What is the Starting Point for Asset Risk Analysis?
Which of the following should be the starting point when performing a risk analysis for an asset?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of the risk assessment workflow, commonly trapping candidates who prematurely jump to solution-oriented steps like control assessment or scenario mapping.
Mastering the sequential steps of IT risk analysis is essential for passing the CRISC exam. The testing community unanimously agrees that evaluating threats must be the initial step before developing scenarios or evaluating controls.
Option B (Assess risk scenarios) is frequently selected because it appears comprehensive, but scenarios cannot be accurately constructed without first identifying the underlying threats and vulnerabilities.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Evaluating threats is the logical and methodologically sound starting point after an asset has been identified. According to ISACA and NIST SP 800-30 guidelines, understanding potential sources of harm is required to determine likelihood, which directly feeds into risk calculation. Without first cataloging threats, you cannot accurately measure exposure or prioritize subsequent analysis steps.Why the Other Options Are Wrong
Assessing controls is a mitigation activity that occurs during risk treatment, long after risks have been analyzed and prioritized. Developing risk scenarios requires prior knowledge of threats and vulnerabilities to construct realistic cause-and-effect models. Updating the risk register is an administrative action that documents findings throughout the process, not a starting analytical step.Community Comment Notes
Test-takers overwhelmingly support this approach, with multiple high-rated comments reinforcing that threat evaluation provides the necessary context for all downstream risk activities. As noted by top voters, you must identify what could harm the asset before you can effectively map out risk scenarios or design appropriate safeguards. This consensus aligns perfectly with official CRISC study objectives and real-world audit practices.Official Reference
Exam Strategy
Always follow the standard risk management sequence: identify assets, evaluate threats and vulnerabilities, calculate likelihood and impact, then select controls. If an option describes gathering intelligence versus implementing a fix, choose the intelligence-gathering step first.
Related Analysis
Practice All CRISC Questions
Access 332 questions with complete answers and detailed explanations.
View Full CRISC Practice Test →