Courseiva
IT Risk Assessment →hardMultiple Choice

CRISC IT Risk Assessment Practice Question

After implementing controls for a high-risk IT process, the residual risk is calculated as medium. The risk owner argues that the controls are not adequate because the inherent risk was critical. Which of the following should be the primary basis for determining control adequacy?

⚠ Common exam trap

CRISC often tests the misconception that controls must eliminate all risk or that inherent risk level dictates control adequacy; candidates should focus on residual risk versus risk appetite and control effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The reduction from inherent risk to residual risk based on control effectiveness

Control adequacy should be determined by the reduction from inherent risk to residual risk based on control effectiveness. The goal of controls is to mitigate risk to an acceptable level; if residual risk is medium and within the organization's risk appetite, the controls may be adequate regardless of the inherent risk being critical. The risk owner's argument that controls are inadequate solely because inherent risk was critical is flawed; what matters is the effectiveness of the controls in reducing risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The number of controls implemented

    Why it's wrong here

    Counting controls measures effort, not effect; adequacy is judged by whether residual risk falls within the organisation's risk appetite, which medium may already satisfy. It is tempting because more controls intuitively suggest stronger protection, and the count would matter when demonstrating coverage breadth during a compliance audit.

  • ✓

    The reduction from inherent risk to residual risk based on control effectiveness

    Why this is correct

    Control adequacy is judged by how far controls reduce inherent risk to residual risk, reflecting actual control effectiveness. A critical inherent rating alone does not prove controls are inadequate; the residual medium result shows measurable reduction, so the owner's argument misreads the basis for adequacy.

  • ✗

    The cost of controls relative to the asset value

    Why it's wrong here

    Cost relative to asset value is a budgeting comparison, not an adequacy test; adequacy depends on residual risk against the defined risk appetite, irrespective of spend. It is tempting because cost-benefit analysis legitimately guides control selection, and would be the right basis when justifying whether a proposed control is worth funding.

  • ✗

    The industry standards for similar processes

    Why it's wrong here

    Industry standards set a baseline expectation, but adequacy here is determined by residual risk measured against the organisation's risk appetite, which medium may already meet. It is tempting because standards provide defensible benchmarks, and would be the correct basis when assessing whether controls satisfy regulatory or certification obligations.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.