Courseiva

CCNA Risk Response and Reporting Questions

75 of 176 questions · Page 2/3 · Risk Response and Reporting · Answers revealed

76
MCQeasy

An organization wants to promote a risk-aware culture. Which of the following actions is most effective in encouraging employees to report incidents without fear?

A.Establishing a non-punitive incident reporting policy
B.Conducting annual security awareness training
C.Publishing risk metrics on the intranet
D.Providing incentives for risk identification
AnswerA

A non-punitive reporting policy removes the fear of disciplinary consequences, which is the primary barrier to incident disclosure. By guaranteeing that honest reporters are not blamed, it directly satisfies the stem's constraint of encouraging employees to report incidents without fear, increasing early detection.

Why this answer

A non-punitive incident reporting policy is the most effective action because it directly removes the fear of retaliation or blame, which is the primary psychological barrier to reporting security incidents. By guaranteeing that employees will not face disciplinary action for reporting their own mistakes or observed issues, the organization fosters psychological safety and encourages timely disclosure. This aligns with the CRISC principle that a risk-aware culture requires trust and openness, which cannot be achieved through training or metrics alone if fear persists.

Exam trap

The trap here is that candidates often choose 'Conducting annual security awareness training' because they equate awareness with culture change, but the question specifically targets the barrier of fear, which training alone cannot remove.

How to eliminate wrong answers

Option B is wrong because annual security awareness training, while important for knowledge, does not address the emotional or cultural barrier of fear; employees may still hide incidents if they believe reporting will lead to punishment. Option C is wrong because publishing risk metrics on the intranet is a communication tactic that informs but does not create a safe reporting environment; it may even increase anxiety if metrics highlight failures without a supportive policy. Option D is wrong because providing incentives for risk identification can inadvertently encourage gaming the system or reporting only low-risk items, and it does not eliminate the fear of consequences for reporting one's own errors or serious incidents.

77
Multi-Selectmedium

An organization is designing a vendor risk assessment process for critical vendors. Which THREE of the following should be included in the initial onboarding assessment?

Select 3 answers
A.Security questionnaires
B.Continuous monitoring via shared intelligence platforms
C.Contract compliance review
D.Annual reassessment
E.SOC 2 report review
AnswersA, C, E

Security questionnaires elicit the vendor's control environment, certifications and data-handling practises at onboarding, providing the baseline evidence needed to assess inherent risk before a critical vendor is engaged or granted access to systems and data.

Why this answer

Security questionnaires (A) are a core onboarding artifact because they elicit the vendor's controls, data handling, and security posture directly from the vendor before any data or access is granted. Contract compliance review (C) is essential at onboarding to verify that the agreement contains required security, privacy, breach-notification, and data-return/retention clauses before the relationship begins. SOC 2 report review (E) is appropriate during initial assessment because it provides independent third-party attestation over the vendor's security, availability, confidentiality, or privacy controls under the Trust Services Criteria.

Continuous monitoring via shared intelligence platforms (B) and annual reassessment (D) are ongoing or periodic post-onboarding activities, not initial onboarding assessment steps, so they do not belong in this phase.

Exam trap

The trap here is confusing ongoing monitoring activities (like continuous monitoring or annual reassessments) with the discrete, upfront steps required during the initial vendor onboarding assessment.

78
Multi-Selectmedium

Which TWO methods are commonly used for continuous monitoring of IT controls?

Select 2 answers
A.SIEM rules for automated testing
B.Board risk review
C.Annual control self-assessment
D.Vulnerability scanning
E.Quarterly internal audit
AnswersA, D

SIEM rules continuously correlate log events against defined conditions, automatically testing control effectiveness in near real time. This satisfies the stem's continuous monitoring requirement by detecting anomalies and control failures without waiting for periodic manual review or point-in-time assessment.

Why this answer

SIEM rules for automated testing (A) are correct because SIEM platforms continuously correlate and analyze log and event data against detection rules, providing real-time, automated monitoring of IT controls such as access violations, configuration changes, and policy breaches. Vulnerability scanning (D) is correct because it is run on a recurring, often automated schedule to continuously identify weaknesses in systems and applications, feeding ongoing control-monitoring and remediation processes. Board risk review (B) is not continuous monitoring; it is a periodic governance activity conducted at scheduled intervals.

Annual control self-assessment (C) is a point-in-time, yearly exercise and therefore not continuous. Quarterly internal audit (E) is a periodic assurance activity performed at defined intervals, not real-time or continuous monitoring.

Exam trap

CRISC often tests the distinction between continuous monitoring (automated, real-time) and periodic assessment (manual, scheduled), so candidates may incorrectly select annual or quarterly activities as continuous.

79
Multi-Selectmedium

An organization is implementing a third-party risk management program. Which TWO are essential components of the initial vendor risk assessment process?

Select 2 answers
A.Security questionnaires
B.Contract compliance review
C.Review of SOC 2 Type II report
D.Quarterly vulnerability scans of vendor networks
E.Annual reassessment
AnswersA, C

Security questionnaires elicit each vendor's controls, data handling and compliance posture before onboarding. This standardised evidence supports consistent, comparable risk tiering across the vendor population, which the initial assessment process requires to prioritise due diligence.

Why this answer

Security questionnaires (A) are essential because they elicit the vendor's self-reported controls, data handling practices, and security posture directly from the vendor, forming the foundational data-gathering step of an initial risk assessment. Reviewing a SOC 2 Type II report (C) is also essential because it provides independent auditor attestation that the vendor's controls operated effectively over a period (typically 6–12 months), validating the claims made in questionnaires. Contract compliance review (B) is a legal/procurement activity that occurs around contracting rather than being a core initial risk-assessment component.

Quarterly vulnerability scans of vendor networks (D) are not feasible or appropriate at the initial assessment stage and typically cannot be performed against third-party infrastructure without authorization. Annual reassessment (E) is a recurring post-onboarding activity, not part of the initial vendor risk assessment.

80
MCQmedium

An organization is implementing a control to prevent unauthorized access to its critical database. The control must be designed to block access attempts in real time. Which type of control should be selected?

A.Corrective control
B.Detective control
C.Preventive control
D.Compensating control
AnswerC

Preventive controls block unauthorised access attempts before they succeed, operating in real time at the point of entry. Detective controls only identify breaches after the fact, and corrective controls respond post-incident, so prevention uniquely satisfies the requirement to stop database access attempts as they occur.

Why this answer

A preventive control is designed to block unauthorized access attempts in real time before they reach the critical database. Technologies such as a database firewall or network access control list (ACL) evaluate each request against a policy and drop the packet or terminate the session immediately, preventing the access from occurring. This aligns with the requirement for real-time blocking, which is the defining characteristic of a preventive control.

Exam trap

The trap here is that candidates often confuse detective controls (like monitoring or logging) with preventive controls, mistakenly thinking that detecting an attempt in real time is the same as blocking it, but detection does not stop the action from occurring.

How to eliminate wrong answers

Option A is wrong because a corrective control acts after an incident has occurred (e.g., restoring a database from backup after a breach), not in real time to block access. Option B is wrong because a detective control identifies and logs unauthorized access attempts (e.g., via audit logs or intrusion detection systems) but does not block them in real time. Option D is wrong because a compensating control is an alternative mechanism used when the primary control is not feasible (e.g., using additional monitoring when encryption cannot be applied), but it is not the first choice for real-time blocking and does not inherently block access in real time.

81
MCQmedium

During a vendor risk assessment, a third-party vendor is classified as "critical" because it has access to sensitive customer data. According to the organization's risk appetite, what minimum security requirement should be mandated for this vendor?

A.SOC 2 Type II report
B.General liability insurance certificate
C.Penetration test results from the vendor
D.Self-assessment questionnaire only
AnswerA

A SOC 2 Type II report independently attests that controls over security, availability and confidentiality operated effectively across a review period, giving assurance proportionate to the critical vendor's access to sensitive customer data and satisfying the risk-appetite requirement for validated third-party control evidence.

Why this answer

A SOC 2 Type II report is the minimum security requirement for a critical vendor with access to sensitive customer data because it provides an independent, audited assessment of the vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time. This aligns with the organization's risk appetite by ensuring that the vendor has demonstrated effective controls in place to protect sensitive data, rather than relying on a point-in-time test or self-reported information.

Exam trap

The trap here is that candidates often choose penetration test results (Option C) because they seem technically rigorous, but they fail to recognize that a point-in-time test does not provide the ongoing assurance of control effectiveness required for a critical vendor with access to sensitive customer data.

How to eliminate wrong answers

Option B is wrong because a general liability insurance certificate covers financial losses from incidents like property damage or bodily injury, not the technical security controls required to protect sensitive customer data. Option C is wrong because penetration test results provide only a point-in-time snapshot of vulnerabilities and do not demonstrate ongoing control effectiveness or compliance with security frameworks. Option D is wrong because a self-assessment questionnaire alone is insufficient for a critical vendor, as it relies on unverified self-reported information and lacks independent validation of security controls.

82
MCQmedium

An organization is selecting a control to reduce the risk of unauthorized data exfiltration. The annual loss expectancy (ALE) for this risk is currently $500,000. The proposed control costs $80,000 annually and is expected to reduce the ALE by 60%. What is the net benefit (reduction in risk exposure minus control cost) of implementing this control?

A.$220,000
B.$420,000
C.$300,000
D.$120,000
AnswerA

A 60% reduction on the $500,000 ALE yields $300,000 in avoided loss. Subtracting the $80,000 annual control cost gives a net benefit of $220,000, satisfying the stem's requirement to quantify risk reduction minus control cost.

Why this answer

The current ALE is $500,000. A 60% reduction lowers the ALE by $300,000 (0.60 × $500,000). The net benefit is the reduction in risk exposure ($300,000) minus the annual control cost ($80,000), resulting in $220,000.

This calculation directly measures the residual risk reduction against the cost of the control, a key concept in cost-benefit analysis for risk response.

Exam trap

The trap here is that candidates often forget to subtract the control cost from the risk reduction, mistakenly selecting the reduction amount ($300,000) as the net benefit, or they incorrectly apply the percentage to the wrong base value, such as subtracting the cost from the original ALE.

How to eliminate wrong answers

Option B ($420,000) is wrong because it incorrectly subtracts the control cost from the original ALE ($500,000 - $80,000), ignoring the 60% reduction factor. Option C ($300,000) is wrong because it represents only the reduction in ALE (60% of $500,000) without subtracting the control cost, failing to account for the expense of implementation. Option D ($120,000) is wrong because it mistakenly calculates the net benefit as the control cost ($80,000) subtracted from the remaining ALE after reduction ($200,000), which confuses residual risk with net benefit.

83
MCQeasy

Which of the following is a Key Risk Indicator (KRI) that provides leading indication of increasing vulnerability risk?

A.Control deficiency rate
B.Patch lag metric
C.Mean time to detect (MTTD)
D.Number of security incidents
AnswerB

Patch lag measures elapsed time between patch release and deployment, rising before exploitation occurs, so it leads vulnerability risk rather than reporting it afterwards. This satisfies the KRI requirement for a leading indication, unlike lagging metrics such as confirmed exploit counts.

Why this answer

Patch lag metric is a leading KRI because it measures the time between patch availability and deployment, directly indicating how exposed systems are to known vulnerabilities before exploitation occurs. A growing patch lag signals increasing vulnerability risk before incidents materialize.

Exam trap

CRISC often tests leading versus lagging indicators by offering metrics like incident counts or MTTD that sound risk-related but are actually lagging, tempting candidates to misclassify them as leading KRIs.

How to eliminate wrong answers

Option A is wrong because control deficiency rate is a lagging indicator — it reflects deficiencies already identified, not future vulnerability risk. Option C is wrong because mean time to detect (MTTD) is a detective performance metric that measures response capability after an event, not a leading indicator of increasing vulnerability. Option D is wrong because the number of security incidents is a lagging indicator that counts events that have already occurred, not a forward-looking vulnerability signal.

84
MCQmedium

A company is evaluating the cost-benefit of a new control that reduces the annualized loss expectancy (ALE) from $500,000 to $100,000. The control has an annual cost of $150,000. What is the net benefit of implementing this control?

A.$350,000
B.$250,000
C.$400,000
D.$50,000
AnswerB

The control lowers annualised loss expectancy by $400,000 ($500,000 − $100,000), then subtracts its $150,000 annual cost, giving a net benefit of $250,000. This satisfies the stem's cost-benefit constraint by quantifying residual risk reduction against control expenditure, confirming the investment yields positive value.

Why this answer

The net benefit of implementing a control is calculated as the reduction in Annualized Loss Expectancy (ALE) minus the annual cost of the control. The ALE reduction is $500,000 - $100,000 = $400,000. Subtracting the annual control cost of $150,000 yields a net benefit of $250,000, making option B correct.

Exam trap

The trap here is that candidates often forget to subtract the annual control cost from the ALE reduction, mistakenly selecting the gross reduction ($400,000) as the net benefit, or they incorrectly subtract the residual ALE instead of the control cost.

How to eliminate wrong answers

Option A is wrong because $350,000 represents the ALE reduction ($400,000) minus only the residual ALE ($100,000) instead of the control cost, a common miscalculation. Option C is wrong because $400,000 is the gross reduction in ALE before subtracting the control's annual cost, ignoring the expense side of cost-benefit analysis. Option D is wrong because $50,000 incorrectly subtracts the control cost from the residual ALE ($100,000 - $150,000 = -$50,000) or misapplies the formula, yielding a negative or minimal value that does not reflect the actual net benefit.

