Courseiva

CRISC Risk Response and Reporting Practice Question

Which of the following is a Key Risk Indicator (KRI) that provides leading indication of increasing vulnerability risk?

⚠ Common exam trap

CRISC often tests leading versus lagging indicators by offering metrics like incident counts or MTTD that sound risk-related but are actually lagging, tempting candidates to misclassify them as leading KRIs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch lag metric

Patch lag metric is a leading KRI because it measures the time between patch availability and deployment, directly indicating how exposed systems are to known vulnerabilities before exploitation occurs. A growing patch lag signals increasing vulnerability risk before incidents materialize.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Control deficiency rate

    Why it's wrong here

    Control deficiency rate counts weaknesses already identified through assessment, so it lags the exposure it describes rather than signalling vulnerabilities yet to be exploited. It is tempting because deficiency counts do correlate with risk posture, making this KRI appropriate when reporting the effectiveness of completed control testing.

  • ✓

    Patch lag metric

    Why this is correct

    Patch lag measures elapsed time between patch release and deployment, rising before exploitation occurs, so it leads vulnerability risk rather than reporting it afterwards. This satisfies the KRI requirement for a leading indication, unlike lagging metrics such as confirmed exploit counts.

  • ✗

    Mean time to detect (MTTD)

    Why it's wrong here

    MTTD measures how long existing incidents take to surface, so it reports detection capability after a compromise rather than forecasting rising vulnerability exposure. It is tempting because faster detection genuinely reduces breach impact, making it the right KRI when the concern is response maturity rather than anticipating new weaknesses.

  • ✗

    Number of security incidents

    Why it's wrong here

    Incident counts record events that have already occurred, making this a lagging indicator of realised risk rather than a leading signal of growing vulnerability. It is tempting because incident volume is easily measured and trended, so it suits reporting historical security performance to management.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.