CRISC Information Technology and Security Practice Question
An insurance company's risk committee is reviewing a new mobile claims application. A penetration test found that the app stores authentication tokens in plaintext in the device's shared application storage, where any other app on a rooted or jailbroken device can read them. The development team proposes to add certificate pinning. Which of the following is the MOST appropriate risk response?
⚠ Common exam trap
It's easy for candidates to confuse a transport-layer control with an at-rest data protection problem, which leads to accepting a finding that remains fully exploitable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate the finding by storing tokens in the platform's secure hardware-backed keystore and removing them from shared application storage.
When a penetration test identifies plaintext storage of authentication tokens in shared application storage, the root cause is insecure secret handling on the endpoint. Moving tokens into the platform's hardware-backed keystore binds them to the application and blocks other apps from reading them. Certificate pinning, insurance, and root detection either address different threats or fail to remove the vulnerability, so remediation of the storage design is the correct response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the finding because certificate pinning will prevent token interception by malicious applications.
Why it's wrong here
Certificate pinning protects the transport channel against man-in-the-middle interception of TLS sessions; it does nothing about tokens already stored in plaintext in shared storage. A malicious app reading the file locally never touches the network layer, so pinning cannot mitigate this finding. Accepting the risk on that basis leaves the actual vulnerability unaddressed.
- ✓
Mitigate the finding by storing tokens in the platform's secure hardware-backed keystore and removing them from shared application storage.
Why this is correct
The confirmed weakness is plaintext token storage readable by other applications, so the direct fix is to move tokens into the operating system's hardware-backed keystore, such as iOS Keychain or Android Keystore, which isolates secrets per application. This addresses the root cause rather than a related but different threat, making it the correct risk response.
- ✗
Avoid the risk by blocking the application from running on rooted or jailbroken devices.
Why it's wrong here
Root and jailbreak detection is easily bypassed and creates false confidence; attackers routinely defeat these checks. The tokens would still be written in plaintext and could be extracted on a device that evades detection. Avoidance via device blocking does not eliminate the underlying design flaw and degrades legitimate customer access.
- ✗
Transfer the risk by purchasing a cyber liability policy that covers mobile application data breaches.
Why it's wrong here
Insurance can compensate financial loss after an incident but does not reduce the likelihood that tokens are stolen from shared storage. The organization would still suffer account takeover and regulatory consequences. Transfer is a valid response for residual risk, yet here a straightforward technical mitigation exists, so transferring instead of fixing is inappropriate.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.