nerdexam
Isaca

CRISC · Question #467

A risk practitioner is defining metrics for security threats that were not identified by antivirus software. Which type of metric is being developed?

The correct answer is B. Key risk indicator (KRI). Metrics for security threats not identified by existing controls, like antivirus, are Key Risk Indicators (KRIs), as they signal potential future risks or exposures.

Submitted by thandi_sa· Apr 18, 2026Risk Response and Reporting

Question

A risk practitioner is defining metrics for security threats that were not identified by antivirus software. Which type of metric is being developed?

Options

  • AKey control indicator (KCI)
  • BKey risk indicator (KRI)
  • COperational level agreement (OLA)
  • DService level agreement (SLA)

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    71% (20)
  • C
    7% (2)
  • D
    18% (5)

Why each option

Metrics for security threats not identified by existing controls, like antivirus, are Key Risk Indicators (KRIs), as they signal potential future risks or exposures.

AKey control indicator (KCI)

Key Control Indicators (KCIs) measure the effectiveness of controls, not the emergence of new or undetected threats.

BKey risk indicator (KRI)Correct

Key Risk Indicators (KRIs) are metrics used to monitor the level of risk an organization faces, providing an early warning signal of increasing risk exposure. When antivirus software fails to identify threats, it indicates a potential gap or emerging threat landscape, which is precisely what a KRI would track to alert management to heightened risk.

COperational level agreement (OLA)

Operational Level Agreements (OLAs) are internal agreements that define service levels between internal departments, unrelated to external threat detection.

DService level agreement (SLA)

Service Level Agreements (SLAs) are external agreements defining the expected level of service from a provider, which is not directly relevant to identifying new threats.

Concept tested: Key Risk Indicator (KRI) definition

Topics

#Key Risk Indicators#Risk Metrics#Threat Monitoring#Risk Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice