Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A bank is identifying IT risks and categorizes a potential data breach as both a compliance risk (due to GDPR) and a reputational risk. This is an example of:

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multiple risk categories for a single risk

A single risk can belong to multiple categories; this is normal in risk categorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Multiple risk categories for a single risk

    Why this is correct

    A single data breach event is being recorded against two distinct risk taxonomies simultaneously: regulatory compliance under GDPR and reputational damage. That dual tagging demonstrates one risk mapping to multiple categories, not separate risks or a single classification.

  • ✗

    Risk aggregation

    Why it's wrong here

    Aggregation combines multiple individual risks into a single higher-level view for reporting or capital purposes. The stem describes one event assigned two category labels, not several risks summed together. Aggregation would be correct when consolidating, say, many application risks into a portfolio-level risk register entry.

  • ✗

    Improper risk classification

    Why it's wrong here

    Categorising one breach under both compliance and reputational headings is valid multi-category classification, not an error. Improper classification would mean assigning a risk to a category that does not apply, or omitting an applicable one. GDPR breach consequences genuinely span both categories, so no misclassification occurs here.

  • ✗

    Risk scenario overlap

    Why it's wrong here

    A single breach event legitimately maps to multiple risk categories; that is inherent to the event, not an overlap of separate scenarios. Risk scenario overlap describes distinct scenarios sharing a common cause or asset, which is not what the stem describes. The stem illustrates one event with multiple consequence categories.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.