easyMultiple Choice
CRISC Practice Question: Is the PRIMARY benefit of using a risk register…
Which of the following is the PRIMARY benefit of using a risk register for monitoring?
⚠ Common exam trap
CRISC often tests the distinction between the risk register's role as a centralized tracking repository versus the functions of monitoring tools (SIEM, KRI dashboards) — candidates confuse 'monitoring' with 'real-time alerting' and pick Option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Centralized repository of all risks.
A risk register serves as the centralized repository where all identified risks, their attributes (likelihood, impact, owner, response), and status are documented and tracked over time. This single source of truth is the PRIMARY benefit for monitoring because it enables consistent tracking, reporting, and escalation of risk status across the enterprise. Real-time alerting and automation are features of GRC tooling layered on top, not the register's core value.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provides real-time alerts.
Why it's wrong here
A risk register is a static or periodically updated record of risks, owners and treatment status; it does not stream telemetry, so real-time alerting requires monitoring tools. It is tempting because registers support ongoing risk monitoring, and would be correct for tracking risk status over review cycles rather than instantaneous detection.
- ✓
Centralized repository of all risks.
Why this is correct
A risk register consolidates identified risks, owners, ratings, and treatment status into one repository, giving consistent visibility for monitoring and reporting. This centralisation enables trend analysis and accountability, which scattered spreadsheets or departmental logs cannot deliver reliably.
- ✗
Eliminates the need for KRIs.
Why it's wrong here
A risk register records identified risks, owners, assessments and treatment status; it does not replace KRIs, which independently quantify risk exposure against thresholds. It is tempting because registers centralise risk data, and would be correct when documenting risk ownership and treatment tracking rather than measuring indicator performance.
- ✗
Automates control testing.
Why it's wrong here
A risk register documents risks and treatment decisions; it performs no automated testing of controls, which requires dedicated control-monitoring or GRC tooling. It is tempting because registers underpin risk monitoring, and would be correct for recording control-testing outcomes and remediation status rather than executing the tests themselves.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.