Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

An organization is conducting a vulnerability assessment of its IT assets. Which of the following sources is MOST authoritative for identifying known software vulnerabilities?

⚠ Common exam trap

CRISC often tests the distinction between vulnerability databases (NVD) and configuration benchmarks (STIGs, CIS) or awareness lists (OWASP Top 10) — candidates who pick STIGs or CIS Benchmarks confuse secure configuration guidance with known-vulnerability identification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NVD (National Vulnerability Database)

The National Vulnerability Database (NVD), maintained by NIST, is the U.S. government repository that enriches and standardizes CVE data with CVSS scores, CWE classifications, and CPE applicability statements. It is the most authoritative public source for identifying known software vulnerabilities because it aggregates and normalizes vulnerability data from vendors and researchers worldwide. Vulnerability scanners and risk tools routinely sync with NVD feeds to identify known CVEs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DISA STIGs

    Why it's wrong here

    DISA STIGs prescribe hardened configuration baselines for specific platforms, not catalogues of known software flaws, so they cannot identify vulnerabilities in the assessed software. They are tempting because they are genuinely authoritative for compliance benchmarking and secure build guidance, and would be the right source when auditing whether systems meet mandated configuration standards.

  • ✗

    OWASP Top 10

    Why it's wrong here

    The OWASP Top 10 catalogues web application risk categories, not individual software vulnerabilities, so it cannot identify specific CVEs affecting assessed assets. It is tempting because it is a recognised awareness and secure-coding reference, and it would be the correct choice when prioritising web application security risks or guiding developer training.

  • ✓

    NVD (National Vulnerability Database)

    Why this is correct

    The NVD is the US government's authoritative repository, enriching CVE entries with CVSS scores, CPE applicability and remediation references. Unlike vendor advisories or forums, it provides standardised, independently curated vulnerability data, making it the most authoritative source for identifying known software vulnerabilities.

  • ✗

    CIS Benchmarks

    Why it's wrong here

    CIS Benchmarks provide configuration hardening baselines, not vulnerability signatures, so they cannot identify known software flaws. They are tempting because they map secure settings for operating systems and applications, and would be the right source when auditing configuration compliance against a hardening standard rather than enumerating CVEs.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.