Courseiva

CRISC Information Technology and Security Practice Question

A risk practitioner is assessing the security of a new software-defined wide area network (SD-WAN) deployment that will carry regulated traffic between branch offices and a cloud environment. The vendor's controller is managed by a third party. Which of the following risks should the practitioner identify as the MOST significant?

⚠ Common exam trap

The trap here is focusing on endpoint or operational issues while overlooking that the centralized controller, especially when third-party managed, is the most consequential single point of failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SD-WAN controller could be compromised through the third-party management interface, allowing policy manipulation and traffic redirection.

In SD-WAN architectures, the controller is a high-value target because it defines and enforces forwarding, segmentation, and encryption policies across all sites. When that controller is managed by a third party, the organization inherits supply-chain and access-control risk. A compromise there can bypass many perimeter defenses and affect every branch simultaneously, so it warrants the greatest attention in a risk assessment of regulated traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SD-WAN controller could be compromised through the third-party management interface, allowing policy manipulation and traffic redirection.

    Why this is correct

    The SD-WAN controller is the central policy and orchestration point; if an attacker gains control through the third-party management plane, they can alter routing, disable encryption, or redirect regulated traffic. This represents a high-impact, high-likelihood risk given the external dependency. It directly threatens confidentiality and integrity of regulated data, making it the most significant risk.

  • ✗

    Branch office staff may bypass the SD-WAN by using personal mobile hotspots for internet access.

    Why it's wrong here

    Policy bypass is a real concern, but it is typically mitigated by endpoint controls and acceptable-use policies. It does not grant an attacker centralized control over the entire network fabric. The impact is localized and less severe than compromise of the orchestration plane that governs all sites.

  • ✗

    The organization may lose visibility into application performance across the SD-WAN fabric.

    Why it's wrong here

    Reduced visibility affects troubleshooting and service-level management, not the security of regulated data. While monitoring is important, it is an operational risk with limited confidentiality or integrity impact. It is less significant than a compromise that could redirect or expose traffic.

  • ✗

    SD-WAN appliances may not support the organization's existing network access control (NAC) solution.

    Why it's wrong here

    Integration gaps can create operational and compliance challenges, but they are usually resolvable through configuration or vendor updates. They do not inherently expose regulated traffic to interception or manipulation. This is a compatibility risk rather than a direct threat to data confidentiality and integrity.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.