hardMultiple Select
CRISC Practice Question: A company's IT risk team is conducting a risk…
A company's IT risk team is conducting a risk identification exercise for a new blockchain-based supply chain solution. Which THREE risks are MOST specific to this technology?
⚠ Common exam trap
ISACA often tests the distinction between generic IT risks and technology-specific risks, so candidates mistakenly select 'high electricity consumption' without considering that many blockchain implementations (especially in enterprise supply chains) do not use energy-intensive proof-of-work.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
51% attack on the underlying consensus mechanism.
Option A is correct because a 51% attack is a blockchain-specific risk in which an entity controlling a majority of consensus power (hashrate in PoW or stake in PoS) can rewrite transaction history or double-spend, directly threatening the integrity of the distributed ledger. Option D is correct because smart contracts execute automatically on-chain, so coding flaws such as reentrancy, integer overflow, or access-control bugs can cause irreversible unintended transactions and fund loss unique to programmable blockchain logic. Option E is correct because blockchain relies on asymmetric cryptography, and loss or compromise of private keys means irreversible loss of asset control, forged signatures, or unauthorized transactions, a risk intrinsic to decentralized key ownership. Option B is not specific to blockchain, since incompatibility with legacy database systems is a generic integration challenge faced by many new enterprise platforms. Option C is not the best fit because high electricity consumption applies mainly to proof-of-work mining and is an environmental/cost concern rather than a core risk unique to all blockchain supply chain solutions, especially permissioned or proof-of-stake networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
51% attack on the underlying consensus mechanism.
Why this is correct
A 51% attack occurs when a single entity controls majority hashing power, enabling transaction reversal or double-spending on the blockchain's consensus mechanism. This satisfies the stem's requirement by naming a risk specific to distributed ledger technology rather than generic IT.
- ✗
Incompatibility with legacy database systems.
Why it's wrong here
Legacy integration difficulty is generic to any new platform, not blockchain-specific. The technology's distinctive risks are key management, smart contract immutability, consensus governance and on-chain data confidentiality. It is tempting because integration work is genuinely required, but the stem asks for risks unique to this technology.
- ✗
High electricity consumption of mining nodes.
Why it's wrong here
Mining electricity consumption applies to proof-of-work public chains, not permissioned supply chain ledgers, which typically use consensus such as PBFT with no mining. It is tempting because cryptocurrency energy debates dominate blockchain coverage, but enterprise deployments rarely mine, so this risk does not transfer.
- ✓
Smart contract vulnerabilities leading to unintended execution.
Why this is correct
Smart contracts execute automatically on-chain once conditions are met, so coding flaws or reentrancy bugs cause irreversible, unintended transactions. This risk is inherent to blockchain's self-executing logic, satisfying the stem's demand for technology-specific risks rather than generic supply chain or IT concerns.
- ✓
Cryptographic key management failures.
Why this is correct
Blockchain relies on private keys to sign transactions and control assets; losing or leaking them compromises ownership irreversibly. This cryptographic dependency is unique to distributed ledger solutions, directly satisfying the stem's requirement for risks specific to the blockchain-based supply chain platform.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.