CRISC IT Risk Identification Practice Question
An organization uses threat intelligence feeds from an Information Sharing and Analysis Center (ISAC). What is the PRIMARY benefit of using ISACs?
⚠ Common exam trap
CRISC often tests the distinction between information sharing bodies and operational controls — candidates pick answers that overstate ISAC authority (legally binding protocols) or understate their scope (replacing internal threat hunting).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They facilitate sharing of sector-specific threat intelligence
ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that collect, analyze, and disseminate threat intelligence relevant to a particular industry (e.g., FS-ISAC for financial services, H-ISAC for healthcare). Their primary value is enabling members to share timely, sector-relevant threat indicators and defensive guidance that they could not easily obtain individually. This directly matches option A.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
They facilitate sharing of sector-specific threat intelligence
Why this is correct
ISACs collect and distribute threat intelligence specific to a sector, letting members benefit from incidents and indicators observed by peers. This sector-specific sharing satisfies the primary benefit constraint, delivering contextual, relevant intelligence beyond generic feeds.
- ✗
They provide free antivirus software to members
Why it's wrong here
ISACs distribute threat intelligence such as indicators and advisories, not antivirus licences or endpoint tooling. It is tempting because membership benefits sometimes include vendor discounts, and would be correct if the organisation sought subsidised security products rather than timely sector threat data.
- ✗
They offer legally binding threat response protocols
Why it's wrong here
ISACs are voluntary information-sharing bodies; their guidance and indicators carry no legal force, so they cannot impose binding response protocols. It is tempting because shared sector guidance feels authoritative, and would be correct for a regulator or contractual framework mandating incident response obligations.
- ✗
They replace the need for internal threat hunting
Why it's wrong here
ISACs share sector-specific threat intelligence; they do not perform internal hunting or monitoring of your own estate, so this overstates their role. It is tempting because feeds inform hunting hypotheses, and would be correct only if the organisation had no internal detection capability at all.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.