Courseiva
easyMultiple Choice

CRISC Practice Question: Is the PRIMARY purpose of a risk register in the…

Which of the following is the PRIMARY purpose of a risk register in the risk identification phase?

⚠ Common exam trap

Watch out — candidates often confuse the risk register's role in identification with later-phase activities like ownership assignment or scoring, leading them to select options that describe downstream processes rather than the immediate documentation purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document identified risks and their characteristics

The primary purpose of a risk register during the risk identification phase is to systematically document each identified risk along with its key characteristics, such as the risk description, cause, impact, and potential triggers. This foundational record ensures that all risks are captured before any subsequent analysis or response planning occurs, aligning with the CRISC domain of IT Risk Identification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign risk owners

    Why it's wrong here

    Assigning risk owners is a risk response task occurring after identification and assessment; the register's primary purpose in the identification phase is recording identified risks. It is tempting because registers do list owners, which is correct during response planning, not while identifying risks.

  • ✓

    Document identified risks and their characteristics

    Why this is correct

    Documenting identified risks and their characteristics is the register's core function during identification, capturing each risk's cause, category, and potential impact before any assessment occurs. This satisfies the stem's identification-phase constraint, since quantification and prioritisation belong to later risk analysis and evaluation stages, not to identification itself.

  • ✗

    Calculate risk scores

    Why it's wrong here

    Calculating risk scores is a risk analysis activity performed after identification; the register's primary purpose during identification is capturing and documenting identified risks. It is tempting because registers do hold scoring fields, which is correct once assessment begins, not while identifying risks.

  • ✗

    Track remediation progress

    Why it's wrong here

    Tracking remediation progress is a monitoring activity performed after responses are implemented; the register's primary purpose during identification is documenting identified risks. It is tempting because registers do track treatment status, which is correct during risk monitoring, not the identification phase.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.