Courseiva
IT Risk Assessment →hardMultiple Choice

CRISC IT Risk Assessment Practice Question

A risk analyst is assessing a critical application's inherent risk. After implementing controls, the residual risk is calculated as high. The analyst determines that the control design is adequate but operating effectiveness is poor. Which factor most likely explains the high residual risk?

⚠ Common exam trap

The trap here is conflating control design with control operating effectiveness; candidates see 'adequate design' and assume the control must be working, overlooking that a well-designed control can still fail in operation and leave residual risk high.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Control operating effectiveness is poor

Residual risk is the risk remaining after controls are applied, and it is a function of both control design and control operating effectiveness. The scenario explicitly states the design is adequate but operating effectiveness is poor, meaning the controls exist on paper but are not functioning as intended in practice. Poor operating effectiveness therefore leaves the original inherent risk largely unmitigated, producing a high residual risk despite good design.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Control design is inadequate

    Why it's wrong here

    The stem states the control design is adequate, so inadequate design cannot be the cause; residual risk remains high because the controls are not operating as designed. Design adequacy is tempting because weak design commonly drives high residual risk, but that scenario is explicitly excluded here.

  • ✓

    Control operating effectiveness is poor

    Why this is correct

    Residual risk reflects inherent risk after controls operate, not merely after they are designed. Adequate design with poor operating effectiveness means controls fail to mitigate in practise, so the high residual risk is explained by ineffective operation rather than design weakness.

  • ✗

    Risk appetite was misstated

    Why it's wrong here

    Risk appetite is the tolerance threshold used to judge whether a given exposure is acceptable; it does not alter control operation, so a misstated appetite cannot cause poor operating effectiveness. It is tempting because appetite shapes risk decisions, but here the controls are designed adequately and merely failing to run as intended.

  • ✗

    Inherent risk is too low

    Why it's wrong here

    Inherent risk is the exposure before controls; if it were too low, residual risk would fall rather than stay high. The option is tempting because inherent risk feeds the residual calculation, but the stem attributes the high residual to poor operating effectiveness of otherwise adequate controls.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.