CRISC Information Technology and Security Practice Question
A software company allows developers to push code directly to production using a CI/CD pipeline. A recent post-incident review found that a developer's compromised credentials were used to deploy malicious code that exfiltrated customer data. Which control would MOST effectively reduce the risk of this specific attack path recurring?
⚠ Common exam trap
The trap here is selecting detective or awareness controls when the incident path was an authentication and authorization weakness that only preventive identity controls can close.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require multi-factor authentication for all developer accounts and enforce short-lived deployment tokens scoped to individual pipelines.
The incident path was a stolen credential granting deployment rights. Strengthening authentication with multi-factor authentication and constraining deployment tokens to short-lived, pipeline-scoped values removes both the sufficiency of a password and the blast radius of a captured token. Scanning, logging and training are valuable controls but do not close the authentication and authorization gap that enabled this specific attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase logging and alerting on production deployments and review alerts weekly.
Why it's wrong here
Better logging improves detection and investigation, but weekly review means a malicious deployment could run for days before anyone notices. It is a detective control that shortens discovery time at best, yet it does not prevent the compromised credential from being used to deploy code, so it is not the most effective reduction of this path.
- ✓
Require multi-factor authentication for all developer accounts and enforce short-lived deployment tokens scoped to individual pipelines.
Why this is correct
The attack relied on a stolen credential being sufficient to deploy code. Multi-factor authentication means a password alone cannot authenticate, and short-lived, pipeline-scoped tokens limit what a captured token can do, directly breaking the specific path used in this incident. This combination is the most targeted reduction of the demonstrated risk.
- ✗
Require developers to complete annual secure coding training and sign an acceptable use policy.
Why it's wrong here
Awareness training and policy attestation influence behaviour but do not stop an external attacker who has already stolen valid credentials. The incident did not stem from a developer's coding mistake, so training and policy acknowledgement leave the authentication and authorization weakness fully intact.
- ✗
Implement static application security testing in the pipeline to scan code before deployment.
Why it's wrong here
Static analysis finds insecure code patterns, but the malicious code here was intentionally deployed by an attacker using valid credentials. A scanner may or may not flag deliberately crafted code, and it does nothing to stop an authenticated attacker from pushing it, so it does not address the credential compromise path.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.