Courseiva

CCNA Information Technology and Security Questions

75 of 152 questions · Page 2/3 · Information Technology and Security · Answers revealed

76
Multi-Selecteasy

Which TWO of the following are key functions of an Architecture Review Board (ARB) in managing risk?

Select 2 answers
A.Managing user access controls
B.Performing daily vulnerability scans
C.Reviewing solution architectures for security risks before implementation
D.Responding to security incidents
E.Ensuring architecture alignment with risk appetite
AnswersC, E

This is a primary ARB responsibility.

Why this answer

A primary function of an Architecture Review Board (ARB) is to evaluate solution architectures for security risks prior to implementation. This proactive review ensures that security controls are embedded in the design phase, reducing the likelihood of vulnerabilities being introduced into production systems.

Exam trap

The trap here is confusing operational security tasks (like access control, scanning, or incident response) with the strategic, governance-focused role of the ARB, which is to ensure architectural decisions align with risk appetite and security requirements before deployment.

77
MCQeasy

A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?

A.IT strategy
B.Risk management policy
C.Business continuity plan
D.Risk register
AnswerB

A risk management policy is the governing document that mandates the organization's approach to risk assessment, treatment, and reporting, satisfying the stem's requirement for a primary source. It establishes authority, scope, and responsibilities, unlike frameworks or procedures, which support implementation rather than define the overarching programme.

Why this answer

The risk management policy is the authoritative document that establishes the organization's overall approach to risk management, including the principles, roles, responsibilities, and processes for risk assessment, treatment, and reporting. It sets the governance framework and mandates how risk activities must be conducted across the IT environment, ensuring consistency and alignment with business objectives.

Exam trap

The trap here is that candidates often confuse the risk register (a tactical tool) with the risk management policy (a strategic governance document), mistakenly thinking the register defines the process rather than just recording the outputs.

How to eliminate wrong answers

Option A is wrong because the IT strategy defines the long-term technology direction and investment priorities, not the specific procedures for risk assessment, treatment, and reporting. Option C is wrong because the business continuity plan focuses on maintaining or restoring operations after a disruption, not on the ongoing risk management process of identifying, analyzing, and treating risks. Option D is wrong because the risk register is a living document that records identified risks, their assessments, and treatment plans, but it does not define the overarching methodology or governance for risk management.

78
MCQmedium

An organization is deploying IoT sensors in a manufacturing plant. Which of the following is the MOST significant security risk associated with these devices?

A.Interference with radio frequency signals
B.Limited data storage capacity
C.High power consumption leading to operational costs
D.Inability to apply security patches due to legacy firmware
AnswerD

Legacy firmware often cannot accept vendor patches, leaving known vulnerabilities permanently exploitable on plant-floor sensors with long service lives. This satisfies the stem's constraint of identifying the most significant risk, since unpatchable devices sustain exposure that segmentation or monitoring alone cannot remediate.

Why this answer

IoT devices often have limited security features and may lack the ability to receive firmware updates, making them vulnerable and expanding the attack surface.

79
MCQhard

A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time data analytics. Which of the following represents the MOST significant risk introduced by this convergence?

A.Increased complexity in managing network bandwidth
B.Potential for increased data redundancy
C.Expansion of the attack surface from IT to OT environments
D.Higher licensing costs for security software
AnswerC

Bridging IT and OT dissolves the air gap that previously isolated industrial control systems. Each newly reachable OT device, protocol and service becomes an additional entry point, so the attack surface expands from enterprise IT into operational technology, exposing safety-critical processes to IT-borne threats.

Why this answer

Connecting ICS to the corporate network expands the attack surface, allowing threats from the IT network to reach OT systems, potentially leading to safety incidents.

80
MCQeasy

A retail company's risk register lists 'unauthorized access to the customer loyalty database' with a likelihood of 4 and an impact of 5 on a 1-5 scale. The CISO asks the risk practitioner to reduce the risk to an acceptable level. Which action BEST represents risk treatment in this situation?

A.Report the risk to the board risk committee and request a decision on acceptance.
B.Recalculate the likelihood and impact scores with the database team and update the risk register.
C.Deploy database activity monitoring and enforce least-privilege access to the loyalty database.
D.Purchase a cyber insurance policy that covers privacy breach response costs.
AnswerC

Risk treatment is the deliberate selection and implementation of controls that modify likelihood or impact. Database activity monitoring detects anomalous access while least-privilege enforcement reduces the chance that compromised accounts can reach sensitive records, directly lowering the likelihood component of the registered risk. This is a concrete, targeted control response rather than documentation or measurement activity.

Why this answer

Risk treatment means selecting and applying controls that change the likelihood or impact of an identified risk. Enforcing least privilege and monitoring database activity directly reduce the chance of unauthorized access, which is the likelihood dimension in the register. Re-scoring, escalation and insurance are assessment, governance and transfer activities that leave the underlying exposure unchanged.

Exam trap

The trap here is confusing activities that document, escalate or transfer risk with activities that actually modify the risk itself.

81
Multi-Selectmedium

An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?

Select 2 answers
A.Model bias causing discriminatory outcomes
B.Model explainability for regulatory compliance
C.Data privacy in AI training
D.High computational cost of model retraining
E.Adversarial attacks on the training data
AnswersA, B

Discriminatory outcomes breach fair-lending legislation and expose the organisation to enforcement action and litigation. Bias arises from unrepresentative training data or proxy variables, so testing for disparate impact across protected groups is a governance control that directly addresses the stem's regulatory oversight constraint.

Why this answer

Option A (Model bias causing discriminatory outcomes) is correct because credit approval is a legally regulated decision domain where biased models can produce discriminatory lending practices, violating fair-lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act, exposing the organization to enforcement actions and reputational harm. Option B (Model explainability for regulatory compliance) is correct because regulators in credit decisions require the ability to understand and justify adverse action reasons, typically under regulations like the Equal Credit Opportunity Act (ECOA) and the Fair Credit Reporting Act (FCRA), making explainability essential for compliance and auditability. Options C, D, and E, while relevant to AI/ML generally, are not the most significant risk considerations in this specific regulated credit-approval scenario: data privacy (C) matters but is secondary to fairness and explainability in lending regulation, high computational cost (D) is an operational efficiency concern rather than a regulatory risk, and adversarial attacks on training data (E) are a security concern that is less directly tied to the regulatory oversight governing credit decisions.

Exam trap

CRISC often tests whether candidates can distinguish the most significant regulatory risks from general operational or security risks, so the trap is selecting data privacy or compute cost when the question is specifically about a regulated credit decision where bias and explainability are the legally material concerns.

82
Multi-Selectmedium

A risk practitioner is evaluating the organization's identity and access management (IAM) controls as part of an IT risk assessment. The organization has a hybrid environment with on-premises Active Directory and a cloud identity provider. Which TWO of the following are the MOST significant risks that should be prioritized? (Choose two.)

Select 2 answers
A.The organization uses single sign-on (SSO) for cloud applications, which may create a single point of failure.
B.Inconsistent identity synchronization between the on-premises directory and the cloud identity provider, leading to stale or orphaned accounts.
C.Excessive standing privileges assigned to service accounts that are not regularly reviewed.
D.Users are required to change passwords every 90 days without a history check.
E.Some legacy applications do not support multi-factor authentication (MFA).
AnswersB, C

When synchronization fails or is misconfigured, accounts disabled on-premises may remain active in the cloud, and terminated users may retain access. This creates unauthorized access paths to cloud resources. In a hybrid model, synchronization integrity is foundational to access control, making this a high-priority risk that can undermine the entire IAM control set.

Why this answer

In hybrid IAM, the greatest risks arise from controls that grant or preserve broad access without adequate oversight. Excessive standing privileges on service accounts enable attackers to move laterally and persist, while synchronization failures can leave active cloud credentials for users who should no longer have access. Both directly undermine the principle of least privilege and are often missed because they sit between on-premises and cloud governance processes.

Exam trap

The trap here is treating common password policy weaknesses or SSO availability as top risks, while missing that service-account privilege sprawl and synchronization integrity are the systemic issues that enable unauthorized access.

83
MCQmedium

A company's risk management policy requires a risk register to be maintained. Which of the following is the primary purpose of a risk register?

A.To assign financial values to all risks
B.To document and track identified risks, assessments, and risk responses
C.To record audit findings
D.To provide a list of all IT assets
AnswerB

A risk register is the central record capturing each identified risk together with its assessment results and chosen responses, enabling tracking and ownership over time. This supports the policy requirement by giving management a single, auditable view of risk status and treatment progress.

Why this answer

The primary purpose of a risk register is to serve as a central repository for documenting and tracking all identified risks, their assessments (including likelihood and impact), and the corresponding risk response strategies. This ensures that risk management activities are transparent, auditable, and actionable throughout the risk lifecycle, aligning with the ISACA CRISC framework.

Exam trap

The trap here is that candidates confuse the risk register with other operational logs (e.g., audit findings or asset inventories) or assume its primary purpose is financial quantification, whereas the CRISC exam emphasizes its role as a comprehensive tracking and documentation tool for the entire risk management process.

How to eliminate wrong answers

Option A is wrong because assigning financial values to risks is a specific activity within risk analysis (e.g., quantitative risk assessment using ALE/SLE), not the primary purpose of the risk register itself; the register may include such values but is not limited to them. Option C is wrong because audit findings are recorded in audit reports or issue logs, not the risk register; the risk register focuses on forward-looking risk identification and treatment, not retrospective audit results. Option D is wrong because a list of all IT assets is typically maintained in an asset inventory or configuration management database (CMDB), not the risk register; the risk register only includes assets relevant to identified risks.

84
MCQmedium

Which standard is specifically designed for industrial automation and control systems security and provides a framework for addressing security in IACS?

A.ISO 27001
B.NERC CIP
C.IEC 62443
D.NIST SP 800-53
AnswerC

IEC 62443 is the only standard written specifically for industrial automation and control systems, defining security requirements across zones and conduits. It directly satisfies the stem's demand for an IACS-specific framework, unlike generic IT standards such as ISO 27001, which lack operational technology controls.

Why this answer

IEC 62443 is the international standard series specifically designed for industrial automation and control systems (IACS) security. It provides a framework for securing IACS across the entire lifecycle, including risk assessment, system design, and operational security, with roles defined for asset owners, system integrators, and product suppliers. It is the de facto standard for OT/ICS security.

Exam trap

CRISC often tests the difference between general IT security standards (ISO 27001, NIST SP 800-53) and sector-specific or OT-specific standards (IEC 62443, NERC CIP), so candidates pick a well-known general standard instead of the IACS-specific one.

How to eliminate wrong answers

Option A is wrong because ISO 27001 is a general information security management system (ISMS) standard applicable to all industries; it does not provide IACS-specific security requirements or control system guidance. Option B is wrong because NERC CIP is a North American regulatory standard specifically for the bulk electric system (power grid) in the US and Canada; it is not a general IACS framework and applies only to registered entities in the electric sector. Option D is wrong because NIST SP 800-53 is a broad catalog of security and privacy controls for US federal information systems; while it can be applied to OT, it is not specifically designed for industrial automation and control systems.

85
MCQmedium

A risk practitioner at a healthcare insurer is mapping the organization's IT risk register to the NIST Cybersecurity Framework (CSF) 2.0. Executive leadership wants assurance that the organization understands which assets and business processes depend on which systems before any risk treatment decisions are made. Which CSF 2.0 function and category BEST addresses this requirement?

A.IDENTIFY (ID) — Asset Management (ID.AM)
B.DETECT (DE) — Continuous Monitoring (DE.CM)
C.GOVERN (GV) — Risk Management Strategy (GV.RM)
D.PROTECT (PR) — Identity Management, Authentication, and Access Control (PR.AA)
AnswerA

ID.AM requires the organization to inventory hardware, software, services, and systems and to map them to business functions and processes. For the healthcare insurer, this directly produces the asset-to-business-process dependency view leadership is asking for, making it the correct foundation before any risk response or treatment decision is taken.

Why this answer

The insurer needs to know which systems support which business processes before deciding on treatment, and that dependency mapping is the core purpose of the IDENTIFY function's Asset Management category. Governance sets direction, PROTECT enforces controls, and DETECT finds events, but none of those produces the asset-to-process inventory that leadership explicitly requested.

Exam trap

The trap here is assuming that any governance or risk strategy category satisfies an executive request for asset visibility, when dependency mapping is really an IDENTIFY function activity.

86
MCQhard

An organization is reviewing its enterprise architecture to identify risks. In which IT architecture layer would a risk related to data classification and data sovereignty be primarily addressed?

