Courseiva

CRISC Risk Response and Reporting Practice Question

A risk manager is updating the risk report for the IT steering committee. Which THREE elements should be included to provide a comprehensive view of the risk posture?

⚠ Common exam trap

ISACA often tests the distinction between operational details (like firewall configs) and strategic risk reporting elements, trapping candidates who confuse granular technical data with the high-level summaries needed for governance-level decision-making.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk trend analysis

Risk trend analysis (B) is correct because tracking how risk exposure changes over time (e.g., increasing, decreasing, or stable risk levels across reporting periods) gives the steering committee insight into whether risk management efforts are effective and where emerging risks are developing. A risk heat map (C) is correct because it visually plots risks by likelihood and impact, enabling the committee to quickly identify and prioritize the highest-exposure areas across the organization's risk posture. Top risks and their status (E) is correct because summarizing the most significant risks along with their current mitigation status, owners, and progress provides the committee with actionable, decision-ready information for governance. Names of all IT employees (A) is not a risk posture element—it is personnel data with no bearing on risk likelihood, impact, or treatment. Detailed configuration of each firewall (D) is far too granular and technical for a steering-committee risk report; such operational detail belongs in technical security documentation, not executive risk reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Names of all IT employees

    Why it's wrong here

    Employee names give no view of risk exposure, likelihood or control effectiveness, so they add nothing to a posture report. It is tempting because personnel data feels relevant to accountability, and would be appropriate in an access review or staffing annex, not in a steering committee risk posture summary.

  • ✓

    Risk trend analysis

    Why this is correct

    Risk trend analysis reveals whether exposure is rising, falling or stable over successive reporting periods, satisfying the committee's need to judge direction rather than a single snapshot. Plotting inherent and residual risk across cycles exposes deteriorating controls and validates whether prior treatments worked, giving the forward-looking context a comprehensive posture view requires.

  • ✓

    Risk heat map

    Why this is correct

    A risk heat map plots likelihood against impact, giving the steering committee a visual, prioritised view of the aggregated risk posture across the enterprise. It satisfies the demand for a comprehensive overview by condensing many individual risks into comparable severity bands, enabling informed direction-setting and resource allocation decisions.

  • ✗

    Detailed configuration of each firewall

    Why it's wrong here

    Per-firewall configuration detail buries the committee in operational data rather than summarising risk exposure and treatment status. It is tempting because firewall misconfiguration is a genuine risk source, and such detail would be correct in a technical security assessment or audit workpaper, not an executive risk report.

  • ✓

    Top risks and their status

    Why this is correct

    Top risks and their status give the steering committee the prioritised exposures and current treatment progress, satisfying the demand for a comprehensive posture view. Reporting only residual scores or heat maps omits ownership and remediation state, so this element supplies the forward-looking tracking the committee needs to govern.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.