CRISC IT Risk Identification Practice Question
A global logistics company's risk practitioner is identifying risks for a new customs-clearance application. She wants to ensure the risk identification is complete before moving to analysis. Which of the following approaches BEST supports completeness of the risk identification?
⚠ Common exam trap
The trap here is equating a technical scan or documentation review with complete risk identification, when completeness requires cross-functional and taxonomy-driven coverage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Facilitating structured workshops with business, IT, compliance, and third-party representatives using a risk taxonomy as a prompt
Complete risk identification requires broad, structured input across business, technology, compliance, and third-party perspectives. A facilitated workshop using a risk taxonomy as a prompt systematically covers categories and surfaces interdependencies that single-source methods miss. Documentation reviews, vulnerability scans, and individual interviews each provide narrow slices and cannot by themselves ensure completeness before analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Running an automated vulnerability scan against the application's internet-facing components and importing the results
Why it's wrong here
A vulnerability scan identifies technical weaknesses in exposed components but says nothing about business process risk, regulatory exposure, third-party dependencies, or insider threats. It is a useful input but far too narrow to support complete risk identification for a customs-clearance application that spans multiple parties and jurisdictions.
- ✗
Reviewing only the application's architecture diagrams and data flow documentation produced by the development team
Why it's wrong here
Architecture and data flow documentation reveal technical components but omit business process, third-party, regulatory, and human factors. Relying on it alone leaves significant categories of risk unidentified. Completeness requires inputs from multiple sources, including business owners and external parties, not just the development team's technical artifacts.
- ✗
Interviewing the application's lead developer about the technologies and frameworks used to build the system
Why it's wrong here
Interviewing a single developer yields a technical view limited to that person's knowledge and role. It misses business impact, compliance obligations, vendor risk, and operational concerns. One interview cannot provide the breadth needed for complete risk identification across a cross-border customs application.
- ✓
Facilitating structured workshops with business, IT, compliance, and third-party representatives using a risk taxonomy as a prompt
Why this is correct
Structured workshops that bring together business, IT, compliance, and third-party perspectives, prompted by a risk taxonomy, systematically surface risks across categories that no single group would identify alone. The taxonomy prevents gaps and the cross-functional dialogue exposes interdependencies, making this the most complete approach before analysis begins.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.