85
MCQmedium

A risk practitioner has completed a quantitative risk analysis for a customer-facing payment platform. The analysis shows an inherent annualized loss expectancy (ALE) of $2.4 million. Management wants to fund a tokenization control that reduces the ALE to $600,000, but the control costs $1.9 million per year to operate. Which action should the risk practitioner recommend?

A.Reject the tokenization control because its annual cost exceeds the reduction in ALE, and document the accepted residual risk.
B.Defer the decision indefinitely until the inherent ALE increases enough to justify the control cost.
C.Implement the tokenization control because it reduces the ALE by $1.8 million.
D.Implement the tokenization control and offset the shortfall by reducing the scope of the annual penetration test.
AnswerA

The control costs $1.9 million but only reduces expected loss by $1.8 million, producing a negative net benefit of $100,000 per year. Spending more than the expected loss avoided is not cost-justified, so the practitioner should advise against funding it and ensure the $600,000 residual ALE is formally accepted by the appropriate risk owner with documented rationale.

Why this answer

Cost-benefit analysis compares the control's annual cost against the reduction in expected loss it produces. Here the $1.9 million cost exceeds the $1.8 million ALE reduction, so the control is not economically justified. The correct response is to advise against funding it while ensuring the remaining $600,000 residual risk is explicitly accepted and documented by the accountable risk owner.

Exam trap

The trap here is treating the gross reduction in ALE as the benefit and never subtracting the control's ongoing cost.

86
MCQmedium

An organization is evaluating a new security control that costs $50,000 annually to implement and maintain. The current annualized loss expectancy (ALE) for a related risk is $200,000. The control is expected to reduce the ALE by 85%. Using cost-benefit analysis, what is the net benefit of implementing this control?

A.$120,000
B.$30,000
C.$170,000
D.$150,000
AnswerA

The control reduces the $200,000 ALE by 85%, giving a mitigated ALE of $30,000 and an $170,000 loss reduction. Subtracting the $50,000 annual cost yields a net benefit of $120,000, satisfying the cost-benefit comparison the stem requires.

Why this answer

The reduction in ALE is 85% of $200,000 = $170,000. The annual control cost is $50,000. Net benefit = $170,000 - $50,000 = $120,000.

87
MCQhard

A multinational manufacturer has completed a quantitative risk analysis for a ransomware scenario affecting its primary ERP system. The analysis shows an annualized loss expectancy (ALE) of $2.4 million. A proposed endpoint detection and response (EDR) solution would cost $600,000 annually and is projected to reduce the ALE by 60%. The CFO asks the risk practitioner to justify the investment. Which of the following is the BEST response?

A.The EDR solution should be approved because any control that reduces risk by more than half automatically satisfies the cost-benefit test.
B.The EDR solution delivers a net risk reduction benefit of $840,000 annually, so it should be approved.
C.The EDR solution costs 25% of the ALE, which is within the accepted industry benchmark for control spending.
D.The EDR solution should be rejected because the residual ALE of $960,000 remains above the organization's risk appetite.
AnswerB

A 60% reduction of the $2.4 million ALE equals $1.44 million in avoided loss. Subtracting the $600,000 annual cost yields a net benefit of $840,000, which is positive and therefore economically justified. This quantitative comparison directly answers the CFO's request for justification and supports approval.

Why this answer

The control reduces the $2.4 million ALE by 60%, avoiding $1.44 million in expected annual loss, and costs $600,000 per year. The net benefit of $840,000 is positive, so the investment is economically justified. The other responses either invoke unsupported benchmarks, assume an unstated appetite threshold, or rely on the percentage reduction without considering cost.

Exam trap

The trap here is treating a large percentage risk reduction as sufficient justification without subtracting the control's annual cost from the avoided loss.

88
MCQeasy

An organization's risk register shows that a critical database containing customer records has a high inherent risk rating. Management installs database activity monitoring, enforces encryption at rest, and implements quarterly access reviews. After these actions, the risk is re-rated as medium. Which risk concept does the re-rated medium value BEST represent?

A.Risk appetite
B.Control risk
C.Residual risk
D.Inherent risk
AnswerC

Residual risk is what remains after controls are designed and operating. Installing database activity monitoring, encryption at rest, and quarterly access reviews reduced the likelihood and impact of the identified threat, so the re-rated medium value reflects the remaining exposure. CRISC practitioners use residual risk, not inherent risk, to judge whether the response brings the risk within the organization's stated tolerance.

Why this answer

Residual risk is the exposure that remains after controls are applied, and it is the figure decision makers should compare against tolerance. The database started with a high inherent rating; monitoring, encryption, and periodic access reviews lowered the likelihood and impact, producing a medium residual rating. Reporting residual risk keeps the risk register meaningful and prevents the organization from funding controls for exposure that has already been mitigated.

Exam trap

The trap here is reading a post-control rating as inherent risk or as a statement of risk appetite rather than as residual risk.

89
MCQmedium

A logistics firm relies on a third-party cloud provider to host its shipment tracking system. The provider's latest SOC 2 report includes a qualified opinion noting that access review controls were not operating effectively during part of the audit period. The firm's risk practitioner must determine the appropriate risk response. Which of the following is the MOST appropriate action?

A.Terminate the contract immediately and migrate the shipment tracking system to a different provider.
B.Assess the impact of the access review exception on the firm's data and implement compensating controls while the provider remediates.
C.Request the provider's remediation plan and take no further action until the next annual SOC 2 report is issued.
D.Accept the risk because the provider holds a SOC 2 report, which demonstrates an adequate control environment.
AnswerB

The qualified opinion signals a specific control weakness, so the practitioner should evaluate how that weakness affects the logistics firm's data and systems. Implementing compensating controls, such as additional monitoring or restricting privileged access, reduces exposure while the provider addresses the root cause. This response is proportionate, risk-based, and maintains service continuity while holding the provider accountable.

Why this answer

A qualified SOC 2 opinion identifies a real control failure at the provider, so the firm cannot simply accept the risk or wait a year for the next report. The practitioner should assess how the access review weakness affects the shipment tracking data and deploy compensating controls during remediation. This protects the firm while preserving the vendor relationship and allows for a proportionate, evidence-based response.

Exam trap

The trap here is treating the existence of a SOC 2 report as assurance of effective controls, when a qualified opinion specifically documents a control failure that requires its own risk response.

90
Multi-Selecteasy

An organization wants to promote a risk-aware culture. Which TWO of the following initiatives are most effective for achieving this?

Select 2 answers
A.Conducting regular security awareness training for all employees
B.Establishing a 'tone from the top' that emphasizes risk management
C.Implementing a blame-free incident reporting system
D.Offering financial incentives for risk identification
E.Increasing the IT risk team budget
AnswersA, B

Regular security awareness training reaches all employees, embedding risk recognition into daily decisions and behaviours. This directly builds the shared understanding and accountability a risk-aware culture requires, satisfying the initiative's aim of shifting attitudes organisation-wide rather than relying on isolated controls.

Why this answer

Option A is correct because regular security awareness training for all employees builds the knowledge and vigilance needed for staff to recognize and respond to risks, which is the foundation of a risk-aware culture. Option B is correct because a 'tone from the top' that emphasizes risk management signals leadership commitment, sets expectations, and drives risk-conscious behavior throughout the organization. Option C, while valuable for encouraging reporting, addresses incident handling rather than directly cultivating organization-wide risk awareness.

Option D can motivate specific behavior but risks incentivizing quantity over quality and does not by itself build a sustainable culture. Option E, increasing the IT risk team budget, strengthens resources but does not directly engage employees or shape organizational attitudes toward risk.

Exam trap

The trap here is that candidates often mistake a blame-free reporting system or financial incentives as cultural drivers, but the CRISC exam emphasizes that culture is shaped by leadership example and continuous education, not by reactive or transactional mechanisms.

91
MCQeasy

An e-commerce company discovers that a third-party payment processor suffered a breach exposing customer card data. The processor contract includes a clause requiring the vendor to indemnify the company for breach-related costs. The risk owner updates the register to show that financial loss from this vendor risk is now borne by the processor. Which risk response strategy has been applied?

A.Risk acceptance
B.Risk transfer
C.Risk avoidance
D.Risk mitigation
AnswerB

The indemnification clause shifts the financial consequence of a breach from the e-commerce company to the payment processor, which is the defining characteristic of risk transfer. The underlying risk of a breach still exists and the company still faces reputational harm, but the monetary loss is contractually assigned to another party. Recording this as transfer correctly reflects the response strategy in the register.

Why this answer

An indemnification clause that makes the payment processor bear breach-related costs shifts the financial consequence of the risk to a third party, which is risk transfer. The breach risk itself and reputational exposure remain with the company, but the monetary loss is contractually reassigned. Mitigation, avoidance, and acceptance do not describe a contractual shifting of financial responsibility, so transfer is the correct classification.

Exam trap

The trap here is confusing contractual risk transfer with mitigation, because both involve doing something about the risk; transfer shifts financial consequence while mitigation reduces likelihood or impact.

92
MCQhard

A software company has a risk appetite statement allowing no more than two hours of downtime per quarter for its customer-facing API. During a quarterly review, the risk practitioner discovers that a single unplanned database failover event caused 90 minutes of downtime, and a separate configuration error caused 45 minutes. Both events were resolved, but no root cause analysis was completed for either. Which of the following should the risk practitioner recommend FIRST?

A.Report to the board that the downtime appetite has been breached and await direction on a response.
B.Initiate a root cause analysis for both incidents to determine whether the downtime events share an underlying control weakness.
C.Revise the risk appetite statement to allow three hours of quarterly downtime, reflecting actual operational reality.
D.Recommend immediate investment in a redundant database cluster to prevent future failover downtime.
AnswerB

The organization has already exceeded its stated downtime appetite, and the absence of root cause analysis means the underlying causes remain unknown. Before changing controls or reporting to the board, the practitioner needs to understand whether the two events stem from a common weakness. Root cause analysis provides that evidence and is the logical first step in determining an appropriate risk response.

Why this answer

The downtime exceeded the stated appetite, and the lack of root cause analysis leaves the reason for the breach unknown. The practitioner's first step should be to investigate both incidents and determine whether a shared control weakness exists. Only with that understanding can a proportionate response be selected, reported accurately, or escalated to governance with meaningful options rather than an unexplained breach.

Exam trap

The trap here is jumping to a technical fix or an appetite revision before establishing why the downtime occurred and whether the incidents share a root cause.

93
MCQhard

An organization has a risk culture where employees are hesitant to report security incidents due to fear of blame. Which of the following initiatives would MOST effectively promote a risk-aware culture?

A.Increase the frequency of security awareness training
B.Establish a confidential incident reporting system with a no-blame policy
C.Conduct more frequent audits to detect unreported incidents
D.Discipline employees who fail to report incidents
AnswerB

A confidential reporting channel combined with a no-blame policy removes the fear of reprisal that suppresses incident reporting, directly addressing the cultural barrier described. Employees report near misses and incidents earlier, improving detection and organisational learning.

Why this answer

Establishing a confidential incident reporting system with a no-blame policy directly addresses the root cause — fear of blame — by removing the deterrent to reporting. This creates psychological safety, which is a prerequisite for a healthy risk-aware culture where employees surface issues early.

Exam trap

The trap is choosing a control-based or punitive response (training, audits, discipline) when the scenario describes a cultural problem — CRISC tests whether candidates address root causes rather than symptoms.

How to eliminate wrong answers

Option A is wrong because more frequent training does not address the fear of blame; employees may still withhold incidents despite knowing better. Option C is wrong because more audits are a detective control that may catch unreported incidents but does not encourage voluntary reporting or fix the cultural problem. Option D is wrong because disciplining employees who fail to report increases fear and further suppresses reporting, worsening the culture.

94
MCQmedium

A financial services firm has completed its annual IT risk assessment. The chief risk officer asks the IT risk analyst to classify each identified risk according to the organization's risk taxonomy before any response decisions are made. Which activity should the analyst perform FIRST?

A.Recalculate the annualized loss expectancy for every risk using the latest asset valuation data.
B.Immediately transfer the highest-rated risks to the cyber insurance carrier to cap the firm's exposure.
C.Publish the complete risk register to the board risk committee for formal acceptance of all identified risks.
D.Map each risk to the relevant business process and asset owner, and assign a consistent risk category and owner.
AnswerD

Structuring risks by business process, asset owner, and consistent taxonomy category creates the traceability needed before any response decision. Without this alignment, the CRO cannot compare risks, delegate ownership, or aggregate exposure across the enterprise, so classification and ownership assignment must precede selecting treatments, calculating residual scores, or reporting to the board.

Why this answer

Classification and ownership assignment come first because every downstream activity, including quantification, treatment selection, transfer, and governance reporting, depends on knowing what each risk is, who owns it, and how it maps to business processes. Establishing a consistent taxonomy and accountable owner creates the structure required for aggregation and defensible risk acceptance at the enterprise level.

Exam trap

The trap here is assuming the most visible or financially quantifiable activity, such as insurance transfer or ALE recalculation, must come first when the foundational step is actually structuring and assigning the risk.

95
MCQeasy

A risk analyst has completed a control self-assessment and found that a key preventive control failed testing in two consecutive quarters. The risk owner asks the analyst to update the risk register. Which action BEST reflects an appropriate risk response?

