You must be able to pick the right risk response for a scenario, classify the control by function, read a KRI trend and act on it, and report risk in business terms aligned to risk appetite. The single most important thing: match the response and reporting to the organization's risk appetite and tolerance.
Start practicing
Risk Response and Reporting — choose a session length
Free · No account required
Domain overview
Domain 3 of CRISC (16%) covers selecting and implementing risk responses, then reporting risk to stakeholders. Questions are scenario-based: you choose controls, interpret KRIs and metrics, align IT risk with enterprise risk management, and judge what leadership reporting should contain. Expect control classification, metric interpretation, and program-integration judgment calls rather than tool configuration.
Exam objectives
Classifying controls as preventive, detective, corrective, or compensating when a scenario describes a new safeguard
Interpreting a Key Risk Indicator trend, such as rising average patch lag time, and selecting the appropriate response
Explaining how integrating IT risk management with enterprise risk management improves decision making and risk visibility
Identifying critical elements of a security awareness program that build a sustained risk-aware culture
Treating a rising KRI as a reporting formality instead of a trigger for reassessing and adjusting the risk response.
Labeling controls by technology rather than by function, so preventive controls get misclassified as detective or corrective.
Reporting raw technical metrics to executives instead of translating risk into business impact and comparing it to risk appetite.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?
2The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?
3A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?
4An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?
5When implementing a new access control system, which activity is essential during the change management process?
6An organization is implementing a continuous monitoring solution for its network. Which of the following is an example of continuous monitoring?
7During a control implementation project, the risk manager discovers that the resource requirements have increased significantly, making the original cost-benefit analysis invalid. What should the risk manager do first?
8Which of the following best describes the purpose of a risk heat map in an IT risk report?
9A critical vendor is being onboarded. The vendor risk appetite policy requires SOC 2 Type II reports for critical vendors. The vendor has provided a SOC 2 Type I report. What should the risk manager do?
10An organization's IT risk team is promoting a risk-aware culture. Which initiative is most likely to encourage employees to report security incidents without fear?
11Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?
12An organization is integrating IT risk into its enterprise risk management (ERM) program. Which TWO of the following are key benefits of this integration?
13A risk manager is designing a third-party risk management program. Which THREE factors should be considered when determining the risk tier of a vendor?
14Which TWO of the following are examples of detective controls?
15An organization is implementing a new access control system to protect sensitive data. Which type of control is most appropriate for preventing unauthorized access?
16A risk manager is evaluating the cost-effectiveness of a proposed control. The control costs $50,000 annually to implement and maintain. The current annual loss expectancy (ALE) for the risk is $200,000, and the control is expected to reduce the ALE by 70%. What is the net benefit (or loss) of implementing the control?
17Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a firewall?
18An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?
19Which type of control testing is typically performed on a continuous basis using automated tools?
20A Key Risk Indicator (KRI) that shows a rising trend in the average time to apply critical security patches suggests:
21An IT risk report for the board of directors should primarily focus on:
22When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:
23An organization wants to promote a risk-aware culture. Which initiative is most effective in encouraging employees to report security incidents without fear?
24An organization's risk report shows a risk heat map with several risks in the high-likelihood, high-impact quadrant. What is the most appropriate action for the risk owner?
25An IT risk manager is developing KRIs for a critical application. Which TWO of the following are leading indicators that the risk level may be increasing? (Select TWO)
26Which type of control is primarily designed to prevent an unwanted event from occurring?
27During a cost-benefit analysis for a new control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce risk by 80% and will cost $150,000 annually to operate. What is the net benefit of implementing the control?
28An organization uses a Key Control Indicator (KCI) to measure control effectiveness. The KCI shows a control deficiency rate of 12% over the past quarter, exceeding the target threshold of 5%. Which action is MOST appropriate as an initial response?
29Which of the following is a Key Risk Indicator (KRI) that provides leading indication of increasing vulnerability risk?
30In IT risk reporting, which level of management typically receives operational risk reporting on a weekly or monthly basis?
