CRISC IT Risk Identification Practice Question
An organization's board has set a risk appetite statement that says: 'We accept moderate levels of operational risk but will not tolerate any compliance violations.' During risk identification, which type of risk should be given the HIGHEST priority?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance risks
Given the zero-tolerance for compliance violations, compliance risks must be prioritized to ensure they are identified and managed accordingly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reputational risks
Why it's wrong here
Reputational risk is not explicitly addressed in the appetite statement.
- ✓
Compliance risks
Why this is correct
Zero tolerance makes compliance risks the highest priority.
- ✗
Operational risks
Why it's wrong here
Moderate acceptance means they are lower priority than compliance.
- ✗
Strategic risks
Why it's wrong here
Strategic risks are not specifically called out in the appetite statement.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.