A.Application architecture layer
B.Business architecture layer
C.Data architecture layer
D.Infrastructure/Technology architecture layer
AnswerC

Data classification and data sovereignty govern how information is categorised, stored and transferred across jurisdictions, which are concerns defined within the data architecture layer. This layer specifies data entities, ownership and residency rules, so the risk is primarily addressed there rather than in application, technology or business architecture.

Why this answer

Data classification and data sovereignty are concerns about how data is categorized, where it resides, and which legal/regulatory jurisdictions govern it — all of which are addressed in the data architecture layer. This layer defines data models, ownership, retention, classification schemes, and cross-border data flow rules. Risk related to sovereignty (e.g., GDPR data residency) is fundamentally a data architecture design issue.

Exam trap

The trap is assuming that because data physically resides on infrastructure, sovereignty and classification belong to the infrastructure layer — CRISC tests whether you understand that data governance policy is defined at the data architecture layer, with infrastructure merely implementing it.

How to eliminate wrong answers

Option A is wrong because application architecture deals with how software components are structured and integrated, not data residency or classification policy. Option B is wrong because business architecture covers business processes, capabilities, and organizational structure — it may inform data policy but does not primarily address classification/sovereignty controls. Option D is wrong because infrastructure/technology architecture concerns servers, networks, and platforms; while data physically resides there, sovereignty and classification are governed at the data layer, not the hardware layer.

87
MCQeasy

Which of the following is a key component of the NIST Cybersecurity Framework's 'Identify' function?

A.Recovery planning
B.Response planning
C.Anomalies and events detection
D.Risk assessment
AnswerD

Risk assessment underpins the Identify function, establishing organisational understanding of cybersecurity risk to systems, assets and data. It inventories assets and evaluates threats and vulnerabilities, directly satisfying the framework's requirement to identify risk before protective controls are selected.

Why this answer

The NIST Cybersecurity Framework's Identify function includes categories such as Asset Management, Business Environment, Governance, Risk Assessment, and Risk Management Strategy. Risk assessment is explicitly a key component of Identify because understanding organizational risk is foundational to prioritizing cybersecurity activities. It is listed under ID.RA in the framework core.

Exam trap

The trap is mixing up the five CSF functions — candidates often associate 'risk assessment' with governance or protection, but CRISC tests that risk assessment is an Identify function, while recovery and response planning belong to Recover and Respond respectively.

How to eliminate wrong answers

Option A is wrong because recovery planning belongs to the Recover function (RC.RP), not Identify. Option B is wrong because response planning belongs to the Respond function (RS.RP). Option C is wrong because anomalies and events detection belongs to the Detect function (DE.AE).

88
MCQeasy

An organization is implementing a bring your own device (BYOD) program. The risk practitioner is asked to identify the control that BEST reduces the risk of data leakage from lost or stolen mobile devices.

A.Require complex passwords on all BYOD devices.
B.Conduct annual security awareness training for BYOD users.
C.Implement mobile device management (MDM) with remote wipe and encryption enforcement.
D.Prohibit storing any corporate data on BYOD devices.
AnswerC

MDM allows the organization to enforce encryption, require screen locks, and remotely wipe corporate data if a device is lost or stolen. This directly mitigates the risk of data leakage by ensuring data is encrypted at rest and can be erased. It is the most effective control for the stated scenario.

Why this answer

The most effective way to reduce data leakage from lost or stolen BYOD devices is to enforce encryption and enable remote wipe through MDM. This ensures that even if the device is compromised, the data remains protected or can be erased. Other controls are helpful but do not provide the same direct technical mitigation.

Exam trap

The trap here is choosing a policy or awareness control when the question asks for the control that best reduces data leakage from a lost device, which requires technical enforcement.

89
MCQmedium

An organization is implementing a new cloud-based CRM system. The risk manager is reviewing the solution architecture for security risks. Which architectural layer should be evaluated to ensure data encryption at rest and in transit?

A.Application architecture
B.Data architecture
C.Infrastructure architecture
D.Business architecture
AnswerB

Data architecture defines how data is stored, classified and protected, encompassing encryption at rest in databases and in transit across networks. Evaluating this layer directly verifies that the CRM's encryption controls satisfy the stem's security requirement.

Why this answer

Data architecture defines how data is stored, processed, and transmitted, including encryption policies. To ensure data encryption at rest (e.g., AES-256 for stored CRM records) and in transit (e.g., TLS 1.2/1.3 for API calls), the risk manager must evaluate the data architecture layer, which specifies encryption standards, key management, and data flow controls.

Exam trap

The trap here is that candidates often confuse 'infrastructure architecture' with data security controls, but encryption policies and data flow protections are explicitly part of the data architecture layer, not the underlying hardware or network layer.

How to eliminate wrong answers

Option A is wrong because application architecture focuses on software components, APIs, and business logic, not on encryption mechanisms for data at rest or in transit. Option C is wrong because infrastructure architecture covers hardware, networks, and virtualization layers, but encryption policies and data flow security are defined at the data architecture level. Option D is wrong because business architecture addresses organizational goals, processes, and governance, not technical encryption controls.

90
Multi-Selectmedium

A risk manager is integrating risk management with IT governance. Which of the following are key elements of an IT risk management programme design? (Choose TWO.)

Select 2 answers
A.Risk assessment methodology
B.Incident response plan
C.Business continuity plan
D.Vendor management policy
E.Risk register
AnswersA, E

A defined risk assessment methodology is essential because it establishes consistent likelihood and impact criteria, enabling risks to be identified, analysed and prioritised against the organisation's risk appetite. This directly satisfies the stem's requirement for governance integration, since IT governance depends on repeatable, comparable risk evaluations feeding escalation and oversight processes.

Why this answer

Option A (Risk assessment methodology) is correct because an IT risk management programme must define a consistent, repeatable approach for identifying, analyzing, and evaluating risks — including likelihood, impact, and risk criteria — so that risks can be prioritized and treated consistently across the enterprise. Option E (Risk register) is correct because it is the core record that captures identified risks, their owners, ratings, treatment decisions, and status, enabling ongoing monitoring and reporting that links IT risk to governance objectives. The other options do not belong as key design elements of an IT risk management programme: an incident response plan (B) and a business continuity plan (C) are operational response and recovery capabilities that may be informed by risk assessments but are not themselves risk programme design components, and a vendor management policy (D) is a third-party governance control that addresses only one risk domain rather than the overall programme structure.

Exam trap

The trap is selecting operational security documents (IR plan, BCP, vendor policy) as risk programme design elements — CRISC tests whether you distinguish foundational risk management components (methodology, register) from adjacent operational plans that consume risk outputs.

91
MCQmedium

An architecture review board (ARB) is evaluating a new solution architecture that processes sensitive data. Which of the following should the ARB review to ensure security risks are addressed before implementation?

A.User acceptance test plan
B.Business case and ROI analysis
C.Threat model and security controls
D.Project timeline and budget
AnswerC

A threat model identifies attack vectors and required mitigations for the sensitive data flows, while the security controls demonstrate those risks are actually treated. Reviewing both before implementation satisfies the ARB's mandate to confirm security risks are addressed prior to build, rather than discovered post-deployment.

Why this answer

The ARB must ensure that security risks are identified and mitigated before implementation. A threat model systematically identifies potential threats (e.g., STRIDE) and maps them to security controls, ensuring that sensitive data is protected against attacks like injection, disclosure, or tampering. Without this review, the architecture could be deployed with unaddressed vulnerabilities.

Exam trap

The trap here is that candidates confuse project governance artifacts (UAT plan, business case, timeline) with security-specific risk assessment deliverables, leading them to select a generic project management option instead of the threat model that directly addresses security risks.

How to eliminate wrong answers

Option A is wrong because a user acceptance test plan validates functional requirements and usability, not security risks or threat mitigation. Option B is wrong because the business case and ROI analysis focus on financial justification and cost-benefit, not on identifying or addressing security threats. Option D is wrong because the project timeline and budget are project management artifacts that track schedule and cost, not security risk assessment or control validation.

92
MCQmedium

A financial institution is considering adopting a new AI/ML model for credit scoring. The model uses customer demographic data and transaction history. Which of the following risks is MOST likely to cause regulatory penalties if not addressed?

A.Data privacy of training data
B.Model drift due to changing economic conditions
C.Model bias leading to unfair lending practices
D.Adversarial attacks on the model
AnswerC

Model bias producing discriminatory lending outcomes directly violates fair-lending regulations, such as the Equal Credit Opportunity Act, exposing the institution to penalties. Because the model ingests demographic data, protected attributes can proxy into scoring decisions, so bias testing and mitigation are mandatory controls under this scenario's regulatory constraint.

Why this answer

Model bias leading to unfair lending practices is the most likely risk to cause regulatory penalties because credit scoring is heavily regulated under fair lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act. If an AI/ML model uses demographic data and produces disparate impact on protected classes, regulators can impose fines, sanctions, and enforcement actions. Unlike data privacy or model drift, bias directly violates anti-discrimination statutes, making it a legal compliance issue with immediate regulatory consequences.

Exam trap

CRISC often tests the distinction between technical risks (like model drift or adversarial attacks) and compliance risks (like bias), where the latter directly triggers regulatory penalties under fair lending laws.

How to eliminate wrong answers

Option A is wrong because while data privacy violations can lead to penalties under GDPR or CCPA, they are typically addressed through consent and data protection measures, and the question emphasizes regulatory penalties for unfair lending, which is a more direct and severe compliance breach. Option B is wrong because model drift affects model performance and accuracy over time but does not inherently violate regulations; it is a model risk management concern, not a direct legal violation. Option D is wrong because adversarial attacks are a security risk that can cause financial loss or data breaches, but they are not specifically tied to regulatory penalties for credit scoring fairness; they are more about model robustness and cybersecurity.

93
MCQeasy

A risk practitioner is reviewing the organization's backup and recovery procedures for critical systems. The organization wants to ensure that backups are protected against ransomware attacks that could encrypt both production data and backups. Which of the following controls is MOST effective for this purpose?

A.Performing daily full backups instead of incremental backups.
B.Encrypting backups with a strong encryption algorithm.
C.Storing backups on the same network as production systems with access controls.
D.Implementing immutable backups that cannot be altered or deleted for a set period.
AnswerD

Immutable backups prevent modification or deletion, even by administrators or attackers with elevated privileges, for a defined retention period. This ensures that a clean copy of data remains available for recovery after a ransomware attack. It directly addresses the risk of backups being encrypted or destroyed, providing a reliable recovery point.

Why this answer

Immutable backups are the most effective control because they cannot be altered or deleted for a set period, ensuring a clean recovery point even if ransomware compromises the network. Other controls like network access controls, encryption, or backup frequency do not prevent backups from being encrypted or deleted by ransomware.

Exam trap

The trap here is assuming that encryption or network access controls alone protect backups, when they do not prevent ransomware from encrypting or deleting backup files.

94
MCQmedium

A risk practitioner at a healthcare payer is reviewing the organization's disaster recovery (DR) strategy for its core claims adjudication system. The business owner has stated that the maximum tolerable downtime is 4 hours, but the current DR plan relies on restoring from nightly tape backups, which would take at least 30 hours. Which of the following is the MOST appropriate action for the risk practitioner to take FIRST?

A.Perform a full business impact analysis to determine whether the 4-hour maximum tolerable downtime is still valid.
B.Document the gap between the recovery time objective and the achievable recovery time, and escalate it to the business owner and IT leadership for a risk decision.
C.Update the DR plan to state that the recovery time objective is 30 hours, because that is what the current infrastructure can achieve.
D.Immediately purchase a real-time replication solution to meet the 4-hour requirement and inform the business owner after implementation.
AnswerB

The practitioner's role is to identify and communicate the misalignment between the stated maximum tolerable downtime and the actual recovery capability, then escalate for a formal risk decision. Documenting and escalating ensures the business owner understands the residual risk and can approve, mitigate, or transfer it, which is the core of risk governance.

Why this answer

The core issue is a mismatch between the business-required recovery time objective and what the current DR strategy can deliver. The risk practitioner must first document and escalate this gap so the business owner can make an informed risk decision. Directly purchasing technology or rewriting the objective without approval would circumvent governance.

Exam trap

The trap here is assuming the risk practitioner should immediately fix the technical shortfall or adjust the objective, rather than escalate the risk for a business decision.

95
Multi-Selectmedium

A risk manager is evaluating IoT device risks for a smart building project. Which TWO of the following are significant IoT security risks?

