CRISC - Risk Assessment - Section 2.3

Conduct vulnerability and control deficiency analysis to identify gaps that expose the organisation to risk.

Conduct vulnerability assessment and control deficiency analysis to identify gaps that expose the organisation to unacceptable risk. Use root cause analysis to distinguish symptoms from underlying weaknesses so that remediation addresses the source rather than the surface finding.

Vulnerability assessmentControl deficiencyGap analysisRoot cause

Practice question for this objective

Free sampleRisk Assessmenthard

Several unrelated incidents trace back to misconfigured firewalls deployed by different teams. A risk practitioner wants the vulnerability analysis to prevent recurrence rather than repeatedly patch symptoms. Which step is the most useful next action?

  • AReconfigure every affected firewall immediately and close each incident as a separately resolved finding
  • BPerform root cause analysis to determine why the misconfigurations keep arising across the separate teams Correct
  • CRaise the residual risk rating for the firewall estate and escalate the revised figure to senior leadership
  • DCommission an external penetration test of the perimeter to confirm the firewalls remain exploitable today
Use root cause analysis to address the systemic source of recurring vulnerabilities rather than repeatedly remediating individual symptoms. When the same class of vulnerability recurs across independent teams, the driver is usually a systemic cause such as missing baselines, weak change control, or untrained staff. Root cause analysis identifies that driver so a single corrective action removes the source, whereas patching each device only resets the symptom until it reappears.

Why A is wrong: Fixing each device feels decisive and fast, but it treats symptoms in isolation and leaves the systemic cause intact, so similar misconfigurations will recur across the teams.

Why B is correct: Root cause analysis targets the systemic source feeding repeated misconfigurations, so addressing it prevents recurrence rather than fixing each firewall as an isolated symptom.

Why C is wrong: Re-rating residual risk records severity for governance, yet it does not explain why the misconfigurations happen, so it cannot prevent the pattern from repeating.

Why D is wrong: A penetration test can confirm exploitability, but it rediscovers symptoms already known from incidents and still leaves the recurring underlying cause unaddressed.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Assessment objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.