CRISC IT Risk Identification Practice Question
A financial services firm's risk practitioner is building a risk register entry for a customer-facing mobile banking application hosted in a public cloud. The application stores PII and processes payments. Management wants to understand the inherent risk before any controls are considered. Which of the following BEST represents the inherent risk of this asset?
⚠ Common exam trap
Watch out — candidates often confuse inherent risk with residual risk or with control cost, which leads to understating exposure before controls are evaluated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The likelihood and impact of loss assuming no controls are in place, derived from the threat environment and the asset's value and exposure.
Inherent risk is the exposure that exists before controls are applied, built from the threat environment and the value and exposure of the asset. For a mobile banking app holding PII and processing payments, the practitioner must assess realistic threat events and their potential impacts without crediting existing safeguards. This baseline enables meaningful comparison once control effectiveness is evaluated and residual risk is determined.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The likelihood and impact of loss assuming no controls are in place, derived from the threat environment and the asset's value and exposure.
Why this is correct
Inherent risk is assessed before considering the mitigating effect of controls, using the threat landscape, asset value, and exposure. For this mobile banking app, that means evaluating realistic threat events against the PII and payment data it handles, independent of any existing security measures. This gives management a baseline against which control effectiveness and residual risk can later be compared.
- ✗
The aggregate cost of the security controls deployed to protect the mobile application and its supporting cloud infrastructure.
Why it's wrong here
Control cost is an input to cost-benefit analysis of risk treatment, not a measure of inherent risk. Inherent risk concerns the possibility and magnitude of loss from threat events, not the money spent to prevent them. Substituting control spend for risk exposure would confuse investment levels with actual exposure and could lead to under- or over-investment decisions.
- ✗
The likelihood and impact of loss after all implemented controls have been applied and validated by internal audit.
Why it's wrong here
This describes residual risk, not inherent risk. Residual risk is what remains after controls are applied and tested. The scenario explicitly asks for the inherent risk before controls are considered, so using post-control figures would understate the exposure and mislead management about the true baseline. Internal audit validation is also not a prerequisite for quantifying inherent risk.
- ✗
The maximum regulatory fine the firm could face if the application suffered a data breach involving customer PII.
Why it's wrong here
A regulatory fine is only one potential impact component and is contingent on a breach occurring. Inherent risk encompasses the full range of likelihood and impact, including financial, reputational, operational, and legal consequences. Using only the maximum fine as the risk measure ignores probability and other impacts, producing an incomplete and potentially misleading risk picture.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.