Select 2 answers
A.Data sovereignty compliance
B.Quantum computing threat to cryptography
C.Vendor lock-in
D.Firmware update challenges
E.Expanded attack surface due to many connected devices
AnswersD, E

Many IoT devices lack automated update mechanisms, and firmware patches are often manual, intermittent or unsupported once vendors end lifecycles. Unpatched firmware leaves known vulnerabilities exploitable for years, a structural weakness distinct from conventional IT patching.

Why this answer

Option D is correct because IoT devices often lack a reliable mechanism for secure firmware updates: many have limited processing power, no signed-update verification, or no supported update channel, leaving known vulnerabilities unpatched and devices exploitable over their lifetime. Option E is correct because a smart building connects potentially thousands of heterogeneous sensors, actuators, and controllers, each exposing network interfaces and services, which dramatically expands the attack surface and gives adversaries more entry points and lateral-movement paths. The remaining options do not belong: data sovereignty compliance (A) is a legal/regulatory concern rather than a technical IoT security risk, quantum computing (B) is a long-term cryptographic threat affecting all IT rather than a significant near-term IoT-specific risk, and vendor lock-in (C) is a business/procurement issue, not a security vulnerability.

Exam trap

The trap is selecting broad governance or emerging-technology risks (data sovereignty, quantum threat, vendor lock-in) as IoT-specific security risks — CRISC tests whether you can distinguish inherent technical IoT vulnerabilities (firmware updates, attack surface) from general enterprise risks that apply to any technology.

96
Multi-Selectmedium

An organization is planning to adopt post-quantum cryptography. Which TWO considerations are MOST important for migration planning?

Select 2 answers
A.Evaluate the cost of quantum computers
B.Assess the cryptographic agility of current systems
C.Identify systems that need long-term confidentiality (e.g., classified data)
D.Train employees on quantum physics
E.Purchase quantum-resistant hardware immediately
AnswersB, C

Cryptographic agility determines how quickly algorithms can be swapped without redesigning applications or protocols. Assessing it exposes hard-coded cryptography and vendor dependencies, so migration planning can schedule remediation of inflexible systems before post-quantum standards are mandated.

Why this answer

Option B is correct because cryptographic agility—the ability of systems to swap algorithms, keys, and protocols without major redesign—is essential for migrating to post-quantum cryptography (PQC), since standards such as ML-KEM (FIPS 203) and ML-DSA (FIPS 204) will continue to evolve and hybrid deployments (e.g., X25519+ML-KEM) must be supported during transition. Option C is correct because systems protecting data with long confidentiality lifetimes (classified, health, financial records) are exposed to 'harvest now, decrypt later' attacks, so migration priority must be driven by how long the data must remain secret versus when a cryptographically relevant quantum computer (CRQC) is expected. Option A is not a migration-planning consideration because the cost of quantum computers is irrelevant to an organization's own cryptographic inventory and transition roadmap.

Option D is unnecessary because adopting PQC requires cryptographic and IT expertise, not training staff in quantum physics. Option E is premature because standardized PQC algorithms run on existing classical hardware via software/firmware updates, so buying 'quantum-resistant hardware' immediately is neither required nor a sound first step.

Exam trap

CRISC often tests the distinction between strategic risk-planning considerations (crypto agility, data lifetime) and tactical or irrelevant distractors (buying hardware, training on physics) — candidates who pick the 'most action-oriented' answer instead of the 'most risk-relevant' answer get it wrong.

97
MCQmedium

An organization is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. Which of the following is the PRIMARY risk introduced by this IT/OT convergence?

A.Reduced availability of OT systems
B.Higher cost of network equipment
C.Expansion of the attack surface to OT systems
D.Increased complexity of data analytics
AnswerC

Connecting ICS to the corporate network exposes OT devices to enterprise-originated threats, expanding the attack surface. Previously isolated industrial protocols and controllers become reachable, enabling lateral movement from compromised corporate endpoints into operational technology, which directly satisfies the stem's IT/OT convergence scenario and its primary risk.

Why this answer

Connecting ICS/OT systems to the corporate IT network exposes previously isolated OT devices to the corporate attack surface, allowing threats that compromise IT to pivot into OT. This expansion of the attack surface is the primary risk of IT/OT convergence because OT systems often lack security controls and cannot be easily patched. The other options are secondary or not risks at all.

Exam trap

The trap is selecting a consequence (reduced availability) or a non-risk (cost, complexity) instead of the root risk — the expansion of the attack surface to OT systems.

How to eliminate wrong answers

Option A is wrong because reduced availability is a potential consequence of a successful attack, not the primary risk introduced by convergence itself; the primary risk is exposure. Option B is wrong because higher equipment cost is a financial consideration, not a security risk, and is not the primary risk of IT/OT convergence. Option D is wrong because increased complexity of data analytics is an operational challenge, not the primary security risk; the question asks for the PRIMARY risk, which is attack surface expansion.

98
MCQmedium

An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?

A.The application does not support mobile devices
B.The application development timeline is aggressive
C.The application uses the latest JavaScript framework
D.The application exposes sensitive customer data through APIs without proper authentication
AnswerD

Exposing sensitive customer data through unauthenticated APIs directly threatens confidentiality, the core risk for a customer-facing application. Microsoft Entra ID authentication controls would mitigate this, but the ARB's primary concern is whether the architecture enforces authentication at all, satisfying the stem's focus on identifying the foremost architectural risk.

Why this answer

The primary risk an Architecture Review Board should consider is the exposure of sensitive customer data through unauthenticated APIs, because this represents a direct, high-impact security and compliance risk (data breach, regulatory penalties, reputational damage). ARBs focus on risks that threaten confidentiality, integrity, and availability of critical assets, and unauthenticated API access to sensitive data is a classic OWASP API Security Top 10 issue.

Exam trap

CRISC often tests the distinction between business/functional risks and security/compliance risks; candidates pick timeline or technology-choice options because they sound like 'architecture' concerns, missing that the ARB prioritizes risks to sensitive data and regulatory posture.

How to eliminate wrong answers

Option A is wrong because lack of mobile support is a business/functional limitation, not a primary security or architectural risk, and it does not threaten data confidentiality or regulatory compliance. Option B is wrong because an aggressive timeline is a project-management risk that may affect quality, but it is not the primary architectural risk the ARB should prioritize over a direct data-exposure flaw. Option C is wrong because using the latest JavaScript framework is a technology-choice consideration (potential support/maturity risk) but not a primary risk to sensitive data; it is a preference, not a vulnerability.

99
MCQmedium

An organization is considering cyber insurance to transfer residual risk. Which factor would MOST significantly influence the premium?

A.Industry sector
B.Company revenue
C.Security controls and incident history
D.Number of employees
AnswerC

Insurers price premiums on the likelihood and cost of a claim, so the maturity of implemented security controls and prior incident history directly determine the assessed loss expectancy. Stronger controls and a clean record lower the residual risk being transferred, reducing the premium.

Why this answer

Cyber insurance premiums are most significantly influenced by the organization's security controls and incident history, because insurers underwrite based on the likelihood and severity of a claim. Strong controls (MFA, EDR, backups, segmentation) and a clean incident history reduce perceived risk and lower premiums; poor controls and prior breaches raise them.

Exam trap

CRISC often tests the distinction between factors that affect policy size (revenue, employees) and factors that affect the risk rate (controls, incident history) — candidates who pick revenue or industry as 'most significant' miss that underwriting is fundamentally about control maturity and claims experience.

How to eliminate wrong answers

Option A is wrong because while industry sector affects risk appetite and available coverage, it is a secondary factor — two companies in the same sector can have vastly different premiums based on their controls and claims history. Option B is wrong because company revenue affects the size of the policy (limits) and thus the absolute premium, but not the rate or risk assessment as significantly as controls and incident history. Option D is wrong because the number of employees is a proxy for scale and potential exposure, but it is not the most significant underwriting factor — a small company with no controls can pay more per employee than a large company with mature security.

100
MCQmedium

A software development company is adopting a DevSecOps approach. The risk manager wants to ensure that security risks are identified early in the development lifecycle. Which of the following practices is MOST effective for integrating risk identification into the CI/CD pipeline?

A.Conduct static application security testing (SAST) as part of the build process.
B.Perform dynamic application security testing (DAST) after deployment to production.
C.Implement runtime application self-protection (RASP) in production to block attacks.
D.Require manual code reviews by the security team before each release.
AnswerA

SAST analyzes source code or binaries for security vulnerabilities during the build phase, allowing developers to identify and fix issues early. Integrating SAST into the CI/CD pipeline automates risk identification without slowing down development. It provides immediate feedback and aligns with the shift-left approach, making it the most effective practice for early risk identification in DevSecOps.

Why this answer

SAST integrated into the build process is the most effective for early risk identification because it analyzes code before it is deployed, providing immediate feedback to developers. This shift-left approach reduces the cost and effort of fixing vulnerabilities later. Other practices like DAST, manual reviews, or RASP occur later or are less scalable for continuous integration.

Exam trap

The trap here is selecting DAST or RASP because they are security testing tools, but they do not identify risks early in the development lifecycle as effectively as SAST.

101
MCQeasy

Which of the following is a key component of an IT risk management programme that documents identified risks, their likelihood, and impact?

A.Risk management policy
B.Risk register
C.Business continuity plan
D.Incident response plan
AnswerB

A risk register is the central artefact that records each identified risk alongside its assessed likelihood and impact, giving the programme a single documented view for prioritisation and tracking. It directly satisfies the stem's requirement to document risks, likelihood and impact.

Why this answer

The risk register is the central repository within an IT risk management programme that formally documents identified risks, their assessed likelihood, and potential impact. It serves as the authoritative record for tracking risk ownership, mitigation status, and residual risk levels, enabling ongoing monitoring and reporting. Without a risk register, an organization cannot systematically manage or communicate its risk posture.

Exam trap

The trap here is that candidates confuse the risk register with the risk management policy, mistakenly thinking the policy document contains the detailed risk inventory, when in fact the policy only sets the governance framework while the register holds the operational risk data.

How to eliminate wrong answers

Option A is wrong because a risk management policy defines the high-level principles, objectives, and responsibilities for risk management, but it does not contain the specific inventory of identified risks, their likelihood, or impact. Option C is wrong because a business continuity plan (BCP) focuses on maintaining or restoring operations after a disruption, not on documenting the full spectrum of identified IT risks and their attributes. Option D is wrong because an incident response plan (IRP) outlines procedures for detecting, responding to, and recovering from security incidents, but it does not serve as the ongoing record of all identified risks, their likelihood, and impact.

102
MCQhard

A risk manager is evaluating the security of a new containerized application deployment in a hybrid cloud environment. The organization uses Kubernetes for orchestration and must ensure that container images are free from known vulnerabilities before deployment. Which of the following controls is MOST effective for this purpose?

A.Integrating a container image scanning tool into the CI/CD pipeline.
B.Enforcing network policies to restrict container-to-container communication.
C.Using a service mesh to encrypt all traffic between microservices.
D.Implementing runtime security monitoring using a tool like Falco.
AnswerA

Container image scanning tools integrated into the CI/CD pipeline automatically scan images for known vulnerabilities before deployment. This shift-left approach prevents vulnerable images from reaching production. It aligns with the requirement to ensure images are free from known vulnerabilities, as scanning occurs at build time and can block deployment if critical issues are found.

Why this answer

The most effective control for ensuring container images are free from known vulnerabilities before deployment is to integrate image scanning into the CI/CD pipeline. This allows automated detection and blocking of vulnerable images at build time. Runtime monitoring, network policies, and service meshes address other security aspects but do not meet the pre-deployment vulnerability assurance requirement.

Exam trap

The trap here is focusing on runtime or network controls when the requirement is specifically about pre-deployment vulnerability assurance of container images.

103
MCQmedium

A hospital's radiology department wants to let contracted teleradiologists read CT scans from home. The scans contain protected health information (PHI) and must remain within the hospital's HIPAA compliance boundary. The CIO asks the risk practitioner to recommend an access approach that minimizes the risk of PHI residing on unmanaged personal devices. Which of the following is the BEST recommendation?

A.Provide teleradiologists with virtual desktop infrastructure (VDI) sessions hosted in the hospital's data center, with local drive and clipboard redirection disabled.
B.Issue each teleradiologist a hospital-owned laptop with full-disk encryption and require them to sign an acceptable use policy.
C.Publish the CT images to a password-protected cloud file-sharing folder and email time-limited download links to each teleradiologist.
D.Grant teleradiologists VPN access to the PACS and let them install the vendor's diagnostic viewer on their personal computers.
AnswerA

VDI keeps PHI inside the hospital-controlled data center because only pixels are streamed to the endpoint, and disabling drive and clipboard redirection prevents scans from being copied to unmanaged home devices. This directly limits data-at-rest exposure while preserving the teleradiology workflow, making it the strongest control for the stated risk.

