highest-priority risk is one with physical consequences. Manipulation of operational parameters (e.g., changing setpoints, valve positions, or PLC logic) can directly cause equipment damage, safety incidents, or environmental harm — consequences unique to OT environments. This makes it the top priority because the potential for physical impact elevates severity beyond typical IT risks.

Exam trap

CRISC often tests the IT vs OT risk distinction, and candidates commonly default to familiar IT risks (malware, DoS, financial system access) — the trap is failing to recognize that OT risks are prioritized by physical safety and equipment consequences, not data confidentiality.

How to eliminate wrong answers

Option A (Increased number of malware infections) is wrong because while malware is a concern, its primary impact is on IT systems and data — it does not inherently produce physical consequences in OT, so it ranks lower than parameter manipulation. Option B (Unauthorized access to corporate financial systems) is wrong because financial system compromise is an IT-domain risk with monetary and reputational impact, but it does not cause physical damage to equipment or safety. Option D (Denial of service affecting IT services) is wrong because DoS on IT services disrupts business operations but does not directly manipulate physical processes or damage equipment — in OT, availability matters, but parameter manipulation is the more severe physical-consequence risk.

20
MCQmedium

A company is implementing COBIT 2019 and wants to ensure that risk management activities are aligned with business objectives. Which governance objective is primarily responsible for evaluating, directing, and monitoring risk management?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM04 — Ensure Resource Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM03 — Ensure Risk Optimization
AnswerD

EDM03 — Ensure Risk Optimization sits within the Evaluate, Direct and Monitor domain, giving the governing body explicit accountability for evaluating risk appetite, directing risk responses and monitoring that risk management stays aligned with enterprise objectives, exactly the governance responsibility the scenario demands.

Why this answer

EDM03 — Ensure Risk Optimization is the COBIT 2019 governance objective specifically responsible for ensuring that enterprise risk is identified, assessed, and managed within the risk appetite, and that risk management activities align with business objectives. It covers evaluating risk, directing risk treatment, and monitoring risk exposure. The other EDM objectives address governance framework, benefits, and resources, not risk optimization.

Exam trap

CRISC often tests the confusion between EDM03 (Risk Optimization) and APO12 (Managed Risk), or between EDM03 and EDM01 — candidates must remember EDM03 is the governance objective explicitly tied to risk.

How to eliminate wrong answers

Option A is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance focuses on establishing and maintaining the governance framework, structures, and decision-making model, not on risk optimization. Option B is wrong because EDM04 — Ensure Resource Optimization concerns optimizing IT resources (people, infrastructure, applications) for cost and value, not risk management. Option C is wrong because EDM02 — Ensure Benefits Delivery focuses on optimizing value and benefits from IT investments, not on evaluating/directing/monitoring risk.

21
MCQmedium

A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?

A.Model bias
B.Adversarial attacks
C.Lack of explainability
D.Data privacy in training
AnswerC

Black-box credit scoring prevents the institution from justifying adverse decisions to regulators, breaching explainability obligations. Addressing this risk directly satisfies the compliance constraint, since undocumented model reasoning cannot be defended during supervisory review or customer appeals.

Why this answer

When a model is a black box and regulatory compliance requires explainability, the most critical risk is the lack of explainability itself — without it, the institution cannot justify credit decisions to regulators, customers, or auditors, and may violate fair lending laws (e.g., ECOA, GDPR Article 22). Explainability is the gating requirement here; bias, adversarial attacks, and data privacy are real risks but secondary to the stated compliance driver. Addressing explainability often also surfaces and mitigates bias.

Exam trap

CRISC often tests whether candidates pick the risk explicitly tied to the stated compliance driver (explainability) versus a more general AI risk (bias, adversarial attacks) that is real but not the primary concern in the scenario.

How to eliminate wrong answers

Option A is wrong because model bias, while a serious fairness risk, is not the stated critical concern — and bias can only be detected and remediated if the model is explainable in the first place. Option B is wrong because adversarial attacks are a security risk relevant to model integrity, but they are not the primary compliance blocker described in the scenario. Option D is wrong because data privacy in training is a regulatory concern (GDPR, CCPA) but is distinct from the explainability requirement for credit decisions, and can be addressed through data minimization and anonymization independently.

22
Multi-Selecthard

An enterprise is migrating to a public cloud environment. Which THREE of the following are critical cloud-specific risk considerations?

Select 3 answers
A.Multi-tenancy isolation failures
B.On-premises network latency
C.Data sovereignty and legal jurisdiction
D.Shared responsibility model gaps
E.Legacy system compatibility
AnswersA, C, D

Public cloud workloads share physical hosts, hypervisors and network fabric with other tenants, so a hypervisor escape, side-channel attack or misconfigured isolation could expose one tenant's data to another. This risk is specific to shared infrastructure and absent from dedicated on-premises hosting.

Why this answer

Multi-tenancy isolation failures (A) are a cloud-specific risk because public cloud providers co-locate workloads from different customers on shared physical hosts, hypervisors, and storage, so a hypervisor escape or misconfigured tenant boundary can expose another tenant's data. Data sovereignty and legal jurisdiction (C) matter because cloud data may be replicated across regions and countries, subjecting it to differing privacy laws, subpoena powers, and residency requirements that the enterprise cannot control contractually alone. Shared responsibility model gaps (D) are critical because the provider secures the cloud (physical, hypervisor, managed services) while the customer secures what they put in it (IAM, encryption, patching of IaaS guests, misconfigured S3 buckets), and unclear ownership of a control creates exploitable blind spots.

On-premises network latency (B) is not cloud-specific since it concerns the legacy data center rather than the public cloud migration itself, and legacy system compatibility (E) is a general migration/modernization concern that applies to any platform change, not a risk unique to public cloud.

Exam trap

CRISC often tests whether candidates distinguish cloud-specific risks (multi-tenancy, sovereignty, shared responsibility) from generic IT risks (latency, legacy compatibility) that exist regardless of cloud.

23
Multi-Selecthard

A risk manager at a retail bank is assessing risks introduced by a new open-source container orchestration platform. The platform will host internal APIs that process non-public customer information. Which TWO of the following are the MOST significant risks that should be prioritized in the risk register? (Choose two.)

Select 2 answers
A.Hard-coded secrets and API keys in container images or orchestration manifests.
B.The platform's community support model may delay resolution of non-security bugs.
C.Lack of a documented container orchestration policy and standards for secure configuration.
D.Increased licensing costs due to the open-source platform's commercial support model.
E.Unpatched vulnerabilities in container images that could lead to unauthorized access to customer data.
AnswersA, E

Hard-coded secrets in images or manifests are easily exposed through image layers, source repositories, or runtime environment variables. In a banking context, exposed API keys could allow attackers to bypass authentication and access customer data. This risk is both highly likely and high impact, and it can be mitigated through secret management tools, image scanning, and secure coding practices, warranting priority in the risk register.

Why this answer

Unpatched container images and hard-coded secrets directly threaten the confidentiality and integrity of non-public customer information. These risks are highly exploitable and can lead to data breaches, regulatory penalties, and reputational damage. Policy gaps, licensing costs, and community support delays are important but secondary; they do not represent immediate, high-impact threats to customer data in a banking context.

Exam trap

The trap here is focusing on governance or cost issues while overlooking that unpatched images and hard-coded secrets are the direct, high-impact threats to customer data.

24
Multi-Selectmedium

Which THREE of the following are typical exclusions in a cyber insurance policy?

Select 3 answers
A.Losses due to power outages without malicious intent
B.Intentional acts by the insured
C.Ransomware payments
D.Acts of war or terrorism
E.Social engineering fraud
AnswersA, B, D

Cyber policies typically exclude physical perils such as power outages without a malicious element, since these are property or business-interruption losses rather than cyber incidents. This exclusion satisfies the stem's requirement by removing non-malicious, non-cyber causes of loss from cover.

Why this answer

Option A (losses due to power outages without malicious intent) is a typical exclusion because cyber policies generally cover malicious cyber events, not non-malicious infrastructure or utility failures that cause business interruption. Option B (intentional acts by the insured) is excluded because insurance cannot cover deliberate wrongdoing or fraudulent conduct by the policyholder, as this would violate the principle of indemnity and public policy. Option D (acts of war or terrorism) is a standard exclusion found in most cyber policies, often tied to war exclusions that remove coverage for state-sponsored or warlike attacks.

Option C (ransomware payments) is not a standard exclusion — many cyber policies explicitly cover ransomware, including reimbursement of ransom payments, subject to conditions. Option E (social engineering fraud) is also not a typical blanket exclusion; it is frequently offered as a covered extension or sub-limit, though it may require specific endorsement rather than being excluded outright.

Exam trap

CRISC often tests the misconception that ransomware and social engineering are excluded, when in fact they are commonly covered (with sub-limits), while power outages, intentional acts, and war/terrorism are the standard exclusions.

25
MCQmedium

A company is migrating critical applications to the cloud. The risk manager is assessing the shared responsibility model. Which risk is the customer typically responsible for?

A.Network infrastructure maintenance
B.Physical security of data centers
C.Data classification and access control
D.Hypervisor security
AnswerC

Under the shared responsibility model the provider secures the cloud infrastructure, while the customer always owns its data. Classification and access control are therefore customer duties, governing who may reach data and how it is labelled, regardless of the deployment model chosen.

Why this answer

According to the shared responsibility model, the customer is responsible for data, access management, and application-level security.

26
MCQhard

A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?

