nerdexam
Isaca

CRISC · Question #632

Upon learning that the number of failed backup attempts continually exceeds the current risk threshold, the risk practitioner should:

The correct answer is A. initiate corrective action to address the known deficiency.. When the number of failed backup attempts consistently exceeds the established risk threshold, the risk practitioner must take immediate action to address this identified deficiency.

Submitted by weili_xi· Apr 18, 2026Risk Response and Reporting

Question

Upon learning that the number of failed backup attempts continually exceeds the current risk threshold, the risk practitioner should:

Options

  • Ainitiate corrective action to address the known deficiency.
  • Badjust the risk threshold to better reflect actual performance.
  • Cinquire about the status of any planned corrective actions.
  • Dkeep monitoring the situation as there is evidence that this is normal.

How the community answered

(39 responses)
  • A
    79% (31)
  • B
    8% (3)
  • C
    10% (4)
  • D
    3% (1)

Why each option

When the number of failed backup attempts consistently exceeds the established risk threshold, the risk practitioner must take immediate action to address this identified deficiency.

Ainitiate corrective action to address the known deficiency.Correct

Exceeding a risk threshold signifies that an unacceptable level of risk has been realized or is imminent, indicating a known deficiency in controls or processes. The appropriate response is to initiate corrective action to bring the risk back within the acceptable threshold and prevent potential data loss or operational disruption due to backup failures.

Badjust the risk threshold to better reflect actual performance.

Adjusting the risk threshold to match poor performance is a form of risk acceptance without remediation and undermines the purpose of risk management, rather than addressing the underlying issue.

Cinquire about the status of any planned corrective actions.

Inquiring about planned corrective actions is insufficient; the situation requires active initiation of new or accelerated existing corrective actions due to the continuous threshold breach.

Dkeep monitoring the situation as there is evidence that this is normal.

Monitoring the situation further is inappropriate when the risk threshold is continually exceeded, as it implies a critical control deficiency that requires immediate attention, not passive observation.

Concept tested: Risk response to threshold breaches

Topics

#Risk Response#Corrective Action#Risk Thresholds#Risk Monitoring

Community Discussion

No community discussion yet for this question.

Full CRISC Practice