Courseiva
mediumMultiple SelectObjective-mapped

What Is the Primary Purpose of a Risk Register?

Which TWO of the following are primary purposes of a risk register?

Quick Answer

Documenting identified risks and their characteristics is a primary purpose of a risk register because the register's core job is to serve as the authoritative, structured inventory of everything the organization knows about its risk landscape, with each entry capturing details like probability, impact, risk score, and the assigned risk owner. Without this documentation function, an organization would have no consistent way to compare risks against each other, prioritize which ones need attention first, or communicate risk posture to stakeholders and auditors. The register's other core purpose is tracking the status of risk treatment over time, meaning whether a control has been implemented, is still in progress, or is overdue, which keeps risk owners accountable and shows whether residual risk is actually being reduced as promised. These two functions work together: you can't track treatment progress on a risk that was never formally documented, and documentation without ongoing tracking becomes a static list that quickly goes stale. This structure reflects standard risk management guidance found in frameworks like NIST SP 800-37 and ISO 31000, both of which treat the risk register as a living record rather than a one-time assessment output. When a question asks about the purpose of a risk register, look for answers describing either the recording of risk details or the ongoing tracking of treatment status, since those are the two pillars it exists to support.

⚠ Common exam trap

Test-takers frequently confuse the risk register with operational security tools like vulnerability scanners or log management systems, leading them to select options that describe technical data storage rather than the risk management documentation and tracking functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Track the status of risk treatment plans

A risk register is a living document used to track the status of risk treatment plans, including whether controls have been implemented, are in progress, or are overdue. This ensures that risk owners are accountable and that residual risk is managed over time. Option B is correct because the primary function of a risk register is to document identified risks along with their characteristics, such as probability, impact, risk score, and owner. These two functions are core to the risk management process as defined by frameworks like NIST SP 800-37 and ISO 31000.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Track the status of risk treatment plans

    Why this is correct

    The risk register tracks mitigation actions and their progress.

  • Document identified risks and their characteristics

    Why this is correct

    This is a core purpose of a risk register.

  • Record network traffic logs

    Why it's wrong here

    Network logs are stored in SIEM or log management systems.

  • Store vulnerability scan results

    Why it's wrong here

    Vulnerability scan results are typically stored in a separate tool or report.

  • Provide a checklist for compliance audits

    Why it's wrong here

    A compliance checklist is a different artifact.

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following is the primary purpose of a risk register?

easy
  • A.To record all security incidents after they occur
  • B.To track changes made to system configurations
  • C.To document and track identified risks and their treatment
  • D.To automatically detect vulnerabilities in the network

Why C: The primary purpose of a risk register is to document and track identified risks along with their treatment plans, including risk owners, likelihood, impact, and mitigation status. This aligns with the Risk Identification, Monitoring and Analysis domain, where the risk register serves as a central repository for risk management activities throughout the system development life cycle.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.