31A company is implementing a new access control system. During the project, the IT team updates the system configuration without notifying the risk team. This leads to a temporary misconfiguration that exposes sensitive data. Which process should have been followed to prevent this issue?
32In third-party risk management, which of the following is typically used for initial onboarding assessment of a vendor?
33An organization wants to promote a risk-aware culture. Which of the following actions is MOST effective for encouraging employees to report incidents without fear?
34During a vendor risk tiering exercise, a vendor that stores the organization's customer PII and is critical for daily operations should be classified as which tier?
35What is the primary purpose of a risk heat map in IT risk reporting?
36In the context of IT risk reporting to the board, which THREE elements should be included to effectively communicate risk?
37Which TWO methods are commonly used for continuous monitoring of IT controls?
38Which type of control is designed to operate before an event to prevent an undesirable outcome?
39An organization is evaluating a new security control that costs $50,000 annually to implement and maintain. The current annualized loss expectancy (ALE) for a related risk is $200,000. The control is expected to reduce the ALE by 85%. Using cost-benefit analysis, what is the net benefit of implementing this control?
40A Key Control Indicator (KCI) for a critical firewall rule set shows an exception rate of 12% over the past month, exceeding the acceptable threshold of 5%. The control owner is responsible for remediation. Which action should the risk practitioner recommend FIRST?
41An organization’s continuous monitoring program includes automated vulnerability scanning and log review. Which of the following is a Key Risk Indicator (KRI) that would BEST signal an increasing risk of a successful network breach?
42During a quarterly control effectiveness test, internal audit finds that a detective control missed 15% of security incidents. The control owner claims this is within the acceptable error rate of 20%. However, the risk practitioner notes that the missed incidents were high-severity. What should the risk practitioner do?
43Which risk reporting level is typically provided to the board of directors and focuses on strategic risk posture?
44An organization is implementing a new access control system. The project manager is concerned about delays due to user training requirements. Which of the following should the risk practitioner prioritize to ensure effective control implementation?
45Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?
46During a vendor risk assessment, an organization discovers that a critical vendor has not performed a security assessment in two years. The vendor is tiered as 'medium risk'. According to best practices, what should the risk practitioner recommend?
47An organization has a risk culture where employees are hesitant to report security incidents due to fear of blame. Which of the following initiatives would MOST effectively promote a risk-aware culture?
48A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)
49Which type of control is designed to stop an undesirable event from occurring?
50A risk practitioner is performing a cost-benefit analysis for a proposed control. The annualized loss expectancy (ALE) for a risk is currently $500,000. The proposed control will reduce the ALE by 80%, and the annual cost of the control is $150,000. What is the net benefit of implementing the control?
51Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a control?
52An organization uses automated SIEM rules to continuously monitor for unauthorized access attempts. This is an example of which type of monitoring?
53A Key Risk Indicator (KRI) for vulnerability management is the "average patch lag time" (number of days between patch release and deployment). In the last month, this metric increased from 15 days to 45 days. How should the risk practitioner interpret this change?
54Which of the following best describes the purpose of tactical risk reporting?
55An organization is implementing a new access control system. Which of the following should be included in the control implementation plan?
56During a vendor risk assessment, a third-party vendor is classified as "critical" because it has access to sensitive customer data. According to the organization's risk appetite, what minimum security requirement should be mandated for this vendor?
57An organization's risk committee reviews a risk heat map showing that a key IT risk has moved from the "high" to "medium" category. However, the associated control's effectiveness has decreased from 95% to 85%. What is the most likely explanation?
58Which of the following is a key element of promoting a risk-aware culture within an IT department?
59A company is integrating its IT risk management program with the enterprise risk management (ERM) program. What is the primary benefit of this integration?
60Which control implementation activity involves updating system configurations and user access rights when a new security tool is deployed?
61A risk practitioner is designing a risk report for the board of directors. Which TWO content elements are most appropriate for strategic risk reporting? (Select two.)
62An organization is implementing continuous monitoring for its critical systems. Which THREE of the following activities are examples of continuous monitoring? (Select three.)
63An organization is implementing a control to prevent unauthorized access to its critical database. The control must be designed to block access attempts in real time. Which type of control should be selected?
