Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is categorizing IT risks for a manufacturing company. Which of the following risks would be classified as an 'operational' IT risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk of production line downtime due to a server failure

Operational IT risks relate to the day-to-day functioning of IT systems and processes. Production line downtime due to a system failure directly impacts operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk of financial loss from a ransomware payment

    Why it's wrong here

    A ransomware payment is a financial-loss consequence, mapping to financial rather than operational risk. It is tempting because ransomware disrupts service delivery, yet CRISC categorises risk by the affected business objective, and monetary loss sits under financial risk.

  • ✗

    Risk of non-compliance with GDPR for customer data stored in the EU

    Why it's wrong here

    GDPR non-compliance is a regulatory and legal exposure, categorised as compliance risk, not operational. It is tempting because the breach often stems from operational failures, but CRISC classifies by the obligation breached, and regulatory penalties fall under compliance.

  • ✓

    Risk of production line downtime due to a server failure

    Why this is correct

    Server failure causing production line downtime is an operational IT risk because it concerns the day-to-day reliability and availability of systems supporting business processes. This satisfies the stem's operational category, which covers disruptions to service delivery and processing, rather than strategic, compliance or external risk domains.

  • ✗

    Risk of reputational damage from a data breach

    Why it's wrong here

    Reputational damage is categorised as strategic or reputational risk, not operational. It is tempting because a data breach usually originates from an operational control failure, yet CRISC assigns the risk to the business objective ultimately affected, which here is reputation.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.