Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

During a risk assessment, the risk practitioner develops a scenario involving a disgruntled employee exfiltrating sensitive customer data through a USB drive. The organization has a strict policy against removable media but lacks technical controls to prevent USB usage. Which element of the risk scenario is the vulnerability?

⚠ Common exam trap

CRISC often tests the distinction between threat, vulnerability, and asset — candidates frequently mislabel the threat actor or the asset as the vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Lack of technical controls to prevent USB usage

In a risk scenario, the vulnerability is the weakness or gap that can be exploited by a threat. Here, the absence of technical controls to prevent USB usage is the weakness, even though a policy exists. The policy alone does not enforce compliance, so the lack of technical enforcement is the vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data exfiltration

    Why it's wrong here

    Data exfiltration is the threat event or consequence — the outcome if the weakness is exploited — not the vulnerability. It is tempting because the scenario's whole point is data leaving the organisation, and exfiltration is a legitimate risk-register entry, but the vulnerability is specifically the missing technical control over removable media.

  • ✓

    Lack of technical controls to prevent USB usage

    Why this is correct

    The vulnerability is the missing technical enforcement of the removable media policy: the absence of controls preventing USB usage is the weakness an attacker exploits. The policy exists, so the gap is technical rather than procedural, enabling the disgruntled employee scenario.

  • ✗

    Disgruntled employee

    Why it's wrong here

    A disgruntled employee is the threat actor — the party who could exploit a weakness — not the weakness itself. It is tempting because insider motive feels central to the scenario, and identifying malicious insiders is a genuine risk-assessment activity, but the vulnerability here is the absence of technical USB controls.

  • ✗

    Sensitive customer data

    Why it's wrong here

    Sensitive customer data is the asset at risk — the thing needing protection — not the vulnerability. It is tempting because data classification drives risk scoring, and identifying crown-jewel assets is core risk work, but the weakness is the absent technical enforcement of the removable-media policy, not the data itself.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.