Courseiva
mediumMultiple Choice

CRISC Practice Question: After a security incident, an organization…

After a security incident, an organization discovers that a critical database was accessed by an unauthorized user due to weak authentication controls. As part of the IT risk assessment process, which step should have identified this vulnerability?

⚠ Common exam trap

Many exam-takers confuse risk identification with risk evaluation or risk treatment, mistakenly thinking that evaluating the impact of a weak control or treating it after discovery is the same as initially finding the vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk identification

Risk identification is the step in the IT risk assessment process where potential vulnerabilities, such as weak authentication controls, are systematically discovered and documented. In this scenario, the weak authentication that allowed unauthorized database access should have been identified during risk identification, which involves cataloging assets, threats, and existing controls. This step precedes any treatment, monitoring, or evaluation activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk treatment

    Why it's wrong here

    Risk treatment selects and implements controls to modify identified risk; it acts after identification, so it cannot discover weak authentication. It is tempting because remediation follows assessment, but it would be correct only once the vulnerability had been identified and evaluated as exceeding the organisation's risk tolerance.

  • ✗

    Risk monitoring

    Why it's wrong here

    Risk monitoring tracks known risks and control performance over time; it does not discover an unassessed weakness such as weak authentication. It is tempting because monitoring follows assessment, but it would be correct only for detecting changes in already-identified risks, not for initially surfacing this vulnerability.

  • ✓

    Risk identification

    Why this is correct

    Risk identification systematically uncovers threats, vulnerabilities and existing controls before incidents occur, so weak authentication on the critical database would have been surfaced here. It satisfies the stem's requirement to determine which assessment step should have detected the vulnerability, preceding risk analysis and evaluation, which merely assess likelihood and impact of already-identified risks.

  • ✗

    Risk evaluation

    Why it's wrong here

    Risk evaluation compares assessed risk against tolerance to decide whether treatment is needed; it operates on risks already identified, so it cannot surface weak authentication controls. It is tempting because it precedes treatment decisions, but it would be correct only once the vulnerability had already been found and analysed.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.