64A risk manager is evaluating the effectiveness of a control that requires dual authorization for high-value transactions. The Key Control Indicator (KCI) for this control is the rate of transactions processed without dual authorization (i.e., exception rate). If the acceptable exception rate is less than 1% and the observed rate is 2.5%, what is the most appropriate immediate action?
65Which of the following is the most appropriate frequency for operational IT risk reporting to IT management?
66An organization is integrating IT risk into its enterprise risk management (ERM) program. What is the primary benefit of this integration?
67A vendor risk manager is tiering vendors based on the criticality of services and data access. A vendor that processes sensitive customer data for a core business application should be classified as which tier?
68An organization wants to promote a risk-aware culture. Which of the following actions is most effective in encouraging employees to report incidents without fear?
69Which of the following is the best example of a Key Control Indicator (KCI) for a firewall rule review process?
70An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is an example of:
71A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?
72A security awareness program is being designed to promote a risk-aware culture. Which TWO elements are most critical for the program's success?
73An organization is selecting a control to prevent unauthorized access to a critical database. Which control type is most appropriate?
74During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control will cost $100,000 annually and is expected to reduce the ALE by 80%. What is the net benefit of implementing this control?
75A key control indicator (KCI) for a critical access control shows a deficiency rate of 12% for the quarter, exceeding the target of 5%. Which of the following should be the risk practitioner's PRIMARY action?
76An organization is implementing a new access control system. Which of the following is the MOST important consideration during the implementation phase?
77Which of the following is a leading Key Risk Indicator (KRI) for the risk of a data breach?
78When integrating IT risk into the enterprise risk management (ERM) program, what is the PRIMARY benefit?
79In third-party risk management, which of the following is MOST indicative of a vendor's control effectiveness for a critical vendor?
80A risk practitioner notices that the number of failed authentication attempts has spiked by 300% over the past week. Which of the following actions should be taken FIRST?
81Which of the following is the BEST example of promoting a risk-aware culture within an organization?
82During a vendor risk assessment, a prospective vendor for critical services cannot provide a SOC 2 Type II report. According to the organization's vendor risk appetite, which action should be taken?
83An organization is implementing continuous monitoring for its critical systems. Which TWO of the following are examples of continuous monitoring techniques? (Select TWO)
84Which THREE of the following are components of an effective IT risk reporting structure for a large enterprise? (Select THREE)
85A risk practitioner is evaluating the effectiveness of a security awareness program. Which TWO indicators would BEST measure whether the program is positively influencing risk culture? (Select TWO)
86An organization is implementing a new control to prevent unauthorized access to its critical database. Which type of control is most appropriate for this requirement?
87A company is evaluating the cost-benefit of a new control that reduces the annualized loss expectancy (ALE) from $500,000 to $100,000. The control has an annual cost of $150,000. What is the net benefit of implementing this control?
88An organization uses a SIEM to automatically test access control rules on a continuous basis. This is an example of which type of monitoring?
89A company is assessing a new vendor that will have access to its customer database. The vendor's security questionnaire reveals they lack SOC 2 certification. According to risk tiering, the vendor is classified as critical. What should the company do?
90An organization notices a spike in failed authentication attempts over the past week. This metric is best classified as which type of risk indicator?
91An IT risk manager is preparing a report for the board of directors. Which of the following content elements is most important for strategic risk reporting?
92A change to a critical application is being implemented without updating the associated security controls. This is most likely a failure in which process?
93Which of the following is the primary purpose of a risk heat map in a risk report?
94A third-party vendor is classified as high risk due to its access to sensitive data. Which THREE activities should be part of ongoing monitoring for this vendor?
95An organization is implementing a new access control system to prevent unauthorized access to sensitive data. Which type of control is being implemented?
96During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control is expected to reduce the ALE by 80% and will cost $150,000 per year. What is the net benefit of implementing the control?
97An organization uses Key Control Indicators (KCIs) to measure the effectiveness of its firewall change management process. Which KCI would best indicate a process deficiency?
98A security operations center (SOC) uses a Security Information and Event Management (SIEM) system to continuously monitor for suspicious activities. Which type of monitoring is being performed?
