Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is facilitating a workshop to identify risks for a new customer-facing payment portal. The CISO wants the exercise to capture risks arising from both internal process weaknesses and external threat sources without producing an unmanageable list. Which approach is MOST appropriate for structuring the risk identification effort?

⚠ Common exam trap

The trap here is equating thorough risk identification with either technical testing or open-ended brainstorming, when the real requirement is a structured pairing of threat sources with assets and processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a structured technique such as scenario analysis that pairs threat sources with affected assets and business processes.

Structured scenario analysis pairs credible threat sources with the assets and business processes they could affect, producing a comprehensive yet bounded set of risk statements. This technique captures internal weaknesses such as process gaps and external sources such as criminal actors in a consistent format, supports later likelihood and impact assessment, and keeps the register manageable. Testing, unrestricted brainstorming, and vendor templates each fall short on coverage, consistency, or relevance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a structured technique such as scenario analysis that pairs threat sources with affected assets and business processes.

    Why this is correct

    Scenario analysis systematically combines plausible threat sources with the assets and business processes they could affect, producing a structured set of risk statements that spans internal weaknesses and external actors. This disciplined pairing keeps the list focused on credible combinations rather than an exhaustive inventory, and it aligns directly with the risk scenario structure used in ISACA guidance, making the outputs suitable for subsequent assessment and treatment.

  • ✗

    Conduct a penetration test of the portal and register only the findings that result in successful exploitation.

    Why it's wrong here

    Penetration testing validates exploitable weaknesses in a deployed environment but covers only a narrow slice of the risk universe. It cannot surface process-level risks such as inadequate change management, unclear ownership, or third-party dependencies that have no directly testable surface. Restricting the register to exploitation findings would leave significant internal and external risk sources unidentified, and the exercise would occur too late to influence design decisions.

  • ✗

    Ask each workshop participant to submit an unrestricted list of every concern they have about the portal.

    Why it's wrong here

    Unstructured brainstorming may surface valuable insights, but it produces overlapping, inconsistently scoped items and tends to reflect the loudest voices or individual experience rather than the actual risk landscape. Without a framework pairing threats, assets, and business processes, the resulting register is difficult to assess, deduplicate, or prioritize. The stated goal of capturing both internal and external sources without an unmanageable list is better served by a structured method.

  • ✗

    Adopt the vendor's standard risk register template and record the categories the vendor already populated.

    Why it's wrong here

    A vendor template reflects generic or another organization's risk profile, not this portal's specific architecture, data flows, and business dependencies. Populating the register from a template invites boilerplate risks that do not apply and omits risks unique to the new environment, such as integration with existing identity systems or payment card data handling. It also bypasses the stakeholder engagement that makes identification credible and actionable.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.