Courseiva

CCNA IT Risk Assessment Questions

75 of 169 questions · Page 1/3 · IT Risk Assessment · Answers revealed

1
MCQmedium

A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?

A.Compensating control such as additional monitoring
B.Preventive control such as patching the vulnerability
C.Corrective control such as backup restoration
D.Detective control such as log monitoring
AnswerB

Patching removes the vulnerable code path entirely, stopping exploitation before it can occur, which is the defining mechanism of a preventive control. This directly satisfies the stem's requirement for the control type most effective at preventing exploitation of the identified web application vulnerability.

Why this answer

A preventive control stops an incident before it occurs, and patching the vulnerability removes the exploitable condition entirely, which is the most effective way to prevent exploitation. Since the vulnerability is identified as critical, remediation via patching directly addresses the root cause rather than merely detecting or recovering from an exploit.

Exam trap

CRISC often tests the distinction between control types; candidates must recognize that 'prevent' questions require a preventive control, not a detective or corrective one, even if those are also valuable.

How to eliminate wrong answers

Option A is wrong because a compensating control (e.g., additional monitoring) only mitigates risk when the primary control cannot be applied; it does not prevent exploitation and is a secondary measure. Option C is wrong because a corrective control (backup restoration) operates after an incident has occurred and does not prevent the vulnerability from being exploited. Option D is wrong because a detective control (log monitoring) identifies an attack in progress or after the fact but does not stop it from succeeding.

2
MCQhard

An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?

A.The residual risk is still critical
B.Controls are effective in reducing risk to a lower level
C.The inherent risk was overestimated
D.Controls are ineffective because residual risk is still above zero
AnswerB

The controls demonstrably lower risk from critical to medium, satisfying the stem's inherent-to-residual reduction. Residual risk of 8 reflects the remaining exposure after control operation, confirming effectiveness rather than mere existence. This axis—measured risk reduction—distinguishes effective controls from implemented-but-ineffective ones.

Why this answer

The reduction from 20 to 8 indicates the controls are effective in reducing risk.

3
MCQeasy

Which of the following is a detective control?

A.Data encryption
B.Intrusion detection system
C.Backup and restore
D.Firewall
AnswerB

An intrusion detection system monitors network traffic and raises alerts on suspicious activity, satisfying the detective control requirement of identifying events after they occur. Unlike preventive controls such as firewalls, which block traffic, it detects and reports intrusions without stopping them, providing the visibility CRISC expects for detection.

Why this answer

Detective controls identify risk events that have occurred. Intrusion detection systems (IDS) monitor network traffic for malicious activity and alert administrators.

4
MCQmedium

A risk practitioner is reviewing the risk register and notices that several risks have not been reassessed in over a year. The business environment has changed significantly due to a new regulation. What is the PRIMARY reason the practitioner should escalate this issue to the risk committee?

A.The risk owners have failed to perform their assigned duties, which is a performance management issue.
B.The risk register may no longer reflect the current risk landscape, leading to ineffective risk treatment decisions.
C.The risk committee is required by regulation to meet at least quarterly to review all risks.
D.The risk assessment methodology itself is flawed and must be replaced with a quantitative approach.
AnswerB

Risk registers must be updated to reflect changes in the internal and external environment. A new regulation can alter likelihood, impact, or risk appetite, making prior assessments obsolete. If the register is stale, treatment plans and resource allocations may be misdirected. Escalation ensures the committee can direct reassessment and realign risk responses with current conditions.

Why this answer

The core issue is that unreviewed risks may no longer be valid after a significant regulatory change. A stale risk register can lead to incorrect treatment priorities and resource allocation. Escalating to the risk committee ensures that reassessment is prioritized and that risk responses are realigned with the new environment, maintaining the effectiveness of risk management.

Exam trap

The trap here is focusing on procedural compliance or individual accountability instead of the substantive risk that outdated assessments may misinform decision-making.

5
MCQeasy

An organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?

A.Eliminates subjectivity in risk assessment
B.Provides comparable results across organizations
C.Quick and easy to communicate
D.Produces financially meaningful results
AnswerC

A 5×5 heat map plots likelihood against impact using ordinal scales, so assessors assign ratings without quantitative data or modelling. This makes results fast to produce and readily understood by executives and business stakeholders, satisfying the need to communicate IT risk posture quickly across the organisation.

Why this answer

A 5×5 risk heat map is a qualitative tool that plots likelihood against impact using ordinal scales, making it fast to produce and easy for executives and non-technical stakeholders to interpret at a glance. Its primary advantage is communication and speed, not quantitative precision.

Exam trap

CRISC often tests the misconception that qualitative heat maps are objective or financially meaningful; candidates must remember that their primary advantage is speed and ease of communication, not precision or comparability.

How to eliminate wrong answers

Option A is wrong because qualitative heat maps are inherently subjective — they rely on expert judgment and ordinal scales, so they do not eliminate subjectivity. Option B is wrong because heat maps are organization-specific; different organizations define their 5×5 scales differently, so results are not directly comparable across organizations. Option D is wrong because qualitative heat maps produce ordinal rankings (e.g., high/medium/low), not financially meaningful monetary values; quantitative methods like FAIR or ALE produce financial results.

6
MCQeasy

A retail company is conducting a risk assessment for its point-of-sale (POS) systems. The risk team determines that the inherent risk of a malware attack is high. The company implements endpoint detection and response (EDR) tools and network segmentation. After these controls, the risk is re-evaluated. What is this re-evaluated risk called?

A.Control risk
B.Detection risk
C.Inherent risk
D.Residual risk
AnswerD

Residual risk is the remaining risk after controls have been implemented. After deploying EDR tools and network segmentation, the risk of a malware attack is reduced but not eliminated. The re-evaluated risk level is therefore the residual risk, which reflects the effectiveness of the controls.

Why this answer

Residual risk is the risk that remains after controls are implemented. In this scenario, the company applied EDR and network segmentation to reduce the high inherent risk of malware. The re-evaluated risk is the residual risk, which should be compared to the organization's risk appetite to determine if further action is needed.

Exam trap

The trap here is confusing residual risk with inherent risk or control risk, especially when a scenario describes both before and after control states.

7
MCQmedium

An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?

A.Accept
B.Avoid
C.Mitigate
D.Transfer
AnswerD

Outsourcing with contractual penalties shifts financial loss from security breaches to the cloud provider. Transfer moves risk to a third party via contract, unlike avoid, mitigate or accept. The penalties clause confirms the loss is borne externally, satisfying the transfer definition.

Why this answer

Outsourcing data center operations to a cloud provider with contractual penalties for security breaches shifts the financial impact of a risk event to a third party. This is the definition of risk transfer, where the organization pays another party (via contract, insurance, or outsourcing) to bear the risk. The strict contractual penalties ensure the provider absorbs the cost if a breach occurs, which is the hallmark of transfer.

Exam trap

CRISC often tests the distinction between risk transfer and risk mitigation, where candidates incorrectly choose 'mitigate' because contractual penalties seem like a control, but the key is that the financial impact is shifted to a third party.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and retaining the potential loss without taking action to shift or reduce it; here the organization is actively shifting the loss to the provider. Option B is wrong because risk avoidance means eliminating the activity or process that generates the risk entirely (e.g., not outsourcing at all), whereas the organization is continuing the activity but shifting the risk. Option C is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact of the risk while retaining it, not transferring the financial consequence to a third party via contract.

8
MCQhard

In the FAIR framework, loss magnitude (LM) is composed of primary loss and secondary loss. Which of the following is an example of secondary loss?

A.Incident response costs
B.Lost business due to reputation damage
C.Legal notification costs
D.System restoration expenses
AnswerB

Lost business from reputation damage is a secondary loss because it is a consequential, stakeholder-driven effect rather than the direct primary loss from the threat event itself. FAIR separates these: primary loss hits the affected asset, while secondary loss captures reactions such as customer defection, satisfying the stem's requirement for a secondary-loss example.

Why this answer

Secondary loss includes indirect costs like reputational damage, loss of customer trust, and share price impact.

9
MCQmedium

A risk analyst is assessing a newly discovered vulnerability in an internet-facing server. The analyst collects several data points: the vulnerability has a CVSS base score of 9.8, there are known exploits in the wild, and the server is critical for processing customer transactions. However, the organization's intrusion detection system has a signature that blocks the specific exploit, and the server is patched monthly. The analyst must determine the risk level. Which of the following should the analyst use to BEST assess the risk?

A.A qualitative risk assessment using a likelihood-impact matrix that incorporates the effectiveness of existing controls and threat intelligence.
B.The CVSS base score alone, because it provides a standardized severity rating.
C.The exploitability subscore of CVSS, because it measures the difficulty of exploiting the vulnerability.
D.The asset's replacement cost, because risk is a function of financial impact.
AnswerA

This approach integrates the vulnerability severity with the organization's control environment (IDS, patching) and real-world threat data (exploits in the wild) to produce a contextual risk rating. It aligns with CRISC's emphasis on business-relevant risk assessment. The analyst can then prioritize remediation based on actual risk exposure rather than raw severity.

Why this answer

The analyst must assess risk by combining vulnerability severity, threat activity, existing controls, and asset criticality. A qualitative matrix that incorporates control effectiveness and threat intelligence provides a business-contextualized risk rating, which is essential for prioritization. CVSS base scores or subscores are inputs but not sufficient alone, and financial impact alone misses likelihood and control factors.

Exam trap

The trap here is assuming that a high CVSS base score directly equates to high organizational risk without considering compensating controls and threat context.

10
MCQmedium

During an IT risk assessment, a risk owner identifies a risk that is within the organization's risk appetite. The recommended risk treatment option is to:

A.Accept the risk with formal sign-off.
B.Avoid the risk by eliminating the activity.
C.Transfer the risk through cyber insurance.
D.Mitigate the risk by implementing additional controls.
AnswerA

Acceptance is the appropriate treatment when a risk falls within the organisation's defined risk appetite, since no further mitigation is justified. Formal sign-off preserves accountability and creates an audit trail, satisfying the stem's requirement that the risk owner document the decision rather than transfer, avoid or mitigate it.

Why this answer

When a risk is within appetite, the appropriate response is to accept it, with formal documentation and sign-off by the risk owner.

11
MCQmedium

A risk analyst is building a risk register for a newly deployed customer relationship management (CRM) system that stores personally identifiable information (PII). The analyst needs to document the risk that an attacker could exfiltrate the PII database. Which of the following BEST represents the threat component of this risk statement?

A.The CRM database contains unencrypted PII fields.
B.An external attacker with data exfiltration capability.
C.The financial impact of a PII breach is estimated at $2 million.
D.The likelihood of a PII breach is rated as high.
AnswerB

The threat component identifies the actor or event that can exploit a vulnerability to cause harm. An external attacker with exfiltration capability is precisely that actor, and pairing it with the unencrypted PII vulnerability produces a complete risk statement. This is the element a risk analyst must document to describe who or what could cause the loss event.

Why this answer

A well-formed risk statement links a threat source to a vulnerability and an impact. The attacker with exfiltration capability is the threat source, while the unencrypted PII fields are the vulnerability and the dollar figure is the impact. Identifying the threat source correctly lets the risk analyst select appropriate controls, such as monitoring for exfiltration behavior, and enables meaningful comparison across other risks in the register.

Exam trap

The trap here is confusing a vulnerability, such as unencrypted PII, with the threat actor who could exploit it.

