CRISC · domain
IT Risk Identification
Domain 1 of CRISC covers identifying IT risk through asset, threat, vulnerability, and scenario analysis aligned to ISACA's risk scenario template and risk taxonomy. Questions test risk appetite versus capacity versus tolerance, categorization of compliance, operational, and strategic risk, and prioritization of scenarios during risk identification.
Focused practice
Practice IT Risk Identification questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about IT Risk Identification
Be able to build a risk scenario using ISACA's template, classify risks into the correct category, and rank scenarios against appetite and tolerance. The single most important thing is separating risk capacity from risk appetite and tolerance.
Applying the ISACA risk scenario template elements: threat actor, threat type, event, asset, and impact.
Distinguishing risk appetite, risk capacity, and risk tolerance as defined in ISACA guidance.
Categorizing IT risk events into operational, compliance, strategic, and reporting categories.
Prioritizing identified risk scenarios by comparing exposure against stated appetite and tolerance.
Watch out for
Common IT Risk Identification exam traps
- ▸Confusing risk capacity (maximum risk an entity can bear) with risk appetite (amount it is willing to accept).
- ▸Treating a GDPR fine as operational risk rather than compliance risk during categorization.
- ▸Mismatching risk scenario template elements, such as naming the threat actor as the asset or event.
Question index
All IT Risk Identification questions (146)
Click any question to see the full explanation, or start a practice session above.
A risk practitioner is updating the risk register after a third-party security incident. Which of the following is the MOST important information to include in the risk register entry for this third-party risk?
Medium2An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?
Easy3A risk practitioner is reviewing the risk register of an e-commerce company and finds that several risks were identified only through past incident reports. The chief risk officer asks how to broaden risk identification to surface risks that have not yet materialized. Which of the following approaches is MOST effective for identifying emerging and previously unconsidered risks?
Medium4A risk practitioner is performing an external threat environment analysis for a retail chain that accepts card payments. The practitioner wants to identify which external factors should be treated as inputs to the likelihood of payment card data compromise. Which TWO of the following are the MOST appropriate inputs? (Choose two.)
Medium5During the risk identification process, an IT risk universe is defined. Which of the following BEST describes the purpose of an IT risk universe?
Medium6A risk practitioner is categorizing IT risks for a manufacturing company. Which of the following risks would be classified as an 'operational' IT risk?
Medium7A risk practitioner is estimating the likelihood of a ransomware event for a manufacturing firm. The firm has endpoint protection, network segmentation, and offline backups, but the practitioner learns that a third-party maintenance vendor has persistent remote access with shared credentials and no multi-factor authentication. Which of the following BEST explains how this finding should affect the likelihood estimate?
Medium8When developing realistic risk scenarios, which THREE components are essential according to the ISACA risk scenario template?
Medium9A risk practitioner is identifying IT risk scenarios for a new e-commerce platform. The platform will process credit card payments and store customer data. Which TWO of the following are examples of external threats that should be considered in the risk identification process? (Choose two.)
Medium10Which of the following is an example of a 'configuration vulnerability' that should be identified during vulnerability assessment?
Easy11A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?
Hard12A risk manager is categorizing IT risks. Which risk category would a potential fine for violating GDPR be assigned to?
Medium13A risk practitioner at a regional bank is building a risk register and needs to classify each identified risk by its origin. The practitioner documents a risk that a critical payment switch will fail during peak transaction volume because a fan assembly in the switch has exceeded its mean time between failures. Which risk category BEST applies to this entry?
Medium14A risk practitioner is conducting an IT risk assessment for a retail bank's new mobile payment application. The threat landscape includes hacktivists, organized crime, and insiders. The practitioner needs to estimate the likelihood of a data breach. Which of the following factors is MOST important to consider when estimating likelihood?
Medium15An organization has a risk register that includes risks related to regulatory compliance, such as GDPR and SOX. The risk practitioner is now categorizing these risks. Which risk category would BEST fit these compliance-related risks?
