Courseiva
IT Risk Identification →mediumMultiple Select

CRISC IT Risk Identification Practice Question

A risk practitioner is identifying risks associated with a new cloud-based customer relationship management (CRM) system. The organization has concerns about data leakage and service availability. Which TWO of the following are examples of vulnerabilities that could lead to these risks? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse threats with vulnerabilities, such as treating a hacktivist group's intentions as a vulnerability, or treating a contractual gap as a technical weakness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CRM system lacks encryption for data at rest.

Vulnerabilities are weaknesses that can be exploited by threats. The lack of encryption for data at rest is a technical vulnerability that could lead to data leakage. The data center's location in a hurricane-prone region is an environmental vulnerability that could lead to service unavailability. The other options are threats, governance statements, or contractual issues, not vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The CRM system lacks encryption for data at rest.

    Why this is correct

    Lack of encryption for data at rest is a technical vulnerability that could lead to data leakage if the storage is compromised. It is a weakness in the system's design or configuration. This directly relates to the risk of unauthorized disclosure of customer data. Therefore, it is a valid vulnerability that the risk practitioner should identify.

  • ✗

    A hacktivist group has announced intentions to target cloud providers.

    Why it's wrong here

    A hacktivist group's intentions represent a threat, not a vulnerability. A threat is a potential cause of harm, while a vulnerability is a weakness. While this threat could exploit vulnerabilities, it is not itself a vulnerability. The practitioner should record it as a threat in the risk scenario, not as a vulnerability.

  • ✓

    The cloud provider's data center is located in a region prone to hurricanes.

    Why this is correct

    A geographic location prone to hurricanes is a vulnerability because it increases the likelihood of service disruption. This is an environmental vulnerability that could lead to availability risk. It is a weakness in the sense that the provider's physical infrastructure is exposed to natural disasters, and without redundancy, the CRM service could become unavailable. This is a valid vulnerability example.

  • ✗

    The organization's risk appetite statement allows for moderate downtime.

    Why it's wrong here

    A risk appetite statement is a governance artifact that defines acceptable risk levels. It is not a vulnerability; it does not represent a weakness that can be exploited. It influences risk treatment decisions but does not cause risk. Therefore, it is not an example of a vulnerability.

  • ✗

    The cloud provider's service level agreement (SLA) does not include penalties for data breaches.

    Why it's wrong here

    An SLA without breach penalties is a contractual weakness, but it is not a vulnerability in the technical sense. It may increase the impact of a data breach by limiting recourse, but it does not directly cause the breach. In risk identification, vulnerabilities are typically technical or process weaknesses. This is more of a control gap or contractual issue, not a vulnerability that leads to data leakage or availability loss.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.