CRISC Information Technology and Security Practice Question
An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?
⚠ Common exam trap
CRISC often tests the distinction between business/functional risks and security/compliance risks; candidates pick timeline or technology-choice options because they sound like 'architecture' concerns, missing that the ARB prioritizes risks to sensitive data and regulatory posture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application exposes sensitive customer data through APIs without proper authentication
The primary risk an Architecture Review Board should consider is the exposure of sensitive customer data through unauthenticated APIs, because this represents a direct, high-impact security and compliance risk (data breach, regulatory penalties, reputational damage). ARBs focus on risks that threaten confidentiality, integrity, and availability of critical assets, and unauthenticated API access to sensitive data is a classic OWASP API Security Top 10 issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application does not support mobile devices
Why it's wrong here
Mobile support is a functional requirement gap, not the primary architecture risk of exposure, data integrity or availability. The ARB's remit is enterprise risk, so missing mobile support is a usability defect. It would be the correct focus for a product owner prioritising channel coverage, not for architecture governance.
- ✗
The application development timeline is aggressive
Why it's wrong here
An aggressive timeline is a delivery risk, not an architecture risk, so it falls outside the ARB's primary remit of design integrity and control coverage. It would be the correct consideration for a project board managing schedule and resourcing, not for architecture governance assessing the solution's inherent risk.
- ✗
The application uses the latest JavaScript framework
Why it's wrong here
Adopting a current JavaScript framework introduces no inherent architecture risk; the risk lies in unpatched dependencies or unsupported versions. The ARB weighs exposure and resilience, not novelty. Choosing the latest framework would be correct when the requirement is long-term vendor support and access to current security fixes.
- ✓
The application exposes sensitive customer data through APIs without proper authentication
Why this is correct
Exposing sensitive customer data through unauthenticated APIs directly threatens confidentiality, the core risk for a customer-facing application. Microsoft Entra ID authentication controls would mitigate this, but the ARB's primary concern is whether the architecture enforces authentication at all, satisfying the stem's focus on identifying the foremost architectural risk.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.