mediumMultiple Choice
CRISC Practice Question: A hospital uses a patient portal that allows…
A hospital uses a patient portal that allows patients to access their medical records. The portal has experienced multiple brute-force login attempts. The risk manager wants to identify the most critical risk scenario. Which of the following should be prioritized?
⚠ Common exam trap
The trap here is that candidates may focus on the immediate technical symptom (denial of service) rather than the primary business impact (unauthorized data access), which is the core of risk identification in CRISC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unauthorized access to patient medical records.
The most critical risk scenario from brute-force login attempts is unauthorized access to patient medical records, as this directly compromises patient privacy and violates HIPAA regulations. While denial of service is a concern, the primary impact of successful brute-force attacks is data breach, not service availability. The risk manager must prioritize the confidentiality of protected health information (PHI) over other operational risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Denial of service due to excessive login attempts.
Why it's wrong here
Brute-force attempts target credential guessing; lockout-driven denial of service is a secondary availability nuisance, not the exposure of medical records. Denial of service would be prioritised where uptime of a clinical or patient-facing service is the asset at risk.
- ✓
Unauthorized access to patient medical records.
Why this is correct
Brute-force attempts threaten credential compromise, and success grants access to patient medical records, causing privacy breach, regulatory penalties and clinical harm. This scenario carries the highest impact and likelihood, so it warrants prioritisation over lesser availability or nuisance risks.
- ✗
Insufficient encryption of data in transit.
Why it's wrong here
Brute-force attempts exploit authentication, not transport; encryption in transit is unaffected by repeated login failures. Insufficient transport encryption would be the priority where traffic is intercepted on the network path, such as unencrypted portal sessions over public Wi-Fi.
- ✗
Phishing attacks targeting portal users.
Why it's wrong here
Phishing deceives users into surrendering credentials, but the scenario describes automated brute-force attempts against the login endpoint, not user deception. Phishing would be prioritised where email is the primary attack vector and user awareness is the control gap.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.