A.Standardize industrial control protocols
B.Reduce energy consumption
C.Ensure interoperability between IT and OT systems
D.Protect the reliability of the bulk electric system
AnswerD

NERC CIP standards mandate controls such as electronic security perimeters, access management and incident reporting for entities operating bulk electric system assets. Their primary objective is protecting the reliability of that system, satisfying the stem's compliance requirement for the power utility.

Why this answer

NERC CIP (Critical Infrastructure Protection) standards are mandatory reliability standards specifically designed to protect the bulk electric system (BES) from cyber and physical threats. Their primary objective is to ensure the reliable operation of the BES by securing the assets that control and monitor it. This is a regulatory requirement for power utilities in North America.

Exam trap

CRISC often tests the distinction between IT and OT security objectives; candidates may confuse interoperability or protocol standardization with the core reliability mission of NERC CIP.

How to eliminate wrong answers

Option A is wrong because NERC CIP does not standardize industrial control protocols; that is the role of organizations like IEC or IEEE. Option B is wrong because reducing energy consumption is an environmental or efficiency goal, not a cybersecurity reliability objective. Option C is wrong because while interoperability between IT and OT may be a consideration, it is not the primary objective of NERC CIP; the focus is on protecting reliability, not enabling integration.

27
MCQeasy

Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?

A.Business interruption
B.Ransomware attacks
C.Social engineering fraud
D.Acts of war
AnswerD

Cyber insurance policies commonly exclude loss from acts of war, since such catastrophic, state-driven events are deemed uninsurable. A risk manager must recognise this exclusion because it leaves the organisation retaining that risk, requiring separate treatment within the risk register rather than assuming cover.

Why this answer

Acts of war (and sometimes terrorism, nation-state cyber operations, or hostile acts) are a common exclusion in cyber insurance policies. Insurers exclude them because the potential for catastrophic, correlated losses across many policyholders is uninsurable. A risk manager must be aware of this exclusion because it can leave the organization without coverage for state-sponsored cyberattacks.

Exam trap

CRISC often tests common cyber insurance exclusions, and candidates commonly pick 'ransomware attacks' or 'social engineering fraud' because they are frequently discussed in the news — the trap is that these are typically covered (with sublimits), while acts of war is the classic uninsurable exclusion.

How to eliminate wrong answers

Option A (Business interruption) is wrong because business interruption is typically a covered loss (often as an add-on or included coverage) in cyber insurance policies, not a common exclusion. Option B (Ransomware attacks) is wrong because ransomware is generally covered under cyber insurance (though sublimits and coinsurance may apply), and it is not a standard exclusion — in fact, it is a primary reason organizations buy cyber insurance. Option C (Social engineering fraud) is wrong because social engineering fraud is often covered, sometimes as a specific sublimit or endorsement, rather than being a common exclusion — though some policies exclude it unless added, it is not the classic exclusion that acts of war represents.

28
MCQmedium

A retail organization is migrating its point-of-sale (POS) processing to a cloud-hosted payment platform. The risk practitioner must select an encryption approach that protects cardholder data while it is actively being processed in memory by the payment application. Which of the following is the MOST appropriate control for this scenario?

A.Implement confidential computing using hardware-based trusted execution environments (TEEs) for the payment workload.
B.Encrypt the payment database tablespaces using transparent data encryption (TDE).
C.Enable TLS 1.3 for all connections between the POS terminals and the cloud payment platform.
D.Store all cardholder data in a tokenized vault and replace PANs with surrogate values in the payment application.
AnswerA

Confidential computing isolates the payment workload inside a hardware-backed trusted execution environment so that memory contents remain encrypted and inaccessible to the hypervisor, host OS, or cloud operator even while the application actively processes them. This directly satisfies the requirement to protect cardholder data in use, which transport and at-rest encryption cannot achieve.

Why this answer

Cardholder data exists in three states, and each requires a different control: in transit, at rest, and in use. The scenario specifies active in-memory processing, which only confidential computing with hardware trusted execution environments addresses, because the enclave keeps memory encrypted and isolated from privileged software. Transport encryption and at-rest encryption leave the processing window exposed.

Exam trap

The trap here is assuming that any strong encryption control, such as TLS or database encryption, automatically covers data in every state.

29
Multi-Selectmedium

Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)

Select 3 answers
A.Exclusions for acts of war or state-sponsored attacks
B.Incident response prerequisites such as mandatory use of approved vendors
C.Coverage scope for different incident types
D.Company's stock price volatility
E.Office location and building security
AnswersA, B, C

War and state-sponsored attack exclusions remove cover for precisely the severe, costly incidents many organisations most need to transfer. Reviewing these exclusions satisfies the evaluation criterion of identifying retained risk, because excluded events remain the organisation's financial responsibility.

Why this answer

Cyber insurance policies have specific coverage scopes, exclusions (e.g., war, negligence), and prerequisites (e.g., multi-factor authentication). Premium factors like security controls also affect cost.

30
MCQmedium

A retail company is moving its customer loyalty application to a SaaS platform. The risk practitioner must ensure that the cloud provider's security controls are adequate. Which of the following is the MOST effective way to obtain assurance over the provider's controls?

A.Rely on the provider's ISO 9001 certification.
B.Conduct a penetration test of the provider's environment.
C.Review the provider's SOC 2 Type II report.
D.Request the provider's completed security questionnaire.
AnswerC

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of the provider's controls over a period of time. This gives the risk practitioner evidence that controls are not only designed appropriately but have been tested and operated effectively, which directly supports risk assessment and monitoring of the outsourced service.

Why this answer

A SOC 2 Type II report is specifically designed to provide independent assurance over a service organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy. It covers both design and operating effectiveness over a period, making it the most reliable evidence for a risk practitioner assessing a cloud provider's control environment.

Exam trap

The trap here is assuming that any certification or questionnaire response provides equivalent assurance, when only an independent audit report over a period demonstrates operating effectiveness.

31
MCQmedium

A risk practitioner is reviewing the organization's vulnerability management process. The team currently relies on the Common Vulnerability Scoring System (CVSS) base score alone to prioritize remediation. The CISO asks for a more risk-based prioritization approach. Which of the following should the practitioner recommend as the MOST effective enhancement?

A.Incorporate the Exploit Prediction Scoring System (EPSS) score and asset criticality into the prioritization.
B.Replace CVSS base scores with the Common Weakness Enumeration (CWE) identifiers for all findings.
C.Apply a uniform 30-day remediation deadline to all high and critical CVSS findings.
D.Increase the frequency of authenticated vulnerability scans from monthly to weekly.
AnswerA

EPSS estimates the probability that a vulnerability will be exploited in the wild within 30 days, and combining it with asset criticality aligns remediation with actual business risk. CVSS base score alone reflects intrinsic severity, not likelihood of exploitation or business impact. This enhancement directly supports risk-based prioritization, which is a core CRISC objective.

Why this answer

Risk-based vulnerability prioritization requires combining likelihood of exploitation with business impact. EPSS provides an empirical, forward-looking probability of exploitation, while asset criticality reflects the business consequence if the asset is compromised. Together they allow the team to focus remediation on the findings that present the greatest actual risk, rather than treating all high CVSS findings as equivalent.

Exam trap

The trap here is assuming that a higher CVSS base score always means higher risk, when exploit likelihood and asset context often change the true priority.

32
MCQmedium

A university is deploying a new student information system that will store grades, financial aid records, and health center notes. The risk practitioner must determine the data classification that drives encryption, access, and retention requirements. Which factor is MOST important in setting that classification?

A.The vendor's default classification assigned in the student information system's configuration templates.
B.The volume of records the system will hold and the projected annual growth rate.
C.The cost of the encryption and access management tools required to protect the system.
D.The potential harm to students and the university if the data is disclosed, altered, or unavailable.
AnswerD

Data classification exists to match protection to impact, so the governing factor is the harm that unauthorized disclosure, modification, or loss would cause to individuals and the institution. Health notes and financial aid records carry regulatory and reputational consequences far beyond their storage cost, and that impact analysis correctly drives the encryption, access, and retention controls.

Why this answer

Classification should be driven by the impact of compromise, because that impact determines how strong encryption, access, and retention controls must be. Student health notes and financial aid records cause significant harm if exposed or altered, so harm analysis is the correct basis. Volume, tooling cost, and vendor defaults are operational or commercial factors that cannot reliably indicate sensitivity.

Exam trap

The trap here is choosing a convenient operational metric such as record volume or vendor default instead of analyzing the harm that disclosure or alteration would cause.

33
MCQhard

A hospital is implementing a new electronic health record (EHR) system. The risk practitioner is concerned about the risk of unauthorized access to patient data by internal staff. Which of the following controls is MOST effective in mitigating this risk?

A.Logging and monitoring of all access to patient records.
B.Role-based access control (RBAC) with least privilege.
C.Encryption of patient data at rest.
D.Annual security awareness training for all staff.
AnswerB

RBAC with least privilege ensures that staff members are granted only the access necessary to perform their job functions. This limits the potential for unauthorized access and reduces the attack surface. It is a preventive control that directly addresses the risk of internal staff accessing patient data they do not need, and it is a fundamental requirement of many healthcare regulations.

Why this answer

RBAC with least privilege is a preventive control that restricts access based on job roles, ensuring staff can only access the patient data necessary for their duties. This directly mitigates the risk of unauthorized internal access. While training, encryption, and monitoring are valuable, they do not prevent an authorized user from accessing data they should not see.

Exam trap

The trap here is confusing detective controls like logging with preventive controls, or assuming encryption at rest protects against all unauthorized access when it only protects data at the storage layer.

34
MCQhard

A risk manager is evaluating the security of a new API gateway that will expose internal microservices to external partners. The gateway will handle authentication, rate limiting, and request routing. Which risk is MOST critical to address before go-live?

