Courseiva
hardMultiple Select

CRISC Practice Question: Which THREE of the following are valid risk…

Which THREE of the following are valid risk identification methods according to ISACA's Risk IT Framework? (Select exactly 3.)

⚠ Common exam trap

Many candidates confuse risk identification techniques with risk response or control activities, mistakenly selecting segregation of duties or risk acceptance as valid identification methods when they are actually part of risk mitigation and risk treatment processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scenario analysis

Scenario analysis (B) is a valid risk identification method in ISACA's Risk IT Framework because it explores plausible future events and their potential impact on IT objectives, helping surface risks that routine monitoring might miss. SWOT analysis (D) is also valid, as it systematically examines internal strengths and weaknesses plus external opportunities and threats to identify risks affecting IT strategy and operations. Brainstorming (E) is likewise a recognized identification technique, using structured group discussion to elicit a broad range of potential IT risk events from stakeholders. Segregation of duties (A) is a preventive control that reduces fraud and error risk rather than a method for identifying risks, and risk acceptance (C) is a risk response option in the Risk IT process, not an identification technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Segregation of duties

    Why it's wrong here

    Segregation of duties is a preventive control that limits fraud risk; it does not identify risks. It is tempting because control assessment feeds the risk register, and it would be the correct answer if the question asked which control mitigates risk rather than which method identifies it.

  • ✓

    Scenario analysis

    Why this is correct

    Scenario analysis is a recognised risk identification method in ISACA's Risk IT Framework, exploring plausible future events to surface risks. It satisfies the stem's requirement by providing a structured, forward-looking technique that complements other valid identification methods listed in the framework.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance is a risk response, chosen after identification and evaluation, not a method for discovering risks. It is tempting because acceptance appears in the same Risk IT process flow, and it would be correct if the question asked how management responds to a risk exceeding tolerance.

  • ✓

    SWOT analysis

    Why this is correct

    SWOT analysis is a valid risk identification method under ISACA's Risk IT Framework, examining strengths, weaknesses, opportunities and threats to expose internal and external risk sources. It satisfies the stem's requirement by systematically identifying risks from strategic and environmental factors.

  • ✓

    Brainstorming

    Why this is correct

    Brainstorming is a valid risk identification method in ISACA's Risk IT Framework, gathering stakeholders to generate potential risk events collectively. It satisfies the stem's requirement by providing a structured group technique that surfaces risks not captured through analytical or historical methods alone.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.