Courseiva

CCNA Crisc Risk Identification Questions

75 of 146 questions · Page 1/2 · Crisc Risk Identification topic · Answers revealed

1
MCQmedium

A risk practitioner is updating the risk register after a third-party security incident. Which of the following is the MOST important information to include in the risk register entry for this third-party risk?

A.The remediation plan and the risk owner's signature
B.The date of the incident and the amount of data compromised
C.A description of the risk event, its impact, and the response taken
D.The name and contact details of the third party
AnswerC

Recording the risk event, its impact and the response taken captures what occurred, the consequence and the mitigation, enabling accurate risk register updates and future comparison. This satisfies the stem's need for the most important entry content after a third-party incident.

Why this answer

A risk register entry must capture the essential elements of the risk: a description of the risk event, its potential or realized impact, and the response taken (or planned). For a third-party security incident, documenting what happened, how it affects the organization, and what was done provides the basis for risk tracking, reporting, and future decision-making. This is the core content that makes the register actionable.

Exam trap

CRISC often tests the distinction between incident details (dates, data volumes, contacts) and the structured risk information (description, impact, response) that belongs in a risk register — candidates may pick incident specifics over the risk-centric content.

How to eliminate wrong answers

Option A is wrong because a remediation plan and signature are important governance artifacts but secondary to the fundamental risk description, impact, and response — without those, the plan lacks context. Option B is wrong because incident date and data volume are incident-specific details, not the structured risk information needed for ongoing risk management and prioritization. Option D is wrong because third-party contact details are vendor management data, not risk register content — they belong in a vendor inventory or contract repository.

2
MCQeasy

An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?

A.Operational risk
B.Compliance risk
C.Financial risk
D.Strategic risk
AnswerB

Regulatory fines for breaching data protection laws arise from failing to meet legal and regulatory obligations, which is precisely the scope of compliance risk. Other categories such as operational or strategic risk do not centre on statutory penalties for non-compliance.

Why this answer

Regulatory fines for non-compliance with data protection laws fall squarely under compliance risk, which encompasses the risk of violating laws, regulations, contracts, or standards and the resulting penalties, sanctions, or legal exposure. Data protection regulations such as GDPR or CCPA are compliance obligations, so the associated fine risk is classified as compliance risk.

Exam trap

CRISC often tests whether candidates can separate the cause of a risk from its consequence — the trap is choosing operational risk because a data breach is operational, when the question asks about the risk of regulatory fines, which is compliance risk.

How to eliminate wrong answers

Option A is wrong because operational risk covers failures in people, processes, and systems (for example, outages, errors, fraud) rather than legal or regulatory violations. Option C is wrong because financial risk concerns monetary losses from market movements, credit defaults, or liquidity issues, not regulatory penalties. Option D is wrong because strategic risk relates to decisions that affect the organization's ability to achieve its long-term objectives, not to legal non-compliance.

3
MCQmedium

A risk practitioner is reviewing the risk register of an e-commerce company and finds that several risks were identified only through past incident reports. The chief risk officer asks how to broaden risk identification to surface risks that have not yet materialized. Which of the following approaches is MOST effective for identifying emerging and previously unconsidered risks?

A.Increase the frequency of reviewing historical incident tickets to capture patterns in past outages.
B.Track the number of open vulnerabilities in the vulnerability management system and escalate when thresholds are exceeded.
C.Rely on the annual external audit findings to identify control weaknesses that could become risks.
D.Conduct scenario analysis workshops with business, technology, and external stakeholders to explore plausible future events.
AnswerD

Scenario analysis workshops bring together diverse perspectives to construct plausible future events that may not appear in incident history. For an e-commerce company, this could surface risks such as payment provider outages, new privacy regulations, or generative AI abuse in customer service. The technique is forward-looking and structured, making it effective for emerging risk identification. Outputs can be added to the risk register with likelihood and impact estimates for treatment decisions.

Why this answer

Scenario analysis workshops are forward-looking and draw on cross-functional and external perspectives to imagine plausible events that have no internal incident history. They are well suited to surfacing emerging risks such as regulatory shifts, technology changes, and third-party dependencies. Historical incident reviews, audit findings, and vulnerability counts are valuable but backward-looking or narrow in scope, so they cannot fulfill the goal of identifying risks that have not yet materialized.

Exam trap

The trap here is choosing a familiar internal data source like incident tickets or audit findings, which only reflects risks already experienced or in scope, rather than a forward-looking technique for unknown risks.

4
Multi-Selectmedium

A risk practitioner is performing an external threat environment analysis for a retail chain that accepts card payments. The practitioner wants to identify which external factors should be treated as inputs to the likelihood of payment card data compromise. Which TWO of the following are the MOST appropriate inputs? (Choose two.)

Select 2 answers
A.The percentage of the chain's stores that have completed a recent internal audit.
B.The prevalence and activity level of organized criminal groups that monetize stolen card data.
C.The turnover rate among store cashiers and the adequacy of their security awareness training.
D.Published reports of new skimming and shimming techniques observed at comparable retailers.
E.The number of point-of-sale terminals the chain operates across all stores.
AnswersB, D

Organized criminal activity that monetizes stolen card data is a direct external driver of the probability that the retail chain will be attacked. It reflects adversary capability and intent in the specific ecosystem where card data has resale value, so it belongs in the likelihood assessment for payment card compromise. Excluding it would leave the analysis anchored only in internal conditions and blind to the demand side of the threat.

Why this answer

External threat inputs describe conditions outside the organization's control that shape how likely an attack is. Organized criminal activity that monetizes card data, and published reports of skimming and shimming techniques used against comparable retailers, both reflect adversary capability and intent in the card payment ecosystem. Terminal counts, cashier turnover, and audit completion are internal attributes better suited to vulnerability, impact, or assurance analysis.

Exam trap

The trap here is treating internal scale and control metrics as threat environment factors simply because they are easy to measure.

5
MCQmedium

During the risk identification process, an IT risk universe is defined. Which of the following BEST describes the purpose of an IT risk universe?

A.A list of all known vulnerabilities in the organization's IT systems
B.A database of past security incidents and their root causes
C.A framework for categorizing risks into strategic, operational, financial, and compliance
D.A comprehensive inventory of all potential IT risks facing the organization
AnswerD

The IT risk universe is the structured catalogue of every plausible IT risk that could affect the organisation, forming the scope from which individual risks are later identified, assessed and prioritised. It ensures risk identification is comprehensive rather than ad hoc.

Why this answer

An IT risk universe is a comprehensive inventory of all potential IT risks facing the organization — it is the master list from which risk assessments, prioritization, and treatment decisions are drawn. It defines the scope of what the organization considers 'in scope' for IT risk management, ensuring no material risk category is overlooked. It is not limited to vulnerabilities, incidents, or a single categorization scheme.

Exam trap

CRISC often tests the distinction between the risk universe and its inputs — candidates confuse it with a vulnerability list or incident database, but the universe is the comprehensive forward-looking inventory of all potential IT risks.

How to eliminate wrong answers

Option A is wrong because a list of known vulnerabilities is a vulnerability register or scan output, which is a subset of the risk universe — vulnerabilities are one input, not the universe itself. Option B is wrong because a database of past incidents is an incident register or historical log; the risk universe is forward-looking and includes risks that have not yet materialized. Option C is wrong because categorizing risks into strategic, operational, financial, and compliance is a taxonomy or framework applied to risks, not the universe itself — the universe is the inventory, and categorization is one way to organize it.

6
MCQmedium

A risk practitioner is categorizing IT risks for a manufacturing company. Which of the following risks would be classified as an 'operational' IT risk?

A.Risk of financial loss from a ransomware payment
B.Risk of non-compliance with GDPR for customer data stored in the EU
C.Risk of production line downtime due to a server failure
D.Risk of reputational damage from a data breach
AnswerC

Server failure causing production line downtime is an operational IT risk because it concerns the day-to-day reliability and availability of systems supporting business processes. This satisfies the stem's operational category, which covers disruptions to service delivery and processing, rather than strategic, compliance or external risk domains.

Why this answer

Operational IT risks relate to the day-to-day functioning of IT systems and processes. Production line downtime due to a system failure directly impacts operations.

7
MCQmedium

A risk practitioner is estimating the likelihood of a ransomware event for a manufacturing firm. The firm has endpoint protection, network segmentation, and offline backups, but the practitioner learns that a third-party maintenance vendor has persistent remote access with shared credentials and no multi-factor authentication. Which of the following BEST explains how this finding should affect the likelihood estimate?

A.Likelihood should be set to the industry average for manufacturing ransomware incidents.
B.Likelihood should decrease because the firm's existing controls are strong.
C.Likelihood should increase because the vendor access path provides an unmitigated entry point.
D.Likelihood should remain unchanged because backup availability determines ransomware outcomes.
AnswerC

Shared credentials without multi-factor authentication create a low-effort, persistent entry point that attackers commonly exploit in supply chain ransomware incidents. Because this path bypasses the firm's endpoint and segmentation controls, it materially raises the probability that an attacker can establish a foothold and escalate. The finding is a direct likelihood driver, so the estimate should rise to reflect the expanded attack surface.

Why this answer

Likelihood reflects how probable an event is given the threat environment and existing controls. The vendor's shared credentials and lack of multi-factor authentication create a persistent, low-effort entry point that bypasses internal defenses, so it raises the probability of a successful ransomware intrusion. Backup availability and industry averages address recovery and context, not this specific exposure.

Exam trap

The trap here is letting strong internal controls or backup availability dominate the likelihood judgment while overlooking a third-party access path that sidesteps those controls.

8
Multi-Selectmedium

When developing realistic risk scenarios, which THREE components are essential according to the ISACA risk scenario template?

Select 3 answers
A.Threat actor
B.Asset/resource
C.Mitigation cost
D.Threat event
E.Detection speed
AnswersA, B, D

The threat actor is the party who could exploit a vulnerability or trigger the event. Naming a specific actor — insider, criminal group, nation-state — grounds the scenario in a realistic capability and intent, which is essential for estimating likelihood within the ISACA risk scenario template.

Why this answer

According to the ISACA risk scenario template, a realistic risk scenario must combine a threat actor (option A), the asset/resource at risk (option B), and the threat event itself (option D). The threat actor identifies who or what could cause harm (e.g., an external attacker, insider, or natural force), the asset/resource specifies what is being targeted or affected (e.g., a database, service, or facility), and the threat event describes the specific action or occurrence that exploits a vulnerability (e.g., SQL injection, ransomware execution, or fire). Together these three elements form the core structure of an ISACA risk scenario, enabling consistent identification, analysis, and communication of risk.

Mitigation cost (option C) is a response/treatment consideration, not a defining component of the scenario itself, and detection speed (option E) is a control effectiveness metric rather than an essential scenario element.

Exam trap

CRISC often tests whether candidates confuse the structural components of a risk scenario (actor, asset, event) with downstream risk-management activities such as mitigation cost or detection capability, which are not part of the template.

9
Multi-Selectmedium

A risk practitioner is identifying IT risk scenarios for a new e-commerce platform. The platform will process credit card payments and store customer data. Which TWO of the following are examples of external threats that should be considered in the risk identification process? (Choose two.)

Select 2 answers
A.Organized criminal groups targeting payment card data.
B.Hacktivists protesting the company's business practices.
C.Third-party service providers with inadequate security controls.
D.Disgruntled employees with access to customer databases.
E.Software bugs in the e-commerce application code.
AnswersA, B

Organized criminal groups are external threats motivated by financial gain. They often target e-commerce platforms to steal credit card data. This is a classic external threat that must be included in risk identification for a payment-processing platform. Their high capability and resources make them a significant risk factor.

Why this answer

External threats are actors or events outside the organization that can cause harm. Organized criminal groups and hacktivists are both external threat actors with different motivations. They should be included in risk identification for an e-commerce platform.

The other options describe internal threats or vulnerabilities, which are not external threats.

Exam trap

The trap here is conflating vulnerabilities, such as software bugs or weak third-party controls, with external threats, leading to incorrect categorization.

10
MCQeasy

Which of the following is an example of a 'configuration vulnerability' that should be identified during vulnerability assessment?

A.A buffer overflow in a custom application
B.An SQL injection flaw in a web form
C.Default administrative passwords left unchanged on a network device
D.Missing security patches on a server
AnswerC

Unchanged default administrative passwords on network devices constitute a configuration vulnerability because the weakness arises from how the device was set up, not from a software defect. This satisfies the stem's requirement by exposing an exploitable misconfiguration that vulnerability assessment should identify, since attackers routinely scan for vendor-default credentials.