99A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?
100An organization is implementing a new control to address a high-risk finding. The project manager has scheduled a user training session and updated the relevant policies. Which implementation phase is being addressed?
101In a risk report presented to the board of directors, which of the following elements is most appropriate to include?
102Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
103An organization wants to promote a risk-aware culture. Which initiative best supports this goal?
104In the context of ERM integration, IT risk is typically considered a subset of which broader risk category?
105Which TWO of the following are examples of continuous monitoring activities? (Select TWO.)
106Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)
107Which TWO of the following are leading indicators that could be used as KRIs for information security risk? (Select TWO.)
108An organization is selecting a control to reduce the risk of unauthorized data exfiltration. The annual loss expectancy (ALE) for this risk is currently $500,000. The proposed control costs $80,000 annually and is expected to reduce the ALE by 60%. What is the net benefit (reduction in risk exposure minus control cost) of implementing this control?
109A risk manager is evaluating a control that addresses a high-risk finding from an internal audit. Which of the following is the MOST important factor in determining whether the control is effective?
110An organization has implemented a new firewall rule to block malicious IP addresses. This is an example of which type of control?
111During a quarterly risk review, the CISO notes that the number of failed authentication attempts has increased by 300% over the last month. The IT team confirms no changes to authentication systems. This metric is BEST categorized as which of the following?
112A company is implementing a new access control system. According to the project plan, user training will be delivered after the system goes live. What change management issue does this present?
113An IT risk report to the board of directors should primarily focus on which of the following?
114A risk owner is reviewing a control that has a deficiency rate of 15%. The target deficiency rate is less than 5%. Which of the following is the MOST appropriate immediate action?
115An organization is implementing continuous monitoring of its network using SIEM rules. Which of the following is the PRIMARY benefit of this approach over periodic manual testing?
116In a risk-aware culture, which of the following behaviors is MOST encouraged?
117An organization uses a KRI that tracks the average time to patch critical vulnerabilities. The metric has been increasing over the past three months. What does this indicate from a risk perspective?
118Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?
119A risk manager is updating the risk report for the IT steering committee. Which THREE elements should be included to provide a comprehensive view of the risk posture?
120An organization is implementing a third-party risk management program. Which TWO are essential components of the initial vendor risk assessment process?
121During a third-party risk management review, the organization is tiering its vendors based on risk. Which TWO of the following criteria are most relevant for determining vendor risk tier?
122An organization wants to promote a risk-aware culture. Which TWO of the following initiatives are most effective for achieving this?
123An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?
124A company's IT risk manager is evaluating Key Risk Indicators (KRIs) for the cybersecurity function. Which TWO of the following are valid examples of leading KRIs?
125An organization is designing a vendor risk assessment process for critical vendors. Which THREE of the following should be included in the initial onboarding assessment?
126A financial services firm's risk register shows that a legacy payment gateway has a high inherent risk of SQL injection. The security team proposes deploying a web application firewall (WAF) in front of the gateway. The risk owner must document how this action will be classified in the risk response plan. Which risk response strategy does deploying the WAF represent?
127A financial services firm maintains a risk register that lists inherent risk ratings for its core banking platform. During an internal audit, the CIO notes that the register has not been updated to reflect the controls implemented over the past 18 months. Which of the following should the risk practitioner do FIRST to address this gap?
128A multinational retailer operates in 14 countries and must report IT risk to its board quarterly. The CISO wants the reporting to drive decisions rather than merely satisfy auditors. Which of the following is the MOST important characteristic of the quarterly IT risk report?
129A multinational manufacturer has completed a quantitative risk analysis for a ransomware scenario affecting its primary ERP system. The analysis shows an annualized loss expectancy (ALE) of $2.4 million. A proposed endpoint detection and response (EDR) solution would cost $600,000 annually and is projected to reduce the ALE by 60%. The CFO asks the risk practitioner to justify the investment. Which of the following is the BEST response?
