Courseiva

CRISC Information Technology and Security Practice Question

A risk practitioner is evaluating the organization's vulnerability management programme. The organization scans its internal network weekly, but the CIO is concerned that critical internet-facing services are not adequately covered. Which TWO of the following changes would MOST improve the identification of exploitable vulnerabilities on externally exposed assets? (Choose two.)

⚠ Common exam trap

The trap here is assuming that more frequent internal scanning or a protective WAF identifies externally exposed vulnerabilities, when discovery and prioritization are the actual gaps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement continuous external attack surface scanning that includes discovery of unknown internet-facing assets.

Improving identification of exploitable vulnerabilities on internet-facing services requires seeing the full external attack surface and knowing which findings matter. Continuous external attack surface scanning discovers and inventories exposed assets, including unknown ones, while threat intelligence correlation prioritizes vulnerabilities that attackers are actively exploiting, focusing remediation where it reduces real risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require business units to self-attest quarterly that their internet-facing applications have no known vulnerabilities.

    Why it's wrong here

    Self-attestation is an unreliable detection method because it depends on the business unit's knowledge and honesty and provides no technical verification. It cannot discover unknown or forgotten assets, and it does not produce the evidence needed to confirm whether exploitable vulnerabilities actually exist on externally exposed services.

  • ✓

    Implement continuous external attack surface scanning that includes discovery of unknown internet-facing assets.

    Why this is correct

    Continuous external scanning detects exposed services and previously unknown assets, such as shadow IT or forgotten cloud instances, that a weekly internal scan would miss. Because attackers target exactly these externally reachable services, identifying and inventorying them is a prerequisite to assessing and remediating exploitable vulnerabilities on the true external attack surface.

  • ✓

    Correlate vulnerability scan results with threat intelligence feeds to prioritize vulnerabilities known to be actively exploited.

    Why this is correct

    Threat intelligence correlation identifies which vulnerabilities are being exploited in the wild, allowing the organization to prioritize remediation of the externally exposed issues that matter most. Combined with external attack surface discovery, this focuses limited remediation effort on exploitable, internet-reachable weaknesses rather than on the full volume of scan findings.

  • ✗

    Deploy a web application firewall (WAF) in front of all internet-facing applications and enable blocking mode.

    Why it's wrong here

    A WAF mitigates exploitation attempts against known application-layer attack patterns, but it does not discover or inventory exposed assets and does not identify vulnerabilities in the underlying services. It is a protective control, not a detection or identification control, so it does not improve the programme's ability to find exploitable vulnerabilities on externally exposed assets.

  • ✗

    Increase the frequency of credentialed internal vulnerability scans from weekly to daily.

    Why it's wrong here

    Credentialed internal scans provide deep visibility into hosts on the internal network, but they do not see internet-facing services hosted outside that network scope, such as cloud load balancers or vendor-managed endpoints. Increasing their frequency improves internal coverage but does not close the identified gap in external exposure, so it is not the most effective change here.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.