Why this answer

A configuration vulnerability arises from improper system settings. Leaving default passwords unchanged is a classic configuration weakness.

11
MCQhard

A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?

A.A planned system upgrade may cause two hours of downtime during maintenance window
B.A vendor is late in delivering a software patch for a low-severity bug
C.A new cloud service may inadvertently expose customer PII due to misconfiguration
D.An employee mistakenly deletes a non-critical test database
AnswerC

Misconfiguration exposing customer PII breaches data-protection obligations, so it sits squarely in the low-tolerance compliance category rather than the moderate operational risk the company accepts. That mismatch with the stated risk appetite triggers immediate escalation to senior management, since regulatory penalties and notification duties cannot be absorbed within the accepted operational threshold.

Why this answer

The risk appetite statement explicitly declares low tolerance for compliance risk, and exposing customer PII triggers regulatory/legal obligations (e.g., GDPR, CCPA, contractual data-protection clauses). Because compliance risk is the organization's stated low-tolerance area, any scenario with potential PII exposure must be escalated immediately to senior management. The other scenarios fall within the 'moderate operational risk' appetite the company has already accepted.

Exam trap

CRISC often tests the distinction between risk appetite/tolerance statements and incident severity — candidates pick the most dramatic-sounding operational event instead of matching the scenario to the stated low-tolerance category (compliance).

How to eliminate wrong answers

Option A is wrong because planned maintenance downtime is a routine operational risk that falls within the company's stated moderate operational risk appetite. Option B is wrong because a late patch for a low-severity bug is a minor operational/supply-chain issue, not a compliance breach. Option D is wrong because deleting a non-critical test database is an operational incident with no regulatory or PII implications and is within the accepted operational risk tolerance.

12
MCQmedium

A risk manager is categorizing IT risks. Which risk category would a potential fine for violating GDPR be assigned to?

A.Operational
B.Financial
C.Strategic
D.Compliance
AnswerD

A GDPR fine arises from failing to meet legal and regulatory obligations, so it belongs in the compliance risk category. Compliance risk covers breaches of laws, regulations and standards, distinct from operational, strategic or technology risk categories.

Why this answer

A fine for violating GDPR is a direct consequence of failing to meet a legal/regulatory obligation, which is the definition of compliance risk. Compliance risk encompasses penalties, sanctions, and legal actions arising from non-conformance with laws, regulations, and standards. Although the fine is monetary, its root cause is regulatory non-compliance, so it belongs in the compliance category.

Exam trap

CRISC often tests categorization by root cause versus consequence — candidates see 'fine' and pick Financial, ignoring that the originating obligation is regulatory (Compliance).

How to eliminate wrong answers

Option A is wrong because operational risk covers failures in processes, people, systems, or external events — not regulatory penalties. Option B is wrong because while a fine is a financial loss, categorizing by consequence rather than cause misclassifies the risk; CRISC categorizes by source/root cause. Option C is wrong because strategic risk relates to business model, competitive position, or long-term objectives, not regulatory enforcement.

13
MCQmedium

A risk practitioner at a regional bank is building a risk register and needs to classify each identified risk by its origin. The practitioner documents a risk that a critical payment switch will fail during peak transaction volume because a fan assembly in the switch has exceeded its mean time between failures. Which risk category BEST applies to this entry?

A.IT operational risk
B.Inherent risk
C.Strategic risk
D.Compliance risk
AnswerA

Hardware component failure that disrupts transaction processing is an IT operational risk because it arises from the day-to-day running of technology infrastructure rather than from a strategic, compliance, or external event. Classifying it here lets the bank aggregate similar availability risks, apply preventive maintenance controls, and measure the residual exposure after those controls, which is exactly what the risk register entry requires.

Why this answer

The scenario describes a loss event caused by the routine operation of technology infrastructure, so it belongs in the IT operational risk category. That classification supports aggregation with other availability and performance risks, drives appropriate preventive controls such as condition-based maintenance and redundant components, and allows residual risk to be measured after treatment. Strategic, compliance, and inherent risk labels describe different dimensions and would misdirect the response.

Exam trap

The trap here is assuming that any risk affecting a critical system must be strategic or compliance-related, when the actual driver is routine technology operations.

14
MCQmedium

A risk practitioner is conducting an IT risk assessment for a retail bank's new mobile payment application. The threat landscape includes hacktivists, organized crime, and insiders. The practitioner needs to estimate the likelihood of a data breach. Which of the following factors is MOST important to consider when estimating likelihood?

A.The industry benchmarks for mobile payment application security spending.
B.The number of vulnerabilities identified in the application's source code.
C.The financial impact of a potential data breach on the bank's reputation.
D.The effectiveness of existing controls and the threat's capability to exploit them.
AnswerD

Likelihood is a function of threat capability, motivation, and the effectiveness of controls. For a mobile payment app, controls like encryption and authentication reduce exploitability. Assessing both the threat's ability to bypass controls and control strength provides a realistic likelihood estimate, making this the most critical factor in this scenario.

Why this answer

Likelihood estimation in IT risk assessment depends on threat capability and motivation relative to control effectiveness. For a mobile payment app, threats like organized crime have high capability, but robust controls can reduce likelihood. The correct factor directly addresses this relationship, while others focus on impact, vulnerability count, or benchmarks that do not provide a direct likelihood estimate.

Exam trap

The trap here is confusing impact-related factors, such as financial loss or reputation, with likelihood estimation, leading to an incorrect risk prioritization.

15
MCQmedium

An organization has a risk register that includes risks related to regulatory compliance, such as GDPR and SOX. The risk practitioner is now categorizing these risks. Which risk category would BEST fit these compliance-related risks?

A.Financial risk
B.Operational risk
C.Compliance risk
D.Strategic risk
AnswerC

GDPR and SOX obligations are statutory and regulatory requirements, and the axis distinguishing compliance risk is exposure to legal or regulatory sanction. Grouping these register entries here reflects their shared driver: failure to meet mandated external obligations.

Why this answer

GDPR and SOX are laws and regulations, so risks tied to them are by definition compliance risks. Compliance risk captures exposure to legal penalties, sanctions, and regulatory action from failing to meet statutory or contractual obligations. Grouping GDPR and SOX under compliance risk aligns with standard CRISC risk taxonomy.

Exam trap

CRISC often tests whether candidates categorize by the nature of the obligation (regulatory) versus the business area affected — picking Operational because 'IT runs the controls' is the common mistake.

How to eliminate wrong answers

Option A is wrong because financial risk covers market, credit, liquidity, and monetary loss exposures — not the legal obligations themselves. Option B is wrong because operational risk addresses process, people, and system failures, not regulatory mandates. Option D is wrong because strategic risk concerns long-term business direction, competitive positioning, and mission alignment, not statutory compliance.

16
MCQeasy

An organization uses threat intelligence feeds from an Information Sharing and Analysis Center (ISAC). What is the PRIMARY benefit of using ISACs?

A.They facilitate sharing of sector-specific threat intelligence
B.They provide free antivirus software to members
C.They offer legally binding threat response protocols
D.They replace the need for internal threat hunting
AnswerA

ISACs collect and distribute threat intelligence specific to a sector, letting members benefit from incidents and indicators observed by peers. This sector-specific sharing satisfies the primary benefit constraint, delivering contextual, relevant intelligence beyond generic feeds.

Why this answer

ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that collect, analyze, and disseminate threat intelligence relevant to a particular industry (e.g., FS-ISAC for financial services, H-ISAC for healthcare). Their primary value is enabling members to share timely, sector-relevant threat indicators and defensive guidance that they could not easily obtain individually. This directly matches option A.

Exam trap

CRISC often tests the distinction between information sharing bodies and operational controls — candidates pick answers that overstate ISAC authority (legally binding protocols) or understate their scope (replacing internal threat hunting).

How to eliminate wrong answers

Option B is wrong because ISACs do not distribute antivirus software — they share intelligence, indicators, and best practices, not endpoint security products. Option C is wrong because ISACs do not issue legally binding threat response protocols; they provide voluntary information sharing and guidance, and their charters are typically non-regulatory. Option D is wrong because ISAC membership supplements, not replaces, internal threat hunting — organizations still need their own detection and response capabilities to act on shared intelligence.

17
MCQhard

A multinational bank is assessing the risk of a distributed denial-of-service (DDoS) attack on its online banking platform. The risk practitioner has identified that the platform is hosted in a single data center with no redundancy. Which of the following BEST describes the relationship between the threat, vulnerability, and risk in this scenario?

A.The DDoS attack is the threat, the single data center is the vulnerability, and the risk is the potential service outage.
B.The DDoS attack is the risk, the single data center is the threat, and the potential service outage is the vulnerability.
C.The DDoS attack is the vulnerability, the single data center is the threat, and the risk is the potential service outage.
D.The DDoS attack is the threat, the single data center is the risk, and the potential service outage is the vulnerability.
AnswerA

A threat is any potential cause of harm; here, the DDoS attack is the threat. A vulnerability is a weakness that can be exploited; the lack of redundancy in a single data center is the vulnerability. Risk is the combination of the probability of an event and its impact; the potential service outage is the risk. This mapping is correct and aligns with ISACA definitions.

Why this answer

In risk terminology, a threat is something that can exploit a vulnerability, a vulnerability is a weakness, and risk is the potential for loss when a threat exploits a vulnerability. Here, the DDoS attack is the threat, the single data center is the vulnerability, and the potential service outage is the risk. Correctly distinguishing these elements is fundamental to IT risk identification and ensures appropriate treatment.

Exam trap

The trap here is mixing up the definitions of threat, vulnerability, and risk, often by treating the attack as the vulnerability or the weakness as the risk.

18
MCQhard

A risk manager at a healthcare organization is identifying risks related to the use of Internet of Medical Things (IoMT) devices. The organization has a large number of legacy devices that cannot be patched. Which of the following is the MOST significant risk factor to consider when assessing the risk of a ransomware attack?

A.The devices are connected to the network without segmentation.
B.The devices generate a large volume of data that is stored indefinitely.
C.The devices use default administrative passwords that are rarely changed.
D.The devices are manufactured by various vendors with different security standards.
AnswerA

Unsegmented networks allow ransomware to spread laterally from IoMT devices to critical systems. Legacy devices that cannot be patched are vulnerable, and without segmentation, they become entry points for attackers. This significantly increases the likelihood and impact of a ransomware attack, making it the most significant risk factor in this scenario.

Why this answer

The most significant risk factor is the lack of network segmentation, which allows ransomware to spread from vulnerable IoMT devices to critical systems. Legacy devices that cannot be patched are inherently risky, but segmentation can contain the impact. Other factors like default passwords or vendor diversity are important but can be addressed more readily than architectural segmentation.

Exam trap

The trap here is focusing on easily fixable vulnerabilities like default passwords while overlooking the systemic risk created by unpatched devices on a flat network.

19
MCQmedium

A risk practitioner at a regional bank is building risk scenarios for the new mobile check deposit feature. The team has identified the event 'attackers exploit a vulnerability in the image processing library to inject malicious code.' Which of the following BEST describes the element that is missing from this risk scenario?

A.The threat community profile, including capability and intent.
B.The control environment currently in place to mitigate the event.
C.The asset or business process affected and the resulting business impact.
D.The regulatory requirement that mandates protection of customer data.
AnswerC

A complete risk scenario pairs a threat event with the asset or process it affects and the resulting business impact. The statement describes only the threat and vulnerability; without naming the affected asset, such as the customer deposit process or the image processing service, and the impact, such as fraudulent deposits or regulatory exposure, the scenario cannot be evaluated or prioritized.

Why this answer

ISACA describes a risk scenario as a threat event acting on an asset or process and producing a business impact. The stem supplies the threat and vulnerability but omits the affected asset and consequence, so the practitioner cannot assess likelihood or impact meaningfully. Adding the asset and impact makes the scenario actionable for risk analysis and prioritization.

Exam trap

The trap here is assuming a detailed threat description is enough to form a complete risk scenario, when the asset and business impact are equally required components.

20
MCQhard

A risk practitioner is assessing the likelihood that a nation-state actor will exfiltrate intellectual property from an aerospace manufacturer. The practitioner wants to express likelihood using a factor that reflects how attractive the manufacturer is as a target relative to its peers. Which approach BEST supports this?

