hardMultiple Select
CRISC Practice Question: Which TWO of the following are valid techniques…
Which TWO of the following are valid techniques for identifying risk in IT risk assessment?
⚠ Common exam trap
A common mix-up: candidates confuse risk identification techniques (like SWOT and brainstorming) with risk analysis or evaluation techniques (like residual risk assessment, risk aggregation, and Monte Carlo simulation), which are applied after risks have already been identified.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SWOT analysis
SWOT analysis (A) is a valid risk-identification technique because it systematically examines Strengths, Weaknesses, Opportunities, and Threats, and the Weaknesses and Threats quadrants directly surface internal and external risks to IT assets and processes. Brainstorming sessions (B) are also a recognized identification technique, as they gather subject-matter experts and stakeholders to openly generate potential risk events, threats, and vulnerabilities before any analysis or prioritization occurs. By contrast, residual risk assessment (C) is not an identification method but an evaluation step performed after controls are applied to determine what risk remains. Risk aggregation (D) is an analysis/reporting activity that combines individual risks into a portfolio or enterprise view, not a way to discover new risks. Monte Carlo simulation (E) is a quantitative risk-analysis technique used to model probability distributions and outcomes, so it belongs to risk evaluation rather than identification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SWOT analysis
Why this is correct
SWOT analysis systematically surfaces threats and weaknesses across internal and external dimensions, satisfying the requirement for a structured risk identification technique. It exposes adverse conditions before scoring, directly feeding the IT risk assessment process. This makes it a valid identification method rather than an evaluation or treatment tool.
- ✓
Brainstorming sessions
Why this is correct
Brainstorming sessions satisfy the stem's requirement for a valid risk identification technique by drawing on participants' collective expertise to surface threats and vulnerabilities not captured by historical data. This qualitative, exploratory approach suits identifying unknown or emerging risks during IT risk assessment, complementing analytical methods such as checklist analysis or fault tree analysis.
- ✗
Residual risk assessment
Why it's wrong here
Residual risk assessment measures the risk remaining after existing controls are applied, so it presupposes that risks and controls are already known. It would be correct during risk evaluation to judge whether treatment is adequate, not during identification.
- ✗
Risk aggregation
Why it's wrong here
Risk aggregation combines individual risk exposures into a portfolio or enterprise view for reporting and prioritisation; it operates on risks already identified. It would be correct during risk evaluation or reporting, not as a technique for discovering risks during the identification stage.
- ✗
Monte Carlo simulation
Why it's wrong here
Monte Carlo simulation quantifies the probability and impact of identified risks by running repeated random trials; it produces risk exposure figures rather than discovering new risks. It would be correct during risk analysis, after identification, to model aggregate loss distributions for the register.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.