CRISC IT Risk Assessment Practice Question
A risk analyst is building a control assessment for a payment processing environment. She needs to determine whether a new control objective is adequately addressed. She has identified the control objective, the associated risk, and the control activity. Which of the following should she do NEXT to complete the control assessment?
⚠ Common exam trap
The trap here is assuming that identifying the control activity completes the assessment, when in fact effectiveness testing is required to validate that the control works as intended.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Test the operating effectiveness of the control activity and document the results.
After defining the control objective, risk, and control activity, the assessor must test the control's operating effectiveness to determine whether the objective is actually met. Design alone does not prove effectiveness. Testing produces evidence that supports a conclusion, which is the purpose of a control assessment in IT risk management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identify additional risks that could affect the same control objective and add them to the assessment scope.
Why it's wrong here
Expanding the scope by identifying additional risks may be useful later, but it does not complete the assessment of the current control objective. The immediate need is to evaluate whether the existing control activity addresses the identified risk. Adding risks before testing the current control would delay the assessment and dilute focus.
- ✗
Perform a business impact analysis to quantify the potential loss from the risk.
Why it's wrong here
A business impact analysis is used in business continuity planning to determine recovery priorities and outage tolerances. It does not evaluate whether a specific control activity is operating effectively. While impact data can inform risk ratings, it is not the next step in a control assessment focused on a single control objective and activity.
- ✗
Revisit the risk register to confirm the risk rating and update the risk appetite statement.
Why it's wrong here
Updating the risk appetite statement is a governance activity, not a control assessment step. The scenario already identified the risk and control objective, so revisiting the risk register does not advance the control assessment. It may be useful for context, but it does not verify whether the control activity is effective in addressing the identified risk.
- ✓
Test the operating effectiveness of the control activity and document the results.
Why this is correct
Testing operating effectiveness is the next logical step after identifying the control objective, risk, and control activity. It verifies whether the control actually works as intended and provides evidence for the control assessment conclusion. Without testing, the assessment is only design-level and cannot support a conclusion about whether the control objective is met in practice.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.