Courseiva

CCNA Risk Response and Reporting Questions

26 of 176 questions · Page 3/3 · Risk Response and Reporting · Answers revealed

151
MCQmedium

Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a control?

A.Control exception rate
B.Number of risk events in the last quarter
C.Time since last audit
D.Percentage of employees who completed security awareness training
AnswerA

Control exception rate quantifies how often a control fails to operate as intended, directly evidencing control effectiveness. Risk appetite thresholds, incident counts and loss totals measure outcomes or tolerance rather than the control's own operating performance.

Why this answer

A Key Control Indicator (KCI) measures how well a specific control is operating. Control exception rate — the frequency with which a control fails or is bypassed — directly measures control effectiveness, making it a textbook KCI. The other options measure risk events, audit timing, or training completion, which are KRIs or compliance metrics.

Exam trap

CRISC often tests the distinction between KCIs (control effectiveness) and KRIs (risk exposure); candidates who pick 'number of risk events' or 'training completion' confuse risk indicators with control indicators.

How to eliminate wrong answers

Option B is wrong because the number of risk events is a Key Risk Indicator (KRI) measuring realized risk, not control performance. Option C is wrong because time since last audit is an assurance scheduling metric, not a measure of control effectiveness. Option D is wrong because training completion percentage measures a training program's reach (a compliance or awareness metric), not the operational effectiveness of a specific control.

152
MCQmedium

Which of the following is the primary purpose of a Key Risk Indicator (KRI)?

A.Measure the effectiveness of controls
B.Document historical incidents
C.Comply with regulatory requirements
D.Provide early warning of changing risk levels
AnswerD

A Key Risk Indicator provides early warning by tracking measurable metrics against defined thresholds, signalling when risk exposure is trending beyond acceptable tolerance. This satisfies the stem's requirement for the primary purpose: enabling proactive risk response before incidents materialise, rather than retrospective reporting or control testing.

Why this answer

The primary purpose of a Key Risk Indicator (KRI) is to provide an early warning of changing risk levels, enabling proactive risk management before an adverse event occurs. KRIs track specific metrics that signal shifts in risk exposure, such as the number of unpatched critical vulnerabilities or failed login attempts, allowing organizations to adjust controls or resources in advance. This forward-looking function distinguishes KRIs from lagging indicators like control effectiveness metrics or incident logs.

Exam trap

The trap here is that candidates confuse KRIs with KPIs or control metrics, mistakenly thinking KRIs measure control effectiveness (Option A) rather than providing early warning of risk changes.

How to eliminate wrong answers

Option A is wrong because measuring the effectiveness of controls is the purpose of Key Performance Indicators (KPIs) or control testing, not KRIs; KRIs focus on risk exposure changes, not control performance. Option B is wrong because documenting historical incidents is the role of incident logs or post-mortem reports, whereas KRIs are forward-looking and designed to predict rather than record past events. Option C is wrong because while KRIs may support regulatory compliance indirectly, their primary purpose is not compliance; compliance requirements are met through specific control frameworks and reporting, not through the early-warning function of KRIs.

153
MCQeasy

What is the primary purpose of a risk heat map in IT risk reporting?

A.Show control performance metrics
B.Display risk trends over time
C.Provide a visual representation of risk levels
D.List upcoming risk events
AnswerC

A risk heat map plots likelihood against impact, using colour coding to show which risks sit in high, medium or low bands. This satisfies the reporting need by letting management and the board quickly compare risk levels across the portfolio and prioritise treatment.

Why this answer

A risk heat map visualizes risks based on likelihood and impact, helping prioritize attention.

154
MCQeasy

An organization wants to promote a risk-aware culture. Which initiative best supports this goal?

A.Focusing only on technical controls
B.Limiting risk awareness training to IT staff
C.Punishing employees who cause security incidents
D.Encouraging incident reporting without blame
AnswerD

Blame-free incident reporting removes the fear of punishment, so staff surface errors and near-misses early. This transparency gives management accurate risk data and reinforces that risk identification is everyone's responsibility, which is the foundation of a risk-aware culture.

Why this answer

Encouraging incident reporting without blame directly supports a risk-aware culture by removing the fear of punishment, which motivates employees to report issues promptly. This allows the organization to identify and respond to risks early, rather than hiding them, and aligns with the risk response principle of learning from incidents to improve controls.

Exam trap

The trap here is that candidates may confuse a risk-aware culture with strict enforcement or technical fixes, but CRISC emphasizes that culture is built on trust and open communication, not punishment or siloed training.

How to eliminate wrong answers

Option A is wrong because focusing only on technical controls ignores the human and cultural factors that are essential for a risk-aware culture; technical controls alone cannot address behavioral risks like failure to report incidents. Option B is wrong because limiting risk awareness training to IT staff excludes other departments (e.g., finance, HR, operations) that also handle sensitive data and face risks, creating blind spots in the organization's risk posture. Option C is wrong because punishing employees who cause security incidents discourages reporting, leading to hidden risks and missed opportunities for root cause analysis, which undermines a proactive risk culture.

