Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

A risk manager is documenting the results of an IT risk assessment. She has identified the risk, analyzed its likelihood and impact, and evaluated existing controls. Which of the following should she do NEXT?

⚠ Common exam trap

The trap here is jumping to control implementation or reporting inherent risk without first determining residual risk, which is the output needed for risk-based decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine the residual risk and compare it to the risk appetite.

The risk assessment process moves from identification to analysis to evaluation. After evaluating controls, the risk manager must calculate residual risk and compare it to risk appetite. This comparison determines whether the risk is acceptable or requires further treatment. It is the basis for risk response decisions and communication to governance bodies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report the inherent risk to the board of directors for acceptance.

    Why it's wrong here

    Reporting inherent risk alone is insufficient because it does not reflect the effect of existing controls. The board needs to understand residual risk to make informed acceptance decisions. Inherent risk is an intermediate input, not the final output of the assessment. The next step is to calculate residual risk before any reporting or acceptance discussion.

  • ✗

    Conduct a new threat modeling exercise to identify additional threats.

    Why it's wrong here

    Threat modeling may be part of risk identification, which has already been completed in this scenario. Repeating it would not advance the assessment. The current phase is risk analysis and evaluation, where residual risk determination is the logical next step. Additional threat modeling could be done later if scope changes, but it is not the immediate next action.

  • ✓

    Determine the residual risk and compare it to the risk appetite.

    Why this is correct

    After analyzing inherent risk and evaluating controls, the next step is to determine residual risk, which is the risk remaining after controls. Comparing residual risk to the organization's risk appetite informs whether additional treatment is needed. This step is essential for making risk-based decisions and for communicating the risk position to stakeholders.

  • ✗

    Implement additional controls to reduce the risk to zero.

    Why it's wrong here

    Risk cannot typically be reduced to zero, and implementing controls before determining residual risk would be premature. The assessment process first requires understanding the current risk level after existing controls. Only then can the risk manager decide if further treatment is warranted. Adding controls without this analysis may lead to unnecessary costs or misplaced efforts.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.