CRISC IT Risk Identification Practice Question
A risk practitioner is analyzing the risk of insider threat in a software development company. The practitioner wants to assess the likelihood of a developer exfiltrating source code. Which of the following factors would MOST directly increase the likelihood of this risk?
⚠ Common exam trap
The trap here is selecting indirect organizational factors, such as turnover or training frequency, instead of the direct enabler of opportunity that privileged access provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The developer has elevated access privileges to the source code repository.
The likelihood of an insider threat depends on motivation, opportunity, and capability. Elevated access privileges provide the opportunity for a developer to exfiltrate source code, making it the most direct factor increasing likelihood. Other factors like turnover or training frequency may influence the environment but do not directly enable the theft. Access control is therefore a critical control point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The developer has elevated access privileges to the source code repository.
Why this is correct
Elevated access privileges directly increase the opportunity for a developer to exfiltrate source code. Even if motivation exists, without access the threat cannot be realized. In insider threat analysis, opportunity is a key likelihood factor, and privileged access is a common enabler. This makes it the most direct factor increasing likelihood in this scenario.
- ✗
The company's security awareness training is conducted annually.
Why it's wrong here
Annual training may be less effective than more frequent training, but it does not directly increase the likelihood of a malicious insider exfiltrating code. Awareness training primarily addresses accidental errors, not deliberate theft. A determined insider is not deterred by training frequency, so this factor has limited direct impact on likelihood.
- ✗
The company has a high turnover rate among developers.
Why it's wrong here
High turnover may increase disgruntlement or create gaps in oversight, but it does not directly enable exfiltration. It is an indirect factor that could influence motivation or control effectiveness. Without access or intent, turnover alone does not materially increase the likelihood of source code theft, so it is less direct than privileged access.
- ✗
The source code repository is hosted in a third-party cloud environment.
Why it's wrong here
Cloud hosting may introduce different risks, such as misconfiguration or provider breaches, but it does not directly increase the likelihood of an insider exfiltrating code. The insider's ability to access and remove code depends on their permissions and monitoring, not on where the repository is hosted. Thus, this factor is less directly relevant.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.