155
MCQmedium

A risk manager is evaluating the cost-effectiveness of a proposed control. The control costs $50,000 annually to implement and maintain. The current annual loss expectancy (ALE) for the risk is $200,000, and the control is expected to reduce the ALE by 70%. What is the net benefit (or loss) of implementing the control?

A.Net benefit of $90,000
B.Net loss of $10,000
C.Net benefit of $140,000
D.Net loss of $50,000
AnswerA

The control reduces ALE by 70% of $200,000, giving a $140,000 mitigated loss. Subtracting the $50,000 annual control cost yields a $90,000 net benefit. This satisfies the stem's cost-effectiveness comparison between control spend and risk reduction.

Why this answer

The control reduces the ALE by 70%, so the mitigated ALE is $200,000 × 0.30 = $60,000, meaning the control saves $140,000 in expected annual loss. Subtracting the $50,000 annual control cost gives a net benefit of $140,000 − $50,000 = $90,000. This is the standard ALE-based cost-benefit calculation used in CRISC risk treatment decisions.

Exam trap

CRISC often tests whether candidates confuse gross savings with net benefit — the most common error is selecting the $140,000 figure by forgetting to subtract the control's annual cost, or misreading the 70% as applying to the cost rather than the ALE.

How to eliminate wrong answers

Option B (net loss of $10,000) is wrong because it appears to subtract the control cost from the wrong base or miscalculates the 70% reduction — the correct savings are $140,000, not $40,000. Option C (net benefit of $140,000) is wrong because it reports the gross savings and forgets to subtract the $50,000 annual control cost. Option D (net loss of $50,000) is wrong because it treats the entire control cost as a loss without applying the 70% ALE reduction, ignoring the benefit side of the equation.

156
MCQhard

An organization uses Key Control Indicators (KCIs) to measure the effectiveness of its firewall change management process. Which KCI would best indicate a process deficiency?

A.Exception rate for changes not following the standard process
B.Percentage of changes approved by the change advisory board
C.Average time to implement a change
D.Number of firewall rules added per month
AnswerA

A high exception rate shows changes bypassing the standard process, revealing weak enforcement or impractical procedures. Unlike volume or cycle-time metrics, exceptions directly evidence control breakdown, making this the strongest indicator of deficiency in firewall change management.

Why this answer

A Key Control Indicator (KCI) measures whether a control is operating effectively. An exception rate for changes not following the standard process directly indicates how often the firewall change management process is bypassed or failing, which is a clear sign of process deficiency. The other options measure activity or volume, not control effectiveness.

Exam trap

CRISC often tests the distinction between KCIs (control effectiveness) and KPIs (performance) — candidates may pick 'average time to implement' as a deficiency indicator, but that is an efficiency metric, not a control effectiveness measure.

How to eliminate wrong answers

Option B is wrong because the percentage of changes approved by the change advisory board measures process adherence for changes that go through the CAB, but a high approval rate could simply mean the CAB approves everything, and it does not indicate deficiency. Option C is wrong because average time to implement a change is an efficiency metric, not a control effectiveness indicator; slow changes may be due to complexity, not a control failure. Option D is wrong because the number of firewall rules added per month is a volume metric that reflects activity, not whether the change management control is working.

157
MCQeasy

Which of the following is the BEST example of promoting a risk-aware culture within an organization?

A.Implementing strict penalties for security violations
B.Assigning risk ownership to IT only
C.Encouraging incident reporting without blame
D.Conducting annual security training
AnswerC

Encouraging incident reporting without blame directly satisfies the stem's cultural objective: staff surface near misses and control failures, generating the data risk assessment depends on. A blame response suppresses disclosure, leaving risks invisible to management. This builds the shared ownership and transparency that a risk-aware culture requires, unlike one-off training or policy documents.

Why this answer

A blame-free incident reporting culture is the foundation of a risk-aware environment. When employees feel safe to report errors or near-misses without fear of punishment, the organization can collect accurate data on control weaknesses and emerging threats, enabling proactive risk response. This aligns with the COBIT 5 principle of fostering a culture of openness and learning, which is essential for effective risk management.

Exam trap

CRISC candidates often mistakenly believe that punitive measures or compliance-focused training are the best ways to foster a risk-aware culture. However, the key is a blame-free reporting environment that encourages openness and learning.

How to eliminate wrong answers

Option A is wrong because strict penalties for security violations create a culture of fear, which discourages incident reporting and drives issues underground, undermining risk awareness and learning. Option B is wrong because assigning risk ownership exclusively to IT ignores that risk is a business-wide concern; effective risk management requires ownership across all departments, including legal, finance, and operations. Option D is wrong because annual security training, while important, is a periodic compliance activity that does not by itself embed continuous risk awareness into daily behaviors or encourage proactive reporting of incidents.

