Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

A global logistics company's risk practitioner is identifying risks for a new customs-clearance application. She wants to ensure the risk identification is complete before moving to analysis. Which of the following approaches BEST supports completeness of the risk identification?

⚠ Common exam trap

The trap here is equating a technical scan or documentation review with complete risk identification, when completeness requires cross-functional and taxonomy-driven coverage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Facilitating structured workshops with business, IT, compliance, and third-party representatives using a risk taxonomy as a prompt

Complete risk identification requires broad, structured input across business, technology, compliance, and third-party perspectives. A facilitated workshop using a risk taxonomy as a prompt systematically covers categories and surfaces interdependencies that single-source methods miss. Documentation reviews, vulnerability scans, and individual interviews each provide narrow slices and cannot by themselves ensure completeness before analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Running an automated vulnerability scan against the application's internet-facing components and importing the results

    Why it's wrong here

    A vulnerability scan identifies technical weaknesses in exposed components but says nothing about business process risk, regulatory exposure, third-party dependencies, or insider threats. It is a useful input but far too narrow to support complete risk identification for a customs-clearance application that spans multiple parties and jurisdictions.

  • ✗

    Reviewing only the application's architecture diagrams and data flow documentation produced by the development team

    Why it's wrong here

    Architecture and data flow documentation reveal technical components but omit business process, third-party, regulatory, and human factors. Relying on it alone leaves significant categories of risk unidentified. Completeness requires inputs from multiple sources, including business owners and external parties, not just the development team's technical artifacts.

  • ✗

    Interviewing the application's lead developer about the technologies and frameworks used to build the system

    Why it's wrong here

    Interviewing a single developer yields a technical view limited to that person's knowledge and role. It misses business impact, compliance obligations, vendor risk, and operational concerns. One interview cannot provide the breadth needed for complete risk identification across a cross-border customs application.

  • ✓

    Facilitating structured workshops with business, IT, compliance, and third-party representatives using a risk taxonomy as a prompt

    Why this is correct

    Structured workshops that bring together business, IT, compliance, and third-party perspectives, prompted by a risk taxonomy, systematically surface risks across categories that no single group would identify alone. The taxonomy prevents gaps and the cross-functional dialogue exposes interdependencies, making this the most complete approach before analysis begins.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.