Medium16An organization uses threat intelligence feeds from an Information Sharing and Analysis Center (ISAC). What is the PRIMARY benefit of using ISACs?
Easy17A multinational bank is assessing the risk of a distributed denial-of-service (DDoS) attack on its online banking platform. The risk practitioner has identified that the platform is hosted in a single data center with no redundancy. Which of the following BEST describes the relationship between the threat, vulnerability, and risk in this scenario?
Hard18A risk manager at a healthcare organization is identifying risks related to the use of Internet of Medical Things (IoMT) devices. The organization has a large number of legacy devices that cannot be patched. Which of the following is the MOST significant risk factor to consider when assessing the risk of a ransomware attack?
Hard19A risk practitioner at a regional bank is building risk scenarios for the new mobile check deposit feature. The team has identified the event 'attackers exploit a vulnerability in the image processing library to inject malicious code.' Which of the following BEST describes the element that is missing from this risk scenario?
Medium20A risk practitioner is assessing the likelihood that a nation-state actor will exfiltrate intellectual property from an aerospace manufacturer. The practitioner wants to express likelihood using a factor that reflects how attractive the manufacturer is as a target relative to its peers. Which approach BEST supports this?
Hard21An organization's board has set a risk appetite statement that says: 'We accept moderate levels of operational risk but will not tolerate any compliance violations.' During risk identification, which type of risk should be given the HIGHEST priority?
Medium22A risk practitioner is assessing the effectiveness of the control environment supporting an online trading platform. Management asserts that controls are mature, but the practitioner must determine which activities constitute control monitoring rather than one-time assurance. Which TWO of the following activities are examples of ongoing control monitoring? (Choose two.)
Hard23During a threat modeling exercise using the STRIDE methodology, a security analyst identifies a threat where an attacker can modify data in transit between a web server and database. Which STRIDE category does this threat belong to?
Hard24A risk practitioner is identifying risks for an organization that has adopted a bring-your-own-device policy for remote workers. The practitioner wants to document vulnerabilities that increase the likelihood of a data loss event. Which TWO of the following are MOST appropriately classified as vulnerabilities in this scenario? (Choose two.)
Medium25Which of the following BEST describes the difference between a threat actor who is a 'hacktivist' and one who is an 'organized crime' actor?
Medium26A risk practitioner at a payments processor is reviewing the organization's risk register and notices that several risk entries describe only the consequence, such as 'customer data is exposed.' The practitioner wants each entry to follow the ISACA risk scenario structure. Which of the following should the practitioner add to each entry to complete the scenario?
Hard27During a vulnerability assessment, a risk practitioner identifies that a web application is vulnerable to SQL injection, which is listed in the OWASP Top 10. Which type of vulnerability identification technique MOST likely discovered this issue?
Medium28When developing IT risk scenarios, connecting them to business impact is critical. Which of the following BEST describes how a risk practitioner should link a technical scenario to business impact?
Hard29A national retail chain is building a risk register for its new e-commerce platform. The CISO asks the risk practitioner to identify the inherent risk associated with a recently disclosed SQL injection vulnerability in a third-party payment gateway module. Which of the following BEST describes inherent risk in this scenario?
Medium30An insurance company is expanding into a new country and must identify IT risks arising from local data protection law, which requires customer data to remain within national borders. The risk practitioner is mapping this requirement into the enterprise risk register. Which of the following is the MOST appropriate way to characterize this risk?
Hard31A retail bank is building a risk register for its newly deployed mobile payment API. The CISO asks the risk practitioner to classify the risk that attackers could manipulate the API request parameters to bypass transaction limits. Under which CRISC risk identification category should this risk PRIMARILY be recorded?
Medium32A company is developing risk scenarios for business impact analysis. Which of the following scenario components directly links the risk event to potential financial loss?
Medium33An organization uses the PASTA threat modeling methodology. In which stage would the team identify threat agents and their capabilities?