12
Multi-Selecthard

An organization is assessing control effectiveness for a firewall. Which THREE factors should be evaluated to determine control effectiveness? (Select THREE)

Select 3 answers
A.Design adequacy of the firewall rules
B.Operating effectiveness of the firewall
C.Cost of the firewall
D.Relevance to the specific risk scenario
E.Frequency of rule updates
AnswersA, B, D

Design adequacy examines whether the firewall rule set, architecture and coverage are capable of mitigating the identified risk if operating as intended. This satisfies the stem's effectiveness assessment because a control with flawed or incomplete design cannot deliver the required protection, regardless of how reliably it runs day to day.

Why this answer

Design adequacy of the firewall rules (A) is correct because control effectiveness begins with whether the ruleset is properly architected to enforce the intended security policy, including correct default-deny posture, rule ordering, and coverage of required traffic flows. Operating effectiveness of the firewall (B) is correct because even a well-designed ruleset must be verified to actually function as intended in production, through testing, monitoring, and evidence that the control operates consistently over time. Relevance to the specific risk scenario (D) is correct because a control is only effective if it directly addresses the identified risk; a technically sound firewall that does not mitigate the specific threat in scope provides no assurance for that scenario.

Cost of the firewall (C) is not a factor in determining control effectiveness, as it relates to budgeting and cost-benefit rather than whether the control actually mitigates risk. Frequency of rule updates (E) is not itself an effectiveness factor, since the quality and appropriateness of changes matter more than how often they occur, and it is subsumed under design adequacy and operating effectiveness.

Exam trap

CRISC often tests the difference between control effectiveness criteria (design, operation, relevance) and control selection criteria (cost, complexity) — candidates pick cost or update frequency because they sound operational.

13
MCQmedium

In assessing control effectiveness, an IS auditor evaluates both design adequacy and operating effectiveness. Which of the following indicates that a control is operating effectively?

A.The control is approved by management
B.The control has been tested and works as designed
C.The control is inexpensive to implement
D.The control is documented in policy
AnswerB

Operating effectiveness is demonstrated when testing confirms the control functions as designed throughout the review period, not merely that it exists. Design adequacy addresses whether the control is suitably constructed; testing evidences actual consistent operation, satisfying the auditor's effectiveness criterion.

Why this answer

Operating effectiveness means the control has been tested and consistently produces the intended result in practice. Even if a control is well-designed, it may fail during actual operation due to misconfiguration, human error, or environmental changes. Testing confirms that the control functions as designed under real conditions, which is the definitive indicator of operating effectiveness.

Exam trap

The trap here is confusing control design (what is planned or documented) with control operation (what actually happens in practice), leading candidates to select policy or approval as evidence of effectiveness.

How to eliminate wrong answers

Option A is wrong because management approval only indicates that the control design is authorized, not that it is actually working in production. Option C is wrong because cost is a factor in control selection and efficiency, not a measure of whether the control operates effectively. Option D is wrong because documentation in policy only proves the control exists on paper, not that it is executed correctly or consistently.

14
MCQeasy

A risk manager is using a 5×5 likelihood-impact matrix to assess a set of identified risks. What is the PRIMARY advantage of using this qualitative method?

A.It provides objective and comparable risk scores across organizations.
B.It is quick and easy to communicate to stakeholders.
C.It produces financially meaningful results for cost-benefit analysis.
D.It requires less data but is time-consuming to complete.
AnswerB

A 5x5 likelihood-impact matrix maps risks to qualitative ratings using predefined scales, requiring no quantitative data or modelling. This makes assessment fast and produces a visual heat map that stakeholders readily interpret, satisfying the need for efficient communication.

Why this answer

Qualitative risk analysis using heat maps is quick and easy to communicate to stakeholders, making it a common initial assessment tool.

15
MCQhard

A financial services firm is evaluating the risk of insider threat in its trading department. The risk team has identified that a small number of traders have elevated privileges that allow them to execute trades and access sensitive market data. The team must determine the MOST effective control to reduce the likelihood of unauthorized trading activity. Which control should they prioritize?

A.Increasing the number of security cameras in the trading floor
B.Conducting regular background checks on all traders
C.Enforcing separation of duties between trade execution and trade confirmation
D.Implementing mandatory vacation and job rotation policies
AnswerC

Separation of duties ensures that no single individual can execute and confirm a trade, which directly reduces the likelihood of unauthorized or fraudulent trading. By requiring a second person to confirm trades, the control prevents a trader from acting alone. This is the most effective preventive control for reducing the likelihood of unauthorized trading activity in this scenario.

Why this answer

Unauthorized trading often involves a single individual exploiting their privileges to execute and conceal trades. Separation of duties between trade execution and confirmation ensures that at least two people are involved in the process, making it much harder for one person to conduct unauthorized activity without detection. This preventive control directly reduces the likelihood of the risk.

Other controls may help but are less direct or timely.

Exam trap

The trap here is choosing detective controls like mandatory vacations or background checks, which do not prevent a trader from executing unauthorized trades in the first place.

16
MCQhard

A multinational manufacturer is assessing the risk of a ransomware attack on its operational technology (OT) network. The risk team has identified that the OT network is segmented from the corporate IT network, but a shared jump server allows administrators to move between them. The team must determine the MOST significant factor that could increase the likelihood of ransomware spreading from IT to OT. Which factor should they prioritize?

A.The lack of antivirus software on OT endpoints
B.The frequency of security awareness training for IT staff
C.The presence of the shared jump server
D.The OT network's use of legacy operating systems
AnswerC

The shared jump server creates a bridge between the corporate IT and OT networks. If an attacker compromises the IT network, they can use the jump server to pivot into the OT environment, bypassing the segmentation. This significantly increases the likelihood of ransomware spreading to OT. The jump server is the most critical factor because it directly enables lateral movement across the security boundary.

Why this answer

The shared jump server acts as a bridge between the segmented IT and OT networks. If ransomware compromises the IT environment, the jump server provides a direct path to the OT network, effectively negating the segmentation. This makes it the most significant factor increasing the likelihood of cross-network spread.

Other factors like legacy systems and missing antivirus affect impact or vulnerability but do not create the initial pathway.

Exam trap

The trap here is focusing on endpoint weaknesses like legacy systems or missing antivirus, while overlooking the architectural connectivity that enables lateral movement across network boundaries.

17
Multi-Selectmedium

A risk assessment of a critical financial application identifies a high inherent risk due to outdated software. The risk manager is considering mitigation options. Which TWO of the following would be considered preventive controls?

Select 2 answers
A.Configuring access controls
B.Deploying an intrusion detection system
C.Implementing a patch management process
D.Establishing a backup and recovery plan
E.Conducting regular security audits
AnswersA, C

Access controls prevent unauthorized access.

Why this answer

Configuring access controls is a preventive control because it proactively restricts unauthorized users from accessing the financial application, reducing the likelihood of a security incident. By enforcing least privilege and authentication mechanisms, it directly mitigates the risk of exploitation of the outdated software by limiting who can interact with it.

Exam trap

The trap here is confusing detective controls (like IDS or audits) or recovery controls (like backups) with preventive controls, especially when the question emphasizes 'mitigation options' for outdated software—candidates often overlook that patching is a direct preventive measure against known vulnerabilities.

18
MCQmedium

A healthcare provider is conducting a risk assessment for its electronic health record (EHR) system. The risk team has identified that a recent upgrade introduced a new vulnerability that could allow unauthorized access to patient data. The vulnerability has a known exploit but no patch is available yet. The team must decide on the BEST immediate risk response. What should they do FIRST?

A.Implement a compensating control such as enhanced monitoring and network isolation
B.Accept the risk because the EHR system is critical to patient care
C.Avoid the risk by shutting down the EHR system
D.Transfer the risk by purchasing cyber insurance
AnswerA

When a vulnerability has a known exploit and no patch is available, implementing compensating controls like enhanced monitoring, intrusion detection, and network isolation can reduce the likelihood or impact of exploitation. This is the most immediate and practical response to mitigate risk while awaiting a patch. It directly addresses the exposure without requiring a permanent fix.

Why this answer

When a vulnerability has a known exploit and no patch is available, the best immediate response is to implement compensating controls that reduce exposure. Enhanced monitoring can detect exploitation attempts, and network isolation can limit access. This approach allows the organization to continue operating while mitigating risk.

Acceptance, transfer, or avoidance are either inappropriate or impractical in this context.

Exam trap

The trap here is jumping to risk transfer or acceptance because a patch is unavailable, instead of applying compensating controls that directly reduce the risk while maintaining critical operations.

19
MCQhard

A multinational corporation is conducting a risk assessment for its third-party vendors. The risk team has assigned a high inherent risk rating to a vendor that provides critical payroll processing. The vendor has recently provided a SOC 2 Type II report with no exceptions, and the contract includes a right-to-audit clause. The risk practitioner must determine the residual risk rating. Which factor is MOST important in making this determination?

A.The scope of the SOC 2 Type II report relative to the payroll processing services.
B.The presence of a right-to-audit clause in the contract.
C.The vendor's financial stability and length of time in business.
D.The number of other clients the vendor serves in the same industry.
AnswerA

The SOC 2 Type II report must cover the specific trust services criteria and processes relevant to payroll processing for the report to reduce residual risk. If the report excludes key systems or controls, the high inherent risk may remain largely unmitigated. Evaluating the scope ensures that the independent assurance actually addresses the risks identified in the assessment, making it the most critical factor.

Why this answer

The scope of the SOC 2 Type II report is the most important factor because it determines whether the independent assurance covers the systems, processes, and trust services criteria relevant to payroll processing. If the report's scope excludes critical controls or infrastructure, the high inherent risk remains largely unaddressed. The right-to-audit clause and vendor characteristics are secondary to understanding whether the controls that matter are actually tested and effective.

Exam trap

The trap here is assuming that any SOC 2 Type II report with no exceptions automatically reduces risk, without verifying that its scope covers the specific services and controls relevant to the risk.

20
Multi-Selecthard

A risk assessment team is prioritizing IT risks for treatment. Which THREE factors should be considered when prioritizing risks? (Select THREE)

Select 3 answers
A.Industry standards for similar risks
B.The inherent risk score of each risk
C.Cost-benefit analysis of potential controls
D.Residual risk after existing controls
E.The risk owner's personal preference
AnswersB, C, D

Higher inherent risks typically get higher priority.

Why this answer

The inherent risk score provides a baseline measure of risk without considering controls, which is essential for prioritizing which risks require immediate attention. This score is typically calculated as a product of likelihood and impact, and it helps the team focus on the most severe potential threats first.

Exam trap

The trap here is that candidates may confuse 'factors to consider when prioritizing risks' with 'inputs to risk assessment' and incorrectly select industry standards (Option A) as a direct prioritization factor, when in fact they are used for benchmarking or compliance, not for ranking treatment urgency.

21
Multi-Selectmedium

A company is evaluating control types for a new system. The security team proposes implementing an intrusion detection system (IDS) and a backup restoration process. Which TWO control types do these represent, respectively?

Select 2 answers
A.Deterrent
B.Preventive
C.Compensating
D.Detective
E.Corrective
AnswersD, E

An IDS monitors activity and raises alerts after or during an event, making it detective rather than preventive. It identifies intrusions without blocking them, which is the defining characteristic of detective controls as opposed to preventive, corrective or compensating types.

Why this answer

An IDS is a detective control (D) because it monitors network or host activity and generates alerts on suspicious or malicious events, but it does not block them, so it identifies rather than prevents incidents. A backup restoration process is a corrective control (E) because it restores systems and data to a known-good state after an incident, directly remediating the impact. Deterrent (A) controls discourage attackers (e.g., warning banners, guards) and do not detect or recover, so they do not fit.

Preventive (B) controls such as firewalls, IPS, or access controls stop events before they occur, which an IDS does not do. Compensating (C) controls are alternative measures used when a primary control cannot be implemented, which is not the case for either IDS or backup restoration here.