A.Assess likelihood by the number of open vulnerabilities rated critical in the last external scan.
B.Derive likelihood from the annualized loss expectancy calculated for previous intellectual property incidents.
C.Score likelihood using a threat attractiveness rating that weighs sector, data value, and geopolitical relevance.
D.Rate likelihood using the historical frequency of malware infections recorded by the endpoint protection platform.
AnswerC

A threat attractiveness rating expresses how desirable the organization is as a target by combining factors such as industry sector, the value of the intellectual property it holds, and its geopolitical profile. This directly captures the adversary's motivation to select this manufacturer over other targets, which is the appropriate likelihood input for a deliberate, actor-driven threat, and it remains stable enough to track as the risk landscape evolves.

Why this answer

Likelihood for a deliberate, actor-driven threat should reflect the adversary's intent and the target's relative appeal, not the volume of incidental events or control gaps. A threat attractiveness rating built from sector, data value, and geopolitical relevance captures why a nation-state would choose this aerospace manufacturer, keeps the likelihood factor independent of impact and vulnerability inputs, and gives a stable basis for comparing the same risk over successive assessment cycles.

Exam trap

The trap here is substituting easily counted control metrics, such as malware hits or scan findings, for a judgment about adversary targeting intent.

21
MCQmedium

An organization's board has set a risk appetite statement that says: 'We accept moderate levels of operational risk but will not tolerate any compliance violations.' During risk identification, which type of risk should be given the HIGHEST priority?

A.Reputational risks
B.Compliance risks
C.Operational risks
D.Strategic risks
AnswerB

The board's statement explicitly declares zero tolerance for compliance violations, making this the binding constraint. Unlike operational risk, where moderate exposure is accepted, any compliance breach exceeds the stated appetite, so compliance risks demand the highest prioritisation during identification.

Why this answer

The board's risk appetite statement explicitly states zero tolerance for compliance violations, meaning any compliance risk falls outside the acceptable risk threshold. Since risk appetite defines the boundaries for risk-taking, risks that breach this threshold must be prioritized highest. Compliance risks directly violate the stated appetite, so they require immediate attention and mitigation.

This aligns with CRISC principles that risk prioritization must align with organizational risk appetite.

Exam trap

CRISC often tests the misconception that operational risks are always the highest priority because they are most frequent, but the key is to align with the stated risk appetite, which here explicitly excludes compliance risks.

How to eliminate wrong answers

Option A is wrong because reputational risks, while important, are not explicitly prohibited by the risk appetite statement; the statement only sets a moderate acceptance for operational risk and zero tolerance for compliance. Option C is wrong because operational risks are explicitly accepted at moderate levels, so they are not the highest priority. Option D is wrong because strategic risks are not mentioned in the risk appetite statement and thus do not directly violate the stated tolerance levels.

22
Multi-Selecthard

A risk practitioner is assessing the effectiveness of the control environment supporting an online trading platform. Management asserts that controls are mature, but the practitioner must determine which activities constitute control monitoring rather than one-time assurance. Which TWO of the following activities are examples of ongoing control monitoring? (Choose two.)

Select 2 answers
A.Reviewing a monthly dashboard of failed login attempts and account lockouts against defined thresholds.
B.Documenting the control environment in the risk register during the annual risk assessment cycle.
C.Performing a control self-assessment workshop with process owners at the start of the fiscal year.
D.Commissioning an external penetration test of the trading platform once every two years.
E.Tracking remediation of open findings from audits and assessments in a centralized register with owners and due dates.
AnswersA, E

Reviewing a recurring dashboard against predefined thresholds is a continuous monitoring activity that detects control degradation or anomalous conditions as they emerge. Because it operates on a defined cadence with escalation criteria, it provides timely evidence that authentication controls continue to function and allows corrective action before losses accumulate. This is characteristic of monitoring rather than a point-in-time audit or assessment performed once and then shelved.

Why this answer

Ongoing monitoring relies on recurring observation with defined thresholds, ownership, and escalation. Reviewing authentication dashboards against thresholds and tracking remediation of open findings both provide continuous visibility into whether controls operate as intended and allow timely intervention. Periodic penetration tests, annual self-assessments, and register documentation are point-in-time or record-keeping activities that do not deliver the continuous feedback loop monitoring requires.

Exam trap

The trap here is treating any control-related activity, such as documentation or an annual self-assessment, as monitoring even though it lacks recurring observation, thresholds, and escalation.

23
MCQhard

During a threat modeling exercise using the STRIDE methodology, a security analyst identifies a threat where an attacker can modify data in transit between a web server and database. Which STRIDE category does this threat belong to?

A.Repudiation
B.Tampering
C.Spoofing
D.Information Disclosure
AnswerB

Tampering covers unauthorised modification of data or systems, including data altered in transit between web server and database. The threat's defining characteristic is integrity violation through modification, not interception or disclosure, which would fall under Information Disclosure.

Why this answer

Tampering involves unauthorized modification of data, which is the 'T' in STRIDE.

24
Multi-Selectmedium

A risk practitioner is identifying risks for an organization that has adopted a bring-your-own-device policy for remote workers. The practitioner wants to document vulnerabilities that increase the likelihood of a data loss event. Which TWO of the following are MOST appropriately classified as vulnerabilities in this scenario? (Choose two.)

Select 2 answers
A.Employees store corporate documents in unmanaged personal cloud storage accounts.
B.A nation-state group is targeting the organization's industry sector.
C.The organization's cyber insurance policy excludes unencrypted device losses.
D.A remote worker's lost laptop could cost the organization regulatory fines.
E.Personal devices lack mandatory full-disk encryption and mobile device management enrollment.
AnswersA, E

This is a vulnerability because it creates an uncontrolled data repository outside the organization's visibility and protection, directly increasing the likelihood that sensitive information is exposed or lost. It reflects a weakness in data handling practices and control coverage rather than an external threat or a business impact. Documenting it as a vulnerability supports targeted controls such as data loss prevention and acceptable use enforcement.

Why this answer

Vulnerabilities are internal weaknesses or control gaps that a threat can exploit to cause harm. Storing corporate documents in unmanaged personal cloud accounts and running personal devices without encryption or management enrollment are both such weaknesses, and each directly raises the likelihood of data loss. The other statements describe a threat actor, a business impact, and an insurance condition, which belong to different components of the risk equation.

Exam trap

The trap here is treating anything undesirable related to the BYOD program, such as a threat actor, an impact statement, or an insurance exclusion, as a vulnerability instead of isolating the internal control weaknesses.

25
MCQmedium

Which of the following BEST describes the difference between a threat actor who is a 'hacktivist' and one who is an 'organized crime' actor?

A.Hacktivists are motivated by ideology; organized crime actors are motivated by financial gain
B.Hacktivists target only government entities; organized crime targets only businesses
C.Hacktivists are always insiders; organized crime actors are external
D.Hacktivists use advanced persistent threats (APTs); organized crime uses commodity malware
AnswerA

Hacktivists pursue ideological or political ends, attacking targets to publicise a cause. Organised crime actors pursue financial gain, typically through ransomware, fraud or data theft. The axis of difference is motivation, which shapes target selection, persistence and monetisation, making this the best description.

Why this answer

The correct answer is A because it accurately captures the fundamental distinction between hacktivists and organized crime actors: motivation. Hacktivists are driven by ideological, political, or social causes, and their attacks are often symbolic or aimed at raising awareness. Organized crime actors, on the other hand, are primarily motivated by financial gain, engaging in activities like ransomware, fraud, and data theft for profit.

This motivational difference is a core concept in risk management, as it influences the threat's targeting, persistence, and methods.

Exam trap

CRISC often tests the ability to distinguish threat actors by their primary motivation, and candidates may incorrectly focus on targeting or sophistication rather than the underlying driver of ideology versus financial gain.

How to eliminate wrong answers

Option B is wrong because it incorrectly limits hacktivists to targeting only government entities and organized crime to only businesses; in reality, hacktivists can target any organization that opposes their ideology, and organized crime can target any entity that yields financial return. Option C is wrong because it falsely claims hacktivists are always insiders; while insiders can be hacktivists, most hacktivists are external actors, and organized crime actors are not exclusively external. Option D is wrong because it inaccurately associates hacktivists with advanced persistent threats (APTs) and organized crime with commodity malware; APTs are typically state-sponsored or highly sophisticated groups, while hacktivists often use simpler tools, and organized crime may use a mix of commodity and custom malware.

26
MCQhard

A risk practitioner at a payments processor is reviewing the organization's risk register and notices that several risk entries describe only the consequence, such as 'customer data is exposed.' The practitioner wants each entry to follow the ISACA risk scenario structure. Which of the following should the practitioner add to each entry to complete the scenario?

A.A regulatory citation and an audit finding reference
B.A risk score and a heat map color
C.A control owner and a remediation due date
D.A threat source and an event, with the asset and consequence
AnswerD

The ISACA risk scenario structure combines a threat source, an event, an asset or resource affected, and the resulting consequence. The current entries capture only consequence, so adding the threat source, the event itself, and the affected asset completes the scenario. This makes the register entry testable and lets the practitioner assess likelihood and impact consistently across entries.

Why this answer

ISACA risk scenarios are built from a threat source, an event, the asset or resource at risk, and the consequence. The existing register entries stop at consequence, so the practitioner must add the missing threat source, event, and affected asset to make each scenario complete and analyzable. Ratings, remediation fields, and compliance references are downstream or supplementary information, not structural components of the scenario.

Exam trap

The trap here is treating a risk score or remediation detail as the missing scenario element, when the scenario is incomplete because it lacks a threat source, event, and asset description.

27
MCQmedium

During a vulnerability assessment, a risk practitioner identifies that a web application is vulnerable to SQL injection, which is listed in the OWASP Top 10. Which type of vulnerability identification technique MOST likely discovered this issue?

A.SAST (Static Application Security Testing)
B.CIS Benchmarks comparison
C.DAST (Dynamic Application Security Testing)
D.DISA STIG scanning
AnswerC

DAST tests a running application from the outside, sending crafted inputs and observing responses, so it detects SQL injection through runtime behaviour. It satisfies the scenario by identifying the exploitable injection flaw in the deployed web application, matching the OWASP Top 10 entry.

Why this answer

DAST (Dynamic Application Security Testing) is correct because it tests a running application from the outside by simulating attacks, such as injecting malicious SQL payloads into input fields, which directly reveals SQL injection vulnerabilities. SQL injection is a runtime flaw that manifests when untrusted input is improperly handled by the application and database, so it is most reliably discovered through dynamic testing. SAST, by contrast, analyzes source code statically and may miss or misidentify injection flaws due to complex data flows.

Thus, DAST is the technique that most likely discovered this issue during a vulnerability assessment.

Exam trap

CRISC often tests the misconception that SAST is the primary method for finding injection flaws because it examines code, but the key differentiator is that DAST tests running applications and is more likely to discover exploitable SQL injection during a vulnerability assessment.

How to eliminate wrong answers

Option A is wrong because SAST analyzes source code without executing it and, while it can flag potential injection patterns, it often produces false positives and cannot confirm exploitability like DAST; moreover, the scenario describes a vulnerability assessment of a running web application, which aligns with dynamic testing. Option B is wrong because CIS Benchmarks are configuration hardening guides for systems and software, not application-layer vulnerability discovery techniques; they do not test for SQL injection. Option D is wrong because DISA STIG scanning checks compliance with security technical implementation guides for hardening, not for runtime application vulnerabilities like SQL injection.

28
MCQhard

When developing IT risk scenarios, connecting them to business impact is critical. Which of the following BEST describes how a risk practitioner should link a technical scenario to business impact?

A.Assign a likelihood rating and an inherent risk score
B.Quantify the impact in terms of financial loss, regulatory penalty, and operational disruption
C.Describe the technical steps of the attack in detail
D.Reference industry benchmarks for similar scenarios
AnswerB

Expressing impact as financial loss, regulatory penalty and operational disruption links the technical scenario to business consequences using the standard impact categories, satisfying the stem's requirement to connect technical risk to business impact. This translation lets leadership compare and prioritise risks using consistent, decision-ready terms.

Why this answer

Quantifying impact in terms of financial loss, regulatory penalty, and operational disruption best links a technical risk scenario to business impact because it translates technical events into measurable business consequences. This allows risk to be expressed in terms that executives and business owners can understand and prioritize. It also supports cost-benefit analysis of risk treatment options.

Exam trap

CRISC often tests the difference between risk assessment (likelihood/impact scoring) and business impact analysis; candidates may pick likelihood scoring or technical description when the question specifically asks how to link to business impact, which requires quantification in business terms.

