CRISC IT Risk Assessment Practice Question
A risk practitioner is reviewing the risk register for a cloud-based customer relationship management (CRM) system. The register contains several entries, and the practitioner must identify which entries represent inherent risk rather than residual risk. Which two of the following entries are examples of inherent risk? (Choose two.)
⚠ Common exam trap
The trap here is equating any risk register entry with inherent risk, when entries that mention implemented controls or control effectiveness actually describe residual risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CRM system stores customer personally identifiable information, and a breach could result in regulatory fines.
Inherent risk is the level of risk before any controls are applied. The entry about the hurricane-prone data center with no redundancy and the entry about storing personally identifiable information with potential regulatory fines both describe raw exposures without reference to mitigating controls. The other entries mention implemented controls, control effectiveness reports, or recovery plans, which relate to residual risk after treatment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The CRM system stores customer personally identifiable information, and a breach could result in regulatory fines.
Why this is correct
This entry describes the inherent exposure associated with storing sensitive data and the potential regulatory consequences. It does not mention any controls that would reduce the risk, so it represents the raw risk before mitigation. Inherent risk includes the value of the asset and the impact of a threat event, which this entry captures through the data sensitivity and fine potential.
- ✗
The vendor's SOC 2 report shows no exceptions, and the risk is considered acceptable.
Why it's wrong here
This entry reflects a control assessment and an acceptance decision, which pertain to residual risk. A clean SOC 2 report indicates that controls are operating effectively, reducing the risk to an acceptable level. It does not describe the inherent exposure before controls. Therefore, it is not an example of inherent risk but rather evidence of effective risk treatment and acceptance.
- ✗
The organization has a disaster recovery plan that is tested annually and meets recovery objectives.
Why it's wrong here
This entry describes a control that mitigates risk, specifically a tested disaster recovery plan. It indicates that the organization has implemented measures to reduce the impact of disruptions. Because it focuses on the control environment and its effectiveness, it relates to residual risk rather than inherent risk. It does not represent the unmitigated exposure of the CRM system.
- ✓
The CRM vendor's data center is located in a region prone to hurricanes, and no redundancy is currently in place.
Why this is correct
This entry describes a risk that exists before any controls are applied. The geographic location and lack of redundancy represent the raw exposure of the system to a natural disaster. Inherent risk is assessed without considering existing controls, so this scenario qualifies. It highlights the potential impact if no mitigating measures are implemented, which is the definition of inherent risk.
- ✗
After implementing multi-factor authentication and encryption, the likelihood of unauthorized access is rated low.
Why it's wrong here
This entry reflects residual risk because it explicitly states that controls such as multi-factor authentication and encryption have been implemented and the likelihood has been reduced. Residual risk is the remaining risk after controls are applied. The scenario describes the outcome of risk treatment, not the original exposure, so it does not represent inherent risk.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.