CRISC Exam Question 356
Which of the following is the BEST reason to use qualitative measures to express residual risk levels related to emerging threats?
Correct Answer: C
Qualitative measures are methods of expressing risk levels using descriptive terms, such as high, medium, or low, based on subjective criteria, such as likelihood, impact, or severity. Qualitative measures are often used to identify and prioritize risks, and to communicate risk information to stakeholders1.
Residual risk is the level of risk that remains after the risk response has been implemented. Residual risk reflects the effectiveness and efficiency of the risk response, and the need for further action or monitoring2.
Emerging threats are new or evolving sources or causes of risk that have the potential to adversely affect the organization's objectives, assets, or operations. Emerging threats are often characterized by uncertainty, complexity, and ambiguity, and may require innovative or adaptive risk responses3.
The best reason to use qualitative measures to express residual risk levels related to emerging threats is that qualitative measures are better able to incorporate expert judgment. Expert judgment is the opinion or advice of a person or a group of people who have specialized knowledge, skills, or experience in a particular domain or field. Expert judgment can help to:
* Provide insights and perspectives on the nature and characteristics of the emerging threats, and their possible causes and consequences
* Assess the likelihood and impact of the emerging threats, and their interactions and dependencies with other risks
* Evaluate the suitability and effectiveness of the risk responses, and their alignment with the organization's risk appetite and tolerance
* Identify and recommend the best practices and lessons learned for managing the emerging threats, and for improving the risk management process45 Qualitative measures are better able to incorporate expert judgment than quantitative measures, which are methods of expressing risk levels using numerical or measurable values, such as percentages, probabilities, or monetary amounts. Quantitative measures are often used to estimate and analyze risks, and to support risk decision making1. However, quantitative measures may not be suitable or feasible for expressing residual risk levels related to emerging threats, because:
* Quantitative measures require reliable and sufficient data and information, which may not be available or accessible for the emerging threats
* Quantitative measures rely on mathematical models and techniques, which may not be able to capture or reflect the complexity and uncertainty of the emerging threats
* Quantitative measures may create a false sense of precision or accuracy, which may not be justified or warranted for the emerging threats
* Quantitative measures may be influenced or manipulated by biases or assumptions, which may not be valid or appropriate for the emerging threats67 Therefore, qualitative measures are better able to incorporate expert judgment, which can enhance the understanding and management of the residual risk levels related to emerging threats.
The other options are not the best reasons to use qualitative measures to express residual risk levels related to emerging threats, but rather some of the advantages or disadvantages of qualitative measures. Qualitative measures require less ongoing monitoring than quantitative measures, because they are simpler and easier to apply and update. However, this does not mean that qualitative measures can eliminate or reduce the need for monitoring, which is an essential part of the risk management process. Qualitative measures are better aligned to regulatory requirements than quantitative measures, because they are more consistent and comparable across different domains and contexts. However, this does not mean that qualitative measures can satisfy or comply with all the regulatory requirements, which may vary depending on the industry or sector. Qualitative measures are easier to update than quantitative measures, because they do not depend on complex calculations or formulas. However, this does not mean that qualitative measures can always reflect the current or accurate risk levels, which may change over time or due to external factors. References =
* Qualitative Risk Analysis vs. Quantitative Risk Analysis - ISACA
* Residual Risk - ISACA
* Emerging Threats - ISACA
* Expert Judgment - ISACA
* Expert Judgment in Project Management: Narrowing the Theory-Practice Gap
* Quantitative Risk Analysis - ISACA
* Quantitative Risk Analysis: A Critical Review
* [CRISC Review Manual, 7th Edition]
Residual risk is the level of risk that remains after the risk response has been implemented. Residual risk reflects the effectiveness and efficiency of the risk response, and the need for further action or monitoring2.
Emerging threats are new or evolving sources or causes of risk that have the potential to adversely affect the organization's objectives, assets, or operations. Emerging threats are often characterized by uncertainty, complexity, and ambiguity, and may require innovative or adaptive risk responses3.
The best reason to use qualitative measures to express residual risk levels related to emerging threats is that qualitative measures are better able to incorporate expert judgment. Expert judgment is the opinion or advice of a person or a group of people who have specialized knowledge, skills, or experience in a particular domain or field. Expert judgment can help to:
* Provide insights and perspectives on the nature and characteristics of the emerging threats, and their possible causes and consequences
* Assess the likelihood and impact of the emerging threats, and their interactions and dependencies with other risks
* Evaluate the suitability and effectiveness of the risk responses, and their alignment with the organization's risk appetite and tolerance
* Identify and recommend the best practices and lessons learned for managing the emerging threats, and for improving the risk management process45 Qualitative measures are better able to incorporate expert judgment than quantitative measures, which are methods of expressing risk levels using numerical or measurable values, such as percentages, probabilities, or monetary amounts. Quantitative measures are often used to estimate and analyze risks, and to support risk decision making1. However, quantitative measures may not be suitable or feasible for expressing residual risk levels related to emerging threats, because:
* Quantitative measures require reliable and sufficient data and information, which may not be available or accessible for the emerging threats
* Quantitative measures rely on mathematical models and techniques, which may not be able to capture or reflect the complexity and uncertainty of the emerging threats
* Quantitative measures may create a false sense of precision or accuracy, which may not be justified or warranted for the emerging threats
* Quantitative measures may be influenced or manipulated by biases or assumptions, which may not be valid or appropriate for the emerging threats67 Therefore, qualitative measures are better able to incorporate expert judgment, which can enhance the understanding and management of the residual risk levels related to emerging threats.
