Courseiva
Risk Response and Reporting →mediumMultiple Select

CRISC Risk Response and Reporting Practice Question

A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?

⚠ Common exam trap

Test-takers frequently confuse operational data (like logs or asset lists) with strategic risk reporting content, failing to recognize that the committee needs summarized, decision-supporting visuals (heat map) and prioritized risk status, not raw technical details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk heat map

A risk heat map (A) is essential because it visually prioritizes risks by likelihood and impact, allowing the IT risk committee to quickly identify and compare exposure across the risk portfolio. Top risks and their status (D) must be included so the committee can focus on the most significant threats, track mitigation progress, and make informed governance decisions. Individual employee performance metrics (B) are an HR concern and do not reflect organizational risk posture. Detailed technical logs (C) are too granular and operational for a quarterly executive-level risk report. A list of all IT assets (E) is an inventory artifact, not a risk report element, and would overwhelm the committee without risk context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk heat map

    Why this is correct

    A risk heat map gives the committee an aggregated, visual view of likelihood and impact across the portfolio, enabling prioritisation and comparison of exposures. This satisfies the stem's requirement for the most important content in a quarterly IT risk committee report.

  • ✗

    Individual employee performance metrics

    Why it's wrong here

    Employee performance metrics measure individual productivity, not IT risk exposure, so they give the committee nothing to prioritise or accept. Such data belongs in HR and performance reviews, where it informs staffing and development decisions.

  • ✗

    Detailed technical logs

    Why it's wrong here

    Detailed technical logs record raw system events for operational troubleshooting, not the aggregated risk exposure, treatment status and residual risk positions a committee needs for oversight decisions. They are tempting because logging underpins monitoring and forensic investigation, and would suit a technical operations or incident review meeting rather than this governance-focused quarterly risk report.

  • ✓

    Top risks and their status

    Why this is correct

    Listing top risks with their current status shows movement since the last quarter, including treatment progress, emerging exposures and changes in rating. This satisfies the stem's requirement for the most important content in a quarterly IT risk committee report.

  • ✗

    List of all IT assets

    Why it's wrong here

    Excessive detail not relevant for risk reporting.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.