Courseiva

CRISC Information Technology and Security Practice Question

A bank is adopting a third-party API gateway to expose account balance services to fintech partners. The risk practitioner must ensure that a partner's excessive or unusual API consumption cannot degrade service for other partners or core banking systems. Which control is MOST appropriate to address this risk?

⚠ Common exam trap

The trap here is choosing a contractual or cryptographic control when the risk is about availability and capacity exhaustion by one consumer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement per-partner rate limiting and quotas at the API gateway, with circuit breakers to shed load before core systems are affected.

The risk is availability degradation caused by disproportionate consumption from one partner. Enforcing per-partner rate limits and quotas at the gateway constrains each consumer, and circuit breakers prevent overload from propagating into core banking. Contractual caps, mutual TLS and response encryption address expectations, authentication and confidentiality respectively, none of which stop a single partner from exhausting shared capacity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement per-partner rate limiting and quotas at the API gateway, with circuit breakers to shed load before core systems are affected.

    Why this is correct

    The stated risk is that one partner's consumption degrades service for others and for core systems. Per-partner rate limiting and quotas cap each consumer's volume, while circuit breakers stop cascading overload from reaching core banking. Together they directly contain the blast radius of a single misbehaving partner, which is exactly the risk described.

  • ✗

    Encrypt account balance responses with a format-preserving encryption scheme before returning them.

    Why it's wrong here

    Response encryption protects confidentiality of balance data but has no effect on request volume or resource consumption. The risk in the scenario concerns availability and capacity rather than disclosure, so this control does not reduce the chance that excessive partner traffic degrades service for others.

  • ✗

    Require all partners to sign a service level agreement specifying maximum transaction volumes.

    Why it's wrong here

    A contractual volume cap sets expectations but does not technically prevent a partner from exceeding it, whether through error or malicious intent. Without an enforcement mechanism at the gateway, the core systems remain exposed to actual traffic, so the agreement alone does not mitigate the operational risk described.

  • ✗

    Enforce mutual TLS between partners and the API gateway for all balance requests.

    Why it's wrong here

    Mutual TLS authenticates partners and protects data in transit, which addresses spoofing and interception rather than volume-driven degradation. A fully authenticated partner can still flood the gateway, so this control does not prevent one consumer from overwhelming shared services and is not the most appropriate response.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.