A.Close the finding because the control is preventive and failures are expected to occur occasionally in any environment.
B.Record the control failure, reassess the inherent and residual risk ratings, and initiate a remediation plan with a target date.
C.Increase the residual risk rating to the maximum and immediately report the organization as non-compliant to regulators.
D.Delete the original control from the register and replace it with a new control entry showing a passing test result.
AnswerB

Repeated control failure means the residual risk assumption is no longer valid, so the register must reflect the failure and the risk must be re-rated. Pairing that with a remediation plan and target date converts the finding into an actionable response and gives the risk owner a basis for deciding whether interim compensating controls or acceptance is warranted while remediation proceeds.

Why this answer

A repeat control failure invalidates prior residual risk assumptions, so the correct response is to record the failure, re-rate inherent and residual risk, and launch a dated remediation plan. Closing the finding, maximizing the rating without analysis, or overwriting the record all distort the risk picture and remove the accountability that drives correction.

Exam trap

The trap here is treating a repeated control failure as routine operational noise rather than as evidence that the recorded residual risk is understated.

96
MCQeasy

Which of the following best describes the purpose of a risk heat map in an IT risk report?

A.To list the top risks in order of priority
B.To illustrate the relationship between risks and controls
C.To provide a visual representation of the likelihood and impact of risks
D.To show the cost of controls
AnswerC

A risk heat map plots risks on a matrix whose axes are likelihood and impact, giving stakeholders a visual picture of relative exposure. This graphical representation satisfies the stem's requirement to describe the heat map's purpose in an IT risk report.

Why this answer

A risk heat map is a visual tool that plots risks on a grid using likelihood (probability) on one axis and impact (consequence) on the other, typically with color coding (green/yellow/red) to indicate severity. Its primary purpose is to give decision-makers an at-a-glance view of which risks fall into high, medium, or low severity zones. This visual representation supports prioritization and communication, but the visualization itself — not the ranking — is the defining purpose.

Exam trap

CRISC often tests the distinction between a heat map (visual likelihood/impact representation) and a risk register or prioritized list — candidates confuse the visualization tool with the ranking or control-mapping artifacts.

How to eliminate wrong answers

Option A is wrong because listing risks in priority order is a ranked risk register or prioritized risk list, not a heat map; a heat map may inform prioritization but does not inherently order items. Option B is wrong because mapping risks to controls is the purpose of a control matrix or risk-control mapping, not a heat map. Option D is wrong because showing control costs is a cost-benefit or budget analysis, which is unrelated to the likelihood/impact visualization a heat map provides.

97
Multi-Selecthard

A financial services firm has completed a risk assessment and determined that the residual risk for its online banking platform exceeds the board-approved risk appetite. The CISO must recommend risk response options to the risk committee. Which TWO of the following are appropriate risk response actions? (Choose two.)

Select 2 answers
A.Implement additional compensating controls to reduce the residual risk to within appetite
B.Remove the platform from the risk register so it no longer appears as an exception in committee reporting
C.Transfer a portion of the exposure through a cyber insurance policy and document the retained risk
D.Recalculate the annualized loss expectancy using a lower single loss expectancy to bring the rating within tolerance
E.Accept the residual risk without further action because the platform generates significant revenue
AnswersA, C

Applying additional compensating controls is the risk mitigation response, directly lowering likelihood or impact so residual risk falls back within the approved appetite. Since the committee has already determined the exposure is unacceptable, reducing it through controls is the primary and most defensible action. It also preserves the business capability while bringing exposure into alignment with the tolerance the board has formally set.

Why this answer

When residual risk exceeds appetite, the risk owner must choose from the recognized response set: mitigate, transfer, avoid, or accept with proper authority. Applying compensating controls reduces the exposure, and transferring part of the financial consequence through insurance addresses what remains. Accepting without authority, recalculating assumptions to change the rating, and deleting the risk from the register are not legitimate responses because they alter the record rather than the risk.

Exam trap

The trap here is treating risk acceptance as a default when exposure exceeds appetite, when acceptance above tolerance requires explicit authority the risk owner does not hold.

98
Multi-Selecthard

A risk manager is designing a third-party risk management program. Which THREE factors should be considered when determining the risk tier of a vendor?

Select 3 answers
A.The vendor's physical location
B.The type of data the vendor will access
C.The vendor's annual revenue
D.The vendor's security certifications and audit results
E.The criticality of the service provided
AnswersB, D, E

Data sensitivity drives inherent risk: vendors accessing confidential, personal or regulated data create higher exposure from breach or misuse. This determines the depth of due diligence and contractual controls applied, directly informing the vendor's risk tier.

Why this answer

Option B is correct because the type of data the vendor will access directly determines the potential impact of a breach — vendors handling regulated data such as PII, PHI, or cardholder data (PCI DSS scope) warrant a higher risk tier than those with no data access. Option D is correct because a vendor's security certifications and audit results (e.g., SOC 2 Type II, ISO/IEC 27001, PCI DSS AOC) provide objective evidence of the maturity and effectiveness of its control environment, which is a core input to tiering. Option E is correct because the criticality of the service provided reflects business impact — an outage or compromise of a vendor supporting a critical business process or system causes far greater operational and financial harm than a non-essential service.

Option A does not belong because a vendor's physical location alone is not a primary tiering factor; geography may inform jurisdictional or regulatory considerations but does not by itself indicate risk level. Option C does not belong because annual revenue is a financial size indicator, not a measure of the risk the vendor poses to the organization's data, systems, or operations.

99
MCQeasy

When implementing a new access control system, which activity is essential during the change management process?

A.Updating the system documentation and user manuals
B.Removing all legacy controls
C.Assigning control ownership to external vendors
D.Disabling audit logs to save storage
AnswerA

Updating documentation and user manuals preserves the integrity of the change record, satisfying the change management requirement for controlled, auditable transitions. This ensures users and administrators understand altered access procedures, reducing operational risk from misconfiguration. Documentation updates also provide the evidence trail auditors need to verify that the access control change was authorised, tested and communicated before deployment.

Why this answer

Updating system documentation and user manuals is essential during change management because it ensures that the new access control system is accurately reflected in operational procedures, training materials, and compliance artifacts. Without updated documentation, users and auditors operate on stale information, leading to misconfigurations and audit findings. Documentation is a key change management deliverable that supports knowledge transfer and ongoing control effectiveness.

Exam trap

CRISC often tests the misconception that technical implementation alone completes a change; candidates overlook that documentation updates are a mandatory change management activity for control sustainability and audit readiness.

How to eliminate wrong answers

Option B is wrong because removing all legacy controls before the new system is validated creates a control gap and risks unauthorized access during transition. Option C is wrong because assigning control ownership to external vendors dilutes accountability and is not a standard change management requirement; ownership should remain with the organization. Option D is wrong because disabling audit logs to save storage destroys the evidence trail needed for monitoring and compliance, directly undermining the access control system's effectiveness.

100
MCQmedium

A credit union's risk committee has approved a risk response for its core banking platform: purchase an insurance policy against ransomware losses and keep the current backup process unchanged. Six months later, a ransomware event encrypts production data and the backup restoration takes four days, breaching regulatory reporting deadlines. Which risk response did the risk committee most likely select, and why did it fail to address the operational impact?

A.Risk transfer, because insurance shifted the financial loss but did not reduce the likelihood or duration of the service outage.
B.Risk mitigation, because the insurance policy reduced the likelihood of a ransomware attack.
C.Risk avoidance, because the committee decided not to invest in additional backup controls.
D.Risk acceptance, because the committee acknowledged the residual risk without purchasing insurance.
AnswerA

Insurance is a classic risk transfer mechanism that compensates for financial loss after an event. It does not alter the underlying likelihood or impact of the operational disruption, so restoration time and regulatory deadlines remained exposed. The committee effectively transferred only the monetary consequence, leaving the availability and compliance risks unmitigated, which is why the four-day outage still occurred.

Why this answer

The committee chose a risk transfer response by buying insurance, which addresses only the financial consequence of a ransomware loss. Because backups and recovery capabilities were left unchanged, the operational and regulatory impacts remained fully exposed, and the four-day restoration breached reporting deadlines. Effective risk response selection must consider whether the chosen treatment addresses the specific impact categories the organization cares about, not just the monetary loss.

Exam trap

The trap here is assuming that any purchased control or policy automatically mitigates operational risk, when insurance transfers only financial loss and leaves availability and compliance exposure intact.

101
Multi-Selectmedium

A hospital network is selecting key risk indicators (KRIs) for its electronic health record (EHR) availability risk. The risk committee wants indicators that will provide early warning before an outage affects patient care. Which TWO of the following are the most appropriate KRIs for this purpose? (Choose two.)

Select 2 answers
A.Total number of change requests submitted for the EHR environment during the past quarter
B.Percentage of critical EHR servers whose monitoring alerts were unacknowledged beyond the response threshold
C.Mean time between failures (MTBF) of the EHR application servers over the trailing twelve months
D.Percentage of EHR database replication lag exceeding the defined threshold over the past 24 hours
E.Number of EHR downtime minutes recorded during the previous quarter
AnswersB, D

Unacknowledged critical alerts indicate that the operations team is not responding to emerging failures within the agreed time. This is a leading indicator because it predicts that a real incident may go undetected or untreated long enough to cause downtime. Measuring the percentage beyond threshold gives a normalized, trendable KRI that directly reflects operational readiness to protect EHR availability.

Why this answer

Replication lag exceeding threshold and unacknowledged critical alerts are leading indicators that measure current degradation of resilience and response capability, giving the risk committee time to intervene before patients are affected. Downtime minutes, long-term MTBF, and raw change volume describe past events or activity levels without predictive value for imminent EHR availability risk, so they do not serve as early-warning KRIs.

Exam trap

The trap here is choosing familiar operational metrics such as downtime minutes or change counts, which are lagging or activity-based, instead of forward-looking indicators of degrading resilience.

102
MCQmedium

Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?

A.Percentage of systems with missing critical patches
B.Number of audit findings resolved
C.Number of security incidents this quarter
D.Total cost of security incidents
AnswerA

Missing critical patches measure a condition that precedes and predicts future loss events, making them a leading indicator. Lagging KRIs, by contrast, record incidents already realised, such as breach counts or downtime hours, so they cannot drive preventive action.

Why this answer

A leading Key Risk Indicator (KRI) predicts future risk events by measuring conditions that precede incidents. Missing critical patches on systems directly indicate a higher likelihood of exploitation, making it a leading indicator. In contrast, lagging KRIs like incident counts or costs measure outcomes after the fact.

Exam trap

The trap here is confusing leading indicators (which predict risk) with lagging indicators (which measure past events), leading candidates to pick options like the number of security incidents or audit findings resolved, which are reactive rather than predictive.

How to eliminate wrong answers

Option B is wrong because the number of audit findings resolved is a lagging indicator that measures remediation activity after issues have been identified, not a predictor of future risk. Option C is wrong because the number of security incidents this quarter is a lagging KRI that reports past events, not a leading indicator of impending risk. Option D is wrong because the total cost of security incidents is a lagging financial metric that quantifies damage after incidents occur, offering no forward-looking risk prediction.

103
MCQhard

An organization wants to promote a risk-aware culture. Which initiative is most effective in encouraging employees to report security incidents without fear?

A.Conducting annual security awareness training
B.Implementing a no-blame incident reporting policy
C.Increasing penalties for policy violations
D.Publishing names of employees who caused incidents
AnswerB

A no-blame policy removes fear of punitive consequences, directly addressing the psychological barrier that suppresses incident reporting. This encourages early disclosure, giving the organisation faster visibility of events and strengthening its overall risk-aware culture more effectively than awareness campaigns or mandatory training alone.

Why this answer

A no-blame incident reporting policy removes the fear of punishment for reporting mistakes, which is the single most effective cultural lever for increasing incident disclosure. Research (e.g., from aviation safety and DevOps postmortems) shows that psychological safety drives reporting rates, and reporting is the prerequisite for detecting and responding to incidents. This directly addresses the 'without fear' requirement in the question.

Exam trap

CRISC often tests the distinction between awareness (knowledge) and culture (behavior) — candidates pick training because it sounds proactive, but the question specifically asks about removing fear, which only a no-blame policy achieves.

How to eliminate wrong answers

Option A is wrong because annual awareness training improves knowledge but does not address the fear of retaliation that suppresses reporting. Option C is wrong because increasing penalties for policy violations does the opposite — it raises the perceived cost of reporting and drives incidents underground. Option D is wrong because publishing names of employees who caused incidents is a punitive, shaming practice that destroys psychological safety and guarantees under-reporting.

104
MCQhard

An organization's risk committee is reviewing a consolidated IT risk report before a board meeting. The report shows that a critical payment system has a residual risk rating above tolerance, but the remediation project is not scheduled to complete for nine months due to vendor dependencies. The committee must decide how to report this to the board. Which of the following is the MOST appropriate action?

A.Delay the board report until the remediation project completes so the report shows only risks within tolerance.
B.Recommend that the board formally accept the risk above tolerance until remediation completes, documenting the rationale and interim compensating controls.
C.Report the risk as being addressed by the remediation project and omit the completion timeline to avoid alarming the board.
D.Reclassify the residual risk as inherent risk so the rating falls within the board-approved tolerance threshold.
AnswerB

When residual risk exceeds tolerance and cannot be remediated within the desired timeframe, the governing body must formally accept it with documented rationale. Presenting the timeline, the reason for the delay, and any compensating controls gives the board the information needed to make an informed acceptance decision. This preserves transparency and accountability.

