Courseiva
easyMultiple Select

CRISC Practice Question: Which TWO of the following are primary sources of…

Which TWO of the following are primary sources of risk identification for IT projects?

⚠ Common exam trap

The trap here is that candidates often mistake external or secondary sources (like industry reports or social media) as primary risk identification sources, when in fact only project-specific documentation and direct stakeholder engagement are considered primary for IT projects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Project documentation (e.g., scope, schedule, budget)

Project documentation (C) is a primary risk-identification source because reviewing the scope, schedule, and budget exposes concrete risk triggers such as unclear requirements, aggressive timelines, and funding shortfalls that are specific to the project. Stakeholder interviews (D) are also a primary source, since stakeholders—sponsors, users, vendors, and team members—hold expert judgment and direct knowledge of assumptions, constraints, and concerns that surface risks not visible in artifacts alone. Both are recognized inputs to the Identify Risks process in standards such as PMBOK, where project documents and stakeholder analysis feed directly into risk registers. By contrast, social media monitoring (A) and industry benchmark reports (E) are secondary or external environmental inputs that may inform risk generally but are not primary project-level sources, and vendor marketing materials (B) are promotional and biased rather than a reliable risk-identification input.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Social media monitoring

    Why it's wrong here

    Social media monitoring captures unstructured public sentiment, not the project-specific risk inputs such as assumptions, constraints and stakeholder concerns. It tempts because it is an external data source, and would be correct when tracking public perception or reputational sentiment surrounding an organisation.

  • ✗

    Vendor marketing materials

    Why it's wrong here

    Vendor marketing materials promote products and omit unfavourable findings, so they cannot reliably surface project risks. They tempt because they describe technology capabilities, and would be correct when gathering product information for a procurement evaluation, not when identifying risks to the project itself.

  • ✓

    Project documentation (e.g., scope, schedule, budget)

    Why this is correct

    Project documentation such as scope, schedule and budget captures assumptions, dependencies and constraints that seed the risk register. Reviewing these artefacts surfaces schedule slippage, scope creep and funding shortfalls, making them a primary identification source for IT projects.

  • ✓

    Stakeholder interviews

    Why this is correct

    Stakeholder interviews surface risks directly from those with vested interests in the project, capturing concerns, assumptions and dependencies that documentation alone misses. They satisfy the stem's requirement for a primary identification source by drawing on human insight across business, technical and user perspectives.

  • ✗

    Industry benchmark reports

    Why it's wrong here

    Industry benchmark reports describe other organisations' risk profiles, not this project's exposures, so they are secondary reference material rather than a primary identification source. They tempt because they inform risk discussions, and would be correct when calibrating risk appetite or comparing maturity against peers.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.