158
MCQhard

A Key Risk Indicator (KRI) for vulnerability management is the "average patch lag time" (number of days between patch release and deployment). In the last month, this metric increased from 15 days to 45 days. How should the risk practitioner interpret this change?

A.The KRI is not relevant because patch lag is a control indicator, not a risk indicator.
B.The risk level has decreased because patches are being evaluated more thoroughly.
C.The risk level remains unchanged because patch lag is a lagging indicator.
D.The risk level has increased because exposure to known vulnerabilities has grown.
AnswerD

Patch lag rising from 15 to 45 days means systems remain unpatched longer, extending exposure to known exploitable vulnerabilities. The KRI movement therefore signals increased risk, satisfying the interpretation that the metric's deterioration reflects a higher likelihood of exploitation.

Why this answer

An increase in average patch lag from 15 to 45 days means critical vulnerabilities remain exploitable for a longer window, directly increasing exposure to known threats. Since KRIs are designed to signal changes in risk levels, a rising KRI indicates the risk level has increased and warrants attention. The correct interpretation is that the organization's exposure to known vulnerabilities has grown.

Exam trap

CRISC often tests whether candidates confuse a rising KRI with improved controls — the trap is interpreting a longer patch lag as 'more thorough evaluation' when it actually signals increased exposure and deteriorating risk posture.

How to eliminate wrong answers

Option A is wrong because patch lag is a valid KRI — it measures a risk driver (exposure window) even though it also reflects control performance; KRIs and KCIs can overlap, and the metric is explicitly used as a KRI here. Option B is wrong because a longer patch lag does not mean patches are being evaluated more thoroughly — it means they are being deployed more slowly, which increases risk, not decreases it. Option C is wrong because whether a metric is leading or lagging does not determine whether risk has changed; a 3x increase in patch lag clearly signals increased risk regardless of indicator type.

159
MCQhard

An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?

A.The patching process is effective because the KRI is still below 60 days
B.The KRI should be replaced with a lagging indicator
C.The vulnerability risk is increasing and requires management attention
D.The risk is within appetite because the increase is gradual
AnswerC

The KRI has breached the 20-day risk appetite threshold, rising from 15 to 30 days, so vulnerability exposure is worsening. This trend signals that patch management controls are degrading, requiring management attention to remediate the control weakness before the risk exceeds tolerance further.

Why this answer

The KRI has risen from 15 to 30 days, exceeding the 20-day risk appetite threshold. When a KRI breaches its threshold, it signals that the risk is outside acceptable limits and requires management attention. The correct conclusion is that vulnerability risk is increasing and must be addressed.

Exam trap

The trap is that candidates may rationalize the increase as 'gradual' or compare it to an irrelevant benchmark (60 days) instead of the defined 20-day threshold — CRISC expects you to treat threshold breaches as clear signals requiring management action.

How to eliminate wrong answers

Option A is wrong because the 60-day figure is arbitrary and not the defined threshold — the threshold is 20 days, and the KRI has exceeded it, so the process is not effective. Option B is wrong because replacing a KRI with a lagging indicator does not address the rising risk; KRIs are specifically chosen to be forward-looking, and swapping them out is not a valid response to a threshold breach. Option D is wrong because the risk is not within appetite — the KRI has crossed the 20-day threshold, and a gradual increase does not make it acceptable; thresholds are binary triggers for action.

160
MCQhard

An energy utility's board risk committee receives a quarterly IT risk report showing that overall risk exposure is within appetite, yet a recent regulatory audit identified unpatched internet-facing systems. The risk manager must improve the report so the committee is not misled in the future. Which change is MOST effective?

A.Delegate preparation of the IT risk report entirely to the internal audit function going forward.
B.Add a section that reconciles reported risk ratings against independent audit and assessment findings.
C.Increase the reporting frequency from quarterly to monthly without changing the content or data sources.
D.Replace quantitative risk ratings with a purely qualitative red, amber, and green status for each risk.
AnswerB

The gap between an in-appetite dashboard and an audit finding signals that self-reported data was incomplete or optimistic. Reconciling reported ratings with independent findings exposes divergence, forces explanation of root causes, and strengthens the credibility of the report. It also creates a feedback loop so that audit results update the risk register rather than sitting outside the reporting process.

Why this answer

When a board dashboard shows acceptable exposure while an independent audit finds real gaps, the reporting process lacks validation. Reconciling reported ratings with audit and assessment findings surfaces divergence, drives root-cause analysis, and ensures independent evidence updates the register. Changing frequency or format, or shifting authorship to audit, leaves the underlying data integrity problem intact.

Exam trap

The trap here is assuming that more frequent reporting or simpler visual formats will fix a credibility problem that actually stems from unvalidated self-reported data.