130A hospital network is selecting key risk indicators (KRIs) for its electronic health record (EHR) availability risk. The risk committee wants indicators that will provide early warning before an outage affects patient care. Which TWO of the following are the most appropriate KRIs for this purpose? (Choose two.)
131A healthcare provider has determined that a new telehealth platform introduces risks that exceed its defined risk tolerance. Senior management decides to purchase cyber insurance to cover potential breach costs rather than modify the platform. Which risk response is management applying?
132A risk practitioner is preparing an IT risk report for the board risk committee. The committee has limited technical background and meets quarterly. Which of the following is the MOST appropriate way to present the aggregated IT risk exposure?
133An e-commerce company discovers that a third-party payment processor suffered a breach exposing customer card data. The processor contract includes a clause requiring the vendor to indemnify the company for breach-related costs. The risk owner updates the register to show that financial loss from this vendor risk is now borne by the processor. Which risk response strategy has been applied?
134A risk practitioner is designing a key risk indicator (KRI) program for a cloud-hosted customer portal. The CISO wants indicators that provide early warning of deteriorating risk conditions rather than reporting losses that have already occurred. Which TWO of the following are the MOST appropriate KRIs for this objective? (Choose two.)
135A financial services firm has completed a risk assessment and determined that the residual risk for its online banking platform exceeds the board-approved risk appetite. The CISO must recommend risk response options to the risk committee. Which TWO of the following are appropriate risk response actions? (Choose two.)
136A software company has completed a risk assessment showing that a critical SaaS platform has a residual risk above appetite due to weak vendor access controls. Budget is limited and the remediation will take six months. The CISO must decide how to proceed while the risk remains elevated. Which action BEST aligns with CRISC risk response principles?
137A credit union's risk committee has approved a risk response for its core banking platform: purchase an insurance policy against ransomware losses and keep the current backup process unchanged. Six months later, a ransomware event encrypts production data and the backup restoration takes four days, breaching regulatory reporting deadlines. Which risk response did the risk committee most likely select, and why did it fail to address the operational impact?
138A financial services firm has completed its annual IT risk assessment. The chief risk officer asks the IT risk analyst to classify each identified risk according to the organization's risk taxonomy before any response decisions are made. Which activity should the analyst perform FIRST?
139A healthcare insurer's risk committee is reviewing key risk indicators (KRIs) for its claims processing platform. The committee wants to ensure the KRIs are actionable and tied to risk appetite. Which TWO of the following characteristics are MOST important for these KRIs to meet that objective? (Choose two.)
140A risk practitioner has completed a risk assessment and documented the findings. Management must now decide how to address each identified risk. Which of the following BEST describes the purpose of the risk response process?
141An organization's risk committee is reviewing a consolidated IT risk report before a board meeting. The report shows that a critical payment system has a residual risk rating above tolerance, but the remediation project is not scheduled to complete for nine months due to vendor dependencies. The committee must decide how to report this to the board. Which of the following is the MOST appropriate action?
142A multinational retailer's risk register shows a high inherent risk for its point-of-sale (POS) payment environment. After implementing tokenization, the risk owner records a residual risk rating of low. During the next quarterly review, the internal audit team finds that several legacy POS terminals still transmit clear-text card data. Which risk response principle was violated?
143A retail company's IT risk manager is preparing a report for the board's audit committee. The report must summarize the current status of the top ten IT risks, the effectiveness of related controls, and any changes since the last quarter. Which of the following is the MOST important quality for this report to possess?
144A healthcare payer's risk committee is deciding how to respond to a risk that its cloud-hosted claims processing platform could become unavailable for more than 24 hours. The platform is critical, the provider offers a financially backed 99.95% availability commitment, and the organization lacks the internal capability to run a secondary environment. Which risk response is MOST appropriate?
145A financial services firm's IT risk register shows that a legacy payment gateway has a high inherent risk of data breach. Management decides to purchase a cyber insurance policy that covers up to $5 million per incident, while keeping the gateway in production unchanged. Which risk response option has management chosen?
146A hospital's IT risk manager is preparing a quarterly risk report for the executive committee. The report currently lists 240 technical vulnerabilities with CVSS scores but no business context. The CIO asks for a report that helps executives decide where to allocate limited remediation funding. Which change best aligns the report with risk response and reporting objectives?
