CRISC Information Technology and Security Practice Question
A risk practitioner is assessing the risk associated with the organization's use of third-party APIs that integrate with its core banking platform. The practitioner needs to determine the MOST effective way to monitor the risk exposure of these APIs on an ongoing basis. Which of the following approaches BEST addresses this requirement?
⚠ Common exam trap
The trap here is assuming that periodic compliance reports or annual assessments provide sufficient ongoing risk monitoring, when they actually leave gaps between reviews.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement API gateway logging and monitor for anomalous behavior using predefined risk thresholds.
Continuous monitoring of third-party API risk requires real-time or near-real-time data. API gateway logging with anomaly detection and risk thresholds provides ongoing visibility into API usage and potential threats. Other options like annual assessments, monthly reports, or static scores are point-in-time or retrospective and do not meet the need for continuous monitoring of dynamic risk exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a static risk score assigned to each third-party API at onboarding.
Why it's wrong here
A static risk score does not change with evolving threats or operational changes, so it fails to provide ongoing monitoring. Risk exposure from third-party APIs is dynamic and can change due to provider updates, new vulnerabilities, or changes in usage patterns. A static score cannot capture these shifts, making it inadequate for continuous risk assessment.
- ✗
Conduct an annual security assessment of each third-party API provider.
Why it's wrong here
An annual assessment does not provide ongoing monitoring and may miss changes in the API provider's security posture that occur between assessments. The scenario requires continuous risk exposure monitoring, so a point-in-time annual review is insufficient. While periodic assessments are valuable, they do not meet the need for real-time or near-real-time visibility into API risk.
- ✓
Implement API gateway logging and monitor for anomalous behavior using predefined risk thresholds.
Why this is correct
API gateway logging captures all API calls and responses, enabling continuous monitoring. By defining risk thresholds for anomalous behavior, the organization can detect deviations that indicate increased risk exposure. This approach provides ongoing, automated visibility into third-party API activity, aligning with the requirement for continuous risk monitoring and early warning of potential issues.
- ✗
Require third-party API providers to submit monthly compliance reports.
Why it's wrong here
Monthly compliance reports are retrospective and may not reflect real-time risk exposure. They also rely on the provider's self-reporting, which may be incomplete or delayed. While useful for contractual compliance, this approach does not provide the continuous monitoring needed to detect emerging risks such as API abuse, misconfigurations, or performance degradation.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.