Courseiva
hardMultiple Select

CRISC Practice Question: A company's IT risk team is conducting a risk…

A company's IT risk team is conducting a risk identification exercise for a new blockchain-based supply chain solution. Which THREE risks are MOST specific to this technology?

⚠ Common exam trap

ISACA often tests the distinction between generic IT risks and technology-specific risks, so candidates mistakenly select 'high electricity consumption' without considering that many blockchain implementations (especially in enterprise supply chains) do not use energy-intensive proof-of-work.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

51% attack on the underlying consensus mechanism.

Option A is correct because a 51% attack is a blockchain-specific risk in which an entity controlling a majority of consensus power (hashrate in PoW or stake in PoS) can rewrite transaction history or double-spend, directly threatening the integrity of the distributed ledger. Option D is correct because smart contracts execute automatically on-chain, so coding flaws such as reentrancy, integer overflow, or access-control bugs can cause irreversible unintended transactions and fund loss unique to programmable blockchain logic. Option E is correct because blockchain relies on asymmetric cryptography, and loss or compromise of private keys means irreversible loss of asset control, forged signatures, or unauthorized transactions, a risk intrinsic to decentralized key ownership. Option B is not specific to blockchain, since incompatibility with legacy database systems is a generic integration challenge faced by many new enterprise platforms. Option C is not the best fit because high electricity consumption applies mainly to proof-of-work mining and is an environmental/cost concern rather than a core risk unique to all blockchain supply chain solutions, especially permissioned or proof-of-stake networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    51% attack on the underlying consensus mechanism.

    Why this is correct

    A 51% attack occurs when a single entity controls majority hashing power, enabling transaction reversal or double-spending on the blockchain's consensus mechanism. This satisfies the stem's requirement by naming a risk specific to distributed ledger technology rather than generic IT.

  • ✗

    Incompatibility with legacy database systems.

    Why it's wrong here

    Legacy integration difficulty is generic to any new platform, not blockchain-specific. The technology's distinctive risks are key management, smart contract immutability, consensus governance and on-chain data confidentiality. It is tempting because integration work is genuinely required, but the stem asks for risks unique to this technology.

  • ✗

    High electricity consumption of mining nodes.

    Why it's wrong here

    Mining electricity consumption applies to proof-of-work public chains, not permissioned supply chain ledgers, which typically use consensus such as PBFT with no mining. It is tempting because cryptocurrency energy debates dominate blockchain coverage, but enterprise deployments rarely mine, so this risk does not transfer.

  • ✓

    Smart contract vulnerabilities leading to unintended execution.

    Why this is correct

    Smart contracts execute automatically on-chain once conditions are met, so coding flaws or reentrancy bugs cause irreversible, unintended transactions. This risk is inherent to blockchain's self-executing logic, satisfying the stem's demand for technology-specific risks rather than generic supply chain or IT concerns.

  • ✓

    Cryptographic key management failures.

    Why this is correct

    Blockchain relies on private keys to sign transactions and control assets; losing or leaking them compromises ownership irreversibly. This cryptographic dependency is unique to distributed ledger solutions, directly satisfying the stem's requirement for risks specific to the blockchain-based supply chain platform.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.