CRISC IT Risk Identification Practice Question
Which of the following is an example of a 'configuration vulnerability' that should be identified during vulnerability assessment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Default administrative passwords left unchanged on a network device
A configuration vulnerability arises from improper system settings. Leaving default passwords unchanged is a classic configuration weakness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A buffer overflow in a custom application
Why it's wrong here
A buffer overflow is a coding defect in the application's own logic, so it is remediated by patching source code rather than by hardening settings. It is tempting because vulnerability scanners do flag memory-safety flaws, but those are software vulnerabilities; configuration vulnerabilities concern insecure settings such as default credentials or unnecessary services.
- ✗
An SQL injection flaw in a web form
Why it's wrong here
SQL injection is an input-validation flaw in application code, fixed by parameterised queries rather than by changing system settings. It is tempting because scanners report it alongside misconfigurations, yet it is a software vulnerability; configuration vulnerabilities cover insecure settings like default accounts, verbose errors or unneeded ports.
- ✓
Default administrative passwords left unchanged on a network device
Why this is correct
Unchanged default administrative passwords on network devices constitute a configuration vulnerability because the weakness arises from how the device was set up, not from a software defect. This satisfies the stem's requirement by exposing an exploitable misconfiguration that vulnerability assessment should identify, since attackers routinely scan for vendor-default credentials.
- ✗
Missing security patches on a server
Why it's wrong here
Missing patches are a patch-management or software vulnerability, tracked against known CVEs, not a configuration weakness. Configuration vulnerabilities cover insecure settings such as default credentials or unnecessary services; patching is remediated through update deployment rather than hardening baselines.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.