Courseiva
hardMultiple Choice

KRI Threshold Breach: First Step — Validate Data and Investigate Root Cause

A company's key risk indicator (KRI) for 'failed login attempts' has exceeded its threshold by 20%. The control owner reports that a recent firewall change caused false positives. What should the risk practitioner do FIRST?

Quick Answer

The correct first step when a KRI threshold breach occurs is to validate the data and investigate the root cause. This is because a threshold breach may result from a data integrity issue—such as a configuration error or false positive—rather than an actual increase in risk exposure. In the CRISC exam, this scenario tests your understanding of the risk response lifecycle, emphasizing that verification must precede any corrective or escalatory action. A common trap is jumping to remediation or escalation without confirming the breach is real, which wastes resources and undermines the risk management process. Remember the memory tip: “Verify before you rectify”—always confirm the data’s accuracy and the underlying cause before deciding on a response.

⚠ Common exam trap

CRISC often tests the tendency to jump to corrective actions before validating the data, but the correct first step is always to investigate and confirm the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Validate the KRI data and investigate the root cause

The first step in risk management is to validate the data and understand the root cause before taking action. A KRI exceeding its threshold may be due to false positives from a firewall change, so the practitioner must confirm whether the alert is genuine. Investigating the root cause ensures that any response is based on accurate information and addresses the actual issue, rather than reacting to a symptom.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Validate the KRI data and investigate the root cause

    Why this is correct

    The firewall change is a plausible alternative cause, so the KRI value itself may be unreliable. Validating the data and tracing the root cause establishes whether the threshold breach is genuine before escalating, avoiding wasted response effort on a false positive.

  • ✗

    Implement additional controls to reduce failed logins

    Why it's wrong here

    Adding controls treats the symptom before the reported firewall change is verified; if the spike is false positives, new controls waste effort on logins that never failed. Additional controls suit a confirmed rise in genuine failed authentications, not an unvalidated indicator anomaly.

  • ✗

    Revert the firewall change immediately

    Why it's wrong here

    Reverting the firewall change destroys evidence and may reopen the exposure the control was mitigating, before confirming the false-positive claim. Reverting suits a confirmed malicious rule. First, validate whether the KRI spike is genuinely false positives by reviewing the firewall change and log data.

  • ✗

    Increase the KRI threshold to eliminate false positives

    Why it's wrong here

    Raising the threshold masks a genuine control failure rather than validating the firewall-induced false positives; the KRI's purpose is to trigger investigation, so the first step is confirming whether the spike is real. Threshold tuning is legitimate only after analysis proves the indicator itself is miscalibrated.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has implemented a key risk indicator (KRI) for system availability, with a threshold of 99.5%. The monitoring team observes that availability has dropped to 99.2% for two consecutive months. What is the most appropriate next step?

medium
  • A.Implement additional redundancy to improve availability.
  • B.Increase the threshold to 99.0% to avoid false alarms.
  • ✓ C.Notify the risk owner and initiate a root cause analysis.
  • D.Escalate immediately to the board of directors.

Why C: A sustained breach of a KRI threshold (99.2% vs. 99.5%) for two consecutive months indicates a systemic issue that requires formal risk management action. The risk owner must be notified to assess the impact, and a root cause analysis (RCA) should be initiated to identify underlying failures—such as network congestion, hardware faults, or software bugs—before any remediation is planned.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.