Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

A risk practitioner is preparing a risk report for the executive committee. The committee has limited time and has previously complained that reports contain too much technical detail. Which approach BEST communicates the most critical IT risks to this audience?

⚠ Common exam trap

The trap here is assuming that more comprehensive technical data automatically produces a more useful executive risk report.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Summarize the top risks by business impact and alignment with risk appetite, with recommended actions.

Executive risk reporting must be selective, business-oriented, and connected to appetite. Summarizing top risks by business impact and appetite alignment, with recommended actions, gives the committee what it needs to govern: which exposures matter, how they compare to tolerance, and what decisions are required. Full registers, scan counts, and incident-only reporting either overwhelm, mislead, or arrive too late.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Focus on the number of vulnerabilities detected in the latest technical scan.

    Why it's wrong here

    Vulnerability counts describe technical activity and often fluctuate with scanner configuration rather than reflecting genuine business exposure. Executives cannot judge whether ten thousand findings are better or worse than eight thousand without context on asset criticality, exploitability, and potential impact. This metric belongs in operational security reporting, where remediation teams can act on it directly.

  • ✗

    Provide the full risk register with all identified risks and their control test results.

    Why it's wrong here

    The complete register is a management and audit tool, not an executive communication device. Presenting every risk and test result overwhelms a time-limited audience and obscures the few exposures that require leadership attention. Executives need aggregation and business context, while the full register remains available for those who need operational depth, such as risk owners and auditors.

  • ✓

    Summarize the top risks by business impact and alignment with risk appetite, with recommended actions.

    Why this is correct

    Executive reporting succeeds when it translates technical findings into business consequence and links them to the appetite leadership approved. Ranking by impact and appetite alignment focuses attention on decisions the committee can actually make, such as funding treatment or accepting a documented exception. Recommended actions close the loop by giving the committee a clear choice rather than raw data.

  • ✗

    Present only risks that have already resulted in a confirmed loss or incident.

    Why it's wrong here

    Restricting reporting to realized events makes the process reactive and hides emerging exposures before they cause harm. Many significant risks, such as concentration of credentials or unpatched internet-facing systems, may not yet have produced a loss but still threaten objectives. Executive oversight depends on seeing forward-looking risk, not just a retrospective incident log.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.