Courseiva

CCNA Crisc Risk Response Questions

75 of 176 questions · Page 1/3 · Crisc Risk Response topic · Answers revealed

1
MCQmedium

A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?

A.No change in risk level
B.Improved security posture
C.Increased vulnerability risk
D.Decreased vulnerability risk
AnswerC

Patch lag measures elapsed time between patch release and deployment. Rising from 15 to 45 days means exposure windows widen, so unpatched vulnerabilities persist longer and the likelihood of exploitation grows. The KRI trend therefore signals increased vulnerability risk, the exposure the metric tracks.

Why this answer

The patch lag KRI measures the time between a patch's release and its deployment. An increase from 15 to 45 days means systems are exposed to known vulnerabilities for a longer period, directly increasing the window of opportunity for exploitation. This trend indicates a worsening security posture and higher vulnerability risk.

Exam trap

The trap here is that candidates may confuse a KRI trend with a risk level itself, thinking a change in the indicator does not necessarily mean a change in risk, but in CRISC, a worsening KRI like patch lag directly signals increased vulnerability risk.

How to eliminate wrong answers

Option A is wrong because a significant increase in patch lag from 15 to 45 days represents a clear change in risk level, not no change. Option B is wrong because an increased patch lag means patches are applied more slowly, which degrades rather than improves the security posture. Option D is wrong because a longer delay in applying patches increases the attack surface and vulnerability risk, rather than decreasing it.

2
MCQmedium

A risk practitioner is preparing an IT risk report for the board risk committee. The committee has limited technical background and meets quarterly. Which of the following is the MOST appropriate way to present the aggregated IT risk exposure?

A.A raw export of the vulnerability scanner console showing every open finding with its CVSS score
B.The mean time to remediate critical incidents compared with the prior four quarters
C.A list of every control test performed during the quarter with pass or fail results
D.A heat map showing inherent and residual risk ratings mapped to the enterprise risk taxonomy
AnswerD

A heat map aligned to the enterprise risk taxonomy lets a non-technical board compare IT risk against other risk domains at a glance, showing both inherent exposure and the effect of controls through residual ratings. It supports aggregation and trend comparison across quarters, which is precisely what a quarterly governance committee needs to prioritize and challenge management decisions.

Why this answer

Board-level risk reporting must translate technical detail into business-relevant exposure that can be compared, aggregated, and tracked over time. Mapping inherent and residual ratings to the enterprise risk taxonomy lets the committee see IT risk alongside other risk categories and judge whether responses are proportionate. Raw findings, individual control tests, and single operational metrics all require interpretation the committee should not have to perform.

Exam trap

The trap here is assuming that more granular technical data automatically makes a report more useful, when governance audiences actually need aggregated, business-contextualized exposure.

3
MCQhard

An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?

A.User training
B.Change management
C.Vulnerability scanning
D.Access review
AnswerB

Change management governs how modifications to existing systems are assessed, approved and recorded, directly satisfying the project manager's need to control alterations during implementation. It prevents unauthorised or untested changes disrupting production, aligning the security control rollout with established baselines and audit trails required under CRISC's change control domain.

Why this answer

Change management ensures that changes to systems are controlled, tested, and approved to prevent unintended disruptions or security gaps. It is essential during control implementation.

4
MCQmedium

During a cost-benefit analysis for a new control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce risk by 80% and will cost $150,000 annually to operate. What is the net benefit of implementing the control?

A.$400,000
B.$100,000
C.$350,000
D.$250,000
AnswerD

Risk reduction equals 80% of the $500,000 ALE, or $400,000. Subtracting the $150,000 annual control operating cost gives a net benefit of $250,000, the figure that justifies the control against the cost-benefit constraint in the stem.

Why this answer

ALE reduction is 80% of $500,000 = $400,000. Net benefit = ALE reduction - annual control cost = $400,000 - $150,000 = $250,000.

5
MCQeasy

Which of the following is the most appropriate frequency for operational IT risk reporting to IT management?

A.Annually
B.Quarterly
C.Weekly or monthly
D.Semi-annually
AnswerC

Operational risk reporting feeds day-to-day IT management, so weekly or monthly cycles align with the pace of operational change and let management act on emerging issues before they escalate. Quarterly or annual intervals would leave operational exposures unaddressed for too long.

Why this answer

Operational risk reporting is typically provided on a weekly or monthly basis to IT management to support day-to-day decision-making.

6
MCQmedium

In third-party risk management, which of the following is MOST indicative of a vendor's control effectiveness for a critical vendor?

A.SOC 2 Type II report
B.Contractual security requirements
C.Vendor's self-assessment questionnaire
D.Vendor's marketing materials
AnswerA

A SOC 2 Type II report provides independent auditor testing of control design and operating effectiveness across a period, directly addressing whether the critical vendor's controls actually functioned. This period-based evidence distinguishes it from self-attestations or Type I point-in-time reports, satisfying the effectiveness criterion.

Why this answer

A SOC 2 Type II report is the most indicative of a vendor's control effectiveness because it provides an independent auditor's opinion on the design and operating effectiveness of controls over a specified period (typically 6–12 months). For a critical vendor, this third-party attestation offers objective evidence that security and privacy controls are actually working, not just promised.

Exam trap

The trap here is that candidates often confuse contractual requirements or self-assessments as sufficient evidence of control effectiveness, but the exam tests that only an independent, audited report like SOC 2 Type II provides the objective assurance needed for critical vendors.

How to eliminate wrong answers

Option B is wrong because contractual security requirements are only promises and obligations, not evidence that controls are actually implemented or effective; they lack independent verification. Option C is wrong because a vendor's self-assessment questionnaire is subjective, unaudited, and prone to bias or incomplete responses, providing no assurance of actual control operation. Option D is wrong because marketing materials are promotional content designed to sell services, not factual evidence of control effectiveness, and they contain no technical or operational details.

7
MCQeasy

An organization is implementing a new access control system. Which of the following should be included in the control implementation plan?

A.Annual cost of the control only
B.Key Risk Indicators (KRIs) for the control
C.Project milestones, training schedule, and documentation updates
D.Risk assessment results
AnswerC

Project milestones, training schedule, and documentation updates constitute the implementation plan's core components, ensuring the control is deployed on time, users are trained, and records reflect the change. This satisfies the stem's requirement for what belongs in a control implementation plan, covering delivery, competence, and audit evidence.

Why this answer

The control implementation plan must be actionable and comprehensive, covering the practical steps needed to deploy the new access control system. Option C includes project milestones (timeline), training schedule (ensuring users and administrators know how to use the system), and documentation updates (keeping policies, procedures, and system documentation current). These elements are essential for a successful implementation and align with CRISC's focus on integrating risk management into business processes.

The other options are either too narrow (cost only) or are inputs to the plan rather than components of the plan itself.

Exam trap

CRISC often tests the distinction between inputs to risk management processes and the components of implementation plans, causing candidates to confuse risk assessment results or KRIs as part of the plan rather than as separate elements.

How to eliminate wrong answers

Option A is wrong because focusing solely on the annual cost of the control ignores other critical aspects of implementation such as timeline, training, and documentation, which are necessary for effective deployment and ongoing operation. Option B is wrong because Key Risk Indicators (KRIs) are metrics used to monitor risk levels after controls are in place; they are not typically part of the implementation plan itself, which focuses on the steps to deploy the control. Option D is wrong because risk assessment results are an input to the decision to implement a control and help define requirements, but they are not components of the implementation plan; the plan should detail how the control will be implemented, not restate the risk assessment.

8
MCQmedium

In third-party risk management, which of the following is typically used for initial onboarding assessment of a vendor?

A.Contract compliance review
B.Security questionnaire
C.SOC 2 Type II report
D.Shared intelligence platform feed
AnswerB

A security questionnaire collects the vendor's control, compliance and data-handling details before any contract or data sharing, making it the standard initial onboarding assessment. It is proportionate and repeatable at scale, unlike audits or penetration tests reserved for higher-risk vendors.

Why this answer

Security questionnaires are commonly used during initial vendor assessment to gather information about the vendor's security posture.

9
MCQmedium

An IT risk manager is preparing a report for the board of directors. Which of the following content elements is most important for strategic risk reporting?

A.Weekly vulnerability scan results
B.IT risk integration with enterprise risk management
C.List of all vendor risk assessments
D.Detailed control performance metrics
AnswerB

Board-level reporting demands a strategic, aggregated view, so integrating IT risk into enterprise risk management lets the board see IT exposure alongside other business risks and prioritise investment accordingly. Standalone IT risk registers lack that enterprise context.

Why this answer

Strategic risk reporting to the board requires a high-level view that aligns IT risk with enterprise objectives. Option B is correct because it demonstrates how IT risk is integrated into the broader enterprise risk management (ERM) framework, enabling the board to understand the business impact of IT risks. This integration is essential for strategic decision-making, as it connects technical risk data to organizational goals and risk appetite.

Exam trap

The trap here is that candidates often confuse operational reporting (e.g., vulnerability scans, control metrics) with strategic reporting, failing to recognize that the board requires a consolidated, business-aligned view of risk rather than detailed technical data.

How to eliminate wrong answers

Option A is wrong because weekly vulnerability scan results are operational, tactical data that is too granular and frequent for board-level strategic reporting; the board needs aggregated risk trends, not raw scan outputs. Option C is wrong because listing all vendor risk assessments is an operational detail that does not convey strategic risk posture or business impact; the board requires a summary of key vendor risks and their effect on enterprise objectives. Option D is wrong because detailed control performance metrics, such as specific control failure rates, are more appropriate for management and audit reporting, not for the board's strategic view, which focuses on risk exposure and mitigation effectiveness at a macro level.

10
MCQhard

An organization's IT risk team is promoting a risk-aware culture. Which initiative is most likely to encourage employees to report security incidents without fear?

A.Establishing a no-blame incident reporting policy
B.Publishing quarterly incident statistics
C.Increasing the frequency of security awareness training
D.Implementing automated incident detection
AnswerA

A no-blame policy removes the fear of punitive consequences, directly addressing the stem's constraint that staff withhold incident reports due to blame. By decoupling reporting from disciplinary action, it increases the volume and speed of disclosures, giving risk management earlier visibility of actual losses and control failures.

Why this answer

A no-blame incident reporting policy directly addresses the psychological barrier of fear of reprisal, which is the primary reason employees hesitate to report security incidents. By explicitly stating that reporters will not face disciplinary action for unintentional errors or omissions, the organization fosters psychological safety and encourages timely reporting, which is critical for effective risk response.

Exam trap

The trap here is that candidates may confuse 'increasing awareness training' (Option C) with addressing fear, when in fact training alone does not remove the organizational culture of blame that discourages reporting.

How to eliminate wrong answers

Option B is wrong because publishing quarterly incident statistics provides transparency and awareness but does not address the fear of personal consequences that prevents employees from reporting incidents. Option C is wrong because increasing the frequency of security awareness training improves knowledge and vigilance but does not remove the fear of blame or punishment for reporting an incident. Option D is wrong because implementing automated incident detection improves technical detection capabilities but does not influence human behavior or the cultural willingness to report incidents voluntarily.

11
MCQmedium

A company is implementing a new access control system. According to the project plan, user training will be delivered after the system goes live. What change management issue does this present?

A.Training after go-live ensures the system is fully operational
B.Training after go-live is more effective because users have context
C.Training after go-live reduces the project budget
D.Training after go-live may lead to user errors and security incidents
AnswerD

Delaying training until after go-live means users operate the new access control system without knowing correct procedures, producing misconfigurations and access errors that become security incidents, directly violating the change management requirement that users be prepared before implementation.

Why this answer

Training should ideally be delivered before go-live to ensure users can operate the system securely. Delaying training increases the risk of errors and security incidents.

12
Multi-Selectmedium

An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?

Select 3 answers
A.Using consistent risk metrics and terminology across IT and enterprise levels
B.Aligning IT risk appetite with enterprise risk appetite
C.Reporting IT risk as a component of broader operational risk
D.Maintaining a separate IT risk register not shared with ERM
E.Reporting IT risks only to the CIO without board visibility
AnswersA, B, C

Shared metrics and terminology let IT risk data roll up into enterprise reporting without translation loss, enabling aggregation and comparison across the ERM framework. This consistency is a foundational integration activity, aligning how risk is measured and described at both levels.

