Courseiva

CRISC Risk Response and Reporting Practice Question

A software company has a risk appetite statement allowing no more than two hours of downtime per quarter for its customer-facing API. During a quarterly review, the risk practitioner discovers that a single unplanned database failover event caused 90 minutes of downtime, and a separate configuration error caused 45 minutes. Both events were resolved, but no root cause analysis was completed for either. Which of the following should the risk practitioner recommend FIRST?

⚠ Common exam trap

The trap here is jumping to a technical fix or an appetite revision before establishing why the downtime occurred and whether the incidents share a root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate a root cause analysis for both incidents to determine whether the downtime events share an underlying control weakness.

The downtime exceeded the stated appetite, and the lack of root cause analysis leaves the reason for the breach unknown. The practitioner's first step should be to investigate both incidents and determine whether a shared control weakness exists. Only with that understanding can a proportionate response be selected, reported accurately, or escalated to governance with meaningful options rather than an unexplained breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report to the board that the downtime appetite has been breached and await direction on a response.

    Why it's wrong here

    Escalating the breach is appropriate eventually, but reporting without any analysis leaves the board unable to make an informed decision. The practitioner should first gather facts so the report can explain causes, likelihood of recurrence, and options. Presenting a bare breach forces governance to direct a response blindly, which is not an effective use of the board's oversight role.

  • ✓

    Initiate a root cause analysis for both incidents to determine whether the downtime events share an underlying control weakness.

    Why this is correct

    The organization has already exceeded its stated downtime appetite, and the absence of root cause analysis means the underlying causes remain unknown. Before changing controls or reporting to the board, the practitioner needs to understand whether the two events stem from a common weakness. Root cause analysis provides that evidence and is the logical first step in determining an appropriate risk response.

  • ✗

    Revise the risk appetite statement to allow three hours of quarterly downtime, reflecting actual operational reality.

    Why it's wrong here

    Adjusting appetite to match performance inverts the purpose of appetite, which is to set a boundary the organization commits to manage within. Doing so without analysis or approval would effectively excuse the breach and could mislead stakeholders about service reliability. Appetite changes should follow strategic decisions, not operational shortfalls, and require formal governance approval.

  • ✗

    Recommend immediate investment in a redundant database cluster to prevent future failover downtime.

    Why it's wrong here

    Proposing a specific technical solution before understanding why the incidents occurred risks addressing symptoms rather than causes. The 45-minute configuration error would not have been prevented by database redundancy. Committing budget without root cause analysis may also be rejected by governance, since the recommendation is not supported by evidence linking the proposed control to the actual failure modes.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.