CRISC Risk Response and Reporting Practice Question
A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?
⚠ Common exam trap
Test-takers frequently confuse operational data (like logs or asset lists) with strategic risk reporting content, failing to recognize that the committee needs summarized, decision-supporting visuals (heat map) and prioritized risk status, not raw technical details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk heat map
A risk heat map (A) is essential because it visually prioritizes risks by likelihood and impact, allowing the IT risk committee to quickly identify and compare exposure across the risk portfolio. Top risks and their status (D) must be included so the committee can focus on the most significant threats, track mitigation progress, and make informed governance decisions. Individual employee performance metrics (B) are an HR concern and do not reflect organizational risk posture. Detailed technical logs (C) are too granular and operational for a quarterly executive-level risk report. A list of all IT assets (E) is an inventory artifact, not a risk report element, and would overwhelm the committee without risk context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk heat map
Why this is correct
A risk heat map gives the committee an aggregated, visual view of likelihood and impact across the portfolio, enabling prioritisation and comparison of exposures. This satisfies the stem's requirement for the most important content in a quarterly IT risk committee report.
- ✗
Individual employee performance metrics
Why it's wrong here
Employee performance metrics measure individual productivity, not IT risk exposure, so they give the committee nothing to prioritise or accept. Such data belongs in HR and performance reviews, where it informs staffing and development decisions.
- ✗
Detailed technical logs
Why it's wrong here
Detailed technical logs record raw system events for operational troubleshooting, not the aggregated risk exposure, treatment status and residual risk positions a committee needs for oversight decisions. They are tempting because logging underpins monitoring and forensic investigation, and would suit a technical operations or incident review meeting rather than this governance-focused quarterly risk report.
- ✓
Top risks and their status
Why this is correct
Listing top risks with their current status shows movement since the last quarter, including treatment progress, emerging exposures and changes in rating. This satisfies the stem's requirement for the most important content in a quarterly IT risk committee report.
- ✗
List of all IT assets
Why it's wrong here
Excessive detail not relevant for risk reporting.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.