Courseiva
easyMultiple Select

CRISC API Gateway Security Practice Question

A risk practitioner is identifying risks related to a new API gateway implementation. Which TWO of the following are MOST likely to be significant risks?

⚠ Common exam trap

Watch out — candidates often confuse operational risks (scalability, cost) with security risks, or they incorrectly assume that outdated programming languages are a direct risk to the API gateway itself, when in fact the gateway abstracts away language-specific vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Insufficient logging of API requests.

Option A is correct because an API gateway is a central enforcement and audit point, and insufficient logging of API requests removes the visibility needed to detect abuse, trace incidents, and meet monitoring/compliance requirements, making it a significant risk. Option C is correct because insecure direct object references (IDOR) let an authenticated caller manipulate object identifiers to access resources or data belonging to other users, a common and high-impact API authorization flaw that a gateway implementation must address. The unmarked options are less significant here: lack of scalability (B) is primarily a performance/availability engineering concern rather than a core risk-identification finding, outdated programming language (D) is a generic technical-debt issue not specific to the API gateway scenario, and high licensing cost (E) is a financial/commercial consideration, not a security or operational risk of the gateway itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Insufficient logging of API requests.

    Why this is correct

    Insufficient API request logging removes the audit trail needed to detect abuse, trace data exfiltration and evidence compliance, directly undermining the gateway's monitoring and accountability controls. For a new API gateway exposing internal services, this gap is a significant risk because threats such as credential stuffing and injection attacks would go undetected, breaching CRISC's risk-identification expectations.

  • ✗

    Lack of scalability for peak loads.

    Why it's wrong here

    Scalability is a performance issue, not a primary security risk.

  • ✓

    Insecure direct object references (IDOR) allowing unauthorized data access.

    Why this is correct

    IDOR arises when the gateway exposes object references without enforcing authorisation checks, letting callers manipulate identifiers to reach other users' data. This directly threatens confidentiality and integrity at the API layer, making it a significant risk for a new gateway implementation.

  • ✗

    Use of outdated programming language.

    Why it's wrong here

    Language choice is indirect; more specific to implementation.

  • ✗

    High licensing cost.

    Why it's wrong here

    Cost is a financial concern, not a risk identification priority.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.