CRISC IT Risk Identification Practice Question
A bank is identifying IT risks and categorizes a potential data breach as both a compliance risk (due to GDPR) and a reputational risk. This is an example of:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multiple risk categories for a single risk
A single risk can belong to multiple categories; this is normal in risk categorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Multiple risk categories for a single risk
Why this is correct
A single data breach event is being recorded against two distinct risk taxonomies simultaneously: regulatory compliance under GDPR and reputational damage. That dual tagging demonstrates one risk mapping to multiple categories, not separate risks or a single classification.
- ✗
Risk aggregation
Why it's wrong here
Aggregation combines multiple individual risks into a single higher-level view for reporting or capital purposes. The stem describes one event assigned two category labels, not several risks summed together. Aggregation would be correct when consolidating, say, many application risks into a portfolio-level risk register entry.
- ✗
Improper risk classification
Why it's wrong here
Categorising one breach under both compliance and reputational headings is valid multi-category classification, not an error. Improper classification would mean assigning a risk to a category that does not apply, or omitting an applicable one. GDPR breach consequences genuinely span both categories, so no misclassification occurs here.
- ✗
Risk scenario overlap
Why it's wrong here
A single breach event legitimately maps to multiple risk categories; that is inherent to the event, not an overlap of separate scenarios. Risk scenario overlap describes distinct scenarios sharing a common cause or asset, which is not what the stem describes. The stem illustrates one event with multiple consequence categories.
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.