Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

Which of the following is the PRIMARY source for identifying known software vulnerabilities in a systematic manner?

⚠ Common exam trap

CRISC often tests the distinction between a vulnerability database (NVD) and security guidance or awareness lists (CIS Benchmarks, OWASP Top 10), causing candidates to select a well-known framework instead of the primary systematic source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

National Vulnerability Database (NVD)

The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, built upon the CVE (Common Vulnerabilities and Exposures) list. It provides a systematic, structured, and continuously updated source of known software vulnerabilities, including CVSS scores, CWE classifications, and affected product configurations. For CRISC, it is the authoritative primary source for identifying vulnerabilities in a repeatable, comprehensive manner, unlike the other options which are either not vulnerability databases or not systematic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    OSINT feeds from social media

    Why it's wrong here

    Social media OSINT is unstructured, unverified and lacks systematic CVE coverage, so it cannot serve as a primary vulnerability source. It suits threat intelligence or brand monitoring, whereas systematic identification requires curated databases such as NVD.

  • ✗

    CIS Benchmarks

    Why it's wrong here

    CIS Benchmarks provide secure configuration baselines for hardening systems, not a catalogue of known software vulnerabilities. Vulnerability enumeration comes from CVE/NVD feeds and vendor advisories, which is the scenario where a benchmark would not apply.

  • ✓

    National Vulnerability Database (NVD)

    Why this is correct

    The National Vulnerability Database provides a systematic, authoritative feed of known vulnerabilities, each mapped to CVE identifiers and enriched with CVSS severity scores. This structured, continuously updated catalogue satisfies the stem's requirement for a primary, repeatable source, unlike vendor advisories or ad hoc threat feeds.

  • ✗

    OWASP Top 10

    Why it's wrong here

    The OWASP Top 10 lists categories of web application risks, not specific known vulnerabilities with identifiers. It guides secure development awareness; systematic enumeration requires CVE/NVD data, which is the scenario where OWASP would not be the source.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.