A.Weak authentication and authorization mechanisms that could allow partners to access unauthorized microservices.
B.Insufficient logging of API requests, which could hinder forensic investigations.
C.Inadequate rate limiting that could allow denial-of-service attacks.
D.Lack of TLS encryption for internal traffic between the gateway and microservices.
AnswerA

The API gateway is the entry point to internal microservices. If authentication or authorization is weak, a partner or attacker could bypass controls and reach services they should not access, leading to data exposure or system compromise. This is a preventive control gap with direct impact on confidentiality and integrity, making it the most critical risk to address before exposing the gateway externally.

Why this answer

The API gateway is the security boundary for external partners. Weak authentication and authorization could allow unauthorized access to internal microservices, directly threatening data confidentiality and integrity. While logging, rate limiting, and internal TLS are important, they are secondary to ensuring that only authorized entities can reach the appropriate services.

Addressing authentication and authorization first prevents the most severe impact.

Exam trap

The trap here is prioritizing availability or detective controls, such as rate limiting or logging, over the preventive control that stops unauthorized access to microservices.

35
MCQhard

A risk manager is evaluating the organization's vulnerability management program. The organization scans its external-facing systems weekly but has no process for prioritizing vulnerabilities based on business impact. Which of the following should the risk manager recommend as the MOST effective improvement?

A.Implement a risk-based vulnerability prioritization process that considers asset criticality, threat intelligence, and exploitability.
B.Require all vulnerabilities to be remediated within 30 days regardless of severity to enforce a strict SLA.
C.Outsource vulnerability scanning to a third-party provider to gain access to more comprehensive threat data.
D.Increase the frequency of external scans to daily to catch vulnerabilities faster.
AnswerA

A risk-based prioritization process ensures that remediation efforts focus on vulnerabilities that pose the greatest risk to the business. By factoring in asset criticality, threat intelligence, and exploitability, the organization can allocate resources efficiently and reduce the most significant exposures first. This directly addresses the missing prioritization component and aligns vulnerability management with business risk.

Why this answer

The program lacks a risk-based approach to prioritization. The most effective improvement is to implement a process that ranks vulnerabilities by the risk they pose, considering asset criticality, threat intelligence, and exploitability. This ensures that limited resources are directed to the most significant risks, aligning vulnerability management with business objectives.

Exam trap

The trap here is equating more frequent scanning or stricter deadlines with better risk management, when the real gap is the absence of risk-based prioritization.

36
MCQhard

A risk practitioner is assessing the security of a new software-defined wide area network (SD-WAN) deployment that will carry regulated traffic between branch offices and a cloud environment. The vendor's controller is managed by a third party. Which of the following risks should the practitioner identify as the MOST significant?

A.The SD-WAN controller could be compromised through the third-party management interface, allowing policy manipulation and traffic redirection.
B.Branch office staff may bypass the SD-WAN by using personal mobile hotspots for internet access.
C.The organization may lose visibility into application performance across the SD-WAN fabric.
D.SD-WAN appliances may not support the organization's existing network access control (NAC) solution.
AnswerA

The SD-WAN controller is the central policy and orchestration point; if an attacker gains control through the third-party management plane, they can alter routing, disable encryption, or redirect regulated traffic. This represents a high-impact, high-likelihood risk given the external dependency. It directly threatens confidentiality and integrity of regulated data, making it the most significant risk.

Why this answer

In SD-WAN architectures, the controller is a high-value target because it defines and enforces forwarding, segmentation, and encryption policies across all sites. When that controller is managed by a third party, the organization inherits supply-chain and access-control risk. A compromise there can bypass many perimeter defenses and affect every branch simultaneously, so it warrants the greatest attention in a risk assessment of regulated traffic.

Exam trap

The trap here is focusing on endpoint or operational issues while overlooking that the centralized controller, especially when third-party managed, is the most consequential single point of failure.

37
MCQmedium

A company is planning to migrate to post-quantum cryptography. What is the primary risk that quantum computing poses to current cryptographic systems?

A.Enhancing encryption key generation
B.Breaking widely used public-key cryptographic algorithms
C.Compromising hash functions for integrity
D.Increased speed of brute-force attacks on symmetric keys
AnswerB

Shor's algorithm lets a sufficiently large quantum computer solve integer factorisation and discrete logarithms in polynomial time, undermining RSA, Diffie-Hellman and ECC — the public-key algorithms protecting key exchange and signatures. Symmetric ciphers like AES are weakened only quadratically by Grover, so they are not the primary risk.

Why this answer

Quantum computers using Shor's algorithm can efficiently solve integer factorization and discrete logarithm problems, threatening RSA and ECC.

38
MCQmedium

A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?

A.Reduced network bandwidth for OT operations
B.Expanded attack surface from IT to OT systems
C.Increased data storage costs
D.Loss of proprietary control protocols
AnswerB

Linking ICS to the corporate network exposes operational technology to threats previously confined to IT, expanding the attack surface across both domains. This satisfies the stem's convergence scenario, where compromised corporate endpoints or lateral movement can now reach industrial control systems directly.

Why this answer

The correct answer is B: Expanded attack surface from IT to OT systems. Connecting ICS/OT networks to corporate IT networks creates a bridge that allows threats to move laterally from IT into OT environments. Historically, OT networks were air-gapped or highly segmented, but IT/OT convergence introduces new entry points and attack vectors, significantly increasing the risk of cyberattacks that can disrupt physical industrial processes.

This is the most significant risk because it can lead to safety incidents, production outages, and physical damage.

Exam trap

CRISC often tests the distinction between operational risks (e.g., bandwidth, storage) and strategic risks (e.g., expanded attack surface), and candidates may choose a technical impact over the broader security risk.

How to eliminate wrong answers

Option A is wrong because reduced network bandwidth is a performance concern, not a risk; IT/OT convergence typically involves dedicated network segments or quality-of-service to prioritize OT traffic, and bandwidth can be managed. Option C is wrong because increased data storage costs are a financial consideration, not a risk; storage is relatively cheap and can be scaled, and it does not directly threaten the organization's mission. Option D is wrong because loss of proprietary control protocols is not a risk; protocols remain in use, and convergence often involves protocol translation or encapsulation, not elimination.

39
MCQhard

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The identity team proposes implementing just-in-time (JIT) privileged access with automated approval workflows and session recording. Which risk is MOST effectively mitigated by this approach compared to standing privileged accounts?

A.The risk of a denial-of-service attack saturating the network perimeter during peak business hours.
B.The risk that database administrators can read sensitive data in production without leaving an audit trail.
C.The risk that unused or stale privileged accounts accumulate and are exploited by attackers or insiders.
D.The risk of credential stuffing attacks against the single sign-on portal used by all employees.
AnswerC

Standing privileged accounts persist indefinitely and are often forgotten, creating a large attack surface. JIT access grants privileges only when needed, for a limited time, with approval and session recording, so dormant entitlements no longer exist. This directly reduces the risk of exploitation of stale or unused privileged accounts by both external attackers and malicious insiders.

Why this answer

Standing privileged accounts are a persistent target because they remain valid even when unused. Just-in-time provisioning eliminates standing entitlements, granting elevated rights only for an approved, time-bound session. This shrinks the attack surface, removes dormant accounts that attackers and insiders could exploit, and adds approval and recording as compensating detective controls.

Exam trap

The trap here is confusing the reduction of standing privileges with broader identity threats like credential stuffing, which JIT access does not address.

40
Multi-Selecthard

A multinational manufacturer is migrating its disaster recovery capability for a core ERP system from a warm standby data center to a cloud-based recovery service. The risk practitioner is validating the recovery design. Which TWO of the following should be validated to confirm the recovery time objective can realistically be met? (Choose two.)

Select 2 answers
A.Confirm the actual data replication lag and whether it stays within the recovery point objective during peak transaction periods.
B.Verify that automated failover orchestration and DNS redirection complete within the documented recovery time objective.
C.Confirm the backup retention schedule aligns with the organization's data classification policy.
D.Confirm that the cloud recovery environment is pre-provisioned with sufficient compute, storage and network capacity for peak load.
E.Review the cloud provider's SOC 2 report to confirm its availability commitments.
AnswersB, D

Recovery time objective is about elapsed time until service is restored. Automated failover and DNS cutover are usually the longest sequential steps in a cloud recovery, so measuring their end-to-end duration against the documented objective is the most direct validation that the time target is achievable in practice rather than aspirational.

Why this answer

Validating a recovery time objective requires measuring the steps that consume restoration time and confirming the target environment can carry production load. Failover orchestration and DNS cutover are typically the longest sequential activities, and pre-provisioned capacity determines whether the restored service can actually run. Replication lag addresses data loss, while assurance reports and retention schedules address different objectives.

Exam trap

The trap here is conflating recovery point objective evidence such as replication lag with recovery time objective evidence about how fast service actually returns.

41
MCQmedium

An organization is evaluating cyber insurance to mitigate financial risk from potential data breaches. Which factor would most likely increase the insurance premium?

A.Implementation of multi-factor authentication
B.Adoption of a cybersecurity framework
C.Regular penetration testing
D.History of previous security incidents
AnswerD

A documented history of previous security incidents directly raises the insurer's assessed loss frequency, increasing the premium. Underwriters price cyber cover on actuarial loss experience, so prior breaches signal elevated recurrence risk and weaker controls, satisfying the stem's requirement to identify the factor that most likely increases the premium charged.

Why this answer

A history of previous security incidents most likely increases the insurance premium because it indicates a higher risk profile to the insurer. Insurers assess past claims and incident frequency as a key factor in determining the likelihood of future breaches, leading to higher premiums or even denial of coverage.