Why this answer

Centralizing PHI in hospital-controlled infrastructure while presenting only a remote display is the most effective way to keep protected health information off unmanaged endpoints. Virtual desktop infrastructure with drive and clipboard redirection disabled preserves clinical workflow yet blocks the common exfiltration paths of copy, print, and local save. Endpoint-centric alternatives leave PHI resident outside the compliance boundary and are far harder to govern.

Exam trap

The trap here is assuming that encryption on a laptop or VPN transport alone satisfies HIPAA, when the real exposure is PHI stored on devices the organization does not control.

104
MCQmedium

An organization is implementing COBIT 2019 and the board has requested assurance that risk management activities are aligned with business objectives. Which governance objective is primarily focused on ensuring risk optimization through evaluation, direction, and monitoring?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM02 — Ensure Benefits Delivery
C.EDM03 — Ensure Risk Optimization
D.EDM04 — Ensure Resource Optimization
AnswerC

EDM03 — Ensure Risk Optimization is the governance objective covering evaluation, direction and monitoring of risk management, ensuring it aligns with business objectives. It sits within the Evaluate, Direct and Monitor domain, matching the board's assurance request.

Why this answer

COBIT 2019's EDM03 — Ensure Risk Optimization is the governance objective that ensures enterprise risk management activities are aligned with business objectives by evaluating, directing, and monitoring risk appetite, tolerance, and capacity. It is the EDM domain objective specifically focused on risk optimization, making it the correct answer for the board's assurance need described.

Exam trap

CRISC often tests the distinction between EDM03 (governance-level risk optimization) and APO12 (management-level risk execution), and candidates frequently pick EDM01 because it sounds like the overarching governance objective rather than the risk-specific one.

How to eliminate wrong answers

Option A is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance focuses on establishing and maintaining the governance framework, not specifically risk optimization. Option B is wrong because EDM02 — Ensure Benefits Delivery focuses on optimizing value from investments and services, not risk. Option D is wrong because EDM04 — Ensure Resource Optimization focuses on ensuring adequate, competent, and optimized resources (people, infrastructure), not risk management alignment.

105
MCQmedium

An organization is designing an IT risk management program. Which of the following should be the PRIMARY consideration when developing a risk register?

A.Aligning risk categories with the COSO internal control framework
B.Ensuring that the register is integrated with the enterprise risk management system
C.Automating the risk register with real-time risk monitoring tools
D.Capturing risk details, including impact, likelihood, and mitigation status
AnswerD

A risk register's core purpose is documenting each identified risk with its impact, likelihood and mitigation status, enabling prioritisation and tracking. Capturing these details is the primary consideration because it drives all subsequent risk decisions.

Why this answer

The primary purpose of a risk register is to serve as the central repository that documents identified risks along with their key attributes—impact, likelihood, mitigation status, ownership, and timelines. Without capturing these core details, the register cannot support risk prioritization, decision-making, or tracking of remediation efforts. Options A, B, and C describe supporting or enhancing elements, but they are secondary to the fundamental requirement of recording essential risk information.

Therefore, D is the primary consideration.

Exam trap

CRISC often tests the distinction between foundational elements and supporting enhancements; candidates may be tempted to choose integration or automation as the 'primary' consideration, but the exam expects recognition that capturing core risk attributes is the essential first step.

How to eliminate wrong answers

Option A is wrong because aligning risk categories with COSO is a useful structuring approach, but it is not the primary consideration—the register must first capture risk details; COSO alignment is a framework choice, not the core purpose. Option B is wrong because integration with the enterprise risk management system is important for aggregation and reporting, but it is an architectural consideration that presupposes the register already contains complete risk data. Option C is wrong because automation with real-time monitoring is an advanced capability that enhances efficiency and timeliness, but it is not fundamental—a risk register can be effective without automation, as long as it captures the necessary risk information.

106
MCQmedium

A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?

A.Vendor lock-in
B.Multi-tenancy isolation
C.Misconfiguration of access controls
D.Data sovereignty compliance
AnswerC

In the shared responsibility model, the provider secures the cloud infrastructure while the customer configures identity and access controls. Misconfigured permissions, such as overly broad roles or public buckets, are the customer's responsibility and are frequently overlooked, exposing sensitive customer data.

Why this answer

In the shared responsibility model, the cloud provider secures the infrastructure (security OF the cloud), while the customer is responsible for securing what they put IN the cloud—including access controls, identity management, and configuration of their own applications and data. Misconfiguration of access controls is the most commonly overlooked risk because organizations often assume the provider handles all security, leading to overly permissive IAM roles, exposed storage buckets, or weak authentication. This risk is directly under the customer's control and is a leading cause of cloud data breaches, making it the most critical to address.

Exam trap

CRISC often tests the misconception that the cloud provider handles all security, leading candidates to overlook customer-side misconfigurations like access controls and instead focus on provider-managed risks such as multi-tenancy isolation or vendor lock-in.

How to eliminate wrong answers

Option A is wrong because vendor lock-in is a strategic and financial risk related to dependency on a single provider, not a direct security control failure in the shared responsibility model; it is typically addressed through architectural design and exit strategies, not immediate access control remediation. Option B is wrong because multi-tenancy isolation is primarily the cloud provider's responsibility to ensure logical separation between tenants; while customers should verify it, it is not the most likely to be overlooked by the customer since providers invest heavily in isolation mechanisms and it is less actionable for the customer. Option D is wrong because data sovereignty compliance is a legal and regulatory risk concerning where data is stored and processed, which is important but often addressed through contractual agreements and region selection, not a day-to-day configuration risk that is frequently overlooked in the shared responsibility model.

107
MCQeasy

Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM02 — Ensure Benefits Delivery
C.EDM04 — Ensure Resource Optimization
D.EDM03 — Ensure Risk Optimization
AnswerD

EDM03 — Ensure Risk Optimization sits in the Evaluate, Direct and Monitor domain, covering evaluation of risk appetite, direction of risk responses and monitoring of risk optimisation, exactly matching the stem's description of optimising risk through evaluation, direction and monitoring.

Why this answer

EDM03 — Ensure Risk Optimization is the governance objective that addresses risk management evaluation, direction, and monitoring.

108
MCQhard

A risk manager is evaluating the risk of quantum computing for the organization's encryption. The organization uses RSA-2048 for data encryption. What is the PRIMARY consideration in planning for post-quantum cryptography migration?

A.The timeline for quantum computers to break RSA-2048
B.The cost of new encryption algorithms
C.The availability of quantum-resistant hardware
D.The performance impact of post-quantum algorithms
AnswerA

Understanding when quantum computers will be capable of breaking current cryptography is essential for planning migration.

Why this answer

Quantum computers capable of breaking RSA-2048 are not expected within the next few years, so the primary consideration is the timeline for quantum advantage to prioritize migration efforts.

109
MCQhard

A healthcare organization is migrating its electronic health records (EHR) to a SaaS provider. The provider offers a standard contract with a 99.9% uptime SLA but no right to audit. The risk manager is concerned about data integrity and availability. Which of the following is the BEST risk response to address the lack of audit rights?

A.Transfer the risk by purchasing cyber insurance that covers data breaches at the SaaS provider.
B.Implement a redundant on-premises EHR system to mitigate the risk of provider failure.
C.Negotiate a contract amendment to include audit rights or obtain independent third-party attestations such as SOC 2 Type II reports.
D.Accept the risk because the SLA guarantees uptime and the provider is reputable.
AnswerC

Negotiating audit rights or accepting independent attestations like SOC 2 Type II provides assurance over the provider's controls without direct auditing. SOC 2 reports cover security, availability, and confidentiality, which are critical for EHR data. This is a practical risk response that balances assurance with vendor relationships, reducing risk to an acceptable level while maintaining compliance with regulations like HIPAA.

Why this answer

The best response is to obtain assurance through contractual audit rights or independent attestations like SOC 2 Type II. This directly addresses the lack of visibility into the provider's controls, which is critical for data integrity and compliance. Other options either accept the risk without assurance, implement costly redundancies that do not solve the problem, or transfer financial risk without addressing the control gap.

Exam trap

The trap here is assuming that an uptime SLA or cyber insurance adequately addresses the risk of not having audit rights, when the core issue is lack of assurance over the provider's security controls.

110
MCQhard

An insurance company's risk committee is reviewing a new mobile claims application. A penetration test found that the app stores authentication tokens in plaintext in the device's shared application storage, where any other app on a rooted or jailbroken device can read them. The development team proposes to add certificate pinning. Which of the following is the MOST appropriate risk response?

A.Accept the finding because certificate pinning will prevent token interception by malicious applications.
B.Mitigate the finding by storing tokens in the platform's secure hardware-backed keystore and removing them from shared application storage.
C.Avoid the risk by blocking the application from running on rooted or jailbroken devices.
D.Transfer the risk by purchasing a cyber liability policy that covers mobile application data breaches.
AnswerB

The confirmed weakness is plaintext token storage readable by other applications, so the direct fix is to move tokens into the operating system's hardware-backed keystore, such as iOS Keychain or Android Keystore, which isolates secrets per application. This addresses the root cause rather than a related but different threat, making it the correct risk response.

Why this answer

When a penetration test identifies plaintext storage of authentication tokens in shared application storage, the root cause is insecure secret handling on the endpoint. Moving tokens into the platform's hardware-backed keystore binds them to the application and blocks other apps from reading them. Certificate pinning, insurance, and root detection either address different threats or fail to remove the vulnerability, so remediation of the storage design is the correct response.

Exam trap

The trap here is confusing a transport-layer control with an at-rest data protection problem, which leads to accepting a finding that remains fully exploitable.

111
Multi-Selecthard

A manufacturing company is evaluating the risks of connecting its OT network to the IT network. Which THREE risks are MOST significant due to IT/OT convergence?

Select 3 answers
A.Expansion of attack paths from IT to OT systems
B.Legacy OT devices lacking modern security controls
C.Compliance with GDPR
D.Potential for physical damage and safety incidents
E.Increased data storage costs
AnswersA, B, D

Interconnecting IT and OT exposes previously isolated industrial control systems to IT-borne threats, letting attackers pivot from compromised business hosts into operational technology. This expanded attack surface is the direct consequence of convergence described in the stem.

Why this answer

Option A is correct because IT/OT convergence creates bridges between previously isolated environments, allowing attackers who compromise IT systems (e.g., via phishing or unpatched enterprise apps) to pivot laterally into OT networks and reach industrial control systems. Option B is correct because many OT devices such as PLCs, RTUs, and HMIs run legacy operating systems and proprietary protocols (e.g., Modbus, DNP3) with no authentication, encryption, or patch support, making them inherently vulnerable once exposed to IT-side threats. Option D is correct because compromised OT systems can directly manipulate physical processes—causing equipment damage, production outages, or safety incidents that endanger personnel, which is a uniquely severe consequence not present in pure IT breaches.

Option C is not a convergence-specific risk; GDPR governs personal data protection and is largely irrelevant to OT process control data. Option E is incorrect because data storage costs are a general IT operational concern, not a significant security or safety risk arising from IT/OT convergence.

Exam trap

CRISC often tests the misconception that IT/OT convergence is primarily a compliance or cost issue — the exam expects you to recognize that safety, physical damage, and expanded attack paths are the dominant risks.

112
MCQeasy

A retail company is implementing a new point-of-sale (POS) system that will process credit card transactions. The risk manager is reviewing the network architecture and notes that the POS devices will be on the same flat network as employee workstations and guest Wi-Fi. Which of the following is the MOST effective risk mitigation to protect cardholder data?

A.Require multi-factor authentication (MFA) for all POS transactions.
B.Implement full-disk encryption on all POS devices to protect data at rest.
C.Deploy an intrusion detection system (IDS) to monitor for malicious traffic.
D.Segment the POS network from other networks and apply strict firewall rules.
AnswerD

Network segmentation isolates the POS system from less secure environments, reducing the attack surface and limiting lateral movement in case of a breach. Strict firewall rules enforce least privilege, allowing only necessary traffic. This is a fundamental PCI DSS requirement and the most effective way to protect cardholder data from threats originating from employee workstations or guest Wi-Fi.

Why this answer

Network segmentation with strict firewall rules is the most effective mitigation because it isolates the POS environment from other networks, preventing attackers from pivoting from compromised workstations or guest Wi-Fi. This aligns with PCI DSS requirements and reduces the scope of compliance. Other controls like encryption, IDS, or MFA are valuable but do not address the fundamental risk of a flat network.

