nerdexam
Isaca

CISA · Question #81

An organization's IT risk assessment should include the identification of:

The correct answer is A. vulnerabilities. An IT risk assessment fundamentally involves identifying weaknesses or flaws within systems and processes that could be exploited.

Submitted by helene.fr· Apr 18, 2026Governance and Management of IT

Question

An organization’s IT risk assessment should include the identification of:

Options

  • Avulnerabilities
  • Bcompensating controls
  • Cbusiness process owners
  • Dbusiness needs

How the community answered

(46 responses)
  • A
    91% (42)
  • B
    4% (2)
  • C
    2% (1)
  • D
    2% (1)

Why each option

An IT risk assessment fundamentally involves identifying weaknesses or flaws within systems and processes that could be exploited.

AvulnerabilitiesCorrect

Vulnerabilities are weaknesses that could be exploited by threats to cause harm, and identifying these is a core component of a risk assessment to understand potential points of failure or attack. Without knowing the vulnerabilities, an organization cannot accurately assess the likelihood or impact of a risk event.

Bcompensating controls

Compensating controls are implemented *after* risks are identified to mitigate them, not identified *as part of* the initial risk identification phase.

Cbusiness process owners

Business process owners are individuals responsible for processes, but their identification is not a direct output of the technical risk assessment itself, though they may provide input.

Dbusiness needs

Business needs define the objectives and requirements, which inform the scope of the risk assessment, but are not direct 'identifications' within the assessment's core findings of risk elements.

Concept tested: IT risk assessment components

Source: https://learn.microsoft.com/en-us/compliance/regulatory/risk-assessment

Topics

#IT Risk Assessment#Vulnerability Identification#Risk Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice