nerdexam
Isaca

CRISC · Question #404

Which of the following actions should a risk practitioner do NEXT when an increased industry trend of external cyber attacks is identified?

The correct answer is A. Conduct a threat and vulnerability analysis.. When an increased industry trend of external cyber attacks is identified, the next action for a risk practitioner should be to conduct a threat and vulnerability analysis.

Submitted by ricky.ec· Apr 18, 2026IT Risk Assessment

Question

Which of the following actions should a risk practitioner do NEXT when an increased industry trend of external cyber attacks is identified?

Options

  • AConduct a threat and vulnerability analysis.
  • BNotify senior management of the new risk scenario.
  • CUpdate the risk impact rating in the risk register.
  • DUpdate the key risk indicator (KRI) in the risk register.

How the community answered

(26 responses)
  • A
    85% (22)
  • B
    8% (2)
  • C
    4% (1)
  • D
    4% (1)

Why each option

When an increased industry trend of external cyber attacks is identified, the next action for a risk practitioner should be to conduct a threat and vulnerability analysis.

AConduct a threat and vulnerability analysis.Correct

An industry trend of increased cyber attacks signifies a heightened threat landscape. Conducting a threat and vulnerability analysis will help determine if the organization is susceptible to these specific types of attacks, identify potential weaknesses, and assess the likelihood and potential impact on the organization's assets. This analysis provides the necessary details before escalating or modifying risk treatments.

BNotify senior management of the new risk scenario.

Notifying senior management is important but typically follows an assessment of the *specific* impact and likelihood to the organization, which is determined by a threat and vulnerability analysis.

CUpdate the risk impact rating in the risk register.

Updating the risk impact rating prematurely without understanding the organization's specific vulnerabilities and exposure to the new trend could lead to inaccurate assessments.

DUpdate the key risk indicator (KRI) in the risk register.

Updating KRIs might be a subsequent step if the analysis reveals new indicators, but the immediate need is to understand the direct implications for the organization.

Concept tested: Risk assessment process steps

Topics

#Risk assessment#Threat analysis#Vulnerability analysis#Cyber security risk

Community Discussion

No community discussion yet for this question.

Full CRISC Practice