easyMultiple Choice
CRISC Practice Question: Is the PRIMARY purpose of a risk register in the…
Which of the following is the PRIMARY purpose of a risk register in the risk identification phase?
⚠ Common exam trap
Watch out — candidates often confuse the risk register's role in identification with later-phase activities like ownership assignment or scoring, leading them to select options that describe downstream processes rather than the immediate documentation purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document identified risks and their characteristics
The primary purpose of a risk register during the risk identification phase is to systematically document each identified risk along with its key characteristics, such as the risk description, cause, impact, and potential triggers. This foundational record ensures that all risks are captured before any subsequent analysis or response planning occurs, aligning with the CRISC domain of IT Risk Identification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign risk owners
Why it's wrong here
Assigning risk owners is a risk response task occurring after identification and assessment; the register's primary purpose in the identification phase is recording identified risks. It is tempting because registers do list owners, which is correct during response planning, not while identifying risks.
- ✓
Document identified risks and their characteristics
Why this is correct
Documenting identified risks and their characteristics is the register's core function during identification, capturing each risk's cause, category, and potential impact before any assessment occurs. This satisfies the stem's identification-phase constraint, since quantification and prioritisation belong to later risk analysis and evaluation stages, not to identification itself.
- ✗
Calculate risk scores
Why it's wrong here
Calculating risk scores is a risk analysis activity performed after identification; the register's primary purpose during identification is capturing and documenting identified risks. It is tempting because registers do hold scoring fields, which is correct once assessment begins, not while identifying risks.
- ✗
Track remediation progress
Why it's wrong here
Tracking remediation progress is a monitoring activity performed after responses are implemented; the register's primary purpose during identification is documenting identified risks. It is tempting because registers do track treatment status, which is correct during risk monitoring, not the identification phase.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.