161
MCQmedium

An organization is integrating IT risk into its enterprise risk management (ERM) program. What is the primary benefit of this integration?

A.It allows IT to operate independently
B.It eliminates all IT risks
C.It reduces the need for IT controls
D.It ensures IT risks are viewed in the context of business objectives
AnswerD

Integrating IT risk into ERM translates technical exposures into business-impact terms, so leadership evaluates them alongside strategic, financial and operational risks. This satisfies the stem's primary-benefit requirement by ensuring IT risks are assessed against business objectives rather than managed in an isolated technical silo.

Why this answer

Integrating IT risk into enterprise risk management (ERM) ensures that IT risks are evaluated in the context of business objectives, enabling prioritization of risk responses that align with strategic goals. This alignment prevents IT from operating in a silo and ensures that risk decisions support overall business value, not just technical compliance.

Exam trap

The trap here is that candidates mistakenly think integration means IT risks are eliminated or that IT can ignore business context, when in fact integration demands that IT risks be translated into business impact terms to drive appropriate control decisions.

How to eliminate wrong answers

Option A is wrong because integrating IT risk into ERM requires IT to align with business objectives, not operate independently; independence would create silos and increase misalignment. Option B is wrong because no risk management process can eliminate all IT risks; residual risk always remains, and the goal is to manage risk to an acceptable level, not zero. Option C is wrong because integration typically increases the need for well-designed IT controls to address risks that are now visible in the business context; reducing controls would increase exposure.

162
MCQhard

A company is implementing a new access control system. During the project, the IT team updates the system configuration without notifying the risk team. This leads to a temporary misconfiguration that exposes sensitive data. Which process should have been followed to prevent this issue?

A.Control design approval
B.Continuous monitoring
C.Change management process
D.Vendor risk assessment
AnswerC

Change management requires configuration changes to be requested, risk-assessed, approved and tested before implementation. The unannounced update bypassed that control, causing the misconfiguration that exposed sensitive data, so this process directly addresses the stem's root cause.

Why this answer

The change management process is the correct answer because it is the formal ITIL/COBIT-aligned control that ensures all configuration changes to production systems are requested, assessed for risk impact, approved by relevant stakeholders (including the risk team), tested, and documented before implementation. In this scenario, the IT team bypassed this process by updating the access control system configuration without notifying the risk team, which is precisely the failure mode change management is designed to prevent. A properly executed change management workflow would have triggered a risk assessment and impact analysis, flagging the sensitive data exposure before the misconfiguration reached production.

Exam trap

CRISC often tests the distinction between preventive controls (change management) and detective controls (continuous monitoring) — candidates frequently select continuous monitoring because it sounds proactive, but the question asks what should have been followed to prevent the issue, not detect it.

How to eliminate wrong answers

Option A is wrong because control design approval is a one-time or periodic activity that validates the design of a control at the outset — it does not govern ongoing operational changes to a live system's configuration. Option B is wrong because continuous monitoring is a detective control that would have identified the misconfiguration after the fact, not a preventive process that stops unauthorized changes from being deployed. Option D is wrong because vendor risk assessment applies to evaluating third-party suppliers and their risk posture, which is irrelevant here since the change was made internally by the IT team.

163
Multi-Selectmedium

A software company is defining key risk indicators (KRIs) for its cloud service availability risk. The risk owner wants indicators that provide early warning of deteriorating conditions rather than after-the-fact outcomes. Which TWO of the following are the most appropriate leading KRIs for this risk? (Choose two.)

Select 2 answers
A.Average time to restore service after a cloud availability incident.
B.Percentage of virtual machines running without current security patches.
C.Percentage of critical cloud components operating above 80% capacity utilization.
D.Number of unplanned availability outages experienced in the past quarter.
E.Count of single points of failure identified in the cloud architecture during the last review.
AnswersC, E

Capacity utilization above a defined threshold is a leading indicator because it signals approaching resource exhaustion before an outage occurs. It is measurable, tied directly to the availability risk, and provides time to scale infrastructure or rebalance workloads. Leading KRIs such as this give the risk owner an actionable warning window, unlike lagging indicators that only confirm an event after service has already degraded.

Why this answer

Leading KRIs detect conditions that precede an adverse event, giving the risk owner time to act. Capacity utilization thresholds and single points of failure both signal latent availability weaknesses before an outage occurs. Outage counts, mean time to restore, and patch currency either describe past events or relate to a different risk category, so they do not satisfy the requirement for early warning indicators specific to cloud service availability.

Exam trap

The trap here is selecting familiar operational metrics like outage counts or restore times, which are lagging indicators, when the scenario explicitly requires early warning of deteriorating conditions.

164
MCQmedium

During a quarterly control effectiveness test, internal audit finds that a detective control missed 15% of security incidents. The control owner claims this is within the acceptable error rate of 20%. However, the risk practitioner notes that the missed incidents were high-severity. What should the risk practitioner do?

