Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A financial services firm's risk practitioner is building a risk register entry for a customer-facing mobile banking application hosted in a public cloud. The application stores PII and processes payments. Management wants to understand the inherent risk before any controls are considered. Which of the following BEST represents the inherent risk of this asset?

⚠ Common exam trap

Watch out — candidates often confuse inherent risk with residual risk or with control cost, which leads to understating exposure before controls are evaluated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The likelihood and impact of loss assuming no controls are in place, derived from the threat environment and the asset's value and exposure.

Inherent risk is the exposure that exists before controls are applied, built from the threat environment and the value and exposure of the asset. For a mobile banking app holding PII and processing payments, the practitioner must assess realistic threat events and their potential impacts without crediting existing safeguards. This baseline enables meaningful comparison once control effectiveness is evaluated and residual risk is determined.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The likelihood and impact of loss assuming no controls are in place, derived from the threat environment and the asset's value and exposure.

    Why this is correct

    Inherent risk is assessed before considering the mitigating effect of controls, using the threat landscape, asset value, and exposure. For this mobile banking app, that means evaluating realistic threat events against the PII and payment data it handles, independent of any existing security measures. This gives management a baseline against which control effectiveness and residual risk can later be compared.

  • ✗

    The aggregate cost of the security controls deployed to protect the mobile application and its supporting cloud infrastructure.

    Why it's wrong here

    Control cost is an input to cost-benefit analysis of risk treatment, not a measure of inherent risk. Inherent risk concerns the possibility and magnitude of loss from threat events, not the money spent to prevent them. Substituting control spend for risk exposure would confuse investment levels with actual exposure and could lead to under- or over-investment decisions.

  • ✗

    The likelihood and impact of loss after all implemented controls have been applied and validated by internal audit.

    Why it's wrong here

    This describes residual risk, not inherent risk. Residual risk is what remains after controls are applied and tested. The scenario explicitly asks for the inherent risk before controls are considered, so using post-control figures would understate the exposure and mislead management about the true baseline. Internal audit validation is also not a prerequisite for quantifying inherent risk.

  • ✗

    The maximum regulatory fine the firm could face if the application suffered a data breach involving customer PII.

    Why it's wrong here

    A regulatory fine is only one potential impact component and is contingent on a breach occurring. Inherent risk encompasses the full range of likelihood and impact, including financial, reputational, operational, and legal consequences. Using only the maximum fine as the risk measure ignores probability and other impacts, producing an incomplete and potentially misleading risk picture.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.