Why this answer

Option A is correct because using consistent risk metrics and terminology across IT and enterprise levels enables IT risk data to be aggregated, compared, and communicated within the ERM framework rather than being siloed in IT-specific language. Option B is correct because aligning IT risk appetite with enterprise risk appetite ensures IT risk tolerances and thresholds are derived from and consistent with the organization's overall risk appetite, which is a core requirement of ERM integration. Option C is correct because reporting IT risk as a component of broader operational risk allows IT risk to be consolidated into enterprise risk reporting, giving leadership a holistic view of risk exposure.

Option D does not belong because maintaining a separate IT risk register not shared with ERM perpetuates silos and prevents aggregation and enterprise-level visibility. Option E does not belong because reporting IT risks only to the CIO without board visibility excludes key governance stakeholders and contradicts the top-down, board-engaged nature of ERM integration.

Exam trap

The trap here is that candidates may think maintaining a separate IT risk register is acceptable for specialized IT risks, but CRISC emphasizes that integration requires sharing and aligning risk information across all levels, not isolating it.

13
MCQmedium

During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control will cost $100,000 annually and is expected to reduce the ALE by 80%. What is the net benefit of implementing this control?

A.$100,000
B.$300,000
C.$400,000
D.$500,000
AnswerB

The control reduces ALE by 80%, giving an annualised loss reduction of $400,000. Subtracting the $100,000 annual control cost yields a net benefit of $300,000, satisfying the cost-benefit constraint in the stem. This figure represents the residual value gained after funding the control.

Why this answer

The current annual loss expectancy (ALE) is $500,000. An 80% reduction lowers the ALE by $400,000, resulting in a new ALE of $100,000. The annual control cost is $100,000, so the net benefit is the reduction in ALE ($400,000) minus the control cost ($100,000), which equals $300,000.

Exam trap

CRISC often tests the distinction between gross reduction in ALE and net benefit, tricking candidates into forgetting to subtract the annual control cost from the ALE reduction.

How to eliminate wrong answers

Option A is wrong because $100,000 represents only the annual control cost, not the net benefit after accounting for the ALE reduction. Option C is wrong because $400,000 is the gross reduction in ALE (80% of $500,000) but fails to subtract the $100,000 control cost. Option D is wrong because $500,000 is the original ALE before any control is applied, ignoring both the reduction and the cost of the control.

14
MCQeasy

A risk practitioner has completed a risk assessment and documented the findings. Management must now decide how to address each identified risk. Which of the following BEST describes the purpose of the risk response process?

A.To document the inherent risk rating for each asset so it can be reported to regulators
B.To transfer ownership of every risk to the information security team for remediation
C.To eliminate all identified risks regardless of the cost of the controls required
D.To select and implement actions that bring residual risk within the organization's risk appetite
AnswerD

The risk response process exists to move exposure from its assessed level to a level the organization is willing to tolerate. Selecting and implementing mitigation, transfer, avoidance, or authorized acceptance achieves that alignment. It is the bridge between knowing what the risk is and doing something proportionate about it, and it is judged by whether residual risk lands within the appetite the board has approved.

Why this answer

Risk response is the decision and action phase that follows assessment. Its purpose is to bring residual risk into alignment with the organization's risk appetite through mitigation, transfer, avoidance, or authorized acceptance. It is not about eliminating all risk, merely documenting ratings, or centralizing ownership in one team; it is about taking proportionate, accountable action on the exposures that matter.

Exam trap

The trap here is confusing the documentation of risk ratings with the act of responding to risk, when recording a rating leaves the exposure unchanged.

15
MCQmedium

A Key Risk Indicator (KRI) that shows a rising trend in the average time to apply critical security patches suggests:

A.Decreasing risk of exploitation
B.Stable risk level
C.Increasing risk of exploitation
D.Improved control effectiveness
AnswerC

A rising average patch time means critical vulnerabilities remain exploitable for longer, widening the window attackers can leverage. The KRI measures exposure duration, so the upward trend directly signals growing likelihood of successful exploitation rather than improved remediation.

Why this answer

A rising trend in the average time to apply critical security patches indicates that systems remain vulnerable for longer periods, increasing the likelihood of exploitation. This is a lagging indicator of control effectiveness and directly points to increased risk.

Exam trap

Candidates may confuse KRIs with KPIs and think a rising trend in a security metric means improved performance, but here it's a risk indicator.

How to eliminate wrong answers

Option A is wrong because decreasing risk would be indicated by a falling trend in patch time, not rising. Option B is wrong because a rising trend indicates a change, not stability. Option D is wrong because improved control effectiveness would result in faster patching, not slower.

16
MCQhard

A risk practitioner notices that the number of failed authentication attempts has spiked by 300% over the past week. Which of the following actions should be taken FIRST?

A.Report the spike to the board
C.Increase the frequency of password changes
D.Analyze the logs to identify the source and nature of the attempts
AnswerD

Analysing logs establishes whether the 300% spike reflects a brute-force attack, misconfigured application or credential-stuffing campaign. This satisfies the first-action constraint by determining the source and nature of the attempts before escalating, blocking or notifying, avoiding a premature response to an unidentified cause.

Why this answer

The first step in responding to a security incident, such as a 300% spike in failed authentication attempts, is to analyze the logs to determine the source and nature of the activity. This aligns with the NIST incident response lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery) where analysis precedes any containment or reporting action. Without understanding whether the spike is due to a brute-force attack, a misconfigured application, or a credential-stuffing campaign, any subsequent action could be premature or ineffective.

Exam trap

The trap here is that candidates often jump to implementing a security control (like MFA or password changes) as a first response, but CRISC emphasizes that analysis and understanding of the risk must precede any response action.

How to eliminate wrong answers

Option A is wrong because reporting a spike to the board without first analyzing the logs is premature; the board requires actionable, analyzed information, not raw alerts. Option B is wrong because implementing multi-factor authentication (MFA) is a long-term control that should be designed and deployed after understanding the attack vector, not as an immediate response to a log spike. Option C is wrong because increasing the frequency of password changes does not address the root cause of failed authentication attempts (e.g., brute force or credential stuffing) and can actually weaken security by encouraging weak passwords; it is not a first-response action.

17
MCQmedium

In IT risk reporting, which level of management typically receives operational risk reporting on a weekly or monthly basis?

A.External auditors
B.Board of directors
C.IT management
D.CISO/CIO
AnswerC

IT management owns day-to-day operational risk, so weekly or monthly reporting matches their remit for monitoring controls, incidents and remediation. Senior executives and the board receive aggregated risk reporting quarterly or annually, making IT management the level whose cadence aligns with operational detail.

Why this answer

IT management is the level that typically receives operational risk reporting on a weekly or monthly cadence because they own the day-to-day operation of systems and controls. Operational risk reports at this frequency give IT managers the detail needed to act on incidents, vulnerabilities, and control gaps. Higher-level audiences receive more aggregated and less frequent reporting.

Exam trap

CRISC often tests the mapping between management level and reporting frequency/granularity — candidates confuse the CISO/CIO's monthly risk posture reporting with IT management's weekly operational reporting, or assume the board receives operational detail.

How to eliminate wrong answers

Option A is wrong because external auditors are independent reviewers who receive evidence during audits, not routine recipients of weekly/monthly operational risk reports. Option B is wrong because the board of directors receives strategic, aggregated risk reporting (typically quarterly or annually), not detailed operational reporting on a weekly or monthly basis. Option D is wrong because the CISO/CIO receives management-level risk reporting, often monthly or quarterly, focused on risk posture and trends rather than the granular operational reports IT management consumes weekly.

18
MCQeasy

An organization's risk register lists a ransomware exposure against its primary order-processing system. The chief information security officer decides to purchase cyber insurance that covers ransomware losses up to $10 million. Which risk response has been selected?

A.Risk transfer
B.Risk avoidance
C.Risk acceptance
D.Risk mitigation
AnswerA

Purchasing cyber insurance shifts the financial consequence of ransomware losses to the insurer in exchange for a premium, which is the defining characteristic of risk transfer. The threat still exists and the system keeps operating, but the economic burden of a covered event moves to a third party. Transferring risk does not eliminate it, so residual exposure such as deductibles and uncovered amounts must still be tracked and accepted.

Why this answer

Risk transfer shifts the financial impact of a risk to another party, most commonly through insurance or contractual indemnification. Purchasing a cyber insurance policy leaves the ransomware threat and the system unchanged while moving the monetary consequence to the insurer. Because deductibles, exclusions, and coverage caps remain the organization's burden, the residual risk must still be recorded and accepted.

Exam trap

The trap here is assuming that any action taken against a risk counts as mitigation, when shifting the financial consequence is specifically transfer.

19
MCQeasy

An IT risk report to the board of directors should primarily focus on which of the following?

A.Strategic risks and risk trends affecting the organization
B.Specific control test results for each system
C.Vendor risk assessment scores for all third parties
D.Detailed weekly operational incidents
AnswerA

Boards govern strategy and appetite, so reporting must translate IT risk into strategic exposure and emerging trends rather than operational detail. This lets directors judge whether risk levels align with tolerance and direct management accordingly, satisfying the board's oversight role.

Why this answer

The board of directors requires a high-level view of IT risk that aligns with business strategy and enterprise risk management. Strategic risks and risk trends provide the necessary context for informed decision-making, focusing on the aggregate impact of risk on organizational objectives rather than operational minutiae.

Exam trap

The CRISC exam often tests the distinction between operational reporting (tactical, detailed) and strategic reporting (aggregated, trend-based), and the trap here is that candidates mistake granular data (like control test results or incident logs) as more 'thorough' or 'accurate' for the board, when in fact the board needs summarized, risk-based insights.

How to eliminate wrong answers

Option B is wrong because specific control test results for each system are too granular for the board; they are more appropriate for operational management and internal audit reporting. Option C is wrong because vendor risk assessment scores for all third parties are tactical details that should be summarized into aggregate risk exposure or trends for board-level reporting. Option D is wrong because detailed weekly operational incidents are operational metrics, not strategic risk information, and would overwhelm the board with noise rather than actionable insight.

20
MCQeasy

Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?

A.Failed authentication spike
B.Number of accounts created
C.Password reset frequency
D.Number of successful logins
AnswerA

A spike in failed authentication attempts is measurable before a breach succeeds, making it a leading indicator. It signals attackers actively probing credentials, unlike lagging indicators such as confirmed account compromises, which only appear after the attack has already occurred.

Why this answer

A leading indicator predicts future risk before loss occurs. A spike in failed authentication attempts is a precursor signal — it suggests credential stuffing, brute-force, or password-spraying activity is underway, which may precede a successful credential-based compromise. Because it is observable before the breach materializes, it functions as a leading indicator that the risk of credential-based attack is increasing.

Exam trap

CRISC often tests the leading vs lagging indicator distinction, and candidates commonly pick 'number of successful logins' or 'password reset frequency' because they sound security-relevant — the trap is that these are lagging or ambiguous metrics, while failed authentication is the predictive precursor.

How to eliminate wrong answers

Option B (Number of accounts created) is wrong because account creation volume is a general operational metric that does not specifically signal credential-based attack activity — it may reflect onboarding, provisioning, or even attacker-created accounts, but it is not a direct precursor of credential attacks. Option C (Password reset frequency) is wrong because password resets are typically a lagging or user-behavior indicator (often triggered after an incident or by helpdesk activity), not a leading signal of credential attack attempts. Option D (Number of successful logins) is wrong because successful logins are a lagging indicator — by the time logins succeed, the attack may already have succeeded; it does not predict increasing risk the way failed attempts do.

21
Multi-Selecthard

A healthcare insurer's risk committee is reviewing key risk indicators (KRIs) for its claims processing platform. The committee wants to ensure the KRIs are actionable and tied to risk appetite. Which TWO of the following characteristics are MOST important for these KRIs to meet that objective? (Choose two.)

