Courseiva

CRISC Risk Response and Reporting Practice Question

A multinational retailer's risk register shows a high inherent risk for its point-of-sale (POS) payment environment. After implementing tokenization, the risk owner records a residual risk rating of low. During the next quarterly review, the internal audit team finds that several legacy POS terminals still transmit clear-text card data. Which risk response principle was violated?

⚠ Common exam trap

The trap here is treating residual risk as a theoretical calculation after a control is purchased, rather than a validated measurement of control coverage and effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk response must be validated against actual control coverage before residual risk is reported.

Residual risk is only meaningful when it reflects validated control effectiveness across the full scope of the risk. The risk owner lowered the rating based on tokenization without confirming that legacy terminals were included, so the reported low residual risk was inaccurate. Risk response and reporting require evidence that controls operate as designed before risk ratings are adjusted downward, and audit findings should trigger reassessment of the affected register entries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk response must be validated against actual control coverage before residual risk is reported.

    Why this is correct

    Residual risk represents what remains after controls are applied, so it must reflect verified control effectiveness across the entire scope. Reporting low residual risk while legacy terminals still transmit clear-text data overstates control coverage and understates exposure. The risk owner should have validated that tokenization covered all in-scope terminals before adjusting the rating, making this the violated principle.

  • ✗

    Risk response must transfer residual risk to a third party whenever inherent risk is rated high.

    Why it's wrong here

    Transfer is only one of several response options and is never automatically required based on inherent risk alone. Organizations may mitigate, accept, avoid, or transfer depending on cost, appetite, and feasibility. In this scenario, the retailer chose mitigation through tokenization, which is a legitimate response; the deficiency was failing to verify that the mitigation actually covered all terminals before declaring low residual risk.

  • ✗

    Risk response must be approved by the board before any residual risk rating can be lowered.

    Why it's wrong here

    Board approval thresholds depend on the organization's risk appetite and delegation of authority, and routine control implementations do not require board sign-off. The scenario problem is that residual risk was reported as low despite incomplete control deployment, not that an approval step was skipped. Requiring board approval for every rating change would be impractical and is not a stated CRISC risk response principle.

  • ✗

    Risk response must always prioritize risk avoidance over risk mitigation for payment environments.

    Why it's wrong here

    No CRISC principle mandates avoidance over mitigation for payment environments. Organizations commonly mitigate payment risk through tokenization, encryption, and segmentation because avoiding card processing entirely is often commercially impossible. The failure here was inaccurate residual risk reporting, not the choice of mitigation over avoidance. Framing avoidance as mandatory misstates the risk response guidance and distracts from the real control coverage gap.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.