nerdexam
Isaca

CRISC · Question #175

Which of the following is the PRIMARY reason for a risk practitioner to review an organization's IT asset inventory?

The correct answer is C. To understand vulnerabilities associated with the use of the assets. The primary reason for a risk practitioner to review an IT asset inventory is to understand the vulnerabilities associated with those assets.

Submitted by lucia.co· Apr 18, 2026IT Risk Assessment

Question

Which of the following is the PRIMARY reason for a risk practitioner to review an organization's IT asset inventory?

Options

  • ATo plan for the replacement of assets at the end of their life cycles
  • BTo assess requirements for reducing duplicate assets
  • CTo understand vulnerabilities associated with the use of the assets
  • DTo calculate mean time between failures (MTBF) for the assets

How the community answered

(27 responses)
  • B
    4% (1)
  • C
    93% (25)
  • D
    4% (1)

Why each option

The primary reason for a risk practitioner to review an IT asset inventory is to understand the vulnerabilities associated with those assets.

ATo plan for the replacement of assets at the end of their life cycles

Planning for asset replacement is an IT operations function, not a primary risk management activity.

BTo assess requirements for reducing duplicate assets

Reducing duplicate assets is an efficiency and cost-saving measure, not the primary focus of risk assessment.

CTo understand vulnerabilities associated with the use of the assetsCorrect

An IT asset inventory provides a comprehensive list of all IT assets, allowing a risk practitioner to identify what needs protection, what specific vulnerabilities (e.g., outdated software, missing patches) might exist for each asset, and how these vulnerabilities could be exploited. This is fundamental for risk assessment and mitigation planning.

DTo calculate mean time between failures (MTBF) for the assets

Calculating MTBF is for reliability engineering and capacity planning, not the core function of a risk practitioner reviewing inventory.

Concept tested: Asset inventory in risk management

Source: https://learn.microsoft.com/en-us/compliance/assurance/shared-responsibility-for-cloud-security#asset-management

Topics

#IT Asset Inventory#Vulnerability Identification#IT Risk Assessment Foundations

Community Discussion

No community discussion yet for this question.

Full CRISC Practice