hardMultiple Choice
CRISC Practice Question: The IT risk manager for a mid-sized e-commerce…
You are the IT risk manager for a mid-sized e-commerce company that processes over 10,000 transactions per day. The company recently migrated its customer database from an on-premises SQL Server to a cloud-based PostgreSQL instance on AWS RDS. The database contains personally identifiable information (PII) including names, addresses, and credit card numbers (stored as encrypted tokens). The migration was performed by the DevOps team with minimal involvement from the security team. Two weeks after the migration, the company experienced a data breach where an attacker exfiltrated a subset of customer records. The forensic investigation revealed that the attacker exploited a misconfigured security group that allowed inbound traffic from the internet on port 5432 (PostgreSQL default port). Additionally, the database had a publicly accessible endpoint, and the master user password was weak (eight characters, no special characters). The attacker used a brute-force attack to guess the password. The security group has since been corrected, and the password has been changed to a strong one. The breach notification laws require reporting within 72 hours. The CEO wants to understand the root cause and prevent recurrence. As the risk manager, which of the following actions should you recommend as the MOST effective to prevent a similar incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement infrastructure-as-code (IaC) security scanning and policy enforcement in the CI/CD pipeline to prevent insecure configurations.
The root cause is the misconfigured security group and weak password, both of which stem from insufficient security review and lack of automated controls. Implementing infrastructure-as-code (IaC) security scanning and policy enforcement in the CI/CD pipeline would automatically catch and block insecure configurations (e.g., publicly accessible database, weak passwords) before deployment, thus preventing similar incidents. Option B is incorrect because an IDS detects attacks in progress but does not prevent the initial misconfiguration. Option C is incorrect because relying on a single DBA to manually review all configurations weekly is error-prone and does not scale. Option D is incorrect because quarterly audits are too infrequent to catch misconfigurations that could be exploited immediately after deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement infrastructure-as-code (IaC) security scanning and policy enforcement in the CI/CD pipeline to prevent insecure configurations.
Why this is correct
Infrastructure-as-code scanning catches the misconfigured security group and publicly accessible endpoint before deployment, enforcing policy in the CI/CD pipeline the DevOps team already uses. This directly addresses the root cause: security controls were bypassed during migration, so shifting detection left prevents recurrence without relying on manual review.
- ✗
Deploy an intrusion detection system (IDS) to monitor database traffic for brute-force attempts.
Why it's wrong here
An IDS detects brute-force attempts after they begin, generating alerts rather than blocking port 5432 exposure or weak credentials. It is tempting because monitoring is a genuine detective control, and it would be correct where the requirement is visibility into attacks rather than preventing misconfiguration.
- ✗
Hire a dedicated database administrator to review all database configurations weekly.
Why it's wrong here
A dedicated administrator reviewing configurations weekly still relies on manual inspection, so a misconfigured security group persists until the next review. It is tempting because dedicated expertise improves oversight, and this would be valid where staffing, not automation, is the binding constraint.
- ✗
Conduct quarterly security audits of cloud infrastructure configurations.
Why it's wrong here
Quarterly audits detect drift only after exposure windows, leaving misconfigured security groups live for months. Audits are tempting because they provide independent assurance and would suit validating compliance posture, but they cannot enforce configuration at deployment time the way automated preventive controls do.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.