Courseiva
IT Risk Assessment →hardMultiple Choice

CRISC IT Risk Assessment Practice Question

An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Controls are effective in reducing risk to a lower level

The reduction from 20 to 8 indicates the controls are effective in reducing risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The residual risk is still critical

    Why it's wrong here

    The stem states residual risk is 8, which is medium, not critical. Controls lowered the score from 20 to 8, demonstrating risk reduction. This option is tempting because 8 remains a notable score, but the band is explicitly medium, so calling it critical contradicts the given rating scale.

  • ✓

    Controls are effective in reducing risk to a lower level

    Why this is correct

    The controls demonstrably lower risk from critical to medium, satisfying the stem's inherent-to-residual reduction. Residual risk of 8 reflects the remaining exposure after control operation, confirming effectiveness rather than mere existence. This axis—measured risk reduction—distinguishes effective controls from implemented-but-ineffective ones.

  • ✗

    The inherent risk was overestimated

    Why it's wrong here

    A residual score of 8 shows the controls reduced risk from 20, so the inherent estimate stands unless evidence shows otherwise. Overestimation would require reassessing likelihood or impact inputs, not observing control effectiveness. This option is tempting when residual risk falls far below inherent, but that gap is precisely the expected outcome of functioning controls.

  • ✗

    Controls are ineffective because residual risk is still above zero

    Why it's wrong here

    Residual risk above zero is normal and expected; controls mitigate rather than eliminate risk entirely. Effectiveness is judged by the reduction from 20 to 8, which is substantial. This option is tempting when zero risk is assumed to be the goal, but that standard is unattainable and not how risk treatment is assessed.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.