Hard34A global manufacturer's risk committee is defining the organization's risk capacity and risk appetite for IT risk. The chief risk officer asks the practitioner to clarify how these two concepts relate. Which of the following statements is MOST accurate?
Hard35A risk practitioner is identifying risks associated with the decommissioning of a legacy data center. The organization plans to migrate all remaining applications to a cloud environment. Which TWO of the following are the MOST significant risks that should be included in the risk register for this project? (Choose two.)
Hard36A risk practitioner is estimating the likelihood of a ransomware event affecting a manufacturing firm's operational technology environment. Historical incident data is sparse, so the practitioner convenes plant engineers, security staff, and the insurance broker to elicit calibrated estimates and combine them into a reasoned likelihood. Which technique is being used?
Hard37Which of the following is a threat intelligence source that provides information about known exploited vulnerabilities, maintained by a government agency?
Easy38Which type of threat actor is characterized by having significant resources, advanced skills, and often state-sponsored objectives?
Easy39A risk practitioner at an insurance company is identifying risks for a newly deployed customer portal that integrates with a third-party identity provider. She wants to document external factors that could increase the likelihood of a data breach. Which TWO of the following are external risk factors she should capture? (Choose two.)
Medium40Which of the following is the PRIMARY source for identifying known software vulnerabilities in a systematic manner?
Medium41A multinational corporation uses commercial threat intelligence feeds and participates in an ISAC. However, they recently missed a critical vulnerability exploited in the wild that was not in their feeds. Which additional source should they incorporate to improve vulnerability identification?
Hard42A hospital's risk practitioner is identifying risks for a new telehealth platform. The IT director asks which source would be MOST useful for identifying vulnerabilities specific to the platform's underlying commercial software components. Which of the following should the practitioner use?
Easy43A risk practitioner at a regional hospital is building a risk register for its new electronic health record (EHR) system. The system stores protected health information (PHI) and is subject to HIPAA. The practitioner wants to ensure that the risk register captures the potential for unauthorized disclosure of PHI. Which of the following should the practitioner PRIMARILY use to identify the relevant threats and vulnerabilities for this system?
Medium44A risk practitioner is assessing the likelihood of a distributed denial-of-service (DDoS) attack against an online retailer's checkout service during peak shopping season. Which of the following factors would MOST increase the assessed likelihood of this event?
Hard45When performing asset-based vulnerability identification, a security analyst uses the Common Vulnerabilities and Exposures (CVE) database along with the National Vulnerability Database (NVD). Which of the following BEST describes the relationship between CVE and NVD?
Hard46A hospital's risk practitioner is building a risk register entry for a ransomware attack on its electronic health record (EHR) system. The practitioner wants to express the risk in terms of how often the event is expected to occur and how much it would cost if it did. Which of the following BEST describes the two components being quantified?
Medium47An organization is assessing risks related to a new cloud-based CRM system. The risk team is developing a risk scenario. Which of the following is the BEST example of a complete risk scenario following the ISACA template?
Medium48A risk manager is developing risk scenarios to present to the board. Which TWO elements are essential for connecting a risk scenario to business impact?
Medium49A risk practitioner is facilitating a workshop to identify risks for a new customer-facing payment portal. The CISO wants the exercise to capture risks arising from both internal process weaknesses and external threat sources without producing an unmanageable list. Which approach is MOST appropriate for structuring the risk identification effort?
Medium50A risk practitioner is cataloging external factors that could create IT risk for a logistics firm expanding into a new country. Which TWO of the following are external factors that should be included in the risk identification effort? (Choose two.)
Hard51A risk practitioner is conducting a risk assessment for a new mobile application that will process credit card payments. The practitioner needs to identify relevant threats. Which of the following is the MOST appropriate source for identifying threats specific to this application?
Easy52A risk practitioner is analyzing the risk of insider threat in a software development company. The practitioner wants to assess the likelihood of a developer exfiltrating source code. Which of the following factors would MOST directly increase the likelihood of this risk?
