Courseiva
hardMultiple Select

CISA Practice Question: Which THREE of the following are key elements…

Which THREE of the following are key elements that should be included in a risk assessment report for information systems?

⚠ Common exam trap

It's easy for candidates to confuse operational or financial details (vendor lists, budgets) with the core risk assessment deliverables, which must focus on assets, vulnerabilities, controls, and risk treatment decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identification of critical assets and their vulnerabilities

A risk assessment report must begin by identifying critical assets and their associated vulnerabilities, since you cannot assess risk without knowing what you are protecting and where its weaknesses lie. Recommendations for risk mitigation or acceptance (option B) are essential because the report's purpose is to guide decision-makers on how to treat each identified risk, whether by reducing, transferring, avoiding, or accepting it. Evaluation of current controls and their effectiveness (option D) is also required, as residual risk can only be determined by measuring how well existing safeguards reduce the likelihood or impact of threats. In contrast, a list of all vendors and their contract terms (option C) is a procurement or vendor-management artifact, not a core risk assessment element, and a detailed budget for implementing security controls (option E) belongs to a remediation or project plan rather than the risk assessment report itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identification of critical assets and their vulnerabilities

    Why this is correct

    A risk assessment must inventory the assets in scope and the weaknesses threatening them; without identifying critical assets and their vulnerabilities, no meaningful likelihood or impact rating is possible. This element anchors the entire assessment, satisfying the requirement for a complete risk assessment report.

  • ✓

    Recommendations for risk mitigation or acceptance

    Why this is correct

    Risk assessment output must guide action, so documenting whether each risk should be mitigated, transferred or accepted gives management a decision basis. Without recommendations for mitigation or acceptance, the report identifies problems but prescribes nothing, failing the report's purpose.

  • ✗

    List of all vendors and their contract terms

    Why it's wrong here

    Vendor inventories and contract terms sit in procurement or third-party management records; a risk assessment report addresses threats, vulnerabilities, likelihood, impact and treatment options. It is tempting because supplier risk feeds the assessment, and a vendor list would be correct when the deliverable is supply chain due diligence rather than the risk report itself.

  • ✓

    Evaluation of current controls and their effectiveness

    Why this is correct

    Assessing existing controls determines residual risk, since inherent risk alone overstates exposure. Evaluating current controls and their effectiveness shows which safeguards already reduce likelihood or impact, so the report reflects the true remaining risk requiring management attention.

  • ✗

    Detailed budget for implementing security controls

    Why it's wrong here

    A risk assessment report documents identified threats, vulnerabilities, likelihood, impact and recommended treatment; control costs belong to a subsequent business case or budget submission. It is tempting because cost justification often accompanies risk findings, and a budget would be the correct artefact when the task is funding approval rather than risk reporting.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.