A.Accept the control as effective since it is within the threshold
B.Escalate the findings to senior management with a recommendation to enhance the control
C.Implement a compensating control to cover high-severity incidents
D.Recommend revising the KCI threshold to include severity weighting
AnswerB

The 20% tolerance applies to aggregate error rate, not severity-weighted misses. Because the 15% failures were high-severity incidents, the control's residual risk exceeds appetite, so the practitioner must escalate to senior management with a recommendation to enhance the control.

Why this answer

The risk practitioner should escalate the findings to senior management with a recommendation to enhance the control because the detective control's failure to detect 15% of incidents, while within the 20% acceptable error rate, specifically missed high-severity incidents. High-severity incidents pose a disproportionate risk to the organization, and a control that fails to detect them is not effective in mitigating critical risks, regardless of meeting a generic threshold. Escalation ensures that management is aware of the residual risk and can authorize appropriate enhancements, such as tuning the control's detection logic or implementing additional monitoring for high-severity events.

Exam trap

The CRISC exam often tests the misconception that meeting a quantitative KCI threshold automatically means a control is effective, without considering the qualitative severity of the incidents missed.

How to eliminate wrong answers

Option A is wrong because accepting the control as effective based solely on the 20% threshold ignores the materiality of the missed incidents; a control that misses high-severity incidents is not effective for risk management, even if it meets a quantitative KCI. Option C is wrong because implementing a compensating control is a tactical response that should be directed by management after escalation, not a first action by the risk practitioner, and it bypasses the need to address the root cause of the control's failure to detect high-severity incidents. Option D is wrong because revising the KCI threshold to include severity weighting is a metric adjustment that does not directly address the immediate control deficiency; the practitioner must first report the finding to management, who can then decide on metric changes as part of a broader remediation plan.

165
MCQeasy

A retail company's IT risk manager is preparing a report for the board's audit committee. The report must summarize the current status of the top ten IT risks, the effectiveness of related controls, and any changes since the last quarter. Which of the following is the MOST important quality for this report to possess?

A.It includes every identified IT risk in the register to ensure completeness of disclosure.
B.It provides a balanced view of risk exposure and control effectiveness, including areas where remediation is behind schedule.
C.It focuses exclusively on risks that have decreased since the prior reporting period to show progress.
D.It uses detailed technical terminology to demonstrate the depth of the IT risk team's analysis.
AnswerB

Board reporting must be balanced and transparent, presenting both strengths and weaknesses. If the report omits risks with overdue remediation, the audit committee cannot fulfill its oversight role or challenge management. A balanced view supports informed governance decisions and aligns with the principle that risk reporting should enable stakeholders to understand actual exposure, not just favorable results.

Why this answer

The report's primary purpose is to enable the audit committee to oversee IT risk effectively. That requires a balanced presentation of exposures and control effectiveness, including unfavorable information such as overdue remediation. Reports skewed toward technical detail, only positive trends, or exhaustive risk lists fail to support informed governance and can hide material exposures from those accountable for oversight.

Exam trap

The trap here is equating completeness or technical depth with good board reporting, when the real requirement is balanced, decision-useful information for a governance audience.

166
Multi-Selecthard

A global manufacturing company is designing its IT risk reporting program. The board has requested that reports be actionable, comparable over time, and aligned with the enterprise risk management framework. Which TWO of the following characteristics are MOST important for the IT risk reports to meet these objectives? (Choose two.)

Select 2 answers
A.Reports include only risks that have been fully mitigated to zero residual risk.
B.Reports are customized for each business unit using different risk scales to reflect local priorities.
C.Reports are generated monthly using raw technical vulnerability scan outputs.
D.Reports use consistent risk scoring criteria and definitions across all business units.
E.Reports present risk information in business context, including potential impact on strategic objectives.
AnswersD, E

Consistent scoring criteria and definitions enable comparability across business units and over time. Without a common taxonomy and rating scale, the board cannot reliably compare risks or track trends. This directly supports the requirement for comparable reporting and alignment with the enterprise risk management framework, which depends on standardized risk language and metrics.

Why this answer

Actionable, comparable, and ERM-aligned reporting requires consistent risk scoring criteria and definitions so risks can be compared across units and over time. It also requires presenting risk in business context, linking technical findings to strategic objectives so the board can prioritize. Raw scan outputs and zero-residual-risk filters fail to provide meaningful governance information, and divergent local scales break comparability.

Exam trap

The trap here is assuming that more frequent or more detailed technical reporting automatically improves board-level risk reporting, when comparability and business context are what make reports actionable and ERM-aligned.

167
MCQeasy

A hospital's IT risk manager is preparing a quarterly risk report for the executive committee. The report currently lists 240 technical vulnerabilities with CVSS scores but no business context. The CIO asks for a report that helps executives decide where to allocate limited remediation funding. Which change best aligns the report with risk response and reporting objectives?

