CRISC IT Risk Identification Practice Question
During a risk assessment, the risk practitioner develops a scenario involving a disgruntled employee exfiltrating sensitive customer data through a USB drive. The organization has a strict policy against removable media but lacks technical controls to prevent USB usage. Which element of the risk scenario is the vulnerability?
⚠ Common exam trap
CRISC often tests the distinction between threat, vulnerability, and asset — candidates frequently mislabel the threat actor or the asset as the vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lack of technical controls to prevent USB usage
In a risk scenario, the vulnerability is the weakness or gap that can be exploited by a threat. Here, the absence of technical controls to prevent USB usage is the weakness, even though a policy exists. The policy alone does not enforce compliance, so the lack of technical enforcement is the vulnerability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data exfiltration
Why it's wrong here
Data exfiltration is the threat event or consequence — the outcome if the weakness is exploited — not the vulnerability. It is tempting because the scenario's whole point is data leaving the organisation, and exfiltration is a legitimate risk-register entry, but the vulnerability is specifically the missing technical control over removable media.
- ✓
Lack of technical controls to prevent USB usage
Why this is correct
The vulnerability is the missing technical enforcement of the removable media policy: the absence of controls preventing USB usage is the weakness an attacker exploits. The policy exists, so the gap is technical rather than procedural, enabling the disgruntled employee scenario.
- ✗
Disgruntled employee
Why it's wrong here
A disgruntled employee is the threat actor — the party who could exploit a weakness — not the weakness itself. It is tempting because insider motive feels central to the scenario, and identifying malicious insiders is a genuine risk-assessment activity, but the vulnerability here is the absence of technical USB controls.
- ✗
Sensitive customer data
Why it's wrong here
Sensitive customer data is the asset at risk — the thing needing protection — not the vulnerability. It is tempting because data classification drives risk scoring, and identifying crown-jewel assets is core risk work, but the weakness is the absent technical enforcement of the removable-media policy, not the data itself.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.