147A software company has a risk appetite statement allowing no more than two hours of downtime per quarter for its customer-facing API. During a quarterly review, the risk practitioner discovers that a single unplanned database failover event caused 90 minutes of downtime, and a separate configuration error caused 45 minutes. Both events were resolved, but no root cause analysis was completed for either. Which of the following should the risk practitioner recommend FIRST?
148A multinational retailer's IT risk manager must define key risk indicators (KRIs) for its third-party payment processing relationships. Which TWO characteristics must the selected KRIs exhibit to be effective for ongoing risk monitoring? (Choose two.)
149A multinational retailer's risk committee is reviewing its risk register. The CISO argues that a newly identified vulnerability in the point-of-sale system should be escalated immediately to the board. The risk manager notes that the vulnerability has a low likelihood of exploitation and existing compensating controls reduce the impact to a tolerable level. Which of the following is the MOST appropriate action for the risk manager to take?
150A software company is defining key risk indicators (KRIs) for its cloud service availability risk. The risk owner wants indicators that provide early warning of deteriorating conditions rather than after-the-fact outcomes. Which TWO of the following are the most appropriate leading KRIs for this risk? (Choose two.)
151A risk analyst has completed a control self-assessment and found that a key preventive control failed testing in two consecutive quarters. The risk owner asks the analyst to update the risk register. Which action BEST reflects an appropriate risk response?
152A risk practitioner has completed a quantitative risk analysis for a customer-facing payment platform. The analysis shows an inherent annualized loss expectancy (ALE) of $2.4 million. Management wants to fund a tokenization control that reduces the ALE to $600,000, but the control costs $1.9 million per year to operate. Which action should the risk practitioner recommend?
153A logistics firm relies on a third-party cloud provider to host its shipment tracking system. The provider's latest SOC 2 report includes a qualified opinion noting that access review controls were not operating effectively during part of the audit period. The firm's risk practitioner must determine the appropriate risk response. Which of the following is the MOST appropriate action?
154A financial services firm's risk committee has approved a risk response plan for its core payment platform. The plan requires monthly tracking of key risk indicators (KRIs) and quarterly reporting of control test results to the board. Six months later, the CIO asks the risk manager to confirm that the approved response is still appropriate given new regulatory guidance. Which of the following should the risk manager do FIRST?
155An organization's risk register lists a risk with an annualized loss expectancy (ALE) of $200,000. A proposed control would reduce the ALE to $50,000, and the control costs $40,000 per year to operate. What is the value of the control's risk reduction?
156A bank's risk committee is reviewing a proposal to increase the risk appetite threshold for third-party data processing failures from 2 to 5 incidents per year. The head of internal audit objects, noting that three such failures occurred in the last 12 months and one caused a regulatory finding. Which action should the risk committee take FIRST?
157An energy utility's board risk committee receives a quarterly IT risk report showing that overall risk exposure is within appetite, yet a recent regulatory audit identified unpatched internet-facing systems. The risk manager must improve the report so the committee is not misled in the future. Which change is MOST effective?
158An organization's risk register lists a ransomware exposure against its primary order-processing system. The chief information security officer decides to purchase cyber insurance that covers ransomware losses up to $10 million. Which risk response has been selected?
159An organization's risk register shows that a critical database containing customer records has a high inherent risk rating. Management installs database activity monitoring, enforces encryption at rest, and implements quarterly access reviews. After these actions, the risk is re-rated as medium. Which risk concept does the re-rated medium value BEST represent?
160A risk practitioner has completed a risk assessment for a new cloud-based payroll platform. The business owner wants to proceed immediately because the platform will save $200,000 annually. The residual risk exceeds the organization's risk appetite, and no compensating controls are in place. Which action should the risk practitioner recommend FIRST?
161A global manufacturing company is designing its IT risk reporting program. The board has requested that reports be actionable, comparable over time, and aligned with the enterprise risk management framework. Which TWO of the following characteristics are MOST important for the IT risk reports to meet these objectives? (Choose two.)
