Courseiva

CRISC · topic practice

IT Risk Identification practice questions

Domain 1 of CRISC covers identifying IT risk through asset, threat, vulnerability, and scenario analysis aligned to ISACA's risk scenario template and risk taxonomy. Questions test risk appetite versus capacity versus tolerance, categorization of compliance, operational, and strategic risk, and prioritization of scenarios during risk identification.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: IT Risk Identification

What the exam tests

What to know about IT Risk Identification

Be able to build a risk scenario using ISACA's template, classify risks into the correct category, and rank scenarios against appetite and tolerance. The single most important thing is separating risk capacity from risk appetite and tolerance.

Applying the ISACA risk scenario template elements: threat actor, threat type, event, asset, and impact.

Distinguishing risk appetite, risk capacity, and risk tolerance as defined in ISACA guidance.

Categorizing IT risk events into operational, compliance, strategic, and reporting categories.

Prioritizing identified risk scenarios by comparing exposure against stated appetite and tolerance.

Watch out for

Common IT Risk Identification exam traps

  • ▸Confusing risk capacity (maximum risk an entity can bear) with risk appetite (amount it is willing to accept).
  • ▸Treating a GDPR fine as operational risk rather than compliance risk during categorization.
  • ▸Mismatching risk scenario template elements, such as naming the threat actor as the asset or event.

Practice set

IT Risk Identification questions

20 questions · select your answer, then reveal the explanation

An organization is developing its IT risk universe. Which of the following is the BEST source of information for identifying potential IT risks?

During a risk identification workshop, a risk owner proposes a scenario: 'A disgruntled employee with privileged access exfiltrates customer data to a competitor.' In the context of the ISACA risk scenario template, which element is missing if the scenario only includes the actor, threat type, event, and asset?

A risk analyst is building a risk register. After identifying a list of risks, what is the NEXT step in the risk identification process according to ISACA best practices?

A financial services firm uses SAST and DAST tools in its application security testing. However, they are struggling to prioritize vulnerabilities from the large number of findings. Which additional technique would BEST help identify the most critical vulnerabilities in the context of business risk?

A security team is using the STRIDE threat modeling methodology for a new web application. Which threat type under STRIDE would be MOST relevant to a SQL injection vulnerability?

An IT risk manager is categorizing risks identified during a recent assessment. Which TWO categories would include the risk of a system outage caused by a software bug?

A risk practitioner is developing a risk scenario for a data breach caused by an insider threat. Which of the following is the MOST realistic and complete risk scenario?

Which TWO of the following are examples of operational vulnerabilities that a risk practitioner might identify?

A security analyst is using a threat modeling approach that focuses on identifying threats based on the system's requirements and design. Which threat modeling methodology is being used?

An organization has identified a new vulnerability in its web application that could allow SQL injection attacks. Which of the following sources would MOST likely have been used to identify this vulnerability?

Which of the following is the PRIMARY purpose of a risk register?

A risk practitioner is using the ISACA risk scenario template to document a scenario. The template includes elements such as threat actor, threat type, event, asset/resource, timing, detection, and response. Which element describes the likelihood that the threat event will occur within a specific timeframe?

An organization is assessing risks related to a third-party cloud provider. Which of the following is the BEST source of threat intelligence for identifying threats targeting the cloud infrastructure?

A risk practitioner is updating the risk register and needs to categorize risks. Which TWO of the following are standard risk categories used in IT risk management?

A project manager is identifying risks for a new software development project using Agile methodology. Which THREE threat modeling techniques are BEST suited for Agile/DevSecOps environments?

A company's risk appetite statement specifies that the organization is willing to accept a moderate level of operational risk to achieve strategic agility. This statement directly influences which activity during IT risk identification?

Which of the following is a primary source of threat intelligence that provides real-time information about active cyber threats and indicators of compromise?

A financial institution is identifying IT risks associated with a new mobile banking application. Which TWO threat modeling techniques are best suited for this scenario? (Select two.)

A risk manager is developing a risk scenario for a potential data breach involving a third-party cloud provider. According to the ISACA risk scenario template, which THREE elements must be included? (Select three.)

Which threat modeling technique is specifically designed to be integrated into Agile and DevSecOps processes, providing a visual and simple approach?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused IT Risk Identification sessions

Start a IT Risk Identification only practice session

Every question in these sessions is drawn from the IT Risk Identification domain — nothing else.

Related practice questions

Related CRISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CRISC exam test about IT Risk Identification?
Be able to build a risk scenario using ISACA's template, classify risks into the correct category, and rank scenarios against appetite and tolerance. The single most important thing is separating risk capacity from risk appetite and tolerance.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just IT Risk Identification questions in a focused session?
Yes — the session launcher on this page draws every question from the IT Risk Identification domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CRISC topics?
Use the topic links above to move to related areas, or go back to the CRISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CRISC exam covers. They are not copied from any real exam or dump site.