Medium53An organization is developing an IT risk universe. Which of the following is the PRIMARY purpose of creating a comprehensive IT risk universe?
Medium54A risk practitioner is using the Delphi technique to estimate the likelihood of a sophisticated ransomware attack against a hospital network. The first round of expert opinions produced widely divergent estimates. Which of the following is the MOST appropriate next step in the Delphi process?
Hard55A risk practitioner is quantifying the potential loss from a ransomware scenario affecting a hospital's electronic health record (EHR) platform. Historical data shows an average of two disruptive malware incidents per year, a 30% probability that any single incident escalates to full EHR encryption, and an estimated $4,000,000 business impact when the EHR is unavailable for a full day. What is the annualized loss expectancy (ALE) for this scenario?
Hard56During a risk identification workshop, the team identifies several vulnerabilities. Which TWO of the following are examples of operational vulnerability identification? (Select two.)
Medium57A risk practitioner is conducting a risk assessment for a new customer-facing mobile application. The practitioner wants to identify risks by examining how data flows between the mobile client, the API gateway, and the backend database. Which of the following techniques is being applied?
Easy58A utility company's risk practitioner is defining the scope of a risk identification exercise for a new advanced metering infrastructure. The practitioner must decide which elements to include. Which action BEST ensures the identification exercise covers the full risk landscape?
Hard59A mid-sized hospital is building its IT risk register. The risk practitioner wants to express the organization's tolerance for a ransomware event that would disrupt electronic health records for 24 hours. Which of the following BEST represents a structured way to document this tolerance?
Medium60A retail company is establishing an IT risk universe. Which of the following should be included as a primary category of IT risk?
Easy61During a VAST threat modeling session for a DevSecOps pipeline, the team focuses on threats that align with agile development. Which of the following is a key advantage of VAST?
Hard62A risk practitioner at a healthcare insurer is identifying risks for a new telehealth platform. The platform integrates with a third-party video vendor, stores protected health information, and must comply with HIPAA. Which of the following is the MOST appropriate FIRST step in identifying IT risk for this platform?
Hard63A risk practitioner is performing risk identification for a manufacturing firm that relies on industrial control systems (ICS) to operate assembly lines. The practitioner is cataloging vulnerabilities that could be exploited to disrupt production. Which TWO of the following represent vulnerabilities rather than threats? (Choose two.)
Hard64A retail bank's risk practitioner is building a risk scenario for its online banking platform. He needs to estimate how frequently an attacker could realistically succeed in exploiting the platform's unpatched web tier. Which of the following provides the MOST quantitative basis for this estimate?
Medium65During risk identification, a risk manager is reviewing threat intelligence sources. Which THREE of the following are considered legitimate sources of threat intelligence? (Choose three.)
Hard66A risk practitioner at a regional hospital is building a risk register entry for the loss of availability of its electronic health record (EHR) system. The practitioner wants to express the risk in a way that supports later quantification and treatment decisions. Which of the following BEST describes how the risk should be documented in the register?
Medium67A risk practitioner is using the ISACA risk scenario development approach to articulate a risk related to a third-party payment processor. The practitioner wants to ensure the scenario includes all key components. Which of the following components is MOST critical to include to enable effective risk analysis and treatment?
Hard68A company is updating its risk register. Which of the following is the primary purpose of a risk register?
Medium69A risk manager is assessing the risk of a distributed denial-of-service (DDoS) attack on a critical online service. The service has a service-level agreement (SLA) that requires 99.9% uptime. The manager has identified that the likelihood of a DDoS attack is high, but the impact is considered low because the service can fail over to a backup data center. Which of the following should the risk manager do NEXT?
Hard70When identifying vulnerabilities, which of the following is the BEST source for configuration-related vulnerabilities in operating systems?
Medium71A risk practitioner at a software company is reviewing external sources to identify emerging IT risks that could affect the organization's cloud-hosted products. The practitioner wants to use sources that provide structured, timely information about newly disclosed software weaknesses. Which TWO of the following sources BEST meet this need? (Choose two.)