Exam trap

CRISC often tests whether candidates confuse detective with preventive controls — IDS is frequently mistaken for a preventive control because it 'stops' attacks, but it only detects, while backups are corrective, not preventive.

22
MCQhard

A risk practitioner is assessing a cloud-hosted payroll application. The vendor's SOC 2 report shows effective controls, but the report covers only the period ending eight months ago, and the vendor has since migrated to a new hosting region. The practitioner needs to determine whether the control environment can still be relied upon. Which of the following is the MOST appropriate next step?

A.Request the vendor's bridge letter and updated SOC 2 report covering the new region, and review the gap period.
B.Perform a full penetration test of the payroll application to validate the vendor's controls.
C.Accept the SOC 2 report as sufficient evidence because the controls were independently audited.
D.Terminate the vendor relationship and migrate payroll to an internally managed platform.
AnswerA

A bridge letter addresses the period between the report end date and the current date, and an updated report covering the new region provides evidence for the changed environment. Reviewing both lets the practitioner evaluate whether controls continued to operate and whether the migration introduced new risks. This is the most direct way to restore assurance without duplicating the vendor's audit work.

Why this answer

Third-party attestation evidence must be current and must cover the environment actually in use. A bridge letter closes the gap between the report period and today, while an updated SOC 2 report covering the new hosting region addresses the changed infrastructure. Together they allow the practitioner to judge whether reliance remains justified, which is the essential next step before deciding on any treatment action.

Exam trap

The trap here is treating an audited SOC 2 report as permanently valid even after a major infrastructure change and a long period gap.

23
MCQmedium

During an IT risk assessment, the risk owner identifies a high inherent risk for a legacy system. After implementing a firewall and intrusion detection system, the residual risk is calculated. Which of the following best describes residual risk?

A.The risk level before any controls are implemented
B.The risk level after considering control effectiveness
C.The risk that is transferred to a third party
D.The risk that is accepted without action
AnswerB

Residual risk is what remains after existing controls are applied to an inherent risk. The firewall and intrusion detection system reduce the high inherent level, so the recalculated figure reflects control effectiveness rather than the untreated exposure.

Why this answer

Residual risk is the level of risk that remains after controls have been implemented and their effectiveness has been factored in. In this scenario, the firewall and intrusion detection system are controls that reduce the inherent risk, but some risk (e.g., from zero-day exploits or misconfigurations) will persist, which is the residual risk.

Exam trap

The trap here is confusing residual risk with inherent risk (Option A) or with risk response strategies like transfer (Option C) or acceptance (Option D), rather than recognizing it as the risk remaining after control implementation.

How to eliminate wrong answers

Option A is wrong because it describes inherent risk, which is the risk level before any controls are implemented, not after. Option C is wrong because it describes risk transfer (e.g., via insurance or outsourcing), which is a risk response strategy, not the remaining risk after controls. Option D is wrong because it describes risk acceptance, which is a decision to tolerate the residual risk without further action, not the residual risk itself.

24
Multi-Selecthard

An organization is performing a quantitative risk analysis using the FAIR framework. Which THREE of the following are direct components of the FAIR model?

Select 3 answers
A.Single Loss Expectancy
B.Loss Event Frequency
C.Threat Event Frequency
D.Annualized Loss Expectancy
E.Vulnerability
AnswersB, C, E

Loss Event Frequency is a core FAIR factor, combining Threat Event Frequency and Vulnerability to express how often loss events occur. It satisfies the stem's requirement for a direct model component, sitting on the frequency axis of risk, which FAIR quantifies as Loss Event Frequency multiplied by Loss Magnitude.

Why this answer

In the FAIR (Factor Analysis of Information Risk) ontology, Loss Event Frequency (B) is a core top-level factor representing how often loss events occur, and it is decomposed into Threat Event Frequency and Vulnerability. Threat Event Frequency (C) is a direct component of FAIR, describing the probable frequency with which threat agents act against an asset. Vulnerability (E) is also a direct FAIR component, defined as the probability that a threat event becomes a loss event, and it combines with Threat Event Frequency to derive Loss Event Frequency.

By contrast, Single Loss Expectancy (A) and Annualized Loss Expectancy (D) are classic qualitative/quantitative risk formulas from traditional risk analysis (SLE = asset value × exposure factor; ALE = SLE × ARO), not native FAIR ontology components.

Exam trap

CRISC often tests the difference between FAIR's factor decomposition (Threat Event Frequency, Vulnerability, Loss Event Frequency) and traditional ALE/SLE formulas — candidates mix the two frameworks.

25
MCQmedium

A risk analyst at a healthcare provider is assessing the risk of a ransomware attack on a clinical data repository. The analyst estimates that a ransomware event would cost $800,000 in recovery and downtime, and that such an event is likely to occur once every four years. What is the annualized loss expectancy (ALE) for this risk?

A.$800,000
B.$3,200,000
C.$200,000
D.$100,000
AnswerC

ALE is calculated as single loss expectancy (SLE) multiplied by annualized rate of occurrence (ARO). Here SLE is $800,000 and ARO is 0.25 (once every four years), so ALE = $800,000 × 0.25 = $200,000. This is the expected annual loss from the ransomware risk and is the correct value for prioritizing treatment options.

Why this answer

Annualized loss expectancy expresses expected yearly loss as single loss expectancy multiplied by annualized rate of occurrence. With an $800,000 single loss and a four-year recurrence, the ARO is 0.25, producing an ALE of $200,000. This normalized annual figure lets the healthcare provider compare the ransomware risk directly against other risks and against the cost of proposed controls.

Exam trap

The trap here is confusing single loss expectancy with annualized loss expectancy, or inverting the recurrence interval instead of converting it to an annualized rate of occurrence.

26
MCQmedium

A global investment firm maintains a central risk register. The CISO wants to reduce the number of entries by consolidating risks that share the same root cause. Which action BEST supports this goal while preserving the risk register's integrity?

A.Group risks by the asset they affect and merge them into a single risk statement per asset.
B.Create a parent risk for each shared root cause and link the related risk entries as sub-risks, retaining their individual details.
C.Move all low-rated risks to a separate spreadsheet outside the central register.
D.Delete duplicate entries and rely on the risk owner's memory to recall the original context.
AnswerB

A parent-child structure clusters risks that stem from the same root cause while retaining each entry's likelihood, impact, owner, and treatment. This reduces the apparent volume of top-level entries without losing the granularity needed for treatment and monitoring. It maintains traceability and supports aggregation for reporting to the board, which is exactly what the CISO needs here.

Why this answer

Consolidating by shared root cause is best achieved with a parent-child hierarchy that preserves the details of each underlying risk. This keeps likelihood, impact, ownership, and treatment traceable while reducing clutter at the top level. Deleting, relocating, or asset-merging entries sacrifices granularity, auditability, or aggregation insight, none of which preserves the register's integrity.

Exam trap

The trap here is assuming that fewer register entries always means better risk management, when the real goal is consolidation without loss of traceability or ownership detail.

27
Multi-Selecthard

A retail company is assessing risk for a legacy point-of-sale system that cannot be patched. The risk team wants to identify controls that would reduce the likelihood of a successful exploitation of known vulnerabilities on these terminals. Which TWO of the following are preventive controls that would BEST reduce the likelihood of exploitation? (Choose two.)

Select 2 answers
A.Conduct quarterly vulnerability scans of the point-of-sale network
B.Segment the point-of-sale terminals onto a dedicated network with strict firewall rules limiting outbound and inbound traffic
C.Enable detailed logging and forward terminal logs to a centralized SIEM for monitoring
D.Deploy application allowlisting on the terminals so only approved executables can run
E.Perform daily backups of terminal configuration and transaction data
AnswersB, D

This is correct because network segmentation with restrictive firewall rules prevents exploitation attempts from reaching the unpatched terminals and limits lateral movement, directly lowering the likelihood that a known vulnerability is successfully exploited. It is a preventive control that reduces exposure even when patching is not feasible on the legacy point-of-sale devices.

Why this answer

Preventive controls reduce the likelihood of a successful attack. Network segmentation with restrictive firewall rules and application allowlisting both stop exploitation attempts from succeeding on unpatched terminals by limiting reachability and blocking unauthorized code execution. Logging, backups, and vulnerability scanning are valuable but are detective or corrective in nature and do not lower the probability of exploitation.

Exam trap

The trap here is treating monitoring, scanning, or backups as if they reduce the likelihood of exploitation, when they are detective or corrective rather than preventive.

28
MCQmedium

A financial services firm has completed a risk assessment of its trading platform. The chief risk officer wants to ensure the assessment results are comparable across business units and that the reasoning behind each likelihood and impact rating is transparent to auditors. Which action BEST supports this objective?

A.Increase the number of risks in the register to ensure no scenario is overlooked
B.Recalculate all risk scores using a 10×10 matrix instead of a 5×5 matrix
C.Assign all risk scoring decisions to a single central analyst
D.Document the rating scales and the specific criteria and evidence used to assign each likelihood and impact value
AnswerD

This is correct because consistent, well-documented rating criteria allow different business units to apply the same scales in comparable ways, and recording the evidence behind each rating gives auditors a clear rationale to review. It directly supports both comparability across units and traceability of assessment judgments for the trading platform risk register.

Why this answer

Comparability and auditability depend on defined rating scales, explicit criteria for each level, and documented evidence supporting each likelihood and impact assignment. These elements let different business units apply the same methodology and let auditors trace how each score was derived, which is more valuable than changing matrix size or centralizing decisions.

Exam trap

The trap here is equating a larger or more granular rating matrix with improved consistency, when consistency actually comes from defined criteria and documented rationale.

29
MCQeasy

During an IT risk assessment, the risk owner decides to accept a risk that falls within the organization's risk appetite. Which of the following actions is most appropriate for the risk owner to take?

A.Document the risk and obtain formal sign-off from the risk owner.
B.Eliminate the business process that creates the risk.
C.Transfer the risk to a third party via insurance.
D.Implement additional controls to reduce the risk to zero.
AnswerA

Acceptance is a deliberate decision, so the risk owner must record the risk in the risk register with its acceptance rationale and obtain formal sign-off. This creates an auditable trail proving the risk was knowingly accepted within the organisation's stated risk appetite, satisfying governance and accountability requirements.

Why this answer

When a risk falls within the organization's risk appetite, the most appropriate action is to formally accept it. The risk owner must document the risk and obtain formal sign-off to ensure accountability and auditability, as required by the risk management framework. This aligns with the principle that risks within appetite do not require additional treatment beyond formal acceptance.

Exam trap

The trap here is that candidates often confuse risk acceptance with risk treatment, assuming that any risk must be mitigated or transferred, but the CRISC exam emphasizes that risks within appetite can be formally accepted without further action.

How to eliminate wrong answers

Option B is wrong because eliminating the business process that creates the risk is a risk avoidance strategy, which is excessive and unnecessary when the risk is within the organization's risk appetite. Option C is wrong because transferring the risk via insurance is a risk treatment option typically reserved for risks that exceed the risk appetite or tolerance, not for those already within acceptable levels. Option D is wrong because implementing additional controls to reduce the risk to zero is impractical and violates the concept of residual risk; risk can rarely be reduced to zero, and doing so would be cost-prohibitive and unnecessary for an accepted risk.

30
Multi-Selectmedium

A risk analyst is building a scenario for a ransomware event affecting a hospital's electronic health record environment. The analyst wants to capture loss magnitude dimensions that are frequently overlooked when only direct recovery costs are counted. Which TWO loss factors should be included to make the magnitude estimate more complete? (Choose two.)