How to eliminate wrong answers

Option A is wrong because assigning likelihood and inherent risk scores rates the risk but does not connect it to business impact; it remains a technical or abstract rating. Option C is wrong because describing technical attack steps provides threat detail but does not articulate business consequences. Option D is wrong because referencing industry benchmarks gives context but does not quantify the organization's specific business impact.

29
MCQmedium

A national retail chain is building a risk register for its new e-commerce platform. The CISO asks the risk practitioner to identify the inherent risk associated with a recently disclosed SQL injection vulnerability in a third-party payment gateway module. Which of the following BEST describes inherent risk in this scenario?

A.The risk that exists before any controls or mitigation efforts are applied to the SQL injection vulnerability in the payment gateway module.
B.The risk that the third-party payment gateway vendor will fail to patch the SQL injection vulnerability within the agreed service level agreement.
C.The risk that the organization's risk appetite statement will be exceeded due to the SQL injection vulnerability.
D.The level of risk that remains after the organization implements compensating controls such as a web application firewall and input validation.
AnswerA

Inherent risk is the raw risk exposure before controls are considered. For the SQL injection vulnerability, this means the potential impact and likelihood assuming no compensating controls exist. This baseline helps the risk practitioner prioritize and later measure the effectiveness of controls. The scenario specifically asks for inherent risk, making this the correct characterization.

Why this answer

Inherent risk is the level of risk before any controls or mitigation actions are applied. In the context of the SQL injection vulnerability, it represents the raw exposure that the organization faces if nothing is done. This baseline is essential for risk practitioners to prioritize risks and later evaluate the effectiveness of controls by comparing inherent and residual risk.

The other options describe residual risk, vendor-specific risk, or risk appetite exceedance, none of which define inherent risk.

Exam trap

The trap here is confusing inherent risk with residual risk, especially when controls are mentioned in the scenario.

30
MCQhard

An insurance company is expanding into a new country and must identify IT risks arising from local data protection law, which requires customer data to remain within national borders. The risk practitioner is mapping this requirement into the enterprise risk register. Which of the following is the MOST appropriate way to characterize this risk?

A.As a technology risk owned by the infrastructure team, because data residency is enforced through server location.
B.As a compliance risk with no linkage to strategic objectives, since the requirement is external and mandatory.
C.As an enterprise risk that links the legal obligation to the market-entry objective, with ownership shared among legal, compliance, and technology stakeholders.
D.As an operational risk to be accepted until a regulator raises a concern, at which point it can be reassessed.
AnswerC

Data residency obligations cross legal, technology, and strategic boundaries, so the risk belongs in the enterprise register with clear linkage to the expansion objective and shared ownership. This framing lets leadership compare the cost of compliant local hosting and controls against the value of the new market, and ensures treatment decisions are made at the right level. It also supports consistent reporting to the board alongside other expansion risks.

Why this answer

A cross-border data residency obligation affects legal compliance, technology architecture, and the strategic decision to enter a market, so it belongs in the enterprise risk register with clear linkage to business objectives and shared ownership. This placement lets leadership weigh treatment costs against expansion value. Treating it as purely technical, isolated from strategy, or deferred until enforcement all misplace the risk and weaken governance.

Exam trap

The trap here is classifying a legal obligation as solely a technology or compliance issue and missing its connection to the strategic objective and enterprise-level ownership.

31
MCQmedium

A retail bank is building a risk register for its newly deployed mobile payment API. The CISO asks the risk practitioner to classify the risk that attackers could manipulate the API request parameters to bypass transaction limits. Under which CRISC risk identification category should this risk PRIMARILY be recorded?

A.IT security risk
B.IT project risk
C.IT operational risk
D.IT compliance risk
AnswerA

Tampering with API parameters to circumvent transaction limits is an intentional compromise of confidentiality, integrity, or authorized use, which is the definition of security risk. Recording it as a security risk links it to threat modeling, secure code review, and authorization testing, and it aligns with how CRISC expects practitioners to separate deliberate adversarial events from accidental operational failures or compliance gaps.

Why this answer

The risk described is a deliberate adversarial action that violates the integrity and authorized use of the payment API, which is the essence of IT security risk. Placing it in that category ensures it is assessed against threat actors, exploitable vulnerabilities, and security controls, and it drives the right treatment such as input validation and authorization hardening, rather than being handled as an availability, compliance, or delivery issue.

Exam trap

The trap here is assuming that any risk involving a live system or an application defect automatically belongs in IT operational risk instead of recognizing the deliberate adversarial intent that makes it a security risk.

32
MCQmedium

A company is developing risk scenarios for business impact analysis. Which of the following scenario components directly links the risk event to potential financial loss?

A.Vulnerability
B.Threat actor
C.Consequence
D.Asset
AnswerC

Consequence describes the resulting impact of a risk event materialising, quantified in financial, operational or regulatory terms. It satisfies the scenario component that directly links the event to potential financial loss, unlike cause, threat source or event description.

Why this answer

In risk scenario development, the consequence component describes the outcome or impact that results from a threat exploiting a vulnerability against an asset — and it is the consequence that is translated into financial loss estimates during business impact analysis. Without a defined consequence, there is no direct linkage from the risk event to monetary impact.

Exam trap

CRISC often tests the distinction between the components of a risk scenario — candidates confuse the asset or vulnerability with the consequence, but only the consequence expresses the financial loss linkage.

How to eliminate wrong answers

Option A is wrong because a vulnerability is a weakness that could be exploited; it is an input to the scenario, not the element that expresses financial loss. Option B is wrong because the threat actor is the entity that may exploit the vulnerability; it describes who or what causes the event, not the resulting impact. Option D is wrong because the asset is the thing of value that could be affected; while asset valuation feeds into impact calculation, the asset itself is not the component that directly links the event to financial loss — the consequence is.

33
MCQhard

An organization uses the PASTA threat modeling methodology. In which stage would the team identify threat agents and their capabilities?

A.Define objectives
B.Threat analysis
C.Vulnerability analysis
D.Decompose application
AnswerB

Threat analysis is the PASTA stage that enumerates threat agents, their capabilities, motivations and objectives, mapping them against the application's assets and attack surface. This directly satisfies the stem's requirement to identify threat agents and capabilities, distinguishing it from decomposition, attack modelling and risk/impact analysis stages.

Why this answer

PASTA's third stage involves profiling threat agents and their capabilities.

34
MCQhard

A global manufacturer's risk committee is defining the organization's risk capacity and risk appetite for IT risk. The chief risk officer asks the practitioner to clarify how these two concepts relate. Which of the following statements is MOST accurate?

A.Risk appetite applies only to financial risks, while risk capacity applies only to IT and operational risks.
B.Risk appetite is the maximum loss the organization can absorb, while risk capacity is the amount of risk management is willing to pursue for returns.
C.Risk capacity is the maximum risk the organization can bear, and risk appetite is the amount of risk it is willing to accept, with appetite normally set within capacity.
D.Risk capacity and risk appetite are interchangeable terms that both describe management's willingness to accept risk.
AnswerC

Capacity reflects the outer boundary of risk the organization can absorb before objectives or solvency are threatened, while appetite is the deliberate, lower level of risk it chooses to take. Setting appetite inside capacity leaves a buffer for unexpected events and keeps strategic risk-taking sustainable. This relationship is the foundation for deriving risk tolerances and limits that the committee can monitor.

Why this answer

Risk capacity defines the outer limit of risk the organization can absorb, while risk appetite is the lower, deliberately chosen level of risk it is willing to accept to pursue objectives. Appetite is normally set within capacity so that a buffer remains for unexpected losses. This hierarchy lets the committee translate strategy into tolerances and limits, and it prevents risk-taking from silently approaching the point where the organization's viability is threatened.

Exam trap

The trap here is swapping the definitions so that capacity sounds like willingness and appetite sounds like ability, which inverts the entire governance hierarchy.

35
Multi-Selecthard

A risk practitioner is identifying risks associated with the decommissioning of a legacy data center. The organization plans to migrate all remaining applications to a cloud environment. Which TWO of the following are the MOST significant risks that should be included in the risk register for this project? (Choose two.)

Select 2 answers
A.Incomplete destruction of sensitive data on decommissioned storage media, leading to unauthorized disclosure.
B.Failure to update the IT service continuity plan to reflect the new cloud architecture.
C.Inability to meet new regulatory requirements for data residency in the cloud environment.
D.Increased cloud subscription costs due to unexpected usage spikes after migration.
E.Loss of institutional knowledge about legacy application dependencies as experienced staff leave or retire.
AnswersA, E

When decommissioning a data center, ensuring that all sensitive data is securely wiped or destroyed from storage media is critical. If not properly handled, residual data could be recovered by unauthorized parties, leading to a data breach. This is a well-known risk in decommissioning projects and must be included in the risk register. It addresses confidentiality and compliance requirements.

Why this answer

The decommissioning of a legacy data center involves unique risks. Loss of institutional knowledge can lead to migration errors and outages, while incomplete data destruction can cause data breaches. These two risks are directly tied to the decommissioning process and should be prioritized in the risk register.

Regulatory data residency, cloud cost spikes, and continuity plan updates are important but are either related to the cloud migration itself or are control activities, not the primary risks of decommissioning.

Exam trap

The trap here is selecting cloud-related risks like data residency or cost, which are not specific to the decommissioning project.

36
MCQhard

A risk practitioner is estimating the likelihood of a ransomware event affecting a manufacturing firm's operational technology environment. Historical incident data is sparse, so the practitioner convenes plant engineers, security staff, and the insurance broker to elicit calibrated estimates and combine them into a reasoned likelihood. Which technique is being used?

A.Delphi technique with structured expert elicitation.
B.Bayesian updating of the prior incident frequency.
C.Monte Carlo simulation of the plant's loss distribution.
D.Fault tree analysis of the ransomware attack path.
AnswerA

The Delphi technique gathers anonymous, iterative expert judgments and converges them toward a calibrated consensus, which fits sparse-data situations perfectly. By combining engineers, security, and the broker, the practitioner draws on operational, technical, and actuarial perspectives. Structured elicitation reduces anchoring and groupthink, producing a reasoned likelihood estimate where historical incident data alone cannot support one.

Why this answer

When incident data is too sparse to support statistical estimation, structured expert elicitation such as the Delphi technique is the appropriate way to generate calibrated likelihood estimates. It pools diverse expertise, uses anonymity and iteration to reduce bias, and converges on a defensible consensus. The resulting estimate can later feed quantitative models if data improves, keeping the analysis honest about its uncertainty.

Exam trap

The trap here is reaching for a quantitative model like Monte Carlo or Bayesian updating when the real problem is that no data exists yet to parameterize those models.

37
MCQeasy

Which of the following is a threat intelligence source that provides information about known exploited vulnerabilities, maintained by a government agency?

A.OSINT
B.NVD
C.CISA KEV
D.ISACs
AnswerC

The CISA Known Exploited Vulnerabilities catalogue is maintained by the US Cybersecurity and Infrastructure Security Agency and lists vulnerabilities with confirmed in-the-wild exploitation, satisfying the stem's government-maintained, known-exploited requirement. Other sources, such as vendor advisories or commercial feeds, lack that specific provenance.

Why this answer

The CISA Known Exploited Vulnerabilities (KEV) catalog is maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and lists vulnerabilities that have been exploited in the wild. It is a government-maintained threat intelligence source specifically focused on known exploited vulnerabilities.

Exam trap

The trap is confusing the NVD with the CISA KEV catalog; both are government-related vulnerability databases, but only KEV specifically lists vulnerabilities known to be exploited in the wild.

How to eliminate wrong answers

Option A is wrong because OSINT (Open Source Intelligence) is a broad category of publicly available information, not a specific government-maintained catalog of exploited vulnerabilities. Option B is wrong because the NVD (National Vulnerability Database) is a repository of vulnerability data maintained by NIST, but it does not exclusively list exploited vulnerabilities; it includes all published CVEs. Option D is wrong because ISACs (Information Sharing and Analysis Centers) are industry-specific information sharing organizations, not government-maintained catalogs of exploited vulnerabilities.

38
MCQeasy

Which type of threat actor is characterized by having significant resources, advanced skills, and often state-sponsored objectives?

A.Script kiddies
B.Organized crime
C.Nation-state APTs
D.Hacktivists
AnswerC

Nation-state advanced persistent threats combine government funding, elite technical capability and geopolitical objectives, enabling prolonged intrusion campaigns that outmatch criminal or insider actors. This matches the stem's significant resources, advanced skills and state-sponsored objectives precisely.

