Courseiva

CRISC Information Technology and Security Practice Question

A company's risk management policy requires a risk register to be maintained. Which of the following is the primary purpose of a risk register?

⚠ Common exam trap

It's easy for candidates to confuse the risk register with other operational logs (e.g., audit findings or asset inventories) or assume its primary purpose is financial quantification, whereas the CRISC exam emphasizes its role as a comprehensive tracking and documentation tool for the entire risk management process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To document and track identified risks, assessments, and risk responses

The primary purpose of a risk register is to serve as a central repository for documenting and tracking all identified risks, their assessments (including likelihood and impact), and the corresponding risk response strategies. This ensures that risk management activities are transparent, auditable, and actionable throughout the risk lifecycle, aligning with the ISACA CRISC framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To assign financial values to all risks

    Why it's wrong here

    A risk register records identified risks with owners, likelihood, impact and treatment status; it does not quantify every risk financially. It is tempting because monetary impact informs prioritisation, and would be correct if the requirement were to express risk exposure in financial terms for cost-benefit decisions.

  • ✓

    To document and track identified risks, assessments, and risk responses

    Why this is correct

    A risk register is the central record capturing each identified risk together with its assessment results and chosen responses, enabling tracking and ownership over time. This supports the policy requirement by giving management a single, auditable view of risk status and treatment progress.

  • ✗

    To record audit findings

    Why it's wrong here

    Audit findings belong in an audit log or issue tracker, not the risk register, which documents identified risks with owners, likelihood, impact and treatment. Recording findings is tempting because both artefacts track outstanding items, but a risk register exists to drive risk-based decisions, not to evidence control testing outcomes.

  • ✗

    To provide a list of all IT assets

    Why it's wrong here

    A risk register catalogues risks and their assessment details, not hardware, software or data holdings. It is tempting because asset inventory underpins risk identification, and would be correct if the policy required a complete listing of IT assets with owners and locations for valuation purposes.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.