CRISC IT Risk Identification 1 — Questions and Answers
Question 1: Which CRISC domain is primarily responsible for identifying IT risk scenarios that could affect business objectives?
- IT Risk Identification (Correct answer)
- IT Risk Assessment
- Risk Response and Mitigation
- Risk and Control Monitoring
Correct answer: IT Risk Identification
The IT Risk Identification domain focuses on recognizing IT risk scenarios linked to business objectives and stakeholder requirements.
Question 2: What is a risk scenario in the context of CRISC?
- A documented description of a threat that could negatively impact business objectives (Correct answer)
- A technical vulnerability found during a penetration test
- A compliance checklist used by auditors
- A financial projection for IT spending
Correct answer: A documented description of a threat that could negatively impact business objectives
A risk scenario describes a threat event, its cause, and its potential impact on IT and business objectives.
Question 3: Which of the following best describes a threat actor in IT risk identification?
- Any entity that could exploit a vulnerability to cause harm (Correct answer)
- A software patch that reduces system exposure
- A business continuity plan
- A risk register entry
Correct answer: Any entity that could exploit a vulnerability to cause harm
A threat actor is any person, group, or system that could exploit vulnerabilities to negatively affect the organization.
Question 4: During IT risk identification, which asset classification approach is most useful?
- Categorizing assets by their criticality and sensitivity to business operations (Correct answer)
- Listing assets alphabetically in a spreadsheet
- Grouping assets solely by hardware type
- Sorting assets by purchase date
Correct answer: Categorizing assets by their criticality and sensitivity to business operations
Classifying assets by criticality and sensitivity helps prioritize which assets require the most rigorous risk identification.
Question 5: What is the primary purpose of maintaining a risk register?
- To document identified risks, their attributes, and status for tracking and communication (Correct answer)
- To store backup copies of IT policies
- To log user access attempts to systems
- To record software license expiry dates
Correct answer: To document identified risks, their attributes, and status for tracking and communication
A risk register is the central repository for recording all identified risks along with their likelihood, impact, owner, and response status.
Question 6: Which technique involves reviewing process flows to identify where IT risks could emerge?
- Business process analysis (Correct answer)
- Penetration testing
- Capacity planning
- Change management review
Correct answer: Business process analysis
Business process analysis examines workflows step-by-step to pinpoint where threats or vulnerabilities could affect IT and business outcomes.
Which CRISC domain is primarily responsible for identifying IT risk scenarios that could affect business objectives?