mediumMultiple Choice
CRISC Practice Question: During a risk assessment for a new financial…
During a risk assessment for a new financial application, the risk manager identifies that the application processes sensitive customer data and is accessible from the internet. Which of the following is the MOST appropriate risk scenario to document?
⚠ Common exam trap
The trap here is that candidates mistake a vulnerability or a control for a complete risk scenario, failing to include the threat actor and business impact that are required for proper risk identification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker could exploit weak authentication mechanisms to gain unauthorized access and exfiltrate customer data, resulting in regulatory fines and reputational damage.
The most appropriate risk scenario because it follows the standard risk scenario structure: threat (attacker), vulnerability (weak authentication), impact (unauthorized access, data exfiltration, regulatory fines, reputational damage). It directly ties the technical weakness to a business consequence, which is essential for communicating risk to stakeholders. The scenario is specific to the application's internet-facing nature and sensitive data processing, making it actionable for risk treatment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application has several unpatched vulnerabilities that increase the likelihood of a security incident.
Why it's wrong here
Unpatched vulnerabilities describe a contributing condition rather than a risk scenario, which should pair a threat event with the asset and its business impact. It is tempting because vulnerability findings feel concrete and actionable; documenting them as scenarios suits vulnerability management tracking, not the risk register's event-and-impact structure.
- ✗
The application will implement multi-factor authentication to prevent unauthorized access.
Why it's wrong here
Multi-factor authentication is a planned control, not a risk scenario, so recording it documents a mitigation rather than the exposure being assessed. It is tempting because MFA genuinely reduces unauthorised-access likelihood; it belongs in the risk response or control description, not in the scenario statement itself.
- ✓
An attacker could exploit weak authentication mechanisms to gain unauthorized access and exfiltrate customer data, resulting in regulatory fines and reputational damage.
Why this is correct
This scenario names the asset, threat vector, exploited weakness, and business impact — internet-facing weak authentication leading to exfiltration, fines, and reputational damage. That structure satisfies risk scenario documentation requirements better than generic vulnerability statements.
- ✗
The application must comply with PCI DSS requirements for data protection.
Why it's wrong here
PCI DSS compliance is a regulatory obligation, not a risk scenario describing a threat event and its impact. It is tempting because the application handles payment data, so the standard genuinely applies; compliance requirements belong in control objectives or requirement mapping, whereas scenarios articulate what could happen and the resulting business consequence.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.