mediumMultiple SelectObjective-mapped
CRISC Practice Question: A risk manager is facilitating a risk…
A risk manager is facilitating a risk identification workshop for a new cloud migration initiative. Which TWO techniques are most effective for identifying potential IT risks at this stage?
⚠ Common exam trap
A common mix-up: candidates confuse risk identification (discovering what could go wrong) with risk analysis (quantifying likelihood/impact) or risk evaluation (comparing against criteria), leading candidates to select ALE calculation or cost-benefit analysis as identification techniques.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Interviewing business unit managers and IT architects
Interviewing business unit managers and IT architects (Option B) is effective because it leverages domain expertise to surface operational and technical risks specific to the cloud migration, such as data residency constraints, API dependencies, or shared responsibility model gaps. This qualitative technique captures tacit knowledge that quantitative methods or automated scans cannot, making it ideal for the early identification stage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Calculating the annualized loss expectancy (ALE) for each identified risk
Why it's wrong here
ALE calculation is part of quantitative risk analysis, which follows risk identification.
- ✓
Interviewing business unit managers and IT architects
Why this is correct
Stakeholder interviews elicit operational threats and business concerns.
- ✗
Conducting a cost-benefit analysis of security controls
Why it's wrong here
Cost-benefit analysis is performed later in the risk assessment process, not during initial identification.
- ✓
Reviewing post-incident reports from previous cloud migrations
Why this is correct
Historical incident data provides real-world threat scenarios and vulnerabilities.
- ✗
Performing a vulnerability scan on the existing infrastructure
Why it's wrong here
Vulnerability scanning is a technical assessment focusing only on vulnerabilities, not full risk scenarios.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.