easyMultiple Choice
CRISC Practice Question: Identifying risks associated with a new…
A company is identifying risks associated with a new cloud-based CRM. Which of the following is the MOST effective method for identifying potential threats?
⚠ Common exam trap
A common mix-up: candidates choose penetration testing (Option C) because it is a familiar technical activity, but the question asks for the 'most effective method for identifying potential threats' in a new system, where proactive collaboration (threat modeling) outperforms reactive testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat modeling workshops with stakeholders
Threat modeling workshops with stakeholders are the most effective method because they leverage diverse expertise to systematically identify threats specific to the cloud-based CRM architecture, including misconfigurations in IAM roles, API vulnerabilities, and data residency issues. This collaborative approach aligns with the CRISC focus on proactive risk identification by considering business context, technical constraints, and regulatory requirements early in the lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Threat modeling workshops with stakeholders
Why this is correct
Threat modelling workshops systematically enumerate threats against the CRM's architecture, data flows and trust boundaries, drawing on stakeholder knowledge of misuse cases and attack surfaces. This structured decomposition surfaces cloud-specific risks such as tenant isolation and API exposure that generic checklists or vulnerability scans would miss.
- ✗
Reviewing industry standards only
Why it's wrong here
Industry standards give a baseline control set, not organisation-specific threats for this CRM deployment. It is tempting as a structured starting point; standards would support control selection, whereas threat identification needs tailored assessment of the actual environment.
- ✗
Conducting penetration testing alone
Why it's wrong here
Penetration testing validates exploitable weaknesses in deployed systems; it does not enumerate threats during design-stage risk identification. It is tempting because it produces concrete findings, but it would be correct later, for validating controls rather than identifying threats.
- ✗
Analyzing historical security incidents from similar organizations
Why it's wrong here
Historical incidents from other organisations reveal generic patterns, not this CRM's specific exposure. It is tempting because real breach data is concrete; however, it cannot account for the company's own architecture, data flows and configurations.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.