Exam trap

CRISC often tests risk factors for insurance; candidates may assume that any security investment lowers premiums, but the question asks what increases premiums, and past incidents are a clear negative indicator.

How to eliminate wrong answers

Option A is wrong because implementing multi-factor authentication reduces risk and would likely lower premiums, not increase them. Option B is wrong because adopting a cybersecurity framework demonstrates a mature security posture, which insurers view favorably and may result in premium discounts. Option C is wrong because regular penetration testing is a proactive security measure that identifies and remediates vulnerabilities, reducing risk and potentially lowering premiums.

42
MCQhard

A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?

A.Increase key lengths for all symmetric encryption to 256 bits
B.Ignore the risk until quantum computers are commercially available
C.Begin post-quantum cryptography migration planning and crypto-agility assessment
D.Replace all existing cryptographic algorithms with post-quantum algorithms immediately
AnswerC

Harvest-now-decrypt-later exposure means encrypted data captured today is at risk once quantum advantage arrives, so migration planning and crypto-agility assessment must start immediately. This satisfies the stem's immediate-action constraint, since inventorying algorithms and enabling rapid substitution takes years.

Why this answer

Beginning post-quantum cryptography (PQC) migration planning and crypto-agility assessment is the most appropriate immediate action because it addresses the long-term risk without premature disruption. Crypto-agility ensures systems can quickly switch algorithms, and planning allows for a smooth transition as standards mature. This proactive approach aligns with risk management principles.

Exam trap

CRISC often tests risk response timing; candidates may choose extreme actions (ignore or immediate replacement) instead of a balanced, proactive approach like planning and agility assessment.

How to eliminate wrong answers

Option A is wrong because increasing symmetric key lengths to 256 bits does not address the quantum threat to asymmetric algorithms (e.g., RSA, ECC), which are vulnerable to Shor's algorithm; symmetric keys are already relatively safe with 256 bits against Grover's algorithm. Option B is wrong because ignoring the risk until quantum computers are available is negligent; migration takes years, and data harvested now could be decrypted later (harvest now, decrypt later). Option D is wrong because immediately replacing all algorithms with post-quantum ones is impractical; PQC standards are still evolving, and many systems lack support, leading to interoperability and performance issues.

43
MCQmedium

A risk practitioner at a healthcare payer is reviewing the organization's identity and access management (IAM) controls. The practitioner discovers that several terminated employees still have active single sign-on (SSO) sessions and directory accounts. Which of the following is the MOST effective control to address this risk?

A.Implement an automated joiner-mover-leaver (JML) process integrated with the HR system to disable accounts and revoke sessions upon termination.
B.Enforce a policy that terminated employees must return their laptops and badges before their final paycheck is issued.
C.Require managers to submit a ticket to the service desk within 24 hours of an employee's termination to request account deactivation.
D.Conduct quarterly user access reviews to identify and remove accounts belonging to terminated employees.
AnswerA

An automated JML process integrated with HR ensures that account disabling and session revocation occur promptly and consistently when an employee leaves. It reduces the window of exposure caused by manual delays and human error, directly mitigating the risk of unauthorized access by terminated employees. This is the most effective preventive and detective control for the described scenario.

Why this answer

The most effective control is an automated JML process integrated with HR, as it ensures timely and consistent deactivation of accounts and revocation of sessions upon termination. Manual or periodic reviews introduce delays that can be exploited. By automating the leaver process, the organization reduces the risk of unauthorized access and aligns with CRISC principles of implementing preventive controls to mitigate IT risk.

Exam trap

The trap here is assuming that manual or periodic reviews, such as quarterly access reviews or ticket-based deactivation, are sufficient to manage the risk of terminated employees retaining access, when in fact they leave significant windows of exposure.

44
MCQhard

A risk manager is evaluating the risk of a distributed denial-of-service (DDoS) attack against the organization's public-facing web application. The organization has a 1 Gbps internet connection and no DDoS mitigation service. Which of the following is the MOST important factor in determining the potential impact of a volumetric DDoS attack?

A.The geographic location of the attackers launching the DDoS attack.
B.The number of users who will be unable to access the application during the attack.
C.The type of web server software used to host the application.
D.The bandwidth of the organization's internet connection compared to the attack traffic volume.
AnswerD

A volumetric DDoS attack aims to saturate the network link. If the attack traffic exceeds the 1 Gbps connection capacity, the link becomes congested, and legitimate traffic cannot pass, causing an outage. The impact is directly determined by whether the attack volume overwhelms the available bandwidth. This makes the connection bandwidth the most important factor in assessing the potential impact.

Why this answer

In a volumetric DDoS attack, the attacker floods the target with a high volume of traffic to exhaust network bandwidth. The potential impact is primarily determined by whether the attack traffic exceeds the organization's internet connection capacity. If the attack volume is greater than 1 Gbps, the link will be saturated, causing an outage.

Thus, the bandwidth of the connection relative to the attack volume is the most critical factor in assessing impact.

Exam trap

The trap here is focusing on downstream consequences like number of users affected or server software, rather than the direct capacity constraint that determines whether a volumetric attack succeeds.

45
MCQeasy

Which enterprise architecture layer is most directly responsible for managing the storage and processing of data, and for which data classification and encryption controls are critical?

A.Application architecture
B.Data architecture
C.Technology architecture
D.Business architecture
AnswerB

Data architecture defines how data is stored, processed, and moved across the enterprise. Because it governs data at rest and in motion, classification and encryption controls belong at this layer, directly addressing the storage and processing responsibility in the stem.

Why this answer

Data architecture is the enterprise architecture layer that defines how data is stored, managed, and processed, including data models, data flows, and storage structures. Data classification and encryption controls are critical at this layer because they directly protect the confidentiality and integrity of data at rest and in transit, ensuring compliance with policies and regulations.

Exam trap

The trap here is that candidates often confuse data architecture with technology architecture, mistakenly thinking that hardware or infrastructure layers are responsible for data classification and encryption, when in fact these controls are defined and managed at the data layer itself.

How to eliminate wrong answers

Option A is wrong because application architecture focuses on the design and interaction of software applications, not on the underlying storage and processing of data, and while applications may implement encryption, the primary responsibility for data classification and encryption controls lies with the data architecture. Option C is wrong because technology architecture deals with the hardware and software infrastructure (e.g., servers, networks, databases) that supports data processing, but it does not define how data is classified or encrypted; those controls are applied to the data itself, which is the domain of data architecture. Option D is wrong because business architecture describes business strategy, processes, and goals, and it does not directly manage data storage, processing, or technical controls like encryption.

46
Multi-Selecteasy

Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)

Select 2 answers
A.Ensures all cyber attacks are prevented
B.Helps align cybersecurity activities with business objectives
C.Provides a prescriptive set of controls for all organizations
D.Provides a common language for communicating cybersecurity risk
E.Replaces the need for a separate risk appetite statement
AnswersB, D

Mapping Framework outcomes to enterprise risk processes ties security spending and controls to stated business objectives, letting leadership prioritise investment by impact. This satisfies the integration benefit of aligning cybersecurity activities with what the organisation is trying to achieve.

Why this answer

Option B is correct because the NIST Cybersecurity Framework (CSF) is designed to be integrated with enterprise risk management so that cybersecurity investments and activities are prioritized according to business objectives, mission needs, and organizational risk tolerances, rather than treated as a purely technical concern. Option D is correct because the CSF Core's Functions, Categories, and Subcategories (Identify, Protect, Detect, Respond, Recover, and Govern in CSF 2.0) establish a standardized taxonomy that gives technical and business stakeholders a common language for describing, discussing, and communicating cybersecurity risk. Option A is incorrect because no framework can guarantee prevention of all cyber attacks; the CSF is risk-based and assumes some incidents will occur, emphasizing detection, response, and recovery.

Option C is incorrect because the CSF is outcome-based and voluntary, not a prescriptive checklist of mandatory controls for every organization. Option E is incorrect because the CSF complements, rather than replaces, an organization's risk appetite statement, which is a governance input used to guide risk-based decisions.

Exam trap

CRISC often tests the difference between a framework's actual benefits (alignment, common language) and overstated claims (prevention, prescriptive controls, replacing governance artifacts), so candidates who pick 'prescriptive controls' or 'replaces risk appetite' misunderstand CSF's voluntary, outcome-based nature.

47
MCQhard

An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?

A.The probable financial impact of a cyber incident
B.The cost of implementing security controls
C.The number of records compromised in a data breach
D.The probability that a threat event will occur
AnswerA

Loss Magnitude in FAIR represents the total monetary loss an organisation would incur from a single loss event, combining primary and secondary loss forms. It satisfies the stem's quantification constraint by expressing impact in financial terms, distinct from probability or frequency. This makes it the probable financial impact of a cyber incident.

Why this answer

In FAIR, Loss Magnitude represents the probable financial impact resulting from a loss event — it quantifies how much money an organization would lose if a threat event materializes into a loss. It is one of the two primary factors (alongside Loss Event Frequency) that combine to produce risk. It encompasses primary and secondary loss forms across productivity, response, replacement, fines, and reputation.

Exam trap

The trap is conflating Loss Magnitude with Loss Event Frequency — candidates often pick the probability-based answer because both are core FAIR terms, but only LM describes financial impact.

How to eliminate wrong answers

Option B is wrong because the cost of implementing security controls is a risk-mitigation expense, not a loss magnitude — FAIR measures loss from realized events, not control spend. Option C is wrong because the number of compromised records is a unit of exposure/volume, not a financial magnitude; record count feeds into loss estimation but is not itself Loss Magnitude. Option D is wrong because the probability a threat event occurs is Loss Event Frequency (LEF), the other half of the FAIR risk equation, not Loss Magnitude.