162A risk practitioner is preparing a quarterly report for the board risk committee. Senior management wants the report to show that IT risk is being managed within appetite, but the practitioner discovers that two critical control failures were identified three weeks ago and remediation is only 40 percent complete. Which approach best satisfies the practitioner's reporting obligation?
163A global retailer's risk committee is reviewing a proposal to transfer the financial impact of payment card fraud to an insurer through a cyber insurance policy. The policy has a $2 million retention and excludes losses caused by unencrypted cardholder data at rest. The organization's cardholder database is currently unencrypted. Which of the following is the MOST significant limitation the risk manager should highlight?
164An IT risk analyst is preparing a report for the board risk committee. The committee wants a single view of how much loss the organization could face from IT risks over the next year if no additional controls are implemented. Which metric should the analyst use?
165A multinational bank must report technology risk to its board risk committee each quarter. The committee has asked the risk team to strengthen the reporting so it drives decisions rather than just describing activity. Which TWO of the following changes would BEST achieve that objective? (Choose two.)
166A healthcare provider has identified a risk that a critical medical imaging system runs on an unsupported operating system. The risk owner determines that the residual risk exceeds the organization's risk appetite, but upgrading the system would cost $2 million and disrupt patient care for several weeks. Which of the following is the MOST appropriate next step?
167A multinational retailer operates in a jurisdiction that requires all payment data to remain within national borders. The risk practitioner is asked to verify that a newly deployed cloud payment service complies with this requirement before it goes live. Which activity best provides this assurance?
168A healthcare provider has experienced repeated phishing incidents that led to credential compromise. The risk committee has approved a new email security control that will quarantine suspicious messages and enforce multifactor authentication. Which TWO activities are essential to validate that the control is operating effectively after implementation? (Choose two.)
169During a quarterly risk review, a risk owner reports that a critical trading application has exceeded its residual risk tolerance for the second consecutive quarter despite remediation efforts. The risk owner proposes to continue remediation and report again next quarter. Which of the following should the risk manager do?
170An organization has decided to purchase cyber insurance to cover potential losses from a ransomware event affecting its order-processing systems. Which risk response has the organization selected?
171A risk practitioner is defining key risk indicators (KRIs) for the organization's third-party risk program after several supplier outages disrupted operations. Which TWO characteristics are essential for these KRIs to be effective for the risk committee? (Choose two.)
172A multinational manufacturer is consolidating IT risk data from business units into a single enterprise risk report for the board. The risk manager must ensure the report supports effective risk-based decision making. Which TWO of the following characteristics are MOST important for the consolidated report to include? (Choose two.)
173During a risk analysis, the risk team finds that a legacy inventory system has a single point of failure: one administrator holds the only credentials for the backup restoration process. The system supports regulatory filings with a hard deadline. Management proposes documenting the situation in the risk register and revisiting it next year. Which action should the risk practitioner take?
174A multinational retailer's risk register shows a high inherent risk rating for its third-party payment processor. The processor has since obtained an independent SOC 2 Type II report with no exceptions, and the retailer's contract includes a right-to-audit clause. The risk owner proposes lowering the residual risk rating to low. Which factor is MOST important for the risk practitioner to consider before approving the revised rating?
175An organization's risk committee is reviewing key risk indicators (KRIs) for its customer-facing web applications. The KRI for average patch latency has breached its threshold for two consecutive quarters, yet the risk register still lists the associated risk as medium with no treatment plan. Which action should the risk practitioner recommend FIRST?
176A risk practitioner is preparing a risk report for the executive committee. The committee has limited time and has previously complained that reports contain too much technical detail. Which approach BEST communicates the most critical IT risks to this audience?
You must be able to pick the right risk response for a scenario, classify the control by function, read a KRI trend and act on it, and report risk in business terms aligned to risk appetite. The single most important thing: match the response and reporting to the organization's risk appetite and tolerance.
The Courseiva CRISC question bank contains 176 questions in the Risk Response and Reporting domain, covering the 16% of the exam attributed to this domain in the official ISACA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Risk Response and Reporting domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included