Certified in Risk and Information Systems Control (CRISC) — Question 770
Which of the following is the GREATEST risk associated with an environment that lacks documentation of the architecture?
Answer options
- A. Network isolation
- B. Overlapping threats
- C. Unknown vulnerabilities
- D. Legacy technology systems
Correct answer: C
Explanation
The correct answer is C, as the absence of architectural documentation can lead to unknown vulnerabilities, making it difficult to identify security weaknesses. The other options, while they pose risks, are less critical in the context of lacking documentation, as network isolation, overlapping threats, and legacy systems can still be managed with proper knowledge of the architecture.