CRISC IT Risk Identification Practice Question
A risk practitioner is identifying risks for a pharmaceutical company that shares clinical trial data with external research partners. The practitioner learns that partners access the data through a shared portal with role-based access, and that one partner recently terminated its agreement but retained portal credentials. Which of the following is the MOST significant risk identification finding?
⚠ Common exam trap
The trap here is gravitating toward broad design concerns or unstated control gaps instead of the specific, confirmed exposure described in the scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Terminated partners retain valid portal credentials after their agreements end.
The strongest finding is the confirmed existence of valid credentials held by a partner whose agreement has ended. That is a concrete threat-to-asset path affecting sensitive clinical trial data, and it must be documented and assessed. General concerns about role design, data sharing, or unstated authentication gaps are either design questions or unsupported assumptions compared with this active exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Clinical trial data is shared with external research partners at all.
Why it's wrong here
Sharing data with research partners is a deliberate business decision that supports the company's mission. Treating the sharing itself as the risk ignores the actual control failure described. The risk arises from inadequate lifecycle management of partner access, not from the existence of the partnership model, which is governed by contracts and privacy agreements.
- ✗
The portal's role-based access model may not align with the principle of least privilege.
Why it's wrong here
Role-based access alignment is a legitimate concern, but it is a general design question rather than the specific exposure described. The scenario gives a concrete fact: a terminated partner still holds valid credentials. That condition represents an active access risk, making the broader least-privilege discussion secondary to the confirmed orphaned access.
- ✓
Terminated partners retain valid portal credentials after their agreements end.
Why this is correct
The confirmed fact that a former partner still holds working credentials is a concrete risk identification finding. It exposes clinical trial data to unauthorized access by an entity with no current contractual obligation. This orphaned access represents a real threat-to-asset path that must be documented, assessed, and remediated through timely deprovisioning controls.
- ✗
The portal does not enforce multi-factor authentication for partner logins.
Why it's wrong here
The scenario does not state that multi-factor authentication is absent, and inferring it introduces an assumption not supported by the facts. Even if it were absent, the confirmed orphaned credential is the more immediate finding because it represents a known, active path to sensitive data rather than a hypothetical control gap.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.