CRISC Risk Monitoring, Reporting, and KRIs 2 — Questions and Answers
Question 1: Which activity is MOST critical to maintaining an accurate risk register over time?
- Regular review and update based on changes in threats, controls, and business context (Correct answer)
- Annual recertification of all risks by IT management
- Automated import of vulnerability scan data into the register
- Archiving old risks to keep the register manageable
Correct answer: Regular review and update based on changes in threats, controls, and business context
A risk register must be actively maintained by updating it as threats evolve, controls change, and business conditions shift to remain a reliable risk management tool.
Question 2: A risk dashboard that shows risks trending toward the red zone is MOST useful for which purpose?
- Triggering proactive risk response before the risk reaches critical levels (Correct answer)
- Documenting post-incident lessons learned
- Justifying the IT security budget to senior management
- Identifying which employees need additional security training
Correct answer: Triggering proactive risk response before the risk reaches critical levels
A worsening trend visible on a risk dashboard gives risk owners advance warning to act before a risk breaches tolerance thresholds.
Question 3: Which metric would BEST serve as a KRI for the risk of insider data theft?
- Number of employees accessing data outside normal business hours (Correct answer)
- Total number of data records in the organization's databases
- Number of external security incidents reported monthly
- Average time to complete employee security awareness training
Correct answer: Number of employees accessing data outside normal business hours
Unusual access patterns such as off-hours data access are leading indicators of potential insider threat activity and directly correlate to insider theft risk.
Question 4: Which condition indicates that a control monitoring program is INEFFECTIVE?
- Control failures are only discovered after security incidents occur (Correct answer)
- Control test results are documented and reported quarterly
- Automated monitoring tools alert within minutes of a control failure
- Control owners review monitoring reports and take corrective action
Correct answer: Control failures are only discovered after security incidents occur
Discovering control failures only after incidents indicates monitoring is reactive rather than proactive, meaning the monitoring program has failed its purpose.
Question 5: Which element should be included in a risk exception report submitted to senior management?
- The risk description, justification for exception, residual risk level, and expiration date (Correct answer)
- A complete list of all accepted risks across the organization
- Technical details of the vulnerabilities associated with the risk
- A comparison of the organization's risk posture to industry benchmarks
Correct answer: The risk description, justification for exception, residual risk level, and expiration date
A risk exception report must document what the risk is, why the exception is justified, the remaining residual risk, and when the exception will be reviewed or expire.
Question 6: The concept of 'risk-based monitoring' means that monitoring intensity should be:
- Proportional to the significance of the risk being monitored (Correct answer)
- Equal across all systems to ensure consistent coverage
- Greatest for systems that were recently upgraded
- Focused exclusively on externally facing systems
Correct answer: Proportional to the significance of the risk being monitored
Risk-based monitoring concentrates resources on higher-risk areas, ensuring that the most significant risks receive the most frequent and rigorous monitoring.
Which activity is MOST critical to maintaining an accurate risk register over time?