CRISC Risk Response and Reporting Practice Question
Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?
⚠ Common exam trap
A common mix-up: candidates confuse leading indicators (which predict risk) with lagging indicators (which measure past events), leading candidates to pick options like the number of security incidents or audit findings resolved, which are reactive rather than predictive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of systems with missing critical patches
A leading Key Risk Indicator (KRI) predicts future risk events by measuring conditions that precede incidents. Missing critical patches on systems directly indicate a higher likelihood of exploitation, making it a leading indicator. In contrast, lagging KRIs like incident counts or costs measure outcomes after the fact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Percentage of systems with missing critical patches
Why this is correct
Missing critical patches measure a condition that precedes and predicts future loss events, making them a leading indicator. Lagging KRIs, by contrast, record incidents already realised, such as breach counts or downtime hours, so they cannot drive preventive action.
- ✗
Number of audit findings resolved
Why it's wrong here
Audit findings resolved counts remediation completed after issues were detected, making it lagging rather than leading. It is the right measure when tracking how effectively previously identified control gaps have been closed over a reporting period.
- ✗
Number of security incidents this quarter
Why it's wrong here
Counting security incidents this quarter records events that already happened, so it is a lagging indicator. Incident counts are correct when measuring historical frequency or trend, not when predicting the likelihood of future risk events.
- ✗
Total cost of security incidents
Why it's wrong here
Total cost of security incidents is a lagging indicator: it quantifies losses after incidents have already occurred, so it cannot signal future risk. Cost metrics are correct when reporting realised impact to management rather than anticipating exposure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.