48
MCQhard

A risk practitioner is assessing the organization's backup and recovery controls for a critical on-premises database. The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is fifteen minutes. The current design replicates backups nightly to an offsite tape vault. Which finding is MOST significant?

A.Tape media have a limited shelf life and may degrade before they are needed for restoration.
B.The recovery time objective of four hours may be unachievable without a documented disaster recovery test.
C.Nightly backups cannot satisfy the fifteen-minute recovery point objective, so up to a day of data could be lost.
D.The backup media are stored offsite, which introduces a delay in retrieving them during a recovery.
AnswerC

The RPO defines the maximum tolerable data loss. A nightly backup means the organization could lose up to twenty-four hours of transactions, far exceeding the fifteen-minute RPO. This is the most significant finding because the design fundamentally cannot meet the stated business requirement, exposing the organization to unacceptable data loss in a recovery scenario.

Why this answer

The RPO of fifteen minutes requires that no more than fifteen minutes of data can be lost, which demands frequent replication or continuous data protection. Nightly backups leave up to a full day of transactions at risk, so the design cannot meet the business requirement. This mismatch is the most significant finding and must drive a redesign toward more frequent replication.

Exam trap

The trap here is focusing on operational details like tape shelf life or offsite retrieval delay, when the decisive issue is that nightly backups cannot meet a fifteen-minute RPO.

49
MCQhard

A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?

A.Implement a unidirectional gateway that enforces one-way data flow
B.Deploy a host-based intrusion detection system on each ICS device
C.Upgrade the ICS to modern protocols with built-in authentication
D.Disconnect the ICS from the corporate network and use manual data transfer
AnswerA

A unidirectional gateway permits data to flow only from the ICS outward to corporate IT, physically preventing inbound commands or protocol exploitation. This isolates the unauthenticated legacy protocols while preserving real-time operational data access, satisfying the availability constraint without modifying the control system.

Why this answer

A unidirectional gateway (data diode) enforces one-way data flow from the ICS to the corporate IT network, preventing any inbound traffic that could exploit the legacy protocols' lack of authentication. This maintains operational availability because the ICS remains isolated from direct network attacks while still providing real-time data access. It is the only option that addresses the authentication gap without disrupting legacy system operations.

Exam trap

The trap here is that candidates often choose upgrading protocols (Option C) as the 'best practice' without considering the operational availability constraints of legacy ICS environments, where a unidirectional gateway provides a non-disruptive security layer.

How to eliminate wrong answers

Option B is wrong because a host-based intrusion detection system (HIDS) on each ICS device can detect attacks but cannot prevent exploitation of unauthenticated legacy protocols; it also adds overhead that may impact real-time control availability. Option C is wrong because upgrading to modern protocols with built-in authentication would require replacing or reconfiguring legacy ICS devices, risking operational downtime and incompatibility with existing field equipment. Option D is wrong because disconnecting the ICS and using manual data transfer eliminates the real-time data access requirement entirely, failing to meet the integration objective and introducing latency and human error.

50
Multi-Selecthard

An organization is deploying IoT devices in a smart building. Which of the following are significant security risks associated with IoT? (Choose THREE.)

Select 3 answers
A.Firmware update challenges due to device diversity
B.Legacy device security gaps from unpatched vulnerabilities
C.Increased power consumption
D.Higher data transmission speeds
E.Expanded attack surface due to many connected devices
AnswersA, B, E

Smart buildings mix devices from many vendors with differing firmware formats and update mechanisms, so no single patching process applies. This diversity makes timely firmware remediation impractical, leaving vulnerabilities unaddressed and directly constituting the update challenge the scenario identifies.

Why this answer

IoT risks include expanded attack surface, legacy device security gaps, and firmware update challenges.

51
MCQmedium

A software company allows developers to push code directly to production using a CI/CD pipeline. A recent post-incident review found that a developer's compromised credentials were used to deploy malicious code that exfiltrated customer data. Which control would MOST effectively reduce the risk of this specific attack path recurring?

A.Increase logging and alerting on production deployments and review alerts weekly.
B.Require multi-factor authentication for all developer accounts and enforce short-lived deployment tokens scoped to individual pipelines.
C.Require developers to complete annual secure coding training and sign an acceptable use policy.
D.Implement static application security testing in the pipeline to scan code before deployment.
AnswerB

The attack relied on a stolen credential being sufficient to deploy code. Multi-factor authentication means a password alone cannot authenticate, and short-lived, pipeline-scoped tokens limit what a captured token can do, directly breaking the specific path used in this incident. This combination is the most targeted reduction of the demonstrated risk.

Why this answer

The incident path was a stolen credential granting deployment rights. Strengthening authentication with multi-factor authentication and constraining deployment tokens to short-lived, pipeline-scoped values removes both the sufficiency of a password and the blast radius of a captured token. Scanning, logging and training are valuable controls but do not close the authentication and authorization gap that enabled this specific attack.

Exam trap

The trap here is selecting detective or awareness controls when the incident path was an authentication and authorization weakness that only preventive identity controls can close.

52
MCQhard

A power utility company is required to comply with NERC CIP standards. The risk manager is assessing the impact of connecting a remote substation's OT network to the corporate WAN. Which of the following is the MOST significant risk that must be addressed to comply with NERC CIP?

A.Violation of electronic security perimeter (ESP) requirements
B.Latency issues affecting real-time control
C.Increased bandwidth costs for WAN connectivity
D.Incompatibility with legacy serial protocols
AnswerA

Connecting OT to the corporate WAN crosses an electronic security perimeter, so NERC CIP ESP controls—firewalls, access control, monitoring at every boundary—are directly triggered. This is the most significant compliance risk because unsecured routable paths between trusted and untrusted networks breach the standard's core requirement.

Why this answer

The [CORRECT] answer is A. NERC CIP standards (specifically CIP-005) mandate the establishment and protection of Electronic Security Perimeters (ESPs) around critical cyber assets. Connecting a remote substation's OT network to the corporate WAN inherently crosses an ESP boundary, requiring strict controls such as firewalls, access control lists, and monitored electronic access points.

Failure to properly define and secure the ESP is a direct compliance violation and the most significant risk because it exposes critical infrastructure to cyber threats.

Exam trap

The trap is selecting an operational or financial concern (latency, bandwidth, legacy protocols) over the regulatory compliance requirement; candidates must remember that NERC CIP is about security controls, and ESP is the foundational control for network connections.

How to eliminate wrong answers

Option B is wrong because latency, while a legitimate operational concern for real-time control, is not a NERC CIP compliance requirement—CIP focuses on security, not performance. Option C is wrong because bandwidth cost is a business/financial consideration, not a regulatory compliance risk under NERC CIP. Option D is wrong because legacy serial protocol incompatibility is a technical integration challenge, not a NERC CIP compliance risk; CIP does not mandate protocol modernization, though it does require protection of those communications.

53
MCQhard

A power utility must comply with NERC CIP standards. Which of the following is a key requirement under these standards?

A.Implementing IEC 62443 for all control systems
B.Identifying and securing Critical Cyber Assets (CCAs)
C.Deploying AI for threat detection
D.Using only air-gapped networks
AnswerB

NERC CIP requires utilities to identify and protect Critical Cyber Assets supporting the bulk electric system, forming the basis for subsequent controls. This directly satisfies the standard's core obligation to catalogue and secure assets whose compromise could disrupt reliable power delivery.

Why this answer

NERC CIP (Critical Infrastructure Protection) standards require utilities to identify and protect Critical Cyber Assets (CCAs) — later evolved into BES Cyber Systems — that support the reliable operation of the Bulk Electric System. Identification, categorization, and implementation of security controls for these assets is a foundational requirement across the CIP standards (CIP-002 through CIP-014).

Exam trap

The trap is selecting a well-known OT standard (IEC 62443) or a trendy technology (AI) as a NERC CIP requirement — candidates must recognize that NERC CIP is a prescriptive, region-specific regulatory framework with its own defined controls.

How to eliminate wrong answers

Option A is wrong because IEC 62443 is an ISA/IEC industrial cybersecurity standard used broadly in OT environments, but it is not a NERC CIP requirement — NERC CIP has its own control framework. Option C is wrong because deploying AI for threat detection is not mandated by NERC CIP; the standards are prescriptive about controls, not specific technologies. Option D is wrong because NERC CIP does not require air-gapped networks — it mandates Electronic Security Perimeters, access controls, and monitoring, which can be met without full air-gapping.

54
MCQmedium

A risk analyst is reviewing the organization's identity and access management (IAM) processes after a recent audit finding. The finding states that terminated employees retained active directory accounts for up to 30 days. Which control should the analyst recommend to BEST address this risk?

A.Require managers to submit a ticket to the IT help desk within 24 hours of an employee's termination.
B.Enforce mandatory password changes every 30 days for all employees, including terminated ones.
C.Conduct quarterly access reviews to identify and disable accounts of terminated employees.
D.Implement automated deprovisioning integrated with the HR system to disable accounts immediately upon termination.
AnswerD

Automated deprovisioning tied to the HR system ensures that account disablement occurs as soon as a termination is recorded, eliminating the 30-day window. This directly addresses the audit finding by reducing the risk of unauthorized access by former employees. It is a preventive control that is both efficient and auditable, and it aligns with least privilege and timely access revocation principles.

