Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A national retail chain is building a risk register for its new e-commerce platform. The CISO asks the risk practitioner to identify the inherent risk associated with a recently disclosed SQL injection vulnerability in a third-party payment gateway module. Which of the following BEST describes inherent risk in this scenario?

⚠ Common exam trap

It's easy for candidates to confuse inherent risk with residual risk, especially when controls are mentioned in the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The risk that exists before any controls or mitigation efforts are applied to the SQL injection vulnerability in the payment gateway module.

Inherent risk is the level of risk before any controls or mitigation actions are applied. In the context of the SQL injection vulnerability, it represents the raw exposure that the organization faces if nothing is done. This baseline is essential for risk practitioners to prioritize risks and later evaluate the effectiveness of controls by comparing inherent and residual risk. The other options describe residual risk, vendor-specific risk, or risk appetite exceedance, none of which define inherent risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The risk that exists before any controls or mitigation efforts are applied to the SQL injection vulnerability in the payment gateway module.

    Why this is correct

    Inherent risk is the raw risk exposure before controls are considered. For the SQL injection vulnerability, this means the potential impact and likelihood assuming no compensating controls exist. This baseline helps the risk practitioner prioritize and later measure the effectiveness of controls. The scenario specifically asks for inherent risk, making this the correct characterization.

  • ✗

    The risk that the third-party payment gateway vendor will fail to patch the SQL injection vulnerability within the agreed service level agreement.

    Why it's wrong here

    This describes a specific vendor management or third-party risk, not inherent risk. While vendor failure to patch is a risk, it is a subset of the overall risk picture and does not define inherent risk. Inherent risk is a broader concept that captures the exposure before controls, regardless of who owns the remediation. This option narrows the scope incorrectly.

  • ✗

    The risk that the organization's risk appetite statement will be exceeded due to the SQL injection vulnerability.

    Why it's wrong here

    This describes a risk appetite breach or tolerance exceedance, which is a comparison of risk to predefined thresholds. It is not the definition of inherent risk. Inherent risk is a measurement of exposure, not a statement about appetite. The scenario asks for the inherent risk itself, not whether it exceeds appetite. This option confuses risk measurement with risk governance.

  • ✗

    The level of risk that remains after the organization implements compensating controls such as a web application firewall and input validation.

    Why it's wrong here

    This describes residual risk, which is the risk remaining after controls are applied. Inherent risk is measured before considering any controls. The scenario asks about inherent risk, so describing the post-control state misidentifies the concept. A web application firewall and input validation would reduce the risk, but that reduction is not part of the inherent risk definition.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.