Courseiva
hardMultiple Choice

CRISC Practice Question: During a merger and acquisition (M&A) due…

During a merger and acquisition (M&A) due diligence, the IT risk manager needs to identify risks in the target company's IT environment. Which approach is most effective for comprehensive risk identification?

⚠ Common exam trap

The trap here is that candidates may overestimate the reliability of self-reported data from questionnaires (Option A) because it seems systematic and efficient, but the CRISC exam emphasizes that direct verification through on-site assessment is essential for comprehensive risk identification in M&A due diligence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct an on-site assessment of the target's IT infrastructure

An on-site assessment (Option D) allows the IT risk manager to directly observe the target's IT infrastructure, including physical security, network configurations, and operational practices. This hands-on approach uncovers risks that may be hidden or misrepresented in self-reported questionnaires, such as outdated firmware, unpatched systems, or insecure network segmentation. It provides the most comprehensive and accurate risk identification for M&A due diligence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send a detailed questionnaire to the target's IT department

    Why it's wrong here

    A questionnaire captures only what the target chooses to disclose, so it cannot verify undocumented systems, shadow IT or inherited vulnerabilities. It is tempting because it is fast and standardised, and would be the right choice for gathering self-assessed control maturity across many suppliers where direct inspection is impractical.

  • ✗

    Review the target's public financial reports

    Why it's wrong here

    Public financial reports aggregate costs and contingencies, disclosing nothing about the target's architecture, patching, access controls or technical debt. It is tempting because it is easily obtained and independent, and would be correct for assessing the financial materiality of an IT risk once technical findings are already known.

  • ✗

    Conduct a war gaming exercise

    Why it's wrong here

    War gaming explores adversarial attack and response scenarios, not the target's actual control environment, so it cannot inventory live systems, contracts or vulnerabilities during due diligence. It is tempting because it surfaces behavioural and insider threats, and would suit validating incident response readiness once the target's environment is already documented.

  • ✓

    Conduct an on-site assessment of the target's IT infrastructure

    Why this is correct

    An on-site assessment directly inspects the target's live infrastructure, configurations and controls, exposing undocumented risks that questionnaires and document reviews miss. It satisfies the due diligence constraint of identifying risks across an unfamiliar environment, where reliance on self-reported data is unreliable. Physical and technical observation reveals gaps in the actual estate.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.