Select 2 answers
A.Each KRI is directly linked to one or more identified risks and the corresponding risk appetite statement.
B.Each KRI is reviewed annually by internal audit to confirm it remains relevant to the business.
C.Each KRI has a defined threshold that triggers a documented escalation or response action.
D.Each KRI is measured using data that is manually collected once per quarter to ensure accuracy.
E.Each KRI is expressed as a monetary value so it can be aggregated with financial risk metrics.
AnswersA, C

A KRI must trace back to a specific risk and the appetite the organization has set for it; otherwise the committee cannot judge whether the measured level is acceptable. Linking the indicator to the claims platform risk and its appetite statement gives the metric meaning and ensures reporting focuses on exposures the insurer has chosen to manage within defined tolerances.

Why this answer

Actionable KRIs tied to risk appetite must connect to specific risks and appetite statements and must have thresholds that trigger defined responses. These two characteristics ensure the committee can interpret the indicator and act before the claims platform exposure exceeds tolerance. Measurement frequency and format are secondary considerations, and assurance review is not a substitute for management ownership of the indicators.

Exam trap

The trap here is confusing measurement mechanics, such as frequency or monetary units, with the governance characteristics that actually make a KRI actionable.

22
MCQmedium

A company is assessing a new vendor that will have access to its customer database. The vendor's security questionnaire reveals they lack SOC 2 certification. According to risk tiering, the vendor is classified as critical. What should the company do?

A.Accept the vendor because the questionnaire indicates other strong controls.
B.Require the vendor to obtain SOC 2 Type II certification before contract signing.
C.Proceed with the contract but increase monitoring frequency.
D.Lower the vendor's tier to medium to avoid the requirement.
AnswerB

Because the vendor is tiered critical and will access the customer database, the company must mandate SOC 2 Type II certification before signing, ensuring independent evidence of control operating effectiveness over time. This satisfies the risk-tiering requirement that critical vendors meet heightened assurance before data access is granted.

Why this answer

A critical-tier vendor with access to sensitive customer data requires independent assurance of security controls. SOC 2 Type II certification provides a rigorous, audited assessment of controls over a period of time, which is essential for a high-risk vendor. Requiring this certification before contract signing ensures the vendor meets the necessary security baseline before any data is exposed.

Exam trap

The trap here is that candidates may underestimate the importance of independent audit evidence for critical vendors and mistakenly choose increased monitoring (Option C) as a sufficient compensating control, when in fact it does not address the root need for verified, preventive controls before data access is granted.

How to eliminate wrong answers

Option A is wrong because accepting a critical-tier vendor based solely on a self-reported questionnaire, even with strong controls, lacks independent verification and audit rigor, which is a key requirement for high-risk data access. Option C is wrong because proceeding with the contract and increasing monitoring frequency does not address the lack of foundational, audited controls; monitoring is a detective control, not a preventive one, and is insufficient for a critical vendor. Option D is wrong because lowering the vendor's tier to avoid a requirement is a form of risk avoidance that circumvents proper risk management and policy, and it does not actually reduce the inherent risk of the vendor's access to sensitive data.

23
MCQeasy

Which type of control testing is typically performed on a continuous basis using automated tools?

A.Annual penetration test
B.Manual control walkthrough
C.Quarterly internal audit review
D.Continuous monitoring
AnswerD

Continuous monitoring relies on automated tooling to evaluate controls and configurations persistently, rather than sampling at a point in time. This contrasts with periodic assessments and substantive walkthrough testing, which are performed at intervals and cannot provide the ongoing assurance automation delivers.

Why this answer

Continuous monitoring is the control testing approach performed on an ongoing, automated basis using tools such as SIEM, configuration compliance scanners, and automated control assessment platforms. It provides real-time or near-real-time assurance that controls remain effective, unlike periodic manual reviews. This matches the question's description of continuous, automated testing.

Exam trap

CRISC often tests the distinction between continuous automated monitoring and periodic manual testing, and candidates commonly pick 'quarterly internal audit review' because it sounds like ongoing oversight — the trap is that quarterly is periodic, not continuous, and audit is not automated control testing.

How to eliminate wrong answers

Option A (Annual penetration test) is wrong because a penetration test is a point-in-time, typically manual or semi-automated assessment conducted annually or after major changes — it is not continuous. Option B (Manual control walkthrough) is wrong because a walkthrough is a manual, periodic procedure performed by auditors or risk staff to verify control design and operation, not an automated continuous activity. Option C (Quarterly internal audit review) is wrong because internal audit reviews are periodic (quarterly) and largely manual, providing retrospective assurance rather than continuous automated monitoring.

24
Multi-Selecthard

A risk manager is updating the risk report for the IT steering committee. Which THREE elements should be included to provide a comprehensive view of the risk posture?

Select 3 answers
A.Names of all IT employees
B.Risk trend analysis
C.Risk heat map
D.Detailed configuration of each firewall
E.Top risks and their status
AnswersB, C, E

Risk trend analysis reveals whether exposure is rising, falling or stable over successive reporting periods, satisfying the committee's need to judge direction rather than a single snapshot. Plotting inherent and residual risk across cycles exposes deteriorating controls and validates whether prior treatments worked, giving the forward-looking context a comprehensive posture view requires.

Why this answer

Risk trend analysis (B) is correct because tracking how risk exposure changes over time (e.g., increasing, decreasing, or stable risk levels across reporting periods) gives the steering committee insight into whether risk management efforts are effective and where emerging risks are developing. A risk heat map (C) is correct because it visually plots risks by likelihood and impact, enabling the committee to quickly identify and prioritize the highest-exposure areas across the organization's risk posture. Top risks and their status (E) is correct because summarizing the most significant risks along with their current mitigation status, owners, and progress provides the committee with actionable, decision-ready information for governance.

Names of all IT employees (A) is not a risk posture element—it is personnel data with no bearing on risk likelihood, impact, or treatment. Detailed configuration of each firewall (D) is far too granular and technical for a steering-committee risk report; such operational detail belongs in technical security documentation, not executive risk reporting.

Exam trap

ISACA often tests the distinction between operational details (like firewall configs) and strategic risk reporting elements, trapping candidates who confuse granular technical data with the high-level summaries needed for governance-level decision-making.

25
MCQmedium

Which of the following best describes the purpose of tactical risk reporting?

A.To satisfy regulatory compliance requirements
B.To inform the board of directors about strategic risk exposure
C.To provide daily operational metrics to system administrators
D.To enable the CISO to make informed decisions about risk mitigation priorities
AnswerD

Tactical reporting translates risk data into prioritised mitigation actions for senior security leadership, supporting near-term resource allocation decisions. Strategic reporting addresses long-term risk appetite, while operational reporting handles day-to-day execution, so tactical reporting uniquely equips the CISO to sequence mitigation priorities.

Why this answer

Tactical risk reporting is designed to provide mid-level management, such as the CISO, with actionable insights to prioritize risk mitigation activities. It focuses on operational risk decisions, not strategic oversight or daily metrics, enabling informed choices about resource allocation and remediation timelines.

Exam trap

The trap here is confusing the audience and time horizon of reporting levels—candidates often mistake tactical reporting for operational metrics (Option C) because both involve technical details, but tactical reporting is decision-focused for management, not daily task execution.

How to eliminate wrong answers

Option A is wrong because tactical risk reporting is not primarily for regulatory compliance; compliance reporting is a separate function that addresses specific legal or contractual requirements. Option B is wrong because informing the board about strategic risk exposure is the purpose of strategic risk reporting, which covers high-level, long-term risk posture. Option C is wrong because providing daily operational metrics to system administrators is the role of operational or technical reporting, not tactical reporting, which targets management decisions.

26
MCQmedium

An IT risk report for the board of directors should primarily focus on:

A.Specific control failures with root cause analysis
B.Detailed technical vulnerability scan results
C.Operational incident counts
D.Top risks, trends, and control performance metrics
AnswerD

Boards govern rather than operate, so they need aggregated top risks, directional trends and control performance metrics to judge whether risk appetite is being met. Operational detail and raw incident logs obscure this strategic view, failing the stem's board-reporting purpose.

Why this answer

A board-level IT risk report should communicate the most significant risks, emerging trends, and the effectiveness of controls in mitigating those risks. This enables directors to make informed strategic decisions and fulfill governance responsibilities. Operational details are typically reserved for management-level reporting.

Exam trap

CRISC often tests the confusion between operational reporting for management and strategic risk reporting for the board, tempting candidates to choose detailed technical data.

How to eliminate wrong answers

Option A is wrong because specific control failures with root cause analysis are too granular for a board audience and belong in management or audit reports. Option B is wrong because detailed technical vulnerability scan results are operational and not strategic; the board needs aggregated risk exposure, not raw scan data. Option C is wrong because operational incident counts are tactical metrics that do not convey the overall risk posture or control effectiveness required for governance.

27
Multi-Selectmedium

Which TWO of the following are examples of continuous monitoring activities? (Select TWO.)

Select 2 answers
A.Continuous vulnerability scanning
B.Annual penetration testing
C.Quarterly user access reviews
D.Automated SIEM rule-based alerts for suspicious activity
E.Monthly review of audit logs
AnswersA, D

Continuous vulnerability scanning qualifies because it runs on an automated, recurring schedule rather than at a single point in time, satisfying the stem's requirement for ongoing detection. Unlike periodic assessments, it feeds findings into risk registers continuously, enabling timely remediation decisions within the organisation's risk tolerance thresholds.

Why this answer

Continuous vulnerability scanning (A) is correct because it runs on an ongoing, automated schedule to detect new weaknesses as they emerge, which is the defining characteristic of a continuous monitoring activity. Automated SIEM rule-based alerts for suspicious activity (D) is also correct because SIEM correlation rules evaluate event streams in real time and generate alerts continuously, providing ongoing detection rather than point-in-time assessment. By contrast, annual penetration testing (B) and quarterly user access reviews (C) are periodic, scheduled point-in-time activities, and monthly review of audit logs (E) is a recurring but interval-based manual review, so none of these qualify as continuous monitoring.

28
MCQmedium

A risk owner is reviewing a control that has a deficiency rate of 15%. The target deficiency rate is less than 5%. Which of the following is the MOST appropriate immediate action?

A.Investigate the root cause of the high deficiency rate
B.Increase the target deficiency rate to 15%
C.Report the deficiency to the external auditor
D.Accept the risk and document the decision
AnswerA

A 15% deficiency rate against a sub-5% target signals the control is failing materially. Root-cause investigation must precede remediation, otherwise corrective actions address symptoms rather than the underlying process, configuration or ownership failure driving the gap.

Why this answer

A deficiency rate of 15% against a target of less than 5% indicates a control failure that requires immediate remediation. Investigating the root cause is the first step in the risk response process to identify why the control is failing and to determine the appropriate corrective action, aligning with the Risk Response and Reporting domain's emphasis on addressing control deficiencies before considering acceptance or reporting.

Exam trap

The trap here is that candidates may choose 'Accept the risk and document the decision' (Option D) because they confuse risk acceptance with a standard response to control deficiencies, but CRISC emphasizes that acceptance is only appropriate after a formal risk assessment and when remediation is not feasible or cost-justified.

How to eliminate wrong answers

Option B is wrong because increasing the target deficiency rate to 15% would lower the control standard without addressing the underlying failure, effectively ignoring the risk and violating the principle of maintaining control effectiveness. Option C is wrong because reporting the deficiency to the external auditor is premature; the immediate action should be internal investigation and remediation, not external disclosure, which occurs after analysis and as part of formal reporting cycles. Option D is wrong because accepting the risk without understanding the root cause or attempting remediation bypasses the risk treatment process; acceptance should be a deliberate decision after evaluating the impact and likelihood, not the first action upon discovering a high deficiency rate.

29
Multi-Selecthard

Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)

Select 3 answers
A.Risk trend analysis over time
B.Risk heat map showing current risk levels
C.Names of all third-party vendors with contracts
D.List of top risks and their mitigation status
E.Detailed control deficiency descriptions
AnswersA, B, D

Trend analysis over time reveals whether risk exposure is rising, falling or stable, letting senior management judge whether current mitigation spending is working. Without this longitudinal view, the report shows only a static snapshot and cannot support the forward-looking direction the board needs for risk appetite decisions.

Why this answer

Option A (Risk trend analysis over time) is essential because senior management needs to see whether the organization's risk posture is improving, worsening, or stable across reporting periods, which supports strategic decisions rather than a single point-in-time snapshot. Option B (Risk heat map showing current risk levels) is correct because a heat map visually prioritizes risks by likelihood and impact, enabling executives to quickly grasp the current risk landscape and focus attention on the highest-exposure areas. Option D (List of top risks and their mitigation status) is correct because it tells leadership which risks matter most and whether remediation efforts are on track, directly supporting accountability and resource allocation.

