Courseiva
easyMultiple Choice

CRISC Practice Question: Defines its risk appetite as 'no more than one…

An organization defines its risk appetite as 'no more than one major security incident per year.' During the year, a major incident occurs. The monitoring team reports this to the risk committee. What should be the NEXT step?

⚠ Common exam trap

The trap here is thinking that the immediate response is to change the risk appetite or escalate to the board. Candidates might overlook the need for a review to inform the decision.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the incident to determine if risk appetite needs adjustment.

The next step should be to review the incident to determine if the risk appetite needs adjustment. Risk appetite is a high-level statement of how much risk an organization is willing to accept. When an incident exceeds the stated appetite, it indicates that either the appetite was unrealistic or controls are inadequate. A review helps determine whether to adjust the appetite or improve controls. This is a proactive governance step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately change the risk appetite to tolerate two incidents per year.

    Why it's wrong here

    Risk appetite is set by governance to reflect the organisation's capacity for loss; revising it downward or upward after an incident simply to accommodate the breach removes the tolerance threshold's control value. It is tempting because appetite statements are periodically reviewed, but that review follows risk assessment, not incident occurrence.

  • ✓

    Review the incident to determine if risk appetite needs adjustment.

    Why this is correct

    The incident breached the stated risk appetite, so the committee must examine what occurred and judge whether the one-incident threshold remains realistic. Reviewing the incident to decide if the appetite needs adjustment is the logical governance follow-up before further treatment decisions.

  • ✗

    Report the breach to the board of directors.

    Why it's wrong here

    Escalating straight to the board skips the committee's own analysis of why the incident breached appetite and what response is warranted, so the board receives a report without a recommended treatment. It is tempting because boards own risk oversight, and direct reporting would be correct once the committee has assessed and formulated its recommendation.

  • ✗

    Accept the incident and continue with current controls.

    Why it's wrong here

    Accepting the incident leaves the appetite breach unaddressed, since exceeding the defined threshold signals that existing controls failed to contain risk within tolerance. It is tempting because some residual risk is always accepted, and acceptance would be correct only after analysis shows the exposure sits within a formally revised appetite.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.