CRISC Risk Response and Reporting Practice Question
A risk practitioner is developing a tactical risk report for the CISO. Which TWO of the following elements should be included in the report? (Select TWO)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control performance metrics
Tactical risk reporting typically includes control performance metrics and top risks with status. Risk heat maps and trend analyses are more strategic, and detailed logs are operational.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Long-term risk trend analysis
Why it's wrong here
Long-term trends are more strategic.
- ✗
Risk heat map
Why it's wrong here
Risk heat maps are more common in strategic reporting.
- ✗
Detailed log analysis from SIEM
Why it's wrong here
Detailed logs are operational, not tactical.
- ✓
Control performance metrics
Why this is correct
Control performance is relevant for tactical management.
- ✓
Top risks and their status
Why this is correct
Top risks and status are key for tactical reporting.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.