Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner at a regional hospital is building a risk register and needs to classify each identified risk by its source. During interviews, staff describe a recurring situation: a radiology scheduling application has no automated account deprovisioning, so terminated employees retain access for weeks until a supervisor manually reports them. Which risk identification category BEST describes this finding?

⚠ Common exam trap

The trap here is assuming that because a terminated employee could cause harm, the finding must be classified as a threat event rather than as the underlying weakness itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A vulnerability, because the absence of automated deprovisioning is a weakness that an actor could exploit.

The missing automated deprovisioning capability is a weakness in an IT process that a threat source could exploit, which by definition is a vulnerability. Identifying it as such allows the risk practitioner to link it to relevant threat sources, assess likelihood and impact, and drive remediation such as automated identity lifecycle management. Threat events describe occurrences, appetite statements describe tolerance, and control objectives describe desired outcomes, none of which match the observed condition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A threat event, because terminated employees could intentionally misuse their retained access.

    Why it's wrong here

    A threat event describes an actual or potential occurrence that can exploit a weakness, such as an insider misusing credentials. Here the described condition is the missing automated deprovisioning process itself, which is a structural weakness, not the occurrence. Recording it as a threat event would misdirect remediation toward monitoring employee behavior instead of fixing the provisioning control gap that exists regardless of anyone's intent.

  • ✓

    A vulnerability, because the absence of automated deprovisioning is a weakness that an actor could exploit.

    Why this is correct

    A vulnerability is a weakness in a process, system, or control that a threat source can exploit. The lack of automated account deprovisioning for the radiology scheduling application is precisely such a weakness: it exists independently of any attacker and persists until the process is corrected. Classifying it correctly drives remediation toward implementing automated lifecycle management rather than toward monitoring or accepting the residual exposure.

  • ✗

    A control objective, because the hospital should define a target for account removal timing.

    Why it's wrong here

    A control objective states the desired outcome a control should achieve, such as removing access within twenty-four hours of termination. While such an objective may eventually be written, the interview finding itself is the weakness, not the objective. Classifying the finding as a control objective would confuse the target state with the observed deficiency and delay proper risk treatment.

  • ✗

    A risk appetite statement, because the hospital has implicitly accepted delayed deprovisioning.

    Why it's wrong here

    Risk appetite is a board-level declaration of how much risk the organization is willing to pursue or retain, not a finding discovered during interviews. Nothing in the scenario indicates the hospital formally decided to tolerate delayed deprovisioning; the gap appears to be an oversight. Treating an operational gap as an appetite decision would bypass the risk assessment process and leave the underlying access control weakness unaddressed.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.