Why this answer

Residual risk above tolerance that cannot be remediated promptly requires formal acceptance by the governing body. The committee should present the timeline, the vendor dependency, and any compensating controls so the board can make an informed decision. Concealing the timeline, relabeling the risk, or delaying the report all deprive the board of information it needs and violate reporting integrity.

Exam trap

The trap here is assuming that an active remediation project removes the need for board involvement, when risk above tolerance still requires formal acceptance until the fix is complete.

105
MCQhard

A risk manager is evaluating the effectiveness of a control that requires dual authorization for high-value transactions. The Key Control Indicator (KCI) for this control is the rate of transactions processed without dual authorization (i.e., exception rate). If the acceptable exception rate is less than 1% and the observed rate is 2.5%, what is the most appropriate immediate action?

A.Investigate the root cause of the exceptions
B.Redesign the control immediately
C.Accept the risk since the rate is still low
D.Increase the acceptable exception rate to 2.5%
AnswerA

The 2.5% exception rate breaches the 1% acceptable threshold, so the control is failing. Root cause investigation identifies why dual authorisation was bypassed before remediation is chosen, ensuring corrective action addresses the actual failure mechanism rather than symptoms.

Why this answer

The observed exception rate of 2.5% exceeds the acceptable threshold of 1%, indicating a control deficiency. The most appropriate immediate action is to investigate the root cause of the exceptions to determine whether the control is failing due to process gaps, user behavior, or system issues. Root cause analysis (RCA) is a foundational step before any remediation, as it prevents premature redesign or unjustified risk acceptance.

Exam trap

The trap here is that candidates may assume a 2.5% exception rate is still 'low' and choose to accept the risk (Option C), but CRISC emphasizes that any deviation from the acceptable threshold requires investigation and remediation, not automatic acceptance.

How to eliminate wrong answers

Option B is wrong because redesigning the control immediately without understanding why the exceptions occur could introduce new risks or waste resources on an ineffective solution; the control may only need tuning or enforcement. Option C is wrong because accepting a risk that exceeds the defined acceptable exception rate violates the risk appetite and policy, and 2.5% is not 'low' when the threshold is 1%. Option D is wrong because increasing the acceptable exception rate to match the observed rate eliminates the control's effectiveness and undermines the purpose of the KCI, which is to detect and reduce unauthorized transactions.

106
Multi-Selectmedium

A security awareness program is being designed to promote a risk-aware culture. Which TWO elements are most critical for the program's success?

Select 2 answers
A.Establishing a risk committee
B.Mandatory annual testing with pass/fail
C.Detailed technical training for all staff
D.Tone from the top
E.Communicating risk in business terms
AnswersD, E

Visible executive sponsorship and consistent leadership messaging establish that risk management matters, shaping employee behaviour across the organisation. Without tone from the top, awareness activities lack credibility and authority, undermining the risk-aware culture the programme is designed to promote.

Why this answer

Option D, 'Tone from the top,' is critical because a risk-aware culture must be visibly championed by senior leadership; when executives model and reinforce risk-conscious behavior, employees perceive security as a genuine organizational priority rather than a compliance formality. Option E, 'Communicating risk in business terms,' is equally essential because awareness messages framed around business impact—such as financial loss, reputational damage, or operational disruption—resonate with staff and drive risk-informed decision-making far better than abstract technical jargon. Together, these two elements establish both the authority and the relevance needed for a sustainable security awareness program.

Option A is not among the marked correct answers because a risk committee is a governance structure that supports risk management but is not itself a critical element of awareness-program success. Option B is not marked correct because mandatory pass/fail testing can create a compliance checkbox mentality rather than fostering genuine risk awareness. Option C is not marked correct because detailed technical training for all staff is unnecessary and impractical; awareness programs should target relevant behaviors, not deep technical expertise.

Exam trap

CRISC often tests the difference between structural elements (committees, training) and cultural drivers (tone from the top, business communication), tricking candidates into selecting process-oriented options.

107
MCQmedium

In the context of ERM integration, IT risk is typically considered a subset of which broader risk category?

A.Strategic risk
B.Financial risk
C.Compliance risk
D.Operational risk
AnswerD

IT risk arises from failures in technology, people and processes supporting service delivery, which is precisely the scope of operational risk. It is therefore treated as a subset of operational risk within ERM, not of strategic, financial or compliance risk categories.

Why this answer

In Enterprise Risk Management (ERM) integration, IT risk is typically categorized as a subset of operational risk because it directly impacts the availability, integrity, and confidentiality of information systems and data, which are core operational assets. Operational risk encompasses failures in internal processes, people, and systems, and IT risk—such as system outages, data breaches, or software defects—falls squarely within this domain. This alignment is reinforced by frameworks like COSO and ISO 31000, which treat technology-related failures as operational risk events.

Exam trap

The trap here is that candidates confuse IT risk with compliance risk (Option C) because many IT failures have regulatory implications (e.g., GDPR breaches), but IT risk is fundamentally about operational continuity, not just legal adherence.

How to eliminate wrong answers

Option A is wrong because strategic risk involves high-level decisions that affect long-term business goals (e.g., market entry or M&A), not the day-to-day technology failures that IT risk addresses. Option B is wrong because financial risk focuses on market fluctuations, credit, and liquidity, whereas IT risk is about system reliability and security, not monetary instruments. Option C is wrong because compliance risk is a subset of operational risk that deals with legal and regulatory adherence, but IT risk is broader, covering non-compliance issues like system performance and availability.

108
MCQmedium

A vendor risk manager is tiering vendors based on the criticality of services and data access. A vendor that processes sensitive customer data for a core business application should be classified as which tier?

A.Critical
B.Low
C.Medium
D.High
AnswerA

Processing sensitive customer data for a core business application combines high data sensitivity with direct operational dependency, the defining criteria for the critical tier. Lower tiers cover vendors with limited data access or non-core services, so this classification satisfies the stem's tiering requirement.

Why this answer

A vendor processing sensitive customer data for a core business application poses the highest potential impact on confidentiality, integrity, and availability. This aligns with the definition of a Critical tier, where failure or breach would cause severe business disruption, regulatory penalties, and reputational damage. The classification is driven by the combination of sensitive data access and the application's essential role in business operations.

Exam trap

The trap here is that candidates may confuse 'High' with 'Critical' because both imply significant risk, but CRISC defines Critical as the highest tier reserved for vendors whose failure would cause catastrophic business impact, often involving sensitive data and core processes simultaneously.

How to eliminate wrong answers

Option B is wrong because a Low tier is reserved for vendors with no access to sensitive data and minimal impact on business operations, which does not apply here. Option C is wrong because a Medium tier typically involves vendors with some data access but not to sensitive customer data, and their services are not core to business continuity. Option D is wrong because a High tier, while indicating significant risk, is often used for vendors with critical services but limited sensitive data access; the presence of both sensitive customer data and a core business application elevates the risk to Critical.

109
MCQhard

During a quarterly risk review, the CISO notes that the number of failed authentication attempts has increased by 300% over the last month. The IT team confirms no changes to authentication systems. This metric is BEST categorized as which of the following?

A.Key Performance Indicator (KPI)
B.Service Level Agreement (SLA) metric
C.Key Risk Indicator (KRI)
D.Key Control Indicator (KCI)
AnswerC

Failed authentication attempts are a measurable metric tracking exposure to credential-based attacks, so the 300% rise signals changing risk likelihood. A KRI quantifies risk exposure and trends, unlike a KPI which measures operational performance, making it the correct categorisation for this authentication anomaly.

Why this answer

A Key Risk Indicator (KRI) is a metric used to signal a change in risk exposure. A 300% increase in failed authentication attempts, with no changes to the authentication system, strongly indicates a potential ongoing brute-force attack or credential stuffing campaign, directly elevating the risk of unauthorized access. This metric is not measuring performance (KPI), contractual service levels (SLA), or the effectiveness of a specific control (KCI), but rather a change in the risk landscape.

Exam trap

The trap here is confusing a KRI with a KPI or KCI because all three are metrics, but a KRI specifically measures changes in risk exposure (like a sudden spike in failed logins), not operational performance or control effectiveness.

How to eliminate wrong answers

Option A is wrong because a Key Performance Indicator (KPI) measures the efficiency or effectiveness of a process or system (e.g., average authentication response time), not a change in risk exposure. Option B is wrong because a Service Level Agreement (SLA) metric is a contractual target for service availability or performance (e.g., 99.9% uptime), not a leading indicator of security risk. Option D is wrong because a Key Control Indicator (KCI) measures the operational health or performance of a specific control (e.g., percentage of accounts with MFA enabled), whereas a spike in failed logins is a direct risk signal, not a control performance metric.

110
MCQmedium

An organization is implementing a new access control system. Which of the following is the MOST important consideration during the implementation phase?

A.Control ownership assignment
B.User training
C.Change management
D.Documentation update
AnswerC

Change management governs how the access control system is transitioned into production, covering impact assessment, testing, approval and rollback. This satisfies the implementation-phase constraint by controlling disruption to live access rights, preventing outages or unauthorised access during cutover.

Why this answer

During the implementation phase of a new access control system, change management is the most critical consideration because it ensures that all changes to the authentication and authorization infrastructure are controlled, tested, and approved before deployment. Without a formal change management process, misconfigurations in protocols like LDAP, RADIUS, or SAML can lead to security gaps or service outages, making it the foundational control for a successful rollout.

Exam trap

The trap here is that candidates often confuse 'most important during implementation' with 'most important overall,' leading them to select user training or documentation, but CRISC emphasizes that uncontrolled changes introduce the highest risk of failure and security incidents during the deployment phase.

How to eliminate wrong answers

Option A is wrong because control ownership assignment is a governance activity that occurs during the design or planning phase, not during implementation; it defines who is accountable for the control after deployment, but does not address the immediate risks of introducing new technology. Option B is wrong because user training, while important for adoption, is a post-implementation or operational activity that does not mitigate the technical risks of misconfiguration or integration failure during the actual deployment of the access control system. Option D is wrong because documentation update is a supporting activity that should occur throughout the lifecycle, but it is not the most critical consideration during implementation; failing to update documentation does not directly cause security incidents or system downtime like a poorly managed change can.

111
MCQmedium

A risk practitioner has completed a risk assessment for a new cloud-based payroll platform. The business owner wants to proceed immediately because the platform will save $200,000 annually. The residual risk exceeds the organization's risk appetite, and no compensating controls are in place. Which action should the risk practitioner recommend FIRST?

A.Escalate the risk to the appropriate risk owner for a formal risk response decision.
B.Accept the risk because the financial benefit outweighs the potential loss.
C.Document the risk in the risk register and take no further action.
D.Implement additional controls immediately and then inform the business owner.
AnswerA

When residual risk exceeds appetite, the practitioner's role is to escalate to the accountable risk owner, who has authority to select avoid, mitigate, transfer, or accept. Escalation preserves governance and ensures the decision is made at the correct level with full visibility of the gap between assessed risk and tolerance, rather than being decided informally by the practitioner or project team.

Why this answer

Residual risk above appetite requires a formal decision by the risk owner, not by the practitioner or the business sponsor. Escalation ensures the accountable party evaluates response options and either approves mitigation, transfers the risk, avoids the initiative, or grants a documented exception. Simply accepting, controlling, or logging the risk would bypass the governance process that defines who may decide.

Exam trap

The trap here is assuming that a strong business case justifies accepting risk that already exceeds the stated risk appetite.

112
MCQhard

An organization notices a spike in failed authentication attempts over the past week. This metric is best classified as which type of risk indicator?

A.Key Control Indicator (KCI)
B.Lagging indicator
C.Key Risk Indicator (KRI)
D.Compliance metric
AnswerC

A Key Risk Indicator tracks measurable trends in risk exposure over time, so a week-long spike in failed authentication attempts fits precisely. Unlike a Key Performance Indicator, which measures operational efficiency, a KRI signals changing likelihood or impact, satisfying the stem's requirement to classify this authentication metric as a risk indicator.

Why this answer

A spike in failed authentication attempts is a direct measure of a risk condition (e.g., brute-force attacks or credential stuffing) that can lead to unauthorized access. This metric is best classified as a Key Risk Indicator (KRI) because it tracks changes in risk exposure over time, enabling proactive risk response. Unlike a KCI, which measures control effectiveness, or a lagging indicator, which reports past incidents, this metric signals an evolving threat in near real-time.

Exam trap

In the CRISC exam, candidates often confuse KRIs and KCIs. The trap here is that failed authentication attempts directly measure risk exposure (KRI) rather than control performance (KCI), even though a control like account lockout might influence the metric.

How to eliminate wrong answers

Option A is wrong because a Key Control Indicator (KCI) measures the performance or effectiveness of a specific control (e.g., percentage of accounts with multi-factor authentication enabled), not the raw frequency of failed authentication attempts. Option B is wrong because a lagging indicator reports outcomes after they have occurred (e.g., number of successful breaches), whereas failed authentication attempts are a leading indicator of potential compromise. Option D is wrong because a compliance metric measures adherence to regulatory or policy requirements (e.g., password complexity rules), not the real-time operational risk of authentication failures.

113
MCQeasy

In a risk-aware culture, which of the following behaviors is MOST encouraged?