Select 2 answers
A.Regulatory penalties and notification obligations triggered by the breach of patient records.
B.The market price of the cryptocurrency demanded by the attacker at the time of the incident.
C.The salary of the security awareness trainer who delivered last year's phishing education sessions.
D.Business interruption losses from unavailable clinical systems during containment and recovery.
E.The annual license renewal cost the hospital already pays for its endpoint protection platform.
AnswersA, D

Ransomware affecting health records typically triggers statutory notification and penalty exposure under health privacy regulations, and these costs can dwarf the ransom itself. Including them makes the magnitude estimate reflect legal and compliance consequences rather than only restoration effort. This directly addresses the scenario's concern about undercounting loss dimensions beyond direct recovery.

Why this answer

Complete loss magnitude estimates for a ransomware scenario must extend past recovery costs to include consequential and secondary effects. Regulatory penalties and notification duties tied to compromised patient records, along with business interruption from unavailable clinical systems, are two such dimensions. Planned expenses such as license fees and prior training spend are not incident-driven losses and would distort the estimate.

Exam trap

The trap here is treating the ransom demand as the headline loss while omitting regulatory and interruption consequences that usually cost far more.

31
MCQeasy

Which type of control is designed to reduce the likelihood of a risk event occurring?

A.Corrective
B.Compensating
C.Preventive
D.Detective
AnswerC

Preventive controls act before an event occurs, blocking or deterring it to lower likelihood. Detective and corrective controls address discovery or recovery after the fact, so they reduce impact rather than probability, which the stem specifically asks about.

Why this answer

Preventive controls are designed to stop a risk event from occurring in the first place. For example, implementing a firewall rule to block unauthorized inbound traffic reduces the likelihood of a network intrusion. This aligns with the CRISC definition of preventive controls as proactive measures that reduce the probability of a risk scenario.

Exam trap

The trap here is that candidates often confuse preventive controls with detective controls, mistakenly thinking that monitoring or alerting (detective) reduces the likelihood of an event, when in fact it only reduces the impact or detection time after the event has occurred.

How to eliminate wrong answers

Option A is wrong because corrective controls are designed to remediate or restore operations after a risk event has occurred, such as restoring data from backup after a ransomware attack, not to reduce the likelihood of the event. Option B is wrong because compensating controls are alternative measures that provide equivalent protection when a primary control is not feasible, such as using additional logging when encryption cannot be applied, but they do not directly reduce the likelihood of the original risk event. Option D is wrong because detective controls are designed to identify and report risk events after they have happened, such as intrusion detection systems (IDS) that alert on malicious traffic, not to prevent the event from occurring.

32
MCQhard

An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:

A.Risk transfer
B.Risk acceptance
C.Risk mitigation
D.Risk avoidance
AnswerA

Liability clauses and cyber insurance shift the financial consequence of payroll errors to the vendor and insurer, while the organisation retains operational responsibility. This is risk transfer, satisfying the stem's high inherent risk mitigated through contractual and insurance mechanisms rather than avoidance or reduction.

Why this answer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or contractual liability clauses. Here, the vendor contract includes liability clauses and the organization obtains cyber insurance — both mechanisms shift financial consequences away from the organization. This is the defining characteristic of risk transfer, making it the correct answer.

Exam trap

CRISC often tests the distinction between risk transfer and risk mitigation, and candidates commonly pick 'risk mitigation' because the scenario mentions a vendor contract — the trap is that liability clauses and insurance shift financial impact (transfer), while mitigation would involve reducing the likelihood or impact of the error itself.

How to eliminate wrong answers

Option B (Risk acceptance) is wrong because acceptance means acknowledging the risk and deciding to bear it without further treatment — here, the organization is actively shifting financial impact via contract and insurance, not accepting it. Option C (Risk mitigation) is wrong because mitigation reduces the likelihood or impact of the risk through controls (e.g., validation checks, segregation of duties) — the scenario does not describe reducing payroll error likelihood, only shifting financial consequences. Option D (Risk avoidance) is wrong because avoidance means eliminating the activity or not undertaking it — the organization is proceeding with outsourcing, not avoiding the risk.

33
Multi-Selectmedium

A company is considering risk transfer for a new IT project. Which TWO options represent valid risk transfer mechanisms? (Select TWO)

Select 2 answers
A.Accepting the risk with sign-off
B.Purchasing cyber insurance
C.Implementing access controls
D.Discontinuing the project
E.Outsourcing with liability clauses
AnswersB, E

Cyber insurance transfers the financial impact of a realised risk to the insurer in exchange for premiums, leaving the organisation to bear only deductibles and uncovered losses. This satisfies the stem's requirement for a valid risk transfer mechanism, since the monetary consequence, not the risk itself, is shifted.

Why this answer

Option B (Purchasing cyber insurance) is a valid risk transfer mechanism because the organization pays a premium to shift the financial impact of covered cyber events, such as data breaches or ransomware, to the insurer. Option E (Outsourcing with liability clauses) is also valid risk transfer because contractual liability clauses shift specified responsibilities and financial consequences for incidents to the third-party vendor. Option A (Accepting the risk with sign-off) is risk acceptance, not transfer, since the organization retains the risk.

Option C (Implementing access controls) is risk mitigation/reduction through preventive controls. Option D (Discontinuing the project) is risk avoidance, as the activity creating the risk is eliminated.

Exam trap

CRISC often tests the confusion between risk response strategies — candidates frequently misclassify mitigation (controls) or avoidance (discontinuing) as transfer, when transfer specifically requires a third party to assume the financial impact.

34
MCQeasy

A risk practitioner is using a 5×5 heat map to assess IT risks. Which of the following is the primary advantage of this qualitative approach?

A.Produces financially meaningful loss estimates
B.Requires less data and time to implement
C.Provides objective and comparable risk scores across organizations
D.Eliminates subjectivity in risk ratings
AnswerB

A 5×5 heat map plots likelihood against impact using ordinal ratings, so it needs no quantitative loss data or statistical modelling. This satisfies the scenario's need for a fast, low-data qualitative assessment, though it sacrifices precision.

Why this answer

A 5×5 heat map is a qualitative risk assessment tool that uses ordinal scales (e.g., low, medium, high) for likelihood and impact. Its primary advantage is that it requires less data and time to implement compared to quantitative methods, which demand detailed financial data and complex calculations. This makes it practical for rapid, high-level IT risk prioritization when precise data is unavailable.

Exam trap

The trap here is that candidates often confuse 'qualitative' with 'objective' or 'comparable,' but qualitative methods are inherently subjective and context-dependent, unlike quantitative methods that produce numeric, comparable outputs.

How to eliminate wrong answers

Option A is wrong because qualitative heat maps do not produce financially meaningful loss estimates; they use subjective ordinal scales (e.g., 'high impact') rather than monetary values, which is a key limitation. Option C is wrong because qualitative scores are subjective and depend on the assessor's judgment, making them not objectively comparable across different organizations or even different teams within the same organization. Option D is wrong because the approach does not eliminate subjectivity; in fact, it relies on expert judgment to assign ratings, which introduces inherent bias and variability.

35
Multi-Selectmedium

A healthcare organization is assessing risks to its electronic health record (EHR) system. The risk team is evaluating the likelihood of a threat event. Which TWO factors are MOST relevant when estimating the likelihood of a threat exploiting a vulnerability? (Choose two.)

Select 2 answers
A.The number of users with access to the EHR system
B.The skill level and motivation of the threat actor
C.The ease of discovery and exploitability of the vulnerability
D.The regulatory fines associated with a data breach
E.The cost of implementing additional security controls
AnswersB, C

The skill level and motivation of a threat actor directly influence the probability that a vulnerability will be exploited. A highly skilled and motivated attacker is more likely to identify and successfully exploit weaknesses. This factor is a core component of threat likelihood estimation in risk assessments, as it reflects the capability and intent of potential adversaries.

Why this answer

Likelihood estimation in risk assessment focuses on factors that influence the probability of a threat exploiting a vulnerability. The skill and motivation of the threat actor and the ease of discovery and exploitability of the vulnerability are direct determinants of that probability. Regulatory fines, user count, and control costs are related to impact or treatment, not likelihood.

Exam trap

The trap here is selecting impact-related factors such as regulatory fines or control costs when asked about likelihood, as these influence the severity of consequences rather than the probability of occurrence.

36
Multi-Selecthard

A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?

Select 3 answers
A.The impact of the risk on operational productivity
B.The likelihood of the threat event occurring
C.The cost of the insurance premium relative to the expected loss
D.The residual risk after insurance is applied
E.The extent of coverage and exclusions in the policy
AnswersC, D, E

Comparing premium against expected loss establishes whether transferring the risk is economically rational. This satisfies the stem's evaluation requirement by testing cost-effectiveness: if premiums approach or exceed probable losses, retention or mitigation may deliver better value than insurance.

Why this answer

Option C is correct because the premium is the direct cost of transferring the risk, and it must be weighed against the expected loss (likelihood × impact) to determine whether the transfer is economically worthwhile. Option D is correct because insurance rarely eliminates a risk entirely; the high deductible and any uncovered portions leave a residual risk that the organization still owns and must evaluate. Option E is correct because the policy's coverage limits and exclusions define exactly which attack types and loss amounts are actually transferred, directly determining the transfer's effectiveness.

Option A is not correct here because operational productivity impact is a factor in assessing the risk itself, not in evaluating whether the insurance transfer works. Option B is likewise not correct because the likelihood of the threat event is an input to the original risk assessment, not a measure of the transfer's effectiveness.

Exam trap

CRISC often tests the misconception that buying insurance equals eliminating risk — candidates must recognize that deductibles, exclusions, and premium economics determine the actual effectiveness of the transfer, not the mere existence of a policy.

37
MCQmedium

An organization identifies a risk that is within its risk appetite. The risk owner decides to formally document the risk and accept it without implementing additional controls. Which of the following is required for this risk acceptance?

A.Avoidance of the business process
B.Transfer of risk to an insurance provider
C.Formal sign-off by the risk owner
D.Implementation of compensating controls
AnswerC

Risk acceptance requires the risk owner to formally sign off, documenting accountability for the decision to tolerate the risk without added controls. This satisfies the requirement that acceptance be authorised at the appropriate level, since the risk falls within the stated risk appetite.

Why this answer

Acceptance requires formal documentation and sign-off by the risk owner, acknowledging the risk within appetite.

38
Multi-Selectmedium

An organization is assessing control effectiveness for a key process. Which TWO aspects should be evaluated to determine if a control is effective?

Select 2 answers
A.Operating effectiveness
B.Compliance with industry standards
C.Number of control owners
D.Design adequacy
E.Cost of implementation
AnswersA, D

Operating effectiveness verifies the control performs consistently as designed over the review period, through testing evidence such as samples, logs or observations. Combined with design adequacy, it establishes whether the control genuinely mitigates the risk within the key process.

Why this answer

Operating effectiveness (A) is correct because a control must actually function as intended over time—evidenced by testing that it is applied consistently, by the right people, at the right frequency—to confirm it mitigates the risk in practice. Design adequacy (D) is correct because a control must first be properly designed to address the identified risk at the right point in the process; a well-designed control that operates as intended is the basis for concluding effectiveness. Together, design adequacy and operating effectiveness are the two standard dimensions used when assessing control effectiveness (as in ISACA/COBIT and audit frameworks).

Compliance with industry standards (B) is not the criterion for effectiveness—a control can be effective even if it exceeds or differs from a standard, and standards compliance is a separate conformance question. The number of control owners (C) is irrelevant to effectiveness; ownership count says nothing about whether the control mitigates risk. Cost of implementation (E) is a cost-benefit consideration, not a measure of whether the control achieves its objective.

Exam trap

The trap is confusing control effectiveness with control compliance or efficiency; candidates may select 'compliance with industry standards' because it sounds important, but effectiveness is about design and operation, not external benchmarks.

