nerdexam
IsacaIsaca

CRISC · Question #584

CRISC Question #584: Real Exam Question with Answer & Explanation

Sign in or unlock CRISC to reveal the answer and full explanation for question #584. The question stem and answer options stay visible for context.

Submitted by carter_n· Apr 18, 2026IT Risk Assessment

Question

Recent penetration testing of an organization's software has identified many different types of security risks. Which of the following is the MOST likely root cause for the identified risk?

Options

  • ASIEM software is producing faulty alerts.
  • BThreat modeling was not utilized in the software design process.
  • CThe configuration management process is not applied consistently during development.
  • DAn identity and access management (IAM) tool has not been properly integrated into the software.

Unlock CRISC to see the answer

You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Threat Modeling#Software Security Design#Vulnerability Root Cause#Penetration Testing
Full CRISC PracticeBrowse All CRISC Questions