Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is mapping identified IT risks to the organization's risk taxonomy. A risk has been logged for 'unauthorized access to the HR system resulting from excessive user privileges.' Under which risk category should this be classified?

⚠ Common exam trap

The trap here is categorizing by downstream impact such as a potential fine rather than by the root cause of the risk event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Operational risk, because it arises from inadequate internal processes and access controls.

Risk categorization should reflect the root cause of the risk event. Excessive user privileges are a failure of internal access management processes, which places the risk in the operational risk category. This classification drives treatment toward entitlement reviews, least-privilege enforcement, and segregation-of-duties controls. Compliance and financial consequences may follow, but they are impacts, not the originating category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Operational risk, because it arises from inadequate internal processes and access controls.

    Why this is correct

    Operational risk covers losses from failed or inadequate internal processes, people, and systems. Excessive user privileges represent a control design or enforcement failure within the HR system's access management process. This categorization correctly directs treatment toward entitlement reviews, least-privilege enforcement, and segregation-of-duties controls rather than toward regulatory or strategic responses.

  • ✗

    Financial risk, because a data breach could result in monetary losses and fines.

    Why it's wrong here

    Financial risk typically refers to losses from market, credit, or liquidity exposures. Although a breach can have monetary consequences, the root cause here is an access control deficiency, which is operational in nature. Labeling it financial would obscure the process and control failure that treatment must address, and it would misalign the risk with the correct remediation owners.

  • ✗

    Strategic risk, because workforce data supports long-term talent planning.

    Why it's wrong here

    Strategic risk relates to decisions about markets, products, and long-term direction. Excessive user privileges in an HR system is a control weakness affecting confidentiality of employee data, not a strategic positioning issue. Classifying it as strategic would misdirect treatment toward business planning rather than access management and segregation of duties remediation.

  • ✗

    Compliance risk, because HR data is subject to privacy regulations.

    Why it's wrong here

    Compliance risk concerns failure to meet laws, regulations, or contractual obligations. While excessive privileges could contribute to a privacy violation, the risk as described is rooted in access control weakness, not a regulatory requirement gap. Categorizing it as compliance could lead to a policy review instead of fixing the underlying entitlement problem.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.