CRISC IT Risk Identification Practice Question
A risk practitioner at a regional bank is building a risk register and needs to classify each identified risk by its origin. The practitioner documents a risk that a critical payment switch will fail during peak transaction volume because a fan assembly in the switch has exceeded its mean time between failures. Which risk category BEST applies to this entry?
⚠ Common exam trap
The trap here is assuming that any risk affecting a critical system must be strategic or compliance-related, when the actual driver is routine technology operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IT operational risk
The scenario describes a loss event caused by the routine operation of technology infrastructure, so it belongs in the IT operational risk category. That classification supports aggregation with other availability and performance risks, drives appropriate preventive controls such as condition-based maintenance and redundant components, and allows residual risk to be measured after treatment. Strategic, compliance, and inherent risk labels describe different dimensions and would misdirect the response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IT operational risk
Why this is correct
Hardware component failure that disrupts transaction processing is an IT operational risk because it arises from the day-to-day running of technology infrastructure rather than from a strategic, compliance, or external event. Classifying it here lets the bank aggregate similar availability risks, apply preventive maintenance controls, and measure the residual exposure after those controls, which is exactly what the risk register entry requires.
- ✗
Inherent risk
Why it's wrong here
Inherent risk describes the level of risk that exists before any controls or mitigations are applied, not the source or type of the risk. The failing fan assembly is a specific cause of loss, and inherent risk does not classify causes. Labeling this entry as inherent risk would confuse the measurement of risk exposure with its origin, and the register would lose the ability to group similar hardware-driven failures for treatment.
- ✗
Strategic risk
Why it's wrong here
Strategic risk relates to adverse decisions about business direction, markets, or major investments that undermine the organization's goals. A single component wearing out is a tactical infrastructure concern, not a consequence of strategy. Filing it as strategic risk would inflate the strategic risk profile and leave the operations team without a clear signal to fund spare parts or redundancy for the payment switch.
- ✗
Compliance risk
Why it's wrong here
Compliance risk covers the possibility of legal or regulatory sanctions, financial loss, or reputational damage from failing to comply with laws, regulations, or standards. A failing fan assembly does not by itself breach any regulation, so this classification misdirects treatment toward policy and audit activities instead of the maintenance and redundancy controls the payment switch actually needs to prevent an outage.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.