CRISC - Information Technology and Security (20% of the exam) - Section 4.2

Manage IT operations risk across change, configuration, asset, problem and incident management, including zero trust principles.

Identify IT operations risks across change management, asset management, incident management, and configuration management disciplines. Apply zero trust architecture principles - such as continuous verification and least-privilege access - to reduce the attack surface exposed by operational processes.

Change managementAsset managementIncident managementZero trust architecture

Practice question for this objective

Free sampleInformation Technology and Securitymedium

An organisation is moving from a perimeter firewall model towards a zero trust architecture for access to internal applications. A project lead argues that once a device passes the initial login at the network edge it should be trusted for the rest of its session. How should the risk practitioner respond to align with zero trust principles?

  • AAgree, because authenticating the device once at the network boundary is the defining control that zero trust relies on to keep internal traffic safe
  • BAgree, provided the internal network is first segmented into zones, since segmentation alone delivers the trust assurances that zero trust is intended to provide
  • CDisagree, because zero trust depends mainly on encrypting all internal traffic, after which a single session-long authentication becomes perfectly acceptable
  • DDisagree, because zero trust assumes no implicit trust and requires continuous verification of identity, device, and context for each access request Correct
Apply the zero trust principle that every access request needs continuous verification rather than one-time trust. Zero trust removes implicit trust based on network location and instead verifies identity, device posture, and context on each request throughout a session, so a single edge login cannot confer ongoing trust for the remainder of that session.

Why A is wrong: One-time boundary authentication is the perimeter model zero trust replaces, so endorsing it is tempting familiarity but contradicts the very principle being adopted.

Why B is wrong: Segmentation supports zero trust and so sounds aligned, but on its own it still permits implicit trust within a zone, which is precisely what the model rejects.

Why C is wrong: Encryption protects data in transit and is good practice, but it does not establish trust in the requester, so it cannot justify a single session-long grant under zero trust.

Why D is correct: Zero trust treats every request as untrusted regardless of location, so access decisions are re-evaluated continuously rather than granted once for a whole session.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Deploy an additional perimeter firewall in front of the internal network so that external traffic is inspected twice before it can reach any workload.

    Why it is wrong: Reinforcing the perimeter only hardens the boundary; once an attacker is inside the flat network the extra edge firewall does nothing to restrain lateral movement.

  • Increase the frequency of the physical stock-take so that the count of servers in the inventory always matches the number of devices on the data-centre floor.

    Why it is wrong: Reconciling counts confirms how many assets exist but says nothing about whether their software is still supported, so unsupported systems would remain unflagged.

  • Schedule more frequent vulnerability scans of the production web servers so that newly relaxed settings are reported to the operations team sooner.

    Why it is wrong: More frequent scanning surfaces drift faster, but detection alone does not stop the servers from diverging from the baseline, so the underlying configuration management weakness persists.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.