A.Focusing only on compliance requirements
B.Assigning blame to individuals for security breaches
C.Hiding minor incidents to maintain performance metrics
D.Reporting security incidents without fear of blame
AnswerD

Blame-free incident reporting encourages staff to surface errors and near-misses promptly. This transparency supplies management with accurate risk data and signals that identifying risk is valued over concealing it, which is the behaviour a risk-aware culture most rewards.

Why this answer

In a risk-aware culture, the primary goal is to encourage transparency and continuous improvement in risk management. Reporting security incidents without fear of blame (Option D) is most encouraged because it enables timely detection, analysis, and remediation of threats, directly supporting the Risk Response and Reporting domain by fostering an environment where incidents are escalated promptly rather than concealed.

Exam trap

The trap here is that candidates may confuse a risk-aware culture with a compliance-driven or blame-oriented culture, mistakenly thinking that strict accountability or adherence to rules is the primary driver, rather than the psychological safety that enables open incident reporting.

How to eliminate wrong answers

Option A is wrong because focusing only on compliance requirements ignores residual risks and emerging threats that are not covered by regulatory checklists, leading to a false sense of security. Option B is wrong because assigning blame to individuals for security breaches discourages reporting and shifts focus from systemic root-cause analysis to punitive measures, which undermines a learning culture. Option C is wrong because hiding minor incidents to maintain performance metrics violates the principle of transparency and can allow small issues to escalate into major breaches, compromising the organization's risk posture.

114
MCQeasy

Which of the following is the primary purpose of a risk heat map in a risk report?

A.To track compliance with regulations
B.To detail remediation plans
C.To prioritize risks based on likelihood and impact
D.To show control performance over time
AnswerC

A risk heat map plots risks on likelihood and impact axes, enabling stakeholders to see which exposures cluster in high-severity zones and therefore warrant attention first. This visual ranking directly supports the report's purpose of prioritising risks for treatment decisions.

Why this answer

A risk heat map visually plots risks on a grid based on their likelihood (probability) and impact (consequence), enabling stakeholders to quickly identify which risks require immediate attention. This prioritization is the primary purpose because it directly supports risk response decisions by highlighting high-priority risks that exceed the organization's risk appetite.

Exam trap

The trap here is that candidates often confuse a risk heat map with a control effectiveness dashboard, mistakenly thinking its purpose is to show control performance over time, when in fact it is solely a prioritization tool based on likelihood and impact.

How to eliminate wrong answers

Option A is wrong because tracking compliance with regulations is a function of compliance dashboards or audit reports, not a risk heat map, which focuses on risk prioritization rather than regulatory adherence. Option B is wrong because detailing remediation plans is the purpose of a risk treatment plan or action tracker, while a heat map only shows the current risk posture without prescribing specific remediation steps. Option D is wrong because showing control performance over time is the role of control effectiveness metrics or trend charts, whereas a heat map provides a static snapshot of risk levels at a point in time, not historical control performance.

115
MCQeasy

Which type of control is primarily designed to prevent an unwanted event from occurring?

A.Corrective control
B.Detective control
C.Directive control
D.Preventive control
AnswerD

Preventive controls intervene on the causal pathway before the unwanted event materialises, stopping it from occurring at all. Detective controls identify events after the fact and corrective controls restore conditions afterwards, so only preventive satisfies the stem's prevention requirement.

Why this answer

A preventive control is designed to stop an unwanted event from occurring in the first place, such as a firewall blocking malicious traffic or a lock preventing unauthorized access. It acts before the event, unlike detective or corrective controls that act after.

Exam trap

CRISC often tests the distinction between preventive and detective controls, with candidates confusing 'detect' with 'prevent' when the question asks about stopping an event before it occurs.

How to eliminate wrong answers

Option A is wrong because corrective controls are implemented after an event to restore systems or mitigate damage, such as backups or incident response. Option B is wrong because detective controls identify and record events after they occur, such as IDS or audit logs, but do not prevent them. Option C is wrong because directive controls provide guidance or instructions to influence behavior, such as policies or procedures, but they do not technically enforce prevention.

116
Multi-Selecthard

An organization is implementing continuous monitoring for its critical systems. Which THREE of the following activities are examples of continuous monitoring? (Select three.)

Select 3 answers
A.Annual internal audit of access controls
B.Weekly vulnerability scanning of all servers
C.Real-time monitoring of firewall logs for anomalies
D.Automated correlation of security events via SIEM
E.Quarterly review of user access rights by managers
AnswersB, C, D

Weekly vulnerability scanning runs on a recurring, automated schedule across all servers, giving ongoing visibility of emerging weaknesses rather than a one-off assessment. This recurring cadence satisfies the continuous monitoring requirement, distinguishing it from periodic point-in-time audits.

Why this answer

Weekly vulnerability scanning of all servers (B) is continuous monitoring because it runs on a recurring, automated schedule that repeatedly detects new weaknesses and configuration drift across the environment. Real-time monitoring of firewall logs for anomalies (C) qualifies because it continuously ingests and inspects traffic events to detect suspicious activity as it occurs. Automated correlation of security events via SIEM (D) is continuous monitoring because the SIEM aggregates and correlates log data from multiple sources in near real time to generate alerts.

In contrast, an annual internal audit of access controls (A) and a quarterly review of user access rights (E) are periodic, point-in-time assessments rather than ongoing automated monitoring activities.

Exam trap

The trap here is that candidates often confuse periodic reviews (like quarterly or annual audits) with continuous monitoring, failing to recognize that continuous monitoring requires frequent, automated, or real-time data collection rather than infrequent manual checks.

117
MCQhard

A key control indicator (KCI) for a critical access control shows a deficiency rate of 12% for the quarter, exceeding the target of 5%. Which of the following should be the risk practitioner's PRIMARY action?

A.Investigate root causes of the high deficiency rate
B.Escalate the deficiency to the board immediately
C.Implement compensating controls to reduce risk
D.Increase the frequency of control testing
AnswerA

A KCI breach signals the control is failing, so the practitioner must first establish why the 12% deficiency rate exceeds the 5% target before selecting remediation. Root-cause investigation is the diagnostic step that determines whether the variance reflects a control design flaw, an execution gap or a measurement error.

Why this answer

The primary action is to investigate root causes because a KCI deficiency rate of 12% against a 5% target indicates a systemic control failure. Without understanding why the access control is failing (e.g., misconfigured role-based access control (RBAC) rules, stale user entitlements, or bypassed multi-factor authentication), any subsequent remediation may be ineffective. Root cause analysis ensures the risk practitioner addresses the underlying issue rather than applying a superficial fix.

Exam trap

The trap here is that candidates often choose 'implement compensating controls' or 'increase testing frequency' because they focus on immediate risk reduction, but the CRISC exam emphasizes that understanding the root cause is the foundational step before any remediation action.

How to eliminate wrong answers

Option B is wrong because escalating a 12% deficiency rate directly to the board without first performing root cause analysis bypasses the risk management process; the board requires actionable insights, not raw metrics. Option C is wrong because implementing compensating controls before understanding the root cause may introduce unnecessary complexity and cost, and could mask the real problem rather than solve it. Option D is wrong because increasing the frequency of control testing only provides more data points on the same failing control; it does not reduce the deficiency rate or address why the control is underperforming.

118
MCQmedium

The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?

A.$400,000
B.$250,000
C.$150,000
D.$350,000
AnswerB

The control lowers annualised loss expectancy by $400,000 ($500,000 − $100,000), then deducts the $150,000 annual cost, giving a net benefit of $250,000. This directly satisfies the stem's cost-effectiveness constraint by quantifying residual risk reduction against control expenditure.

Why this answer

The net benefit of a control is calculated as the reduction in Annualized Loss Expectancy (ALE) minus the annual cost of the control. The ALE reduction is $500,000 - $100,000 = $400,000. Subtracting the $150,000 annual control cost gives a net benefit of $250,000.

Exam trap

CRISC often tests whether candidates confuse the gross risk reduction (ALE before minus ALE after) with the net benefit, which requires subtracting the control's annual cost.

How to eliminate wrong answers

Option A is wrong because $400,000 represents only the gross ALE reduction before subtracting the control's annual cost. Option C is wrong because $150,000 is simply the annual cost of the control, not the net benefit. Option D is wrong because $350,000 does not correspond to any valid calculation from the given figures (it appears to be a miscalculation such as subtracting only part of the cost).

119
Multi-Selectmedium

Which THREE of the following are components of an effective IT risk reporting structure for a large enterprise? (Select THREE)

Select 3 answers
A.Strategic risk reporting to the board on a semi-annual basis
B.Tactical risk reporting to the CISO on a quarterly basis
C.Annual risk reporting to IT operational staff
D.Daily risk reporting to the board
E.Operational risk reporting to IT management on a weekly basis
AnswersA, B, E

Board-level strategic risk reporting on a semi-annual cadence matches the governance oversight layer of a large enterprise, giving directors aggregated, forward-looking risk exposure without operational noise. This satisfies the stem's requirement for a reporting structure spanning strategic, tactical and operational tiers.

Why this answer

Option A is correct because strategic risk reporting to the board on a semi-annual basis aligns with the board's governance and oversight role, giving directors a periodic, high-level view of enterprise risk posture without overwhelming them with operational detail. Option B is correct because tactical risk reporting to the CISO on a quarterly basis matches the CISO's responsibility for managing the information security risk program and provides a cadence suitable for tracking risk treatment progress and emerging threats. Option E is correct because operational risk reporting to IT management on a weekly basis supports timely decision-making on day-to-day control failures, incidents, and remediation activities that require rapid attention.

Option C is not appropriate because annual reporting to IT operational staff is too infrequent for the operational level, where risks change quickly and require continuous awareness. Option D is not appropriate because daily risk reporting to the board is excessive and misaligned with the board's strategic oversight role, which relies on summarized, periodic reporting rather than daily operational data.

Exam trap

The trap here is that candidates confuse the frequency and audience for risk reporting, assuming that more frequent reporting to higher levels is always better, when in fact the board needs less frequent, strategic summaries and operational staff need more frequent, detailed updates.

120
Multi-Selecthard

A company's IT risk manager is evaluating Key Risk Indicators (KRIs) for the cybersecurity function. Which TWO of the following are valid examples of leading KRIs?

Select 2 answers
A.System downtime due to security incidents
B.Patch lag metric for critical systems
C.Failed authentication spike detection
D.Number of audit findings related to access controls
E.Number of successful cyber attacks in the past quarter
AnswersB, C

Patch lag measures the interval between vulnerability disclosure and remediation, quantifying exposure before exploitation occurs. It satisfies the stem's leading requirement by predicting future breach likelihood rather than reporting past incidents, and targets critical systems where unpatched flaws most directly elevate residual risk.

Why this answer

Option B (Patch lag metric for critical systems) is a valid leading KRI because it measures the time between patch release and deployment, a predictive indicator of exposure to known vulnerabilities before an incident occurs. Option C (Failed authentication spike detection) is also a leading KRI because a sudden increase in failed logins can signal credential-stuffing, brute-force, or password-spraying attempts, providing an early warning of an imminent compromise. In contrast, Option A (System downtime due to security incidents) is a lagging indicator, as it records impact after an incident has already happened.

Option D (Number of audit findings related to access controls) is a lagging compliance metric reflecting past control weaknesses rather than forward-looking risk. Option E (Number of successful cyber attacks in the past quarter) is likewise lagging, since it counts breaches that have already succeeded.

Exam trap

The trap here is confusing lagging indicators (which measure past events like downtime or audit findings) with leading indicators (which predict future risk), leading candidates to select outcome-based metrics like successful attacks instead of proactive measures like patch lag.

121
MCQmedium

An organization's risk report shows a risk heat map with several risks in the high-likelihood, high-impact quadrant. What is the most appropriate action for the risk owner?

A.Report to the board without any analysis
B.Ignore the risks as they are inherent
C.Accept the risk without further action
D.Evaluate current controls and consider additional treatment
AnswerD

High-likelihood, high-impact risks sit above appetite, so the owner must assess whether existing controls actually reduce exposure, then decide on additional treatment such as mitigation, transfer or avoidance. Inaction leaves the residual risk unmanaged, breaching the stem's heat-map escalation.

Why this answer

Risks in the high-likelihood, high-impact quadrant exceed the organization's risk appetite and require active treatment. The risk owner should first evaluate the effectiveness of existing controls, then consider additional treatment options (mitigate, transfer, avoid, or accept with justification). Simply accepting or ignoring high-exposure risks is not defensible risk management.

Exam trap

CRISC often tests risk response discipline — candidates pick 'accept' or 'report' because they sound decisive, but high-high risks require control evaluation and treatment consideration, not passive acceptance.

How to eliminate wrong answers

Option A is wrong because reporting to the board without analysis provides no decision support and abdicates the risk owner's responsibility. Option B is wrong because 'inherent risk' does not mean unmanageable; inherent risk is the exposure before controls, and the owner must assess residual risk. Option C is wrong because accepting a high-likelihood, high-impact risk without further action is only valid if it is within appetite and formally documented, which is unlikely in this quadrant.

122
MCQhard

A risk practitioner is preparing a quarterly report for the board risk committee. Senior management wants the report to show that IT risk is being managed within appetite, but the practitioner discovers that two critical control failures were identified three weeks ago and remediation is only 40 percent complete. Which approach best satisfies the practitioner's reporting obligation?

