Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner at a regional bank is building a risk register and needs to classify each identified risk by its origin. The practitioner documents a risk that a critical payment switch will fail during peak transaction volume because a fan assembly in the switch has exceeded its mean time between failures. Which risk category BEST applies to this entry?

⚠ Common exam trap

The trap here is assuming that any risk affecting a critical system must be strategic or compliance-related, when the actual driver is routine technology operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IT operational risk

The scenario describes a loss event caused by the routine operation of technology infrastructure, so it belongs in the IT operational risk category. That classification supports aggregation with other availability and performance risks, drives appropriate preventive controls such as condition-based maintenance and redundant components, and allows residual risk to be measured after treatment. Strategic, compliance, and inherent risk labels describe different dimensions and would misdirect the response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IT operational risk

    Why this is correct

    Hardware component failure that disrupts transaction processing is an IT operational risk because it arises from the day-to-day running of technology infrastructure rather than from a strategic, compliance, or external event. Classifying it here lets the bank aggregate similar availability risks, apply preventive maintenance controls, and measure the residual exposure after those controls, which is exactly what the risk register entry requires.

  • ✗

    Inherent risk

    Why it's wrong here

    Inherent risk describes the level of risk that exists before any controls or mitigations are applied, not the source or type of the risk. The failing fan assembly is a specific cause of loss, and inherent risk does not classify causes. Labeling this entry as inherent risk would confuse the measurement of risk exposure with its origin, and the register would lose the ability to group similar hardware-driven failures for treatment.

  • ✗

    Strategic risk

    Why it's wrong here

    Strategic risk relates to adverse decisions about business direction, markets, or major investments that undermine the organization's goals. A single component wearing out is a tactical infrastructure concern, not a consequence of strategy. Filing it as strategic risk would inflate the strategic risk profile and leave the operations team without a clear signal to fund spare parts or redundancy for the payment switch.

  • ✗

    Compliance risk

    Why it's wrong here

    Compliance risk covers the possibility of legal or regulatory sanctions, financial loss, or reputational damage from failing to comply with laws, regulations, or standards. A failing fan assembly does not by itself breach any regulation, so this classification misdirects treatment toward policy and audit activities instead of the maintenance and redundancy controls the payment switch actually needs to prevent an outage.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.