Courseiva

CRISC Information Technology and Security Practice Question

An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?

⚠ Common exam trap

CRISC often tests the distinction between business/functional risks and security/compliance risks; candidates pick timeline or technology-choice options because they sound like 'architecture' concerns, missing that the ARB prioritizes risks to sensitive data and regulatory posture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application exposes sensitive customer data through APIs without proper authentication

The primary risk an Architecture Review Board should consider is the exposure of sensitive customer data through unauthenticated APIs, because this represents a direct, high-impact security and compliance risk (data breach, regulatory penalties, reputational damage). ARBs focus on risks that threaten confidentiality, integrity, and availability of critical assets, and unauthenticated API access to sensitive data is a classic OWASP API Security Top 10 issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application does not support mobile devices

    Why it's wrong here

    Mobile support is a functional requirement gap, not the primary architecture risk of exposure, data integrity or availability. The ARB's remit is enterprise risk, so missing mobile support is a usability defect. It would be the correct focus for a product owner prioritising channel coverage, not for architecture governance.

  • ✗

    The application development timeline is aggressive

    Why it's wrong here

    An aggressive timeline is a delivery risk, not an architecture risk, so it falls outside the ARB's primary remit of design integrity and control coverage. It would be the correct consideration for a project board managing schedule and resourcing, not for architecture governance assessing the solution's inherent risk.

  • ✗

    The application uses the latest JavaScript framework

    Why it's wrong here

    Adopting a current JavaScript framework introduces no inherent architecture risk; the risk lies in unpatched dependencies or unsupported versions. The ARB weighs exposure and resilience, not novelty. Choosing the latest framework would be correct when the requirement is long-term vendor support and access to current security fixes.

  • ✓

    The application exposes sensitive customer data through APIs without proper authentication

    Why this is correct

    Exposing sensitive customer data through unauthenticated APIs directly threatens confidentiality, the core risk for a customer-facing application. Microsoft Entra ID authentication controls would mitigate this, but the ARB's primary concern is whether the architecture enforces authentication at all, satisfying the stem's focus on identifying the foremost architectural risk.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.