Exam trap

The trap here is choosing encryption or monitoring as the primary control, while overlooking that network segmentation directly prevents unauthorized access to cardholder data.

113
MCQmedium

According to the NIST Cybersecurity Framework, which function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Identify
B.Protect
C.Respond
D.Detect
AnswerB

The Protect function covers developing and implementing safeguards — access control, awareness training, data security and protective technology — to ensure delivery of critical infrastructure services. This matches the stem's wording precisely, distinguishing it from Identify, Detect, Respond and Recover.

Why this answer

The NIST Cybersecurity Framework's Protect function (PR) covers the safeguards needed to ensure delivery of critical infrastructure services — including access control, awareness training, data security, information protection processes, maintenance, and protective technology. It is the function that directly addresses preventive controls.

Exam trap

CRISC often tests the confusion between Protect and Detect — candidates may pick Detect thinking it covers safeguards, but Detect is about discovering events, while Protect is about implementing preventive safeguards.

How to eliminate wrong answers

Option A is wrong because Identify (ID) focuses on understanding the business context, assets, and risks — it is about discovery and governance, not implementing safeguards. Option C is wrong because Respond (RS) covers actions taken during or after a detected incident (response planning, communications, analysis, mitigation). Option D is wrong because Detect (DE) focuses on discovering cybersecurity events through monitoring and anomaly detection, not on implementing safeguards.

114
MCQeasy

In the context of IT governance, which COBIT 2019 process is specifically focused on ensuring risk optimization?

A.EDM01 — Ensure Governance Framework Setting and Maintenance
B.EDM04 — Ensure Resource Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM03 — Ensure Risk Optimization
AnswerD

EDM03 — Ensure Risk Optimization sits in the Evaluate, Direct and Monitor domain, tasking the governing body with ensuring IT-related risk appetite, tolerance and capacity are understood and optimised. It is the COBIT 2019 process explicitly scoped to risk optimisation.

Why this answer

COBIT 2019's EDM03 — Ensure Risk Optimization is the governance process specifically focused on ensuring that IT-related risk is identified, assessed, and managed within the enterprise's risk appetite. It is part of the Evaluate, Direct, and Monitor (EDM) domain, which is the governance domain.

Exam trap

CRISC often tests the distinction between EDM03 (Ensure Risk Optimization) and APO12 (Manage Risk) — candidates may confuse governance-level risk oversight with management-level risk execution.

How to eliminate wrong answers

Option A is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance focuses on establishing and maintaining the governance framework, not on risk optimization. Option B is wrong because EDM04 — Ensure Resource Optimization focuses on optimizing IT resources (people, infrastructure, applications), not risk. Option C is wrong because EDM02 — Ensure Benefits Delivery focuses on optimizing the value contribution of IT investments, not risk.

115
MCQhard

A financial services firm is adopting a DevSecOps model. The risk practitioner wants to ensure that security risks are identified and addressed as early as possible in the software development lifecycle. Which of the following practices BEST supports this objective?

A.Conducting a penetration test immediately before production deployment.
B.Requiring developers to complete annual secure coding training.
C.Performing dynamic application security testing (DAST) on a staging environment.
D.Integrating static application security testing (SAST) into the continuous integration pipeline.
AnswerD

SAST tools analyze source code for security flaws as developers commit changes, providing immediate feedback. This integration into the CI pipeline embeds security into the earliest stages of development, allowing issues to be fixed before they propagate. It directly supports the DevSecOps principle of identifying and addressing risks early.

Why this answer

Integrating SAST into the CI pipeline allows security checks to run automatically with every code commit, giving developers immediate feedback on vulnerabilities. This shifts security left, enabling fixes during development when they are cheapest and fastest to resolve. Other practices like penetration testing, training, and DAST are valuable but do not provide the same early, continuous, code-level risk detection.

Exam trap

The trap here is equating any security testing with shifting left; only practices embedded in the early coding and build stages truly identify risks as early as possible.

116
Multi-Selecthard

A global company is moving its critical applications to a public cloud. Which THREE of the following are key risk considerations in the shared responsibility model?

Select 3 answers
A.Physical security of data centers
B.Identity and access management
C.Compliance with regulatory requirements for data handling
D.Data encryption and key management
E.Network firewall configuration
AnswersB, C, D

Identity and access management sits with the customer in the shared responsibility model. The provider secures the platform, but the company must manage its own users, roles, federated identities, and privileged access, so weak IAM controls remain a significant risk when moving critical applications to public cloud.

Why this answer

In the shared responsibility model, the cloud provider secures the physical infrastructure, while the customer remains responsible for securing what they put in the cloud. Option B (Identity and access management) is correct because the customer must manage their own users, roles, permissions, and authentication mechanisms (e.g., IAM policies, MFA) to prevent unauthorized access to cloud resources. Option C (Compliance with regulatory requirements for data handling) is correct because the customer is accountable for ensuring that data stored and processed in the cloud meets applicable laws and standards such as GDPR, HIPAA, or PCI DSS, even though the provider may offer compliant infrastructure.

Option D (Data encryption and key management) is correct because protecting data at rest and in transit, along with managing encryption keys (e.g., via KMS or customer-managed keys), is a customer responsibility in the shared model. Option A (Physical security of data centers) is not a customer risk consideration because the cloud provider is responsible for physical security of its facilities. Option E (Network firewall configuration) is not marked correct because, while customers often manage firewalls and security groups, the question asks for key risk considerations in the shared responsibility model, and firewall configuration is a specific control rather than a broad risk category like IAM, compliance, or encryption/key management.

Exam trap

CRISC often tests the boundary of the shared responsibility model—candidates incorrectly include provider-owned controls like physical security or overlook customer-owned domains like key management and compliance.

117
Multi-Selectmedium

A risk manager is evaluating the application of IEC 62443 for industrial control systems. Which THREE of the following are key security requirements addressed by this standard?

Select 3 answers
A.Environmental monitoring (temperature, humidity)
B.Identification and authentication control
C.System integrity
D.Physical security of data centers
E.Use control (authorization)
AnswersB, C, E

Ensures only authorized users and devices access the system.

Why this answer

IEC 62443 is a series of standards specifically designed for the security of Industrial Automation and Control Systems (IACS). It addresses cybersecurity requirements to protect these systems from cyber threats. Identification and authentication control (B) is a foundational requirement, ensuring that only authorized users and devices can access the system, which is critical for preventing unauthorized access to industrial processes.

Exam trap

The trap here is that candidates may confuse general operational or physical security measures (like environmental monitoring or data center security) with the specific cybersecurity controls mandated by IEC 62443 for industrial control systems.

118
MCQmedium

An organization is developing a new cloud-based application that will process personal data of EU citizens. The risk manager is assessing the shared responsibility model with the cloud service provider (CSP). Which of the following is the MOST critical risk to address in the risk assessment?

A.Lack of encryption at rest
B.Vendor lock-in due to proprietary APIs
C.Data sovereignty and cross-border data transfer restrictions
D.Multi-tenancy isolation failures
AnswerC

Under GDPR, personal data of EU citizens may not be transferred to jurisdictions lacking adequate protection, and the CSP controls where replicas and backups reside. This legal constraint sits with the organisation, not the provider, so it must be assessed explicitly.

Why this answer

When processing EU citizens' personal data in the cloud, the most critical risk is data sovereignty and cross-border transfer restrictions under GDPR. The regulation limits transfers of personal data outside the EU/EEA unless adequate safeguards (e.g., Standard Contractual Clauses, adequacy decisions) are in place. A CSP may store or replicate data in regions the organization did not intend, creating legal exposure that outweighs the other technical risks.

Exam trap

CRISC often tests the distinction between technical security risks and regulatory compliance risks — candidates pick encryption or isolation because they sound like 'security,' missing that GDPR data sovereignty is the dominant legal risk when EU personal data is involved.

How to eliminate wrong answers

Option A is wrong because lack of encryption at rest is a serious control gap, but it is a mitigable technical control and does not carry the same legal/regulatory weight as unlawful cross-border transfer under GDPR. Option B is wrong because vendor lock-in is a strategic and cost risk, not a regulatory compliance risk — it does not expose the organization to fines or enforcement actions. Option D is wrong because multi-tenancy isolation failures are a real cloud risk, but CSPs typically contractually address isolation, and a breach is a security incident rather than the primary compliance risk in this GDPR-specific scenario.

119
Multi-Selecthard

An organization is planning for post-quantum cryptography migration. Which THREE of the following are key considerations for this migration?

Select 3 answers
A.Inventory of all cryptographic assets and dependencies
B.Replacing all existing hardware immediately
C.Crypto agility to easily replace algorithms
D.Timeline estimates for when quantum computers can break current cryptography
E.Eliminating cloud services to reduce risk
AnswersA, C, D

Knowing where cryptography is used is essential.

Why this answer

A comprehensive inventory of cryptographic assets and dependencies is essential to identify all systems, applications, and data that rely on current cryptographic algorithms (e.g., RSA, ECDSA, Diffie-Hellman). Without this inventory, the organization cannot prioritize migration efforts, assess impact, or ensure that no legacy cryptographic dependency is overlooked during the transition to post-quantum algorithms.

Exam trap

The trap here is that candidates may confuse 'crypto agility' (Option C) with 'immediate hardware replacement' (Option B), or assume that cloud services must be eliminated (Option E) rather than recognizing that inventory, agility, and timeline are the three core strategic considerations for a phased, risk-based migration.

120
Multi-Selectmedium

A risk manager is designing an IT risk management programme. Which THREE of the following are essential components of a risk management policy?

Select 3 answers
A.Risk assessment methodology
B.Specific risk treatment plans
C.Risk appetite statement
D.Detailed risk register
E.Roles and responsibilities for risk management
AnswersA, C, E

Methodology defines how risks are assessed.

Why this answer

A risk assessment methodology is an essential component of a risk management policy because it defines the standardized approach for identifying, analyzing, and evaluating IT risks. Without a prescribed methodology, risk assessments would be inconsistent, making it impossible to compare risks across the organization or to align them with the risk appetite. The policy must mandate a repeatable process, such as NIST SP 800-30 or ISO 31010, to ensure objectivity and defensibility in risk decisions.

Exam trap

The trap here is that candidates confuse operational artifacts (risk treatment plans and risk registers) with policy-level components, failing to recognize that the policy sets the framework and mandates, not the specific details of each risk response.

121
MCQmedium

A financial services firm is migrating its customer relationship management (CRM) system to a SaaS provider. The risk practitioner must assess the provider's security posture. Which of the following is the MOST reliable source of assurance?

A.A SOC 2 Type II report covering the relevant trust services criteria.
B.The provider's marketing materials and security whitepaper.
C.The provider's completed self-assessment questionnaire.
D.A penetration test report the provider commissioned last year.
AnswerA

A SOC 2 Type II report is an independent auditor's opinion on the design and operating effectiveness of controls over a period of time. It provides reliable evidence about security, availability, and confidentiality controls relevant to a SaaS provider. For a CRM holding customer data, this report gives the most credible assurance of the provider's control environment.

Why this answer

For a SaaS provider handling customer data, the most reliable assurance comes from an independent audit of controls over time. A SOC 2 Type II report provides exactly that, covering relevant trust services criteria. Other sources are either self-reported, point-in-time, or not designed for comprehensive risk assessment.

Exam trap

The trap here is treating a self-assessment or a one-time penetration test as equivalent to an independent, period-based audit of controls.

122
MCQeasy

Which of the following is a primary concern when using AI/ML models for decisions subject to regulatory oversight?

A.Adversarial attacks
B.Model bias
C.Explainability of model decisions
D.Data privacy in training
AnswerC

Explainability directly addresses the regulatory constraint: overseers must be able to audit and justify automated decisions. Unlike accuracy or performance, explainability determines whether an organisation can demonstrate compliance and accountability to regulators, satisfying the stem's oversight requirement. Opaque models, even accurate ones, fail this obligation because decisions cannot be traced or defended.

Why this answer

When AI/ML models drive decisions subject to regulatory oversight (e.g., credit, hiring, healthcare), explainability is the primary concern because regulators and affected individuals must understand how a decision was reached. Without explainability, the organization cannot demonstrate compliance with laws like GDPR Article 22 (right to explanation) or fair lending regulations, and cannot defend decisions in audits or disputes.

Exam trap

CRISC often tests the difference between technical AI risks (adversarial attacks, bias, privacy) and regulatory/oversight risks — candidates pick bias or privacy because they are prominent AI concerns, missing that explainability is the linchpin for regulatory accountability.

