hardMultiple Choice
KRI Threshold Breach: First Step — Validate Data and Investigate Root Cause
A company's key risk indicator (KRI) for 'failed login attempts' has exceeded its threshold by 20%. The control owner reports that a recent firewall change caused false positives. What should the risk practitioner do FIRST?
Quick Answer
The correct first step when a KRI threshold breach occurs is to validate the data and investigate the root cause. This is because a threshold breach may result from a data integrity issue—such as a configuration error or false positive—rather than an actual increase in risk exposure. In the CRISC exam, this scenario tests your understanding of the risk response lifecycle, emphasizing that verification must precede any corrective or escalatory action. A common trap is jumping to remediation or escalation without confirming the breach is real, which wastes resources and undermines the risk management process. Remember the memory tip: “Verify before you rectify”—always confirm the data’s accuracy and the underlying cause before deciding on a response.
⚠ Common exam trap
CRISC often tests the tendency to jump to corrective actions before validating the data, but the correct first step is always to investigate and confirm the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate the KRI data and investigate the root cause
The first step in risk management is to validate the data and understand the root cause before taking action. A KRI exceeding its threshold may be due to false positives from a firewall change, so the practitioner must confirm whether the alert is genuine. Investigating the root cause ensures that any response is based on accurate information and addresses the actual issue, rather than reacting to a symptom.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Validate the KRI data and investigate the root cause
Why this is correct
The firewall change is a plausible alternative cause, so the KRI value itself may be unreliable. Validating the data and tracing the root cause establishes whether the threshold breach is genuine before escalating, avoiding wasted response effort on a false positive.
- ✗
Implement additional controls to reduce failed logins
Why it's wrong here
Adding controls treats the symptom before the reported firewall change is verified; if the spike is false positives, new controls waste effort on logins that never failed. Additional controls suit a confirmed rise in genuine failed authentications, not an unvalidated indicator anomaly.
- ✗
Revert the firewall change immediately
Why it's wrong here
Reverting the firewall change destroys evidence and may reopen the exposure the control was mitigating, before confirming the false-positive claim. Reverting suits a confirmed malicious rule. First, validate whether the KRI spike is genuinely false positives by reviewing the firewall change and log data.
- ✗
Increase the KRI threshold to eliminate false positives
Why it's wrong here
Raising the threshold masks a genuine control failure rather than validating the firewall-induced false positives; the KRI's purpose is to trigger investigation, so the first step is confirming whether the spike is real. Threshold tuning is legitimate only after analysis proves the indicator itself is miscalibrated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has implemented a key risk indicator (KRI) for system availability, with a threshold of 99.5%. The monitoring team observes that availability has dropped to 99.2% for two consecutive months. What is the most appropriate next step?
medium- A.Implement additional redundancy to improve availability.
- B.Increase the threshold to 99.0% to avoid false alarms.
- ✓ C.Notify the risk owner and initiate a root cause analysis.
- D.Escalate immediately to the board of directors.
Why C: A sustained breach of a KRI threshold (99.2% vs. 99.5%) for two consecutive months indicates a systemic issue that requires formal risk management action. The risk owner must be notified to assess the impact, and a root cause analysis (RCA) should be initiated to identify underlying failures—such as network congestion, hardware faults, or software bugs—before any remediation is planned.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.