CRISC Practice Questions
KRI / KPI and SDLC - 40 Questions
Interactive Quiz
Question 1 of 40
0%
Score: 0
Correct: 0
Wrong: 0
Part 1: KRI and KPI
1 What is the PRIMARY purpose of a Key Risk Indicator (KRI)?
Answer: B - To provide early warning of increasing risk exposure
A KRI is a forward-looking metric that provides early warning signals of increasing risk exposure, allowing management to take proactive action before a risk materializes.
2 What is the PRIMARY purpose of a Key Performance Indicator (KPI)?
Answer: C - To measure how well the organization is achieving its business objectives
A KPI measures performance against business objectives and strategic goals. It focuses on past or current performance, not on risk exposure.
3 Which of the following BEST distinguishes a KRI from a KPI?
Answer: A - KRIs are forward-looking and risk-focused; KPIs are backward-looking and performance-focused
KRIs are predictive and focus on risk exposure. KPIs are historical and focus on performance. Both can be quantitative or qualitative.
4 A KRI should ideally be:
Answer: D - Measurable, relevant, and linked to a specific risk
Effective KRIs must be measurable, relevant to the risk they monitor, and clearly linked to a specific risk. They should be simple enough to be understood and acted upon.
5 Which of the following is the BEST example of a KRI?
Answer: B - Percentage of critical systems missing the latest security patch
Missing patches is a forward-looking risk indicator. It signals potential vulnerability and exposure. The other options are performance indicators.
6 Which of the following is the BEST example of a KPI?
Answer: C - Percentage of projects delivered on time and on budget
This KPI measures performance against a business objective (project delivery). The other options are risk-related indicators.
7 What does a KRI threshold represent?
Answer: A - The level at which a risk indicator triggers action or escalation
KRI thresholds define acceptable and unacceptable levels of risk. When a threshold is breached, it triggers action, escalation, or management response.
8 How often should KRIs be reported?
Answer: D - At a frequency that matches the speed at which the risk can change
KRI reporting frequency should align with how quickly the underlying risk can change. Fast-changing risks require more frequent monitoring.
9 A KRI that consistently exceeds its threshold should trigger:
Answer: B - Management action, escalation, or a review of controls
When a KRI breaches its threshold, it signals increasing risk. This should prompt management action, escalation to senior management or the Board, and a review of controls.
10 Which of the following is a KEY characteristic of an effective KRI?
Answer: C - It is predictive of future risk events
An effective KRI is predictive, helping the organization anticipate risk events. It should be measurable, relevant, and actionable.
11 Who is primarily responsible for defining and monitoring KPIs within an organization?
Answer: A - Business management and process owners
KPIs are typically defined and monitored by business management and process owners because they measure performance against business objectives.
12 Which of the following is a common PITFALL when designing KRIs?
Answer: D - Using too many KRIs that are not actionable
A common pitfall is over-reporting KRIs that are not linked to actionable outcomes. Effective KRI programs use a focused set of meaningful metrics.
13 Which type of indicator is a "lagging indicator"?
Answer: B - One that measures past outcomes or events
Lagging indicators measure what has already happened, such as number of incidents. Leading indicators predict what might happen in the future.
14 Which type of indicator is a "leading indicator"?
Answer: C - Percentage of employees who have not completed security awareness training
Untrained employees are a leading indicator of potential future security incidents. The other options are lagging indicators (measuring what already happened).
15 A KRI dashboard for the Board should PRIMARILY focus on:
Answer: A - Strategic and high-impact risks with clear trend indicators
Board-level KRI dashboards should focus on strategic, high-impact risks and trends, not granular operational details which belong at management level.
16 Which of the following BEST describes the relationship between KRIs and KPIs?
Answer: D - They complement each other and provide a balanced view of performance and risk
KRIs and KPIs are complementary. Together, they provide a balanced view of how well the organization is performing and how much risk it is taking.
17 A KRI that is NO LONGER relevant to the organization should be:
Answer: B - Reviewed and removed or replaced with a more relevant indicator
KRI programs should be reviewed regularly to ensure metrics remain relevant. Outdated KRIs should be retired and replaced with more meaningful indicators.
18 When a KRI approaches its threshold, the BEST course of action is to:
Answer: C - Investigate the cause and consider proactive mitigation
When a KRI approaches its threshold, this is an early warning. The best action is to investigate the cause and take proactive mitigation before the risk materializes.
19 Which of the following is a characteristic of a GOOD KPI?
Answer: A - It is aligned with strategic objectives and is measurable
Effective KPIs are aligned with strategic objectives, measurable, and regularly reviewed. They should be objective, not subjective.
20 Which of the following BEST describes a "key risk indicator" in the context of CRISC?
Answer: D - A forward-looking metric that provides early warning of increasing risk exposure
A KRI is forward-looking, provides early warning, and helps the organization anticipate and manage risk before it materializes. It complements rather than replaces risk assessment.
21 What is the PRIMARY purpose of the System Development Life Cycle (SDLC)?
Answer: B - To provide a structured approach for developing and managing systems from initiation to retirement
SDLC provides a structured framework covering all phases of system development, from planning through deployment and eventual retirement. It does not eliminate risk or replace project management.
22 At which stage of the SDLC should security requirements FIRST be defined?
Answer: C - During the requirements/planning phase
Security requirements should be defined early during the requirements/planning phase. This is more cost-effective and ensures security is built into the system rather than added later.
23 Which SDLC phase is typically the MOST expensive to fix a security defect?
Answer: A - Production / Post-implementation
The later a defect is discovered, the more expensive it is to fix. Fixing defects in production is far more costly than addressing them during requirements or design.
