Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

A hospital's risk practitioner is identifying risks for a new telehealth platform. The IT director asks which source would be MOST useful for identifying vulnerabilities specific to the platform's underlying commercial software components. Which of the following should the practitioner use?

⚠ Common exam trap

The trap here is choosing an internal document that sounds security-related, such as postmortems, when the question asks specifically about identifying vulnerabilities in commercial software components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Common Vulnerabilities and Exposures (CVE) database.

CVE is the standard reference catalog for publicly known vulnerabilities in commercial and open-source products, making it the most direct source for identifying weaknesses in the telehealth platform's software components. The other sources address incidents, business impact, or service performance rather than the technical vulnerabilities present in the commercial software itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A business impact analysis (BIA) questionnaire.

    Why it's wrong here

    A BIA collects information about process criticality, recovery objectives, and dependencies, not technical weaknesses in software. It answers how much an outage would hurt, not what vulnerabilities exist in the platform's components. Using a BIA as a vulnerability source confuses impact analysis with vulnerability identification, and it would not surface specific CVE entries for the commercial software in use.

  • ✗

    The IT balanced scorecard and service level reports.

    Why it's wrong here

    A balanced scorecard and SLA reports measure performance, availability, and service delivery against targets. They can reveal operational weaknesses such as recurring outages, but they do not enumerate software vulnerabilities. For identifying specific weaknesses in commercial components, these management reporting tools lack the technical granularity and the external vulnerability data that a CVE search provides.

  • ✓

    The Common Vulnerabilities and Exposures (CVE) database.

    Why this is correct

    CVE is a publicly maintained catalog of known vulnerabilities in commercial and open-source software, each with a unique identifier. Because the telehealth platform relies on commercial components, searching CVE entries for those products surfaces specific, documented weaknesses that can feed the risk register. It directly addresses vulnerability identification for known software, which is exactly the task described.

  • ✗

    The organization's incident response postmortem reports.

    Why it's wrong here

    Postmortems describe incidents that already occurred at this organization, so they identify exploited weaknesses rather than the broad set of vulnerabilities present in commercial components. For a newly deployed telehealth platform, there may be no relevant history at all. While postmortems are valuable for control improvement, they are not the primary source for cataloging software vulnerabilities in third-party products.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.