Courseiva
mediumMultiple Choice

CRISC Practice Question: A large retailer is implementing a new…

A large retailer is implementing a new point-of-sale (POS) system. The project manager wants to identify risks related to payment card data security. Which risk identification technique would be MOST effective for this purpose?

⚠ Common exam trap

A common mix-up: candidates choose 'Brainstorming session with the project team' because it seems collaborative and proactive, but they fail to recognize that for technical data security risks, a structured, visual analysis like a DFD review is far more precise and complete.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Flow Diagram (DFD) review

A Data Flow Diagram (DFD) review is most effective because it visually maps how payment card data moves through the POS system—from card swipe to authorization to storage—identifying exactly where data is at rest, in transit, or processed. This allows the team to pinpoint specific PCI DSS control gaps (e.g., unencrypted transmission, unnecessary retention) that other techniques might miss.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk register review from past projects

    Why it's wrong here

    A past-project register captures risks from comparable POS deployments, but it cannot surface threats specific to this system's card-data flows, acquirer interfaces or PCI DSS scope. It is tempting because registers are a standard CRISC input, and would be correct when historical projects share the same architecture and threat landscape.

  • ✗

    Brainstorming session with the project team

    Why it's wrong here

    Brainstorming with the project team draws on internal assumptions and misses external payment card attack vectors, so it cannot systematically surface cardholder data risks. It is tempting because it is quick and collaborative, and would be correct when exploring novel or poorly understood risks where no structured reference framework exists.

  • ✓

    Data Flow Diagram (DFD) review

    Why this is correct

    A data flow diagram review maps where cardholder data enters, moves through, and leaves the POS system, exposing interception and storage points. This satisfies the payment card data security focus by revealing risks tied to actual data movement rather than generic threat lists.

  • ✗

    SWOT analysis

    Why it's wrong here

    SWOT analysis examines internal strengths and weaknesses against external opportunities and threats at organisational strategy level, not cardholder data flows through POS components. It is tempting because it is a recognised risk technique, and would be correct when assessing overall business strategy rather than payment card data security in a specific system.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.