How to eliminate wrong answers

Option A is wrong because adversarial attacks are a security concern, but they are not the primary regulatory issue — regulators focus on whether decisions can be explained and justified, not on whether inputs can be manipulated. Option B is wrong because model bias is a critical fairness concern and often a regulatory focus, but it is a subset of the broader explainability problem — you cannot detect or remediate bias without understanding how the model reaches decisions. Option D is wrong because data privacy in training is important, but it concerns the input data, not the decision-making process that regulators scrutinize; privacy can be addressed with anonymization and consent, whereas explainability is intrinsic to the model's architecture.

123
MCQmedium

During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?

A.Deploy the application across multiple cloud regions with automated failover
B.Purchase cyber insurance to cover financial losses
C.Implement encryption at rest and in transit
D.Conduct a business impact analysis (BIA)
AnswerA

Deploying across multiple cloud regions with automated failover directly removes the single-region dependency identified by the ARB, satisfying the resilience constraint the stem raises. Unlike backup-only or manual recovery approaches, automated failover maintains service availability during a regional outage, which is the specific risk the proposed architecture currently leaves unmitigated.

Why this answer

The identified risk is the lack of disaster recovery for a single-region cloud deployment. The best mitigation is to deploy across multiple cloud regions with automated failover, which directly addresses the availability and resilience gap by ensuring the application survives a regional outage. This is a preventive/architectural control that reduces both likelihood and impact of downtime.

Exam trap

CRISC often tests the difference between risk mitigation, risk transfer, and risk assessment — candidates select insurance (transfer) or BIA (assessment) when the question asks for the BEST recommendation to mitigate an availability risk, which requires a preventive architectural control.

How to eliminate wrong answers

Option B is wrong because cyber insurance is a financial risk transfer mechanism — it compensates losses after an incident but does not restore service or prevent downtime, so it does not mitigate the availability risk. Option C is wrong because encryption at rest and in transit addresses confidentiality and data protection, not availability or disaster recovery; it is irrelevant to the single-region resilience gap. Option D is wrong because a business impact analysis identifies and quantifies the consequences of disruption, but it is an assessment activity, not a mitigation — it does not reduce the risk itself.

124
MCQeasy

Which COBIT 2019 governance objective focuses on ensuring that the enterprise's risk appetite and tolerance are understood, articulated, and communicated, and that risk is managed appropriately?

A.EDM04 — Ensure Resource Optimization
B.EDM03 — Ensure Risk Optimization
C.EDM02 — Ensure Benefits Delivery
D.EDM01 — Ensure Governance Framework Setting and Maintenance
AnswerB

EDM03 governs risk by setting appetite and tolerance, then directing risk management across the enterprise. The stem requires an objective covering articulation and communication of risk appetite plus appropriate treatment, which is precisely EDM03's remit within the Evaluate, Direct and Monitor domain.

Why this answer

EDM03 — Ensure Risk Optimization is the COBIT 2019 governance objective specifically designed to ensure that the enterprise's risk appetite and risk tolerance are defined, communicated, and understood, and that risk is managed within those boundaries. It focuses on aligning risk management with enterprise objectives and ensuring that residual risk is acceptable.

Exam trap

The trap here is that candidates often confuse 'risk optimization' (EDM03) with 'resource optimization' (EDM04) because both terms include 'optimization,' but EDM03 is the only one that explicitly addresses risk appetite, tolerance, and management.

How to eliminate wrong answers

Option A is wrong because EDM04 — Ensure Resource Optimization focuses on managing IT resources (applications, information, infrastructure, people) efficiently and effectively, not on risk appetite or tolerance. Option C is wrong because EDM02 — Ensure Benefits Delivery is concerned with optimizing value from IT-enabled investments and services, not with risk management. Option D is wrong because EDM01 — Ensure Governance Framework Setting and Maintenance deals with establishing and maintaining the governance framework (structures, principles, processes), not directly with risk appetite articulation or risk management.

125
MCQeasy

When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?

A.Shared responsibility model misunderstandings
B.Data may be stored in jurisdictions with different privacy laws
C.Multi-tenancy isolation gaps
D.Vendor lock-in due to proprietary APIs
AnswerB

Data sovereignty concerns arise because cloud providers may replicate or store data in jurisdictions whose privacy laws differ from the organisation's own, potentially breaching regulatory obligations. This legal exposure, not encryption or availability, is the key risk when assessing cloud computing.

Why this answer

Data sovereignty is a key concern in cloud computing risk because data may be stored in jurisdictions with different privacy laws. This means that data could be subject to legal requirements that conflict with the organization's own compliance obligations, such as GDPR or HIPAA.

Exam trap

The trap is confusing data sovereignty with other cloud risks like shared responsibility or multi-tenancy; candidates must focus on the legal jurisdiction aspect.

How to eliminate wrong answers

Option A is wrong because shared responsibility model misunderstandings relate to security responsibilities, not specifically data sovereignty. Option C is wrong because multi-tenancy isolation gaps are a security concern, not a legal jurisdiction issue. Option D is wrong because vendor lock-in is a strategic risk, not directly about data sovereignty.

126
MCQeasy

Which of the following is a characteristic of IoT devices that increases cybersecurity risk?

A.Built-in hardware security modules
B.Limited processing power for security features
C.Standardized communication protocols
D.Regular automatic firmware updates
AnswerB

Constrained CPUs and memory prevent IoT devices from running robust encryption, patching, or intrusion detection, so security controls are weakened or omitted. This processing limitation directly widens the attack surface, satisfying the stem's characteristic that increases cybersecurity risk.

Why this answer

IoT devices are frequently constrained by cost, size, and power, which limits CPU, memory, and battery. This directly restricts their ability to run strong encryption, host-based firewalls, secure boot, or frequent patching, expanding the attack surface. Limited processing power is therefore a structural characteristic that elevates cybersecurity risk.

Exam trap

The trap here is that candidates may equate 'standardized protocols' or 'automatic updates' with risk, when in fact those are generally risk-reducing; the exam tests whether you recognize that resource constraints — not standards — are the inherent IoT weakness.

How to eliminate wrong answers

Option A is wrong because hardware security modules (HSMs) or secure elements actually reduce risk by protecting keys and enabling secure boot. Option C is wrong because standardized communication protocols can improve interoperability and, when security is built in (e.g., TLS, MQTT over TLS), they do not inherently increase risk. Option D is wrong because regular automatic firmware updates are a mitigating control that reduces risk, not a risk-increasing characteristic.

127
MCQeasy

Which of the following is the PRIMARY purpose of a risk register in an IT risk management program?

A.To document and track identified risks and their treatment plans
B.To provide a historical record of past incidents
C.To calculate key risk indicators (KRIs)
D.To ensure compliance with regulatory requirements
AnswerA

A risk register records each identified risk, its owner, likelihood and impact ratings, and the agreed treatment plan, giving management a single authoritative view for tracking and reporting. This documentation and tracking function is its primary purpose within the IT risk management programme.

Why this answer

The risk register is the central repository for documenting identified risks, their assessed impact and likelihood, and the corresponding treatment plans (e.g., mitigate, accept, transfer, avoid). Its primary purpose is to provide a structured, living record that enables ongoing tracking, prioritization, and management of risk treatment activities throughout the IT risk management lifecycle.

Exam trap

The trap here is that candidates confuse the risk register's primary purpose with secondary benefits like compliance or metrics, leading them to choose options that describe outputs or uses of the register rather than its core function of documenting and tracking risks and treatments.

How to eliminate wrong answers

Option B is wrong because a risk register is forward-looking and focused on current and future risks, not a historical log of past incidents (that would be an incident log or post-mortem database). Option C is wrong because key risk indicators (KRIs) are metrics derived from risk data to provide early warning signals, but the risk register itself does not calculate them; it stores the underlying risk data that may feed KRI calculations. Option D is wrong while compliance may be a benefit of using a risk register, its primary purpose is risk management and treatment tracking, not specifically ensuring regulatory compliance (which is the role of compliance frameworks and audit programs).

128
MCQhard

A hospital network is deploying a new medical imaging archive. The risk practitioner learns that the vendor's support engineers require remote access to the archive for maintenance. Which of the following is the BEST control to manage the third-party access risk?

A.Implement privileged access management with session recording, just-in-time elevation, and full session brokering through a jump host.
B.Grant vendor engineers a dedicated local administrator account with a strong password rotated every 90 days.
C.Require the vendor to carry cyber insurance and provide a certificate of insurance annually.
D.Require vendor engineers to sign an annual acceptable use policy before access is granted.
AnswerA

Privileged access management with just-in-time elevation, brokered sessions, and recording ensures vendor engineers receive only the access needed for the approved maintenance window, that credentials are vaulted rather than shared, and that every action is attributable. This directly controls the third-party access risk while preserving the audit trail required for regulated medical data.

Why this answer

Third-party remote access creates standing privileged exposure that must be constrained technically, not just contractually. Privileged access management with just-in-time elevation, credential vaulting, session brokering, and recording limits vendor reach to approved windows and produces attributable evidence. Policy signatures, standing admin accounts, and insurance certificates leave the actual access path uncontrolled.

Exam trap

The trap here is treating contractual or administrative assurances, such as policy sign-off or insurance, as equivalent to a technical control over privileged sessions.

129
MCQmedium

A manufacturing company is integrating its operational technology (OT) network with the corporate IT network to enable real-time data analytics. Which of the following risks should be prioritized during the risk assessment?

A.Attack path expansion from IT to OT networks
B.Incompatibility of IT and OT software versions
C.Increased latency in OT communications
D.Loss of data integrity in analytics dashboards
AnswerA

Integrating IT and OT creates bidirectional conduits, so compromised corporate credentials or endpoints can pivot into operational technology, disrupting physical production. This attack path expansion directly addresses the stem's priority: the newly bridged trust boundary between previously air-gapped OT and corporate IT, where Microsoft Entra ID compromise could cascade into safety-critical systems.

Why this answer

Integrating OT and IT networks creates a new attack path from the IT network to the OT network. Since OT systems often lack modern security controls and run legacy protocols (e.g., Modbus, DNP3), an attacker who compromises the IT network can pivot into the OT environment, potentially disrupting physical processes. This risk is prioritized because it introduces a direct, high-impact threat to safety and availability that did not exist before the integration.

Exam trap

The trap here is that candidates often focus on operational risks like latency or compatibility (options B and C) because they seem more immediate to the integration, but CRISC prioritizes security risks that introduce new attack vectors with potential for physical damage.

How to eliminate wrong answers

Option B is wrong because software version incompatibility is a compatibility or integration issue, not a security risk that would be prioritized in a risk assessment focused on security; it is typically addressed during project planning or testing. Option C is wrong because increased latency in OT communications is a performance or operational risk, not a security risk; while important, it does not represent the primary threat introduced by network integration. Option D is wrong because loss of data integrity in analytics dashboards is a consequence of a security incident (e.g., tampering) but not the root risk; the prioritized risk is the attack path that enables such tampering.

130
MCQeasy

A risk analyst is assessing the risk of a legacy application that stores customer data in plaintext. The application is scheduled for decommissioning in 18 months, but until then it must remain operational. Which of the following is the BEST risk response?

A.Accept the risk because the application will be decommissioned soon and the cost of encryption is not justified.
B.Implement database encryption at rest and in transit for the legacy application as a compensating control until decommissioning.
C.Transfer the risk by purchasing cyber insurance to cover potential data breach costs.
D.Avoid the risk by immediately shutting down the legacy application, even if it disrupts business operations.
AnswerB

Implementing encryption at rest and in transit is a feasible compensating control that protects the data even if the application is compromised. It addresses the plaintext storage risk directly and reduces the potential impact. This is the best response because it mitigates the risk during the remaining operational period without requiring major application changes, and it aligns with data protection best practices.

Why this answer

Implementing encryption at rest and in transit is the best risk response because it directly mitigates the risk of plaintext data exposure. It acts as a compensating control that can be applied without major changes to the legacy application, protecting sensitive data until decommissioning. This approach balances risk reduction with operational continuity, unlike acceptance, transfer, or avoidance which either leave the risk or disrupt business.

Exam trap

The trap here is assuming that because the application will be decommissioned soon, it is acceptable to leave the data unprotected or to rely solely on insurance, rather than applying a feasible technical control.

131
MCQmedium

A hospital is deploying IoT medical devices that connect to the network. Which risk is MOST concerning from a cybersecurity perspective?

A.Expanded attack surface due to many devices
B.Data sovereignty compliance
C.Firmware update challenges
D.Vendor lock-in
AnswerA

Each connected IoT medical device adds an entry point, so the aggregate attack surface grows faster than the hospital can patch or monitor it, giving adversaries more unmanaged vectors into clinical networks than any single device weakness.