Medium72Which threat actor is most likely motivated by political ideology and may target government systems?
Easy73A risk practitioner at a regional bank is compiling a list of internal threat sources for the enterprise risk assessment. Which TWO of the following are internal threat sources that should be included? (Choose two.)
Medium74Which TWO of the following are types of insider threats?
Easy75A risk practitioner at a regional bank is building a threat landscape for its new mobile payment platform. A recently published report from a national CERT indicates that a loosely organized group has been targeting payment APIs across the region, exploiting known authentication weaknesses. The practitioner wants to determine whether this group should be treated as a relevant threat source in the risk register. Which of the following is the MOST appropriate FIRST step?
Medium76A risk practitioner is reviewing the organization's risk register and notices that a risk related to outdated encryption protocols on a file server has been assigned an owner. According to CRISC principles, what is the PRIMARY responsibility of the risk owner?
Easy77Which of the following threat actors is MOST likely to be motivated by ideology rather than financial gain?
Easy78A risk practitioner is identifying risks associated with a new cloud-based customer relationship management (CRM) system. The organization has concerns about data leakage and service availability. Which TWO of the following are examples of vulnerabilities that could lead to these risks? (Choose two.)
Medium79A risk practitioner is performing a risk assessment on an organization's use of a cloud-based payroll platform. The practitioner is identifying the inherent risk factors that exist before any controls are considered. Which TWO of the following are inherent risk factors for this scenario? (Choose two.)
Hard80A risk practitioner is selecting a risk analysis technique for a new mobile banking feature. The team has limited historical loss data, the feature involves several interconnected components, and stakeholders disagree about how failures propagate between them. Management wants a technique that structures expert judgment about causal pathways and produces a visual model of how component failures combine to cause the top-level loss event. Which technique BEST meets these requirements?
Hard81A risk practitioner at a healthcare insurance company is building the risk register entry for ransomware affecting its claims-processing platform. The practitioner must document the loss event type, the asset at risk, and the expected loss magnitude in the organization's risk taxonomy. Which of the following BEST describes the risk component that represents the expected loss magnitude?
Medium82A hospital's risk practitioner is assessing a new telehealth platform that stores protected health information. During risk identification, she maps threats to the platform. Which of the following BEST illustrates a threat to this platform rather than a vulnerability or a control weakness?
Hard83A risk practitioner is developing a risk scenario for a potential ransomware attack. Using the ISACA risk scenario template, which element describes the entity that initiates the attack?
Hard84A company is adopting a DevSecOps approach and wants to conduct threat modeling early in the development lifecycle. Which threat modeling methodology is BEST suited for this environment due to its focus on agile and continuous integration?
Medium85A risk practitioner is mapping identified IT risks to the organization's risk taxonomy. A risk has been logged for 'unauthorized access to the HR system resulting from excessive user privileges.' Under which risk category should this be classified?
Hard86A retail bank is documenting its risk appetite for IT risk. The board states that the bank will accept only minimal risk of unauthorized disclosure of customer payment data, but is willing to accept moderate availability risk in internal reporting systems. A risk practitioner is asked to translate this statement into operational terms. Which action BEST reflects establishing risk tolerance in this context?
Easy87Which THREE of the following are common consequences in an IT risk scenario?
Medium88A risk practitioner is identifying external threats to a retail bank's online transaction platform. The bank wants to understand threats that originate from outside the organization and target customer accounts. Which TWO of the following are external threats relevant to this scenario? (Choose two.)
Hard89A retail company's risk practitioner is reviewing how risks flow between the enterprise risk management function and the IT risk function. The CISO argues that IT risks should be reported only within IT, while the CRO wants material IT risks elevated to the enterprise register. Which CRISC principle BEST resolves this disagreement?