Option C is not essential because listing every third-party vendor with contract details is a procurement or vendor-management artifact, not a concise risk-reporting element for senior management. Option E is not essential because detailed control deficiency descriptions are operational-level detail better suited to audit or control-owner reports, whereas senior management needs aggregated, decision-oriented risk information.

Exam trap

The trap here is that candidates confuse operational detail (like vendor lists or control descriptions) with strategic reporting content, failing to recognize that senior management needs aggregated, decision-focused information rather than granular technical data.

30
MCQhard

An organization's risk committee reviews a risk heat map showing that a key IT risk has moved from the "high" to "medium" category. However, the associated control's effectiveness has decreased from 95% to 85%. What is the most likely explanation?

A.The control testing frequency was increased.
B.The inherent risk has decreased due to external factors.
C.The risk assessment methodology was changed.
D.The control owner has implemented additional compensating controls.
AnswerB

A heat map plots residual risk, which combines inherent risk and control effectiveness. A fall in inherent risk from external factors can outweigh the control's decline from 95% to 85%, lowering residual risk from high to medium.

Why this answer

The risk heat map shows a reduction in residual risk from high to medium, yet the control effectiveness dropped from 95% to 85%. This apparent contradiction is best explained by a decrease in inherent risk—the risk before controls are applied. If inherent risk falls (e.g., due to external factors like new regulations or reduced threat activity), the residual risk can decrease even if the control becomes less effective, because the starting risk level is lower.

Exam trap

The trap here is that candidates assume a decrease in control effectiveness must always increase residual risk, ignoring that a simultaneous decrease in inherent risk can more than compensate, leading to a net reduction in residual risk.

How to eliminate wrong answers

Option A is wrong because increasing control testing frequency typically improves control effectiveness or detects failures earlier, not decreases it; it would not cause effectiveness to drop from 95% to 85%. Option C is wrong because changing the risk assessment methodology could alter how risk is categorized, but the question states the control's effectiveness has measurably decreased, which is a factual change in control performance, not a methodological reclassification. Option D is wrong because implementing additional compensating controls would generally increase overall control effectiveness or at least maintain it, not reduce it from 95% to 85%.

31
MCQeasy

A healthcare provider has determined that a new telehealth platform introduces risks that exceed its defined risk tolerance. Senior management decides to purchase cyber insurance to cover potential breach costs rather than modify the platform. Which risk response is management applying?

A.Risk transfer
B.Risk avoidance
C.Risk acceptance
D.Risk mitigation
AnswerA

Transfer shifts the financial consequences of a risk to a third party, and insurance is the classic example. By purchasing coverage, management retains the operational risk but moves the monetary impact of a breach to the insurer. This matches the decision to keep the platform while offloading financial exposure.

Why this answer

Insurance shifts the financial burden of a potential breach to the insurer, which is the defining characteristic of risk transfer. The telehealth platform continues to operate, so the risk is not avoided, and no technical control was added, so it is not mitigated. Because management acted rather than simply tolerating the exposure, acceptance does not apply.

Exam trap

The trap here is confusing risk transfer with risk acceptance because the underlying platform risk remains in place even though insurance was purchased.

32
MCQmedium

Which of the following is a leading Key Risk Indicator (KRI) for the risk of a data breach?

A.Average time to detect a breach
B.Number of data breaches in the past quarter
C.Percentage of systems with unpatched critical vulnerabilities
D.Number of security incidents closed
AnswerC

Unpatched critical vulnerabilities represent exposure that attackers can exploit, so the percentage measures conditions preceding a breach rather than breach incidents already suffered. That forward-looking quality makes it a leading indicator, unlike metrics such as confirmed data loss volumes.

Why this answer

A leading KRI predicts future risk events. The percentage of systems with unpatched critical vulnerabilities directly indicates an increasing attack surface and likelihood of exploitation, making it a leading indicator for a data breach. In contrast, lagging indicators like detection time or breach count measure past incidents.

Exam trap

The trap here is that candidates confuse lagging indicators (like breach count or detection time) with leading indicators, failing to recognize that a leading KRI must predict future risk, not measure past events.

How to eliminate wrong answers

Option A is wrong because average time to detect a breach (Mean Time to Detect, MTTD) is a lagging indicator that measures the effectiveness of detection controls after a breach has occurred, not a predictor of future breaches. Option B is wrong because the number of data breaches in the past quarter is a lagging indicator that reports historical incidents, providing no forward-looking insight into the likelihood of a future breach. Option D is wrong because the number of security incidents closed is a lagging operational metric reflecting past remediation activity, not a leading indicator of breach risk.

33
MCQmedium

A healthcare provider has identified a risk that a critical medical imaging system runs on an unsupported operating system. The risk owner determines that the residual risk exceeds the organization's risk appetite, but upgrading the system would cost $2 million and disrupt patient care for several weeks. Which of the following is the MOST appropriate next step?

A.Transfer the risk by purchasing cyber insurance and take no other action.
B.Accept the risk because patient care disruption outweighs the security risk.
C.Escalate the risk to the appropriate governance body with options and recommendations for a risk response decision.
D.Implement a compensating control and close the risk without further reporting.
AnswerC

When residual risk exceeds the risk appetite, the risk owner must escalate it to the governance body authorized to make risk acceptance or funding decisions. Presenting options, such as phased upgrade, compensating controls, or formal acceptance with mitigation, enables informed decision-making. This aligns with CRISC principles of escalation and governance for risks beyond tolerance.

Why this answer

When residual risk exceeds the organization's risk appetite, the risk owner must escalate to the governance body empowered to make risk response decisions. That body can weigh the $2 million upgrade cost and patient care disruption against the security exposure, and choose among options such as phased remediation, compensating controls, or formal risk acceptance. Unilateral acceptance, silent closure, or insurance-only responses bypass required governance.

Exam trap

The trap here is treating a compelling business disruption argument as justification for unilateral risk acceptance, when any risk above appetite must be escalated to the authorized governance body for a formal decision.

34
MCQhard

A multinational retailer operates in 14 countries and must report IT risk to its board quarterly. The CISO wants the reporting to drive decisions rather than merely satisfy auditors. Which of the following is the MOST important characteristic of the quarterly IT risk report?

A.It links IT risk exposure to business objectives and states the residual risk against the board-approved risk appetite.
B.It reports the percentage of controls tested and the number of audit findings closed during the quarter.
C.It includes a complete inventory of every vulnerability detected during the quarter, ranked by CVSS score.
D.It compares the organization's risk scores with those of industry peers using a published benchmark.
AnswerA

Board-level reporting is effective only when it connects technology risk to the business outcomes the board cares about and expresses exposure relative to the approved risk appetite. This lets directors judge whether risk is within tolerance and where to direct resources. Raw technical metrics or control counts do not support that judgment, so business-aligned residual risk reporting is the most important characteristic in this scenario.

Why this answer

Effective board reporting translates IT risk into business terms and states residual risk relative to the board-approved risk appetite, enabling directors to make informed decisions about resource allocation and tolerance. Technical inventories, compliance activity metrics, and peer benchmarks may supplement the report but do not by themselves show whether the organization is operating within acceptable risk limits, which is the primary purpose of quarterly risk reporting to the board.

Exam trap

The trap here is equating volume of technical detail or compliance activity with decision-useful risk reporting, when boards need business-aligned residual risk against appetite.

35
MCQmedium

Which of the following is the best example of a Key Control Indicator (KCI) for a firewall rule review process?

A.Number of firewall breaches per quarter
B.Percentage of firewall rules reviewed within the defined period
C.Number of firewall administrators
D.Time since last firewall software update
AnswerB

A Key Control Indicator measures control performance, and the percentage of firewall rules reviewed within the defined period quantifies how consistently the review process operates. This satisfies the stem's requirement for a KCI by providing a measurable, time-bound metric rather than a qualitative statement.

Why this answer

A Key Control Indicator (KCI) measures the effectiveness of a control by tracking its operational performance. For a firewall rule review process, the percentage of rules reviewed within the defined period directly indicates whether the control (periodic review) is being executed as intended, ensuring that stale or overly permissive rules are identified and remediated on schedule.

Exam trap

The CRISC exam often tests the distinction between KCIs (control performance) and KRIs (risk outcomes), so the trap here is confusing a lagging outcome metric (breaches) with a leading process metric (review completion).

How to eliminate wrong answers

Option A is wrong because the number of firewall breaches per quarter is a Key Risk Indicator (KRI), not a KCI; it measures the outcome of control failure rather than the performance of the control itself. Option C is wrong because the number of firewall administrators is a staffing metric unrelated to the operational effectiveness of the rule review process; it does not indicate whether reviews are completed on time. Option D is wrong because the time since the last firewall software update measures patch management hygiene, not the adherence to a rule review schedule; it is a separate control indicator for vulnerability management.

36
MCQeasy

An IT risk analyst is preparing a report for the board risk committee. The committee wants a single view of how much loss the organization could face from IT risks over the next year if no additional controls are implemented. Which metric should the analyst use?

A.Annualized loss expectancy (ALE)
B.Return on security investment (ROSI)
C.Recovery time objective (RTO)
D.Control deficiency rate
AnswerA

ALE expresses the expected annual monetary loss from a risk and is calculated as single loss expectancy multiplied by annualized rate of occurrence. It gives the board a forward-looking, quantified view of potential loss exposure before additional controls, which is exactly what the committee requested. It is the standard metric for comparing and prioritizing IT risks in financial terms.

Why this answer

The board requested a single monetary view of potential annual loss from IT risks with no additional controls, which is precisely what annualized loss expectancy provides. ROSI is a control-investment metric, control deficiency rate measures control performance, and RTO is a time-based recovery target. Only ALE combines likelihood and financial impact into an expected annual loss figure suitable for board-level risk reporting.

Exam trap

The trap here is confusing a control performance indicator, such as deficiency rate, with a quantified loss exposure metric such as ALE.

37
MCQeasy

An organization is selecting a control to prevent unauthorized access to a critical database. Which control type is most appropriate?

A.Detective control
B.Corrective control
C.Directive control
D.Preventive control
AnswerD

Preventive controls stop unauthorised access before it occurs, directly satisfying the stem's requirement to prevent access to the critical database. Detective controls only identify access after the fact, and corrective controls restore service afterwards, so neither blocks the initial intrusion.

Why this answer

Preventive control is the most appropriate because it directly stops unauthorized access before it occurs. For a critical database, this includes mechanisms like database firewalls, access control lists (ACLs), or mandatory access control (MAC) policies that enforce authentication and authorization at the point of entry, such as requiring valid credentials and role-based permissions before any query is processed.

Exam trap

The trap here is that candidates often confuse 'preventive' with 'detective' controls, mistakenly thinking that logging and monitoring (detective) are sufficient to stop unauthorized access, when in fact they only provide visibility after the fact.

How to eliminate wrong answers

Option A is wrong because detective controls, such as audit logs or intrusion detection systems (IDS), only identify unauthorized access after it has happened, not prevent it. Option B is wrong because corrective controls, like restoring from a backup or applying a patch, are used to remediate damage after an incident, not to block initial access. Option C is wrong because directive controls, such as security policies or acceptable use agreements, guide behavior but do not technically enforce or block access to the database.

38
MCQhard

An organization is implementing a new control to address a high-risk finding. The project manager has scheduled a user training session and updated the relevant policies. Which implementation phase is being addressed?

A.Control monitoring
B.Risk assessment
C.Control implementation
D.Control design
AnswerC

Training and policy updates are execution activities, not design or assessment. Control implementation covers deploying the approved control into operation, which includes enabling people and processes through training and revised policies. This satisfies the stem's requirement to identify the phase where the control is actually put in place.

Why this answer

These activities (training and documentation updates) are part of the control implementation phase, specifically after the control is designed and before going live.

39
MCQeasy

Which risk reporting level is typically provided to the board of directors and focuses on strategic risk posture?