The other options are not the best reasons to use qualitative measures to express residual risk levels related to emerging threats, but rather some of the advantages or disadvantages of qualitative measures. Qualitative measures require less ongoing monitoring than quantitative measures, because they are simpler and easier to apply and update. However, this does not mean that qualitative measures can eliminate or reduce the need for monitoring, which is an essential part of the risk management process. Qualitative measures are better aligned to regulatory requirements than quantitative measures, because they are more consistent and comparable across different domains and contexts. However, this does not mean that qualitative measures can satisfy or comply with all the regulatory requirements, which may vary depending on the industry or sector. Qualitative measures are easier to update than quantitative measures, because they do not depend on complex calculations or formulas. However, this does not mean that qualitative measures can always reflect the current or accurate risk levels, which may change over time or due to external factors. References =
* Qualitative Risk Analysis vs. Quantitative Risk Analysis - ISACA
* Residual Risk - ISACA
* Emerging Threats - ISACA
* Expert Judgment - ISACA
* Expert Judgment in Project Management: Narrowing the Theory-Practice Gap
* Quantitative Risk Analysis - ISACA
* Quantitative Risk Analysis: A Critical Review
* [CRISC Review Manual, 7th Edition]
CRISC Exam Question 357
An organization is planning to engage a cloud-based service provider for some of its data-intensive business processes. Which of the following is MOST important to help define the IT risk associated with this outsourcing activity?
Correct Answer: A
According to the CRISC Review Manual (Digital Version), the right to audit the provider is the most important factor to help define the IT risk associated with outsourcing activity to a cloud-based service provider, as it enables the organization to verify the compliance and performance of the provider with the contractual obligations and service level agreements. The right to audit the provider helps to:
* Assess the security, availability, confidentiality, integrity, and privacy of the data and processes hosted by the provider
* Identify and evaluate the risks and controls related to the cloud-based services and the provider's infrastructure
* Monitor and measure the quality and effectiveness of the cloud-based services and the provider's governance and management practices
* Report and resolve any issues or incidents related to the cloud-based services and the provider's operations
* Ensure the alignment of the cloud-based services and the provider's policies and standards with the organization's objectives and requirements References = CRISC Review Manual (Digital Version), Chapter 3: IT Risk Response, Section 3.3: Risk Response Options, pp. 176-1771
* Assess the security, availability, confidentiality, integrity, and privacy of the data and processes hosted by the provider
* Identify and evaluate the risks and controls related to the cloud-based services and the provider's infrastructure
* Monitor and measure the quality and effectiveness of the cloud-based services and the provider's governance and management practices
* Report and resolve any issues or incidents related to the cloud-based services and the provider's operations
* Ensure the alignment of the cloud-based services and the provider's policies and standards with the organization's objectives and requirements References = CRISC Review Manual (Digital Version), Chapter 3: IT Risk Response, Section 3.3: Risk Response Options, pp. 176-1771
CRISC Exam Question 358
Because of a potential data breach, an organization has decided to temporarily shut down its online sales order system until sufficient controls can be implemented. Which risk treatment has been selected?
Correct Answer: A
Risk avoidance involves ceasing activities that expose the organization to significant risks, such as shutting down the sales order system. This decision aligns with Risk Treatment Strategies aimed at eliminating exposure.
CRISC Exam Question 359
The risk associated with an asset after controls are applied can be expressed as:
Correct Answer: C
The risk associated with an asset after controls are applied can be expressed as a function of the likelihood and impact, as it helps to measure and quantify the residual risk level and exposure. Residual risk is the risk that remains after the implementation of controls or risk treatments. Residual risk can be calculated by multiplying the likelihood and impact of a risk event, where likelihood is the probability or frequency of the risk event occurring, and impact is the consequence or severity of the risk event on the asset or objective.
Residual risk can be expressed as:
ResidualRisk=Likelihood×Impact
Expressing the risk associated with an asset after controls are applied as a function of the likelihood and impact helps to provide the following benefits:
* It enables a data-driven and evidence-based approach to risk assessment and reporting, rather than relying on subjective or qualitative judgments.
* It facilitates a consistent and standardized way of measuring and communicating risk levels and exposure across the organization and to the external stakeholders.
* It supports the alignment of risk management and control activities with the organizational strategy and objectives, and helps to evaluate the achievement of the desired outcomes.
* It helps to identify and prioritize the areas for improvement and enhancement of the risk management and control processes, and guide the development and implementation of corrective or preventive actions.