Medium90A risk practitioner is connecting a risk scenario to business impact. The scenario involves a ransomware attack that encrypts critical financial systems, resulting in a two-week outage. Which of the following is the MOST appropriate business impact category?
Hard91A newly hired risk analyst is asked to classify the organization's risk universe before any assessment begins. The analyst lists categories such as strategic, operational, financial, compliance, and reputational. Which of the following BEST explains why this categorization is useful for IT risk identification?
Easy92In the context of threat modeling for a web application, which technique is specifically designed to be integrated into Agile and DevSecOps processes, emphasizing collaboration and visualization?
Hard93During a risk assessment, the risk practitioner develops a scenario involving a disgruntled employee exfiltrating sensitive customer data through a USB drive. The organization has a strict policy against removable media but lacks technical controls to prevent USB usage. Which element of the risk scenario is the vulnerability?
Hard94Which of the following best describes risk capacity?
Easy95Which of the following is a key characteristic of a well-maintained risk register?
Easy96A retail bank's risk practitioner is assessing the risk that a core banking system outage could halt transaction processing. The practitioner wants to identify the specific conditions or characteristics of the environment that could allow the outage to occur or worsen its effect, rather than the events themselves. Which of the following is the practitioner identifying?
Hard97A risk practitioner is using the TRIKE threat modeling methodology. Which TWO of the following are characteristics of TRIKE?
Hard98A risk practitioner is creating a risk scenario for a ransomware attack. Which of the following is the BEST sequence to describe the scenario using the ISACA risk scenarios template?
Medium99A manufacturing firm's risk practitioner is facilitating a workshop to identify IT risks for a new industrial control system (ICS) rollout. Operational engineers, IT staff, and a third-party integrator are present. Which of the following approaches BEST supports comprehensive IT risk identification in this setting?
Medium100A hospital's risk practitioner is identifying risks to its electronic health record platform. The practitioner documents that a single system administrator holds the only account with rights to restore the production database, and no documented procedure exists for that task. Which risk factor does this finding PRIMARILY represent?
Easy101A financial services firm is conducting a risk assessment for a new mobile banking application. The risk practitioner needs to evaluate the likelihood of a threat exploiting a vulnerability. Which of the following factors is MOST relevant when assessing the likelihood of a threat event?
Medium102An organization is conducting a vulnerability assessment of its IT assets. Which of the following sources is MOST authoritative for identifying known software vulnerabilities?
Easy103An organization uses the PASTA threat modeling methodology for a new e-commerce platform. Which of the following is a key characteristic of PASTA?
Hard104A security analyst is reviewing CVE entries and NVD data to identify vulnerabilities in software assets. This activity is part of which vulnerability identification approach?
Medium105Which of the following best describes the purpose of an IT risk universe?
Easy106A risk practitioner is using the MITRE ATT&CK framework to identify threats relevant to a financial services firm's cloud-hosted trading platform. The practitioner wants to focus on techniques adversaries use after obtaining initial access to cloud infrastructure. Which of the following BEST describes how ATT&CK should be applied in this risk identification effort?
Hard107A risk practitioner is analyzing the threat landscape for a hospital's connected medical devices. The devices run legacy operating systems that cannot be patched and are accessible from the clinical network. Which factor MOST increases the likelihood of exploitation?
Medium108A risk practitioner at a financial services firm is identifying IT risk scenarios for a new mobile banking application. The firm uses the ISACA risk scenario development approach. Which TWO of the following are essential components of a well-defined risk scenario? (Choose two.)
Hard109During a threat modeling exercise for a new web application, the team uses STRIDE. Which threat type under STRIDE corresponds to an attacker modifying data in transit?
Medium110A regional insurance company has just completed an IT risk assessment and documented the identified risks in a central repository. The risk practitioner now wants to ensure that each risk has an assigned owner, a defined response, and a status that can be tracked over time. Which of the following should the practitioner use to meet these needs?
