Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

A financial services firm is performing an IT risk assessment on a legacy trading platform. The risk team has identified several weaknesses in the platform's patch management process. Which TWO of the following are examples of vulnerabilities that should be recorded in the risk register? (Choose two.)

⚠ Common exam trap

The trap here is treating a threat source such as an announced attacker campaign as a vulnerability simply because both appear in the same risk discussion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch deployment requires manual approval by a single administrator.

Vulnerabilities are internal weaknesses in people, processes, or technology that a threat can exploit. An unsupported operating system and a manual single-administrator patch approval process both qualify because they exist inside the environment and degrade the firm's ability to prevent exploitation. The hacker announcement is a threat source, the revenue figure is business criticality, and the insurance exclusion is a risk financing condition, so none belong in the vulnerability field of the register.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firm's cyber insurance policy excludes losses from unpatched systems.

    Why it's wrong here

    An insurance exclusion is a contractual and financial transfer condition, not a technical or process weakness in the platform. It changes who bears the loss rather than whether a threat can exploit the system. Treating it as a vulnerability would confuse risk treatment and financing decisions, since the exclusion is relevant to residual risk acceptance and coverage review, not to the patch management weakness itself.

  • ✓

    Patch deployment requires manual approval by a single administrator.

    Why this is correct

    A manual, single-person approval bottleneck is a process vulnerability because it creates delay, human error, and a single point of failure in patch deployment. This weakness exists in the organization's procedures and can be exploited indirectly by attackers who rely on slow patching windows. Recording it enables the risk team to recommend automation, segregation of duties, and service-level targets for patch cycles.

  • ✗

    The trading platform processes approximately 40 percent of the firm's revenue.

    Why it's wrong here

    Revenue concentration describes business criticality or asset value, not a vulnerability. It informs impact severity and prioritization but does not represent a weakness that a threat could exploit. Recording criticality in the vulnerability field would distort the risk calculation, because criticality multiplies consequence while a vulnerability affects the probability that a threat event succeeds.

  • ✗

    A hacker collective has publicly announced targeting of trading firms.

    Why it's wrong here

    A hacker collective announcing targets describes a threat source, not a vulnerability. Threat sources are external actors or events with the potential to cause harm, and they are recorded separately in the risk statement. Confusing this announcement with a vulnerability would misdirect treatment toward patching when the appropriate response may involve threat intelligence, monitoring, or deterrence measures against the actor.

  • ✓

    The platform runs an operating system version no longer supported by the vendor.

    Why this is correct

    An unsupported operating system is a classic vulnerability because the vendor no longer issues security patches, leaving known flaws permanently unaddressed. This condition exists within the asset and can be exploited by a threat. Recording it in the risk register allows the risk team to assess exposure, prioritize remediation or compensating controls, and track the weakness until the platform is upgraded or isolated.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.