CRISC IT Risk Identification Practice Question
A risk practitioner is performing an external threat environment analysis for a retail chain that accepts card payments. The practitioner wants to identify which external factors should be treated as inputs to the likelihood of payment card data compromise. Which TWO of the following are the MOST appropriate inputs? (Choose two.)
⚠ Common exam trap
The trap here is treating internal scale and control metrics as threat environment factors simply because they are easy to measure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The prevalence and activity level of organized criminal groups that monetize stolen card data.
External threat inputs describe conditions outside the organization's control that shape how likely an attack is. Organized criminal activity that monetizes card data, and published reports of skimming and shimming techniques used against comparable retailers, both reflect adversary capability and intent in the card payment ecosystem. Terminal counts, cashier turnover, and audit completion are internal attributes better suited to vulnerability, impact, or assurance analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The percentage of the chain's stores that have completed a recent internal audit.
Why it's wrong here
Internal audit completion is an assurance and governance metric about the organization's own control environment. It measures how well the chain verifies its controls, not how likely external actors are to attempt card data theft. Treating audit coverage as a threat input would invert the relationship between assurance activity and threat conditions and would give a falsely reassuring likelihood score as audit coverage improves.
- ✓
The prevalence and activity level of organized criminal groups that monetize stolen card data.
Why this is correct
Organized criminal activity that monetizes stolen card data is a direct external driver of the probability that the retail chain will be attacked. It reflects adversary capability and intent in the specific ecosystem where card data has resale value, so it belongs in the likelihood assessment for payment card compromise. Excluding it would leave the analysis anchored only in internal conditions and blind to the demand side of the threat.
- ✗
The turnover rate among store cashiers and the adequacy of their security awareness training.
Why it's wrong here
Cashier turnover and awareness training describe internal control strength and personnel vulnerability, both of which are internal to the organization. They affect how easily an adversary succeeds once it targets the chain, but they do not represent the external threat environment. Placing them in the external threat input set would conflate the organization's own weaknesses with conditions outside its control, making the threat picture inaccurate.
- ✓
Published reports of new skimming and shimming techniques observed at comparable retailers.
Why this is correct
Reports of new skimming and shimming methods at comparable retailers are external threat intelligence that shows which techniques adversaries are actively using against this industry. This directly informs the likelihood that the chain's payment environment will be attacked with those methods, so it is a valid external threat input. Ignoring it would let the analysis miss a technique that is already proven in the retail card ecosystem.
- ✗
The number of point-of-sale terminals the chain operates across all stores.
Why it's wrong here
Terminal count is an internal asset attribute that influences exposure and potential impact, not an external factor. It tells the practitioner how large the attack surface is but says nothing about whether adversaries are actively pursuing card data in that market. Using it as a threat input would double-count the estate size, which is already captured in vulnerability and impact analysis, and would distort the likelihood rating.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.