Easy111A risk practitioner is facilitating a workshop to identify risks for a new customer data analytics platform. During the session, participants repeatedly describe how a competitor might copy the platform's features and how a regulator might question the platform's data retention practices. The practitioner wants to ensure the workshop produces structured risk statements rather than general concerns. Which of the following should the practitioner do NEXT?
Hard112A financial services firm's risk practitioner is building a risk register entry for a customer-facing mobile banking application hosted in a public cloud. The application stores PII and processes payments. Management wants to understand the inherent risk before any controls are considered. Which of the following BEST represents the inherent risk of this asset?
Medium113A company is implementing a risk identification process for third-party risks. Which THREE factors should be considered when identifying risks from a critical software vendor?
Hard114A risk practitioner is preparing a risk register for a hospital's new telemedicine platform. During interviews, the CIO states that the platform's availability is critical because clinicians rely on it for urgent consultations. The practitioner needs to document how this business dependency influences risk identification. Which of the following BEST describes the role of business criticality in this context?
Easy115A financial services firm is identifying risks for a new mobile banking feature that will rely on a third-party identity verification provider. The vendor has provided a SOC 2 Type II report, but the firm has not yet reviewed it. Which of the following BEST describes how the firm should treat the vendor-related risk during identification?
Medium116A risk practitioner is identifying risks for a pharmaceutical company that shares clinical trial data with external research partners. The practitioner learns that partners access the data through a shared portal with role-based access, and that one partner recently terminated its agreement but retained portal credentials. Which of the following is the MOST significant risk identification finding?
Hard117Which THREE of the following are common business impact categories used in risk scenarios?
Medium118An organization has a risk appetite statement that says 'We accept up to $5 million in operational losses per year.' However, a new cloud migration project is estimated to have a potential operational loss of $8 million if a critical failure occurs. The risk capacity of the organization is $20 million. What should the risk practitioner recommend?
Hard119A risk practitioner at a regional bank is building a risk register entry for the loss of a critical core banking application. The head of IT operations insists on recording a single, point-in-time likelihood estimate of 15% derived from last year's incident log, and refuses to consider any range. Which CRISC-aligned principle should the practitioner apply to MOST appropriately represent this IT risk?
Medium120A bank is identifying IT risks and categorizes a potential data breach as both a compliance risk (due to GDPR) and a reputational risk. This is an example of:
Medium121An organization's board has issued a risk appetite statement indicating that the company is willing to accept a moderate level of operational risk but has zero tolerance for compliance violations. This statement primarily defines which of the following?
Easy122A risk scenario is being developed for a phishing attack leading to credential theft. Using ISACA's risk scenario template, which component would describe the 'threat event'?
Medium123A risk practitioner is assessing the risk of a distributed denial-of-service (DDoS) attack against an online retailer's public storefront. The CISO asks which factors would MOST directly increase the likelihood that such an attack would succeed in disrupting service. (Choose two.)
Hard124During IT risk identification, which document serves as the central repository for all identified risks, their characteristics, and current status?
Easy125During a risk assessment, the risk practitioner is identifying threats to an application. Which threat modeling technique is specifically designed to analyze application threats using categories such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Easy126A hospital's risk practitioner is building a risk register entry for the loss of a critical electronic health record (EHR) system. The practitioner wants to express the risk in a way that combines the probability of the event with the magnitude of its business impact so that leadership can compare it against other enterprise risks. Which of the following BEST represents this expression?
Medium127A risk practitioner at a regional hospital is building a risk register and needs to classify each identified risk by its source. During interviews, staff describe a recurring situation: a radiology scheduling application has no automated account deprovisioning, so terminated employees retain access for weeks until a supervisor manually reports them. Which risk identification category BEST describes this finding?
Medium128An organization uses the CISA Known Exploited Vulnerabilities (KEV) catalog as a primary source for vulnerability identification. This catalog is BEST described as:
Medium129A risk practitioner at a healthcare payer is building the risk identification taxonomy for a new claims-processing platform. The CISO asks why the taxonomy must explicitly distinguish between a 'threat event' and a 'loss event' rather than treating both as 'risk' in the register. Which statement BEST justifies that distinction?
