CRISC Information Technology and Security Practice Question
A risk manager at a retail bank is assessing risks introduced by a new open-source container orchestration platform. The platform will host internal APIs that process non-public customer information. Which TWO of the following are the MOST significant risks that should be prioritized in the risk register? (Choose two.)
⚠ Common exam trap
The trap here is focusing on governance or cost issues while overlooking that unpatched images and hard-coded secrets are the direct, high-impact threats to customer data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hard-coded secrets and API keys in container images or orchestration manifests.
Unpatched container images and hard-coded secrets directly threaten the confidentiality and integrity of non-public customer information. These risks are highly exploitable and can lead to data breaches, regulatory penalties, and reputational damage. Policy gaps, licensing costs, and community support delays are important but secondary; they do not represent immediate, high-impact threats to customer data in a banking context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hard-coded secrets and API keys in container images or orchestration manifests.
Why this is correct
Hard-coded secrets in images or manifests are easily exposed through image layers, source repositories, or runtime environment variables. In a banking context, exposed API keys could allow attackers to bypass authentication and access customer data. This risk is both highly likely and high impact, and it can be mitigated through secret management tools, image scanning, and secure coding practices, warranting priority in the risk register.
- ✗
The platform's community support model may delay resolution of non-security bugs.
Why it's wrong here
Community support delays can affect operational stability and availability, but they are less significant than direct threats to customer data confidentiality and integrity. Non-security bugs might cause outages or performance issues, yet the scenario emphasizes non-public customer information, making data breach risks more critical. This option is a secondary operational risk rather than a priority security risk for the register.
- ✗
Lack of a documented container orchestration policy and standards for secure configuration.
Why it's wrong here
While a missing policy is a governance weakness, it is a secondary or enabling risk rather than a direct technical threat. The absence of standards can lead to misconfigurations, but the immediate risk of unpatched images and misconfigured secrets is more significant to customer data protection. Policies are important for long-term risk management but do not by themselves cause a breach.
- ✗
Increased licensing costs due to the open-source platform's commercial support model.
Why it's wrong here
Licensing costs are a financial and operational concern, not a direct information security risk to customer data. While cost overruns can affect project viability, they do not threaten the confidentiality, integrity, or availability of non-public customer information. This risk would be managed in a financial or project risk register, not as a top IT security risk for the orchestration platform.
- ✓
Unpatched vulnerabilities in container images that could lead to unauthorized access to customer data.
Why this is correct
Container images often include outdated libraries and base images with known vulnerabilities. In a bank processing non-public customer information, an unpatched vulnerability could be exploited to gain unauthorized access, exfiltrate data, or move laterally. This risk is directly tied to the confidentiality and integrity of customer data, making it a top priority for the risk register and remediation through image scanning and patch management.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.