Courseiva
IT Risk Identification →mediumMultiple Select

CRISC IT Risk Identification Practice Question

A risk practitioner at a regional bank is compiling a list of internal threat sources for the enterprise risk assessment. Which TWO of the following are internal threat sources that should be included? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any actor who attacks the bank is an internal source, when internal classification depends on trusted access rather than on intent or target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A terminated employee who retained a VPN credential

Internal threat sources are actors who operate within or with trusted access to the organization, including current and former employees, contractors, and other insiders with authorized privileges. The terminated employee with a retained credential and the contractor with privileged platform access both meet that definition. Hacktivists, nation-state actors, and organized crime groups are external sources even when they target the bank.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A nation-state actor conducting espionage against financial regulators

    Why it's wrong here

    A nation-state actor is an external threat source with high capability and resources, typically motivated by geopolitical or economic espionage. It does not rely on trusted internal access to the bank, so it is categorized as external. Placing it among internal sources would misstate the control environment needed to address insider risk.

  • ✓

    A terminated employee who retained a VPN credential

    Why this is correct

    A former employee who still holds valid access is an internal threat source because the actor has or had trusted access to bank systems. Insider threats include malicious, negligent, and compromised insiders, and the terminated employee with a live credential fits the malicious or negligent insider category. This directly affects the likelihood assessment for unauthorized access scenarios.

  • ✓

    A contractor with privileged access to the core banking platform

    Why this is correct

    A contractor granted privileged access is treated as an internal threat source because the actor operates with trusted, authorized access inside the environment. Third parties with elevated rights can cause loss through error, omission, or misuse. The bank must include this source when assessing scenarios such as unauthorized transaction modification or data exfiltration.

  • ✗

    An organized crime group running ransomware campaigns

    Why it's wrong here

    An organized crime group is an external threat source driven by financial gain, operating from outside the bank's trust boundary. Although it may use insiders or social engineering, the group itself is external. Listing it as internal would confuse the origin of the threat with the vector it might exploit and distort the insider risk picture.

  • ✗

    A hacktivist group targeting the bank's public website

    Why it's wrong here

    A hacktivist group is an external threat source motivated by ideology and operating outside the organization. It may target the bank, but it does not have trusted internal access, so it belongs in the external threat landscape rather than the internal source list. Including it would misclassify the source and skew the likelihood estimate for insider-related scenarios.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.