CRISC IT Risk Identification Practice Question
A risk practitioner at a regional bank is building a threat landscape for its new mobile payment platform. A recently published report from a national CERT indicates that a loosely organized group has been targeting payment APIs across the region, exploiting known authentication weaknesses. The practitioner wants to determine whether this group should be treated as a relevant threat source in the risk register. Which of the following is the MOST appropriate FIRST step?
⚠ Common exam trap
The trap here is treating external threat intelligence as a direct input to the risk register without first assessing the threat source against the organization's specific assets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assess the group's capability, intent, and opportunity against the bank's specific mobile payment assets.
Threat sources become relevant only when evaluated against the organization's own assets through capability, intent, and opportunity. A CERT report signals activity in the sector, but the bank must determine whether the group can realistically reach and exploit its mobile payment APIs. That asset-centric analysis is the first step before the threat is entered into the risk register or any control is selected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately add the group to the risk register as a high-rated threat because it appears in a national CERT report.
Why it's wrong here
Adding a threat based solely on external reporting skips the assessment of whether the group actually targets the bank's specific assets or has the capability to exploit them. Threat intelligence must be contextualized to the organization's environment. Registering it as high without validation inflates the risk profile and misallocates resources to a threat that may not be relevant.
- ✗
Implement additional authentication controls on the mobile payment APIs to mitigate the reported weaknesses.
Why it's wrong here
Implementing controls is a risk response activity that belongs after the risk has been identified and evaluated. The scenario asks for the first step in determining whether the group is a relevant threat source, not for remediation. Acting on a general report without first establishing relevance could lead to unnecessary spending and does not fulfill the risk identification objective.
- ✗
Subscribe to additional commercial threat intelligence feeds to obtain more detail on the group's activities.
Why it's wrong here
More intelligence may enrich understanding, but the practitioner already has a credible government source. The gap is not data volume; it is the analysis of that data against the bank's own assets. Additional feeds without an asset-based relevance assessment add cost and noise rather than answering whether the group is a relevant threat source for this platform.
- ✓
Assess the group's capability, intent, and opportunity against the bank's specific mobile payment assets.
Why this is correct
Risk identification requires evaluating threat sources in terms of capability, intent, and opportunity relative to the organization's own assets. The CERT report establishes general activity, but relevance to the bank depends on whether the group can realistically reach and exploit the mobile payment APIs. This asset-centric assessment determines if the threat is material and warrants entry into the risk register.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.