CRISC IT Risk Identification Practice Question
A retail bank's risk practitioner is assessing the risk that a core banking system outage could halt transaction processing. The practitioner wants to identify the specific conditions or characteristics of the environment that could allow the outage to occur or worsen its effect, rather than the events themselves. Which of the following is the practitioner identifying?
⚠ Common exam trap
The trap here is conflating vulnerabilities with threat events, because both appear in risk statements; the distinguishing question is whether the item is a weakness that exists in the environment or an occurrence that acts upon it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerabilities
Risk identification separates the threat, which is what can cause harm, from the vulnerability, which is the condition that allows the threat to succeed or magnifies the consequence. The practitioner's focus on characteristics of the environment that permit or worsen an outage therefore points to vulnerabilities. Documenting these conditions is what enables the organization to select controls that address the actual weaknesses in the core banking environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Vulnerabilities
Why this is correct
Vulnerabilities are the weaknesses or conditions in people, processes, technology, or the environment that a threat can exploit to cause harm. Characteristics such as an end-of-life operating system, an untested failover process, or a single network path are exactly these conditions. Identifying them lets the practitioner connect specific threats to the banking system and target controls that reduce the chance or severity of an outage.
- ✗
Threat events
Why it's wrong here
Threat events are the actual occurrences, such as a hardware failure, a cyberattack, or a natural disaster, that can cause harm. The practitioner in this scenario is looking for the conditions that permit or amplify such occurrences, not the occurrences themselves. Listing threat events alone would describe what might happen without explaining why the environment is susceptible, leaving the risk assessment incomplete for control design.
- ✗
Risk appetite statements
Why it's wrong here
A risk appetite statement expresses how much risk the organization is willing to accept in pursuit of its objectives. It is a governance input that guides how much mitigation is warranted, not an inventory of the environmental conditions that could allow an outage. Confusing the two would lead the practitioner to document management's tolerance instead of the technical and procedural weaknesses that need remediation.
- ✗
Key performance indicators
Why it's wrong here
Key performance indicators measure how well processes are achieving their objectives, such as transaction throughput or system availability percentages. They can reveal that availability is degrading, but they do not describe the underlying conditions that make the system susceptible to an outage. Using them in place of a vulnerability assessment would describe symptoms rather than root causes and would not support targeted control selection.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.