Courseiva
IT Risk Identification →hardMultiple Select

CRISC IT Risk Identification Practice Question

A risk practitioner is performing a risk assessment on an organization's use of a cloud-based payroll platform. The practitioner is identifying the inherent risk factors that exist before any controls are considered. Which TWO of the following are inherent risk factors for this scenario? (Choose two.)

⚠ Common exam trap

The trap here is counting strong existing controls as inherent risk factors, which reverses the order of inherent and residual risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Payroll processing depends on a single third-party provider with no in-house fallback process.

Inherent risk factors describe the exposure that exists by virtue of the assets, data, and dependencies involved, before any protective measures are applied. Sensitive employee data and dependence on a single provider without fallback both raise potential impact and likelihood regardless of controls. Audit reports, multifactor authentication, and penetration testing are control evidence that belongs in the residual risk analysis, not the inherent assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Payroll processing depends on a single third-party provider with no in-house fallback process.

    Why this is correct

    Concentration and lack of redundancy are inherent characteristics of the operating model, not controls. If the provider suffers an outage or fails, payroll cannot run and employees go unpaid, which is a business impact that exists independent of any protective measure. This dependency is therefore an inherent risk factor that must be captured before evaluating the vendor's resiliency controls or the organization's contingency arrangements.

  • ✗

    The vendor performs quarterly penetration testing of its external infrastructure.

    Why it's wrong here

    Penetration testing is a detective and validation control that identifies weaknesses; it does not create the underlying exposure being assessed. It belongs in the control evaluation that follows inherent risk rating. Treating testing frequency as an inherent factor would confuse causes of risk with responses to risk, and it could mislead leadership into believing the organization's exposure is lower before any control effectiveness has actually been judged.

  • ✗

    The vendor's most recent SOC 2 Type II report shows no exceptions in its change management controls.

    Why it's wrong here

    A clean SOC 2 report describes the effectiveness of a control environment, which is evidence used in residual risk assessment, not an inherent risk factor. Including it here confuses control assurance with underlying exposure. The practitioner should record the report as evidence that reduces assessed likelihood or impact after controls, and it would be inappropriate to treat a favorable audit result as a driver of inherent risk.

  • ✓

    The payroll platform stores direct deposit banking details and national identification numbers for all employees.

    Why this is correct

    Data sensitivity is a classic inherent risk factor: the presence of banking details and national identifiers raises the potential magnitude of any confidentiality breach regardless of controls. Inherent risk is assessed before controls, so the mere concentration of regulated personal data in one vendor platform increases exposure. This factor would remain relevant even if the vendor's controls were later rated as strong, because it describes the asset's nature rather than protection.

  • ✗

    The organization enforces multifactor authentication for all administrator access to the payroll platform.

    Why it's wrong here

    Multifactor authentication is a preventive control that reduces the likelihood of credential compromise. Because inherent risk is defined as exposure before controls, this measure is excluded from the inherent assessment and instead informs the residual rating. Listing it as an inherent factor would double-count the control and understate the organization's true exposure if the control later failed or was misconfigured.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.