* It provides feedback and learning opportunities for the risk management and control processes, and helps to foster a culture of continuous improvement and innovation.
The other options are not the best ways to express the risk associated with an asset after controls are applied.
A function of the cost and effectiveness of controls is a measure of the inputs or outputs of the risk management and control processes, but it does not indicate the risk level or exposure. The likelihood of a given threat is a component of the risk calculation, but it does not reflect the impact or consequence of the threat. The magnitude of an impact is a component of the risk calculation, but it does not reflect the likelihood or probability of the risk event. References = Risk Assessment and Analysis Methods: Qualitative and Quantitative, IT Risk Resources | ISACA, Residual Risk: Definition, Formula & Management - Video & Lesson ...
Residual risk can be expressed as:
ResidualRisk=Likelihood×Impact
Expressing the risk associated with an asset after controls are applied as a function of the likelihood and impact helps to provide the following benefits:
* It enables a data-driven and evidence-based approach to risk assessment and reporting, rather than relying on subjective or qualitative judgments.
* It facilitates a consistent and standardized way of measuring and communicating risk levels and exposure across the organization and to the external stakeholders.
* It supports the alignment of risk management and control activities with the organizational strategy and objectives, and helps to evaluate the achievement of the desired outcomes.
* It helps to identify and prioritize the areas for improvement and enhancement of the risk management and control processes, and guide the development and implementation of corrective or preventive actions.
* It provides feedback and learning opportunities for the risk management and control processes, and helps to foster a culture of continuous improvement and innovation.
The other options are not the best ways to express the risk associated with an asset after controls are applied.
A function of the cost and effectiveness of controls is a measure of the inputs or outputs of the risk management and control processes, but it does not indicate the risk level or exposure. The likelihood of a given threat is a component of the risk calculation, but it does not reflect the impact or consequence of the threat. The magnitude of an impact is a component of the risk calculation, but it does not reflect the likelihood or probability of the risk event. References = Risk Assessment and Analysis Methods: Qualitative and Quantitative, IT Risk Resources | ISACA, Residual Risk: Definition, Formula & Management - Video & Lesson ...
CRISC Exam Question 360
The PRIMARY benefit associated with key risk indicators (KRls) is that they:
Correct Answer: D
Key risk indicators (KRIs) are metrics that provide information on the level of exposure to a given risk. They enable ongoing monitoring of emerging risk by alerting the organization when the risk level exceeds the predefined threshold or tolerance. By using KRIs, the organization can track the changes in the risk environment and take timely and appropriate actions to mitigate or avoid the risk.
Helping an organization identify emerging threats, benchmarking the organization's risk profile, and identifying trends in the organization's vulnerabilities are all possible uses of KRIs, but they are not the primary benefit. The primary benefit is to enable ongoing monitoring of emerging risk, which encompasses all these aspects and more. References = CRISC Review Manual, 7th Edition, ISACA, 2020, page 27-281
Helping an organization identify emerging threats, benchmarking the organization's risk profile, and identifying trends in the organization's vulnerabilities are all possible uses of KRIs, but they are not the primary benefit. The primary benefit is to enable ongoing monitoring of emerging risk, which encompasses all these aspects and more. References = CRISC Review Manual, 7th Edition, ISACA, 2020, page 27-281
- Other Version
- 1849ISACA.CRISC.v2026-07-15.q907
- 2254ISACA.CRISC.v2026-03-31.q857
- 2602ISACA.CRISC.v2026-01-15.q649
- 5700ISACA.CRISC.v2025-09-26.q726
- 6773ISACA.CRISC.v2025-01-04.q999
- 3505ISACA.CRISC.v2024-06-13.q683
- 4788ISACA.CRISC.v2024-04-02.q999
- 4513ISACA.CRISC.v2023-07-10.q544
- 6997ISACA.CRISC.v2022-05-25.q338
- 76ISACA.Actual4dump.CRISC.v2022-04-12.by.newman.349q.pdf
- 6628ISACA.CRISC.v2022-02-22.q349
- 6833ISACA.CRISC.v2021-10-27.q295
- 42ISACA.Updatedumps.CRISC.v2021-09-05.by.bonnie.114q.pdf
- Latest Upload
- 189Microsoft.AI-300.v2026-08-08.q76
- 142Splunk.SPLK-1004.v2026-08-08.q55
- 127Oracle.1Z0-1075-26.v2026-08-08.q22
- 134VMware.3V0-21.25.v2026-08-08.q35
- 212APICS.CPIM-8.0.v2026-08-08.q264
- 196Cisco.300-720.v2026-08-08.q115
- 159Splunk.SPLK-1003.v2026-08-08.q94
- 147ISACA.AAIR.v2026-08-07.q41
- 139Microsoft.70-123.v2026-08-07.q37
- 152AMP.CRL.v2026-08-07.q61
[×]
Download PDF File
Enter your email address to download ISACA.CRISC.v2025-08-27.q675 Practice Test
