hardMultiple SelectObjective-mapped
CRISC Practice Question: Which THREE factors should be considered when…
Which THREE factors should be considered when determining the inherent risk level of a new IT project prior to any controls?
⚠ Common exam trap
Many exam-takers confuse inherent risk factors with control factors, mistakenly selecting team experience (D) or historical incidents (B) as inherent risk drivers, when in fact these are inputs for control effectiveness or residual risk assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory requirements governing the project's outcomes.
Regulatory requirements (A) are a key factor in determining inherent risk because they impose mandatory compliance obligations that, if unmet, can result in legal penalties, fines, or operational shutdowns. For a new IT project, the inherent risk level is assessed based on the nature of the data processed and the applicable laws (e.g., GDPR, HIPAA, PCI DSS) before any controls are applied. This is a fundamental input to the risk assessment, as non-compliance risk exists independently of any security measures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Regulatory requirements governing the project's outcomes.
Why this is correct
Strict regulations increase the consequence of non-compliance, raising inherent risk.
- ✗
Past security incidents in similar projects.
Why it's wrong here
Past incidents reflect historical control failures, not inherent project risk without controls.
- ✓
Complexity of the project's technology stack.
Why this is correct
Greater complexity typically increases the probability of vulnerabilities, raising inherent risk.
- ✗
Experience level of the project team.
Why it's wrong here
Team experience is a mitigating control, not a factor of inherent risk.
- ✓
Extent of external network connectivity.
Why this is correct
More connectivity increases the attack surface, elevating inherent risk.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.