CRISC IT Risk Assessment Practice Question
A risk assessment team is prioritizing risks for treatment using inherent risk ratings. Which TWO factors should be considered when deciding which risks to treat first?
⚠ Common exam trap
CRISC often tests the confusion between inherent and residual risk — candidates pick 'number of controls already in place' which relates to residual risk, not inherent prioritization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cost-benefit analysis of potential controls
Option B (Cost-benefit analysis of potential controls) is correct because risk treatment decisions must weigh the cost of implementing a control against the expected reduction in loss exposure; a control is only justified when its benefit (risk reduction) exceeds its cost, ensuring resources are allocated efficiently. Option C (Risk ranking by inherent risk score) is correct because inherent risk ratings—likelihood and impact assessed before controls—establish the priority order; risks with the highest inherent scores represent the greatest potential exposure and should generally be treated first. Option A is not a prioritization factor by itself, since replacement value is only one input into impact and does not account for likelihood or existing controls. Option D is incorrect because a department's budget is an organizational constraint, not a risk-based criterion for prioritization. Option E is incorrect because the number of controls already in place relates to residual risk and control effectiveness, not to ranking inherent risk for treatment priority.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The asset's replacement value
Why it's wrong here
Replacement value is an asset-valuation input, not an inherent risk factor; inherent risk derives from likelihood and impact of the threat event itself. It tempts because financial value feeds impact quantification during business impact analysis, where it would legitimately inform treatment decisions.
- ✓
Cost-benefit analysis of potential controls
Why this is correct
Cost-benefit analysis weighs each control's implementation expense against the risk reduction it delivers, revealing where treatment gives the greatest return. This satisfies the stem's prioritisation requirement by ensuring resources target risks where mitigation is economically justified rather than merely highest-scoring.
- ✓
Risk ranking by inherent risk score
Why this is correct
Ranking by inherent risk score orders risks by exposure magnitude before controls are applied, directing limited treatment resources to the highest-impact exposures first. This satisfies the stem's prioritisation requirement by giving an objective, comparable basis for sequencing treatment across the assessed risk register.
- ✗
The risk owner's department budget
Why it's wrong here
A department's budget reflects ability to fund treatment, not the likelihood or impact of the risk, so it cannot rank inherent exposure. It is tempting because funding constrains what can be remediated, and would be correct when assessing residual risk treatment capacity rather than prioritising inherent risk.
- ✗
The number of controls already in place
Why it's wrong here
Existing controls affect residual risk, not inherent risk, which by definition excludes them; prioritising on inherent ratings means control coverage is irrelevant here. It tempts because control counts do inform treatment sequencing once residual exposure is compared, making it a valid input in a residual-risk-based prioritisation exercise.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.