24 In the SDLC, when should user acceptance testing (UAT) occur?
Answer: D - After development but before deployment to production
UAT occurs after development and system testing are complete, but before deployment to production. This ensures the system meets user requirements before it goes live.
25 What is the MAIN purpose of separating development, testing, and production environments?
Answer: B - To prevent unauthorized or untested changes from reaching production
Environment separation ensures that only properly developed, tested, and approved code reaches production. It reduces the risk of introducing defects or unauthorized changes into live systems.
26 Which of the following is a KEY security consideration during the design phase of the SDLC?
Answer: C - Threat modeling and security architecture review
Threat modeling and security architecture review during the design phase help identify and mitigate security risks before development begins. This is more cost-effective than fixing issues later.
27 What is the PRIMARY purpose of a post-implementation review (PIR) in the SDLC?
Answer: A - To evaluate whether the project met its objectives and to identify lessons learned
A post-implementation review evaluates whether the project achieved its objectives, identifies lessons learned, and provides input for future projects. It does not assign blame.
28 Which SDLC model is BEST suited for projects with rapidly changing requirements?
Answer: D - Agile
Agile methodologies are iterative and adaptive, making them well suited for projects with rapidly changing requirements. Waterfall is more rigid and sequential.
29 In a secure SDLC, when should security testing be performed?
Answer: B - Throughout the entire SDLC at each relevant phase
Security testing should be integrated throughout the SDLC, not just at the end. This includes requirements review, design review, code review, and security testing before deployment.
30 What is the PRIMARY risk of NOT involving information security in the SDLC?
Answer: C - Security vulnerabilities may be introduced that are expensive to fix later
Excluding security from the SDLC leads to vulnerabilities being built into the system, which are costly and difficult to remediate after deployment. Security must be integrated from the start.
31 Which of the following is the CORRECT order of the SDLC phases?
Answer: A - Planning, Requirements, Design, Development, Testing, Deployment, Maintenance
The standard SDLC sequence is Planning, Requirements, Design, Development, Testing, Deployment, and Maintenance. Some variations add a retirement/disposal phase at the end.
32 Which of the following is a KEY control in the change management process of the SDLC?
Answer: D - Formal change approval and segregation of duties between development and deployment
Formal change approval and segregation of duties between developers and those who deploy to production are critical change management controls. This prevents unauthorized or untested changes.
33 In the context of the SDLC, what does "shift left" refer to?
Answer: B - Integrating security and testing activities earlier in the SDLC
"Shift left" means moving security and quality activities earlier in the SDLC. This is more cost-effective and reduces the risk of defects and vulnerabilities reaching production.
34 Which of the following is a CRITICAL control during the deployment phase of the SDLC?
Answer: C - A documented rollback plan in case of deployment failure
A documented rollback plan is critical to minimize business disruption if deployment fails. It should be tested and approved before deployment begins.
35 What is the MAIN purpose of a feasibility study in the SDLC?
Answer: A - To determine whether the project is technically, financially, and operationally viable
A feasibility study evaluates whether the project is technically, financially, and operationally viable before significant resources are committed. It is typically done during the planning phase.
36 Which of the following is a common risk associated with the maintenance phase of the SDLC?
Answer: D - Unauthorized or poorly tested changes being introduced into production
The maintenance phase is vulnerable to unauthorized or poorly tested changes. Strong change management and segregation of duties are essential controls in this phase.
37 What is the PRIMARY purpose of conducting a security risk assessment during the SDLC?
Answer: B - To identify, evaluate, and mitigate security risks associated with the system
A security risk assessment identifies, evaluates, and helps mitigate security risks. It does not eliminate all vulnerabilities or replace security testing.
38 Which of the following is MOST important when managing third-party or outsourced software development?
Answer: C - Contractual security requirements and independent verification of deliverables
When outsourcing development, contractual security requirements and independent verification are essential. Organizations remain accountable for the security of their systems regardless of who develops them.
39 What is the PRIMARY purpose of a data migration plan in the SDLC?
Answer: A - To ensure accurate and complete transfer of data from the old system to the new one
A data migration plan ensures data is accurately and completely transferred from the old system to the new one. It includes validation, reconciliation, and rollback procedures.
40 In the SDLC, what is the PRIMARY objective of the disposal/retirement phase?
Answer: D - To securely retire the system and protect sensitive data from unauthorized access
The disposal/retirement phase ensures systems and data are securely retired, including data sanitization, archiving where required, and proper disposal of hardware to prevent data leakage.
🏆
Quiz Complete!
0 / 40
0
Correct
0
Wrong
40
Total
Quick Reference Summary
| Concept | Purpose | Key Characteristics |
|---|---|---|
| KRI | Early warning of increasing risk | Forward-looking, predictive, risk-focused |
| KPI | Measure business performance | Backward-looking, historical, performance-focused |
| SDLC | Structured system development | Planning, Requirements, Design, Development, Testing, Deployment, Maintenance |
| Secure SDLC | Integrate security throughout development | Shift left, threat modeling, security testing at each phase |
Exam Tips
- KRI vs KPI - KRI is forward-looking (risk); KPI is backward-looking (performance).
- Leading vs Lagging - Leading indicators predict; lagging indicators confirm what already happened.
- KRI threshold breach - Triggers escalation, management action, and control review.
- SDLC security - Security must be integrated from the requirements phase, not added at the end.
- Cost of fixing defects - Increases significantly the later they are discovered in the SDLC.
- Change management - Formal approval and segregation of duties are critical in the SDLC.
- Post-implementation review - Evaluates objectives and lessons learned, not blame.






0 $type={blogger}:
Post a Comment