Courseiva

CRISC Information Technology and Security Practice Question

A risk manager is evaluating the security of a new API gateway that will expose internal microservices to external partners. The gateway will handle authentication, rate limiting, and request routing. Which risk is MOST critical to address before go-live?

⚠ Common exam trap

The trap here is prioritizing availability or detective controls, such as rate limiting or logging, over the preventive control that stops unauthorized access to microservices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Weak authentication and authorization mechanisms that could allow partners to access unauthorized microservices.

The API gateway is the security boundary for external partners. Weak authentication and authorization could allow unauthorized access to internal microservices, directly threatening data confidentiality and integrity. While logging, rate limiting, and internal TLS are important, they are secondary to ensuring that only authorized entities can reach the appropriate services. Addressing authentication and authorization first prevents the most severe impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Weak authentication and authorization mechanisms that could allow partners to access unauthorized microservices.

    Why this is correct

    The API gateway is the entry point to internal microservices. If authentication or authorization is weak, a partner or attacker could bypass controls and reach services they should not access, leading to data exposure or system compromise. This is a preventive control gap with direct impact on confidentiality and integrity, making it the most critical risk to address before exposing the gateway externally.

  • ✗

    Insufficient logging of API requests, which could hinder forensic investigations.

    Why it's wrong here

    Logging is important for detection and response, but it is a detective control. Without proper authentication and authorization, an attacker could access internal microservices directly, causing a breach that logging would only record after the fact. While logging gaps are a risk, they are less critical than preventive controls that stop unauthorized access in the first place.

  • ✗

    Inadequate rate limiting that could allow denial-of-service attacks.

    Why it's wrong here

    Rate limiting protects availability, but it does not prevent unauthorized access to microservices. A denial-of-service attack may cause disruption, but a breach of authentication could lead to data theft or lateral movement, which is typically more severe. Rate limiting is important, yet it is secondary to ensuring that only authorized partners can access the appropriate services.

  • ✗

    Lack of TLS encryption for internal traffic between the gateway and microservices.

    Why it's wrong here

    Encrypting internal traffic is a good defense-in-depth measure, but it assumes the request is already authorized. If authentication is weak, an attacker could still access microservices even with encryption. The most critical risk is unauthorized access, which encryption alone does not prevent. TLS protects data in transit, but it does not enforce who can access what.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.