CRISC - Information Technology and Security (20% of the exam) - Section 4.1

Apply enterprise architecture concepts to understand how technology decisions affect IT risk.

Apply enterprise architecture concepts - spanning the technology stack, data architecture, and system interconnections - to understand how technology decisions introduce or mitigate IT risk. Recognise that architecture risk arises when design choices create complexity, single points of failure, or shadow IT outside governance visibility.

Enterprise architectureTechnology stackData architectureArchitecture risk

Practice question for this objective

Free sampleInformation Technology and Securitymedium

A retail group is launching three new digital initiatives at once, and each delivery team has independently chosen its own programming language, hosting model and integration style. A risk practitioner wants to use the enterprise architecture function to reduce the IT risk this autonomy creates. Which use of enterprise architecture would most directly reduce that risk?

  • AAllow each team full freedom now and reconcile the differing technology choices into common patterns once all three initiatives have shipped
  • BRequire every team to adopt one identical technology stack regardless of whether it suits the specific problem each initiative solves
  • CPublish architecture principles and reference patterns that every initiative must justify any deviation against before build begins Correct
  • DRecord each team's chosen technologies in the configuration management database so the differences are at least visible to operations
Enterprise architecture reduces IT risk by guiding technology decisions through agreed principles and reference patterns before solutions are built. Enterprise architecture manages risk proactively by setting principles and reference patterns that shape design choices early, turning uncontrolled divergence into reviewed, justified exceptions rather than fragmentation that must be remediated after delivery.

Why A is wrong: Reconciling after delivery is tempting because it avoids slowing teams, but rework is far costlier later and the divergent choices have already created the integration and support risk by then.

Why B is wrong: Mandating a single stack looks like strong standardisation, but forcing an unsuitable choice creates its own risk and ignores the fit-for-purpose judgement that architecture governance is meant to apply.

Why C is correct: Shared principles and reference patterns constrain technology choices up front, so divergence becomes a deliberate, reviewed exception rather than an unmanaged source of fragmentation and risk.

Why D is wrong: Recording choices improves visibility, which is useful, but it documents the fragmentation after the fact rather than steering the decisions that create the risk in the first place.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Let the business unit procure the platform first and ask the architecture function to document it in the repository once it has been deployed into production.

    Why it is wrong: Recording a tool after deployment keeps the repository current, but it does nothing to manage the risk of the purchase itself and locks in the redundancy the practitioner was asked about.

  • Capturing the attribute in three systems consumes excess storage, which raises the long-term cost of retaining patient records across the estate

    Why it is wrong: Storage cost is a tempting concrete concern, but the architectural risk here is the integrity of the data, not the modest expense of holding a few duplicated fields.

  • The vendor will stop answering operational support tickets, so the team must resolve routine configuration and tuning issues without the supplier's help desk after the cut-off.

    Why it is wrong: Losing operational help-desk support is a real consequence and tempting because it follows from the announcement, but it is an availability and supportability concern that does not match the direct security exposure the practitioner is mapping.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.