CRISC IT Risk Identification Practice Question
A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?
⚠ Common exam trap
CRISC often tests the distinction between risk appetite/tolerance statements and incident severity — candidates pick the most dramatic-sounding operational event instead of matching the scenario to the stated low-tolerance category (compliance).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A new cloud service may inadvertently expose customer PII due to misconfiguration
The risk appetite statement explicitly declares low tolerance for compliance risk, and exposing customer PII triggers regulatory/legal obligations (e.g., GDPR, CCPA, contractual data-protection clauses). Because compliance risk is the organization's stated low-tolerance area, any scenario with potential PII exposure must be escalated immediately to senior management. The other scenarios fall within the 'moderate operational risk' appetite the company has already accepted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A planned system upgrade may cause two hours of downtime during maintenance window
Why it's wrong here
Planned downtime inside a maintenance window is routine operational risk, explicitly accepted at moderate levels by the risk appetite statement. It tempts because availability impact feels urgent, yet no compliance obligation is breached, so immediate senior management escalation is not warranted.
- ✗
A vendor is late in delivering a software patch for a low-severity bug
Why it's wrong here
A late patch for a low-severity bug is an operational issue within the company's stated moderate operational risk appetite, so it does not trigger immediate escalation. It tempts because vendor delays sound like compliance exposure, but no regulatory obligation is breached here.
- ✓
A new cloud service may inadvertently expose customer PII due to misconfiguration
Why this is correct
Misconfiguration exposing customer PII breaches data-protection obligations, so it sits squarely in the low-tolerance compliance category rather than the moderate operational risk the company accepts. That mismatch with the stated risk appetite triggers immediate escalation to senior management, since regulatory penalties and notification duties cannot be absorbed within the accepted operational threshold.
- ✗
An employee mistakenly deletes a non-critical test database
Why it's wrong here
Deleting a non-critical test database is a contained operational error matching the accepted moderate operational risk appetite. It tempts because data loss sounds severe, but the database is non-critical and no compliance requirement is implicated, so immediate escalation is unnecessary.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.