39
MCQhard

A software development company is assessing the risk of a data breach in its cloud-based source code repository. The risk assessment team has identified that the repository contains proprietary algorithms and customer data. The team is considering implementing a control that would encrypt the data at rest. Which of the following BEST describes the impact of this control on the risk?

A.It eliminates the risk of a data breach entirely.
B.It transfers the risk to the cloud provider.
C.It reduces the likelihood of a data breach by making it harder for attackers to access the data.
D.It reduces the impact of a data breach by rendering the data unreadable to unauthorized parties.
AnswerD

Encryption at rest ensures that data stored in the repository is encrypted, so if an attacker gains access, they cannot read the data without the decryption key. This directly reduces the impact of a breach because the confidentiality of the data is preserved. It does not prevent the breach itself, but it mitigates the consequences, such as intellectual property theft or regulatory penalties. This is a classic impact-reducing control.

Why this answer

Encryption at rest is a control that reduces the impact of a data breach by making the data unreadable without the decryption key. It does not reduce the likelihood of an attacker gaining access, nor does it transfer or eliminate the risk. It is an impact-mitigating control that protects confidentiality even if other defenses fail.

This aligns with the principle of defense in depth.

Exam trap

The trap here is assuming that encryption prevents breaches (reduces likelihood) or eliminates risk, when it primarily reduces impact by protecting data confidentiality.

40
MCQmedium

A financial services firm is performing an IT risk assessment on its legacy 3270-based transaction processing system. The system has no vendor support, no documentation, and only two remaining staff members who understand its internals. The risk committee asks the risk analyst to determine the MOST appropriate way to characterize the risk associated with this asset. Which of the following should the analyst do FIRST?

A.Immediately migrate the workload to a modern platform to eliminate the unsupported technology exposure.
B.Quantify the asset's replacement cost and depreciated book value to express risk in monetary terms.
C.Purchase cyber insurance covering business interruption losses from system outages.
D.Identify and document the threats, vulnerabilities, and business impact specific to the legacy environment.
AnswerD

Risk characterization begins with identifying the relevant threats (hardware failure, loss of key personnel), vulnerabilities (no vendor patches, no documentation), and business impact (transaction outages, reconciliation errors). Only after these elements are articulated can the firm assess likelihood and impact and select a treatment. Jumping to quantification or control selection before identification would leave critical exposure drivers unexamined and produce an incomplete risk picture.

Why this answer

Characterizing risk requires first identifying the threats, vulnerabilities, and business impacts associated with the asset, because likelihood and impact assessment depend on those inputs. Legacy platforms with no vendor support and concentrated tribal knowledge present availability and knowledge-loss exposures that must be articulated before any treatment decision. Quantifying value, migrating, or buying insurance are downstream activities that presume the risk has already been understood and documented.

Exam trap

The trap here is treating risk characterization as a financial valuation exercise or jumping straight to a treatment, when the foundational step is identifying threats, vulnerabilities, and business impact.

41
MCQmedium

An organization is evaluating risks and decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk treatment option does this represent?

A.Transfer
B.Accept
C.Mitigate
D.Avoid
AnswerA

Purchasing cyber insurance shifts the financial consequence of a breach to an insurer for a premium, which is risk transfer. This satisfies the stem because the organisation retains the threat but not the loss burden, distinguishing transfer from mitigation, avoidance or acceptance.

Why this answer

Transfer involves shifting risk to a third party, such as through insurance or outsourcing with liability transfer.

42
MCQhard

A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk assessment team has identified that the likelihood of an attack is high due to recent industry trends, and the impact would be severe, including patient safety risks and regulatory fines. The organization has a limited budget and wants to implement controls that provide the greatest risk reduction. Which of the following risk response strategies is MOST appropriate in this scenario?

A.Risk acceptance by documenting the risk and taking no action due to budget constraints.
B.Risk mitigation by implementing layered controls such as regular backups, employee training, and endpoint detection and response.
C.Risk transfer by purchasing cyber insurance to cover all potential losses.
D.Risk avoidance by discontinuing the use of the EHR system.
AnswerB

Risk mitigation reduces the likelihood or impact of a risk through controls. For ransomware, layered controls like offline backups, security awareness training, and endpoint detection can significantly reduce the chance of a successful attack and enable rapid recovery. Given the high likelihood and severe impact, mitigation is the most practical strategy to protect patient safety and meet regulatory requirements without halting essential operations.

Why this answer

Risk mitigation is the most appropriate strategy because it reduces both the likelihood and impact of a ransomware attack through layered controls. Given the criticality of the EHR system and the severe consequences, simply transferring or accepting the risk would leave the organization vulnerable. Avoidance is impractical.

Mitigation aligns with the need to protect patient safety and comply with regulations while operating within budget constraints.

Exam trap

The trap here is assuming that cyber insurance (risk transfer) fully addresses the risk, when it only covers financial losses and does not prevent operational disruption or patient harm.

43
MCQeasy

A risk manager uses a 5x5 heat map to plot the likelihood and impact of identified risks. This approach is an example of which type of risk analysis?

A.Qualitative risk analysis
B.Quantitative risk analysis
C.Hybrid risk analysis
D.Semi-quantitative risk analysis
AnswerA

A 5x5 heat map plots likelihood and impact using ordinal rating scales rather than monetary values, which is the defining mechanism of qualitative risk analysis. It satisfies the scenario's constraint of subjective, expert-driven ranking, unlike quantitative analysis, which requires numerical data such as annualised loss expectancy.

Why this answer

A 5x5 heat map is a qualitative risk analysis technique that uses ordinal scales for likelihood and impact to derive risk ratings.

44
Multi-Selectmedium

A retail company is conducting an IT risk assessment for its point-of-sale (POS) system. The risk team has identified several threats, including malware, insider theft, and denial-of-service (DoS) attacks. The company currently uses antivirus software, firewalls, and role-based access controls. Which TWO of the following are the MOST appropriate risk response actions to address the identified threats? (Choose two.)

Select 2 answers
A.Conduct regular security awareness training for employees handling POS transactions.
B.Outsource POS management to a third-party service provider.
C.Implement network segmentation to isolate the POS system from the corporate network.
D.Increase the backup frequency for POS transaction logs.
E.Purchase cyber insurance to transfer the financial impact of a data breach.
AnswersA, C

Security awareness training helps mitigate insider threats and reduces the likelihood of successful phishing or social engineering attacks, which are common vectors for malware. It is a preventive control that addresses the human factor. For POS systems, training employees on secure practices and threat recognition is essential. This action directly addresses the identified threats, especially insider theft and malware. It complements technical controls.

Why this answer

Network segmentation and security awareness training are the most appropriate risk response actions because they directly mitigate the identified threats. Segmentation reduces the attack surface and limits lateral movement, while training addresses human-related risks like insider theft and phishing. These are preventive controls that reduce likelihood and impact.

The other options either transfer risk without reducing it or focus on recovery rather than addressing the threats themselves.

Exam trap

The trap here is selecting risk transfer or recovery options instead of preventive controls that directly reduce the likelihood or impact of the threats.

45
MCQmedium

A financial services firm is conducting an IT risk assessment on a legacy trading application. The assessment team wants to prioritize risks based on the combination of the likelihood of a threat event and the magnitude of its impact. The firm has limited resources and needs to focus on the most significant risks first. Which of the following BEST describes the purpose of using a risk map (heat map) in this context?

A.To provide a visual representation of risks based on their likelihood and impact, helping to prioritize risk response efforts.
B.To calculate the exact annualized loss expectancy (ALE) for each identified risk.
C.To eliminate the need for a detailed risk assessment by providing a quick overview.
D.To determine the effectiveness of existing controls by comparing inherent and residual risk.
AnswerA

A risk map (heat map) plots risks on a matrix of likelihood and impact, enabling the firm to visually identify which risks fall into high-priority zones. This helps allocate limited resources to the most significant risks first, aligning with the goal of prioritizing risk response. It does not quantify exact losses or replace detailed analysis, but it is a key tool for communicating and prioritizing risk.

Why this answer

A risk map (heat map) is a qualitative tool that plots risks on a matrix of likelihood and impact, enabling the firm to visually identify and prioritize the most significant risks. This is particularly useful when resources are limited, as it helps focus attention on high-priority areas. It does not calculate exact losses, replace detailed assessment, or directly measure control effectiveness, but it supports communication and prioritization.

Exam trap

The trap here is assuming that a risk map provides quantitative precision or replaces the need for detailed risk analysis, when it is actually a qualitative prioritization aid.

46
MCQmedium

An insurance company is assessing the risk of a distributed denial-of-service (DDoS) attack against its customer portal. The risk team estimates that a threat actor group has both the capability and the intent to launch such an attack, and that the portal has an unpatched vulnerability that could be exploited to amplify the attack. Which factor does the unpatched vulnerability PRIMARILY represent in this risk scenario?

A.Impact
B.Threat
C.Risk appetite
D.Vulnerability
AnswerD

This is correct because the unpatched weakness in the portal is a flaw or gap that a threat actor could exploit. In risk assessment, vulnerability represents the internal weakness that, combined with a threat and its potential impact, creates risk. It is the condition that enables the threat actor's capability and intent to translate into a successful DDoS amplification against the customer portal.

Why this answer

In risk assessment, vulnerability is the internal weakness or gap that a threat can exploit. The threat actor group provides capability and intent, while impact describes the resulting harm. The unpatched portal flaw is the vulnerability that enables the DDoS amplification, so it is the factor the risk team should prioritize for remediation.

Exam trap

The trap here is conflating the threat actor's capability and intent with the vulnerability, when the unpatched flaw is the exploitable weakness rather than the threat itself.

47
MCQhard

During a quantitative risk analysis, the risk team calculates the loss event frequency (LEF) using the FAIR framework. If the threat event frequency (TEF) is 10 per year and the vulnerability (V) is 0.3, what is the LEF?

A.10.3 per year
B.30 per year
C.0.3 per year
D.3 per year
AnswerD

In FAIR, loss event frequency derives from threat event frequency multiplied by vulnerability, so 10 × 0.3 yields 3 loss events per year. This satisfies the stem's quantitative requirement, converting ten annual threat events into the subset that actually becomes losses given the 0.3 vulnerability rate.

Why this answer

In the FAIR framework, loss event frequency (LEF) is calculated as the product of threat event frequency (TEF) and vulnerability (V). Given TEF = 10 per year and V = 0.3, LEF = 10 × 0.3 = 3 per year. This represents the expected number of loss events per year, accounting for the probability that a threat event will actually result in a loss.

Exam trap

The trap here is that candidates may confuse the multiplicative relationship in FAIR with additive or divisive operations, or mistakenly treat vulnerability as the final frequency rather than a probability multiplier.

How to eliminate wrong answers

Option A is wrong because 10.3 per year results from incorrectly adding TEF and V (10 + 0.3), but LEF is a multiplicative product, not a sum. Option B is wrong because 30 per year results from dividing TEF by V (10 / 0.3 ≈ 33.3) or multiplying by the reciprocal, which misapplies the FAIR formula. Option C is wrong because 0.3 per year treats V as the LEF itself, ignoring TEF entirely; LEF must incorporate both TEF and V multiplicatively.

48
MCQmedium

A retail company is prioritizing risks for the coming year. Management wants to focus resources where the potential financial loss is greatest, but the risk team has only ordinal likelihood and impact ratings. Which approach BEST supports this prioritization?

A.Ask each department head to vote on which risks feel most urgent.
B.Convert the ordinal ratings into a single composite score by multiplying likelihood rank by impact rank.
C.Rank risks alphabetically by asset name to ensure consistent ordering.
D.Estimate a monetary loss range and annual frequency for each risk, then calculate expected annual loss.
AnswerD

Expected annual loss combines an estimated loss magnitude with an estimated frequency, producing a monetary value that can be compared and summed across risks. Even rough ranges give management a defensible basis for ranking by financial exposure. This directly answers the goal of focusing resources where potential loss is greatest, and it aligns with quantitative risk analysis techniques used in CRISC.

