CRISC IT Risk Identification 2 — Questions and Answers
Question 1: What role does a risk owner play in the IT risk identification process?
- Accountable for managing a specific risk and ensuring appropriate responses are taken (Correct answer)
- Responsible only for documenting risks in the register
- In charge of conducting penetration tests
- Oversees the IT budget allocation
Correct answer: Accountable for managing a specific risk and ensuring appropriate responses are taken
A risk owner is accountable for monitoring and managing a specific risk, including ensuring that responses are implemented and effective.
Question 2: Which of the following is an example of an internal threat source?
- A disgruntled employee with access to sensitive systems (Correct answer)
- A nation-state hacking group
- A natural disaster such as a flood
- A third-party vendor malware campaign
Correct answer: A disgruntled employee with access to sensitive systems
Internal threat sources originate from within the organization, such as employees, contractors, or insiders with system access.
Question 3: What is the difference between a vulnerability and a threat in IT risk identification?
- A vulnerability is a weakness that can be exploited; a threat is a potential event that could exploit it (Correct answer)
- A threat is a weakness; a vulnerability is the probability of exploitation
- Both terms are interchangeable in CRISC
- A vulnerability is always human-caused; a threat is always technical
Correct answer: A vulnerability is a weakness that can be exploited; a threat is a potential event that could exploit it
A vulnerability is a weakness in a system or process, while a threat is an event or actor that could exploit that weakness to cause harm.
Question 4: Which CRISC concept refers to the combination of likelihood and impact of a risk?
- Risk level (Correct answer)
- Risk appetite
- Control objective
- Residual risk
Correct answer: Risk level
Risk level is the overall measure of a risk derived from its likelihood of occurrence multiplied by its potential impact on the organization.
Question 5: What is the purpose of a threat landscape analysis in CRISC risk identification?
- To understand current and emerging threats relevant to the organization's industry and environment (Correct answer)
- To design technical controls for known vulnerabilities
- To create a disaster recovery plan
- To audit user access privileges
Correct answer: To understand current and emerging threats relevant to the organization's industry and environment
Threat landscape analysis surveys the external and internal environment to identify the types of threats most likely to affect the organization.
Question 6: Which document typically provides the foundational framework for IT risk identification activities?
- IT risk management policy (Correct answer)
- Acceptable use policy
- Software development lifecycle (SDLC) guide
- Incident response playbook
Correct answer: IT risk management policy
The IT risk management policy defines the scope, methodology, roles, and objectives that guide all risk identification activities.
What role does a risk owner play in the IT risk identification process?