CRISC IT Risk Assessment Practice Question
A risk analyst is assessing a critical application's inherent risk. After implementing controls, the residual risk is calculated as high. The analyst determines that the control design is adequate but operating effectiveness is poor. Which factor most likely explains the high residual risk?
⚠ Common exam trap
The trap here is conflating control design with control operating effectiveness; candidates see 'adequate design' and assume the control must be working, overlooking that a well-designed control can still fail in operation and leave residual risk high.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control operating effectiveness is poor
Residual risk is the risk remaining after controls are applied, and it is a function of both control design and control operating effectiveness. The scenario explicitly states the design is adequate but operating effectiveness is poor, meaning the controls exist on paper but are not functioning as intended in practice. Poor operating effectiveness therefore leaves the original inherent risk largely unmitigated, producing a high residual risk despite good design.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Control design is inadequate
Why it's wrong here
The stem states the control design is adequate, so inadequate design cannot be the cause; residual risk remains high because the controls are not operating as designed. Design adequacy is tempting because weak design commonly drives high residual risk, but that scenario is explicitly excluded here.
- ✓
Control operating effectiveness is poor
Why this is correct
Residual risk reflects inherent risk after controls operate, not merely after they are designed. Adequate design with poor operating effectiveness means controls fail to mitigate in practise, so the high residual risk is explained by ineffective operation rather than design weakness.
- ✗
Risk appetite was misstated
Why it's wrong here
Risk appetite is the tolerance threshold used to judge whether a given exposure is acceptable; it does not alter control operation, so a misstated appetite cannot cause poor operating effectiveness. It is tempting because appetite shapes risk decisions, but here the controls are designed adequately and merely failing to run as intended.
- ✗
Inherent risk is too low
Why it's wrong here
Inherent risk is the exposure before controls; if it were too low, residual risk would fall rather than stay high. The option is tempting because inherent risk feeds the residual calculation, but the stem attributes the high residual to poor operating effectiveness of otherwise adequate controls.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.