CRISC IT Risk Identification Practice Question
An organization is updating its IT risk universe. Which of the following is the MOST important factor to consider when defining the universe?
⚠ Common exam trap
CRISC often tests the misconception that risk identification should be filtered by likelihood, budget, or historical occurrence, when in fact the universe must be comprehensive before any prioritization occurs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks
The IT risk universe should be comprehensive — it must capture all potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks. Defining the universe is an identification exercise, not a prioritization exercise; filtering by likelihood, budget, or past occurrence at this stage would create blind spots and undermine the risk register's completeness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Historical loss data only
Why it's wrong here
Historical loss data alone omits emerging, regulatory and third-party risks never yet realised. It tempts because loss data underpins quantitative risk assessment and capital modelling, where it is a valid input once the universe is already defined.
- ✓
All potential IT risks regardless of likelihood, including cyber, operational, compliance, third-party, project, and change risks
Why this is correct
Defining the risk universe requires capturing every plausible IT risk before any assessment or scoring occurs. Restricting it to high-likelihood items would blind the organisation to low-probability, high-impact threats across cyber, operational, compliance, third-party, project and change domains, undermining the completeness the universe demands.
- ✗
Risks that are within the current budget to mitigate
Why it's wrong here
Budget constrains treatment, not identification; the risk universe must capture all plausible risk events regardless of affordability, or emerging exposures are silently excluded. It tempts because cost-feasibility filters drive remediation prioritisation, where budget-limited scope is genuinely correct.
- ✗
Only risks that have been realized in the past year
Why it's wrong here
Restricting the universe to risks realised in the past year excludes plausible, unmanifested threats, so it cannot support forward-looking risk assessment. It is tempting because incident history genuinely informs likelihood estimates and control validation, and a lessons-learned review would rightly draw on prior-year events — but that is an input, not the scope definition.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.