Why this answer

IoT medical devices dramatically expand the attack surface because each device is a potential entry point, often with weak default credentials, unpatched firmware, and limited security controls. In a hospital, this expansion is the most concerning risk because it multiplies exposure across the network.

Exam trap

The trap is picking firmware update challenges because it sounds technical and specific — candidates overlook that the broader, more strategic risk is the sheer expansion of the attack surface across many unmanaged devices.

How to eliminate wrong answers

Option B is wrong because data sovereignty is a compliance concern, not the primary cybersecurity risk from IoT proliferation. Option C is wrong because firmware update challenges are a real issue but are a subset of the broader attack surface problem. Option D is wrong because vendor lock-in is a business/strategic risk, not a cybersecurity risk.

132
MCQeasy

An organization is implementing a new identity and access management (IAM) system. The risk practitioner is asked to identify the control that would BEST reduce the risk of unauthorized access due to compromised user credentials.

A.Enforcing a strong password policy with complexity and expiration requirements.
B.Implementing multi-factor authentication (MFA) for all user accounts.
C.Implementing account lockout after three failed login attempts.
D.Conducting regular security awareness training for all employees.
AnswerB

MFA requires an additional factor beyond a password, such as a token or biometric, making it significantly harder for an attacker to gain access even if the password is compromised. This directly mitigates the risk of unauthorized access due to stolen credentials. It is the most effective control because it adds a layer that cannot be easily replicated by an attacker who only has the password.

Why this answer

Multi-factor authentication (MFA) is the most effective control to reduce the risk of unauthorized access from compromised credentials because it requires an additional factor that an attacker is unlikely to possess. Password policies, training, and account lockout are useful but do not prevent access when valid credentials are stolen and used. MFA directly addresses the risk by adding a barrier that cannot be overcome with the password alone.

Exam trap

The trap here is assuming that strong password policies or user training alone can prevent unauthorized access, overlooking that stolen credentials can bypass these measures.

133
MCQeasy

A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?

A.Risk treatment plan
B.Risk register
C.Risk management policy
D.Risk assessment methodology
AnswerC

The risk management policy establishes the organisation's overall intent, scope, objectives and governance for risk, providing the mandate from which frameworks, processes and procedures are subsequently derived. Creating it first ensures all later risk activities align with approved direction.

Why this answer

A risk management policy establishes the principles, objectives, and responsibilities for risk management, providing a foundation for all other risk management activities.

134
Multi-Selecthard

An organization is implementing IEC 62443 for its industrial control systems. Which THREE of the following are key requirements of IEC 62443? (Select three.)

Select 3 answers
A.Applying security levels (SL) to each zone based on risk
B.Ensuring all industrial components have a secure development lifecycle (SDL)
C.Using proprietary protocols to enhance performance
D.Conducting a risk assessment to identify security zones and conduits
E.Implementing a single-vendor solution to reduce complexity
AnswersA, B, D

IEC 62443 requires segmentation into zones and conduits, with each zone assigned a target security level derived from assessed risk. This risk-based SL assignment is a foundational requirement, directly matching the stem's option and governing the countermeasures each zone must implement.

Why this answer

Option A is correct because IEC 62443 requires assigning Security Levels (SL 1–4) to each zone and conduit based on the assessed risk, so that target security levels can be defined and verified for the assets within them. Option B is correct because IEC 62443-4-1 specifies secure development lifecycle (SDL) requirements for product suppliers, including practices such as threat modeling, secure coding, and vulnerability handling for industrial components. Option D is correct because the standard mandates a risk assessment as the foundation for identifying zones and conduits, which are then used to segment the ICS network and apply appropriate countermeasures.

Option C is incorrect because IEC 62443 promotes open, standards-based and interoperable protocols rather than proprietary ones, which can hinder security monitoring and integration. Option E is incorrect because the standard favors defense-in-depth and segmentation across multiple vendors and layers, not single-vendor lock-in, which does not by itself reduce risk.

Exam trap

CRISC often tests the misconception that IEC 62443 mandates proprietary or single-vendor solutions, when in fact it is a risk-based, multi-vendor standard centered on zones, conduits, security levels, and secure development.

135
Multi-Selectmedium

A risk practitioner is evaluating the organization's vulnerability management programme. The organization scans its internal network weekly, but the CIO is concerned that critical internet-facing services are not adequately covered. Which TWO of the following changes would MOST improve the identification of exploitable vulnerabilities on externally exposed assets? (Choose two.)

Select 2 answers
A.Require business units to self-attest quarterly that their internet-facing applications have no known vulnerabilities.
B.Implement continuous external attack surface scanning that includes discovery of unknown internet-facing assets.
C.Correlate vulnerability scan results with threat intelligence feeds to prioritize vulnerabilities known to be actively exploited.
D.Deploy a web application firewall (WAF) in front of all internet-facing applications and enable blocking mode.
E.Increase the frequency of credentialed internal vulnerability scans from weekly to daily.
AnswersB, C

Continuous external scanning detects exposed services and previously unknown assets, such as shadow IT or forgotten cloud instances, that a weekly internal scan would miss. Because attackers target exactly these externally reachable services, identifying and inventorying them is a prerequisite to assessing and remediating exploitable vulnerabilities on the true external attack surface.

Why this answer

Improving identification of exploitable vulnerabilities on internet-facing services requires seeing the full external attack surface and knowing which findings matter. Continuous external attack surface scanning discovers and inventories exposed assets, including unknown ones, while threat intelligence correlation prioritizes vulnerabilities that attackers are actively exploiting, focusing remediation where it reduces real risk.

Exam trap

The trap here is assuming that more frequent internal scanning or a protective WAF identifies externally exposed vulnerabilities, when discovery and prioritization are the actual gaps.

136
MCQmedium

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The organization uses role-based access control (RBAC) but has experienced several incidents where employees retained access to systems after transferring to different departments. Which of the following is the MOST effective control to address this risk?

A.Implement mandatory password rotation every 30 days for all users.
B.Conduct periodic user access reviews with managers certifying that their direct reports have appropriate access.
C.Integrate the HR system with the IAM system to automatically revoke old roles and grant new roles upon a change in employee status or department.
D.Require all employees to sign an acceptable use policy annually.
AnswerC

Automating role changes based on HR events ensures that access rights are updated immediately when an employee transfers, eliminating the lag that leads to retained access. This preventive control directly addresses the root cause: the lack of timely de-provisioning and re-provisioning of access when roles change. It reduces reliance on manual processes and periodic reviews.

Why this answer

The root cause of the incidents is that access rights are not updated when employees change roles. The most effective control is to automate the synchronization of role changes from HR to the IAM system, ensuring timely revocation of old access and assignment of new access. This preventive control addresses the issue at the source and reduces reliance on periodic reviews.

Exam trap

The trap here is selecting periodic access reviews or password policies, which are detective or irrelevant, instead of a preventive automated provisioning control triggered by HR events.

137
MCQhard

A bank is adopting a third-party API gateway to expose account balance services to fintech partners. The risk practitioner must ensure that a partner's excessive or unusual API consumption cannot degrade service for other partners or core banking systems. Which control is MOST appropriate to address this risk?

A.Implement per-partner rate limiting and quotas at the API gateway, with circuit breakers to shed load before core systems are affected.
B.Encrypt account balance responses with a format-preserving encryption scheme before returning them.
C.Require all partners to sign a service level agreement specifying maximum transaction volumes.
D.Enforce mutual TLS between partners and the API gateway for all balance requests.
AnswerA

The stated risk is that one partner's consumption degrades service for others and for core systems. Per-partner rate limiting and quotas cap each consumer's volume, while circuit breakers stop cascading overload from reaching core banking. Together they directly contain the blast radius of a single misbehaving partner, which is exactly the risk described.

Why this answer

The risk is availability degradation caused by disproportionate consumption from one partner. Enforcing per-partner rate limits and quotas at the gateway constrains each consumer, and circuit breakers prevent overload from propagating into core banking. Contractual caps, mutual TLS and response encryption address expectations, authentication and confidentiality respectively, none of which stop a single partner from exhausting shared capacity.

Exam trap

The trap here is choosing a contractual or cryptographic control when the risk is about availability and capacity exhaustion by one consumer.

138
MCQmedium

An organization is evaluating cyber insurance options. Which of the following factors is MOST likely to influence the insurance premium?

A.The organization's annual revenue
B.The number of employees in the IT department
C.The organization's cybersecurity maturity and incident history
D.The organization's credit rating
AnswerC

Insurers price premiums according to assessed risk, so demonstrated cybersecurity maturity and prior incident history directly determine underwriting confidence and coverage terms. Stronger controls and fewer breaches lower perceived loss likelihood, reducing the premium charged.

Why this answer

An organization's cybersecurity maturity and incident history (C) is the most direct factor influencing cyber insurance premiums because insurers assess the likelihood and potential cost of a claim based on the organization's security controls, past breaches, and risk management practices. A mature security posture with few incidents lowers the perceived risk and therefore the premium.

Exam trap

The trap is selecting revenue (A) because it is a familiar underwriting factor for other insurance types — candidates must recognize that cyber insurance uniquely weights security maturity and incident history as the primary premium drivers.

How to eliminate wrong answers

Option A is wrong because annual revenue affects the potential size of a claim (higher revenue = higher potential loss), but it is a secondary factor — insurers weight security posture more heavily because it directly predicts the probability of an incident. Option B is wrong because the number of IT staff is not a standard underwriting factor; what matters is the effectiveness of controls, not headcount. Option D is wrong because credit rating is relevant to financial insurance products but is not a primary factor in cyber insurance underwriting — insurers focus on security controls, incident history, and industry risk profile.

139
MCQhard

A risk manager is assessing the potential impact of quantum computing on the organization's cryptographic infrastructure. What is the MOST immediate action the organization should take?

A.Purchase quantum-resistant hardware security modules
B.Conduct a cryptographic inventory to identify vulnerable systems
C.Immediately replace all encryption with post-quantum algorithms
D.Discontinue use of public key cryptography
AnswerB

Quantum computing threatens asymmetric cryptography once sufficiently powerful machines exist, but remediation depends on knowing where cryptography is deployed. A cryptographic inventory identifies vulnerable systems, algorithms and key lengths, giving the baseline required before migration planning can begin, making it the most immediate and actionable step.

Why this answer

The first step is to inventory all cryptographic systems to understand where quantum-vulnerable algorithms are used, enabling a migration plan.

140
MCQmedium

An organization is migrating its customer relationship management (CRM) system to a SaaS provider. The vendor's audit report shows a SOC 2 Type II opinion with no exceptions, but the report's period ended eight months ago. The risk practitioner must assess whether the residual risk is acceptable. Which action BEST addresses the gap in assurance?

A.Perform a penetration test against the SaaS provider's production environment to validate its controls directly.
B.Request a bridge letter or gap letter covering the period since the report ended and review the vendor's remediation of any changes.
C.Require the vendor to purchase cyber insurance and name the organization as an additional insured as a compensating control.
D.Accept the SOC 2 Type II report as sufficient evidence because it was issued by an independent CPA firm.
AnswerB

A bridge letter documents the vendor's controls and any changes during the gap between the audit period end and the current date. Reviewing it, along with any reported incidents or control changes, provides the missing assurance for the current period and allows the risk practitioner to judge whether residual risk remains acceptable.

Why this answer

SOC 2 Type II reports are point-in-time documents that cover only the stated audit period. When the report is stale, the risk practitioner needs evidence of controls during the gap. A bridge or gap letter is the standard mechanism for that period, supplemented by review of changes and incidents, allowing an informed residual risk determination.

Exam trap

The trap here is assuming that a Type II SOC 2 report provides perpetual assurance, when it only covers the specific audit period and requires a bridge letter for the gap.

141
MCQmedium

An organization is designing its identity and access management architecture. The risk practitioner wants to reduce the risk of credential theft leading to unauthorized access to critical systems. Which of the following is the MOST effective control to address this risk?

A.Enforce a password complexity policy requiring 14 characters with mixed character classes and 60-day expiration.
B.Deploy phishing-resistant multi-factor authentication using FIDO2 security keys for access to critical systems.
C.Require users to complete annual security awareness training covering password hygiene and social engineering.
D.Implement account lockout after five failed attempts and alert the service desk when lockouts occur.
AnswerB

FIDO2 security keys bind authentication to the legitimate origin and use public-key cryptography, so a stolen password or a relayed phishing page cannot produce a valid assertion. This directly breaks the credential theft path into critical systems, which is exactly the risk the architecture must reduce.