Medium130A risk practitioner is selecting a risk analysis technique for a new payment processing system. The team has limited historical loss data, wants to incorporate expert judgment, and needs to prioritize risks for management review. Which technique is MOST appropriate?
Easy131A risk practitioner is evaluating the risk that a cloud provider's regional outage disrupts a company's order management system. The company has a recovery time objective (RTO) of four hours, but the provider's documented regional recovery capability is estimated at twelve hours. Which of the following BEST characterizes the risk exposure this gap represents?
Hard132A risk practitioner is interviewing business unit leaders to identify IT risks for an annual risk assessment. One leader states that the customer relationship management system is critical because sales staff cannot work without it. Which of the following BEST describes the risk practitioner's next action to validate this input?
Easy133A risk practitioner is reviewing the organization's risk register and notices that a risk related to a legacy payroll system has been assigned an owner from the IT department. The risk owner is responsible for which of the following?
Easy134A global logistics company's risk practitioner is identifying risks for a new customs-clearance application. She wants to ensure the risk identification is complete before moving to analysis. Which of the following approaches BEST supports completeness of the risk identification?
Hard135A risk practitioner is developing risk scenarios for a new cloud service. Which THREE of the following elements should be included in a complete risk scenario?
Medium136An organization is implementing a new cloud-based customer relationship management (CRM) system. Which of the following risk categories would BEST describe the risk of the CRM system failing to meet performance expectations?
Medium137A manufacturer is identifying IT risk associated with a legacy inventory management system that no longer receives vendor security patches. The risk practitioner documents the unsupported platform as a vulnerability. Which additional asset-based factor should the practitioner evaluate to determine how this vulnerability contributes to overall risk?
Medium138A global retailer is identifying IT risks related to a new cloud-based point-of-sale (POS) system. The risk practitioner wants to use a top-down approach. Which of the following is the MOST appropriate starting point for this approach?
Hard139A risk analyst is identifying threats to a retail bank's newly deployed public application programming interface (API) that allows third-party fintech partners to initiate account transfers. Which of the following is the MOST relevant threat to consider during risk identification for this API?
Easy140A risk practitioner is facilitating a risk identification workshop for a retail bank's new real-time payments service. Business stakeholders keep proposing controls such as multifactor authentication and transaction limits as 'risks.' Which action BEST keeps the identification phase technically sound?
Hard141An organization is updating its IT risk universe. Which of the following is the MOST important factor to consider when defining the universe?
Medium142A hospital network is identifying IT risks for its newly deployed medical imaging archive. The risk practitioner wants to document risks in a way that links each risk to the business process it could disrupt. Which CRISC concept is the practitioner applying when connecting an IT risk to the business objective it threatens?
Easy143When using STRIDE for threat modeling, which threat category involves an attacker gaining unauthorized access to a system by pretending to be a legitimate user?
Medium144Which of the following threat actors is MOST likely to be motivated by financial gain and possess moderate to high technical capabilities?
Medium145In developing a risk scenario, connecting a threat event to business impact is crucial. Which of the following is the BEST example of a properly connected risk scenario?
Medium146A risk practitioner at a regional hospital is building a risk register entry for the loss of availability of the electronic health record (EHR) system. The CIO asks which element of the risk scenario establishes the frequency with which the loss event is expected to occur so that the register can be prioritized against other entries. Which component of the risk scenario should the practitioner document?
MediumOther domains
All CRISC exam domains
Frequently asked questions
- What does the IT Risk Identification domain cover on the CRISC exam?
- Be able to build a risk scenario using ISACA's template, classify risks into the correct category, and rank scenarios against appetite and tolerance. The single most important thing is separating risk capacity from risk appetite and tolerance.
- How many questions are in this domain?
- This page lists all 146 IT Risk Identification questions in the CRISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only IT Risk Identification questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.