Courseiva
hardMultiple SelectObjective-mapped

CRISC Practice Question: Which THREE factors should be considered when…

Which THREE factors should be considered when determining the inherent risk level of a new IT project prior to any controls?

⚠ Common exam trap

Many exam-takers confuse inherent risk factors with control factors, mistakenly selecting team experience (D) or historical incidents (B) as inherent risk drivers, when in fact these are inputs for control effectiveness or residual risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Regulatory requirements governing the project's outcomes.

Regulatory requirements (A) are a key factor in determining inherent risk because they impose mandatory compliance obligations that, if unmet, can result in legal penalties, fines, or operational shutdowns. For a new IT project, the inherent risk level is assessed based on the nature of the data processed and the applicable laws (e.g., GDPR, HIPAA, PCI DSS) before any controls are applied. This is a fundamental input to the risk assessment, as non-compliance risk exists independently of any security measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Regulatory requirements governing the project's outcomes.

    Why this is correct

    Strict regulations increase the consequence of non-compliance, raising inherent risk.

  • Past security incidents in similar projects.

    Why it's wrong here

    Past incidents reflect historical control failures, not inherent project risk without controls.

  • Complexity of the project's technology stack.

    Why this is correct

    Greater complexity typically increases the probability of vulnerabilities, raising inherent risk.

  • Experience level of the project team.

    Why it's wrong here

    Team experience is a mitigating control, not a factor of inherent risk.

  • Extent of external network connectivity.

    Why this is correct

    More connectivity increases the attack surface, elevating inherent risk.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.