CRISC IT Risk Assessment Practice Question
An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Controls are effective in reducing risk to a lower level
The reduction from 20 to 8 indicates the controls are effective in reducing risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The residual risk is still critical
Why it's wrong here
The stem states residual risk is 8, which is medium, not critical. Controls lowered the score from 20 to 8, demonstrating risk reduction. This option is tempting because 8 remains a notable score, but the band is explicitly medium, so calling it critical contradicts the given rating scale.
- ✓
Controls are effective in reducing risk to a lower level
Why this is correct
The controls demonstrably lower risk from critical to medium, satisfying the stem's inherent-to-residual reduction. Residual risk of 8 reflects the remaining exposure after control operation, confirming effectiveness rather than mere existence. This axis—measured risk reduction—distinguishes effective controls from implemented-but-ineffective ones.
- ✗
The inherent risk was overestimated
Why it's wrong here
A residual score of 8 shows the controls reduced risk from 20, so the inherent estimate stands unless evidence shows otherwise. Overestimation would require reassessing likelihood or impact inputs, not observing control effectiveness. This option is tempting when residual risk falls far below inherent, but that gap is precisely the expected outcome of functioning controls.
- ✗
Controls are ineffective because residual risk is still above zero
Why it's wrong here
Residual risk above zero is normal and expected; controls mitigate rather than eliminate risk entirely. Effectiveness is judged by the reduction from 20 to 8, which is substantial. This option is tempting when zero risk is assumed to be the goal, but that standard is unattainable and not how risk treatment is assessed.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.