Why this answer

Nation-state advanced persistent threats (APTs) are characterized by significant resources, advanced technical skills, and objectives aligned with state interests, such as espionage, sabotage, or influence operations. They are typically well-funded and persistent.

Exam trap

The trap is equating 'significant resources and advanced skills' with organized crime; however, organized crime is financially motivated, while state-sponsored objectives are the key differentiator for nation-state APTs.

How to eliminate wrong answers

Option A is wrong because script kiddies are unskilled attackers who use existing tools and have limited resources. Option B is wrong because organized crime groups are motivated by financial gain and may have resources, but they are not typically state-sponsored and their objectives are profit-driven. Option D is wrong because hacktivists are ideologically motivated and usually have limited resources and skills compared to nation-state actors.

39
Multi-Selectmedium

A risk practitioner at an insurance company is identifying risks for a newly deployed customer portal that integrates with a third-party identity provider. She wants to document external factors that could increase the likelihood of a data breach. Which TWO of the following are external risk factors she should capture? (Choose two.)

Select 2 answers
A.The identity provider's recent history of service outages and security incidents disclosed in its public trust reports
B.The insurer's internal policy requiring multi-factor authentication for all administrative access to the portal
C.The insurer's internal change management process for deploying portal updates
D.The current regulatory penalties for privacy breaches in the jurisdictions where the insurer operates
E.The number of privileged accounts the insurer's own IT staff hold on the portal's backend systems
AnswersA, D

The provider's incident history is an external factor outside the insurer's direct control that directly affects breach likelihood for the portal. Documenting it supports third-party risk assessment and helps the practitioner set monitoring and contractual expectations. It belongs in the external factor category because it describes the vendor's environment rather than an internal control or process.

Why this answer

External risk factors are conditions outside the organization's direct control that affect the likelihood or impact of a risk event. A third-party identity provider's incident history and changing regulatory penalty regimes both originate outside the insurer and vary independently of its own actions. Internal policies, privileged account counts, and change management processes are internal conditions or controls that the organization itself shapes.

Exam trap

The trap here is assuming any factor that affects breach likelihood is external, when internal controls and processes also qualify as risk factors but are internally controlled.

40
MCQmedium

Which of the following is the PRIMARY source for identifying known software vulnerabilities in a systematic manner?

A.OSINT feeds from social media
B.CIS Benchmarks
C.National Vulnerability Database (NVD)
D.OWASP Top 10
AnswerC

The National Vulnerability Database provides a systematic, authoritative feed of known vulnerabilities, each mapped to CVE identifiers and enriched with CVSS severity scores. This structured, continuously updated catalogue satisfies the stem's requirement for a primary, repeatable source, unlike vendor advisories or ad hoc threat feeds.

Why this answer

The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, built upon the CVE (Common Vulnerabilities and Exposures) list. It provides a systematic, structured, and continuously updated source of known software vulnerabilities, including CVSS scores, CWE classifications, and affected product configurations. For CRISC, it is the authoritative primary source for identifying vulnerabilities in a repeatable, comprehensive manner, unlike the other options which are either not vulnerability databases or not systematic.

Exam trap

CRISC often tests the distinction between a vulnerability database (NVD) and security guidance or awareness lists (CIS Benchmarks, OWASP Top 10), causing candidates to select a well-known framework instead of the primary systematic source.

How to eliminate wrong answers

Option A is wrong because OSINT feeds from social media are unstructured, unverified, and lack the systematic, standardized vulnerability identifiers and metadata needed for a reliable vulnerability management process. Option B is wrong because CIS Benchmarks are prescriptive configuration hardening guidelines, not a database of known software vulnerabilities; they help prevent exploitation but do not enumerate vulnerabilities. Option D is wrong because the OWASP Top 10 is an awareness document that lists the most critical web application security risks, not a comprehensive, systematic database of known software vulnerabilities.

41
MCQhard

A multinational corporation uses commercial threat intelligence feeds and participates in an ISAC. However, they recently missed a critical vulnerability exploited in the wild that was not in their feeds. Which additional source should they incorporate to improve vulnerability identification?

A.CISA KEV catalog
B.NVD database
C.OSINT from social media
D.Vendor advisories only
AnswerA

The CISA Known Exploited Vulnerabilities catalog lists vulnerabilities confirmed as exploited in the wild, including those absent from commercial feeds and ISAC sharing. Incorporating it closes the gap that let the exploited vulnerability go unidentified, directly addressing the missed in-the-wild exploitation described in the stem.

Why this answer

The CISA KEV catalog specifically lists vulnerabilities that have been confirmed as exploited in the wild, which is exactly the gap described—a critical vulnerability exploited in the wild that was missed by commercial feeds and ISAC participation. Incorporating KEV ensures the organization prioritizes vulnerabilities with known active exploitation, regardless of whether they appear in commercial feeds. This makes it the correct additional source.

Exam trap

CRISC often tests the difference between vulnerability severity (NVD/CVSS) and confirmed exploitation (CISA KEV); the trap is selecting NVD because it is a well-known government vulnerability database, when the question specifically asks about a vulnerability exploited in the wild that was missed by existing feeds.

How to eliminate wrong answers

Option B is wrong because the NVD is a comprehensive vulnerability database that catalogs CVEs with CVSS scores but does not specifically identify which vulnerabilities are known to be exploited in the wild, so it would not have closed the gap described. Option C is wrong because OSINT from social media is unstructured, unverified, and not a reliable or systematic source for identifying exploited vulnerabilities. Option D is wrong because vendor advisories only cover vulnerabilities in that specific vendor's products and would not provide the cross-vendor, exploitation-confirmed coverage that KEV offers.

42
MCQeasy

A hospital's risk practitioner is identifying risks for a new telehealth platform. The IT director asks which source would be MOST useful for identifying vulnerabilities specific to the platform's underlying commercial software components. Which of the following should the practitioner use?

A.A business impact analysis (BIA) questionnaire.
B.The IT balanced scorecard and service level reports.
C.The Common Vulnerabilities and Exposures (CVE) database.
D.The organization's incident response postmortem reports.
AnswerC

CVE is a publicly maintained catalog of known vulnerabilities in commercial and open-source software, each with a unique identifier. Because the telehealth platform relies on commercial components, searching CVE entries for those products surfaces specific, documented weaknesses that can feed the risk register. It directly addresses vulnerability identification for known software, which is exactly the task described.

Why this answer

CVE is the standard reference catalog for publicly known vulnerabilities in commercial and open-source products, making it the most direct source for identifying weaknesses in the telehealth platform's software components. The other sources address incidents, business impact, or service performance rather than the technical vulnerabilities present in the commercial software itself.

Exam trap

The trap here is choosing an internal document that sounds security-related, such as postmortems, when the question asks specifically about identifying vulnerabilities in commercial software components.

43
MCQmedium

A risk practitioner at a regional hospital is building a risk register for its new electronic health record (EHR) system. The system stores protected health information (PHI) and is subject to HIPAA. The practitioner wants to ensure that the risk register captures the potential for unauthorized disclosure of PHI. Which of the following should the practitioner PRIMARILY use to identify the relevant threats and vulnerabilities for this system?

A.A review of the vendor's SOC 2 Type II report
B.A control self-assessment (CSA) workshop with clinical staff
C.A business impact analysis (BIA) focused on recovery time objectives
D.A vulnerability assessment combined with a threat modeling exercise
AnswerD

A vulnerability assessment scans the EHR system for known technical weaknesses (e.g., missing patches, misconfigurations), while threat modeling systematically identifies how threats could exploit those weaknesses to cause unauthorized disclosure. Together they provide a structured, evidence-based inventory of threats and vulnerabilities. This is the primary approach for identifying relevant risks in a new system handling sensitive data.

Why this answer

Threat modeling and vulnerability assessment are complementary techniques that together provide a comprehensive identification of threats and vulnerabilities. Threat modeling explores how threat agents could exploit weaknesses, while vulnerability assessment discovers actual technical flaws. This combination ensures the risk register is grounded in both design-level and operational weaknesses, which is essential for a system holding PHI.

Other methods either focus on control effectiveness or impact, not identification.

Exam trap

The trap here is assuming that a compliance report or control assessment satisfies the need to identify threats and vulnerabilities, when in fact those activities evaluate controls rather than discover new weaknesses.

44
MCQhard

A risk practitioner is assessing the likelihood of a distributed denial-of-service (DDoS) attack against an online retailer's checkout service during peak shopping season. Which of the following factors would MOST increase the assessed likelihood of this event?

A.The checkout service uses a content delivery network with DDoS mitigation
B.The organization has no documented incident response plan for availability attacks
C.The checkout service is hosted in a single data center region
D.Peer retailers experienced a surge in DDoS attacks during the same peak period last year
AnswerD

Observed attacks against comparable organizations in the same seasonal window indicate an active, capable threat community targeting this sector. That external threat activity directly raises the probability that the retailer's checkout service will be attacked during the upcoming peak. Threat intelligence and peer incident data are core inputs to likelihood estimation in a risk assessment.

Why this answer

Likelihood reflects the probability that a threat will act against an exposed asset, so evidence of an active threat community targeting similar retailers in the same season is the strongest driver. Mitigating controls such as CDN-based DDoS protection lower likelihood, while resilience gaps and missing response plans primarily affect impact and recovery. Peer incident data is a standard threat intelligence input for likelihood estimation.

Exam trap

The trap here is selecting an architectural weakness such as single-region hosting, which affects the severity of an outage rather than the probability that an attack will occur.

45
MCQhard

When performing asset-based vulnerability identification, a security analyst uses the Common Vulnerabilities and Exposures (CVE) database along with the National Vulnerability Database (NVD). Which of the following BEST describes the relationship between CVE and NVD?

A.Both databases are identical and maintained by the same organization.
B.CVE is the authoritative source for vulnerability scoring, while NVD assigns identifiers.
C.NVD lists only vulnerabilities that are actively exploited, while CVE lists all known vulnerabilities.
D.CVE provides unique identifiers for vulnerabilities, and NVD provides additional analysis including CVSS scores.
AnswerD

CVE assigns each publicly disclosed vulnerability a unique identifier (CVE-YYYY-NNNN). NVD enriches those CVE records with analysis, including CVSS severity scores, CWE classification and affected product data, so the two are complementary rather than duplicates.

Why this answer

CVE (Common Vulnerabilities and Exposures) is a dictionary that assigns a unique identifier (e.g., CVE-2024-12345) to each publicly disclosed vulnerability, providing a common naming standard. NVD (National Vulnerability Database), maintained by NIST, consumes CVE records and enriches them with CVSS base scores, CWE classifications, CPE applicability statements, and references. So CVE provides the identifier and NVD provides the analysis and scoring.

Exam trap

The trap here is confusing the roles of CVE and NVD — candidates often assume CVE provides scoring or that NVD assigns the CVE IDs, when in fact CVE is the identifier dictionary and NVD is the enrichment/scoring database.

How to eliminate wrong answers

Option A is wrong because CVE is maintained by MITRE (sponsored by CISA) while NVD is maintained by NIST — they are distinct organizations with distinct roles, not identical databases. Option B is wrong because it reverses the roles: CVE assigns identifiers, not scores, and NVD provides CVSS scoring, not identifiers. Option C is wrong because NVD does not limit itself to actively exploited vulnerabilities; it catalogs all CVE entries it enriches, while actively exploited vulnerabilities are tracked separately in CISA's Known Exploited Vulnerabilities (KEV) catalog.

46
MCQmedium

A hospital's risk practitioner is building a risk register entry for a ransomware attack on its electronic health record (EHR) system. The practitioner wants to express the risk in terms of how often the event is expected to occur and how much it would cost if it did. Which of the following BEST describes the two components being quantified?

A.Threat and vulnerability
B.Inherent risk and residual risk
C.Likelihood and impact
D.Risk appetite and risk tolerance
AnswerC

Likelihood expresses how probable the ransomware event is over a defined period, and impact expresses the resulting loss in financial or operational terms. Together they form the two core dimensions used to score a risk register entry. For the EHR scenario, likelihood might be annualized probability and impact could be quantified as recovery cost plus downtime revenue loss.

Why this answer

Quantitative risk analysis expresses each risk event through the probability it will occur and the resulting loss if it does. Likelihood and impact are the standard ISACA dimensions used in a risk register entry, and they can be combined into annualized loss expectancy. Governance thresholds, contributing factors, and control-state comparisons are separate concepts that do not describe the two quantified components.

