Courseiva

CRISC Risk Response and Reporting Practice Question

An organization has a risk culture where employees are hesitant to report security incidents due to fear of blame. Which of the following initiatives would MOST effectively promote a risk-aware culture?

⚠ Common exam trap

The trap is choosing a control-based or punitive response (training, audits, discipline) when the scenario describes a cultural problem — CRISC tests whether candidates address root causes rather than symptoms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a confidential incident reporting system with a no-blame policy

Establishing a confidential incident reporting system with a no-blame policy directly addresses the root cause — fear of blame — by removing the deterrent to reporting. This creates psychological safety, which is a prerequisite for a healthy risk-aware culture where employees surface issues early.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the frequency of security awareness training

    Why it's wrong here

    Awareness training addresses knowledge gaps, not the fear of blame that suppresses reporting, so the cultural barrier remains. It is tempting because training is the usual lever for improving security behaviour, and it would be correct where staff simply lack the knowledge to recognise or report incidents.

  • ✓

    Establish a confidential incident reporting system with a no-blame policy

    Why this is correct

    A confidential reporting channel combined with a no-blame policy removes the fear of reprisal that suppresses incident reporting, directly addressing the cultural barrier described. Employees report near misses and incidents earlier, improving detection and organisational learning.

  • ✗

    Conduct more frequent audits to detect unreported incidents

    Why it's wrong here

    Audits detect unreported incidents after the fact and reinforce the punitive perception that drives under-reporting, worsening the culture. It is tempting because auditing is a standard assurance control, and it would be correct where the concern is verifying compliance rather than encouraging voluntary disclosure.

  • ✗

    Discipline employees who fail to report incidents

    Why it's wrong here

    Disciplining non-reporters directly strengthens the blame culture, increasing the fear that already stops employees reporting. It is tempting because sanctions appear to enforce accountability, and they would be correct where deliberate concealment, rather than fear, is the identified problem.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.