Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

An organization is updating its IT risk universe. Which of the following is the MOST important factor to consider when defining the universe?

⚠ Common exam trap

CRISC often tests the misconception that risk identification should be filtered by likelihood, budget, or historical occurrence, when in fact the universe must be comprehensive before any prioritization occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks

The IT risk universe should be comprehensive — it must capture all potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks. Defining the universe is an identification exercise, not a prioritization exercise; filtering by likelihood, budget, or past occurrence at this stage would create blind spots and undermine the risk register's completeness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Historical loss data only

    Why it's wrong here

    Historical loss data alone omits emerging, regulatory and third-party risks never yet realised. It tempts because loss data underpins quantitative risk assessment and capital modelling, where it is a valid input once the universe is already defined.

  • ✓

    All potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks

    Why this is correct

    Defining the risk universe requires capturing every plausible IT risk before any assessment or scoring occurs. Restricting it to high-likelihood items would blind the organisation to low-probability, high-impact threats across cyber, operational, compliance, third-party, project and change domains, undermining the completeness the universe demands.

  • ✗

    Risks that are within the current budget to mitigate

    Why it's wrong here

    Budget constrains treatment, not identification; the risk universe must capture all plausible risk events regardless of affordability, or emerging exposures are silently excluded. It tempts because cost-feasibility filters drive remediation prioritisation, where budget-limited scope is genuinely correct.

  • ✗

    Only risks that have been realized in the past year

    Why it's wrong here

    Restricting the universe to risks realised in the past year excludes plausible, unmanifested threats, so it cannot support forward-looking risk assessment. It is tempting because incident history genuinely informs likelihood estimates and control validation, and a lessons-learned review would rightly draw on prior-year events — but that is an input, not the scope definition.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.