IsacaIsaca
CRISC · Question #584
CRISC Question #584: Real Exam Question with Answer & Explanation
Sign in or unlock CRISC to reveal the answer and full explanation for question #584. The question stem and answer options stay visible for context.
Submitted by carter_n· Apr 18, 2026IT Risk Assessment
Question
Recent penetration testing of an organization's software has identified many different types of security risks. Which of the following is the MOST likely root cause for the identified risk?
Options
- ASIEM software is producing faulty alerts.
- BThreat modeling was not utilized in the software design process.
- CThe configuration management process is not applied consistently during development.
- DAn identity and access management (IAM) tool has not been properly integrated into the software.
Unlock CRISC to see the answer
You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Threat Modeling#Software Security Design#Vulnerability Root Cause#Penetration Testing