Exam trap

The trap here is assuming that threat and vulnerability are the quantified components of a risk entry, when they are inputs that shape likelihood and impact rather than the measured dimensions themselves.

47
MCQmedium

An organization is assessing risks related to a new cloud-based CRM system. The risk team is developing a risk scenario. Which of the following is the BEST example of a complete risk scenario following the ISACA template?

A.A DDoS attack on the CRM disrupts service, leading to operational downtime.
B.A hacker exploits a vulnerability in the CRM to steal customer data, resulting in financial loss.
C.An external attacker (actor) performs a SQL injection (threat type) to exfiltrate customer records from the CRM database (event/asset); occurs during off-hours (timing); detected by IDS after 2 hours (detection); leads to regulatory fines and reputational damage (consequence).
D.A disgruntled employee leaks data from the CRM, causing reputational damage.
AnswerC

A complete ISACA risk scenario names the actor, threat type, event and affected asset, timing, detection, and consequence. This option supplies all six elements, describing an external attacker using SQL injection to exfiltrate customer records, with detection delay and resulting regulatory and reputational impact.

Why this answer

ISACA's risk scenario template requires a structured narrative that identifies the threat actor, threat type, event, asset, timing, detection method, and consequence. Option C is the only choice that includes all these elements — actor (external attacker), threat type (SQL injection), event/asset (exfiltration from CRM database), timing (off-hours), detection (IDS after 2 hours), and consequence (regulatory fines and reputational damage). This completeness is what makes it a valid risk scenario rather than a vague risk statement.

Exam trap

CRISC often tests whether candidates can distinguish a complete risk scenario (with actor, threat, asset, timing, detection, consequence) from a simple risk statement that only names a threat and an outcome.

How to eliminate wrong answers

Option A is wrong because it only names a threat (DDoS) and a generic outcome (downtime) without identifying the actor, asset specifics, timing, detection, or quantified consequence — it is a risk statement, not a full scenario. Option B is wrong because although it names a threat actor and outcome, it omits timing, detection method, and asset specificity, and uses vague terms like 'financial loss' without a structured consequence. Option D is wrong because it identifies an insider threat and reputational damage but lacks timing, detection, asset detail, and a structured consequence statement.

48
Multi-Selectmedium

A risk manager is developing risk scenarios to present to the board. Which TWO elements are essential for connecting a risk scenario to business impact?

Select 2 answers
A.Threat actor motivation
B.Vulnerability score
C.Detection time
D.Consequence (e.g., financial loss)
E.Business impact statement
AnswersD, E

Consequence quantifies what happens to the organisation if the risk eventuates — financial loss, regulatory penalty or service disruption. It is the causal link translating a risk scenario into measurable business impact, giving the board a basis for comparing scenarios against risk appetite.

Why this answer

Option D, consequence such as financial loss, is essential because it translates a technical or threat event into measurable business outcomes (e.g., revenue loss, regulatory fines, recovery cost), which is exactly what connects the scenario to business impact. Option E, a business impact statement, is essential because it formally articulates how the scenario affects business objectives, operations, or stakeholders, providing the board with a clear linkage between risk and organizational impact. Together, consequence and the business impact statement bridge the gap between risk scenarios and business-level decision-making.

Option A, threat actor motivation, is useful for threat modeling but does not by itself quantify or express business impact. Option B, vulnerability score, is a technical severity metric (e.g., CVSS) that does not directly map to business consequences. Option C, detection time, is an operational metric that influences exposure but is not an essential element for connecting a scenario to business impact.

Exam trap

CRISC often tests the confusion between technical severity metrics (vulnerability score, detection time) and business-facing elements (consequence, business impact statement) when linking risk scenarios to organizational impact.

49
MCQmedium

A risk practitioner is facilitating a workshop to identify risks for a new customer-facing payment portal. The CISO wants the exercise to capture risks arising from both internal process weaknesses and external threat sources without producing an unmanageable list. Which approach is MOST appropriate for structuring the risk identification effort?

A.Use a structured technique such as scenario analysis that pairs threat sources with affected assets and business processes.
B.Conduct a penetration test of the portal and register only the findings that result in successful exploitation.
C.Ask each workshop participant to submit an unrestricted list of every concern they have about the portal.
D.Adopt the vendor's standard risk register template and record the categories the vendor already populated.
AnswerA

Scenario analysis systematically combines plausible threat sources with the assets and business processes they could affect, producing a structured set of risk statements that spans internal weaknesses and external actors. This disciplined pairing keeps the list focused on credible combinations rather than an exhaustive inventory, and it aligns directly with the risk scenario structure used in ISACA guidance, making the outputs suitable for subsequent assessment and treatment.

Why this answer

Structured scenario analysis pairs credible threat sources with the assets and business processes they could affect, producing a comprehensive yet bounded set of risk statements. This technique captures internal weaknesses such as process gaps and external sources such as criminal actors in a consistent format, supports later likelihood and impact assessment, and keeps the register manageable. Testing, unrestricted brainstorming, and vendor templates each fall short on coverage, consistency, or relevance.

Exam trap

The trap here is equating thorough risk identification with either technical testing or open-ended brainstorming, when the real requirement is a structured pairing of threat sources with assets and processes.

50
Multi-Selecthard

A risk practitioner is cataloging external factors that could create IT risk for a logistics firm expanding into a new country. Which TWO of the following are external factors that should be included in the risk identification effort? (Choose two.)

Select 2 answers
A.The organization's chosen encryption standard for data at rest.
B.The firm's internal security awareness training completion rate.
C.New data residency and privacy regulations in the target country.
D.The maturity of the local telecommunications and power infrastructure.
E.The technical skill level of the firm's current IT staff.
AnswersC, D

Data residency and privacy laws are external, environmental factors outside the firm's control that can create compliance and operational risk. They influence where data may be stored and processed, affecting architecture and vendor choices. Capturing them during identification ensures the expansion plan accounts for legal constraints before systems are deployed, rather than discovering violations after the fact.

Why this answer

External factors are conditions outside the organization's control that shape its risk landscape. New data residency and privacy regulations and the maturity of local telecom and power infrastructure both originate in the target country's legal and physical environment, so they must be identified during expansion planning. Internal items such as staff skills, training rates, and encryption choices are capability and control decisions the firm governs itself.

Exam trap

The trap here is listing internal control weaknesses or capability gaps as external factors, when external factors must originate outside the organization's own control.

51
MCQeasy

A risk practitioner is conducting a risk assessment for a new mobile application that will process credit card payments. The practitioner needs to identify relevant threats. Which of the following is the MOST appropriate source for identifying threats specific to this application?

A.The business continuity plan for the payment processing system
B.The IT department's list of approved software vendors
C.A threat intelligence feed that includes mobile and payment card threats
D.The organization's previous audit findings for other applications
AnswerC

Threat intelligence feeds provide current, relevant information about threat actors, tactics, techniques, and procedures (TTPs) targeting mobile payment systems. This is the most appropriate source because it is specific to the technology and industry, enabling the practitioner to identify threats such as credential stuffing, mobile malware, and API abuse. It directly supports the identification of threats for this application.

Why this answer

Threat intelligence feeds are designed to provide up-to-date information on threats relevant to specific technologies and industries. For a mobile payment app, a feed covering mobile and payment card threats will identify threat actors, attack vectors, and emerging TTPs. This enables the risk practitioner to build a realistic threat landscape.

Other sources like audit findings or continuity plans are secondary and do not offer the same breadth or currency.

Exam trap

The trap here is selecting internal documents like audit findings or vendor lists, which are not threat sources, instead of external threat intelligence that is specific to the technology.

52
MCQmedium

A risk practitioner is analyzing the risk of insider threat in a software development company. The practitioner wants to assess the likelihood of a developer exfiltrating source code. Which of the following factors would MOST directly increase the likelihood of this risk?

A.The developer has elevated access privileges to the source code repository.
B.The company's security awareness training is conducted annually.
C.The company has a high turnover rate among developers.
D.The source code repository is hosted in a third-party cloud environment.
AnswerA

Elevated access privileges directly increase the opportunity for a developer to exfiltrate source code. Even if motivation exists, without access the threat cannot be realized. In insider threat analysis, opportunity is a key likelihood factor, and privileged access is a common enabler. This makes it the most direct factor increasing likelihood in this scenario.

Why this answer

The likelihood of an insider threat depends on motivation, opportunity, and capability. Elevated access privileges provide the opportunity for a developer to exfiltrate source code, making it the most direct factor increasing likelihood. Other factors like turnover or training frequency may influence the environment but do not directly enable the theft.

Access control is therefore a critical control point.

Exam trap

The trap here is selecting indirect organizational factors, such as turnover or training frequency, instead of the direct enabler of opportunity that privileged access provides.

53
MCQmedium

An organization is developing an IT risk universe. Which of the following is the PRIMARY purpose of creating a comprehensive IT risk universe?

A.To ensure all potential IT risks are considered and documented
B.To prioritize risks based on their financial impact
C.To assign risk owners to each identified risk
D.To calculate the aggregated risk exposure for the organization
AnswerA

A comprehensive IT risk universe ensures no material risk is omitted from scoping, so every potential IT risk is identified and documented before assessment. This completeness underpins later risk evaluation, appetite setting and treatment, preventing blind spots that would otherwise distort the organisation's overall IT risk profile.

Why this answer

The IT risk universe is a comprehensive inventory of all plausible IT-related risks an organization faces, organized by category (e.g., infrastructure, applications, data, third parties, people). Its primary purpose is to ensure completeness — that all potential IT risks are considered and documented — so that subsequent risk assessment, prioritization, and treatment are built on a complete foundation. Without completeness, later steps may overlook material risks.

Exam trap

CRISC often tests the sequence of risk management activities — candidates confuse the purpose of the risk universe (completeness of identification) with downstream activities like prioritization, ownership assignment, or exposure aggregation.

How to eliminate wrong answers

Option B is wrong because prioritizing risks by financial impact is a subsequent step performed after the risk universe is populated; prioritization is not the purpose of creating the universe. Option C is wrong because assigning risk owners is a downstream governance activity that occurs once risks are identified and assessed, not the reason for building the universe. Option D is wrong because calculating aggregated risk exposure is an analytical output that depends on the universe existing first; it is a use of the universe, not its primary purpose.

54
MCQhard

A risk practitioner is using the Delphi technique to estimate the likelihood of a sophisticated ransomware attack against a hospital network. The first round of expert opinions produced widely divergent estimates. Which of the following is the MOST appropriate next step in the Delphi process?

A.Replace the expert panel with a quantitative Monte Carlo simulation to model the ransomware likelihood.
B.Provide a statistical summary of the first-round estimates to the experts and ask them to revise their estimates in a second anonymous round.
C.Discard the highest and lowest estimates and average the remaining responses to produce a single likelihood value.
D.Convene a face-to-face meeting where experts debate their estimates until a unanimous consensus is reached.
AnswerB

The Delphi method involves iterative rounds where experts receive anonymized feedback, such as the median and interquartile range, and then revise their estimates. This controlled feedback helps converge toward consensus without direct confrontation. In this scenario, the divergent first-round estimates should be summarized and returned to the experts for a second round. This is the standard next step in the Delphi process.

Why this answer

The Delphi technique is an iterative, anonymous expert elicitation method. After the first round, the facilitator provides a statistical summary of the responses, such as the median and range, to the experts. The experts then revise their estimates in a second anonymous round.

This process repeats until consensus or stability is achieved. Providing feedback and allowing revision is the defining characteristic of Delphi, making the second anonymous round the correct next step.

Exam trap

The trap here is thinking that averaging or face-to-face debate is part of Delphi, when in fact anonymity and iterative feedback are essential.

55
MCQhard

A risk practitioner is quantifying the potential loss from a ransomware scenario affecting a hospital's electronic health record (EHR) platform. Historical data shows an average of two disruptive malware incidents per year, a 30% probability that any single incident escalates to full EHR encryption, and an estimated $4,000,000 business impact when the EHR is unavailable for a full day. What is the annualized loss expectancy (ALE) for this scenario?

A.$12,000,000
B.$2,400,000
C.$1,200,000
D.$8,000,000
AnswerB

Annualized loss expectancy equals single loss expectancy multiplied by annualized rate of occurrence. The single loss expectancy is $4,000,000 times 30%, or $1,200,000 per disruptive incident. Multiplying by two incidents per year yields $2,400,000. This figure gives leadership a defensible annual expected loss that can be compared directly against the annual cost of proposed controls when prioritizing risk treatment decisions.

