CRISC IT Risk Assessment Practice Question
A risk practitioner is prioritizing IT risks for treatment. Which factor should be the PRIMARY basis for prioritization?
⚠ Common exam trap
CRISC often tests the distinction between risk-based prioritization and cost/feasibility-based prioritization, tempting candidates to pick 'cost of controls' because it sounds pragmatic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk level (inherent or residual)
Risk prioritization must be driven by the level of risk itself — whether inherent or residual — because that reflects the likelihood and impact the organization actually faces. CRISC frames risk treatment as a response to evaluated risk, so the magnitude of risk determines what gets addressed first. Ease, cost, and personal preference are inputs to the treatment decision, not the primary basis for ranking risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ease of implementing controls
Why it's wrong here
Prioritisation must reflect likelihood and business impact, not how easily a control can be deployed. Ease of implementation is an input to treatment sequencing once risks are ranked, so it would be the right consideration when scheduling remediation effort, not when determining which risks matter most.
- ✓
Risk level (inherent or residual)
Why this is correct
Risk level drives prioritisation because it combines likelihood and impact into a single comparable value, whether inherent or residual. Treatment resources should target the highest-rated risks first, so this factor directly satisfies the stem's requirement to rank IT risks for remediation.
- ✗
Cost of controls
Why it's wrong here
Control cost is a treatment consideration, not a ranking criterion; a low-cost control for a minor risk still leaves that risk below a high-impact one. Cost belongs in the cost-benefit comparison performed after risks are ranked by likelihood and business impact, not as the primary basis for ordering them.
- ✗
Business unit manager's preference
Why it's wrong here
A manager's preference is subjective and unrelated to the risk's likelihood or impact on business objectives. Stakeholder input informs treatment decisions, but prioritisation must be driven by risk magnitude; preference would only be relevant when selecting between treatment options of comparable residual risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.