Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: During a merger and acquisition (M&A) due…

During a merger and acquisition (M&A) due diligence, the IT risk manager needs to identify risks in the target company's IT environment. Which approach is most effective for comprehensive risk identification?

⚠ Common exam trap

The trap here is that candidates may overestimate the reliability of self-reported data from questionnaires (Option A) because it seems systematic and efficient, but the CRISC exam emphasizes that direct verification through on-site assessment is essential for comprehensive risk identification in M&A due diligence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct an on-site assessment of the target's IT infrastructure

An on-site assessment (Option D) allows the IT risk manager to directly observe the target's IT infrastructure, including physical security, network configurations, and operational practices. This hands-on approach uncovers risks that may be hidden or misrepresented in self-reported questionnaires, such as outdated firmware, unpatched systems, or insecure network segmentation. It provides the most comprehensive and accurate risk identification for M&A due diligence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send a detailed questionnaire to the target's IT department

    Why it's wrong here

    Questionnaires may be incomplete or biased; they do not provide direct evidence.

  • Review the target's public financial reports

    Why it's wrong here

    Financial reports do not contain technical IT risk information.

  • Conduct a war gaming exercise

    Why it's wrong here

    War gaming is for strategic scenarios, not for identifying existing risks in a target environment.

  • Conduct an on-site assessment of the target's IT infrastructure

    Why this is correct

    On-site assessment enables direct observation, interviews, and hands-on review, yielding the most reliable risk identification.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.