CRISC Risk Response and Reporting Practice Question
Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?
⚠ Common exam trap
CRISC often tests the leading vs lagging indicator distinction, and candidates commonly pick 'number of successful logins' or 'password reset frequency' because they sound security-relevant — the trap is that these are lagging or ambiguous metrics, while failed authentication is the predictive precursor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Failed authentication spike
A leading indicator predicts future risk before loss occurs. A spike in failed authentication attempts is a precursor signal — it suggests credential stuffing, brute-force, or password-spraying activity is underway, which may precede a successful credential-based compromise. Because it is observable before the breach materializes, it functions as a leading indicator that the risk of credential-based attack is increasing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Failed authentication spike
Why this is correct
A spike in failed authentication attempts is measurable before a breach succeeds, making it a leading indicator. It signals attackers actively probing credentials, unlike lagging indicators such as confirmed account compromises, which only appear after the attack has already occurred.
- ✗
Number of accounts created
Why it's wrong here
Account creation is not directly related to credential attacks.
- ✗
Password reset frequency
Why it's wrong here
Reset frequency reflects forgotten passwords and helpdesk load, not attacker behaviour; users resetting often indicates poor usability or expiry policy. It would be the right indicator when assessing operational support demand or password policy effectiveness, not credential-attack likelihood.
- ✗
Number of successful logins
Why it's wrong here
Successful logins measure post-authentication activity, not attack likelihood; they rise with legitimate user growth and cannot signal credential compromise. The metric is tempting because it supports capacity planning and availability monitoring, where volume trends matter. Detecting credential-based attack risk requires failed authentication attempts, impossible-travel alerts, or leaked-credential matches from Microsoft Entra ID.
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.