Courseiva
IT Risk Identification →mediumMultiple Select

CRISC IT Risk Identification Practice Question

During a risk identification workshop, the team identifies several vulnerabilities. Which TWO of the following are examples of operational vulnerability identification? (Select two.)

⚠ Common exam trap

CRISC often tests the boundary between operational and technical vulnerabilities — candidates pick patch or firmware issues because they sound like 'vulnerabilities,' but the question specifically asks for operational (process/control) weaknesses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inadequate access control review process

Operational vulnerability identification focuses on weaknesses in day-to-day processes, procedures, and human/administrative controls rather than specific technical flaws in systems or code. Option A, an inadequate access control review process, is correct because it is a procedural/process weakness—failing to periodically review who has access means operational controls are not being maintained, which is a classic operational vulnerability. Option D, weak password policy enforcement, is correct because it reflects a failure in enforcing an administrative/operational control (e.g., not applying complexity, rotation, or lockout rules), which is a process and governance issue rather than a single technical defect. By contrast, option B (outdated firewall firmware) and option C (missing security patches on servers) are technical vulnerabilities tied to unpatched software/hardware, and option E (SQL injection in the web application) is a technical application flaw, so they fall under technical rather than operational vulnerability identification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Inadequate access control review process

    Why this is correct

    An inadequate access control review process is an operational vulnerability: a weakness in the ongoing procedures that govern how access rights are checked and recertified. It satisfies the stem's requirement for operational identification, since it arises from day-to-day process execution rather than project or architectural design.

  • ✗

    Outdated firewall firmware

    Why it's wrong here

    Outdated firmware is a technical or configuration weakness in an asset, identified through vulnerability scanning or patch management, not through operational process review. It is tempting because firmware gaps do create exploitable exposure, but operational vulnerabilities concern failed or missing day-to-day controls such as unreviewed access.

  • ✗

    Missing security patches on servers

    Why it's wrong here

    Missing patches is a technical vulnerability, not an operational one; operational vulnerabilities concern people, processes and procedures, such as inadequate change control or untrained staff. It tempts because patch management is a recurring operational task, yet the resulting exposure itself is classified as technical.

  • ✓

    Weak password policy enforcement

    Why this is correct

    Weak password policy enforcement is an operational vulnerability, stemming from how authentication controls are actually applied day to day rather than from design. It satisfies the stem's operational criterion because the weakness lies in ongoing execution of the password policy, not in its documented definition.

  • ✗

    SQL injection vulnerability in the web application

    Why it's wrong here

    SQL injection is a software or application-code weakness, identified through secure code review or penetration testing, not operational vulnerability identification. It is tempting because it is a genuine vulnerability, but operational identification covers infrastructure and configuration weaknesses such as missing patches, outdated firmware or misconfigured services.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.