Why this answer

The audit finding highlights a delay between termination and account disablement, creating a window for unauthorized access. An automated deprovisioning process integrated with the HR system is the most effective preventive control because it removes human latency and ensures accounts are disabled immediately upon termination. Manual tickets and periodic reviews are detective or delayed, and password expiration does not deactivate accounts.

Exam trap

The trap here is choosing a manual or detective control, such as a help desk ticket or quarterly review, when the finding demands immediate, automated revocation.

55
Multi-Selecthard

An organization is deploying IoT devices for environmental monitoring in a manufacturing facility. Which THREE of the following are significant security risks that should be addressed? (Select THREE.)

Select 3 answers
A.Expanded attack surface due to numerous connected devices
B.Vendor lock-in due to proprietary protocols
C.Lack of firmware update capabilities for security patches
D.Data sovereignty issues for sensor data
E.Use of legacy components with known vulnerabilities
AnswersA, C, E

Each connected IoT device adds a potential entry point, so the sheer number of endpoints materially widens the attack surface an adversary can probe. This directly satisfies the scenario's environmental-monitoring deployment, where many low-power sensors often lack hardening, patching or monitoring, multiplying exploitable weaknesses.

Why this answer

Option A is correct because deploying many IoT sensors multiplies entry points (each device's network services, management interfaces, and APIs), greatly expanding the attack surface an adversary can probe or exploit. Option C is correct because IoT devices without a secure firmware update mechanism cannot receive patches for newly disclosed CVEs, leaving them permanently vulnerable to exploitation. Option E is correct because legacy components often run outdated firmware or unsupported OS/protocol stacks with publicly known vulnerabilities that attackers can leverage.

Option B is not a direct security risk but a business/procurement concern, and Option D concerns legal/regulatory data residency rather than a technical security vulnerability.

Exam trap

CRISC often tests the distinction between security risks and non-security concerns such as vendor lock-in or data sovereignty; candidates who select B or D confuse business/compliance issues with technical security exposure.

56
Multi-Selectmedium

A risk practitioner is assessing the security of the organization's software development lifecycle (SDLC). The organization wants to integrate security controls to reduce the risk of introducing vulnerabilities into production. Which TWO of the following are the MOST effective preventive controls to implement during the development phase? (Choose two.)

Select 2 answers
A.Conduct static application security testing (SAST) on source code before code is merged into the main branch.
B.Require developers to complete secure coding training and adhere to a secure coding standard.
C.Implement a web application firewall (WAF) in front of the production application to block malicious traffic.
D.Perform dynamic application security testing (DAST) on applications in the production environment after deployment.
E.Conduct a penetration test on the application after it is deployed to production.
AnswersA, B

SAST analyzes source code for security flaws without executing the program, allowing developers to identify and fix vulnerabilities early in the development phase. Integrating SAST into the CI/CD pipeline before merge ensures that insecure code does not progress to later stages. This is a preventive control that reduces the cost and effort of remediation compared to finding issues in production.

Why this answer

The most effective preventive controls during development are those that stop vulnerabilities from being introduced in the first place. Static application security testing (SAST) analyzes code before it is merged, catching flaws early. Secure coding training and standards give developers the skills to write safer code.

Both are proactive measures integrated into the development phase, unlike DAST, WAF, or penetration testing, which are detective or perimeter controls applied later.

Exam trap

The trap here is confusing detective controls like DAST or penetration testing with preventive controls that belong earlier in the development lifecycle.

57
MCQeasy

In the NIST Cybersecurity Framework, which function is primarily focused on developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Detect
B.Protect
C.Recover
D.Identify
AnswerB

Protect encompasses the safeguards that limit or contain a cybersecurity event's impact, directly satisfying the stem's requirement to ensure delivery of critical infrastructure services. Its categories cover identity management, access control, awareness training, data security, maintenance and protective technology — the controls that actually secure service delivery.

Why this answer

The Protect function in the NIST Cybersecurity Framework (CSF) covers the safeguards that limit or contain the impact of a cybersecurity event — access control, awareness training, data security, information protection processes, maintenance, and protective technology. It is explicitly defined as developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services. Detect, Identify, and Recover address different phases of the risk lifecycle.

Exam trap

CRISC often tests the exact CSF function definitions — the trap is confusing Protect (safeguards) with Detect (monitoring) or Identify (asset/risk understanding), since all three sound defensive.

How to eliminate wrong answers

Option A is wrong because Detect focuses on developing and implementing activities to identify the occurrence of a cybersecurity event (continuous monitoring, detection processes, anomalies) — it does not implement safeguards. Option C is wrong because Recover focuses on developing and implementing activities to restore capabilities or services impaired by a cybersecurity event (recovery planning, improvements, communications). Option D is wrong because Identify focuses on understanding the cybersecurity risk to systems, people, assets, data, and capabilities (asset management, business environment, governance, risk assessment) — it is foundational but not the safeguard-implementation function.

58
MCQeasy

According to COBIT 2019, which governance objective is primarily concerned with evaluating, directing, and monitoring the management of IT risk?

A.EDM03 — Ensure Risk Optimization
B.EDM02 — Ensure Benefits Delivery
C.EDM04 — Ensure Resource Optimization
D.EDM01 — Ensure Governance Framework Setting and Maintenance
AnswerA

EDM03 addresses risk optimisation within the Evaluate, Direct and Monitor domain, ensuring IT-related risk is identified, assessed and kept within the enterprise's risk appetite. It satisfies the stem's governance objective because EDM03 specifically covers evaluating, directing and monitoring IT risk management.

Why this answer

EDM03 — Ensure Risk Optimization is the governance objective that focuses on evaluating, directing, and monitoring risk management to ensure the enterprise's risk appetite and risk tolerance are understood and articulated.

59
MCQmedium

A financial services firm is deploying a new customer portal on a public cloud. The security team proposes using digital certificates to authenticate the portal to clients and sign sensitive transaction data. The risk manager must evaluate the residual risk after certificate deployment. Which of the following is the MOST significant residual risk related to the certificate lifecycle?

A.The certificate's private key might be stored in a hardware security module (HSM) with weak access controls.
B.The certificate's public key algorithm might be deprecated, requiring reissuance.
C.The certificate authority's root certificate might be compromised, allowing attackers to forge certificates.
D.Certificate revocation lists (CRLs) might become too large to distribute efficiently.
AnswerC

Compromise of a trusted root CA undermines the entire chain of trust, enabling attackers to issue fraudulent certificates that appear legitimate. This is a catastrophic residual risk because it can affect all certificates issued under that root, including those used for authentication and signing. Even with strong internal controls, reliance on a third-party CA introduces this systemic risk that cannot be fully mitigated by the organization.

Why this answer

A root certificate authority compromise is the most significant residual risk because it can invalidate the trust model for all certificates issued under that CA. Unlike internal control gaps or operational issues, this risk is external and can have widespread impact, including forged certificates for the organization's portal. Risk managers must consider third-party dependencies and the potential for cascading effects when evaluating residual risk.

Exam trap

The trap here is focusing on internal certificate management issues like key storage or algorithm deprecation while overlooking the systemic risk of a compromised root CA.

60
MCQhard

A multinational corporation is migrating its customer relationship management (CRM) system to a public cloud provider. The data includes personally identifiable information (PII) from multiple jurisdictions. Which risk should be considered most critical during the cloud architecture review?

A.Multi-tenancy isolation failures
B.Data sovereignty and cross-border data transfer restrictions
C.Shared responsibility model gaps for patching
D.Vendor lock-in due to proprietary APIs
AnswerB

PII from multiple jurisdictions triggers conflicting legal requirements about where data may reside and when it may cross borders. Data sovereignty and transfer restrictions therefore dominate the architecture review, since violating them creates regulatory and contractual exposure that other cloud risks do not.

Why this answer

The CRM migration involves PII from multiple jurisdictions, making data sovereignty and cross-border data transfer restrictions the most critical risk. Regulations like GDPR (EU) and local data localization laws (e.g., Russia, China) can impose fines or block transfers if data leaves approved regions. This risk directly impacts legal compliance and operational continuity, outweighing technical concerns like isolation or patching.

Exam trap

The trap here is that candidates confuse technical risks like multi-tenancy or patching with the overriding legal and regulatory risk of data sovereignty, which is the most critical for multinational PII migrations.

How to eliminate wrong answers

Option A is wrong because multi-tenancy isolation failures are a general cloud risk but less critical here; the CRM data is PII, but the primary legal risk is jurisdictional, not technical co-mingling. Option C is wrong because shared responsibility model gaps for patching are operational risks that can be mitigated via SLAs and automated patching, not the most critical for cross-jurisdiction PII. Option D is wrong because vendor lock-in due to proprietary APIs is a long-term strategic risk, not an immediate compliance or legal threat during migration of regulated data.

61
MCQmedium

A hospital's radiology department wants to replace its on-premises PACS archive (DICOM images) with a vendor-hosted SaaS platform. The vendor stores images in its own multitenant cloud and provides a web viewer. Before signing, the risk practitioner must confirm which control MOST directly addresses the risk that a vendor-side compromise could expose patient images to other tenants.

A.Require the vendor to publish a SOC 2 Type II report covering the last twelve months.
B.Require annual penetration testing of the hospital's own internal network by an external firm.
C.Confirm the contract includes a right-to-audit clause allowing the hospital to inspect the vendor's data center.
D.Verify the vendor enforces strict tenant isolation and encryption key separation in the multitenant storage layer.
AnswerD

In a multitenant SaaS PACS, the dominant exposure is logical separation failure, so confirming that tenant isolation is enforced and that each tenant's encryption keys are segregated directly mitigates cross-tenant image disclosure. This control targets the actual mechanism by which one customer could read another customer's DICOM objects, making it the most direct risk response for the stated scenario.

