Courseiva

CRISC Risk Response and Reporting Practice Question

A hospital's IT risk manager is preparing a quarterly risk report for the executive committee. The report currently lists 240 technical vulnerabilities with CVSS scores but no business context. The CIO asks for a report that helps executives decide where to allocate limited remediation funding. Which change best aligns the report with risk response and reporting objectives?

⚠ Common exam trap

The trap here is equating more technical detail or cleaner formatting with better risk reporting, when executives actually need business impact and likelihood context to make funding decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Group vulnerabilities by the business processes and assets they affect, and express exposure in terms of potential impact and likelihood.

Risk reporting to executives must translate technical findings into business language. Grouping vulnerabilities by affected processes and assets and expressing exposure through impact and likelihood gives leaders the context needed to prioritize remediation spending against organizational objectives. Raw counts, technical artifacts, or alphabetical ordering do not support funding decisions because they omit the business consequences that drive risk-based prioritization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report only the total count of vulnerabilities and the percentage remediated within the past quarter.

    Why it's wrong here

    Counts and remediation percentages provide a activity metric but omit which business services are exposed and how severe the consequences could be. Executives could see progress without understanding where the greatest residual risk remains, leading to misallocation of funds. Risk reporting should connect control status to business impact, not reduce a complex exposure to a single volume statistic.

  • ✓

    Group vulnerabilities by the business processes and assets they affect, and express exposure in terms of potential impact and likelihood.

    Why this is correct

    Executive decision-making requires business context, not raw technical counts. Mapping vulnerabilities to the processes and assets they threaten, then expressing exposure through impact and likelihood, lets leaders compare remediation options against organizational objectives and risk appetite. This transforms a technical inventory into actionable risk information, which is the core purpose of risk reporting to senior stakeholders.

  • ✗

    Sort the vulnerabilities alphabetically by vendor name so the report is easier to navigate.

    Why it's wrong here

    Alphabetical sorting improves navigation but does nothing to convey business risk or support prioritization. The CIO's request is about allocating limited remediation funding, which requires understanding which exposures threaten critical services and which are tolerable. Vendor-based ordering ignores impact, likelihood, and asset criticality, so it fails to meet the reporting objective described in the scenario.

  • ✗

    Increase the report's technical depth by including exploit code snippets and packet captures for each vulnerability.

    Why it's wrong here

    Adding exploit code and packet captures increases technical detail without improving executive decision support. Executives need to understand business consequences, funding trade-offs, and risk prioritization, not exploitation mechanics. This change would make the report less usable for the intended audience and would not help allocate limited remediation funding based on organizational impact.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.