Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: A financial institution is integrating a new…

A financial institution is integrating a new cloud-based analytics platform that will process sensitive customer data. The project team is conducting risk identification. Which technique would be MOST effective for identifying risks related to the integration of this platform with existing on-premises systems?

⚠ Common exam trap

Many candidates choose vulnerability scanning (Option A) because they mistakenly believe that scanning API endpoints is sufficient for integration risk identification, but vulnerability scanning only finds known flaws in the API code, not architectural threats like insecure data flows or trust boundary violations that threat modeling uniquely addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Threat modeling of the integration architecture.

Threat modeling of the integration architecture is the most effective technique because it systematically identifies potential security threats, attack vectors, and vulnerabilities specific to the data flows, trust boundaries, and API interactions between the cloud-based analytics platform and existing on-premises systems. Unlike generic methods, threat modeling (e.g., STRIDE or PASTA) focuses on the unique integration points, such as authentication handshakes, data-in-transit encryption (TLS 1.2/1.3), and session management, which are critical for protecting sensitive customer data during integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vulnerability scanning of the cloud platform's API endpoints.

    Why it's wrong here

    Scanning identifies existing vulnerabilities but not design flaws in integration.

  • Brainstorming sessions with the project team.

    Why it's wrong here

    Brainstorming is useful but may not systematically cover all integration risks.

  • Threat modeling of the integration architecture.

    Why this is correct

    Threat modeling systematically identifies threats to the integration points, such as data flow, trust boundaries, and authentication.

  • SWOT analysis to assess strengths, weaknesses, opportunities, and threats.

    Why it's wrong here

    SWOT is strategic, not technical, and may not capture integration-specific risks.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.