CRISC - Risk Assessment (22% of the exam) - Section 2.3

Conduct vulnerability and control deficiency analysis to identify gaps that expose the organisation to risk.

Conduct vulnerability assessment and control deficiency analysis to identify gaps that expose the organisation to unacceptable risk. Use root cause analysis to distinguish symptoms from underlying weaknesses so that remediation addresses the source rather than the surface finding.

Vulnerability assessmentControl deficiencyGap analysisRoot cause

Practice question for this objective

Free sampleRisk Assessmenthard

Several unrelated incidents trace back to misconfigured firewalls deployed by different teams. A risk practitioner wants the vulnerability analysis to prevent recurrence rather than repeatedly patch symptoms. Which step is the most useful next action?

  • AReconfigure every affected firewall immediately and close each incident as a separately resolved finding
  • BPerform root cause analysis to determine why the misconfigurations keep arising across the separate teams Correct
  • CRaise the residual risk rating for the firewall estate and escalate the revised figure to senior leadership
  • DCommission an external penetration test of the perimeter to confirm the firewalls remain exploitable today
Use root cause analysis to address the systemic source of recurring vulnerabilities rather than repeatedly remediating individual symptoms. When the same class of vulnerability recurs across independent teams, the driver is usually a systemic cause such as missing baselines, weak change control, or untrained staff. Root cause analysis identifies that driver so a single corrective action removes the source, whereas patching each device only resets the symptom until it reappears.

Why A is wrong: Fixing each device feels decisive and fast, but it treats symptoms in isolation and leaves the systemic cause intact, so similar misconfigurations will recur across the teams.

Why B is correct: Root cause analysis targets the systemic source feeding repeated misconfigurations, so addressing it prevents recurrence rather than fixing each firewall as an isolated symptom.

Why C is wrong: Re-rating residual risk records severity for governance, yet it does not explain why the misconfigurations happen, so it cannot prevent the pattern from repeating.

Why D is wrong: A penetration test can confirm exploitability, but it rediscovers symptoms already known from incidents and still leaves the recurring underlying cause unaddressed.

See more CRISC practice questions, answers explained.

Exam traps in Risk Assessment

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • An external threat, because attackers actively scan the internet for exposed administrative interfaces protected by default credentials

    Why it is wrong: Opportunistic scanning is a real threat that could exploit this, but the question asks for the underlying cause, which is the absence of a required hardening control rather than the actor.

  • The chronological order in which each control gap was first recorded in the issue tracking system

    Why it is wrong: Logging order is easy to sort by and feels objective, but it reflects discovery sequence rather than risk, so it would misdirect remediation effort toward older yet trivial gaps.

  • A vulnerability exists because the recertification schedule runs only four times each year across the estate

    Why it is wrong: Quarterly cadence is tempting to blame, but the timing is not the issue when the control itself fails to remove the right accounts; cadence alone does not explain leakage.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.