Courseiva
IT Risk Assessment →hardMultiple Choice

CRISC IT Risk Assessment Practice Question

An organization calculated the inherent risk for a critical system as 'High' using a 5x5 heat map. After implementing controls, the residual risk is assessed as 'Medium'. What does this indicate about the control effectiveness?

⚠ Common exam trap

Test-takers frequently assume any reduction in risk means controls are fully effective and risk is acceptable, but CRISC requires you to compare residual risk against the organization's specific risk appetite and target level, not just the inherent risk baseline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Controls are partially effective, reducing risk but not to the target level

The movement from 'High' inherent risk to 'Medium' residual risk indicates that the implemented controls have reduced the risk level by one step on the 5x5 heat map, but have not eliminated it entirely. Since the residual risk is still 'Medium' rather than 'Low' or 'Very Low', the controls are only partially effective—they mitigate some of the risk but do not bring it down to the organization's target risk appetite or tolerance level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Controls are fully effective and risk is now acceptable

    Why it's wrong here

    A drop from High to Medium shows controls reduced risk but residual remains above the organisation's acceptance threshold, so effectiveness is partial. It is tempting because any reduction looks like success, and full effectiveness would be correct only if residual fell within the defined risk appetite.

  • ✗

    Controls are ineffective and need replacement

    Why it's wrong here

    Residual falling from High to Medium proves the controls altered likelihood or impact, so they are not ineffective. It is tempting because Medium still exceeds appetite, and replacement would be correct only where residual risk remained unchanged or increased after implementation.

  • ✓

    Controls are partially effective, reducing risk but not to the target level

    Why this is correct

    The drop from High inherent risk to Medium residual risk shows controls are operating but only partially, since risk remains above the organisation's defined tolerance. Residual risk reflects what persists after control implementation, so a Medium rating confirms mitigation occurred without reaching the target level, meaning further treatment or additional controls are required.

  • ✗

    Residual risk should equal inherent risk if controls are effective

    Why it's wrong here

    Effective controls reduce inherent risk to a lower residual level; equality would indicate controls changed nothing. It is tempting because it sounds like a baseline comparison, and it would be correct only where no controls exist or where controls are entirely ineffective, leaving risk unmitigated.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.