Courseiva
easyMultiple ChoiceObjective-mapped

CRISC Practice Question: Is implementing a new identity and access…

An organization is implementing a new identity and access management (IAM) system. The risk manager is tasked with identifying risks associated with the migration from legacy authentication to single sign-on (SSO). Which of the following is the GREATEST risk during this migration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Legacy authentication accounts may remain active, creating orphan accounts.

Legacy accounts that are not disabled after migration become unmanaged orphan accounts, which can be exploited by attackers, posing a significant security risk. Option A is less severe because password reuse, while a risk, is not unique to this migration and is generally mitigated by SSO policies. Option B is incorrect because increased convenience does not inherently reduce security awareness; in fact, SSO can improve security by reducing password fatigue. Option D is incorrect because while help desk call volumes may initially rise, this is an operational issue, not a security risk, and is typically temporary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Users may reuse strong passwords across multiple systems.

    Why it's wrong here

    Password reuse is a risk but not the greatest during migration.

  • Users may experience increased convenience, leading to reduced security awareness.

    Why it's wrong here

    Convenience is not a direct risk; it is a benefit.

  • Legacy authentication accounts may remain active, creating orphan accounts.

    Why this is correct

    Orphan accounts are a high-risk security issue if not disabled.

  • Help desk call volumes may increase due to SSO authentication failures.

    Why it's wrong here

    SSO typically reduces help desk calls.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.