mediumMultiple Choice
CRISC Practice Question: During a risk assessment for a cloud migration…
During a risk assessment for a cloud migration project, the risk team identifies that the new SaaS application has not been tested for interoperability with existing identity management systems. The project manager argues that the integration will be straightforward and asks to remove this from the risk register. Which of the following is the BEST response from the risk practitioner?
⚠ Common exam trap
CRISC often tests the misconception that a stakeholder's assurance ('it'll be straightforward') justifies removing a risk — the trap is treating opinion as assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Keep the risk in the register with a note that further assessment is needed.
An untested integration with identity management is a legitimate risk that has not been assessed or quantified, so it must remain in the register with a note that further assessment is required. Removing it based on the project manager's assumption would bypass the risk process and eliminate visibility. The risk practitioner's role is to preserve the risk until evidence supports a formal decision.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the risk as it is low priority.
Why it's wrong here
Removing the risk contradicts CRISC's requirement that identified risks be recorded and evaluated; untested interoperability with identity systems is an unassessed exposure, not a proven low priority. Deletion is tempting when a risk appears minor, and would be valid only after analysis shows negligible likelihood and impact with documented acceptance.
- ✓
Keep the risk in the register with a note that further assessment is needed.
Why this is correct
Keeping the risk in the register preserves visibility of an unassessed interoperability exposure until evidence exists, satisfying the requirement that unidentified integration failures remain tracked. Removing it on the project manager's assumption would eliminate the risk before any testing against Microsoft Entra ID confirms compatibility, leaving the residual impact unmanaged.
- ✗
Accept the risk but document the decision.
Why it's wrong here
Acceptance presumes the risk has been analysed and a conscious decision made by the accountable owner; here no interoperability testing has occurred, so likelihood and impact remain unknown. Acceptance is tempting because it closes the register entry quickly, and would be correct once testing quantified residual risk and management formally approved tolerating it.
- ✗
Escalate to the project steering committee.
Why it's wrong here
Escalation transfers the decision upward without the risk practitioner first documenting the untested interoperability and its potential impact; steering committees govern direction, not risk-register content. It is tempting because escalation suits issues exceeding the practitioner's authority, such as funding or scope disputes, but here the practitioner owns the assessment and should record the risk.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.