Why this answer

To prioritize by greatest potential financial loss, the team needs a monetary measure. Estimating loss ranges and annual frequencies yields expected annual loss, which can be compared across risks and aggregated. Ordinal multiplication, alphabetical ordering, and subjective voting do not produce a reliable financial ranking, so they cannot guide resource allocation as effectively.

Exam trap

The trap here is believing that multiplying ordinal likelihood and impact ranks creates a valid financial measure, when ordinal scales lack equal intervals.

49
Multi-Selectmedium

A risk assessment team is prioritizing risks for treatment using inherent risk ratings. Which TWO factors should be considered when deciding which risks to treat first?

Select 2 answers
A.The asset's replacement value
B.Cost-benefit analysis of potential controls
C.Risk ranking by inherent risk score
D.The risk owner's department budget
E.The number of controls already in place
AnswersB, C

Cost-benefit analysis weighs each control's implementation expense against the risk reduction it delivers, revealing where treatment gives the greatest return. This satisfies the stem's prioritisation requirement by ensuring resources target risks where mitigation is economically justified rather than merely highest-scoring.

Why this answer

Option B (Cost-benefit analysis of potential controls) is correct because risk treatment decisions must weigh the cost of implementing a control against the expected reduction in loss exposure; a control is only justified when its benefit (risk reduction) exceeds its cost, ensuring resources are allocated efficiently. Option C (Risk ranking by inherent risk score) is correct because inherent risk ratings—likelihood and impact assessed before controls—establish the priority order; risks with the highest inherent scores represent the greatest potential exposure and should generally be treated first. Option A is not a prioritization factor by itself, since replacement value is only one input into impact and does not account for likelihood or existing controls.

Option D is incorrect because a department's budget is an organizational constraint, not a risk-based criterion for prioritization. Option E is incorrect because the number of controls already in place relates to residual risk and control effectiveness, not to ranking inherent risk for treatment priority.

Exam trap

CRISC often tests the confusion between inherent and residual risk — candidates pick 'number of controls already in place' which relates to residual risk, not inherent prioritization.

50
Multi-Selectmedium

A retail company is conducting a risk assessment for its point-of-sale (POS) system. The risk team has identified several factors that could affect the likelihood of a data breach. Which TWO factors are considered threat event frequency components that increase the likelihood of a breach? (Choose two.)

Select 2 answers
A.The strength of the encryption used for payment card data
B.The number of attempted intrusions per month
C.The percentage of POS terminals running outdated software
D.The average time to detect a breach
E.The presence of organized crime groups targeting retail payment systems
AnswersB, E

The number of attempted intrusions per month is a direct measure of threat event frequency. A higher number of attempts increases the likelihood that one will succeed, assuming the vulnerability exists. This is a key input in quantitative risk analysis models like FAIR, where threat event frequency is estimated from historical data or industry trends. It directly affects the probability of a breach.

Why this answer

Threat event frequency is the rate at which threat actors attempt to exploit a vulnerability. The number of attempted intrusions per month directly measures this rate. The presence of organized crime groups targeting retail payment systems indicates a higher frequency of attacks because these groups are actively seeking to compromise POS systems.

The other factors relate to vulnerability, detection, or impact, not the frequency of threat events.

Exam trap

The trap here is confusing vulnerability factors, such as outdated software or encryption strength, with threat event frequency, which is about how often attacks are attempted.

51
MCQeasy

Which of the following best describes residual risk?

A.Risk that is transferred to a third party
B.Risk that is avoided by eliminating the activity
C.Risk without any controls in place
D.Risk after assessing control effectiveness
AnswerD

Residual risk is the exposure that remains after controls have been implemented and their effectiveness assessed. It reflects what is left once mitigation is accounted for, distinguishing it from inherent risk, which exists before any controls are applied.

Why this answer

Residual risk is the risk that remains after management has implemented risk responses and assessed the effectiveness of existing controls. It is calculated by considering the inherent risk (risk without controls) and the risk reduction provided by controls, factoring in control gaps or weaknesses. Option D correctly captures this definition by emphasizing the assessment of control effectiveness.

Exam trap

The trap here is confusing inherent risk (risk with no controls) with residual risk (risk after controls), leading candidates to incorrectly select Option C, especially when the question emphasizes 'risk assessment' without explicitly mentioning control evaluation.

How to eliminate wrong answers

Option A is wrong because transferring risk to a third party (e.g., via insurance or outsourcing) is a risk response strategy, not a measure of remaining risk after controls. Option B is wrong because avoiding risk by eliminating the activity is another risk response (risk avoidance), not the residual risk that persists after controls are applied. Option C is wrong because risk without any controls in place is defined as inherent risk, not residual risk; residual risk explicitly accounts for controls that are in place and their effectiveness.

52
MCQhard

A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk team has identified that the organization performs daily incremental backups and weekly full backups, but the backups are stored on the same network share as the EHR data. The risk owner argues that the backup strategy reduces the impact of a ransomware attack. Which statement BEST describes the residual risk after considering this control?

A.The residual risk is unchanged from the inherent risk because backups are a preventive control.
B.The residual risk is medium because the weekly full backup provides a fallback if incremental backups fail.
C.The residual risk is low because daily backups ensure data can be restored with minimal loss.
D.The residual risk is high because the backups are not isolated and could be encrypted along with the primary data.
AnswerD

Storing backups on the same network share as the primary data means ransomware can encrypt both, eliminating the recovery benefit. The control is not effective in reducing impact. Thus, the residual risk remains high. This is a common pitfall in backup strategies; best practice is to keep offline or immutable backups. The risk practitioner should identify this as a control weakness and recommend remediation.

Why this answer

The backup strategy is ineffective against ransomware because the backups reside on the same network share as the primary EHR data. Ransomware can encrypt both, so the organization may lose both primary and backup data. Therefore, the residual risk remains high.

The risk practitioner should recognize this control weakness and recommend isolating backups, such as using offline or immutable storage. This is a critical aspect of IT risk assessment: evaluating control effectiveness, not just existence.

Exam trap

The trap here is assuming that any backup strategy reduces risk, without considering whether the backups are isolated from the threat.

53
MCQmedium

A risk assessment identifies a high-likelihood, high-impact risk associated with a legacy system. The business owner decides to decommission the system to eliminate the risk. Which risk treatment option is being applied?

A.Mitigate
B.Accept
C.Transfer
D.Avoid
AnswerD

Decommissioning the legacy system removes the risk's source entirely, so no residual likelihood or impact remains. Avoidance is the only treatment that eliminates exposure rather than reducing or transferring it, satisfying the stem's high-likelihood, high-impact constraint.

Why this answer

Avoidance involves eliminating the activity that creates the risk, such as decommissioning a system.

54
MCQeasy

A newly appointed risk owner is reviewing a risk register entry for an aging payroll application. The entry shows a likelihood rating, an impact rating, an inherent risk score, and a residual risk score, but no owner signature or review date. Which action should the risk practitioner take FIRST to strengthen the register's usefulness for IT risk assessment?

A.Confirm the accountable risk owner and establish a review date so the entry has clear ownership and currency.
B.Escalate the entry to the audit committee as an unowned high risk requiring immediate remediation funding.
C.Recompute the inherent and residual scores using a different likelihood and impact scale.
D.Remove the inherent risk score and retain only the residual risk score to simplify reporting.
AnswerA

A risk register entry without an accountable owner or review date cannot support monitoring, treatment decisions, or escalation, because no one is responsible and the data may be stale. Confirming ownership and setting a review cadence is the foundational fix that makes every other register attribute usable. This directly matches the missing fields described in the scenario.

Why this answer

A register entry is only actionable when someone is accountable and the data is kept current. Confirming the risk owner and setting a review date converts a static record into a managed risk with monitoring and escalation paths. Scoring adjustments, escalations, or field deletions do not remedy the underlying governance gap that the scenario describes.

Exam trap

The trap here is treating a missing owner as a documentation nuisance rather than the accountability failure that blocks all downstream risk management.

55
MCQmedium

A risk analyst at a regional bank is assessing the risk to its core banking platform. The analyst finds that the platform has a known vulnerability with a high exploitability score, but the platform is isolated on a segmented network with no external connectivity and strict change control. The analyst must determine the PRIMARY factor that reduces the likelihood of exploitation. Which factor should the analyst emphasize?

A.The bank's risk appetite statement
B.The strict change control process
C.The vulnerability's high exploitability score
D.The network segmentation and lack of external connectivity
AnswerD

Network segmentation and the absence of external connectivity directly reduce the attack surface and limit the pathways an attacker could use to reach the vulnerable platform. Even with a high exploitability score, the likelihood of exploitation drops because the threat actor cannot easily access the asset. This is the primary factor that lowers likelihood in this scenario.

Why this answer

The likelihood of exploitation depends on both the vulnerability's characteristics and the threat actor's ability to reach the asset. Network segmentation and lack of external connectivity create a barrier that prevents or severely limits access, making exploitation unlikely even if the vulnerability is severe. The other factors either increase concern or provide indirect governance benefits but do not directly reduce the likelihood of a successful attack.

Exam trap

The trap here is assuming that a high exploitability score always dominates the risk assessment, ignoring compensating controls like network isolation that directly reduce the likelihood of exploitation.

56
MCQhard

In the FAIR model, 'Loss Event Frequency' is calculated as:

A.Threat Event Frequency × Asset Value
B.Threat Event Frequency × Vulnerability
C.Threat Event Frequency × Loss Magnitude
D.Annualized Rate of Occurrence × Single Loss Expectancy
AnswerB

FAIR derives Loss Event Frequency from how often threat agents act against the asset, multiplied by the probability those actions succeed given existing controls. Vulnerability here is the percentage of threat events that become loss events, not a separate control rating.

Why this answer

In the FAIR model, Loss Event Frequency (LEF) is the product of Threat Event Frequency (TEF) and Vulnerability (Vuln). This represents how often a threat agent successfully exploits a weakness, making option B correct. The formula is LEF = TEF × Vuln, where Vulnerability is the probability that a threat event will result in a loss.

Exam trap

The trap here is that candidates confuse the FAIR model's Loss Event Frequency with the traditional quantitative risk formula ARO × SLE, leading them to select option D, but FAIR separates frequency from magnitude and uses Vulnerability as a probability factor rather than a direct loss value.

How to eliminate wrong answers

Option A is wrong because Asset Value is used in calculating Loss Magnitude, not Loss Event Frequency; multiplying Threat Event Frequency by Asset Value conflates frequency with impact. Option C is wrong because Loss Magnitude is a separate component in the FAIR model used to derive risk, not a factor in Loss Event Frequency; multiplying TEF by Loss Magnitude would incorrectly combine frequency and impact into a single metric. Option D is wrong because Annualized Rate of Occurrence (ARO) × Single Loss Expectancy (SLE) is the formula for Annualized Loss Expectancy (ALE) in quantitative risk analysis, not Loss Event Frequency in FAIR.

57
Multi-Selecthard

An organization is conducting a risk assessment and finds that the inherent risk for a critical asset is very high due to a high threat event frequency and high vulnerability. The current controls are assessed as adequate in design but not operating effectively. Which THREE of the following should be considered when calculating residual risk?

Select 3 answers
A.Inherent risk score
B.Control design adequacy
C.Cost-benefit analysis of controls
D.Control operating effectiveness
E.Risk appetite statement
AnswersA, B, D

Residual risk is based on inherent risk reduced by controls.

