hardMultiple Select
CRISC Practice Question: Which THREE of the following are key indicators…
Which THREE of the following are key indicators that a risk identification process is effective? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse project management metrics (like budget or schedule) with risk management effectiveness indicators, leading them to select 'completed within budget' instead of recognizing that coverage, stakeholder input, and timeliness are the true measures of a robust risk identification process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process covers all critical business processes
Option B is correct because an effective risk identification process must cover all critical business processes, ensuring that risks to essential operations, revenue streams, and service delivery are surfaced rather than only technical or peripheral concerns. Option C is correct because involving key stakeholders across the organization brings diverse perspectives from business, IT, legal, compliance, and operations, which improves completeness and accuracy of identified risks. Option D is correct because risk identification is not a one-time event; repeating it at regular intervals or when significant changes occur (new systems, mergers, regulatory shifts, threat landscape changes) keeps the risk register current and relevant. Option A is not correct because identifying 'all known vulnerabilities' is an unrealistic and overly narrow goal—risk identification focuses on risks, not just vulnerabilities, and completeness of vulnerability enumeration is not the measure of process effectiveness. Option E is not correct because completing the process within budget reflects cost efficiency, not effectiveness; a process can be cheap yet miss critical risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The process identifies all known vulnerabilities
Why it's wrong here
Claiming all known vulnerabilities are identified is unverifiable and conflates completeness with effectiveness; new risks continually emerge. Exhaustive vulnerability enumeration suits a technical scanning or assessment scope, whereas an effective identification process is evidenced by breadth of sources, repeatability and stakeholder engagement.
- ✓
The process covers all critical business processes
Why this is correct
Coverage of all critical business processes demonstrates that risk identification is comprehensive, satisfying the completeness criterion an effective process requires. Gaps in critical processes would leave material risks undetected, so full scope confirms the process captures exposures across the organisation's most significant operations rather than only isolated areas.
- ✓
The process involves input from key stakeholders across the organization
Why this is correct
Stakeholder input across the organisation ensures risks are identified from every business unit, not just IT. This breadth satisfies the effectiveness indicator that identification captures the full risk landscape, since siloed input leaves material exposures undiscovered.
- ✓
The process is repeated at regular intervals or triggered by significant changes
Why this is correct
Regular repetition plus event-driven triggers keeps the risk register current as the environment shifts. This satisfies the effectiveness indicator that identification is continuous rather than a one-off exercise, catching newly emerged threats and changed conditions.
- ✗
The process is completed within budget
Why it's wrong here
Budget adherence measures process efficiency, not whether risks were actually surfaced. Cost control would be a valid indicator for a project management or resource-planning review, but effectiveness of risk identification is judged by coverage, stakeholder participation and the discovery of previously unknown risks.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.