CRISC Information Technology and Security Practice Question
Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exclusions for acts of war or state-sponsored attacks
Cyber insurance policies have specific coverage scopes, exclusions (e.g., war, negligence), and prerequisites (e.g., multi-factor authentication). Premium factors like security controls also affect cost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Exclusions for acts of war or state-sponsored attacks
Why this is correct
War and state-sponsored attack exclusions remove cover for precisely the severe, costly incidents many organisations most need to transfer. Reviewing these exclusions satisfies the evaluation criterion of identifying retained risk, because excluded events remain the organisation's financial responsibility.
- ✓
Incident response prerequisites such as mandatory use of approved vendors
Why this is correct
Insurers often require pre-approved vendors and defined response steps before paying claims. Verifying these prerequisites satisfies the evaluation criterion of confirming the organisation can actually meet the conditions attached to cover, since unmet conditions can void an otherwise valid claim.
- ✓
Coverage scope for different incident types
Why this is correct
Policies define which incident types they indemnify, so mismatches leave gaps. Confirming scope covers the incidents the organisation actually faces satisfies the evaluation criterion of aligning cover with real exposure, rather than assuming a generic policy responds to every event.
- ✗
Company's stock price volatility
Why it's wrong here
Stock price volatility is a financial-market metric with no bearing on cyber insurance underwriting, which assesses data exposure, incident response and regulatory liability. It tempts because insurers do weigh financial health, but share-price movement is not a coverage criterion for a cyber policy.
- ✗
Office location and building security
Why it's wrong here
Physical office location and building security fall under general property or premises cover, not cyber insurance, which addresses data breaches, ransomware and network incidents. It tempts because physical controls support overall security, but they are not a coverage consideration when evaluating a cyber policy.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.