A.Report the failures with their current remediation status, the residual risk exposure, and an expected completion date.
B.Report only that remediation is 40 percent complete, without describing the underlying failures or their impact.
C.Exclude the failures from the report because remediation is already underway and the exposure is temporary.
D.Report the control failures only after remediation is complete so the committee receives final, accurate information.
AnswerA

Transparent reporting of material control failures, current remediation progress, residual exposure, and a target date gives the committee the information it needs to judge whether risk remains within appetite. This preserves the integrity of risk reporting and allows governance bodies to direct resources or escalate. It also creates an auditable record that the issue was known and actively managed rather than concealed.

Why this answer

Risk reporting must give governance bodies a timely, accurate view of material exposures and the status of treatment. Disclosing the control failures along with remediation progress, residual risk, and an expected completion date lets the risk committee judge appetite alignment and direct action. Suppressing or diluting the information misstates the control environment and undermines oversight.

Exam trap

The trap here is equating incomplete remediation with immaturity of the issue, and therefore concluding it is too early to report.

123
MCQeasy

An organization is implementing a new access control system to prevent unauthorized access to sensitive data. Which type of control is being implemented?

A.Detective control
B.Compensating control
C.Preventive control
D.Corrective control
AnswerC

A preventive control stops unauthorised access attempts before they succeed, which matches the stated objective of preventing access to sensitive data. Unlike detective or corrective controls, it acts on the cause at the point of entry rather than identifying or remediating after the event.

Why this answer

An access control system that prevents unauthorized access to sensitive data is a preventive control because it enforces security policies before access is granted. Technologies like mandatory access control (MAC) or role-based access control (RBAC) with Access Control Lists (ACLs) block unauthorized users at the point of entry, reducing the risk of data exposure.

Exam trap

The trap here is that candidates confuse preventive controls with detective controls because both involve monitoring, but preventive controls actively block access (e.g., firewall deny rules) while detective controls only log or alert after the fact.

How to eliminate wrong answers

Option A is wrong because detective controls, such as audit logs or intrusion detection systems, identify unauthorized access after it has occurred, not prevent it. Option B is wrong because compensating controls are alternative measures used when primary controls are not feasible, such as additional monitoring for legacy systems, not the primary access control system itself. Option D is wrong because corrective controls, like data restoration from backups or revoking compromised credentials, address damage after an incident, not prevent initial unauthorized access.

124
Multi-Selectmedium

A risk practitioner is evaluating the effectiveness of a security awareness program. Which TWO indicators would BEST measure whether the program is positively influencing risk culture? (Select TWO)

Select 2 answers
A.Time spent on training per employee
B.Number of security policies updated
C.Increase in reported phishing attempts by employees
D.Number of employees who completed training
E.Decrease in incidents caused by human error
AnswersC, E

Rising employee reports of phishing demonstrate proactive detection behaviour rather than passive compliance, directly evidencing a culture where staff treat security as their responsibility. This satisfies the stem's requirement for an indicator that the programme positively influences risk culture, since reporting suspicious emails reflects engagement and psychological safety rather than mere training completion.

Why this answer

Option C is correct because a rise in reported phishing attempts demonstrates that employees are actively recognizing and reporting suspicious emails, which reflects heightened security awareness and a stronger risk culture rather than a failure. Option E is correct because a reduction in incidents caused by human error directly shows that employee behavior has changed in a way that lowers organizational risk, which is the ultimate goal of a security awareness program. Options A and D are activity or completion metrics that only show participation, not whether awareness or behavior actually improved.

Option B measures policy maintenance work, not the workforce's risk culture or the program's influence on employee behavior.

Exam trap

The trap here is confusing activity-based metrics (time spent, completion rates) with outcome-based metrics (behavior change, incident reduction), which is a common CRISC pitfall when evaluating program effectiveness.

125
Multi-Selecthard

A multinational bank must report technology risk to its board risk committee each quarter. The committee has asked the risk team to strengthen the reporting so it drives decisions rather than just describing activity. Which TWO of the following changes would BEST achieve that objective? (Choose two.)

Select 2 answers
A.Include a longer narrative describing every control test performed during the quarter.
B.Add trend analysis showing how key risk indicators have moved against their thresholds over several reporting periods.
C.Delegate the entire board report to the IT operations manager to reduce preparation time.
D.Report each key risk indicator against its defined appetite and tolerance with clear breach status.
E.Increase the number of metrics reported from twenty to sixty to provide more coverage.
AnswersB, D

Trend analysis converts point-in-time metrics into a directional picture, letting the committee see whether exposure is improving or deteriorating relative to thresholds. That context supports decisions about resource allocation and escalation because members can judge whether current controls are working. Without trends, each report is an isolated snapshot and the committee cannot tell whether prior interventions produced results.

Why this answer

Reporting that drives decisions must connect metrics to the limits leadership approved and show direction over time. Trend analysis against thresholds and breach status against appetite both give the committee a basis to act, such as approving remediation funding or accepting a documented exception. Expanded narratives, more metrics, or delegated authorship add volume or shift perspective without improving the committee's ability to decide.

Exam trap

The trap here is equating more data and longer narratives with better risk reporting for a board committee.

126
MCQmedium

A risk practitioner is performing a cost-benefit analysis for a proposed control. The annualized loss expectancy (ALE) for a risk is currently $500,000. The proposed control will reduce the ALE by 80%, and the annual cost of the control is $150,000. What is the net benefit of implementing the control?

A.$100,000
B.$250,000
C.$400,000
D.$350,000
AnswerB

Reducing the $500,000 ALE by 80% yields an annualized loss expectancy of $100,000, a $400,000 risk reduction. Subtracting the control's $150,000 annual cost gives a net benefit of $250,000, satisfying the stem's cost-benefit requirement. This figure represents the residual value after control costs.

Why this answer

The control reduces the ALE by 80%, so the risk reduction benefit is 0.80 × $500,000 = $400,000. The net benefit is the benefit minus the control cost: $400,000 − $150,000 = $250,000. This represents the expected annual savings after implementing the control.

Exam trap

The trap is forgetting to subtract the control's annual cost from the risk reduction benefit, or incorrectly subtracting the cost from the residual ALE instead of the benefit.

How to eliminate wrong answers

Option A ($100,000) is wrong because it incorrectly subtracts the control cost from the remaining ALE ($100,000) rather than from the risk reduction benefit. Option C ($400,000) is wrong because it represents the gross benefit (80% of ALE) without subtracting the $150,000 control cost. Option D ($350,000) is wrong because it likely results from miscalculating the reduction (e.g., using 70% instead of 80%) or subtracting the wrong amount.

127
MCQhard

An organization uses a SIEM to automatically test access control rules on a continuous basis. This is an example of which type of monitoring?

A.Continuous monitoring
B.Key Risk Indicator monitoring
C.Vulnerability scanning
D.Periodic control testing
AnswerA

Automated SIEM rules testing access control rules on a continuous basis constitute continuous monitoring: control assessment occurs in real time or near real time rather than at discrete intervals, so deviations are detected as they arise instead of during periodic point-in-time reviews.

Why this answer

A SIEM that automatically tests access control rules on a continuous basis performs ongoing validation of rule effectiveness and compliance. This is a classic example of continuous monitoring, where security controls are assessed in real-time or near-real-time without manual intervention, ensuring that access policies remain effective against evolving threats.

Exam trap

The trap here is confusing continuous monitoring with periodic control testing. Many candidates incorrectly assume that automated testing must be a scheduled vulnerability scan, but the key differentiator is the 'continuous' nature versus scheduled intervals. In the context of CRISC, continuous monitoring is a risk response strategy that provides real-time assurance over controls.

How to eliminate wrong answers

Option B is wrong because Key Risk Indicator (KRI) monitoring focuses on tracking specific risk metrics (e.g., number of failed logins) rather than directly testing the functionality of access control rules. Option C is wrong because vulnerability scanning identifies known software vulnerabilities (e.g., missing patches) in systems, not the correctness or enforcement of access control rules. Option D is wrong because periodic control testing occurs at scheduled intervals (e.g., quarterly audits), whereas the scenario explicitly states 'continuous basis', which implies ongoing, automated validation rather than discrete, scheduled tests.

128
MCQeasy

Which control implementation activity involves updating system configurations and user access rights when a new security tool is deployed?

A.User training
B.Project management
C.Documentation update
D.Change management
AnswerD

Change management governs configuration baselines and access rights whenever a new tool alters the environment, ensuring updates are authorised, tested and documented. It directly satisfies the stem's requirement to control system configuration and user access changes during deployment, preventing unauthorised or untested modifications.

Why this answer

Deploying a new security tool requires updating system configurations and user access rights, which directly impacts the operational environment. Change management (Option D) is the formal process that governs these modifications to ensure they are authorized, tested, and documented, minimizing risk of disruption or security gaps. This aligns with the CRISC domain of Risk Response and Reporting, where controlled changes are a key risk mitigation activity.

Exam trap

The trap here is that candidates may confuse 'change management' with 'project management' because both involve planning and coordination, but change management specifically governs the technical alterations to configurations and access rights, whereas project management handles the broader initiative's logistics.

How to eliminate wrong answers

Option A is wrong because user training focuses on educating personnel on how to use the new tool, not on updating system configurations or access rights. Option B is wrong because project management oversees the overall deployment timeline, budget, and resources, but does not directly handle the technical updates to configurations and access controls. Option C is wrong because documentation update records the changes after they are made, but it is not the activity that performs the actual configuration and access right updates.

129
MCQeasy

An organization has implemented a new firewall rule to block malicious IP addresses. This is an example of which type of control?

A.Directive control
B.Preventive control
C.Corrective control
D.Detective control
AnswerB

Blocking malicious IP addresses stops the traffic before it reaches the target, so the control acts on the threat event itself rather than detecting it afterwards or repairing damage. Prevention is the defining characteristic, distinguishing it from detective controls such as logging and corrective controls such as restoration.

Why this answer

A firewall rule that blocks malicious IP addresses is a preventive control because it proactively stops unauthorized traffic before it can reach the internal network. By filtering packets based on source IP addresses, the firewall enforces access control policies at the network layer, preventing potential attacks from ever being initiated. This aligns with the CRISC definition of preventive controls, which are designed to avoid or deter undesirable events.

Exam trap

The trap here is confusing preventive controls with detective controls, as candidates often think of firewalls as 'detecting' threats, but the key distinction is that a firewall rule actively blocks (prevents) traffic, not merely logs or alerts on it.

How to eliminate wrong answers

Option A is wrong because directive controls are policies, procedures, or guidelines that define acceptable behavior (e.g., an acceptable use policy), not technical mechanisms that block traffic. Option C is wrong because corrective controls are applied after an incident to restore operations (e.g., restoring from backup after a ransomware attack), not to block threats in real time. Option D is wrong because detective controls identify and log malicious activity after it has occurred (e.g., intrusion detection system alerts), whereas a firewall rule actively prevents the traffic from entering.

130
MCQmedium

An organization’s continuous monitoring program includes automated vulnerability scanning and log review. Which of the following is a Key Risk Indicator (KRI) that would BEST signal an increasing risk of a successful network breach?

A.Average time to patch critical vulnerabilities
B.Spike in failed authentication attempts from external IPs
C.Number of firewall rule changes per month
D.Percentage of systems with up-to-date antivirus signatures
AnswerB

Failed external authentication attempts are a leading indicator: they rise before a breach succeeds, revealing active credential-guessing or brute-force activity against exposed services. Unlike lagging measures such as confirmed incidents, this spike gives continuous monitoring data that signals escalating likelihood, directly satisfying the KRI requirement for early warning.

Why this answer

A Key Risk Indicator (KRI) is a forward-looking metric that signals changes in risk exposure. A spike in failed authentication attempts from external IPs is a leading indicator of attempted unauthorized access — such as brute-force or credential-stuffing attacks — and directly signals increasing likelihood of a successful network breach. It is actionable and tied to a specific threat vector.

Exam trap

CRISC often tests the distinction between KRIs (leading, risk-signaling metrics) and KPIs (performance/coverage metrics) — candidates frequently pick control-effectiveness metrics like patch time or AV coverage instead of threat-activity indicators.

How to eliminate wrong answers

Option A is wrong because average time to patch critical vulnerabilities is more of a Key Performance Indicator (KPI) for patch management effectiveness — it measures process efficiency, not directly an increasing breach risk signal. Option C is wrong because the number of firewall rule changes per month measures change activity; while excessive changes can introduce risk, the metric alone does not signal an active or increasing breach threat. Option D is wrong because percentage of systems with up-to-date antivirus signatures is a compliance/coverage KPI — high coverage is good, but it does not indicate an increasing risk of breach; it measures control effectiveness, not threat activity.

131
MCQhard

During a control implementation project, the risk manager discovers that the resource requirements have increased significantly, making the original cost-benefit analysis invalid. What should the risk manager do first?

A.Continue the project and request additional budget later
B.Escalate to the board for approval of additional funds
C.Cancel the project immediately
D.Perform a revised cost-benefit analysis
AnswerD

Revised resource requirements invalidate the original cost-benefit analysis, so recalculating costs against expected benefits restores the basis for a go/no-go decision. Performing this revised analysis first gives management accurate figures before any scope, budget or approval changes are considered.

Why this answer

When resource requirements change enough to invalidate the original cost-benefit analysis, the risk manager's first step is to perform a revised cost-benefit analysis to reassess whether the control is still justified relative to the risk it mitigates. This provides the objective data needed before any decision to continue, escalate, or cancel. CRISC emphasizes that risk decisions must be based on current, accurate information rather than assumptions.

