hardMultiple SelectObjective-mapped
CISA Practice Question: Which THREE of the following are key elements…
Which THREE of the following are key elements that should be included in a risk assessment report for information systems?
⚠ Common exam trap
It's easy for candidates to confuse operational or financial details (vendor lists, budgets) with the core risk assessment deliverables, which must focus on assets, vulnerabilities, controls, and risk treatment decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identification of critical assets and their vulnerabilities
A is correct because a risk assessment report must identify critical assets and their vulnerabilities to establish the scope and basis for risk analysis. Without this, the report cannot prioritize which systems require immediate attention or justify subsequent control recommendations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identification of critical assets and their vulnerabilities
Why this is correct
Needed to understand what is at risk.
- ✓
Recommendations for risk mitigation or acceptance
Why this is correct
Provides actionable next steps.
- ✗
List of all vendors and their contract terms
Why it's wrong here
Not typically part of an IS risk assessment report.
- ✓
Evaluation of current controls and their effectiveness
Why this is correct
Essential to assess residual risk.
- ✗
Detailed budget for implementing security controls
Why it's wrong here
Budget is a separate planning document.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.