CRISC IT Risk Assessment Practice Question
A global investment firm maintains a central risk register. The CISO wants to reduce the number of entries by consolidating risks that share the same root cause. Which action BEST supports this goal while preserving the risk register's integrity?
⚠ Common exam trap
The trap here is assuming that fewer register entries always means better risk management, when the real goal is consolidation without loss of traceability or ownership detail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a parent risk for each shared root cause and link the related risk entries as sub-risks, retaining their individual details.
Consolidating by shared root cause is best achieved with a parent-child hierarchy that preserves the details of each underlying risk. This keeps likelihood, impact, ownership, and treatment traceable while reducing clutter at the top level. Deleting, relocating, or asset-merging entries sacrifices granularity, auditability, or aggregation insight, none of which preserves the register's integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Group risks by the asset they affect and merge them into a single risk statement per asset.
Why it's wrong here
Grouping by asset merges risks that may have different threat sources, vulnerabilities, and owners, which destroys the one-to-one mapping between risk statement and root cause. It also obscures accountability because a single asset-level entry cannot be assigned meaningfully to several risk owners. This does not preserve integrity of the register and is not the best consolidation approach.
- ✓
Create a parent risk for each shared root cause and link the related risk entries as sub-risks, retaining their individual details.
Why this is correct
A parent-child structure clusters risks that stem from the same root cause while retaining each entry's likelihood, impact, owner, and treatment. This reduces the apparent volume of top-level entries without losing the granularity needed for treatment and monitoring. It maintains traceability and supports aggregation for reporting to the board, which is exactly what the CISO needs here.
- ✗
Move all low-rated risks to a separate spreadsheet outside the central register.
Why it's wrong here
Moving risks out of the central register fragments the risk data and defeats the purpose of having a single source of truth. Low-rated risks can aggregate into significant exposure, and removing them hides that aggregation from leadership. This does not consolidate by root cause and actually reduces the register's completeness, so it is not appropriate.
- ✗
Delete duplicate entries and rely on the risk owner's memory to recall the original context.
Why it's wrong here
Deleting entries and relying on human recollection removes the audit trail that CRISC requires for risk registers. Without documented context, future assessments cannot reconstruct why a risk was rated or treated a certain way. This is a destructive shortcut that undermines governance and would fail an audit, so it cannot be the best action to preserve integrity.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.