easyMultiple ChoiceObjective-mapped
CRISC Practice Question: Defines its risk appetite as 'no more than one…
An organization defines its risk appetite as 'no more than one major security incident per year.' During the year, a major incident occurs. The monitoring team reports this to the risk committee. What should be the NEXT step?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the incident to determine if risk appetite needs adjustment.
After a major incident occurs, the risk committee should analyze the incident to determine if the current risk appetite remains appropriate or if adjustments are needed. Option A is incorrect because immediately changing the risk appetite without analysis is reactive and may not align with organizational objectives. Option C is incorrect because reporting to the board of directors is typically done after analysis and determination of impact, not as the immediate next step. Option D is incorrect because accepting the incident without review fails to address potential gaps in controls or risk appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately change the risk appetite to tolerate two incidents per year.
Why it's wrong here
Changing without analysis is arbitrary.
- ✓
Review the incident to determine if risk appetite needs adjustment.
Why this is correct
Appropriate escalation and review.
- ✗
Report the breach to the board of directors.
Why it's wrong here
Board reporting may follow committee review.
- ✗
Accept the incident and continue with current controls.
Why it's wrong here
No analysis of improvement.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.