CRISC IT Risk Identification Practice Question
A risk practitioner is estimating the likelihood of a ransomware event for a manufacturing firm. The firm has endpoint protection, network segmentation, and offline backups, but the practitioner learns that a third-party maintenance vendor has persistent remote access with shared credentials and no multi-factor authentication. Which of the following BEST explains how this finding should affect the likelihood estimate?
⚠ Common exam trap
The trap here is letting strong internal controls or backup availability dominate the likelihood judgment while overlooking a third-party access path that sidesteps those controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Likelihood should increase because the vendor access path provides an unmitigated entry point.
Likelihood reflects how probable an event is given the threat environment and existing controls. The vendor's shared credentials and lack of multi-factor authentication create a persistent, low-effort entry point that bypasses internal defenses, so it raises the probability of a successful ransomware intrusion. Backup availability and industry averages address recovery and context, not this specific exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Likelihood should be set to the industry average for manufacturing ransomware incidents.
Why it's wrong here
Benchmark averages are useful context but cannot replace organization-specific analysis. The practitioner has concrete evidence of an elevated exposure, so applying a generic industry rate would ignore the very condition being assessed. Risk estimates should reflect the firm's actual control environment and threat exposure, and deferring to an average would mask the added risk from the vendor connection.
- ✗
Likelihood should decrease because the firm's existing controls are strong.
Why it's wrong here
The firm's internal controls reduce risk from many vectors, but they do not neutralize a third-party access path that bypasses those controls. A shared-credential, non-MFA remote connection can be used to reach segmented networks and disable backups. Treating strong internal controls as sufficient ignores the specific exposure introduced by the vendor, so this estimate would understate likelihood.
- ✓
Likelihood should increase because the vendor access path provides an unmitigated entry point.
Why this is correct
Shared credentials without multi-factor authentication create a low-effort, persistent entry point that attackers commonly exploit in supply chain ransomware incidents. Because this path bypasses the firm's endpoint and segmentation controls, it materially raises the probability that an attacker can establish a foothold and escalate. The finding is a direct likelihood driver, so the estimate should rise to reflect the expanded attack surface.
- ✗
Likelihood should remain unchanged because backup availability determines ransomware outcomes.
Why it's wrong here
Backups affect impact and recoverability, not the probability that an intrusion occurs. Ransomware actors increasingly target backups first, so their presence does not guarantee quick recovery. Holding likelihood constant because backups exist confuses a recovery control with a preventive one and overlooks how the vendor access path increases the chance of initial compromise and lateral movement.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.