Courseiva
easyMultiple Select

CRISC Practice Question: Which TWO of the following are primary sources of…

Which TWO of the following are primary sources of risk identification for IT projects? (Select exactly 2.)

⚠ Common exam trap

Watch out — candidates often confuse operational artifacts (like firewall logs or security baselines) with project-level risk identification sources, or mistakenly think the risk treatment plan is an input rather than an output of the risk identification process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Project documentation

Option B (Project documentation) is a primary source of risk identification because artifacts such as the project charter, scope statement, WBS, schedule, assumptions log, and stakeholder register expose uncertainties, dependencies, and constraints that can become risks. Option E (Lessons learned from previous projects) is also a primary source, since historical records from comparable projects reveal recurring threats, failure patterns, and effective mitigations that should inform the current risk register. Option A (Security baseline) is a control configuration reference, not a risk identification input; it defines required settings rather than surfacing project risks. Option C (Risk treatment plan) is an output of the risk management process that documents responses to already-identified risks, so it cannot be a primary source of identification. Option D (Firewall logs) are operational security monitoring data used for detection and incident response, not a standard project risk identification source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security baseline

    Why it's wrong here

    A security baseline defines the minimum configuration standard already mandated, so it prescribes controls rather than revealing unknown risks. It is tempting because baselines expose gaps during audits, but those gaps are findings against a known standard, not a primary identification source for project risk.

  • ✓

    Project documentation

    Why this is correct

    Project documentation — charters, plans, assumptions and requirements — surfaces risks early by exposing dependencies, scope gaps and constraints. It satisfies the criterion of being a primary, project-specific source rather than an external or generic one.

  • ✗

    Risk treatment plan

    Why it's wrong here

    A risk treatment plan records responses to risks already identified, so it cannot serve as an input that surfaces new risks. It is tempting because treatment planning sits within the same risk process, but it is an output of identification and analysis, not a source feeding it.

  • ✗

    Firewall logs

    Why it's wrong here

    Firewall logs record permitted and denied traffic for operational monitoring and incident investigation; they do not systematically surface project risks such as scope, resource or vendor exposure. They are tempting because they reveal security events, but that is threat detection, not project risk identification.

  • ✓

    Lessons learned from previous projects

    Why this is correct

    Lessons learned from previous projects capture realised risks, their causes and effective responses, giving historical evidence for identifying likely risks in the current project. This satisfies the criterion of a primary source grounded in organisational experience.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.