What is the Starting Point for Asset Risk Analysis?

Which of the following should be the starting point when performing a risk analysis for an asset?

  1. Assess controls.
  2. Assess risk scenarios.
  3. Evaluate threats. Source Reference Answer
  4. Update the risk register.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your understanding of the risk assessment workflow, commonly trapping candidates who prematurely jump to solution-oriented steps like control assessment or scenario mapping.

Mastering the sequential steps of IT risk analysis is essential for passing the CRISC exam. The testing community unanimously agrees that evaluating threats must be the initial step before developing scenarios or evaluating controls.

Option B (Assess risk scenarios) is frequently selected because it appears comprehensive, but scenarios cannot be accurately constructed without first identifying the underlying threats and vulnerabilities.

Community Discussion (4 comments)

Silvias4 👍 2 Selected: C
First you evaluate threats.
Radko96 👍 2 Selected: C
First evaluate threats
dolumo 👍 2 Selected: C
i think this should be C. You evaluate the threats first before you can properly draw up effective risk scenarios.
Baddest 👍 3 Selected: C
C. Evaluate threats. Evaluating threats involves identifying potential sources of harm or danger to the asset. By understanding the threats that could impact the asset, organizations can better assess the associated risks and implement appropriate controls to mitigate them effectively. Threat evaluation provides essential context for analyzing the likelihood and potential impact of various risk scenarios associated with the asset.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Evaluating threats is the logical and methodologically sound starting point after an asset has been identified. According to ISACA and NIST SP 800-30 guidelines, understanding potential sources of harm is required to determine likelihood, which directly feeds into risk calculation. Without first cataloging threats, you cannot accurately measure exposure or prioritize subsequent analysis steps.

Why the Other Options Are Wrong

Assessing controls is a mitigation activity that occurs during risk treatment, long after risks have been analyzed and prioritized. Developing risk scenarios requires prior knowledge of threats and vulnerabilities to construct realistic cause-and-effect models. Updating the risk register is an administrative action that documents findings throughout the process, not a starting analytical step.

Community Comment Notes

Test-takers overwhelmingly support this approach, with multiple high-rated comments reinforcing that threat evaluation provides the necessary context for all downstream risk activities. As noted by top voters, you must identify what could harm the asset before you can effectively map out risk scenarios or design appropriate safeguards. This consensus aligns perfectly with official CRISC study objectives and real-world audit practices.

Official Reference

Exam Strategy

Always follow the standard risk management sequence: identify assets, evaluate threats and vulnerabilities, calculate likelihood and impact, then select controls. If an option describes gathering intelligence versus implementing a fix, choose the intelligence-gathering step first.

Related Analysis

Practice All CRISC Questions

Access 332 questions with complete answers and detailed explanations.

View Full CRISC Practice Test →

← Back to CRISC Study Guide