CRISC IT Risk Identification Practice Question
A utility company's risk practitioner is defining the scope of a risk identification exercise for a new advanced metering infrastructure. The practitioner must decide which elements to include. Which action BEST ensures the identification exercise covers the full risk landscape?
⚠ Common exam trap
The trap here is equating the project's technical boundary with the risk boundary, when the risk landscape extends across processes, vendors, and dependencies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include internal processes, third parties, and dependencies that interact with the new infrastructure.
A complete identification exercise follows the service and data flows rather than the project's technical boundary. For advanced metering infrastructure, that means including internal billing and outage processes, third-party communication providers, field operations, and regulatory dependencies, because risks frequently arise at these interfaces. A technology-only scope, a register-driven scope, or a deferred timeline would all leave material exposures unidentified or identified too late to influence design.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Limit the exercise to the technologies the project team will deploy directly.
Why it's wrong here
Restricting scope to directly deployed technologies ignores interfaces with legacy billing systems, third-party communications providers, field crews, and regulators that can introduce risk to the metering program. Risks often emerge at integration points rather than inside a single component, so this narrow scope would leave significant exposures unidentified. It also sets a precedent that later phases of the program fall outside risk review, weakening governance over the initiative.
- ✗
Base scope on the risk categories already recorded in the enterprise risk register.
Why it's wrong here
An existing register reflects past assessments and may not contain categories relevant to a new metering program, such as operational technology convergence or smart meter firmware supply chain risk. Anchoring scope to it creates a closed loop that perpetuates prior blind spots. The practitioner should instead derive scope from the program's objectives and dependencies, then map findings back into the register to enrich it.
- ✗
Defer identification until the infrastructure has been operating for one full billing cycle.
Why it's wrong here
Waiting a full billing cycle means risks are identified only after they have had the opportunity to materialize, which defeats the purpose of proactive identification. Design-stage decisions about segmentation, firmware update mechanisms, and vendor contracts are far cheaper to influence than post-deployment fixes. Deferral also conflicts with the principle that risk identification should inform project and architecture choices before commitments are locked in.
- ✓
Include internal processes, third parties, and dependencies that interact with the new infrastructure.
Why this is correct
Advanced metering infrastructure depends on internal billing and outage processes, communications vendors, field operations, and regulatory reporting, so identifying risks across these interactions exposes exposures that a technology-only view misses. This scope supports end-to-end risk scenarios, lets the practitioner trace cascading effects from a meter compromise through to customer billing, and aligns the identification exercise with how the utility actually delivers service.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.