CRISC IT Risk Assessment Practice Question
A risk practitioner is calculating the residual risk for a critical asset. Which THREE factors should be considered?
⚠ Common exam trap
It's easy for candidates to confuse factors that influence the decision to accept residual risk (like risk appetite and cost of controls) with the direct inputs required to calculate the residual risk level itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control design adequacy
Residual risk is the risk remaining after controls are applied. To calculate it, you must know the inherent risk level (the risk before controls) and then assess how effectively controls reduce that risk. Control design adequacy and operating effectiveness determine how much the inherent risk is mitigated, directly impacting the residual risk calculation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cost of controls
Why it's wrong here
Residual risk derives from inherent risk and the effectiveness of implemented controls, not their cost; spend informs control selection, not the residual calculation itself. It tempts because budgeting is part of risk treatment planning, yet the arithmetic of residual exposure excludes financial outlay.
- ✓
Control design adequacy
Why this is correct
Residual risk depends on how much inherent risk the controls are capable of mitigating, which is determined by design adequacy. A poorly designed control cannot reduce exposure regardless of how diligently it is operated, so design adequacy directly shapes the residual risk figure.
- ✗
Risk appetite
Why it's wrong here
Risk appetite is a governance threshold used to judge whether residual risk is acceptable, not an input to computing it. It tempts because appetite shapes treatment decisions, but the calculation combines inherent likelihood and impact with control effectiveness, not tolerance levels.
- ✓
Inherent risk level
Why this is correct
Residual risk is derived by applying control mitigation to the inherent risk level, so the starting inherent exposure must be quantified first. Without knowing the gross risk before controls, the practitioner cannot determine how much risk remains after mitigation.
- ✓
Control operating effectiveness
Why this is correct
Residual risk equals inherent risk reduced by the controls in place, so the practitioner must assess how reliably those controls actually operate. A control that is poorly implemented or inconsistently applied leaves more risk than its design suggests.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.