A.Report only the total count of vulnerabilities and the percentage remediated within the past quarter.
B.Group vulnerabilities by the business processes and assets they affect, and express exposure in terms of potential impact and likelihood.
C.Sort the vulnerabilities alphabetically by vendor name so the report is easier to navigate.
D.Increase the report's technical depth by including exploit code snippets and packet captures for each vulnerability.
AnswerB

Executive decision-making requires business context, not raw technical counts. Mapping vulnerabilities to the processes and assets they threaten, then expressing exposure through impact and likelihood, lets leaders compare remediation options against organizational objectives and risk appetite. This transforms a technical inventory into actionable risk information, which is the core purpose of risk reporting to senior stakeholders.

Why this answer

Risk reporting to executives must translate technical findings into business language. Grouping vulnerabilities by affected processes and assets and expressing exposure through impact and likelihood gives leaders the context needed to prioritize remediation spending against organizational objectives. Raw counts, technical artifacts, or alphabetical ordering do not support funding decisions because they omit the business consequences that drive risk-based prioritization.

Exam trap

The trap here is equating more technical detail or cleaner formatting with better risk reporting, when executives actually need business impact and likelihood context to make funding decisions.

168
MCQmedium

A risk manager is evaluating a control that addresses a high-risk finding from an internal audit. Which of the following is the MOST important factor in determining whether the control is effective?

A.The vendor's reputation for providing reliable security solutions
B.Key control indicators (KCIs) such as control deficiency rate and test results
C.The cost of the control relative to the asset value
D.The control's alignment with industry best practices
AnswerB

KCIs provide measurable evidence of how reliably the control performs in practise, directly satisfying the audit finding's requirement to prove effectiveness. Deficiency rate and test results reveal whether the control operates consistently, which is the decisive factor when a high-risk finding demands demonstrable, ongoing assurance rather than design intent alone.

Why this answer

B is correct because the effectiveness of a control is determined by its ability to reduce risk to an acceptable level, which is directly measured by key control indicators (KCIs) such as the control deficiency rate and test results. These metrics provide empirical evidence of whether the control is operating as intended and mitigating the identified high-risk finding. Without such performance data, any assessment of effectiveness is speculative.

Exam trap

The trap here is that candidates often confuse 'alignment with best practices' (Option D) with proof of effectiveness, but CRISC requires evidence of actual control performance, not just theoretical compliance.

How to eliminate wrong answers

Option A is wrong because a vendor's reputation does not guarantee that the specific control implementation is effective in the organization's unique environment; effectiveness must be validated through actual testing and monitoring. Option C is wrong because cost relative to asset value is a factor in cost-benefit analysis, not a direct measure of control effectiveness; a low-cost control can be effective, and a high-cost control can fail. Option D is wrong because alignment with industry best practices is a design consideration, not a proof of operational effectiveness; a control may follow best practices but still have implementation flaws or be insufficient for the specific risk context.

169
Multi-Selectmedium

An organization is integrating IT risk into its enterprise risk management (ERM) program. Which TWO of the following are key benefits of this integration?

Select 2 answers
A.Reduces the overall risk appetite of the organization
B.Eliminates the need for separate IT risk reporting
C.Guarantees that all IT risks are mitigated
D.Ensures IT risk is considered in strategic decisions
E.Provides a consistent risk language across the organization
AnswersD, E

Embedding IT risk into ERM feeds technology exposure into enterprise-level planning, so strategic decisions account for IT risk alongside financial and operational risk. This satisfies the integration goal of aligning IT risk with strategic decision-making.

Why this answer

Option D is correct because integrating IT risk into ERM ensures that technology-related exposures are evaluated alongside financial, operational, and strategic risks when leadership makes strategic decisions, so IT risk becomes part of governance rather than a siloed technical concern. Option E is correct because ERM integration establishes common risk terminology, scales, and criteria (for example, shared likelihood/impact definitions and risk appetite statements), giving the whole organization a consistent risk language for identifying, assessing, and reporting IT and non-IT risks. Option A is incorrect because integration does not inherently reduce the organization's risk appetite; risk appetite is set by leadership and integration only helps align IT risk with it.

Option B is incorrect because IT risk still requires its own reporting detail and metrics even when aggregated into ERM. Option C is incorrect because no framework guarantees that all IT risks are mitigated; integration improves visibility and prioritization, not elimination of all risk.

Exam trap

CRISC often tests the difference between benefits of integration (strategic alignment, consistent language) and misconceptions (eliminating reporting, guaranteeing mitigation, reducing appetite) — candidates frequently select absolute statements like 'eliminates' or 'guarantees' which are almost always wrong in risk management contexts.

170
MCQmedium

A critical vendor is being onboarded. The vendor risk appetite policy requires SOC 2 Type II reports for critical vendors. The vendor has provided a SOC 2 Type I report. What should the risk manager do?