Why this answer

Credential theft defeats knowledge-based authentication regardless of password strength, so the strongest mitigation changes the authentication factor itself. Phishing-resistant FIDO2 authentication uses origin-bound public-key cryptography, meaning stolen passwords or relayed phishing sessions cannot authenticate. Complexity rules, lockout, and awareness training are useful supporting controls but do not break the theft-to-access path.

Exam trap

The trap here is assuming that stronger passwords or user education meaningfully prevent attackers who have already stolen valid credentials.

142
Multi-Selecthard

A risk manager is assessing IT/OT convergence risks at a manufacturing plant. Which TWO of the following are primary risks introduced by connecting industrial control systems to the corporate network?

Select 2 answers
A.Attack path expansion from IT to OT
B.Reduced operational efficiency
C.Increased data storage costs
D.Legacy system vulnerabilities exposed
E.Simplified remote access
AnswersA, D

Bridging IT and OT networks creates a traversable route from the corporate estate into control systems. An attacker who compromises an office workstation can pivot laterally to operational technology, satisfying the stem's requirement to identify a primary convergence risk.

Why this answer

Option A (Attack path expansion from IT to OT) is correct because bridging the corporate network with industrial control systems creates a conduit through which IT-side threats—such as compromised business workstations, phishing footholds, or lateral-movement tools like PsExec—can pivot into OT environments that were previously air-gapped or isolated behind a DMZ, dramatically widening the adversary's reachable attack surface. Option D (Legacy system vulnerabilities exposed) is correct because many ICS/SCADA devices and protocols (e.g., Modbus, DNP3, older Siemens/Rockwell PLCs) were designed without authentication, encryption, or patchability, so once reachable from corporate subnets their unpatched CVEs become exploitable in ways that were not possible under physical segmentation. Option B is not a primary convergence risk—convergence is typically pursued to improve efficiency through better data visibility and analytics, not to reduce it.

Option C is incorrect because increased data storage costs are an incidental IT budgeting concern, not a security risk introduced by IT/OT connectivity. Option E is incorrect because simplified remote access is generally a business benefit of convergence (enabling remote monitoring and diagnostics), even though it must be secured; it is not itself a primary risk introduced by the connection.

Exam trap

CRISC often tests whether candidates can distinguish primary security risks (attack path expansion, legacy vulnerabilities) from operational or financial impacts (efficiency, storage costs) or benefits (simplified remote access), so the trap is selecting non-risk items as primary risks.

143
MCQeasy

A risk practitioner is documenting how the organization handles the risk that a critical SaaS vendor could suffer an outage that halts order processing. The vendor publishes a 99.9% uptime commitment and will credit service fees if it is missed. Which action BEST addresses the residual business impact that the credit does not cover?

A.Renegotiate the service level agreement to raise the uptime commitment to 99.99%.
B.Increase the cyber insurance limit to cover business interruption losses from vendor outages.
C.Maintain a documented business continuity plan with a manual order-processing fallback and periodic testing.
D.Request the vendor's SOC 2 Type II report and file it with the vendor risk assessment.
AnswerC

Service credits compensate fees, not lost revenue, customer defection, or regulatory deadlines, so the residual impact of a prolonged order-processing halt remains with the organization. A tested manual fallback with defined recovery time objectives keeps orders flowing during an outage and demonstrates that continuity risk has been actively treated rather than merely acknowledged in the vendor contract.

Why this answer

Because service credits only refund fees and cannot restore lost orders, the organization retains the operational impact of a vendor outage. A documented and tested business continuity plan with a manual fallback directly reduces that impact by keeping order processing alive, whereas contract changes, assurance reports, and insurance all leave the business unable to operate during the outage.

Exam trap

The trap here is treating a service-level credit or a higher uptime target as mitigation, when neither restores business operations during an actual outage.

144
MCQhard

A financial services firm is deploying a security information and event management (SIEM) platform. The risk practitioner is asked to advise on how to keep the alert pipeline trustworthy so that detection and response decisions rest on reliable data. Which of the following is the MOST important control to prioritize?

A.Enable full packet capture retention for at least ninety days across all network segments.
B.Tune correlation rules to reduce the number of alerts reaching the analyst queue.
C.Protect the integrity and time synchronization of log sources and the collection path end to end.
D.Maximize the number of log sources ingested so that no event type is missed.
AnswerC

Detection and response decisions depend on logs being authentic and correctly ordered in time. If an attacker can alter logs in transit or manipulate host clocks, correlation breaks down and incidents can be hidden or fabricated. Securing the collection path and enforcing consistent time synchronization is therefore the foundational control for a trustworthy pipeline.

Why this answer

A SIEM is only as reliable as the events it receives, so the priority is ensuring those events are authentic and consistently time-stamped. Protecting log sources and the transport path against tampering, and synchronizing clocks, prevents attackers from hiding activity or fabricating evidence. Volume, tuning, and packet capture all matter operationally but none of them restores confidence in data that could have been altered.

Exam trap

The trap here is equating more logging and better tuning with trustworthy detection, when the real dependency is the integrity and time ordering of the events themselves.

145
Multi-Selecteasy

An organization is considering adopting the NIST Cybersecurity Framework to manage cybersecurity risk. Which of the following are core functions of the framework? (Choose TWO.)

Select 2 answers
A.Prevent
B.Mitigate
C.Protect
D.Analyze
E.Identify
AnswersC, E

Protect is a NIST CSF core function, encompassing access control, awareness training, data security and protective technology. It satisfies the framework's structure by delivering the safeguards that limit or contain the impact of a potential cybersecurity event.

Why this answer

The NIST Cybersecurity Framework defines five core functions: Identify, Protect, Detect, Respond, and Recover. Option E (Identify) is correct because it covers understanding the organization's assets, risks, and governance to prioritize cybersecurity efforts. Option C (Protect) is correct because it encompasses safeguards such as access control, awareness training, and data security to limit or contain the impact of a potential cybersecurity event.

Options A (Prevent), B (Mitigate), and D (Analyze) are not among the five core functions, even though they describe related risk-management concepts; the framework uses Detect, Respond, and Recover instead of those terms.

Exam trap

CRISC often tests the exact five functions of the NIST CSF, and candidates may confuse them with other risk management terms like 'Prevent' or 'Mitigate' which are not part of the core functions.

146
Multi-Selecthard

A risk practitioner is assessing a proposed bring-your-own-device (BYOD) programme for a law firm where attorneys will access matter files containing privileged client data. The CISO asks which controls are MOST important to reduce the risk of data leakage from lost or compromised personal devices. (Choose two.)

Select 2 answers
A.Require attorneys to sign an acceptable use policy acknowledging that personal devices may be inspected.
B.Block all access to matter files from outside the firm's office network by IP allowlisting.
C.Increase cyber insurance limits to cover regulatory fines from client data breaches.
D.Deploy mobile device management (MDM) with remote wipe and containerization of firm data.
E.Enforce full-device encryption with keys escrowed by the firm and require a device passcode.
AnswersD, E

MDM with remote wipe and a managed container lets the firm selectively remove or lock matter files without erasing the attorney's personal photos and apps. Containerization keeps privileged data inside an encrypted, policy-controlled space, so a compromised personal app cannot freely read or exfiltrate client information.

Why this answer

The two controls that actually prevent privileged client data from being exposed when a personal device is lost or compromised are escrowed full-device encryption and MDM with remote wipe plus containerization. Together they protect data at rest and allow selective removal of firm data, while the other choices are policy, perimeter, or financial measures that do not stop the leakage scenario.

Exam trap

The trap here is selecting policy or insurance options because they sound comprehensive, when the scenario asks specifically for controls that reduce data leakage from lost or compromised personal devices.

147
MCQhard

A risk manager is using the FAIR model to quantify cyber risk. After analyzing a ransomware scenario, the probable loss event frequency (LEF) is estimated at 0.2 per year, and the probable loss magnitude (LM) is $5 million. What is the annualized loss expectancy (ALE) in this scenario?

A.$500,000
B.$250,000
C.$5,000,000
D.$1,000,000
AnswerD

Multiplying loss event frequency (0.2) by loss magnitude ($5 million) yields $1,000,000 annualised loss expectancy, satisfying the FAIR requirement to express risk as a monetary annual figure. This correctly applies the ALE formula, giving the risk manager a quantified basis for comparing the ransomware scenario against other risks.

Why this answer

Annualized Loss Expectancy (ALE) is calculated as Loss Event Frequency (LEF) multiplied by Loss Magnitude (LM). Here, LEF = 0.2 per year and LM = $5,000,000, so ALE = 0.2 × $5,000,000 = $1,000,000. This represents the expected annualized financial loss from the ransomware scenario.

Exam trap

CRISC often tests whether candidates can correctly apply the ALE formula and avoid confusing it with LM alone or misapplying the frequency — the trap is picking the Loss Magnitude ($5M) or miscalculating the multiplication.

How to eliminate wrong answers

Option A ($500,000) is wrong because it would result from multiplying 0.1 × $5M or 0.2 × $2.5M, neither of which matches the given inputs. Option B ($250,000) is wrong because it would result from 0.05 × $5M, which misapplies the LEF. Option C ($5,000,000) is wrong because it is simply the Loss Magnitude without applying the frequency — it ignores the probability of occurrence entirely.

148
Multi-Selecthard

A risk practitioner is assessing the security of an organization's use of public cloud infrastructure. The organization stores sensitive data in object storage buckets. Which TWO of the following are the MOST significant risks related to misconfigured cloud storage? (Choose two.)

Select 2 answers
A.Insufficient logging and monitoring of access to bucket objects.
B.Use of a single cloud region for data residency.
C.Inability to export data due to vendor lock-in.
D.Unauthorized public access to data due to overly permissive bucket policies.
E.Lack of encryption at rest for stored objects.
AnswersA, D

Without adequate logging and monitoring, unauthorized access or changes to bucket contents may go undetected. This impairs incident detection and response, and prevents accountability. For sensitive data, the inability to detect and investigate access is a critical risk that compounds the impact of any misconfiguration.

Why this answer

Misconfigured cloud storage most often results in data exposure through overly permissive access policies and goes unnoticed due to insufficient logging and monitoring. These two risks directly affect confidentiality and the ability to detect and respond to incidents. Other options are either less directly related to misconfiguration or are not security risks in the same sense.

Exam trap

The trap here is focusing on encryption or availability concerns when the primary risks of misconfiguration are unauthorized access and lack of detection.

149
MCQmedium

A hospital's radiology department wants to let referring physicians upload imaging orders through a new web portal that stores protected health information (PHI). The risk practitioner must ensure the portal meets the HIPAA Security Rule. Which of the following is the MOST appropriate control to implement first?

A.Deploy full-disk encryption on all endpoint devices used by referring physicians.
B.Sign a business associate agreement with the portal software vendor.
C.Conduct a risk analysis to identify threats and vulnerabilities to the PHI processed by the portal.
D.Implement role-based access control for all portal users.
AnswerC

The HIPAA Security Rule requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI. This risk analysis is the foundational first step that drives the selection of all subsequent administrative, physical, and technical safeguards for the new portal.

Why this answer

The HIPAA Security Rule is built on a risk management framework, and its first required implementation specification is an accurate and thorough risk analysis. Before selecting encryption, access controls, or contracts, the organization must identify and evaluate the risks to electronic PHI. That analysis then informs the selection of reasonable and appropriate safeguards for the portal.

Exam trap

The trap here is assuming that a specific technical safeguard like encryption is always the first step, when HIPAA requires a risk analysis to drive control selection.

150
Multi-Selectmedium

An OT environment is being assessed for compliance with IEC 62443. Which TWO of the following are key security requirements of this standard?

Select 2 answers
A.Segmentation of networks into zones and conduits
B.Mandatory cloud-based backup for all control systems
C.Annual penetration testing by an external firm
D.Use of AES-256 encryption for all communications
E.Implementation of security levels (SL) for control systems
AnswersA, E

Defense-in-depth zones and conduits are core concepts.

Why this answer

IEC 62443 requires segmentation of OT networks into zones and conduits to isolate critical control systems from less trusted networks and control communication flows. This is a foundational security requirement because it limits the blast radius of a cyber incident and enforces access controls between different security levels.

Exam trap

A common pitfall is misunderstanding that 'security levels' (SL) in IEC 62443 are indeed a key requirement—they define the target security capability for each zone/conduit (SL 1-4). The trap is that some candidates may view SL as merely a classification rather than an actionable requirement, but the standard mandates implementing appropriate SLs for each zone. Option B (mandatory cloud backup) and D (AES-256 encryption) are not explicit requirements of IEC 62443, while annual external testing (C) may be recommended but is not a key requirement like zones/conduits and SLs.

← PreviousPage 2 of 3 · 152 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Information Technology and Security questions.