A.Tactical risk reporting
B.Compliance risk reporting
C.Strategic risk reporting
D.Operational risk reporting
AnswerC

Strategic risk reporting addresses enterprise-wide, long-horizon risk posture and aggregated exposure, which is the language and scope a board requires for governance oversight. Operational and tactical reporting deal with day-to-day or function-level detail, not the strategic posture the stem specifies.

Why this answer

Strategic risk reporting is the correct level for the board of directors because it focuses on high-level, long-term risks that could affect the organization's strategic objectives and overall business posture. Unlike tactical or operational reports, strategic reports aggregate risk data into a format that supports governance, risk appetite decisions, and capital allocation at the executive level.

Exam trap

The trap here is that candidates often confuse 'strategic' with 'operational' or 'tactical' because they think the board needs detailed technical data, when in fact the board requires aggregated, high-level information focused on long-term strategy and risk appetite.

How to eliminate wrong answers

Option A is wrong because tactical risk reporting is designed for mid-level management and focuses on specific projects or processes, not the enterprise-wide strategic posture required by the board. Option B is wrong because compliance risk reporting is narrowly scoped to regulatory and legal obligations, such as SOX or GDPR, and does not encompass the broader strategic risk landscape. Option D is wrong because operational risk reporting deals with day-to-day risks like system failures or process errors, which are too granular and short-term for board-level strategic oversight.

40
Multi-Selecthard

A multinational manufacturer is consolidating IT risk data from business units into a single enterprise risk report for the board. The risk manager must ensure the report supports effective risk-based decision making. Which TWO of the following characteristics are MOST important for the consolidated report to include? (Choose two.)

Select 2 answers
A.Consistent risk rating criteria and definitions applied across all business units.
B.A complete inventory of every IT asset and its configured technical settings.
C.A forecast of IT budget spend for the next three fiscal years.
D.Detailed descriptions of every control deficiency identified during the reporting period.
E.Comparison of residual risk against approved risk tolerance for each material risk.
AnswersA, E

Consolidating data from multiple units is meaningless if each unit rates likelihood and impact differently. Common criteria and definitions make ratings comparable, allow aggregation without distortion, and let the board see a true enterprise view. This consistency also supports trend analysis over time and fair prioritization across regions and functions, which is essential when resources are limited and trade-offs must be justified.

Why this answer

An enterprise risk report earns its value by enabling decisions, which requires two things: comparability and relevance to tolerance. Consistent rating criteria and definitions across business units make aggregated data trustworthy, while showing residual risk against approved tolerance tells the board where intervention is needed. Together they convert disparate unit-level data into a coherent enterprise view that supports prioritization, resource allocation, and formal risk acceptance decisions.

Exam trap

The trap here is selecting exhaustive operational detail, such as full asset inventories or every control deficiency, instead of the comparability and tolerance context that make a consolidated report decision-useful.

41
MCQhard

A change to a critical application is being implemented without updating the associated security controls. This is most likely a failure in which process?

A.Control design
B.Change management
C.Project management
D.User training
AnswerB

Change management governs modifications to production systems, ensuring security controls are assessed and updated alongside application changes. This scenario's failure to update associated controls during implementation directly violates that process, making it the correct answer over risk assessment or control monitoring.

Why this answer

A change to a critical application that bypasses updating security controls is a direct failure of the change management process. Change management requires that all changes, including security controls, be reviewed, approved, and documented before implementation to maintain the risk posture. Without this process, the organization loses visibility and control over the security implications of the change, leading to potential vulnerabilities.

Exam trap

The trap here is that candidates confuse 'control design' (the initial architecture of controls) with the ongoing governance process of 'change management' that ensures controls are kept in sync with system modifications.

How to eliminate wrong answers

Option A is wrong because control design refers to the initial creation or selection of controls, not the process of ensuring they are updated when a change occurs. Option C is wrong because project management focuses on delivering a project's scope, schedule, and budget, not specifically on the procedural requirement to update security controls during operational changes. Option D is wrong because user training addresses end-user competency, not the procedural governance of change implementation and security control alignment.

42
Multi-Selectmedium

Which TWO of the following are leading indicators that could be used as KRIs for information security risk? (Select TWO.)

Select 2 answers
A.Number of security incidents in the past quarter
B.Number of audit findings from the last audit
C.Patch lag (average time to apply critical patches)
D.Spike in failed authentication attempts
E.Percentage of employees who completed security awareness training
AnswersC, D

Patch lag measures how long critical vulnerabilities remain unpatched, exposing the organisation to exploitation. Because it tracks a condition that precedes a potential breach, it functions as a leading indicator, unlike lagging metrics such as incident counts that record harm already realised.

Why this answer

Option C (patch lag, the average time to apply critical patches) is a leading indicator because it measures an exposure window that predicts future compromise likelihood — the longer critical patches remain unapplied, the greater the chance an attacker exploits a known CVE — so it signals risk before incidents occur. Option D (a spike in failed authentication attempts) is a leading indicator because it reflects anomalous activity such as brute-force or credential-stuffing attempts that typically precede a breach, giving early warning of an imminent attack. The unmarked options are lagging or outcome metrics: A (number of security incidents in the past quarter) and B (number of audit findings from the last audit) both report events that have already happened, and E (percentage of employees who completed security awareness training) is a compliance/training completion metric rather than a predictive signal of attack activity.

Exam trap

The trap here is that candidates often confuse lagging indicators (like incident counts or audit findings) with leading indicators, failing to recognize that KRIs must be predictive and forward-looking to proactively manage risk rather than merely report on past events.

43
MCQeasy

An organization uses automated SIEM rules to continuously monitor for unauthorized access attempts. This is an example of which type of monitoring?

A.Periodic control testing
B.Vulnerability scanning
C.Access review
D.Continuous monitoring
AnswerD

Continuous monitoring fits because the SIEM rules run automatically and without interruption, satisfying the stem's requirement for continuous oversight of unauthorised access attempts. Unlike periodic or ad hoc reviews, this provides ongoing, real-time detection aligned with CRISC's definition of continuous monitoring as automated, recurring control assessment.

Why this answer

Continuous monitoring involves the use of automated tools, such as Security Information and Event Management (SIEM) systems, to provide real-time or near-real-time oversight of security events. In this scenario, the SIEM rules are configured to detect unauthorized access attempts as they occur, which aligns directly with the definition of continuous monitoring rather than periodic or point-in-time assessments.

Exam trap

The trap here is that candidates confuse 'continuous monitoring' with 'periodic control testing' or 'access review' because they all involve oversight of access, but only continuous monitoring uses automated, real-time detection of events as they happen, not scheduled checks or static permission audits.

How to eliminate wrong answers

Option A is wrong because periodic control testing refers to scheduled, manual or automated checks performed at set intervals (e.g., quarterly or annually), not the ongoing, real-time analysis provided by SIEM rules. Option B is wrong because vulnerability scanning is a specific type of assessment that identifies known vulnerabilities (e.g., missing patches, misconfigurations) in systems or networks, not the detection of unauthorized access attempts in real time. Option C is wrong because an access review is a periodic or ad-hoc audit of user permissions and entitlements (e.g., reviewing Active Directory group memberships), not the continuous detection of access attempts via SIEM correlation rules.

44
MCQmedium

In a risk report presented to the board of directors, which of the following elements is most appropriate to include?

A.Vendor security assessment scores for all vendors
B.Detailed weekly firewall log analysis
C.List of all IT incidents from the past month
D.Risk heat map with top risks and status
AnswerD

A risk heat map with top risks and status translates complex risk data into a visual, prioritised format that boards can act on. It satisfies the stem's board-level audience constraint by focusing on material exposures and treatment progress, rather than operational detail, enabling informed governance decisions without requiring technical depth.

Why this answer

A risk report to the board of directors should be strategic and concise, focusing on top risks and their status. A risk heat map with top risks and status provides an executive-level view that supports governance and decision-making without overwhelming the board with operational detail. This is the most appropriate element for a board audience.

Exam trap

CRISC often tests the audience-appropriateness of risk reporting — candidates pick detailed operational data when the board needs strategic, aggregated risk views.

How to eliminate wrong answers

Option A is wrong because vendor security assessment scores for all vendors is too granular and operational for a board report. Option B is wrong because detailed weekly firewall log analysis is a technical operational artifact, not board-level information. Option C is wrong because a list of all IT incidents from the past month is tactical and lacks the risk context the board needs.

45
MCQmedium

A security operations center (SOC) uses a Security Information and Event Management (SIEM) system to continuously monitor for suspicious activities. Which type of monitoring is being performed?

A.Periodic control testing
B.Compliance audit
C.Vulnerability scanning
D.Continuous monitoring
AnswerD

A SIEM ingesting and correlating event data around the clock to detect suspicious activity is performing continuous monitoring, the ongoing, automated observation of systems and controls. This satisfies the stem's requirement for uninterrupted surveillance rather than periodic or ad hoc review.

Why this answer

The SOC is using a SIEM system to continuously monitor for suspicious activities, which aligns with continuous monitoring. Continuous monitoring involves real-time or near-real-time collection and analysis of security events to detect threats as they occur, rather than at scheduled intervals. SIEM systems aggregate logs and alerts from various sources to provide ongoing visibility into the security posture.

Exam trap

The trap here is that candidates confuse continuous monitoring with vulnerability scanning or periodic testing, but the key differentiator is the real-time, event-driven nature of SIEM-based monitoring versus scheduled or point-in-time assessments.

How to eliminate wrong answers

Option A is wrong because periodic control testing involves scheduled assessments (e.g., quarterly penetration tests) to verify control effectiveness, not real-time monitoring. Option B is wrong because a compliance audit is a point-in-time evaluation against regulatory standards (e.g., PCI DSS), not ongoing surveillance. Option C is wrong because vulnerability scanning is a periodic or scheduled process to identify known vulnerabilities (e.g., using Nessus or Qualys), not continuous monitoring of suspicious activities.

46
MCQeasy

A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?

A.Corrective control
B.Preventive control
C.Detective control
D.Directive control
AnswerB

Preventive controls block unauthorised access attempts before they reach the critical database, matching the stem's objective to prevent rather than detect. Authentication, authorisation and network filtering deny intrusion at entry, whereas detective controls only identify breaches after they occur.

Why this answer

A preventive control is designed to stop an incident before it occurs — access controls, authentication, encryption, and firewalls are classic examples. Preventing unauthorized database access is definitionally a preventive objective, so a preventive control (e.g., RBAC, MFA, network segmentation) is the correct category.

Exam trap

The trap is that candidates confuse 'detective' with 'preventive' because monitoring feels proactive — but detection only reveals an event after it happens; only a preventive control stops the unauthorized access itself.

How to eliminate wrong answers

Option A is wrong because corrective controls act after an incident to restore normal operations (e.g., backups, patching, incident response) — they do not stop unauthorized access in the first place. Option C is wrong because detective controls identify that an event occurred (e.g., IDS, log monitoring, SIEM alerts) but do not block it; detection is reactive to the event. Option D is wrong because directive controls establish policy or guidance (e.g., security policies, awareness training, procedures) — they influence behavior but do not technically enforce access restrictions.

47
MCQeasy

Which type of control is designed to operate before an event to prevent an undesirable outcome?

A.Preventive control
B.Detective control
C.Corrective control
D.Compensating control
AnswerA

Preventive controls act on the cause before an event occurs, blocking the undesirable outcome rather than detecting it afterwards or compensating for it. This directly satisfies the stem's requirement that the control operates before the event, unlike detective or corrective controls.

Why this answer

A preventive control is designed to operate before an event to stop an undesirable outcome from occurring. In risk management, this includes measures such as firewalls blocking unauthorized traffic before it reaches the internal network, or access control lists (ACLs) preventing unauthorized users from reading sensitive files. These controls proactively enforce security policies to reduce the likelihood of a risk event.

Exam trap

In the ISACA CRISC exam, candidates often confuse preventive controls (e.g., firewalls, access controls) with detective controls (e.g., intrusion detection systems). Remember that preventive controls act before an event, while detective controls identify events that have already occurred.

How to eliminate wrong answers

Option B (Detective control) is wrong because it operates during or after an event to identify that an undesirable outcome has occurred, such as intrusion detection systems (IDS) logging suspicious activity after the fact. Option C (Corrective control) is wrong because it operates after an event to restore normal operations, like applying a patch to fix a vulnerability that was exploited. Option D (Compensating control) is wrong because it is an alternative control used when a primary control is not feasible, not specifically designed to operate before an event.