Why this answer

Annualized loss expectancy is derived by first computing single loss expectancy, which is the impact of $4,000,000 multiplied by the 30% probability of escalation, giving $1,200,000. Multiplying that by the annualized rate of occurrence of two incidents per year produces $2,400,000. This expected annual loss can be weighed directly against the yearly cost of controls such as immutable backups, segmentation, and detection tooling.

Exam trap

The trap here is multiplying the raw impact by the annual incident count and forgetting to weight the impact by the probability that an incident escalates into full EHR encryption.

56
Multi-Selectmedium

During a risk identification workshop, the team identifies several vulnerabilities. Which TWO of the following are examples of operational vulnerability identification? (Select two.)

Select 2 answers
A.Inadequate access control review process
B.Outdated firewall firmware
C.Missing security patches on servers
D.Weak password policy enforcement
E.SQL injection vulnerability in the web application
AnswersA, D

An inadequate access control review process is an operational vulnerability: a weakness in the ongoing procedures that govern how access rights are checked and recertified. It satisfies the stem's requirement for operational identification, since it arises from day-to-day process execution rather than project or architectural design.

Why this answer

Operational vulnerability identification focuses on weaknesses in day-to-day processes, procedures, and human/administrative controls rather than specific technical flaws in systems or code. Option A, an inadequate access control review process, is correct because it is a procedural/process weakness—failing to periodically review who has access means operational controls are not being maintained, which is a classic operational vulnerability. Option D, weak password policy enforcement, is correct because it reflects a failure in enforcing an administrative/operational control (e.g., not applying complexity, rotation, or lockout rules), which is a process and governance issue rather than a single technical defect.

By contrast, option B (outdated firewall firmware) and option C (missing security patches on servers) are technical vulnerabilities tied to unpatched software/hardware, and option E (SQL injection in the web application) is a technical application flaw, so they fall under technical rather than operational vulnerability identification.

Exam trap

CRISC often tests the boundary between operational and technical vulnerabilities — candidates pick patch or firmware issues because they sound like 'vulnerabilities,' but the question specifically asks for operational (process/control) weaknesses.

57
MCQeasy

A risk practitioner is conducting a risk assessment for a new customer-facing mobile application. The practitioner wants to identify risks by examining how data flows between the mobile client, the API gateway, and the backend database. Which of the following techniques is being applied?

A.Vulnerability scanning
B.Business impact analysis
C.Threat modeling
D.Control self-assessment
AnswerC

Threat modeling examines a system's architecture and data flows to identify where threats could exploit weaknesses. By tracing data between the mobile client, API gateway, and backend database, the practitioner is building the data-flow view that threat modeling uses to find exposure points such as unvalidated input or weak authentication between tiers. This makes it the technique being applied.

Why this answer

Threat modeling is the structured technique for examining system architecture, trust boundaries, and data flows to identify where threats can act. Tracing data between the mobile client, API gateway, and database is exactly the data-flow analysis that threat modeling performs. The other techniques address control evaluation, automated weakness detection, or business process criticality rather than architectural data movement.

Exam trap

The trap here is selecting vulnerability scanning because it also identifies weaknesses, when the distinguishing activity is architectural data-flow analysis rather than automated probing.

58
MCQhard

A utility company's risk practitioner is defining the scope of a risk identification exercise for a new advanced metering infrastructure. The practitioner must decide which elements to include. Which action BEST ensures the identification exercise covers the full risk landscape?

A.Limit the exercise to the technologies the project team will deploy directly.
B.Base scope on the risk categories already recorded in the enterprise risk register.
C.Defer identification until the infrastructure has been operating for one full billing cycle.
D.Include internal processes, third parties, and dependencies that interact with the new infrastructure.
AnswerD

Advanced metering infrastructure depends on internal billing and outage processes, communications vendors, field operations, and regulatory reporting, so identifying risks across these interactions exposes exposures that a technology-only view misses. This scope supports end-to-end risk scenarios, lets the practitioner trace cascading effects from a meter compromise through to customer billing, and aligns the identification exercise with how the utility actually delivers service.

Why this answer

A complete identification exercise follows the service and data flows rather than the project's technical boundary. For advanced metering infrastructure, that means including internal billing and outage processes, third-party communication providers, field operations, and regulatory dependencies, because risks frequently arise at these interfaces. A technology-only scope, a register-driven scope, or a deferred timeline would all leave material exposures unidentified or identified too late to influence design.

Exam trap

The trap here is equating the project's technical boundary with the risk boundary, when the risk landscape extends across processes, vendors, and dependencies.

59
MCQmedium

A mid-sized hospital is building its IT risk register. The risk practitioner wants to express the organization's tolerance for a ransomware event that would disrupt electronic health records for 24 hours. Which of the following BEST represents a structured way to document this tolerance?

A.A vulnerability assessment report showing unpatched EHR servers.
B.A risk register entry that lists ransomware as a high-likelihood, high-impact risk.
C.A business impact analysis that estimates the financial cost of a 24-hour EHR outage.
D.A documented risk appetite statement that specifies the maximum acceptable downtime and data loss for EHR systems.
AnswerD

A risk appetite statement quantifies how much risk the organization is willing to accept for a specific risk category or system. By stating maximum tolerable downtime and data loss, the hospital creates a measurable threshold that guides decisions on controls, insurance, and response planning. This directly supports IT risk identification by defining the boundary between acceptable and unacceptable risk.

Why this answer

A risk appetite statement is the formal mechanism for expressing how much risk an organization is willing to accept. It translates broad tolerance into specific, measurable limits such as maximum downtime and data loss. This gives the risk practitioner a clear benchmark for evaluating whether a ransomware risk is within or outside acceptable boundaries, enabling consistent risk response decisions.

Exam trap

The trap here is confusing risk assessment outputs, like a business impact analysis or vulnerability report, with a formal statement of risk appetite that explicitly defines acceptable risk levels.

60
MCQeasy

A retail company is establishing an IT risk universe. Which of the following should be included as a primary category of IT risk?

A.Market risk
B.Third-party risk
C.Inflation risk
D.Interest rate risk
AnswerB

Third-party risk is a primary IT risk category because vendors and partners introduce exposure through shared data, integrated systems and outsourced processes. Including it in the risk universe ensures supplier dependencies are assessed alongside internal threats.

Why this answer

Third-party risk is a primary IT risk category because organizations increasingly depend on vendors, cloud providers, and service integrators whose failures, breaches, or non-compliance directly affect the organization's IT risk posture. It belongs in the IT risk universe alongside categories such as cybersecurity, availability, data integrity, and compliance risk. Market, inflation, and interest rate risks are financial/market risks, not IT risk categories.

Exam trap

CRISC often tests whether candidates can distinguish IT risk categories from financial/market risk categories, so the trap is selecting a familiar-sounding financial risk (market, inflation, interest rate) instead of the IT-relevant third-party risk.

How to eliminate wrong answers

Option A is wrong because market risk is a financial risk category (price movements, demand shifts) and is not a primary IT risk category in an IT risk universe. Option C is wrong because inflation risk is a macroeconomic/financial risk, not an IT risk. Option D is wrong because interest rate risk is a treasury/financial risk and does not describe technology-related exposure.

61
MCQhard

During a VAST threat modeling session for a DevSecOps pipeline, the team focuses on threats that align with agile development. Which of the following is a key advantage of VAST?

A.It requires detailed system architecture upfront
B.It replaces the need for vulnerability scanning
C.It is tailored for use in agile and DevOps environments
D.It focuses on compliance requirements only
AnswerC

VAST's defining advantage is that it was designed specifically for Agile and DevOps delivery, scaling threat modelling across many fast-moving teams and integrating into sprint workflows. This directly satisfies the stem's constraint of aligning threats with agile development during a DevSecOps pipeline session.

Why this answer

VAST is designed to integrate with agile and DevOps, providing continuous threat modeling.

62
MCQhard

A risk practitioner at a healthcare insurer is identifying risks for a new telehealth platform. The platform integrates with a third-party video vendor, stores protected health information, and must comply with HIPAA. Which of the following is the MOST appropriate FIRST step in identifying IT risk for this platform?

A.Perform a penetration test of the telehealth platform before go-live.
B.Purchase cyber insurance to transfer the financial impact of a breach.
C.Review the third-party video vendor's SOC 2 report and contract terms.
D.Inventory the platform's assets, data flows, and regulatory obligations to define the risk context.
AnswerD

Risk identification begins with understanding the context: what assets exist, how data moves, who touches it, and what legal or contractual requirements apply. For a telehealth platform handling protected health information, this establishes the scope against which threats, vulnerabilities, and impacts can be assessed. Without this foundation, subsequent activities such as vendor review, testing, or control selection lack a reliable basis and may miss critical exposures.

Why this answer

Effective risk identification starts with establishing context: the assets involved, the data flows, the dependencies, and the regulatory environment. Inventorying the telehealth platform's components, protected health information movement, and HIPAA obligations gives the practitioner the basis to enumerate threats and vulnerabilities. Only after this scope is defined do activities such as vendor assurance review, penetration testing, and insurance decisions become targeted and defensible.

Exam trap

The trap here is jumping to a control or treatment activity such as penetration testing or insurance, which feels proactive but actually assumes the risk identification work is already complete.

63
Multi-Selecthard

A risk practitioner is performing risk identification for a manufacturing firm that relies on industrial control systems (ICS) to operate assembly lines. The practitioner is cataloging vulnerabilities that could be exploited to disrupt production. Which TWO of the following represent vulnerabilities rather than threats? (Choose two.)

Select 2 answers
A.Flat network architecture that allows engineering workstations to reach production PLCs without segmentation.
B.A severe storm causing extended power loss to the manufacturing plant.
C.A nation-state group conducting reconnaissance against critical manufacturing infrastructure.
D.Ransomware operators targeting industrial organizations for extortion payments.
E.Unpatched programmable logic controllers (PLCs) running firmware with known remote code execution flaws.
AnswersA, E

A flat network that permits engineering workstations to directly reach production PLCs is an architectural weakness. It increases the likelihood that a compromised workstation can pivot to control systems. This is a vulnerability because it is a condition of the environment that can be remediated through segmentation, firewalls, and access controls. It is a classic ICS risk finding, and its identification supports design changes that reduce the blast radius of an incident.

Why this answer

Vulnerabilities are internal weaknesses or conditions that a threat can exploit, such as unpatched PLCs with known flaws and flat network architecture exposing production systems. Threat actors and natural events exist independently and are classified as threats. Correctly separating the two is essential because treatment differs: vulnerabilities are remediated through patching, segmentation, and configuration, while threats are addressed by reducing exposure and improving detection and response.

Exam trap

The trap here is labeling threat actors or natural hazard events as vulnerabilities, which misdirects treatment toward controlling the attacker or the weather instead of fixing internal weaknesses.

64
MCQmedium

A retail bank's risk practitioner is building a risk scenario for its online banking platform. He needs to estimate how frequently an attacker could realistically succeed in exploiting the platform's unpatched web tier. Which of the following provides the MOST quantitative basis for this estimate?

A.Historical loss-event data from the bank's own incident and fraud systems for comparable attack types
B.The Common Vulnerability Scoring System (CVSS) base score of each unpatched vulnerability on the web tier
C.The mean time to remediate critical vulnerabilities reported by the bank's vulnerability management team
D.The annualized rate of new vulnerabilities published in the National Vulnerability Database (NVD) for web servers
AnswerA

Historical internal loss-event data reflects how often comparable attacks actually succeeded against this bank's environment, including its existing controls and threat exposure. This makes it the most defensible quantitative input for frequency estimation in the risk scenario, since it is grounded in observed events rather than theoretical severity or generic external statistics.

Why this answer

Frequency estimation in a risk scenario should be grounded in data that reflects how often the event actually occurs in the organization's own environment. Internal loss-event and incident data capture real attack attempts that succeeded despite existing controls. CVSS scores, industry vulnerability publication rates, and remediation timeliness describe severity or process performance rather than the expected rate of successful exploitation.

Exam trap

The trap here is treating a severity metric such as CVSS as if it were a frequency metric for the risk scenario.

65
Multi-Selecthard

During risk identification, a risk manager is reviewing threat intelligence sources. Which THREE of the following are considered legitimate sources of threat intelligence? (Choose three.)

