nerdexam
Isaca

CRISC · Question #482

The percentage of unpatched systems is a:

The correct answer is D. key risk indicator (KRI).. The percentage of unpatched systems serves as a key risk indicator (KRI) because it measures a condition that can signal increased risk to the organization.

Submitted by olafpl· Apr 18, 2026Risk Response and Reporting

Question

The percentage of unpatched systems is a:

Options

  • Athreat vector.
  • Bcritical success factor (CSF).
  • Ckey performance indicator (KPI).
  • Dkey risk indicator (KRI).

How the community answered

(59 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    7% (4)
  • D
    88% (52)

Why each option

The percentage of unpatched systems serves as a key risk indicator (KRI) because it measures a condition that can signal increased risk to the organization.

Athreat vector.

A threat vector is the path or method an attacker uses to gain unauthorized access or deliver malware, not a metric of a system's state.

Bcritical success factor (CSF).

A critical success factor (CSF) is an element necessary for an organization or project to achieve its mission or goals, not a specific risk metric.

Ckey performance indicator (KPI).

A key performance indicator (KPI) measures how well an organization is achieving its strategic and operational goals, typically related to output or efficiency, rather not risk levels.

Dkey risk indicator (KRI).Correct

A Key Risk Indicator (KRI) is a metric used to provide an early signal of increasing risk exposure for an organization, where a higher percentage of unpatched systems directly indicates increased vulnerability and potential for a security incident. Monitoring this metric helps proactively manage and reduce the likelihood of successful attacks due to unaddressed vulnerabilities.

Concept tested: Key risk indicator identification

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Key Risk Indicators (KRI)#Risk Metrics#Risk Monitoring#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice