Courseiva

CRISC Risk Response and Reporting Practice Question

A risk practitioner has completed a risk assessment and documented the findings. Management must now decide how to address each identified risk. Which of the following BEST describes the purpose of the risk response process?

⚠ Common exam trap

Many candidates confuse the documentation of risk ratings with the act of responding to risk, when recording a rating leaves the exposure unchanged.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To select and implement actions that bring residual risk within the organization's risk appetite

Risk response is the decision and action phase that follows assessment. Its purpose is to bring residual risk into alignment with the organization's risk appetite through mitigation, transfer, avoidance, or authorized acceptance. It is not about eliminating all risk, merely documenting ratings, or centralizing ownership in one team; it is about taking proportionate, accountable action on the exposures that matter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To document the inherent risk rating for each asset so it can be reported to regulators

    Why it's wrong here

    Documenting inherent ratings is part of risk assessment and reporting, not the response process. Recording a rating changes nothing about the exposure itself. Response requires a decision and an action, whether that is adding a control, transferring exposure, exiting an activity, or formally accepting the risk with the appropriate authority.

  • ✗

    To transfer ownership of every risk to the information security team for remediation

    Why it's wrong here

    Risk ownership belongs with the business process owner who has the authority and budget to change the activity generating the risk, not with a single central team. Assigning all risks to information security removes accountability from the people who control the underlying process and typically overwhelms a team that cannot remediate business-owned exposures. Ownership assignment is part of the process, but wholesale transfer to one team is not its purpose.

  • ✗

    To eliminate all identified risks regardless of the cost of the controls required

    Why it's wrong here

    Eliminating every risk is neither achievable nor economically rational; some risks are inherent to the business model and some controls cost more than the exposure they address. The objective is to align residual risk with appetite, not to reach zero risk. Pursuing total elimination would divert resources from higher-priority exposures and could make core business activities unviable.

  • ✓

    To select and implement actions that bring residual risk within the organization's risk appetite

    Why this is correct

    The risk response process exists to move exposure from its assessed level to a level the organization is willing to tolerate. Selecting and implementing mitigation, transfer, avoidance, or authorized acceptance achieves that alignment. It is the bridge between knowing what the risk is and doing something proportionate about it, and it is judged by whether residual risk lands within the appetite the board has approved.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.