Exam trap

CRISC often tests the instinct to escalate or cancel when costs change — the correct first step is always to gather updated information (revised cost-benefit analysis) before making a governance decision.

How to eliminate wrong answers

Option A is wrong because continuing the project and requesting budget later bypasses governance and commits resources without validating whether the control still provides value relative to its new cost. Option B is wrong because escalating to the board for additional funds is premature — the board needs a revised cost-benefit analysis to make an informed decision, and escalation without that analysis violates the risk management process. Option C is wrong because cancelling immediately is an overreaction; the revised analysis may show the control is still cost-effective, and cancellation without analysis ignores the risk exposure the control was meant to address.

132
Multi-Selectmedium

A healthcare provider has experienced repeated phishing incidents that led to credential compromise. The risk committee has approved a new email security control that will quarantine suspicious messages and enforce multifactor authentication. Which TWO activities are essential to validate that the control is operating effectively after implementation? (Choose two.)

Select 2 answers
A.Review the vendor's marketing materials and SOC 2 report to confirm the product supports quarantine and MFA features.
B.Conduct periodic control testing by simulating phishing campaigns and reviewing whether messages are quarantined and MFA is enforced.
C.Confirm that the project to implement the control was completed within the approved budget and schedule.
D.Ask employees to sign an acknowledgment that they have read the updated acceptable use policy.
E.Collect and analyze control performance metrics, such as the percentage of suspicious emails quarantined and MFA challenge success rates, and report exceptions.
AnswersB, E

Simulated phishing campaigns and verification of MFA enforcement directly test whether the new control performs as designed against realistic attack patterns. This produces evidence about control effectiveness rather than assuming implementation equals effectiveness. Periodic testing also reveals configuration drift and user bypass behaviors, allowing the risk committee to confirm that the approved risk response is actually reducing the phishing exposure.

Why this answer

Validation of a control requires evidence that it operates as intended in the production environment. Simulated phishing tests combined with MFA enforcement checks directly exercise the control against realistic threats, while performance metrics and exception reporting provide continuous, quantifiable evidence of effectiveness. Vendor documentation, policy acknowledgment, and project delivery metrics may support the program but do not demonstrate that the control is actually working.

Exam trap

The trap here is treating vendor certifications and policy attestations as evidence of control effectiveness, when only direct testing and performance monitoring demonstrate operating effectiveness.

133
MCQeasy

An organization has decided to purchase cyber insurance to cover potential losses from a ransomware event affecting its order-processing systems. Which risk response has the organization selected?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerD

Purchasing insurance shifts the financial consequence of a specified loss to a third party in exchange for a premium. The risk itself still exists and the systems remain exposed, but the monetary impact is contractually borne by the insurer within policy limits and conditions. This is the defining characteristic of transfer as a risk response.

Why this answer

Insurance is the classic transfer response: a premium is exchanged for the insurer's assumption of defined financial losses. The operational risk of ransomware remains with the organization, which is why transfer is often paired with mitigation. Avoidance would end the activity, mitigation would reduce likelihood or impact directly, and acceptance would retain the loss without external coverage.

Exam trap

The trap here is treating insurance as mitigation because it feels like a protective measure rather than a financial arrangement.

134
Multi-Selectmedium

A risk practitioner is designing a key risk indicator (KRI) program for a cloud-hosted customer portal. The CISO wants indicators that provide early warning of deteriorating risk conditions rather than reporting losses that have already occurred. Which TWO of the following are the MOST appropriate KRIs for this objective? (Choose two.)

Select 2 answers
A.Number of confirmed data breaches reported to regulators in the last quarter
B.Total annual cost of cyber insurance premiums for the customer portal
C.Percentage of critical portal servers with missing high-severity patches older than 30 days
D.Average time to close security incidents after they have been detected
E.Number of privileged accounts lacking multifactor authentication on the portal
AnswersC, E

Unpatched high-severity vulnerabilities are a leading indicator because they measure a condition that raises the likelihood of a future compromise before any incident occurs. Tracking the percentage of servers outside the 30-day window provides an early warning signal tied directly to the threat landscape. This aligns with the CISO's request for predictive rather than lagging indicators.

Why this answer

Leading indicators measure conditions that precede loss, such as unpatched high-severity vulnerabilities and privileged accounts without multifactor authentication. Both can be tracked continuously and remediated before an attacker exploits them. Breach counts, insurance premiums, and incident closure times all describe outcomes or costs that appear only after risk has already materialized.

Exam trap

The trap here is selecting operational security metrics that feel proactive, such as incident closure time, when they actually measure events that have already occurred.

135
MCQhard

A Key Control Indicator (KCI) for a critical firewall rule set shows an exception rate of 12% over the past month, exceeding the acceptable threshold of 5%. The control owner is responsible for remediation. Which action should the risk practitioner recommend FIRST?

A.Temporarily disable the firewall rules causing exceptions
B.Implement an automated rule change management process
C.Update the KCI threshold to 12%
D.Conduct a root cause analysis of the exceptions
AnswerD

Root cause analysis identifies why exceptions exceeded the 5% threshold before remediation is chosen. Acting on symptoms risks recurring breaches, so understanding whether the cause is rule misconfiguration, process drift or user behaviour ensures the control owner applies the correct corrective action first.

Why this answer

The first step in addressing an elevated KCI is to investigate the root cause of the exceptions to determine if they are due to rule misconfigurations, policy violations, or other issues before taking corrective action.

136
MCQmedium

An organization is implementing a new access control system to protect sensitive data. Which type of control is most appropriate for preventing unauthorized access?

A.Detective control
B.Preventive control
C.Corrective control
D.Compensating control
AnswerB

Preventive controls stop unauthorised access attempts before they succeed, directly satisfying the stem's requirement to prevent rather than merely detect or correct. Authentication, authorisation and encryption mechanisms block intrusion at the point of entry, unlike detective controls that only reveal breaches after the fact.

Why this answer

A preventive control is designed to stop unauthorized access from occurring in the first place, which is exactly what an access control system does — it enforces authentication and authorization before granting access to sensitive data. Preventive controls are the primary defense against unauthorized access because they act before the security event occurs. This is the most appropriate control type for the stated objective.

Exam trap

CRISC often tests the preventive vs. detective distinction — candidates pick detective because access control systems generate logs, but the primary purpose of an access control system is to prevent unauthorized access, not to detect it after the fact.

How to eliminate wrong answers

Option A is wrong because a detective control identifies unauthorized access after it has occurred (e.g., IDS, audit logs, SIEM alerts) — it does not prevent access, only detects it. Option C is wrong because a corrective control remediates damage or restores systems after an incident (e.g., backups, patch management, incident response) — it operates after the fact, not before. Option D is wrong because a compensating control is an alternative measure used when a primary control cannot be implemented (e.g., compensating for a missing encryption control with network segmentation); it is not the primary control type for preventing unauthorized access.

137
Multi-Selecthard

A third-party vendor is classified as high risk due to its access to sensitive data. Which THREE activities should be part of ongoing monitoring for this vendor?

Select 3 answers
A.Contract compliance reviews to ensure terms are met.
B.Requiring SOC 2 Type II certification before contract signing.
C.Continuous monitoring via shared threat intelligence platforms.
D.Annual reassessment of the vendor's security posture.
E.Initial onboarding security questionnaire review.
AnswersA, C, D

Contract compliance reviews verify the vendor still meets agreed security, privacy and service terms, directly addressing the sensitive-data access that makes this vendor high risk. Reviews detect drift from contractual obligations before it becomes a reportable exposure.

Why this answer

Option A is correct because ongoing monitoring for a high-risk vendor must include contract compliance reviews, which verify that the vendor continues to meet agreed security, privacy, and service-level terms throughout the relationship, not just at signing. Option C is correct because continuous monitoring via shared threat intelligence platforms provides real-time visibility into emerging threats, indicators of compromise, and the vendor's security posture, which is essential for a vendor with access to sensitive data. Option D is correct because annual reassessment of the vendor's security posture is a recurring due-diligence activity that re-evaluates controls, risk ratings, and changes in the vendor's environment over time.

Option B is not part of ongoing monitoring because requiring SOC 2 Type II certification is a pre-contract due-diligence step performed before signing, not a continuous monitoring activity. Option E is also not ongoing monitoring because the initial onboarding security questionnaire review occurs only at the start of the relationship and does not provide continuous oversight.

Exam trap

The trap here is confusing pre-contract due diligence activities (like SOC 2 certification or initial questionnaires) with ongoing monitoring activities, leading candidates to select options that are valid but belong to a different phase of the vendor risk management lifecycle.

138
MCQmedium

A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?

A.Investigate the root cause of the high exception rate
B.Increase the acceptable threshold to 20%
C.Replace the control with a different one
D.Escalate to the board immediately
AnswerA

A 15% exception rate signals the control is failing beyond tolerance, so the control owner must first determine why exceptions occur before remediating. Root-cause investigation identifies whether the issue is rule design, process adherence or tooling, informing corrective action.

Why this answer

A KCI exception rate exceeding the threshold indicates a process failure, not necessarily a control failure. The control owner must first perform root cause analysis to determine whether the exceptions are due to misconfigured rules, policy violations, or environmental changes before taking corrective action. This aligns with the CRISC principle that control owners are responsible for monitoring and improving control effectiveness through investigation.

Exam trap

ISACA often tests the misconception that exceeding a KCI threshold automatically requires escalation or control replacement, when in fact the immediate step is always root cause analysis to determine if the threshold breach is a temporary anomaly or a systemic issue.

How to eliminate wrong answers

Option B is wrong because arbitrarily increasing the threshold to 20% masks the underlying issue and violates the principle of maintaining risk appetite; thresholds should be based on risk tolerance, not adjusted to avoid alarms. Option C is wrong because replacing the control without understanding why exceptions occurred is premature and could introduce new risks; the existing control may be effective if the root cause is addressed. Option D is wrong because escalation to the board is reserved for material risk events or control failures that exceed the risk appetite after investigation; a 15% exception rate does not warrant board-level escalation as an immediate action.

139
Multi-Selecthard

An IT risk manager is developing KRIs for a critical application. Which TWO of the following are leading indicators that the risk level may be increasing? (Select TWO)

Select 2 answers
A.Average patch lag time increasing
B.Failed authentication spike
C.Audit findings of control deficiencies
D.Number of successful intrusions
E.Number of security incidents in the past month
AnswersA, B

Patch lag measures exposure duration before remediation, so lengthening lag signals accumulating unpatched vulnerabilities and rising likelihood of exploitation. It is a leading indicator because it predicts future incidents rather than reporting past losses, satisfying the KRI requirement for forward-looking risk trend data.

Why this answer

Option A (Average patch lag time increasing) is correct because a growing delay between patch release and deployment is a leading indicator: it signals accumulating unpatched vulnerabilities and weakening patch management before any exploit or incident occurs. Option B (Failed authentication spike) is correct because a sudden rise in failed logons is a leading indicator of credential-stuffing, brute-force, or password-spraying activity, which precedes a potential account compromise. Option C is a lagging indicator because audit findings document control deficiencies that already exist, reflecting past state rather than predicting future risk increase.

Option D is a lagging indicator since successful intrusions are realized events that have already occurred. Option E is also lagging because counting past security incidents measures historical impact, not forward-looking risk trajectory.

Exam trap

CRISC often tests the distinction between leading and lagging indicators, and candidates frequently select incident counts or audit findings because they sound risk-related, missing that these are backward-looking outcomes rather than predictive signals.

140
Multi-Selectmedium

A risk practitioner is designing a risk report for the board of directors. Which TWO content elements are most appropriate for strategic risk reporting? (Select two.)

Select 2 answers
A.Trend analysis of top key risk indicators
B.List of all control deficiencies
C.Names of employees who failed phishing tests
D.Risk heat map showing overall risk exposure
E.Detailed log analysis results
AnswersA, D

Board-level strategic reporting requires forward-looking insight, and trend analysis of top key risk indicators shows whether exposure is rising or falling against appetite over time, enabling directors to govern direction rather than review past operational detail.

Why this answer

Option A (Trend analysis of top key risk indicators) is correct because the board needs a forward-looking, aggregated view of how the organization's most significant risks are changing over time, and KRIs distilled to the top risks give directors the directional insight required for strategic oversight rather than operational detail. Option D (Risk heat map showing overall risk exposure) is correct because a heat map aggregates likelihood and impact across the enterprise into a single visual that lets the board quickly grasp the overall risk profile and prioritize where to focus governance attention. The remaining options do not belong at the strategic level: B (List of all control deficiencies) is an exhaustive operational/audit artifact better suited to management or the audit committee, C (Names of employees who failed phishing tests) is personally identifiable, tactical HR/security data inappropriate for board reporting, and E (Detailed log analysis results) is raw technical data that belongs to IT operations or security teams, not strategic risk reporting.

Exam trap

The trap here is that candidates confuse operational reporting details (like control deficiencies or phishing test results) with strategic-level content, failing to recognize that the board requires aggregated, decision-useful summaries rather than granular data.

141
MCQhard

A software company has completed a risk assessment showing that a critical SaaS platform has a residual risk above appetite due to weak vendor access controls. Budget is limited and the remediation will take six months. The CISO must decide how to proceed while the risk remains elevated. Which action BEST aligns with CRISC risk response principles?

