Courseiva
hardMultiple Choice

CRISC Practice Question: A company has a low risk appetite but high risk…

A company has a low risk appetite but high risk tolerance. Which of the following scenarios is consistent with this situation?

⚠ Common exam trap

Watch out — candidates often confuse risk appetite (the willingness to take risk) with risk tolerance (the capacity to withstand risk), leading candidates to incorrectly associate high tolerance with accepting high risk, when in fact high tolerance allows for acceptance of residual risk after controls are applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The company invests heavily in cybersecurity controls but accepts some residual risk

A low risk appetite means the company is unwilling to accept high levels of risk, while high risk tolerance indicates it can absorb the financial or operational impact of residual risk that remains after controls are applied. Investing heavily in cybersecurity controls reduces inherent risk to a low residual level, aligning with the low appetite, and the acceptance of some residual risk is consistent with the high tolerance. This scenario reflects a balanced approach where controls are prioritized to meet appetite, and tolerance allows for manageable leftover risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The company avoid controls and accepts high risk

    Why it's wrong here

    Avoiding controls and accepting high risk breaches the low-appetite requirement to keep exposure minimal. It is tempting because high tolerance permits accepting risk, and would be correct where appetite is also high, allowing controls to be skipped in pursuit of objectives.

  • ✓

    The company invests heavily in cybersecurity controls but accepts some residual risk

    Why this is correct

    Risk appetite is the level of risk the organisation is willing to pursue, while tolerance is the acceptable deviation from that appetite. Heavy investment in controls reflects low appetite, and accepting residual risk shows tolerance for variation within limits.

  • ✗

    The company has aggressive growth targets and accepts any IT risk

    Why it's wrong here

    Accepting any IT risk contradicts a low risk appetite, which demands minimal risk exposure. It is tempting because aggressive growth with high tolerance sounds consistent, and would fit a company with high appetite and high tolerance, not the low-appetite scenario described.

  • ✗

    The company invests minimally in controls and has low residual risk

    Why it's wrong here

    Minimal control investment yielding low residual risk is internally inconsistent; low appetite requires strong controls. It is tempting because low residual risk appears to satisfy low appetite, and would be correct if the company genuinely tolerated little risk rather than tolerating high exposure.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.