Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

An organization uses threat intelligence feeds from an Information Sharing and Analysis Center (ISAC). What is the PRIMARY benefit of using ISACs?

⚠ Common exam trap

CRISC often tests the distinction between information sharing bodies and operational controls — candidates pick answers that overstate ISAC authority (legally binding protocols) or understate their scope (replacing internal threat hunting).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They facilitate sharing of sector-specific threat intelligence

ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that collect, analyze, and disseminate threat intelligence relevant to a particular industry (e.g., FS-ISAC for financial services, H-ISAC for healthcare). Their primary value is enabling members to share timely, sector-relevant threat indicators and defensive guidance that they could not easily obtain individually. This directly matches option A.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    They facilitate sharing of sector-specific threat intelligence

    Why this is correct

    ISACs collect and distribute threat intelligence specific to a sector, letting members benefit from incidents and indicators observed by peers. This sector-specific sharing satisfies the primary benefit constraint, delivering contextual, relevant intelligence beyond generic feeds.

  • ✗

    They provide free antivirus software to members

    Why it's wrong here

    ISACs distribute threat intelligence such as indicators and advisories, not antivirus licences or endpoint tooling. It is tempting because membership benefits sometimes include vendor discounts, and would be correct if the organisation sought subsidised security products rather than timely sector threat data.

  • ✗

    They offer legally binding threat response protocols

    Why it's wrong here

    ISACs are voluntary information-sharing bodies; their guidance and indicators carry no legal force, so they cannot impose binding response protocols. It is tempting because shared sector guidance feels authoritative, and would be correct for a regulator or contractual framework mandating incident response obligations.

  • ✗

    They replace the need for internal threat hunting

    Why it's wrong here

    ISACs share sector-specific threat intelligence; they do not perform internal hunting or monitoring of your own estate, so this overstates their role. It is tempting because feeds inform hunting hypotheses, and would be correct only if the organisation had no internal detection capability at all.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.