Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is identifying risks for a pharmaceutical company that shares clinical trial data with external research partners. The practitioner learns that partners access the data through a shared portal with role-based access, and that one partner recently terminated its agreement but retained portal credentials. Which of the following is the MOST significant risk identification finding?

⚠ Common exam trap

The trap here is gravitating toward broad design concerns or unstated control gaps instead of the specific, confirmed exposure described in the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Terminated partners retain valid portal credentials after their agreements end.

The strongest finding is the confirmed existence of valid credentials held by a partner whose agreement has ended. That is a concrete threat-to-asset path affecting sensitive clinical trial data, and it must be documented and assessed. General concerns about role design, data sharing, or unstated authentication gaps are either design questions or unsupported assumptions compared with this active exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Clinical trial data is shared with external research partners at all.

    Why it's wrong here

    Sharing data with research partners is a deliberate business decision that supports the company's mission. Treating the sharing itself as the risk ignores the actual control failure described. The risk arises from inadequate lifecycle management of partner access, not from the existence of the partnership model, which is governed by contracts and privacy agreements.

  • ✗

    The portal's role-based access model may not align with the principle of least privilege.

    Why it's wrong here

    Role-based access alignment is a legitimate concern, but it is a general design question rather than the specific exposure described. The scenario gives a concrete fact: a terminated partner still holds valid credentials. That condition represents an active access risk, making the broader least-privilege discussion secondary to the confirmed orphaned access.

  • ✓

    Terminated partners retain valid portal credentials after their agreements end.

    Why this is correct

    The confirmed fact that a former partner still holds working credentials is a concrete risk identification finding. It exposes clinical trial data to unauthorized access by an entity with no current contractual obligation. This orphaned access represents a real threat-to-asset path that must be documented, assessed, and remediated through timely deprovisioning controls.

  • ✗

    The portal does not enforce multi-factor authentication for partner logins.

    Why it's wrong here

    The scenario does not state that multi-factor authentication is absent, and inferring it introduces an assumption not supported by the facts. Even if it were absent, the confirmed orphaned credential is the more immediate finding because it represents a known, active path to sensitive data rather than a hypothetical control gap.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.