Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

A hospital network is identifying IT risks for its newly deployed medical imaging archive. The risk practitioner wants to document risks in a way that links each risk to the business process it could disrupt. Which CRISC concept is the practitioner applying when connecting an IT risk to the business objective it threatens?

⚠ Common exam trap

A common mix-up: candidates confuse an assurance activity like scanning or testing, which finds weaknesses, with the identification activity that ties a risk to the business objective it endangers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk identification through business process mapping.

Connecting each IT risk to the business process and objective it can disrupt is business process mapping within risk identification. It shifts the conversation from technical faults to business consequences, enabling the hospital to prioritize risks that affect patient care and regulatory obligations. This linkage is what makes a risk register useful for decision making rather than a mere inventory of technical issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk identification through business process mapping.

    Why this is correct

    Linking an IT risk to the business process and objective it can disrupt is the essence of business process mapping during risk identification. It ensures risks are framed in terms of business impact, not just technical faults, so prioritization reflects what the hospital actually cares about, such as timely diagnosis and patient safety. This business-centric framing is a core CRISC expectation.

  • ✗

    Penetration testing of the imaging network.

    Why it's wrong here

    Penetration testing attempts to exploit weaknesses to demonstrate real attack paths. It is an assurance activity that validates controls and reveals exploitable conditions, but it does not document the relationship between an IT risk and the business process it threatens. The practitioner's goal is business-aligned risk framing, which penetration testing alone does not deliver.

  • ✗

    Control self-assessment of the imaging archive configuration.

    Why it's wrong here

    A control self-assessment evaluates whether existing controls are designed and operating effectively. It is a testing and assurance activity that occurs after risks are identified, not the mechanism that connects a risk to a business process. Here the practitioner is still framing which business objectives are exposed, so a control self-assessment is premature and answers a different question.

  • ✗

    Vulnerability scanning of the archive servers.

    Why it's wrong here

    Vulnerability scanning discovers technical weaknesses in hosts and applications. It produces a list of findings but does not by itself tie those weaknesses to the clinical or business processes they could interrupt. Scanning is a valuable input to risk identification, yet it addresses technical exposure rather than the business linkage the practitioner is trying to establish.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.