Why this answer

Inherent risk score (A) is correct because residual risk is calculated by considering the inherent risk level and the effectiveness of controls in reducing that risk. Since the inherent risk is very high due to high threat frequency and vulnerability, this baseline score must be factored into the residual risk calculation to determine the remaining risk after controls are applied.

Exam trap

The trap here is that candidates often confuse risk appetite (E) as a direct input to residual risk calculation, when it is actually a threshold for evaluating residual risk, not a component of its calculation.

58
MCQmedium

A risk analyst is evaluating a critical customer database. The asset value is $2,000,000; the exposure factor if the database is compromised is 40%. The annualized rate of occurrence (ARO) for a successful breach is estimated at 0.25. What is the annualized loss expectancy (ALE)?

A.$800,000
B.$200,000
C.$2,000,000
D.$500,000
AnswerB

SLE is $2,000,000 × 0.40 = $800,000. ALE = SLE × ARO = $800,000 × 0.25 = $200,000. This represents the expected annual loss from this specific risk before any controls are applied, which is the correct quantitative output for prioritizing the risk against other assessed risks.

Why this answer

ALE is calculated as SLE × ARO. Here SLE = $2,000,000 × 0.40 = $800,000, and ARO = 0.25, so ALE = $800,000 × 0.25 = $200,000. This quantitative metric helps the risk practitioner compare the expected annual loss of this risk against other risks and against the cost of potential controls.

Exam trap

The trap here is confusing SLE with ALE and stopping the calculation before applying the annualized rate of occurrence.

59
MCQmedium

An organization uses the FAIR framework to calculate annualized loss expectancy (ALE) for a specific risk. Given that the single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2, what is the ALE?

A.$250,000
B.$100,000
C.$10,000
D.$50,000
AnswerC

Multiplying SLE by ARO yields the annualised loss expectancy: $50,000 × 0.2 = $10,000. This satisfies the stem's requirement to quantify expected yearly loss for the risk, giving decision-makers the cost baseline needed to compare against control costs during risk response prioritisation.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Given SLE = $50,000 and ARO = 0.2, the ALE is $50,000 × 0.2 = $10,000. This aligns with the FAIR framework's quantitative risk analysis formula.

Exam trap

The trap here is that candidates often confuse the ALE formula with the SLE formula or misplace the decimal point in ARO (0.2 vs. 2.0), leading to inflated values like $100,000 or $250,000.

How to eliminate wrong answers

Option A ($250,000) is wrong because it incorrectly divides SLE by ARO ($50,000 / 0.2) instead of multiplying, a common arithmetic reversal. Option B ($100,000) is wrong because it multiplies SLE by 2 (a misinterpretation of ARO as 2.0) rather than by the correct factor of 0.2. Option D ($50,000) is wrong because it assumes ARO = 1.0, ignoring the given 0.2 frequency and treating the loss as occurring once per year.

60
Multi-Selecthard

A financial services firm is performing an IT risk assessment on a legacy trading platform. The risk team has identified several weaknesses in the platform's patch management process. Which TWO of the following are examples of vulnerabilities that should be recorded in the risk register? (Choose two.)

Select 2 answers
A.The firm's cyber insurance policy excludes losses from unpatched systems.
B.Patch deployment requires manual approval by a single administrator.
C.The trading platform processes approximately 40 percent of the firm's revenue.
D.A hacker collective has publicly announced targeting of trading firms.
E.The platform runs an operating system version no longer supported by the vendor.
AnswersB, E

A manual, single-person approval bottleneck is a process vulnerability because it creates delay, human error, and a single point of failure in patch deployment. This weakness exists in the organization's procedures and can be exploited indirectly by attackers who rely on slow patching windows. Recording it enables the risk team to recommend automation, segregation of duties, and service-level targets for patch cycles.

Why this answer

Vulnerabilities are internal weaknesses in people, processes, or technology that a threat can exploit. An unsupported operating system and a manual single-administrator patch approval process both qualify because they exist inside the environment and degrade the firm's ability to prevent exploitation. The hacker announcement is a threat source, the revenue figure is business criticality, and the insurance exclusion is a risk financing condition, so none belong in the vulnerability field of the register.

Exam trap

The trap here is treating a threat source such as an announced attacker campaign as a vulnerability simply because both appear in the same risk discussion.

61
MCQeasy

A risk manager is using a 5x5 heat map to assess IT risks. Which of the following best describes the primary limitation of this qualitative risk analysis approach?

A.It requires extensive historical data to be accurate.
B.It is time-consuming and complex to implement.
C.It is subjective and not comparable across organizations.
D.It provides objective, financially meaningful results.
AnswerC

A 5x5 heat map relies on ordinal scales whose labels and thresholds each organisation defines differently, so ratings reflect assessor judgement rather than calibrated measurement. This satisfies the stem's focus on the primary limitation: scores cannot be meaningfully benchmarked across organisations, undermining consistent enterprise-wide risk comparison.

Why this answer

A 5x5 heat map is a qualitative technique: likelihood and impact are assigned ordinal ratings (e.g., 1–5) based on expert judgment rather than measured data. Because the scales are defined locally and the ratings are subjective, results are not directly comparable across organizations or even across business units with different risk appetites. This subjectivity is the primary limitation.

Exam trap

The trap is that candidates associate 'risk analysis' with data and rigor, so they pick the answer about needing historical data — but that describes quantitative analysis, while heat maps are deliberately qualitative and subjective.

How to eliminate wrong answers

Option A is wrong because qualitative heat maps explicitly do not require extensive historical data — that is a characteristic of quantitative analysis (e.g., Monte Carlo, FAIR). Option B is wrong because heat maps are valued for being fast and simple to implement; complexity and time consumption are criticisms of quantitative methods, not qualitative ones. Option D is wrong because heat maps produce ordinal, not financially meaningful, results — expressing risk in monetary terms requires quantitative techniques like annualized loss expectancy (ALE).

62
MCQmedium

Which of the following best describes the primary limitation of qualitative risk analysis?

A.It requires extensive historical data
B.It is subjective and not comparable across organizations
C.It cannot produce financial loss estimates
D.It is time-consuming and complex
AnswerB

Subjectivity and lack of comparability are key limitations.

Why this answer

Qualitative risk analysis relies on expert judgment, ordinal scales (e.g., high/medium/low), and subjective ratings rather than numerical data. Its primary limitation is that these ratings are subjective and organization-specific, making them difficult to compare across different organizations or even across teams using different scales. This lack of standardization and comparability is the core weakness.

Exam trap

CRISC often tests the confusion between limitations of qualitative analysis (subjectivity, non-comparability) and characteristics of quantitative analysis (data requirements, complexity, financial estimates).

How to eliminate wrong answers

Option A is wrong because qualitative analysis specifically does not require extensive historical data — that is a characteristic of quantitative analysis, which needs frequency and loss data. Option C is wrong because while qualitative analysis typically does not produce financial loss estimates, that is a characteristic rather than the primary limitation; the deeper issue is subjectivity and non-comparability. Option D is wrong because qualitative analysis is generally faster and simpler than quantitative analysis, not time-consuming and complex — that describes quantitative methods like FAIR or Monte Carlo simulation.

63
Multi-Selecthard

A quantitative risk analysis using FAIR requires estimating which THREE primary factors?

Select 3 answers
A.Risk appetite
B.Vulnerability
C.Loss magnitude
D.Threat event frequency
E.Control cost
AnswersB, C, D

FAIR estimates loss event frequency from threat event frequency and vulnerability, combined with loss magnitude, to quantify risk in monetary terms. Vulnerability is one of the three primary factors, representing the probability a threat event becomes a loss.

Why this answer

In FAIR (Factor Analysis of Information Risk), the primary factors estimated for quantitative risk analysis are threat event frequency (D), vulnerability (B), and loss magnitude (C). Threat event frequency (D) captures how often a threat agent is expected to act against an asset, which drives the likelihood side of the risk equation. Vulnerability (B) is the probability that a threat event becomes a loss event, given the resistance strength of the asset's controls, and it modifies threat event frequency into loss event frequency.

Loss magnitude (C) represents the probable financial impact per loss event, combining primary and secondary loss forms, and it is multiplied by loss event frequency to produce annualized loss exposure. Risk appetite (A) is a governance-level tolerance statement rather than a FAIR-estimated factor, and control cost (E) is an input to cost-benefit analysis of mitigations, not one of the three primary FAIR estimation factors.

Exam trap

CRISC often tests whether candidates can distinguish FAIR's primary estimation factors (threat event frequency, vulnerability, loss magnitude) from contextual elements like risk appetite and control cost.

64
MCQmedium

When prioritizing risk treatment actions, which of the following should be the primary consideration?

A.Ease of implementation
B.Compliance requirements only
C.Risk level and cost-benefit analysis
D.Risk owner preference
AnswerC

Risk level and cost-benefit analysis directly satisfy the prioritisation constraint by ranking treatments against both exposure magnitude and the economics of mitigation. Residual risk reduction per unit of spend determines sequencing, ensuring limited resources target the highest-impact exposures first rather than addressing every identified risk equally.

Why this answer

Risk treatment prioritization should be driven by the level of risk (likelihood and impact) combined with a cost-benefit analysis of the treatment options. This ensures that resources are allocated to the most significant risks where the treatment provides the greatest reduction in risk relative to its cost, aligning with business objectives and risk appetite.

Exam trap

CRISC often tests the misconception that ease of implementation or compliance alone should drive risk treatment prioritization, when the primary consideration is risk level combined with cost-benefit analysis.

How to eliminate wrong answers

Option A is wrong because ease of implementation is a secondary factor — a low-risk issue that is easy to fix should not be prioritized over a high-risk issue that is harder to address. Option B is wrong because compliance requirements are one input but not the sole consideration; focusing only on compliance can leave significant non-regulatory risks untreated. Option D is wrong because risk owner preference is subjective and may not align with organizational risk priorities or cost-benefit outcomes.

65
Multi-Selectmedium

A risk analyst is assessing the impact of a potential ransomware attack. Which THREE categories of business impact should be considered?

Select 3 answers
A.Geographic diversity
B.Operational downtime
C.Financial losses (direct and indirect)
D.Technical complexity
E.Regulatory fines
AnswersB, C, E

Correct; operational impact affects productivity.

Why this answer

Operational downtime (B) is a direct consequence of a ransomware attack, as encryption of critical systems halts business processes, leading to lost productivity and revenue. This category is essential for impact assessment because it quantifies the duration and scope of service disruption, which directly affects operational continuity.

Exam trap

The trap here is confusing risk factors (like technical complexity or geographic diversity) with impact categories, leading candidates to select options that describe the attack's nature or mitigation rather than its direct business consequences.

66
MCQeasy

Which of the following is an example of a detective control in IT risk management?

A.Firewall
B.Data encryption
C.Backup restoration
D.Intrusion Detection System (IDS)
AnswerD

An IDS monitors network traffic and raises alerts on suspicious activity, satisfying the detective control requirement of identifying incidents after they occur. Unlike preventive controls such as firewalls, which block traffic, or corrective controls, it provides visibility and evidence, enabling timely response to potential intrusions.

Why this answer

Detective controls identify risk events after they occur. Intrusion Detection Systems (IDS) monitor network traffic to detect malicious activity.

67
MCQmedium

A risk manager decides to accept a risk because the cost of controls exceeds the potential loss. Which of the following is required for this risk treatment option?

A.Elimination of the business process
B.Transfer of risk via insurance
C.Implementation of compensating controls
D.Formal sign-off by the risk owner
AnswerD

Risk acceptance demands documented accountability, so formal sign-off by the risk owner satisfies the stem's requirement. The owner holds authority over the affected asset and bears residual loss, making their approval the control that legitimises accepting the risk rather than treating it. Without that signature, acceptance is unowned and unenforceable.