A.Transfer the risk to the SaaS vendor by sending a notification letter describing the control weaknesses.
B.Document an interim compensating control, set a remediation timeline, and obtain formal risk acceptance from the accountable business owner until closure.
C.Lower the inherent risk rating in the register so that residual risk falls within the approved appetite.
D.Suspend all access to the SaaS platform until the vendor access controls are fully remediated.
AnswerB

When residual risk exceeds appetite and full remediation cannot be immediate, the appropriate response is to apply interim compensating controls, commit to a timeline, and have the accountable business owner formally accept the remaining risk. This maintains transparency, assigns ownership, and keeps the exposure visible to governance. It aligns with CRISC principles because risk decisions belong to the business owner, not solely to security.

Why this answer

With residual risk above appetite and remediation requiring six months, the sound approach is to implement interim compensating controls, establish a remediation timeline, and obtain formal acceptance from the accountable business owner. This keeps exposure transparent and owned while respecting business continuity. Suspending service, manipulating ratings, or merely notifying the vendor do not appropriately manage the risk or satisfy governance and reporting expectations.

Exam trap

The trap here is treating a notification letter as risk transfer or lowering a risk score as a response, when real transfer requires contractual or insurance mechanisms and ratings must reflect evidence.

142
MCQeasy

An organization is implementing a new control to prevent unauthorized access to its critical database. Which type of control is most appropriate for this requirement?

A.Compensating control
B.Preventive control
C.Corrective control
D.Detective control
AnswerB

A preventive control stops unauthorised access attempts before they succeed, directly satisfying the requirement to prevent access to the critical database. Detective controls would only identify breaches after the fact, and corrective controls remediate afterwards, neither meeting the stated prevention objective.

Why this answer

A preventive control is the most appropriate because it directly stops unauthorized access before it can occur. For a critical database, this could involve implementing database-level access control lists (ACLs), network firewall rules restricting traffic to specific IP ranges, or mandatory multi-factor authentication (MFA) on the database service. These mechanisms enforce the security policy at the point of entry, blocking the threat actor before any interaction with the data.

Exam trap

The trap here is that candidates often confuse 'preventive' with 'detective' controls, mistakenly choosing detective controls (like logging) because they are more visible in audit reports, but the question explicitly asks for a control that 'prevents' access, which requires a proactive blocking mechanism.

How to eliminate wrong answers

Option A is wrong because a compensating control is an alternative measure used when the primary control cannot be implemented due to technical or business constraints, not the first choice for a direct requirement like preventing unauthorized access. Option C is wrong because a corrective control (e.g., restoring a database from a backup after a breach) acts after an incident has occurred, failing to meet the requirement to prevent access in the first place. Option D is wrong because a detective control (e.g., database audit logs or intrusion detection systems) only identifies unauthorized access after it has happened, providing no proactive prevention.

143
MCQmedium

A risk practitioner is preparing a risk report for the executive committee. The committee has limited time and has previously complained that reports contain too much technical detail. Which approach BEST communicates the most critical IT risks to this audience?

A.Focus on the number of vulnerabilities detected in the latest technical scan.
B.Provide the full risk register with all identified risks and their control test results.
C.Summarize the top risks by business impact and alignment with risk appetite, with recommended actions.
D.Present only risks that have already resulted in a confirmed loss or incident.
AnswerC

Executive reporting succeeds when it translates technical findings into business consequence and links them to the appetite leadership approved. Ranking by impact and appetite alignment focuses attention on decisions the committee can actually make, such as funding treatment or accepting a documented exception. Recommended actions close the loop by giving the committee a clear choice rather than raw data.

Why this answer

Executive risk reporting must be selective, business-oriented, and connected to appetite. Summarizing top risks by business impact and appetite alignment, with recommended actions, gives the committee what it needs to govern: which exposures matter, how they compare to tolerance, and what decisions are required. Full registers, scan counts, and incident-only reporting either overwhelm, mislead, or arrive too late.

Exam trap

The trap here is assuming that more comprehensive technical data automatically produces a more useful executive risk report.

144
MCQeasy

An organization's risk register lists a risk with an annualized loss expectancy (ALE) of $200,000. A proposed control would reduce the ALE to $50,000, and the control costs $40,000 per year to operate. What is the value of the control's risk reduction?

A.$10,000
B.$200,000
C.$150,000
D.$40,000
AnswerC

The value of the risk reduction is the original ALE minus the residual ALE: $200,000 - $50,000 = $150,000. This represents the expected annual loss avoided by implementing the control. Comparing this to the $40,000 annual control cost shows a positive net benefit, making the control economically justified from a quantitative standpoint.

Why this answer

The value of the risk reduction is the difference between the original ALE and the residual ALE after the control is applied. Here, $200,000 minus $50,000 equals $150,000. This figure represents the expected annual loss avoided.

Comparing it to the $40,000 annual control cost yields a net benefit of $110,000, indicating the control is cost-effective.

Exam trap

The trap here is confusing the control's operating cost or net benefit with the risk reduction value, when the risk reduction is strictly the drop in expected annual loss before and after the control.

145
MCQmedium

A financial services firm's risk committee has approved a risk response plan for its core payment platform. The plan requires monthly tracking of key risk indicators (KRIs) and quarterly reporting of control test results to the board. Six months later, the CIO asks the risk manager to confirm that the approved response is still appropriate given new regulatory guidance. Which of the following should the risk manager do FIRST?

A.Immediately escalate to the board that the existing risk response plan is invalid and must be replaced.
B.Commission a penetration test of the payment platform to produce fresh technical evidence for the committee.
C.Suspend the quarterly board reporting until the regulatory guidance has been fully interpreted by legal counsel.
D.Reassess the risk and control environment against the new regulatory guidance to determine whether the approved response remains within tolerance.
AnswerD

The approved response was based on assumptions that new regulatory guidance may have altered. CRISC practice requires reassessing the risk, evaluating whether existing controls still mitigate it to within tolerance, and only then proposing changes to the risk response. This preserves the traceability of the risk decision and gives the committee evidence on which to act, rather than reacting to guidance in isolation.

Why this answer

When the external environment changes, the risk practitioner must first determine whether the previously approved risk response still keeps the risk within the organization's tolerance. That means reassessing the risk, the effectiveness of existing controls, and the alignment of the response with new regulatory expectations before recommending any change. This maintains evidence-based governance and gives the risk committee a defensible basis for deciding whether to accept, modify, or escalate the response.

Exam trap

The trap here is assuming that any new regulatory guidance automatically invalidates the approved risk response and warrants immediate board escalation.

146
MCQhard

A bank's risk committee is reviewing a proposal to increase the risk appetite threshold for third-party data processing failures from 2 to 5 incidents per year. The head of internal audit objects, noting that three such failures occurred in the last 12 months and one caused a regulatory finding. Which action should the risk committee take FIRST?

A.Evaluate whether existing third-party controls and remediation plans can bring incident frequency within the current threshold before changing the appetite.
B.Immediately approve the new threshold to align reporting with actual performance and close the audit finding.
C.Reject the proposal and take no further action because the current threshold already reflects the board's intent.
D.Delegate the decision to the third-party management team since they own the vendor relationships.
AnswerA

Changing risk appetite to match current performance inverts the intended relationship: appetite should drive acceptable exposure, not be adjusted to accommodate poor results. The committee should first assess whether control improvements can reduce incident frequency to the existing threshold. Only after determining that the threshold is unachievable or misaligned with strategy should appetite revision be considered, with audit and regulatory implications weighed.

Why this answer

Risk appetite defines the level of risk the organization is willing to accept and should guide performance, not be retrofitted to justify it. Before raising the threshold, the committee must determine whether improved third-party controls can reduce failures to within the existing limit. Adjusting appetite to match poor results would normalize the exposure, conflict with the regulatory finding, and weaken governance oversight.

Exam trap

The trap here is treating risk appetite as a reporting calibration that should match actual performance, rather than a governance boundary that performance must be brought into alignment with.

147
MCQhard

A multinational retailer's risk register shows a high inherent risk for its point-of-sale (POS) payment environment. After implementing tokenization, the risk owner records a residual risk rating of low. During the next quarterly review, the internal audit team finds that several legacy POS terminals still transmit clear-text card data. Which risk response principle was violated?

A.Risk response must be validated against actual control coverage before residual risk is reported.
B.Risk response must transfer residual risk to a third party whenever inherent risk is rated high.
C.Risk response must be approved by the board before any residual risk rating can be lowered.
D.Risk response must always prioritize risk avoidance over risk mitigation for payment environments.
AnswerA

Residual risk represents what remains after controls are applied, so it must reflect verified control effectiveness across the entire scope. Reporting low residual risk while legacy terminals still transmit clear-text data overstates control coverage and understates exposure. The risk owner should have validated that tokenization covered all in-scope terminals before adjusting the rating, making this the violated principle.

Why this answer

Residual risk is only meaningful when it reflects validated control effectiveness across the full scope of the risk. The risk owner lowered the rating based on tokenization without confirming that legacy terminals were included, so the reported low residual risk was inaccurate. Risk response and reporting require evidence that controls operate as designed before risk ratings are adjusted downward, and audit findings should trigger reassessment of the affected register entries.

Exam trap

The trap here is treating residual risk as a theoretical calculation after a control is purchased, rather than a validated measurement of control coverage and effectiveness.

148
MCQmedium

An organization wants to promote a risk-aware culture. Which of the following actions is MOST effective for encouraging employees to report incidents without fear?

A.Reward employees for zero incidents
B.Establish a non-punitive incident reporting policy
C.Implement automated monitoring tools
D.Conduct security awareness training annually
AnswerB

A non-punitive policy removes the fear of blame or reprisal, which is the specific barrier stopping employees from reporting incidents. Awareness campaigns or training alone cannot overcome that fear, so this directly satisfies the stem's constraint of encouraging reporting without fear.

Why this answer

A non-punitive incident reporting policy directly removes the fear of retaliation or blame, which is the primary barrier to reporting. By guaranteeing that employees will not be punished for reporting incidents (including their own mistakes), the organization encourages transparency and timely disclosure. This aligns with CRISC principles of fostering a risk-aware culture where risk information flows freely.

Other options do not address the fear factor; rewards for zero incidents can actually discourage reporting, automated tools don't change human behavior, and annual training is insufficient to build trust.

Exam trap

CRISC often tests the difference between technical controls and cultural enablers; candidates may mistakenly choose automated monitoring or training as the most effective, overlooking that fear of punishment is a human factor that only policy can address.

How to eliminate wrong answers

Option A is wrong because rewarding zero incidents incentivizes employees to hide incidents to earn rewards, directly undermining reporting. Option C is wrong because automated monitoring tools detect issues but do not address the cultural fear that prevents employees from voluntarily reporting incidents. Option D is wrong because annual security awareness training, while useful for knowledge, does not create a safe environment for reporting; it may even increase fear if it emphasizes punishment.

149
MCQmedium

An organization is implementing a continuous monitoring solution for its network. Which of the following is an example of continuous monitoring?

A.Monthly control testing by internal audit
B.Annual penetration testing
C.Quarterly access reviews
D.Daily automated vulnerability scanning
AnswerD

Daily automated vulnerability scanning repeatedly and systematically inspects network assets on a scheduled basis, generating current findings without manual intervention. This satisfies continuous monitoring's defining characteristic of ongoing automated observation, unlike one-off assessments or periodic manual reviews that capture only point-in-time snapshots.

Why this answer

Continuous monitoring means ongoing, automated observation of controls and risk indicators at frequent intervals. Daily automated vulnerability scanning fits this definition because it runs repeatedly without manual intervention and provides near-real-time visibility into the control environment. The other options are periodic, point-in-time activities.

Exam trap

CRISC often tests the distinction between continuous monitoring (frequent, automated) and periodic activities (monthly, quarterly, annual); candidates who focus on the depth of the activity rather than its frequency pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because monthly control testing is periodic, not continuous — it provides a snapshot once a month. Option B is wrong because annual penetration testing is an infrequent, deep-dive assessment, the opposite of continuous monitoring. Option C is wrong because quarterly access reviews are periodic attestations, not automated continuous observation.

150
Multi-Selectmedium

A multinational retailer's IT risk manager must define key risk indicators (KRIs) for its third-party payment processing relationships. Which TWO characteristics must the selected KRIs exhibit to be effective for ongoing risk monitoring? (Choose two.)

Select 2 answers
A.They are kept confidential from the vendor so the vendor cannot influence the reported results.
B.They are tied to a specific risk statement and have defined thresholds that trigger escalation.
C.They are reviewed and updated only during the annual enterprise risk assessment cycle.
D.They are measurable at a defined frequency from data the organization can reliably obtain.
E.They are expressed exclusively as monetary values so executives can compare them to budget.
AnswersB, D

An effective KRI links directly to an identified risk and carries thresholds that dictate when action or escalation is required. Without this linkage, the metric is just operational reporting. With it, the retailer knows that a breach of the threshold signals increasing exposure and initiates the documented risk response process, keeping monitoring connected to governance rather than producing data with no decision path.

Why this answer

Effective KRIs are quantifiable on a reliable schedule and explicitly tied to a risk with thresholds that drive escalation. Those two properties turn measurement into monitoring. Restricting indicators to monetary units, refreshing them only annually, or hiding them from the vendor all break the feedback loop that makes an indicator actionable for third-party payment risk.

Exam trap

The trap here is assuming an indicator must be financial or confidential to be credible, when usefulness depends on reliable periodic measurement and a threshold linked to a specific risk.

← PreviousPage 2 of 3 · 176 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Risk Response and Reporting questions.