Why this answer

Because the images would reside in a shared multitenant platform, the risk that matters most is logical separation failure between customers. Confirming enforced tenant isolation with segregated encryption keys directly addresses that failure mode. Audit reports, right-to-audit clauses and internal penetration tests provide valuable assurance and leverage but do not specifically prevent one tenant from accessing another tenant's DICOM data.

Exam trap

The trap here is treating vendor assurance artifacts such as SOC 2 reports or right-to-audit clauses as equivalent to evidence that tenant isolation is actually enforced.

62
MCQhard

A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?

A.Establishment of an electronic security perimeter around critical cyber assets
B.Adoption of a cloud-based backup solution
C.Use of quantum-resistant encryption for all communications
D.Implementation of IEC 62443 security levels
AnswerA

NERC CIP requires responsible entities to define and protect an Electronic Security Perimeter enclosing critical cyber assets, controlling all electronic access points into the bulk electric system environment. This is a mandated CIP-005 control, unlike generic measures such as encryption or patching, which are not perimeter-specific.

Why this answer

NERC CIP standards require identification and protection of critical cyber assets, including clear boundaries (electronic security perimeters) to control access.

63
MCQhard

A hospital's risk practitioner is evaluating a new telehealth platform that will process protected health information (PHI). The platform will be hosted by a third-party vendor. Which of the following is the MOST critical risk to address during contract negotiations?

A.The vendor's service level agreement (SLA) for platform uptime.
B.The vendor's use of subcontractors to support the platform.
C.The vendor's data breach notification timeline and liability for regulatory penalties.
D.The vendor's geographic location and data residency practices.
AnswerC

Under HIPAA, the covered entity remains responsible for PHI even when a business associate handles it. The contract must define when and how the vendor will notify the hospital of a breach and who bears the cost of regulatory penalties and patient notifications. Without these terms, the hospital faces unmitigated financial and reputational risk.

Why this answer

When a third party processes PHI, the hospital must ensure the business associate agreement clearly assigns responsibility for breach notification and regulatory penalties. This contractual protection is the most critical risk treatment because it directly addresses the hospital's legal and financial exposure under HIPAA. Other concerns like subcontractors, uptime, and data residency are important but secondary to the allocation of liability.

Exam trap

The trap here is focusing on operational issues like uptime or data location, while overlooking the contractual need to transfer or share liability for PHI breaches.

64
MCQeasy

An organization's data classification policy labels customer payment records as confidential. A risk practitioner is reviewing how the data is protected at rest in a public cloud object storage bucket. Which control BEST ensures that a misconfigured bucket does not expose the data to unauthorized parties?

A.Enable server-side encryption with a customer-managed key for the object storage bucket.
B.Configure versioning and object lock on the bucket to preserve data integrity and prevent deletion.
C.Enforce bucket policies and access control lists that deny public access and apply least privilege to identities.
D.Enable access logging and monitor the bucket for unusual download activity.
AnswerC

The primary cause of cloud storage exposure is permissive bucket policies or ACLs that grant public or broad access. Enforcing deny-public-access settings and least-privilege identity policies directly prevents unauthorized parties from reading the confidential objects, which is the exact exposure scenario. Encryption complements this but does not substitute for correct access control.

Why this answer

Cloud object storage exposure almost always stems from permissive bucket policies or ACLs. Denying public access and applying least-privilege identity policies prevents unauthorized reads at the point of access, directly protecting confidentiality. Encryption, versioning, and logging are useful complementary controls but do not by themselves stop a misconfiguration from granting access.

Exam trap

The trap here is equating encryption at rest with protection against misconfiguration, when encryption does not restrict access granted by a permissive bucket policy.

65
MCQeasy

A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?

A.EDM03 — Ensure Risk Optimization
B.EDM04 — Ensure Resource Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM01 — Ensure Governance Framework Setting and Maintenance
AnswerA

COBIT 2019's EDM03 governance objective sits within the Evaluate, Direct and Monitor domain and explicitly assigns accountability for ensuring risk management is optimised, aligning risk appetite with enterprise objectives. It is the specific objective covering risk optimisation, not risk identification or treatment execution.

Why this answer

COBIT 2019's governance objectives are organized under the EDM (Evaluate, Direct, Monitor) domain. EDM03 — Ensure Risk Optimization is the specific governance objective that ensures enterprise risk is identified, assessed, and managed within the entity's risk appetite, and that risk management activities are optimized. It is the governance-level counterpart to the management-level APO12 (Manage Risk) objective.

Exam trap

CRISC often tests the distinction between the four EDM objectives (EDM01 governance framework, EDM02 benefits delivery, EDM03 risk optimization, EDM04 resource optimization), so candidates who confuse 'risk optimization' with 'resource optimization' pick EDM04.

How to eliminate wrong answers

Option B is wrong because EDM04 — Ensure Resource Optimization focuses on ensuring that adequate and appropriate resources (people, process, technology) are available and optimized, not on risk optimization. Option C is wrong because EDM02 — Ensure Benefits Delivery focuses on optimizing value delivery from investments and services, i.e., benefits realization, not risk. Option D is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance focuses on establishing and maintaining the governance framework (structures, principles, mechanisms), not specifically on optimizing risk.

66
MCQmedium

An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?

A.Vendor lock-in to proprietary protocols
B.Expanded attack surface with unpatched devices
C.Insufficient bandwidth for data transmission
D.Data integrity issues from sensor malfunction
AnswerB

Unpatchable, low-power IoT sensors each expose services that attackers can reach, so every added device widens the exploitable footprint. Prioritising this expanded attack surface with unpatched devices addresses the constraint that firmware cannot be remediated easily across the remote facility.

Why this answer

IoT sensors with limited processing power that cannot be easily patched represent a classic expanded attack surface with unpatched devices. Each unpatched sensor is a potential entry point into the network, and the sheer number of devices multiplies the risk. Because patching is infeasible, compensating controls (network segmentation, monitoring, least privilege) become critical, making this the priority risk for the risk manager.

Exam trap

CRISC often tests prioritization of security risk over operational or strategic risk, so candidates who pick vendor lock-in or bandwidth issues mistake business/performance concerns for the most pressing security exposure.

How to eliminate wrong answers

Option A is wrong because vendor lock-in to proprietary protocols is a strategic/business continuity concern, not the most immediate security risk; it affects flexibility and cost, not the likelihood of compromise. Option C is wrong because insufficient bandwidth is an availability/performance issue that can be addressed with network upgrades or edge processing, and it does not represent a security threat vector. Option D is wrong because data integrity issues from sensor malfunction are a reliability/data-quality concern; while relevant, they are typically addressed through calibration and redundancy and do not carry the same adversarial risk as an unpatched, network-exposed device.

67
MCQhard

A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?

A.Multi-tenancy isolation vulnerabilities
B.Vendor lock-in due to proprietary APIs
C.Shared responsibility model gaps
D.Data sovereignty and cross-border data transfer restrictions
AnswerD

Data residency laws restrict where customer data may be stored and transferred, so a cloud analytics platform spanning jurisdictions risks unlawful cross-border movement of sensitive records. This legal constraint, not generic breach exposure, creates the greatest compliance risk for the institution.

Why this answer

Data sovereignty issues arise when data is stored in jurisdictions with conflicting or unknown legal frameworks, posing significant compliance risk.

68
MCQmedium

A risk practitioner is helping a mid-sized healthcare organization update its IT risk register after migrating patient scheduling to a SaaS platform. The vendor's SOC 2 Type II report shows no exceptions, but the contract omits breach notification timelines and data deletion commitments. Which action BEST addresses the residual risk?

A.Accept the risk because the SOC 2 Type II report confirms the vendor's controls are operating effectively.
B.Transfer the risk by purchasing a cyber insurance policy that covers third-party data breaches.
C.Amend the contract to include specific breach notification timelines, data deletion rights, and audit rights, then reassess the residual risk.
D.Perform a penetration test against the SaaS platform to validate the vendor's security controls.
AnswerC

The SOC 2 report addresses the vendor's internal controls, but the missing contractual terms represent unmitigated legal and compliance risk. Amending the contract to add breach notification timelines, data deletion commitments, and audit rights directly addresses those gaps. Reassessing residual risk afterward ensures the risk register reflects the improved control environment and the organization's reduced exposure.

Why this answer

The vendor's SOC 2 Type II report gives assurance over controls, but it does not replace contractual protections. Missing breach notification timelines and data deletion commitments create legal, regulatory, and reputational risk that the organization must address. Amending the contract to include these terms, along with audit rights, directly mitigates the gap and allows the risk practitioner to reassess residual risk accurately.

Exam trap

The trap here is assuming that a clean SOC 2 Type II report eliminates the need to address contractual gaps such as breach notification and data deletion terms.

69
Multi-Selectmedium

A risk practitioner is assessing the security of an organization's software development lifecycle (SDLC). The organization wants to integrate security early to reduce the cost and impact of fixing vulnerabilities. Which TWO of the following practices are MOST effective for achieving this goal? (Choose two.)

Select 2 answers
A.Performing penetration testing just before production release.
B.Training developers on secure coding practices.
C.Using a web application firewall (WAF) to block attacks in production.
D.Conducting a security audit after the application is deployed.
E.Conducting static application security testing (SAST) during the coding phase.
AnswersB, E

Secure coding training equips developers with the knowledge to avoid common vulnerabilities such as injection and cross-site scripting. When developers understand security principles, they can write more secure code from the start, reducing the need for later fixes. This is a foundational shift-left practice that embeds security into the development process and directly reduces the cost of remediation.