Select 3 answers
A.Government advisories such as CISA Known Exploited Vulnerabilities (KEV) catalog
B.Unverified social media rumors
C.OSINT (Open-Source Intelligence) feeds
D.Information Sharing and Analysis Centers (ISACs)
E.Vendor sales presentations
AnswersA, C, D

Government advisories such as the CISA KEV catalog are authoritative, vetted sources listing vulnerabilities known to be actively exploited. They provide reliable, actionable intelligence for risk identification, satisfying the requirement for legitimate threat intelligence sources rather than unverified or vendor-marketing material.

Why this answer

OSINT (open-source intelligence), ISACs (sector-specific sharing), and government advisories (e.g., CISA KEV) are established threat intelligence sources. Social media rumor and vendor sales pitches are not reliable.

66
MCQmedium

A risk practitioner at a regional hospital is building a risk register entry for the loss of availability of its electronic health record (EHR) system. The practitioner wants to express the risk in a way that supports later quantification and treatment decisions. Which of the following BEST describes how the risk should be documented in the register?

A.As a paired statement of the event, its cause, and its business impact, such as 'EHR outage caused by ransomware exploitation of an unpatched server, leading to delayed clinical care and regulatory reporting failure'.
B.As a list of all unpatched servers and their IP addresses across the clinical network.
C.As a statement of the threat source only, such as 'ransomware gang targeting healthcare'.
D.As an accepted risk with no further detail because the EHR vendor holds a Business Associate Agreement.
AnswerA

A well-formed risk statement pairs a cause (unpatched server) with an event (ransomware-driven EHR outage) and a business consequence (delayed care, reporting failure). This structure lets the practitioner assess likelihood and impact, assign inherent and residual ratings, and choose treatment. It also aligns the register entry with ISACA guidance that risks be expressed in business-relevant terms so leadership can compare and fund responses.

Why this answer

Expressing risk as a cause-event-impact triplet gives the practitioner the components needed to estimate likelihood and magnitude and to select treatment. It also links technical conditions to business outcomes, which is what the register is for. The other choices capture only an actor, only a vulnerability inventory, or an unsupported acceptance decision, none of which supports quantification or comparison across the risk portfolio.

Exam trap

The trap here is treating a vulnerability finding or a threat actor profile as if it were a risk, when a risk requires an event tied to a business impact.

67
MCQhard

A risk practitioner is using the ISACA risk scenario development approach to articulate a risk related to a third-party payment processor. The practitioner wants to ensure the scenario includes all key components. Which of the following components is MOST critical to include to enable effective risk analysis and treatment?

A.The asset, threat, vulnerability, and potential impact
B.The name of the specific threat actor group
C.The regulatory requirements applicable to the payment processor
D.The cost of the third-party processor's service
AnswerA

The core components of a risk scenario are the asset at risk, the threat that could affect it, the vulnerability that could be exploited, and the potential impact. These elements enable the practitioner to assess likelihood and impact, and to determine appropriate risk treatment. Without them, the scenario is incomplete and cannot be effectively analyzed or managed.

Why this answer

A well-structured risk scenario includes the asset, threat, vulnerability, and impact. These components allow the practitioner to assess the probability and consequence of the risk and to design appropriate responses. Other details like threat actor names, costs, or regulations are secondary and do not replace the fundamental elements needed for risk analysis and treatment.

Exam trap

The trap here is focusing on contextual details like the threat actor's name or regulatory requirements, which are not the core components that enable risk analysis and treatment.

68
MCQmedium

A company is updating its risk register. Which of the following is the primary purpose of a risk register?

A.To define risk appetite
B.To record and track identified risks and their treatment
C.To store threat intelligence feeds
D.To document all IT assets
AnswerB

The risk register is the central repository capturing each identified risk, its owner, likelihood, impact and agreed treatment, enabling ongoing tracking and review. This satisfies the stem's requirement to update the register with identified risks and their treatment.

Why this answer

A risk register's primary purpose is to serve as the central repository that records identified risks, their owners, likelihood/impact ratings, and treatment decisions (mitigate, transfer, accept, avoid), enabling ongoing tracking and reporting. It is a living document used by risk managers to monitor status over time. Defining risk appetite is a governance activity that precedes and informs the register, not its purpose.

Exam trap

CRISC often tests the distinction between governance artifacts — candidates confuse the risk register (a tracking tool) with risk appetite (a policy decision) or with asset/threat inventories (data sources).

How to eliminate wrong answers

Option A is wrong because risk appetite is set by senior management/board as a policy statement about how much risk the organization is willing to accept; it is an input to the register, not the register's purpose. Option C is wrong because threat intelligence feeds are external data sources that may inform risk identification, but the register stores risk entries, not raw feeds. Option D is wrong because IT asset inventory is maintained in a CMDB or asset management system; while assets may be referenced in risk entries, documenting all assets is not the register's function.

69
MCQhard

A risk manager is assessing the risk of a distributed denial-of-service (DDoS) attack on a critical online service. The service has a service-level agreement (SLA) that requires 99.9% uptime. The manager has identified that the likelihood of a DDoS attack is high, but the impact is considered low because the service can fail over to a backup data center. Which of the following should the risk manager do NEXT?

A.Validate the effectiveness of the failover mechanism under a DDoS attack.
B.Transfer the risk by purchasing cyber insurance for DDoS attacks.
C.Mitigate the risk by implementing a DDoS protection service.
D.Accept the risk because the impact is low and the SLA can be met.
AnswerA

The risk manager assumed low impact based on failover, but that assumption must be validated. Failover may not work under a DDoS attack if the backup data center is also targeted or if failover triggers are not met. Validating the control ensures the impact assessment is accurate and the risk is properly understood.

Why this answer

The risk manager's impact assessment relies on the failover mechanism working during a DDoS attack. Before proceeding, the manager must validate that the failover can handle a DDoS scenario. If it cannot, the impact may be higher than assumed.

Validating the control ensures the risk assessment is accurate and informs subsequent risk response decisions.

Exam trap

The trap here is accepting the impact assessment at face value without verifying the underlying control, which could lead to underestimating risk.

70
MCQmedium

When identifying vulnerabilities, which of the following is the BEST source for configuration-related vulnerabilities in operating systems?

A.NVD
B.CVE database
C.OWASP Top 10
D.CIS Benchmarks
AnswerD

CIS Benchmarks provide prescriptive, platform-specific secure configuration baselines for operating systems, mapping directly to configuration weaknesses. They satisfy the stem's configuration focus by detailing exact settings, registry values and service states to compare against, unlike vulnerability scanners that detect missing patches or generic threat feeds lacking hardening guidance.

Why this answer

CIS Benchmarks are industry-recognized configuration guidelines that help identify and remediate configuration-related vulnerabilities in operating systems. Unlike NVD or CVE which catalog known vulnerabilities, CIS Benchmarks provide actionable hardening steps for system configurations.

71
Multi-Selectmedium

A risk practitioner at a software company is reviewing external sources to identify emerging IT risks that could affect the organization's cloud-hosted products. The practitioner wants to use sources that provide structured, timely information about newly disclosed software weaknesses. Which TWO of the following sources BEST meet this need? (Choose two.)

Select 2 answers
A.Prior-year internal audit findings
B.National Vulnerability Database (NVD) records
C.Common Vulnerabilities and Exposures (CVE) listings
D.Internal employee satisfaction survey results
E.Facilities maintenance work order logs
AnswersB, C

The NVD enriches CVE identifiers with severity scoring, affected product mappings, and references, making it a structured and timely source for prioritizing newly disclosed weaknesses. It allows the practitioner to filter and rank vulnerabilities relevant to the cloud products in scope. Because it is maintained as a public reference with consistent data fields, it directly supports emerging-risk identification and comparison across many software components.

Why this answer

Emerging IT risk identification benefits from external, structured, and current sources that describe newly disclosed weaknesses. CVE listings supply standardized identifiers for disclosed vulnerabilities, and NVD records add severity scoring and product mappings that let the practitioner prioritize. Together they provide the timeliness and structure needed.

Internal surveys, past audit findings, and facilities logs are either retrospective, unrelated to software weaknesses, or both, so they cannot fulfill the same purpose.

Exam trap

The trap here is treating any internal record as a valid risk identification source, when the requirement specifically calls for structured and timely external information about newly disclosed software weaknesses.

72
MCQeasy

Which threat actor is most likely motivated by political ideology and may target government systems?

A.Organized crime
B.Nation-state APT
C.Hacktivist
D.Script kiddie
AnswerC

Hacktivists are driven by political, ideological or social agendas, and they frequently deface or disrupt government, military and activist-related systems to publicise their cause. Unlike financially motivated cybercriminals or state-sponsored actors, their primary motivation is ideological, matching the stem's political-ideology and government-target criteria.

Why this answer

Hacktivists are threat actors whose primary motivation is political ideology, social activism, or protest. They often target government systems to disrupt operations, deface websites, or leak sensitive information in order to advance their political agenda, making option C correct.

Exam trap

The trap here is confusing nation-state APTs with hacktivists because both may target government systems, but the key differentiator is motivation: nation-state APTs act for geopolitical or espionage reasons, while hacktivists are driven by political ideology and often seek public visibility.

How to eliminate wrong answers

Option A is wrong because organized crime is motivated by financial gain, not political ideology, and typically targets financial institutions or data for resale. Option B is wrong because nation-state APTs are state-sponsored actors focused on espionage, geopolitical advantage, or strategic disruption, not primarily political ideology or public protest. Option D is wrong because script kiddies are unskilled attackers using pre-made tools for notoriety or fun, lacking the ideological motivation to specifically target government systems.

73
Multi-Selectmedium

A risk practitioner at a regional bank is compiling a list of internal threat sources for the enterprise risk assessment. Which TWO of the following are internal threat sources that should be included? (Choose two.)

Select 2 answers
A.A nation-state actor conducting espionage against financial regulators
B.A terminated employee who retained a VPN credential
C.A contractor with privileged access to the core banking platform
D.An organized crime group running ransomware campaigns
E.A hacktivist group targeting the bank's public website
AnswersB, C

A former employee who still holds valid access is an internal threat source because the actor has or had trusted access to bank systems. Insider threats include malicious, negligent, and compromised insiders, and the terminated employee with a live credential fits the malicious or negligent insider category. This directly affects the likelihood assessment for unauthorized access scenarios.

Why this answer

Internal threat sources are actors who operate within or with trusted access to the organization, including current and former employees, contractors, and other insiders with authorized privileges. The terminated employee with a retained credential and the contractor with privileged platform access both meet that definition. Hacktivists, nation-state actors, and organized crime groups are external sources even when they target the bank.

Exam trap

The trap here is assuming that any actor who attacks the bank is an internal source, when internal classification depends on trusted access rather than on intent or target.

74
Multi-Selecteasy

Which TWO of the following are types of insider threats?

Select 2 answers
A.Malicious
B.Nation-state
C.Hacktivist
D.Negligent
E.Script kiddie
AnswersA, D

Malicious insiders act with deliberate intent to steal data, sabotage systems or abuse privileged access for gain. This satisfies the stem's requirement for an insider threat type, contrasting premeditated action with accidental or coerced behaviour.

Why this answer

Insider threats can be malicious (intentional harm) or negligent (unintentional mistakes).

75
MCQmedium

A risk practitioner at a regional bank is building a threat landscape for its new mobile payment platform. A recently published report from a national CERT indicates that a loosely organized group has been targeting payment APIs across the region, exploiting known authentication weaknesses. The practitioner wants to determine whether this group should be treated as a relevant threat source in the risk register. Which of the following is the MOST appropriate FIRST step?

A.Immediately add the group to the risk register as a high-rated threat because it appears in a national CERT report.
B.Implement additional authentication controls on the mobile payment APIs to mitigate the reported weaknesses.
C.Subscribe to additional commercial threat intelligence feeds to obtain more detail on the group's activities.
D.Assess the group's capability, intent, and opportunity against the bank's specific mobile payment assets.
AnswerD

Risk identification requires evaluating threat sources in terms of capability, intent, and opportunity relative to the organization's own assets. The CERT report establishes general activity, but relevance to the bank depends on whether the group can realistically reach and exploit the mobile payment APIs. This asset-centric assessment determines if the threat is material and warrants entry into the risk register.

Why this answer

Threat sources become relevant only when evaluated against the organization's own assets through capability, intent, and opportunity. A CERT report signals activity in the sector, but the bank must determine whether the group can realistically reach and exploit its mobile payment APIs. That asset-centric analysis is the first step before the threat is entered into the risk register or any control is selected.

Exam trap

The trap here is treating external threat intelligence as a direct input to the risk register without first assessing the threat source against the organization's specific assets.

Page 1 of 2 · 146 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Crisc Risk Identification questions.