Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

A risk practitioner is calculating the residual risk for a critical asset. Which THREE factors should be considered?

⚠ Common exam trap

It's easy for candidates to confuse factors that influence the decision to accept residual risk (like risk appetite and cost of controls) with the direct inputs required to calculate the residual risk level itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Control design adequacy

Residual risk is the risk remaining after controls are applied. To calculate it, you must know the inherent risk level (the risk before controls) and then assess how effectively controls reduce that risk. Control design adequacy and operating effectiveness determine how much the inherent risk is mitigated, directly impacting the residual risk calculation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cost of controls

    Why it's wrong here

    Residual risk derives from inherent risk and the effectiveness of implemented controls, not their cost; spend informs control selection, not the residual calculation itself. It tempts because budgeting is part of risk treatment planning, yet the arithmetic of residual exposure excludes financial outlay.

  • ✓

    Control design adequacy

    Why this is correct

    Residual risk depends on how much inherent risk the controls are capable of mitigating, which is determined by design adequacy. A poorly designed control cannot reduce exposure regardless of how diligently it is operated, so design adequacy directly shapes the residual risk figure.

  • ✗

    Risk appetite

    Why it's wrong here

    Risk appetite is a governance threshold used to judge whether residual risk is acceptable, not an input to computing it. It tempts because appetite shapes treatment decisions, but the calculation combines inherent likelihood and impact with control effectiveness, not tolerance levels.

  • ✓

    Inherent risk level

    Why this is correct

    Residual risk is derived by applying control mitigation to the inherent risk level, so the starting inherent exposure must be quantified first. Without knowing the gross risk before controls, the practitioner cannot determine how much risk remains after mitigation.

  • ✓

    Control operating effectiveness

    Why this is correct

    Residual risk equals inherent risk reduced by the controls in place, so the practitioner must assess how reliably those controls actually operate. A control that is poorly implemented or inconsistently applied leaves more risk than its design suggests.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.