20+ practice questions focused on Risk Response and Reporting — one of the most tested topics on the Certified in Risk and Information Systems Control CRISC exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Risk Response and Reporting PracticeDuring a cost-benefit analysis for a proposed control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce the ALE to $100,000. The control implementation cost is $150,000, and the annual operating cost is $30,000. What is the net annual benefit of the control?
Explanation: The net annual benefit is calculated as the reduction in ALE minus the annual operating cost and the implementation cost (treated as an annual cost for this calculation). The reduction in ALE is $500,000 - $100,000 = $400,000. Subtracting the annual operating cost of $30,000 gives $370,000, then subtracting the implementation cost of $150,000 yields $220,000.
Which of the following is the best example of a Key Control Indicator (KCI) for a firewall rule review process?
Explanation: A Key Control Indicator (KCI) measures the effectiveness of a control by tracking its operational performance. For a firewall rule review process, the percentage of rules reviewed within the defined period directly indicates whether the control (periodic review) is being executed as intended, ensuring that stale or overly permissive rules are identified and remediated on schedule.
An organization is implementing continuous monitoring for its network security controls. Which TWO of the following are examples of continuous monitoring techniques?
Explanation: Options D and E are correct because continuous monitoring involves automated, ongoing validation of security controls. Option D, automated control testing via SIEM rules, operates in real-time by analyzing logs and triggering alerts. Option E, weekly vulnerability scanning, while scheduled, is an automated process that provides frequent, regular assessments, which is a key component of a continuous monitoring program. In contrast, options A, B, and C are performed too infrequently (annually or quarterly) to be considered continuous.
A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?
Explanation: Preventive controls are designed to stop an incident from occurring. In this case, preventing unauthorized access aligns with a preventive control.
The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?
Explanation: The ALE reduction is $400,000. Subtracting the control cost of $150,000 gives a net benefit of $250,000.
+15 more Risk Response and Reporting questions available
Practice all Risk Response and Reporting questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Risk Response and Reporting. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Risk Response and Reporting questions on the CRISC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Risk Response and Reporting is tested as part of the Certified in Risk and Information Systems Control CRISC blueprint. Practicing with targeted Risk Response and Reporting questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CRISC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Risk Response and Reporting is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Risk Response and Reporting practice session with instant scoring and detailed explanations.
Start Risk Response and Reporting Practice →