A.Request a SOC 2 Type II report from the vendor
B.Downgrade the vendor to a lower tier
C.Exempt the vendor from the requirement
D.Accept the Type I report as sufficient
AnswerA

The policy mandates SOC 2 Type II, which tests control operating effectiveness over a period (typically 6–12 months), whereas Type I only attests design at a single point in time. Requesting the Type II report satisfies the critical vendor requirement directly.

Why this answer

The vendor risk appetite policy explicitly requires SOC 2 Type II reports for critical vendors, and the vendor only provided a Type I report. The risk manager must enforce the policy as written, so the correct action is to request the Type II report from the vendor. Accepting a Type I or exempting the vendor would violate the stated policy and undermine the control.

Exam trap

CRISC often tests the difference between SOC 2 Type I and Type II — candidates may think Type I is 'good enough' or that downgrading the vendor is a pragmatic solution, but the exam expects strict adherence to the stated policy and the correct escalation path.

How to eliminate wrong answers

Option B is wrong because downgrading the vendor to a lower tier is a policy change that has not been authorized and does not address the missing Type II report — it sidesteps the requirement rather than fulfilling it. Option C is wrong because exempting the vendor from the requirement bypasses the risk appetite policy without proper exception approval and would leave a critical vendor unassessed. Option D is wrong because a SOC 2 Type I report only covers the suitability of controls at a point in time, not their operating effectiveness over a period — it does not satisfy a Type II requirement.

171
MCQmedium

A multinational retailer operates in a jurisdiction that requires all payment data to remain within national borders. The risk practitioner is asked to verify that a newly deployed cloud payment service complies with this requirement before it goes live. Which activity best provides this assurance?

A.Reviewing the cloud provider's publicly available service level agreement for uptime commitments.
B.Confirming that the provider holds a current ISO/IEC 27001 certification for its information security management system.
C.Verifying the configured data storage and processing regions and obtaining contractual commitments on data location.
D.Obtaining the cloud provider's general SOC 2 Type II report covering security and availability.
AnswerC

Residency compliance depends on both technical configuration and legal commitment. Confirming that the service is provisioned only in in-country regions, including backups and disaster recovery, demonstrates where data actually resides, while contractual language obligates the provider to maintain that restriction. Together they give direct, verifiable assurance tied to the specific regulatory requirement before go-live.

Why this answer

Data residency obligations are satisfied only by evidence of where data actually resides plus a binding commitment that it stays there. Verifying the provisioned regions, including replication and backup locations, and securing contractual data-location terms directly addresses the regulatory requirement. General certifications and availability agreements speak to security or uptime, not geographic confinement of payment data.

Exam trap

The trap here is accepting a well-known security certification as proof of regulatory data residency compliance.

172
MCQmedium

A financial services firm's IT risk register shows that a legacy payment gateway has a high inherent risk of data breach. Management decides to purchase a cyber insurance policy that covers up to $5 million per incident, while keeping the gateway in production unchanged. Which risk response option has management chosen?

A.Risk mitigation
B.Risk avoidance
C.Risk acceptance
D.Risk transfer
AnswerD

Risk transfer shifts the financial consequence of a risk to a third party, typically through insurance or contractual agreements. By purchasing a cyber insurance policy while leaving the gateway in production, management accepts the operational risk but transfers the financial impact up to $5 million to the insurer. This matches the definition of risk transfer in CRISC risk response.

Why this answer

The scenario describes management choosing to keep the high-risk payment gateway in production while purchasing an insurance policy to cover financial losses. This is risk transfer because the financial impact of a potential breach is shifted to the insurer. Risk mitigation would require implementing controls to reduce likelihood or impact, avoidance would require eliminating the gateway, and acceptance would mean bearing the loss without transferring it.

Exam trap

The trap here is assuming that any risk response involving insurance automatically counts as risk mitigation because it reduces financial exposure, when in fact insurance transfers the financial consequence rather than reducing the underlying likelihood or impact.

173
MCQhard

A multinational retailer's risk committee is reviewing its risk register. The CISO argues that a newly identified vulnerability in the point-of-sale system should be escalated immediately to the board. The risk manager notes that the vulnerability has a low likelihood of exploitation and existing compensating controls reduce the impact to a tolerable level. Which of the following is the MOST appropriate action for the risk manager to take?

A.Document the vulnerability in the risk register with its assessed likelihood, impact, and compensating controls, and report it through the normal risk reporting process.
B.Override the CISO's assessment and remove the vulnerability from the risk register to avoid unnecessary alarm.
C.Escalate the vulnerability to the board because all identified vulnerabilities must be reported to the highest governance body.
D.Close the vulnerability without documentation because the compensating controls already reduce the risk to an acceptable level.
AnswerA

The risk manager should apply the organization's risk assessment criteria, document the vulnerability with its likelihood, impact, and compensating controls, and route it through the standard reporting process. Since the residual risk is tolerable, board escalation is not required. This approach maintains an accurate risk register and respects defined escalation thresholds based on risk appetite.

