Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is conducting a risk assessment for a new mobile application that will process credit card payments. The practitioner needs to identify relevant threats. Which of the following is the MOST appropriate source for identifying threats specific to this application?

⚠ Common exam trap

The trap here is selecting internal documents like audit findings or vendor lists, which are not threat sources, instead of external threat intelligence that is specific to the technology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A threat intelligence feed that includes mobile and payment card threats

Threat intelligence feeds are designed to provide up-to-date information on threats relevant to specific technologies and industries. For a mobile payment app, a feed covering mobile and payment card threats will identify threat actors, attack vectors, and emerging TTPs. This enables the risk practitioner to build a realistic threat landscape. Other sources like audit findings or continuity plans are secondary and do not offer the same breadth or currency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The business continuity plan for the payment processing system

    Why it's wrong here

    A business continuity plan focuses on recovery and resilience, not threat identification. It may mention risks like outages, but it does not provide detailed threat intelligence on malicious actors or attack methods. Using it as a primary source would miss many relevant cyber threats, so it is not the most appropriate choice.

  • ✗

    The IT department's list of approved software vendors

    Why it's wrong here

    A list of approved vendors is a control inventory, not a threat source. It does not describe how attackers might target the mobile app. While supply chain threats exist, the approved vendor list alone does not identify specific threats like injection attacks or insecure data storage. It is not an appropriate source for threat identification.

  • ✓

    A threat intelligence feed that includes mobile and payment card threats

    Why this is correct

    Threat intelligence feeds provide current, relevant information about threat actors, tactics, techniques, and procedures (TTPs) targeting mobile payment systems. This is the most appropriate source because it is specific to the technology and industry, enabling the practitioner to identify threats such as credential stuffing, mobile malware, and API abuse. It directly supports the identification of threats for this application.

  • ✗

    The organization's previous audit findings for other applications

    Why it's wrong here

    Previous audit findings can reveal recurring control weaknesses, but they are not a comprehensive source of threats specific to a new mobile payment app. They may not cover emerging threats like mobile-specific malware or API attacks. While useful as a secondary input, they are not the most appropriate primary source for threat identification in this context.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.