Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

A small logistics company has no formal risk assessment process. The new IT manager wants to introduce a simple, repeatable method to identify and evaluate IT risks. Which action should the manager take FIRST?

⚠ Common exam trap

The trap here is jumping to tools or testing as the first step, when a repeatable process actually begins with agreed risk criteria and rating scales.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define risk criteria and a common likelihood and impact scale for the organization.

A repeatable risk process depends on agreed criteria and consistent rating scales. Defining these first allows the company to identify, analyze, and evaluate risks in a uniform way, and it makes later tooling or testing meaningful. Purchasing tools, testing systems, or outsourcing decisions before establishing criteria puts technology and activity ahead of methodology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Commission a full penetration test of all external systems.

    Why it's wrong here

    A penetration test examines technical vulnerabilities but does not establish a risk management process or criteria. Results would be difficult to interpret and prioritize without agreed likelihood and impact scales. While testing is valuable, it is a focused technical activity, not the foundational step for creating a repeatable risk assessment method, so it should not come first.

  • ✗

    Outsource all risk decisions to an external consulting firm.

    Why it's wrong here

    Outsourcing decisions removes ownership and leaves the company unable to sustain the process once the engagement ends. The organization still needs internal criteria and understanding to accept and manage risk. Consultants can assist, but the company must own its risk framework. Delegating decisions entirely does not build the repeatable internal capability the manager is trying to create.

  • ✓

    Define risk criteria and a common likelihood and impact scale for the organization.

    Why this is correct

    Establishing risk criteria and shared scales gives everyone a consistent basis for rating and comparing risks. It is the foundation on which identification, analysis, and evaluation depend, and it can be documented simply without expensive tooling. Once criteria exist, the company can repeat the process, track changes, and prioritize treatment. This is the logical first step for building a formal program.

  • ✗

    Purchase an automated governance, risk, and compliance tool.

    Why it's wrong here

    A GRC tool automates an existing process; it does not create one. Without defined risk criteria, scales, and workflows, the tool would simply store inconsistent data. Buying technology before establishing methodology wastes budget and can entrench poor practices. The manager should first define how risks will be identified and evaluated, so tooling is premature at this stage.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.