48
MCQmedium

Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?

A.To reduce the frequency of IT risk reporting
B.To eliminate the need for IT risk assessments
C.To provide a holistic view of risk across the organization
D.To replace IT risk management with ERM
AnswerC

Integrating IT risk reporting into enterprise risk management aggregates technology exposures alongside financial, operational and compliance risks, so leadership sees interconnected exposures rather than a siloed technology list. This holistic aggregation is the primary purpose, enabling consistent prioritisation and comparison against the organisation's overall risk appetite.

Why this answer

Integrating IT risk reporting into the ERM program provides a holistic view of risk across the organization by aligning IT-specific risks with strategic, operational, and compliance risks. This integration ensures that decision-makers can prioritize and respond to risks based on their aggregate impact, rather than treating IT risks in isolation. The primary purpose is to enable a unified risk posture that supports enterprise-wide governance and resource allocation.

Exam trap

ISACA often tests the misconception that ERM integration aims to replace or reduce IT-specific risk management activities, when in fact it seeks to elevate IT risk visibility to the enterprise level without eliminating specialized IT risk processes.

How to eliminate wrong answers

Option A is wrong because the purpose of integration is not to reduce the frequency of reporting but to enhance the quality and context of risk information; frequency is determined by risk velocity and materiality, not by integration alone. Option B is wrong because integrating IT risk reporting into ERM does not eliminate the need for IT risk assessments; IT risk assessments remain essential for identifying, analyzing, and evaluating specific technical threats, vulnerabilities, and controls. Option D is wrong because ERM does not replace IT risk management; rather, it subsumes IT risk as a component of the overall risk portfolio, requiring continued specialized IT risk management practices.

49
MCQhard

A global retailer's risk committee is reviewing a proposal to transfer the financial impact of payment card fraud to an insurer through a cyber insurance policy. The policy has a $2 million retention and excludes losses caused by unencrypted cardholder data at rest. The organization's cardholder database is currently unencrypted. Which of the following is the MOST significant limitation the risk manager should highlight?

A.Cyber insurance cannot be used as a risk response because it does not reduce the likelihood of a fraud event.
B.The exclusion for unencrypted cardholder data means the transfer will not respond to a loss from the current database configuration.
C.The insurer, not the risk committee, will now own the risk and control decisions for the payment environment.
D.The retention amount is too low to provide meaningful financial protection for a global retailer.
AnswerB

Risk transfer only works when the transferred event falls within the policy's coverage. Because the cardholder database is unencrypted and the policy excludes losses from unencrypted data at rest, a breach of that database would fall outside coverage, leaving the organization to bear the full financial impact. This is the material limitation the committee must weigh before treating insurance as the response.

Why this answer

Transferring risk through insurance is effective only when the loss event is actually covered. An exclusion for unencrypted cardholder data at rest directly conflicts with the current state of the cardholder database, so a breach of that database would not be indemnified. The risk manager must flag this gap so the committee understands that the proposed transfer does not address the organization's most likely fraud loss scenario, and that encryption or another response is needed.

Exam trap

The trap here is assuming that purchasing a cyber insurance policy automatically transfers the relevant fraud risk without checking policy exclusions against the actual control state.

50
Multi-Selecthard

A risk practitioner is defining key risk indicators (KRIs) for the organization's third-party risk program after several supplier outages disrupted operations. Which TWO characteristics are essential for these KRIs to be effective for the risk committee? (Choose two.)

Select 2 answers
A.Each indicator reflects the total number of suppliers onboarded during the reporting period.
B.Each indicator is reviewed only during the annual enterprise risk assessment cycle.
C.Each indicator is measurable from data that can be collected reliably and repeatedly.
D.Each indicator is tied to a defined risk threshold that triggers a specific escalation or response.
E.Each indicator is expressed as a qualitative rating assigned by the relationship manager.
AnswersC, D

A KRI is only useful if it can be calculated consistently from dependable sources; otherwise trends and thresholds are meaningless. Reliable, repeatable measurement lets the risk committee compare periods, detect deterioration, and trust the signal. Indicators built on anecdotal data or manual estimates that vary by analyst introduce noise and erode confidence, defeating the purpose of monitoring third-party risk over time.

Why this answer

Effective KRIs are measurable from reliable, repeatable data and are linked to thresholds that trigger defined action. Those two properties turn a metric into a decision-support tool for the risk committee. Activity counts, subjective ratings, and annual-only reviews lack the objectivity, relevance, and timeliness needed to warn about third-party disruption before it affects operations.

Exam trap

The trap here is selecting indicators that are easy to collect, such as supplier counts, instead of ones that actually signal risk exposure.

51
MCQhard

A company is integrating its IT risk management program with the enterprise risk management (ERM) program. What is the primary benefit of this integration?

A.It allows IT to operate independently from business units.
B.It eliminates the requirement for a separate IT risk register.
C.It provides a holistic view of risk across the organization.
D.It reduces the need for IT-specific risk assessments.
AnswerC

Integration aggregates IT risk with operational, financial and strategic risk registers, giving leadership a consolidated enterprise-wide view rather than isolated silos. This holistic perspective improves prioritisation and capital allocation, ensuring IT risk is evaluated against overall organisational risk appetite during decision-making.

Why this answer

Integration ensures that IT risks are considered in the context of overall organizational objectives and that risk responses are aligned across the enterprise.

52
MCQmedium

A financial services firm maintains a risk register that lists inherent risk ratings for its core banking platform. During an internal audit, the CIO notes that the register has not been updated to reflect the controls implemented over the past 18 months. Which of the following should the risk practitioner do FIRST to address this gap?

A.Remove the affected entries from the register until a complete enterprise risk assessment can be scheduled.
B.Reclassify all entries from inherent to residual risk so the register aligns with the audit terminology.
C.Reassess the residual risk for each entry by evaluating the effectiveness of the implemented controls.
D.Escalate the finding to the board risk committee and request additional budget for a full risk assessment.
AnswerC

The register reflects inherent risk but ignores control effectiveness, so the residual risk is misstated. Reassessing residual risk by evaluating the controls already implemented directly corrects the outdated ratings and restores the register's accuracy. This is the logical first step because the identified gap is precisely the failure to reflect controls in the risk position.

Why this answer

The register captured inherent risk but never reflected the controls deployed over 18 months, so the residual risk position is stale. The practitioner must evaluate control effectiveness and recalculate residual risk for each affected entry. Escalation, deletion, or relabeling do not correct the data and would leave decision-makers with a misleading view of the firm's actual risk exposure.

Exam trap

The trap here is assuming the register is wrong because risks were never identified, when the actual gap is that implemented controls were never reflected in the residual ratings.

53
MCQmedium

During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control is expected to reduce the ALE by 80% and will cost $150,000 per year. What is the net benefit of implementing the control?

A.$100,000
B.$250,000
C.$400,000
D.$350,000
AnswerB

The control reduces the $500,000 ALE by 80%, a $400,000 saving, against a $150,000 annual cost. Subtracting that cost gives a net benefit of $250,000. The calculation uses the ALE reduction minus the control's yearly expense, matching the stated figures exactly.

Why this answer

The current annual loss expectancy (ALE) is $500,000. An 80% reduction means the control saves $400,000 per year. Subtracting the annual control cost of $150,000 yields a net benefit of $250,000.

This is calculated as (ALE × reduction percentage) – control cost.

Exam trap

The trap here is that candidates often forget to subtract the annual control cost from the gross savings, mistakenly selecting the gross savings ($400,000) as the net benefit.

How to eliminate wrong answers

Option A ($100,000) is wrong because it incorrectly subtracts the control cost from the reduced ALE ($100,000 = $100,000 – $0?) or miscalculates the savings as 20% of ALE. Option C ($400,000) is wrong because it represents the gross savings (80% of $500,000) without subtracting the $150,000 annual control cost. Option D ($350,000) is wrong because it likely results from subtracting the control cost from the original ALE ($500,000 – $150,000) and ignoring the 80% reduction factor.

54
MCQmedium

During a quarterly risk review, a risk owner reports that a critical trading application has exceeded its residual risk tolerance for the second consecutive quarter despite remediation efforts. The risk owner proposes to continue remediation and report again next quarter. Which of the following should the risk manager do?

A.Accept the risk owner's proposal because remediation is already underway and progress is being made.
B.Escalate the tolerance breach to the risk committee and recommend a formal risk response decision, such as acceptance, additional mitigation, or avoidance.
C.Re-rate the application's residual risk to within tolerance to reflect the remediation work already completed.
D.Direct the risk owner to implement additional controls immediately without involving the risk committee.
AnswerB

When residual risk remains above tolerance across reporting periods despite remediation, the decision exceeds the risk owner's authority. The risk manager should escalate to the risk committee with the evidence and options so a formal response decision can be made and documented. This preserves accountability, ensures the breach is visible to those empowered to accept it, and prevents uncontrolled drift in the organization's risk profile.

Why this answer

A residual risk that stays above tolerance across multiple reporting periods is a governance event, not a routine remediation update. The risk manager's role is to make the breach visible, present the evidence and available response options, and let the risk committee decide whether to accept, mitigate further, transfer, or avoid. Documenting that decision maintains accountability and keeps the organization's risk profile aligned with its stated tolerance.

Exam trap

The trap here is treating continued remediation effort as equivalent to an approved decision to accept the ongoing tolerance breach.

55
MCQhard

An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is an example of:

A.Periodic control testing
B.Continuous monitoring
C.Access review
D.Vulnerability scanning
AnswerB

SIEM rules that alert when failed logins exceed a threshold constitute continuous monitoring: automated, ongoing collection and analysis of event data against defined criteria. This matches the stem exactly, distinguishing it from periodic assessments or manual review, and satisfies the requirement for real-time anomaly detection.

Why this answer

This scenario describes continuous monitoring because the SIEM is configured with rules that automatically and perpetually analyze login events in real time, generating alerts when the count of failed logins surpasses a predefined threshold. Unlike periodic or manual checks, this process operates 24/7 without human intervention, directly detecting anomalies as they occur.

Exam trap

The trap here is that candidates confuse 'continuous monitoring' with 'continuous auditing' or assume any automated activity is 'vulnerability scanning,' but the key differentiator is the real-time, rule-based detection of operational anomalies versus scheduled scans for configuration weaknesses.

How to eliminate wrong answers

Option A is wrong because periodic control testing involves scheduled, manual or automated assessments of controls at fixed intervals (e.g., quarterly reviews), whereas the SIEM rule runs continuously without a schedule. Option C is wrong because an access review is a manual or semi-automated process that examines user permissions and entitlements against policy, not real-time detection of failed login anomalies. Option D is wrong because vulnerability scanning identifies known software vulnerabilities (e.g., missing patches, misconfigurations) by probing systems, not by monitoring authentication failure patterns.

56
MCQhard

A healthcare payer's risk committee is deciding how to respond to a risk that its cloud-hosted claims processing platform could become unavailable for more than 24 hours. The platform is critical, the provider offers a financially backed 99.95% availability commitment, and the organization lacks the internal capability to run a secondary environment. Which risk response is MOST appropriate?

A.Transfer the financial consequence through contract terms and insurance while implementing a tested recovery capability with the provider.
B.Avoid the risk entirely by terminating the cloud contract and rebuilding the claims platform in an internally managed data center.
C.Accept the risk and document the decision, relying on the provider's service level agreement as the sole safeguard.
D.Reduce the risk by negotiating a higher availability percentage in the service level agreement without adding recovery arrangements.
AnswerA

Because internal capability is absent, the practical response combines transferring financial exposure via contractual remedies and cyber or business interruption insurance with mitigating operational impact through provider-supported recovery arrangements that are regularly tested. This layered approach addresses both the monetary loss and the service restoration gap, which is what the committee actually needs for a critical platform.

Why this answer

For a critical platform with no internal recovery capability, the realistic response is layered: contractual remedies and insurance transfer the financial loss, while provider-supported recovery arrangements mitigate the operational outage. Pure acceptance leaves patients and regulators exposed, avoidance is disproportionate, and a stronger SLA alone changes expectations without building the capability to restore service.

