Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner at a regional bank is building a threat landscape for its new mobile payment platform. A recently published report from a national CERT indicates that a loosely organized group has been targeting payment APIs across the region, exploiting known authentication weaknesses. The practitioner wants to determine whether this group should be treated as a relevant threat source in the risk register. Which of the following is the MOST appropriate FIRST step?

⚠ Common exam trap

The trap here is treating external threat intelligence as a direct input to the risk register without first assessing the threat source against the organization's specific assets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess the group's capability, intent, and opportunity against the bank's specific mobile payment assets.

Threat sources become relevant only when evaluated against the organization's own assets through capability, intent, and opportunity. A CERT report signals activity in the sector, but the bank must determine whether the group can realistically reach and exploit its mobile payment APIs. That asset-centric analysis is the first step before the threat is entered into the risk register or any control is selected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately add the group to the risk register as a high-rated threat because it appears in a national CERT report.

    Why it's wrong here

    Adding a threat based solely on external reporting skips the assessment of whether the group actually targets the bank's specific assets or has the capability to exploit them. Threat intelligence must be contextualized to the organization's environment. Registering it as high without validation inflates the risk profile and misallocates resources to a threat that may not be relevant.

  • ✗

    Implement additional authentication controls on the mobile payment APIs to mitigate the reported weaknesses.

    Why it's wrong here

    Implementing controls is a risk response activity that belongs after the risk has been identified and evaluated. The scenario asks for the first step in determining whether the group is a relevant threat source, not for remediation. Acting on a general report without first establishing relevance could lead to unnecessary spending and does not fulfill the risk identification objective.

  • ✗

    Subscribe to additional commercial threat intelligence feeds to obtain more detail on the group's activities.

    Why it's wrong here

    More intelligence may enrich understanding, but the practitioner already has a credible government source. The gap is not data volume; it is the analysis of that data against the bank's own assets. Additional feeds without an asset-based relevance assessment add cost and noise rather than answering whether the group is a relevant threat source for this platform.

  • ✓

    Assess the group's capability, intent, and opportunity against the bank's specific mobile payment assets.

    Why this is correct

    Risk identification requires evaluating threat sources in terms of capability, intent, and opportunity relative to the organization's own assets. The CERT report establishes general activity, but relevance to the bank depends on whether the group can realistically reach and exploit the mobile payment APIs. This asset-centric assessment determines if the threat is material and warrants entry into the risk register.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.