mediumMultiple Choice
CRISC Practice Question: After a security incident, an organization…
After a security incident, an organization discovers that a critical database was accessed by an unauthorized user due to weak authentication controls. As part of the IT risk assessment process, which step should have identified this vulnerability?
⚠ Common exam trap
Many exam-takers confuse risk identification with risk evaluation or risk treatment, mistakenly thinking that evaluating the impact of a weak control or treating it after discovery is the same as initially finding the vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk identification
Risk identification is the step in the IT risk assessment process where potential vulnerabilities, such as weak authentication controls, are systematically discovered and documented. In this scenario, the weak authentication that allowed unauthorized database access should have been identified during risk identification, which involves cataloging assets, threats, and existing controls. This step precedes any treatment, monitoring, or evaluation activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk treatment
Why it's wrong here
Risk treatment selects and implements controls to modify identified risk; it acts after identification, so it cannot discover weak authentication. It is tempting because remediation follows assessment, but it would be correct only once the vulnerability had been identified and evaluated as exceeding the organisation's risk tolerance.
- ✗
Risk monitoring
Why it's wrong here
Risk monitoring tracks known risks and control performance over time; it does not discover an unassessed weakness such as weak authentication. It is tempting because monitoring follows assessment, but it would be correct only for detecting changes in already-identified risks, not for initially surfacing this vulnerability.
- ✓
Risk identification
Why this is correct
Risk identification systematically uncovers threats, vulnerabilities and existing controls before incidents occur, so weak authentication on the critical database would have been surfaced here. It satisfies the stem's requirement to determine which assessment step should have detected the vulnerability, preceding risk analysis and evaluation, which merely assess likelihood and impact of already-identified risks.
- ✗
Risk evaluation
Why it's wrong here
Risk evaluation compares assessed risk against tolerance to decide whether treatment is needed; it operates on risks already identified, so it cannot surface weak authentication controls. It is tempting because it precedes treatment decisions, but it would be correct only once the vulnerability had already been found and analysed.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.