Exam trap

The trap here is treating a financially backed availability commitment as equivalent to actual recovery capability, when it only compensates loss and does not restore the service.

57
Multi-Selectmedium

Which TWO of the following are examples of detective controls?

Select 2 answers
A.Encryption of data at rest
B.Firewall rules
C.Log monitoring and analysis
D.Intrusion detection system (IDS)
E.Data backup process
AnswersC, D

Log monitoring and analysis examines recorded event data to identify incidents after or during occurrence, which is the defining characteristic of a detective control. It does not prevent events, distinguishing it from preventive controls such as firewalls or access restrictions.

Why this answer

Log monitoring and analysis (C) is a detective control because it continuously reviews and correlates event logs to identify and alert on suspicious or anomalous activity after it occurs, providing visibility into incidents rather than preventing them. An intrusion detection system (IDS) (D) is likewise detective: it passively inspects network or host traffic and raises alerts when it matches known attack signatures or behavioral anomalies, without blocking the traffic itself. By contrast, encryption of data at rest (A) and firewall rules (B) are preventive controls that stop unauthorized access or disclosure before it happens, and a data backup process (E) is a corrective/recovery control that restores data after a loss event, so none of these three are detective controls.

Exam trap

CRISC often tests the preventive-vs-detective distinction by including strong-sounding controls like encryption and firewalls, so candidates must ask 'does this stop an event or detect it?' rather than picking the most security-sounding option.

58
Multi-Selectmedium

During a third-party risk management review, the organization is tiering its vendors based on risk. Which TWO of the following criteria are most relevant for determining vendor risk tier?

Select 2 answers
A.Criticality of service provided
B.Number of vendor employees
C.Level of data access the vendor has
D.Annual contract value
E.Vendor geographic location
AnswersA, C

Vendor risk tiering hinges on how severely a failure would disrupt the organization, so criticality of the service provided directly drives impact scoring. A vendor supporting a core revenue or safety function warrants a higher tier and deeper due diligence than one supplying peripheral services.

Why this answer

The criticality of the service provided (A) directly determines the potential business impact if the vendor fails, making it a primary factor in risk tiering. Similarly, the level of data access (C) dictates the confidentiality and privacy risks, as vendors handling sensitive or regulated data (e.g., PII, PHI) pose higher inherent risk. Both criteria align with the ISACA risk management framework, which prioritizes impact and data sensitivity over financial or operational metrics.

Exam trap

ISACA often tests the misconception that financial metrics like contract value or vendor size directly correlate with risk, but the CRISC exam emphasizes that risk is driven by data sensitivity and business impact, not cost or scale.

59
MCQhard

An organization is implementing continuous monitoring of its network using SIEM rules. Which of the following is the PRIMARY benefit of this approach over periodic manual testing?

A.Reduces the need for security staff
B.Is less expensive than periodic testing
C.Eliminates all false positives
D.Provides real-time detection of security events
AnswerD

SIEM rules correlate log and event data continuously, alerting as activity occurs rather than at scheduled test intervals. This satisfies the stem's continuous monitoring requirement by shrinking detection latency, so threats are identified in real time instead of after periodic manual testing.

Why this answer

Continuous monitoring via SIEM rules provides real-time detection of security events, enabling immediate identification and response to threats as they occur. This is the primary benefit over periodic manual testing, which only identifies issues at discrete intervals and cannot catch events that happen between tests.

Exam trap

The trap here is that candidates may confuse 'continuous monitoring' with 'automated response' or assume it reduces staffing needs, but the CRISC exam emphasizes that the primary benefit is real-time detection, not cost savings or elimination of human oversight.

How to eliminate wrong answers

Option A is wrong because continuous monitoring does not eliminate the need for security staff; it augments their capabilities but still requires analysts to investigate alerts, tune rules, and respond to incidents. Option B is wrong because continuous monitoring often involves higher upfront and ongoing costs for SIEM infrastructure, licensing, and staffing compared to periodic manual testing. Option C is wrong because SIEM rules can produce false positives due to misconfigurations, noisy data sources, or overly broad rule logic; they do not eliminate all false positives.

60
MCQhard

A multinational retailer's risk register shows a high inherent risk rating for its third-party payment processor. The processor has since obtained an independent SOC 2 Type II report with no exceptions, and the retailer's contract includes a right-to-audit clause. The risk owner proposes lowering the residual risk rating to low. Which factor is MOST important for the risk practitioner to consider before approving the revised rating?

A.Whether the SOC 2 report's scope and testing period cover the specific services, systems, and controls the retailer relies on.
B.Whether the retailer has exercised its right-to-audit clause at least once in the past three years.
C.Whether the processor's SOC 2 report was issued by a well-known audit firm with a strong market reputation.
D.Whether the processor has publicly announced any data breaches during the current fiscal year.
AnswerA

A SOC 2 Type II report only provides assurance over the systems, services, and controls within its stated scope and testing period. If the processor's report excludes the payment application or the relevant control objectives, the no-exceptions opinion does not support lowering residual risk. Confirming scope alignment is therefore the most important step before accepting the revised rating.

Why this answer

Before reducing residual risk based on third-party assurance, the practitioner must confirm that the assurance actually covers the systems, services, and control objectives the organization relies upon. Scope and period alignment determines whether the SOC 2 Type II opinion is relevant evidence. Auditor reputation, audit clause usage, and public breach history may inform judgment but cannot substitute for verifying that the report addresses the specific risk under review.

Exam trap

The trap here is accepting a clean third-party assurance report at face value without confirming that its scope and testing period cover the services the organization actually depends on.

61
MCQeasy

Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a firewall?

A.Number of security incidents reported
B.Number of blocked intrusion attempts
C.Average time to patch vulnerabilities
D.Percentage of employees who completed security training
AnswerB

Blocked intrusion attempts measure the firewall's actual defensive effectiveness against real traffic, making it a KCI rather than a configuration metric. Rule counts or patch levels indicate effort or state, not control performance, so this satisfies the stem's requirement for an effectiveness measure.

Why this answer

A KCI measures the performance or effectiveness of a control. The number of blocked intrusion attempts is a direct measure of the firewall's preventive effectiveness.

62
MCQmedium

Which of the following is a key element of promoting a risk-aware culture within an IT department?

A.Establishing an anonymous incident reporting system
B.Outsourcing risk management to a third party
C.Conducting annual performance reviews
D.Requiring employees to sign non-disclosure agreements
AnswerA

An anonymous reporting channel lets staff raise risk concerns and near-misses without fear of reprisal, increasing the volume and honesty of information reaching management. This directly satisfies the cultural requirement by encouraging open, proactive risk communication across the IT department.

Why this answer

An anonymous incident reporting system encourages employees to report risks, errors, and near-misses without fear of retaliation, which is fundamental to building a risk-aware culture where people feel safe to speak up. It directly promotes transparency and proactive risk identification, key elements of a risk-aware culture.

Exam trap

CRISC often tests the confusion between risk culture enablers (like anonymous reporting) and generic HR or legal tools (performance reviews, NDAs) that do not directly promote risk awareness.

How to eliminate wrong answers

Option B is wrong because outsourcing risk management to a third party does not foster internal risk awareness; it may even distance employees from risk ownership. Option C is wrong because annual performance reviews are unrelated to risk culture and may even discourage reporting if tied to punitive measures. Option D is wrong because non-disclosure agreements are legal tools to protect confidentiality, not mechanisms to promote a risk-aware culture; they do not encourage open discussion of risks.

63
MCQmedium

During a vendor risk assessment, a prospective vendor for critical services cannot provide a SOC 2 Type II report. According to the organization's vendor risk appetite, which action should be taken?

A.Lower the vendor's tier to reduce requirements
B.Accept the vendor's self-assessment instead
C.Reject the vendor or request a formal risk acceptance
D.Onboard the vendor with additional monitoring
AnswerC

Without a SOC 2 Type II report, assurance over the vendor's control operating effectiveness is absent, breaching the stated risk appetite for critical services. Rejecting the vendor or escalating to formal risk acceptance satisfies that constraint, ensuring residual risk is consciously owned rather than silently absorbed.

Why this answer

A SOC 2 Type II report provides independent assurance over a service organization's controls over a period of time. When a prospective vendor for critical services cannot provide this report, and the organization's risk appetite is defined, the appropriate action is to reject the vendor or require a formal risk acceptance from the risk owner. This ensures that any deviation from the required control evidence is explicitly acknowledged and approved, rather than bypassing the requirement.

Exam trap

The trap here is that candidates may assume 'additional monitoring' (Option D) is a valid compensating control, but the CRISC exam emphasizes that for critical services, independent assurance (like SOC 2) is a non-negotiable baseline, and monitoring is a detective control, not a preventive or directive control that replaces the need for formal risk acceptance.

How to eliminate wrong answers

Option A is wrong because lowering the vendor's tier to reduce requirements would arbitrarily weaken the control baseline for a critical service, which contradicts the principle of aligning controls with risk criticality. Option B is wrong because accepting a vendor's self-assessment instead of a SOC 2 Type II report removes independent verification, introducing a conflict of interest and potentially hiding control weaknesses. Option D is wrong because onboarding the vendor with additional monitoring does not address the lack of foundational control assurance; monitoring can detect issues but cannot replace the need for pre-contract evidence of control effectiveness.

64
MCQhard

An organization's risk committee is reviewing key risk indicators (KRIs) for its customer-facing web applications. The KRI for average patch latency has breached its threshold for two consecutive quarters, yet the risk register still lists the associated risk as medium with no treatment plan. Which action should the risk practitioner recommend FIRST?

A.Escalate the KRI breach to the risk owner and require reassessment of the risk rating and treatment plan.
B.Immediately raise the risk rating to high in the risk register without consulting the risk owner.
C.Wait until the next scheduled quarterly risk committee meeting to present the KRI trend for discussion.
D.Recommend purchasing additional cyber insurance to cover the potential loss from unpatched applications.
AnswerA

A sustained KRI breach indicates that the risk environment has changed and the existing rating may no longer be valid. The practitioner's first step is to escalate to the accountable risk owner so the risk can be reassessed and a treatment decision documented. This maintains the integrity of the risk register and ensures reporting reflects actual conditions rather than stale assessments.

Why this answer

A KRI that breaches its threshold for two consecutive quarters signals that the underlying risk profile has deteriorated, yet the register still shows a stale medium rating without treatment. The practitioner should escalate to the accountable risk owner so the risk can be reassessed and a documented treatment decision made. Unilateral rating changes, premature insurance recommendations, and deferred discussion all bypass the owner's accountability and delay necessary action.

Exam trap

The trap here is assuming the practitioner should directly modify the risk register, when the correct first step is escalation to the risk owner for reassessment.

65
MCQmedium

A financial services firm's risk register shows that a legacy payment gateway has a high inherent risk of SQL injection. The security team proposes deploying a web application firewall (WAF) in front of the gateway. The risk owner must document how this action will be classified in the risk response plan. Which risk response strategy does deploying the WAF represent?

A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerA

Deploying a WAF reduces the likelihood and impact of SQL injection by filtering malicious input before it reaches the payment gateway. In CRISC terms, this is risk mitigation because a control is applied to bring the residual risk within the organization's risk appetite while the underlying asset and threat remain. The risk is not eliminated, transferred, or avoided, so mitigation is the accurate classification.

Why this answer

Applying a web application firewall reduces the likelihood and impact of SQL injection against the legacy payment gateway, which is the definition of risk mitigation. The organization continues to operate the asset and retains the residual risk, so avoidance, transfer, and acceptance do not describe the action. Correct classification matters because the risk register and reporting must reflect the true response strategy and its effect on residual risk.

Exam trap

The trap here is assuming that any security control automatically means risk avoidance, when avoidance requires eliminating the activity that creates the risk.

66
MCQhard

When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:

A.Reporting IT risks only to the CIO
B.Eliminating IT risk reporting to the board
C.Mapping IT risks to enterprise risk categories
D.Using separate risk scoring for IT risks
AnswerC

Mapping IT risks to enterprise risk categories lets IT risk be aggregated, compared and reported alongside other risks within the ERM framework. Without that alignment, IT risk stays siloed and cannot inform enterprise-level risk appetite or reporting, which is the integration's core purpose.

