CRISC Risk Response and Reporting Practice Question
An IT risk report for the board of directors should primarily focus on:
⚠ Common exam trap
CRISC often tests the confusion between operational reporting for management and strategic risk reporting for the board, tempting candidates to choose detailed technical data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Top risks, trends, and control performance metrics
A board-level IT risk report should communicate the most significant risks, emerging trends, and the effectiveness of controls in mitigating those risks. This enables directors to make informed strategic decisions and fulfill governance responsibilities. Operational details are typically reserved for management-level reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Specific control failures with root cause analysis
Why it's wrong here
Control failures and root cause analysis are operational detail that a board cannot act on strategically; board reporting should aggregate risk exposure against business objectives and risk appetite. It is tempting because root cause analysis is exactly what an IT risk committee or control owner needs, but that audience differs from the board.
- ✗
Detailed technical vulnerability scan results
Why it's wrong here
Vulnerability scan output is technical, voluminous and tactical, so it obscures the aggregated risk posture and appetite alignment the board needs for strategic decisions. It is tempting because scan results are concrete evidence of exposure, and they would be the right content for a security operations or technical remediation meeting, not board reporting.
- ✗
Operational incident counts
Why it's wrong here
Operational incident counts provide a lagging indicator of security events, but the board requires a forward-looking risk posture assessment that aligns with business objectives and risk appetite. This metric fails to convey residual risk levels or control effectiveness, which are the board’s primary concern. It is tempting because incident counts are concrete and easily tracked in security operations centres, and would be correct for an operational review of security team performance rather than a strategic risk report.
- ✓
Top risks, trends, and control performance metrics
Why this is correct
Boards govern rather than operate, so they need aggregated top risks, directional trends and control performance metrics to judge whether risk appetite is being met. Operational detail and raw incident logs obscure this strategic view, failing the stem's board-reporting purpose.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.