Courseiva
hardMultiple SelectObjective-mapped

CISA Practice Question: Which THREE of the following are key elements…

Which THREE of the following are key elements that should be included in a risk assessment report for information systems?

⚠ Common exam trap

It's easy for candidates to confuse operational or financial details (vendor lists, budgets) with the core risk assessment deliverables, which must focus on assets, vulnerabilities, controls, and risk treatment decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Identification of critical assets and their vulnerabilities

A is correct because a risk assessment report must identify critical assets and their vulnerabilities to establish the scope and basis for risk analysis. Without this, the report cannot prioritize which systems require immediate attention or justify subsequent control recommendations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identification of critical assets and their vulnerabilities

    Why this is correct

    Needed to understand what is at risk.

  • Recommendations for risk mitigation or acceptance

    Why this is correct

    Provides actionable next steps.

  • List of all vendors and their contract terms

    Why it's wrong here

    Not typically part of an IS risk assessment report.

  • Evaluation of current controls and their effectiveness

    Why this is correct

    Essential to assess residual risk.

  • Detailed budget for implementing security controls

    Why it's wrong here

    Budget is a separate planning document.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.