Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?

⚠ Common exam trap

A common mix-up: candidates confuse leading indicators (which predict risk) with lagging indicators (which measure past events), leading candidates to pick options like the number of security incidents or audit findings resolved, which are reactive rather than predictive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of systems with missing critical patches

A leading Key Risk Indicator (KRI) predicts future risk events by measuring conditions that precede incidents. Missing critical patches on systems directly indicate a higher likelihood of exploitation, making it a leading indicator. In contrast, lagging KRIs like incident counts or costs measure outcomes after the fact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Percentage of systems with missing critical patches

    Why this is correct

    Missing critical patches measure a condition that precedes and predicts future loss events, making them a leading indicator. Lagging KRIs, by contrast, record incidents already realised, such as breach counts or downtime hours, so they cannot drive preventive action.

  • ✗

    Number of audit findings resolved

    Why it's wrong here

    Audit findings resolved counts remediation completed after issues were detected, making it lagging rather than leading. It is the right measure when tracking how effectively previously identified control gaps have been closed over a reporting period.

  • ✗

    Number of security incidents this quarter

    Why it's wrong here

    Counting security incidents this quarter records events that already happened, so it is a lagging indicator. Incident counts are correct when measuring historical frequency or trend, not when predicting the likelihood of future risk events.

  • ✗

    Total cost of security incidents

    Why it's wrong here

    Total cost of security incidents is a lagging indicator: it quantifies losses after incidents have already occurred, so it cannot signal future risk. Cost metrics are correct when reporting realised impact to management rather than anticipating exposure.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.