Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

A retail bank's risk practitioner is assessing the risk that a core banking system outage could halt transaction processing. The practitioner wants to identify the specific conditions or characteristics of the environment that could allow the outage to occur or worsen its effect, rather than the events themselves. Which of the following is the practitioner identifying?

⚠ Common exam trap

The trap here is conflating vulnerabilities with threat events, because both appear in risk statements; the distinguishing question is whether the item is a weakness that exists in the environment or an occurrence that acts upon it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerabilities

Risk identification separates the threat, which is what can cause harm, from the vulnerability, which is the condition that allows the threat to succeed or magnifies the consequence. The practitioner's focus on characteristics of the environment that permit or worsen an outage therefore points to vulnerabilities. Documenting these conditions is what enables the organization to select controls that address the actual weaknesses in the core banking environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Vulnerabilities

    Why this is correct

    Vulnerabilities are the weaknesses or conditions in people, processes, technology, or the environment that a threat can exploit to cause harm. Characteristics such as an end-of-life operating system, an untested failover process, or a single network path are exactly these conditions. Identifying them lets the practitioner connect specific threats to the banking system and target controls that reduce the chance or severity of an outage.

  • ✗

    Threat events

    Why it's wrong here

    Threat events are the actual occurrences, such as a hardware failure, a cyberattack, or a natural disaster, that can cause harm. The practitioner in this scenario is looking for the conditions that permit or amplify such occurrences, not the occurrences themselves. Listing threat events alone would describe what might happen without explaining why the environment is susceptible, leaving the risk assessment incomplete for control design.

  • ✗

    Risk appetite statements

    Why it's wrong here

    A risk appetite statement expresses how much risk the organization is willing to accept in pursuit of its objectives. It is a governance input that guides how much mitigation is warranted, not an inventory of the environmental conditions that could allow an outage. Confusing the two would lead the practitioner to document management's tolerance instead of the technical and procedural weaknesses that need remediation.

  • ✗

    Key performance indicators

    Why it's wrong here

    Key performance indicators measure how well processes are achieving their objectives, such as transaction throughput or system availability percentages. They can reveal that availability is degrading, but they do not describe the underlying conditions that make the system susceptible to an outage. Using them in place of a vulnerability assessment would describe symptoms rather than root causes and would not support targeted control selection.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.