Courseiva
Risk Response and Reporting →mediumMultiple Select

CRISC Risk Response and Reporting Practice Question

A risk practitioner is designing a risk report for the board of directors. Which TWO content elements are most appropriate for strategic risk reporting? (Select two.)

⚠ Common exam trap

Many exam-takers confuse operational reporting details (like control deficiencies or phishing test results) with strategic-level content, failing to recognize that the board requires aggregated, decision-useful summaries rather than granular data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trend analysis of top key risk indicators

Option A (Trend analysis of top key risk indicators) is correct because the board needs a forward-looking, aggregated view of how the organization's most significant risks are changing over time, and KRIs distilled to the top risks give directors the directional insight required for strategic oversight rather than operational detail. Option D (Risk heat map showing overall risk exposure) is correct because a heat map aggregates likelihood and impact across the enterprise into a single visual that lets the board quickly grasp the overall risk profile and prioritize where to focus governance attention. The remaining options do not belong at the strategic level: B (List of all control deficiencies) is an exhaustive operational/audit artifact better suited to management or the audit committee, C (Names of employees who failed phishing tests) is personally identifiable, tactical HR/security data inappropriate for board reporting, and E (Detailed log analysis results) is raw technical data that belongs to IT operations or security teams, not strategic risk reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Trend analysis of top key risk indicators

    Why this is correct

    Board-level strategic reporting requires forward-looking insight, and trend analysis of top key risk indicators shows whether exposure is rising or falling against appetite over time, enabling directors to govern direction rather than review past operational detail.

  • ✗

    List of all control deficiencies

    Why it's wrong here

    A list of all control deficiencies is operational detail that overwhelms board-level reporting; strategic reports need aggregated risk exposure and trends. It is tempting because deficiency lists suit management or audit audiences, but directors require summarised risk posture aligned to objectives.

  • ✗

    Names of employees who failed phishing tests

    Why it's wrong here

    Naming individual employees is operational HR detail, not strategic risk information; the board needs aggregated exposure and risk appetite alignment. It is tempting because phishing failure rates do evidence human-risk control effectiveness, and such names would suit an operational security awareness report to line management.

  • ✓

    Risk heat map showing overall risk exposure

    Why this is correct

    A risk heat map aggregates likelihood and impact across the portfolio, giving the board a single view of overall exposure and concentrations. This satisfies the strategic reporting need for a concise, comparable picture of where risk appetite is threatened.

  • ✗

    Detailed log analysis results

    Why it's wrong here

    Raw log analysis is operational forensic detail that cannot inform board-level strategic risk decisions; the board requires aggregated risk trends and business impact. It is tempting because logs underpin detection metrics, and detailed log review would be correct for an operational security monitoring or incident investigation report.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.