Why this answer

When a risk manager decides to accept a risk because the cost of controls exceeds the potential loss, the risk treatment option is risk acceptance. This requires formal acknowledgment and sign-off by the risk owner, who is accountable for the risk and must document the decision, typically in a risk register, to ensure governance and auditability.

Exam trap

The trap here is that candidates confuse risk acceptance with risk mitigation or transfer, assuming that any decision involving cost analysis must lead to controls or insurance, but the question explicitly states the cost of controls exceeds the potential loss, making formal acceptance the correct treatment option.

How to eliminate wrong answers

Option A is wrong because elimination of the business process is a risk avoidance strategy, not acceptance; it would remove the risk entirely by discontinuing the activity, which is a different treatment option. Option B is wrong because transfer of risk via insurance shifts the financial impact to a third party, but the question specifies acceptance due to cost-benefit analysis, not transfer. Option C is wrong because implementation of compensating controls is a risk mitigation strategy that reduces risk to an acceptable level, whereas acceptance involves no additional controls and relies on the existing risk level being tolerated.

68
Multi-Selecteasy

In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?

Select 2 answers
A.Likelihood
B.Impact
C.Risk appetite
D.Cost of mitigation
E.Control effectiveness
AnswersA, B

Likelihood is one of the two axes in a qualitative risk assessment, paired with impact, to derive the overall risk rating. It expresses the probability that a given threat will exploit a vulnerability, directly satisfying the stem's requirement for the elements used to determine that rating.

Why this answer

In a qualitative risk assessment, risk rating is determined by combining the likelihood of a threat occurring with the impact of that threat on business objectives. Likelihood (A) and impact (B) are the two fundamental elements used in a risk matrix to assign a qualitative rating such as high, medium, or low. This approach relies on subjective judgment rather than numerical data, making it suitable for scenarios where precise quantification is not feasible.

Exam trap

The trap here is that candidates often confuse the inputs for inherent risk rating (likelihood and impact) with factors used in residual risk calculation or risk treatment decisions, such as control effectiveness or cost of mitigation.

69
Multi-Selectmedium

A risk practitioner is facilitating a risk assessment workshop for a new cloud-based HR system. The team is identifying threats. Which TWO of the following are examples of threat events that should be considered? (Choose two.)

Select 2 answers
A.An unpatched web server software vulnerability
B.A natural disaster causing a cloud data center outage
C.A malicious insider exfiltrating employee personal data
D.Lack of encryption for data at rest
E.Inadequate security awareness training for employees
AnswersB, C

A natural disaster causing a data center outage is a threat event. It can lead to loss of availability of the HR system. Even though the cloud provider may have controls, the organization should consider this threat as part of its risk assessment, especially for critical systems. It is an external event with potential business impact.

Why this answer

Threat events are occurrences or actions that can cause harm, such as a malicious insider exfiltrating data or a natural disaster causing an outage. Vulnerabilities like unpatched software, lack of encryption, or inadequate training are conditions that threats may exploit. Distinguishing between threats and vulnerabilities is essential for accurate risk scenarios.

Exam trap

The trap here is listing vulnerabilities as threats, which confuses the two and leads to incomplete risk scenarios.

70
MCQmedium

In a qualitative risk assessment, a risk owner argues that the likelihood of a cyberattack is low because the organization has strong perimeter defenses. However, the analyst notes that the impact would be catastrophic. Which limitation of qualitative analysis is most relevant?

A.It relies on subjective judgments
B.It is not comparable across organizations
C.It is time-consuming and data-intensive
D.It does not produce financial values
AnswerA

Qualitative assessment rates likelihood and impact using judgement-based scales rather than measurable frequencies, so the owner's confidence in perimeter defences becomes an unverified subjective input. This subjectivity is the limitation, since no objective data validates the low-likelihood claim despite the catastrophic impact.

Why this answer

Qualitative risk assessment relies on subjective judgments, such as the risk owner's belief that strong perimeter defenses make an attack unlikely, despite the analyst's view that impact would be catastrophic. This subjectivity can lead to inconsistent or biased risk ratings. The scenario highlights how personal opinion can skew likelihood estimates, which is a core limitation of qualitative analysis.

Exam trap

CRISC often tests the limitation of qualitative analysis as subjectivity, but candidates may confuse it with lack of financial values or comparability, which are also limitations but not the most relevant in a scenario about conflicting expert opinions.

How to eliminate wrong answers

Option B is wrong because while qualitative assessments may be hard to compare across organizations, the scenario does not involve cross-organizational comparison. Option C is wrong because qualitative analysis is typically less time-consuming and data-intensive than quantitative analysis. Option D is wrong because although qualitative analysis does not produce financial values, the scenario focuses on subjective likelihood judgment, not the lack of monetary impact.

71
Multi-Selectmedium

An organization is evaluating risk treatment options for a critical vulnerability. Which TWO options would be considered risk mitigation?

Select 2 answers
A.Purchase cyber insurance
B.Accept the risk with formal sign-off
C.Discontinue the vulnerable service
D.Deploy an intrusion prevention system
E.Implement a security patch
AnswersD, E

An intrusion prevention system actively blocks detected malicious traffic inline, reducing the likelihood or impact of exploitation. This lowers residual risk while retaining the vulnerability, which is the defining mechanism of risk mitigation rather than avoidance, transfer or acceptance.

Why this answer

Deploying an intrusion prevention system (IPS) is a risk mitigation measure because it actively monitors and blocks malicious traffic targeting the vulnerability, reducing the likelihood of exploitation. Implementing a security patch directly removes the vulnerability, thereby reducing both the likelihood and impact of a potential attack. Both actions modify the risk by applying technical controls to lower the residual risk level.

Exam trap

The trap here is confusing risk mitigation (reducing likelihood/impact through controls) with risk transfer (insurance), risk acceptance (formal sign-off), or risk avoidance (discontinuing the service), which are distinct treatment options in the CRISC risk response framework.

72
MCQeasy

Which risk treatment option is being used when an organization decides to stop a business activity that creates a high-risk exposure?

A.Avoid
B.Accept
C.Mitigate
D.Transfer
AnswerA

Risk avoidance eliminates the exposure entirely by discontinuing the activity that generates it, rather than transferring, mitigating or accepting the risk. Stopping the business activity removes both the likelihood and impact, which is the defining characteristic of the avoid treatment option.

Why this answer

When an organization stops a business activity that creates high-risk exposure, it is applying the risk avoidance treatment option. This is a deliberate decision to eliminate the risk entirely by discontinuing the associated process, system, or operation, rather than attempting to reduce or transfer the residual risk. In IT risk management, avoidance is often chosen when the cost or impact of mitigation exceeds the benefit of the activity, or when the risk level is intolerable under any control scenario.

Exam trap

The trap here is that candidates often confuse 'avoid' with 'mitigate,' thinking that any action to reduce risk is avoidance, but CRISC specifically tests that avoidance means completely eliminating the risk by discontinuing the activity, not just applying controls to lower it.

How to eliminate wrong answers

Option B (Accept) is wrong because risk acceptance involves acknowledging the risk and its potential impact without taking action to reduce it, which is the opposite of stopping the activity. Option C (Mitigate) is wrong because mitigation involves implementing controls to reduce the likelihood or impact of the risk while continuing the activity, not ceasing it entirely. Option D (Transfer) is wrong because risk transfer shifts the financial burden of the risk to a third party (e.g., via insurance or outsourcing) but does not stop the underlying business activity or eliminate the operational exposure.

73
MCQeasy

An IT risk manager is reviewing the risk register and finds that the same database server appears in three separate risk entries: one for unauthorized access, one for data corruption, and one for denial of service. What is the PRIMARY benefit of structuring the register this way rather than combining all three into a single entry?

A.It reduces the total number of controls that must be implemented.
B.It eliminates the need to reassess the risks during the next assessment cycle.
C.It allows each risk to be assessed and treated based on its distinct threat, vulnerability, and impact.
D.It guarantees that the risk register will align with the organization's risk appetite.
AnswerC

Granular risk entries preserve the unique threat, vulnerability, and impact profile of each scenario. Unauthorized access, data corruption, and denial of service have different causes, likelihoods, and consequences, and they demand different controls. Keeping them separate lets the risk manager assign accurate ratings, target treatment effectively, and track residual risk for each scenario rather than averaging unrelated exposures into a single misleading figure.

Why this answer

Separate risk entries preserve the distinct threat, vulnerability, and impact characteristics of each scenario affecting the database server. This granularity enables accurate likelihood and impact ratings, targeted control selection, and clear ownership. Combining unrelated scenarios into one entry would obscure which threat drives which consequence and would make it difficult to measure whether a specific control reduced the risk it was meant to address.

Exam trap

The trap here is assuming that fewer register entries always mean simpler and better risk management, when granularity actually improves treatment accuracy.

74
MCQmedium

An organization is considering purchasing cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?

A.Accept
B.Transfer
C.Avoid
D.Mitigate
AnswerB

Purchasing cyber insurance shifts the financial consequence of a breach to a third party, which is risk transfer. The organisation retains the risk itself but compensates for losses through the insurer, rather than avoiding, mitigating or accepting it.

Why this answer

Purchasing cyber insurance transfers the financial consequences of a data breach to an insurer in exchange for premiums, which is the definition of risk transfer. The organization retains some residual risk (deductibles, uncovered losses, reputational damage), but the primary treatment mechanism is transfer. This is distinct from mitigation, which reduces likelihood or impact through controls.

Exam trap

CRISC often tests the distinction between transfer and mitigate, so the trap is assuming that buying insurance reduces the likelihood or impact of a breach rather than simply shifting financial consequences to a third party.

How to eliminate wrong answers

Option A is wrong because acceptance means acknowledging the risk and taking no action to reduce or transfer it, whereas buying insurance is an active treatment. Option C is wrong because avoidance means eliminating the activity or asset that creates the risk (e.g., not collecting PII at all), not insuring it. Option D is wrong because mitigation reduces the probability or impact through controls such as patching, encryption, or MFA, whereas insurance does not reduce the likelihood of a breach — it only compensates for financial loss.

75
MCQeasy

An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?

A.Threat Event Frequency
B.Annualized Loss Expectancy
C.Primary Loss
D.Secondary Loss
AnswerA

Loss Event Frequency decomposes into Threat Event Frequency and Vulnerability, so Threat Event Frequency is a direct LEF input. It measures how often threat agents act against the asset, which then combines with vulnerability to yield loss event frequency.

Why this answer

In the FAIR (Factor Analysis of Information Risk) ontology, Loss Event Frequency (LEF) is composed of Threat Event Frequency (TEF) and Vulnerability (the probability that a threat event becomes a loss event). Threat Event Frequency is therefore a direct component of LEF. Annualized Loss Expectancy, Primary Loss, and Secondary Loss belong to the loss magnitude side of the model, not LEF.

Exam trap

CRISC often tests FAIR taxonomy, so the trap is confusing LEF components (Threat Event Frequency, Vulnerability) with Loss Magnitude components (Primary Loss, Secondary Loss) or with derived metrics like ALE.

How to eliminate wrong answers

Option B is wrong because Annualized Loss Expectancy (ALE) is a derived output (ALE = SLE × ARO) and is not a component of FAIR's LEF; it is a separate quantitative risk metric. Option C is wrong because Primary Loss is part of Loss Magnitude (the other half of FAIR), representing direct losses from a loss event. Option D is wrong because Secondary Loss is also part of Loss Magnitude, representing indirect or follow-on losses such as fines, reputation damage, and legal costs.

Page 1 of 3 · 169 questions totalNext →

Ready to test yourself?

Try a timed practice session using only IT Risk Assessment questions.