CRISC IT Risk Identification Practice Question
A risk practitioner is conducting a risk assessment for a new mobile application that will process credit card payments. The practitioner needs to identify relevant threats. Which of the following is the MOST appropriate source for identifying threats specific to this application?
⚠ Common exam trap
The trap here is selecting internal documents like audit findings or vendor lists, which are not threat sources, instead of external threat intelligence that is specific to the technology.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A threat intelligence feed that includes mobile and payment card threats
Threat intelligence feeds are designed to provide up-to-date information on threats relevant to specific technologies and industries. For a mobile payment app, a feed covering mobile and payment card threats will identify threat actors, attack vectors, and emerging TTPs. This enables the risk practitioner to build a realistic threat landscape. Other sources like audit findings or continuity plans are secondary and do not offer the same breadth or currency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The business continuity plan for the payment processing system
Why it's wrong here
A business continuity plan focuses on recovery and resilience, not threat identification. It may mention risks like outages, but it does not provide detailed threat intelligence on malicious actors or attack methods. Using it as a primary source would miss many relevant cyber threats, so it is not the most appropriate choice.
- ✗
The IT department's list of approved software vendors
Why it's wrong here
A list of approved vendors is a control inventory, not a threat source. It does not describe how attackers might target the mobile app. While supply chain threats exist, the approved vendor list alone does not identify specific threats like injection attacks or insecure data storage. It is not an appropriate source for threat identification.
- ✓
A threat intelligence feed that includes mobile and payment card threats
Why this is correct
Threat intelligence feeds provide current, relevant information about threat actors, tactics, techniques, and procedures (TTPs) targeting mobile payment systems. This is the most appropriate source because it is specific to the technology and industry, enabling the practitioner to identify threats such as credential stuffing, mobile malware, and API abuse. It directly supports the identification of threats for this application.
- ✗
The organization's previous audit findings for other applications
Why it's wrong here
Previous audit findings can reveal recurring control weaknesses, but they are not a comprehensive source of threats specific to a new mobile payment app. They may not cover emerging threats like mobile-specific malware or API attacks. While useful as a secondary input, they are not the most appropriate primary source for threat identification in this context.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.