Why this answer

IT risk should be treated as a component of broader operational risk to ensure alignment with enterprise-level risk appetite and reporting.

67
MCQmedium

During a vendor risk assessment, an organization discovers that a critical vendor has not performed a security assessment in two years. The vendor is tiered as 'medium risk'. According to best practices, what should the risk practitioner recommend?

A.Request a current SOC 2 report or equivalent assessment
B.Downgrade the vendor to low risk to reduce monitoring frequency
C.Accept the risk because the vendor is only medium risk
D.Terminate the relationship immediately
AnswerA

A current SOC 2 report provides independent assurance over the vendor's control environment, closing the two-year evidence gap. Requesting it satisfies the assessment requirement proportionately, since medium-tier vendors warrant validated attestation rather than full on-site audits, enabling informed tiering and remediation decisions.

Why this answer

A SOC 2 report (or equivalent, such as an ISO 27001 certification or a SIG assessment) provides independent assurance over a vendor's controls, including security monitoring and assessment cadence. Since the vendor is tiered as 'medium risk' and has not performed a security assessment in two years, the risk practitioner should request current evidence of control effectiveness rather than accept, ignore, or escalate the risk prematurely. This aligns with the CRISC principle of verifying control status before making risk response decisions.

Exam trap

The trap here is that candidates may assume 'medium risk' automatically justifies risk acceptance (Option C), but CRISC requires that acceptance be based on current control evidence, not just the risk tier label.

How to eliminate wrong answers

Option B is wrong because downgrading a vendor's risk tier to reduce monitoring frequency would violate the risk assessment's integrity; the vendor's lack of assessment indicates a control gap, not a lower inherent risk. Option C is wrong because accepting risk without understanding the current control state (i.e., without a recent assessment) is premature and contradicts the risk response process, which requires informed acceptance based on evidence. Option D is wrong because terminating the relationship immediately is an extreme response that ignores the possibility of obtaining a current assessment or remediation plan; it fails to consider business continuity and the vendor's criticality.

68
Multi-Selectmedium

A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?

Select 2 answers
A.Risk heat map
B.Individual employee performance metrics
C.Detailed technical logs
D.Top risks and their status
E.List of all IT assets
AnswersA, D

A risk heat map gives the committee an aggregated, visual view of likelihood and impact across the portfolio, enabling prioritisation and comparison of exposures. This satisfies the stem's requirement for the most important content in a quarterly IT risk committee report.

Why this answer

A risk heat map (A) is essential because it visually prioritizes risks by likelihood and impact, allowing the IT risk committee to quickly identify and compare exposure across the risk portfolio. Top risks and their status (D) must be included so the committee can focus on the most significant threats, track mitigation progress, and make informed governance decisions. Individual employee performance metrics (B) are an HR concern and do not reflect organizational risk posture.

Detailed technical logs (C) are too granular and operational for a quarterly executive-level risk report. A list of all IT assets (E) is an inventory artifact, not a risk report element, and would overwhelm the committee without risk context.

Exam trap

The trap here is that candidates confuse operational data (like logs or asset lists) with strategic risk reporting content, failing to recognize that the committee needs summarized, decision-supporting visuals (heat map) and prioritized risk status, not raw technical details.

69
Multi-Selecthard

An organization is implementing continuous monitoring for its critical systems. Which TWO of the following are examples of continuous monitoring techniques? (Select TWO)

Select 2 answers
A.Continuous vulnerability scanning
B.Weekly review of access logs by a manager
C.Automated SIEM rules to detect anomalies
D.Annual penetration testing
E.Quarterly control testing by internal audit
AnswersA, C

Continuous vulnerability scanning automatically and repeatedly identifies new weaknesses across critical systems, providing the ongoing, real-time assurance that continuous monitoring demands. Periodic manual reviews or annual assessments lack the automation and frequency the technique requires.

Why this answer

Option A (Continuous vulnerability scanning) is correct because it is an automated, ongoing process that repeatedly identifies new vulnerabilities as systems and threat data change, which is a core continuous monitoring technique. Option C (Automated SIEM rules to detect anomalies) is correct because SIEM correlation rules and alerting run continuously against real-time log and event streams, providing ongoing detection rather than point-in-time assessment. Option B (Weekly review of access logs by a manager) is a periodic, manual review, so it is not continuous.

Option D (Annual penetration testing) is a point-in-time, typically yearly assessment, not continuous monitoring. Option E (Quarterly control testing by internal audit) is periodic assurance performed on a quarterly cycle, not continuous monitoring.

70
MCQmedium

An organization is implementing a new access control system. The project manager is concerned about delays due to user training requirements. Which of the following should the risk practitioner prioritize to ensure effective control implementation?

A.Accelerate the deployment to meet the project deadline
B.Implement a compensating control to reduce training requirements
C.Delay the entire project until training can be completed
D.Ensure user training is completed before go-live
AnswerD

Completing user training before go-live ensures staff can operate the access control system correctly from day one. Untrained users generate misconfigurations, workarounds and access errors that undermine the control, so sequencing training ahead of launch directly prevents the delays and control failures the project manager fears.

Why this answer

User training is a critical success factor for access control systems because misconfigured or improperly used controls can lead to security gaps. Ensuring training is completed before go-live (Option D) aligns with the principle that a control is only effective if users understand how to operate it correctly, preventing human error that could bypass the control's intended protections.

Exam trap

The trap here is that candidates may choose Option B (compensating control) thinking it is a valid risk treatment, but the question asks for what ensures effective control implementation, not just risk reduction—training is non-negotiable for the primary control to work as designed.

How to eliminate wrong answers

Option A is wrong because accelerating deployment to meet a deadline sacrifices control effectiveness; a rushed rollout without user training increases the risk of misconfiguration and security incidents. Option B is wrong because implementing a compensating control to reduce training requirements does not address the root cause—users must still understand the primary access control system to avoid errors that the compensating control cannot fully mitigate. Option C is wrong because delaying the entire project is unnecessarily disruptive; training can be completed in parallel with other project phases, and a full delay may introduce new risks from prolonged use of legacy systems.

71
MCQhard

During a vendor risk tiering exercise, a vendor that stores the organization's customer PII and is critical for daily operations should be classified as which tier?

A.Critical
B.Medium
C.High
D.Low
AnswerA

Handling customer PII plus daily operational dependency means a vendor outage or breach causes regulatory, financial and continuity impact simultaneously. That combination of data sensitivity and operational criticality places the vendor in the critical tier, matching the stem's tiering criteria.

Why this answer

Vendors with access to sensitive data and high service criticality are typically classified as critical (highest tier).

72
MCQeasy

Which type of control is designed to stop an undesirable event from occurring?

A.Corrective control
B.Preventive control
C.Directive control
D.Detective control
AnswerB

Preventive controls act before or during an event, blocking it from occurring through mechanisms such as access restrictions, segregation of duties or input validation. Detective controls only identify events after the fact, and corrective controls restore operations afterwards, so prevention uniquely satisfies stopping the undesirable event.

Why this answer

Preventive control is designed to stop an undesirable event from occurring by enforcing policies or technical barriers before the event happens. For example, a firewall rule that blocks inbound traffic on port 23 (Telnet) prevents unauthorized remote access attempts, directly reducing the likelihood of a security incident.

Exam trap

The trap here is that candidates often confuse preventive controls with detective controls, mistakenly thinking that monitoring or alerting (detective) can stop an event, when in fact prevention requires proactive blocking mechanisms like access control lists (ACLs) or input validation.

How to eliminate wrong answers

Option A is wrong because corrective control is applied after an undesirable event has occurred, aiming to restore normal operations (e.g., restoring data from backup after a ransomware attack). Option C is wrong because directive control guides behavior through policies or procedures but does not physically or technically stop an event (e.g., a password policy requiring complex passwords does not prevent a brute-force attack by itself). Option D is wrong because detective control identifies that an undesirable event has occurred or is occurring, such as an intrusion detection system (IDS) alerting on suspicious traffic, but it does not stop the event.

73
Multi-Selecthard

In the context of IT risk reporting to the board, which THREE elements should be included to effectively communicate risk?

Select 3 answers
A.Detailed technical logs
B.Top risks and status
C.Risk heat map
D.Employee performance reviews
E.Risk trend analysis
AnswersB, C, E

Top risks and status give the board a prioritised view of the most significant exposures and whether mitigation is on track, satisfying the need for concise, decision-useful reporting. Raw technical logs or exhaustive registers would obscure the strategic picture the board requires.

Why this answer

Option B (Top risks and status) is correct because board-level reporting must prioritize the most significant risks and their current mitigation status, giving directors a concise view of what threatens organizational objectives and how management is responding. Option C (Risk heat map) is correct because a heat map visually plots risks by likelihood and impact, enabling the board to quickly grasp relative exposure and prioritize attention without wading through technical detail. Option E (Risk trend analysis) is correct because showing how risk levels change over time (e.g., increasing, stable, or decreasing) demonstrates whether risk management is effective and supports forward-looking governance decisions.

Option A (Detailed technical logs) does not belong because raw logs are operational artifacts for IT staff, not strategic governance information, and would overwhelm the board with irrelevant granularity. Option D (Employee performance reviews) does not belong because individual HR performance data is unrelated to enterprise risk communication and would be inappropriate to present in a board risk report.

Exam trap

CRISC often tests the distinction between operational/technical detail and strategic risk communication, tempting candidates to select detailed technical logs because they seem data-rich, when the board requires aggregated, business-oriented views like top risks, heat maps, and trends.

74
MCQhard

An organization uses a KRI that tracks the average time to patch critical vulnerabilities. The metric has been increasing over the past three months. What does this indicate from a risk perspective?

A.The control effectiveness is improving
B.The risk of exploitation is increasing
C.The risk appetite has been reduced
D.The risk of exploitation is decreasing
AnswerB

Longer patch times leave critical vulnerabilities exposed for extended windows, so the likelihood that an attacker exploits a known flaw rises. The KRI measures exposure duration, and a sustained upward trend signals deteriorating risk posture requiring escalation or remediation.

Why this answer

An increasing average time to patch critical vulnerabilities indicates that the organization is taking longer to remediate known security weaknesses. From a risk perspective, this directly increases the window of exposure, making it more likely that an attacker will exploit a vulnerability before a patch is applied. Therefore, the risk of exploitation is increasing.

Exam trap

The trap here is that candidates may confuse a rising KRI metric with improved security posture, failing to recognize that longer remediation times increase exposure and risk of exploitation.

How to eliminate wrong answers

Option A is wrong because an increasing patch time indicates control effectiveness is deteriorating, not improving; effective controls would show decreasing or stable patch times. Option C is wrong because risk appetite is a strategic decision about acceptable risk levels, not a metric derived from patch timeliness; a reduced risk appetite would typically drive faster patching, not slower. Option D is wrong because it is the direct opposite of the correct interpretation; increasing patch time means the risk of exploitation is increasing, not decreasing.

75
MCQhard

During a risk analysis, the risk team finds that a legacy inventory system has a single point of failure: one administrator holds the only credentials for the backup restoration process. The system supports regulatory filings with a hard deadline. Management proposes documenting the situation in the risk register and revisiting it next year. Which action should the risk practitioner take?

A.Transfer the risk by purchasing additional cyber insurance for the inventory system.
B.Agree, because the risk is documented and the system still functions today.
C.Escalate the concentration risk and recommend immediate interim controls such as credential escrow or a second trained administrator.
D.Remove the administrator's access until a permanent solution is approved.
AnswerC

The finding combines high impact with a low-cost remedy, which justifies prompt action rather than annual review. Credential escrow or a cross-trained backup administrator reduces both availability and integrity exposure quickly. Escalating also places the decision with the accountable owner, ensuring the regulatory deadline risk is weighed against the effort of remediation now.

Why this answer

A single point of failure tied to a hard regulatory deadline and held by one person warrants prompt treatment, especially when low-cost interim measures exist. Escalating with a recommendation to escrow credentials or train a second administrator addresses availability and fraud exposure immediately while a permanent solution is designed. Deferring, blocking access, or relying solely on insurance leaves the operational and compliance risk intact.

Exam trap

The trap here is believing that logging a risk in the register and scheduling a future review constitutes an adequate risk response.

Page 1 of 3 · 176 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Crisc Risk Response questions.