Why this answer

The risk manager should follow the organization's established risk assessment and reporting criteria. Since the vulnerability has low likelihood and compensating controls keep residual risk within tolerance, it does not meet the threshold for board escalation. Documenting it in the risk register with supporting rationale and reporting through normal channels ensures accurate risk visibility while avoiding unnecessary escalation.

Exam trap

The trap here is equating a CISO's escalation request with a governance requirement, leading to unnecessary board reporting instead of applying the organization's defined risk appetite and escalation thresholds.

174
MCQeasy

When integrating IT risk into the enterprise risk management (ERM) program, what is the PRIMARY benefit?

A.Improved compliance with IT standards
B.Reduced IT operational costs
C.Increased frequency of risk assessments
D.Better alignment of IT risk with business objectives
AnswerD

Embedding IT risk within ERM expresses technical exposures in business-impact terms, so decisions weigh them against strategic objectives rather than treating them as isolated technology issues. This satisfies the stem's primary-benefit requirement, giving leadership a consolidated, objective-aligned view of risk.

Why this answer

Integrating IT risk into ERM ensures that IT risk decisions are directly linked to business strategy and objectives, enabling leadership to prioritize risks that could impact critical business outcomes. This alignment is the primary benefit because it transforms IT risk from a technical concern into a strategic business driver, facilitating better resource allocation and governance.

Exam trap

The trap here is that candidates confuse operational benefits (cost reduction, compliance, or process frequency) with the strategic benefit of business alignment, which is the core purpose of integrating IT risk into ERM.

How to eliminate wrong answers

Option A is wrong because improved compliance with IT standards is a secondary outcome, not the primary benefit; compliance supports risk management but does not inherently align IT risk with business goals. Option B is wrong because reducing IT operational costs is a potential operational efficiency gain, not the core purpose of ERM integration, which focuses on strategic risk alignment rather than cost-cutting. Option C is wrong because increased frequency of risk assessments is a tactical process change that does not guarantee better business alignment; ERM integration prioritizes relevance and decision-making over assessment cadence.

175
Multi-Selecthard

A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)

Select 3 answers
A.Contract compliance reviews
B.Ongoing monitoring via annual reassessments
C.Review of vendor's cyber insurance policy
D.Initial onboarding assessment including security questionnaires
E.Vendor self-assessment without validation
AnswersA, B, D

Contract compliance reviews verify that the vendor's actual security and privacy practises match the contractual obligations agreed at onboarding, providing the assurance the financial services company needs that third-party risk remains within its stated tolerance throughout the relationship.

Why this answer

Option A (Contract compliance reviews) is correct because an effective vendor risk assessment process must verify that the vendor continuously meets the security, privacy, and service-level obligations defined in the contract, ensuring accountability and detecting drift from agreed controls. Option B (Ongoing monitoring via annual reassessments) is correct because vendor risk is not static; periodic reassessments (at least annually, or upon significant changes) are needed to re-evaluate the vendor's security posture, financial health, and compliance status over the life of the relationship. Option D (Initial onboarding assessment including security questionnaires) is correct because due diligence before engagement is a foundational step—standardized questionnaires (e.g., SIG, CAIQ) help evaluate the vendor's controls, data handling practices, and risk level before any data or access is granted.

Option C is not among the marked correct answers because, while reviewing a vendor's cyber insurance policy can be a useful supplementary check, it is not one of the core components of the risk assessment process itself. Option E is not correct because a vendor self-assessment without independent validation is insufficient—it lacks verification and objectivity, which are essential to a credible risk assessment.

Exam trap

The trap here is that candidates often confuse risk transfer mechanisms (like cyber insurance) with risk assessment activities, leading them to select option C, when in fact insurance does not evaluate the vendor's actual security posture or operational risk.

176
MCQhard

An organization uses a Key Control Indicator (KCI) to measure control effectiveness. The KCI shows a control deficiency rate of 12% over the past quarter, exceeding the target threshold of 5%. Which action is MOST appropriate as an initial response?

A.Report the deficiency to the board for oversight
B.Increase the frequency of control testing to monthly
C.Immediately replace the control with a more robust one
D.Conduct a root cause analysis of the deficiencies
AnswerD

A 12% deficiency rate against a 5% threshold signals the control is not operating effectively. Root cause analysis is the appropriate initial step, establishing why deficiencies occur before selecting remediation, avoiding premature fixes that address symptoms rather than the underlying failure.

Why this answer

A high deficiency rate indicates the control is not working as intended. The first step is to investigate root causes to determine necessary remediation.

← PreviousPage 3 of 3 · 176 questions total

Ready to test yourself?

Try a timed practice session using only Risk Response and Reporting questions.