CRISC Information Technology and Security Practice Question
A university is deploying a new student information system that will store grades, financial aid records, and health center notes. The risk practitioner must determine the data classification that drives encryption, access, and retention requirements. Which factor is MOST important in setting that classification?
⚠ Common exam trap
The trap here is choosing a convenient operational metric such as record volume or vendor default instead of analyzing the harm that disclosure or alteration would cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The potential harm to students and the university if the data is disclosed, altered, or unavailable.
Classification should be driven by the impact of compromise, because that impact determines how strong encryption, access, and retention controls must be. Student health notes and financial aid records cause significant harm if exposed or altered, so harm analysis is the correct basis. Volume, tooling cost, and vendor defaults are operational or commercial factors that cannot reliably indicate sensitivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor's default classification assigned in the student information system's configuration templates.
Why it's wrong here
Vendor templates are generic starting points and cannot reflect the university's legal, contractual, and reputational exposure. Adopting the vendor default would outsource a governance decision to a third party and could conflict with FERPA, HIPAA, or institutional policy, so it is not a sound basis for classification.
- ✗
The volume of records the system will hold and the projected annual growth rate.
Why it's wrong here
Volume affects storage, backup, and performance design, but it does not determine sensitivity. A small set of health center notes demands stronger protection than a large set of publicly posted course catalogs, so sizing metrics would misclassify the data and could leave regulated records under-protected.
- ✗
The cost of the encryption and access management tools required to protect the system.
Why it's wrong here
Control cost is a consideration when selecting safeguards, not when assigning classification. If cost drove classification, the most expensive-to-protect data would be labeled least sensitive, which inverts the purpose of the scheme and would leave financial aid and health information exposed to comply with a budget rather than a risk decision.
- ✓
The potential harm to students and the university if the data is disclosed, altered, or unavailable.
Why this is correct
Data classification exists to match protection to impact, so the governing factor is the harm that unauthorized disclosure, modification, or loss would cause to individuals and the institution. Health notes and financial aid records carry regulatory and reputational consequences far beyond their storage cost, and that impact analysis correctly drives the encryption, access, and retention controls.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.