Why this answer

Integrating security early in the SDLC means identifying and fixing vulnerabilities during development rather than after deployment. Static application security testing (SAST) and secure coding training are both shift-left practices that enable developers to find and prevent flaws early, reducing remediation costs. Penetration testing, post-deployment audits, and WAFs are later-stage or runtime controls that do not achieve early integration.

Exam trap

The trap here is selecting later-stage controls like penetration testing or WAFs as effective for early integration, when they actually address vulnerabilities after code is written or deployed.

70
MCQmedium

A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?

A.Model bias
B.Adversarial attacks
C.Explainability requirements
D.Data privacy in AI training
AnswerA

Model bias is the AI/ML risk where training data or algorithm design produces systematically unfair outcomes for particular demographic groups. It directly matches the stem's concern about biased credit-scoring decisions against protected groups, distinguishing it from other risks such as drift, opacity or overfitting.

Why this answer

Model bias occurs when an AI/ML model produces systematically unfair outcomes against certain demographic groups, often because training data reflects historical discrimination or underrepresentation. In credit scoring, if the model learns from historical lending data that excluded or disadvantaged certain groups, it will replicate and even amplify that bias. This is the risk most directly associated with biased outcomes.

Exam trap

CRISC often tests the distinction between AI/ML risk categories (bias, adversarial attacks, explainability, privacy), so candidates who pick explainability or privacy miss that the question is about unfair outcomes, which is bias.

How to eliminate wrong answers

Option B is wrong because adversarial attacks involve malicious actors deliberately manipulating inputs to cause the model to misclassify (e.g., evasion, poisoning), not unintentional bias against demographic groups. Option C is wrong because explainability requirements concern the ability to understand and articulate how a model reaches a decision — a related but distinct governance concern, not the bias itself. Option D is wrong because data privacy in AI training concerns the handling of personal data used to train models (e.g., consent, GDPR), not the fairness of model outputs.

71
MCQmedium

A risk practitioner is designing an IT risk management programme. Which of the following is the BEST sequence of components to establish?

A.Risk register, risk assessment methodology, risk treatment process, risk reporting, risk management policy
B.Risk assessment methodology, risk register, risk treatment process, risk management policy, risk reporting
C.Risk reporting, risk management policy, risk assessment methodology, risk register, risk treatment process
D.Risk management policy, risk assessment methodology, risk register, risk treatment process, risk reporting
AnswerD

Establishing the policy first sets risk appetite and governance, then methodology standardises assessment, the register records findings, treatment addresses them, and reporting communicates results. This order ensures each component builds on approved direction rather than ad hoc activity.

Why this answer

The best sequence starts with a risk management policy, which provides the mandate and framework. Then a risk assessment methodology defines how risks are identified and evaluated. Next, a risk register captures the risks.

Then a risk treatment process defines how to respond. Finally, risk reporting communicates to stakeholders. This logical order ensures that each component builds on the previous one.

Exam trap

CRISC often tests the logical sequence of establishing risk management components, and candidates may incorrectly place reporting or register before policy and methodology.

How to eliminate wrong answers

Option A is wrong because it starts with a risk register before establishing a methodology or policy, which is illogical. Option B is wrong because it places risk management policy after risk treatment, but policy should come first to guide the entire process. Option C is wrong because it starts with risk reporting before any assessment or policy, which is backwards.

72
MCQmedium

A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?

A.Threat event frequency
B.Loss magnitude
C.Vulnerability severity score
D.Annualized rate of occurrence
AnswerB

FAIR quantifies risk as loss event frequency multiplied by loss magnitude. Loss magnitude estimates the probable financial impact of a breach, covering primary and secondary response, replacement and reputational costs, which is exactly the factor needed for the impact calculation.

Why this answer

In the FAIR (Factor Analysis of Information Risk) model, risk is quantified as the probable frequency and probable magnitude of future loss. To calculate the probable financial impact of a data breach, the practitioner must estimate Loss Magnitude — the monetary value of the loss event, typically broken down into primary loss (response, replacement, fines) and secondary loss (reputation, legal, competitive advantage). Threat event frequency drives the probability side of the equation, not the impact side.

Exam trap

CRISC often tests the distinction between frequency factors (TEF, ARO) and magnitude factors (Loss Magnitude, SLE) in quantitative risk models — candidates who see 'financial impact' and grab a familiar acronym like ARO or a severity score like CVSS fall into the trap.

How to eliminate wrong answers

Option A is wrong because Threat Event Frequency (TEF) is a frequency/likelihood factor in FAIR that estimates how often threat agents act against the asset — it feeds the probability of loss, not the financial magnitude. Option C is wrong because Vulnerability Severity Score (e.g., CVSS) is a technical severity metric, not a FAIR financial loss variable, and FAIR deliberately avoids severity scores in favor of calibrated probability and loss estimates. Option D is wrong because Annualized Rate of Occurrence (ARO) is a classic quantitative risk formula input (SLE × ARO = ALE), not a FAIR loss magnitude factor, and it measures frequency, not impact.

73
MCQmedium

During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?

A.Require encryption (e.g., TLS) for the communication
B.Transfer the risk to a third-party vendor
C.Accept the risk because the legacy system cannot be changed
D.Decommission the legacy system immediately
AnswerA

TLS encrypts data in transit, directly removing the plain-text exposure over the public network that the ARB flagged. Encryption is a preventive control that reduces likelihood, which suits an architectural review where the risk is interception of credentials or sensitive payloads.

Why this answer

Requiring encryption (e.g., TLS) directly mitigates the confidentiality and integrity risk of plaintext transmission over a public network by protecting data in transit. This is the most appropriate risk treatment because it addresses the root cause—unprotected communication—without disrupting the legacy system's functionality. TLS provides encryption, authentication, and integrity checking, which are standard controls for this scenario.

The ARB should mandate this as a condition of approval.

Exam trap

CRISC often tests the misconception that risk transfer (e.g., to a vendor) or acceptance is acceptable when a simple technical control like encryption can mitigate the risk; candidates may overlook that encryption is a direct and feasible treatment.

How to eliminate wrong answers

Option B is wrong because transferring risk to a third-party vendor does not eliminate the vulnerability; the vendor may not accept liability for plaintext transmission, and the organization still retains reputational and regulatory risk. Option C is wrong because accepting the risk is inappropriate when a feasible and cost-effective mitigation (encryption) exists; acceptance should only be considered after all other treatments are evaluated and if the risk is within tolerance. Option D is wrong because decommissioning the legacy system immediately is a drastic, potentially disruptive action that may not be feasible due to business dependencies, and it does not address the immediate need for secure communication.

74
MCQmedium

An organization is implementing the NIST Cybersecurity Framework to manage cyber risk. The risk manager is mapping the 'Detect' function to existing risk management processes. Which of the following activities is MOST directly aligned with the 'Detect' function?

A.Implementing continuous security monitoring of network traffic
B.Developing an incident response plan
C.Conducting a business impact analysis
D.Establishing a patch management process
AnswerA

Continuous security monitoring of network traffic directly fulfils the Detect function's requirement to identify cybersecurity events as they occur. Unlike Identify or Protect activities, detection demands ongoing visibility, and traffic monitoring provides the timely anomaly discovery the framework expects, satisfying the stem's mapping of Detect to risk management processes.

Why this answer

The NIST Cybersecurity Framework's Detect function (DE) covers activities that identify the occurrence of a cybersecurity event, including continuous security monitoring (DE.CM), anomaly and event detection (DE.AE), and detection processes (DE.DP). Implementing continuous security monitoring of network traffic maps directly to DE.CM-1 (network monitoring) and is the clearest example of a Detect activity. It is about discovering events, not responding to or preventing them.

Exam trap

CRISC often tests function-boundary confusion in the NIST CSF — candidates see 'incident response plan' or 'patch management' and pick them because they sound security-related, missing that Respond and Protect functions are distinct from Detect.

How to eliminate wrong answers

Option B is wrong because developing an incident response plan belongs to the Respond function (RS.RP — response planning), which executes after a detection occurs. Option C is wrong because conducting a business impact analysis is part of risk assessment and business continuity planning, aligned with the Identify function (ID.RA, ID.BE) and not the Detect function. Option D is wrong because establishing a patch management process is a Protect function activity (PR.IP — protective technology and maintenance), aimed at preventing exploitation rather than detecting it.

75
MCQmedium

A global retailer is migrating its point-of-sale (POS) transaction processing to a public cloud provider. The risk practitioner must ensure that the organization's payment card data remains compliant with PCI DSS. Which of the following is the MOST appropriate control to implement FIRST?

A.Implement a web application firewall (WAF) in front of the cloud-based POS application.
B.Require the cloud provider to sign a PCI DSS attestation of compliance (AOC).
C.Encrypt all cardholder data at rest and in transit using strong cryptography.
D.Conduct a data discovery and classification exercise to identify all cardholder data locations.
AnswerD

Before any controls can be effectively applied, the organization must know where cardholder data is stored, processed, and transmitted in the cloud environment. Data discovery and classification define the scope of PCI DSS compliance and ensure that subsequent controls are applied to the correct assets, preventing gaps or unnecessary effort.

Why this answer

The first step in any cloud migration involving cardholder data is to discover and classify that data to define the PCI DSS scope. Without knowing where the data resides, the organization cannot accurately apply encryption, firewalls, or contractual controls. Data discovery ensures that all subsequent risk treatments are targeted and complete, forming the foundation for compliance.

Exam trap

The trap here is assuming that encryption or a WAF is always the first control, when in fact you cannot protect data you have not yet located and classified.

Page 1 of 3 · 152 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Information Technology and Security questions.