Courseiva
Risk Response and ReportinghardMultiple SelectObjective-mapped

CRISC Risk Response and Reporting Practice Question

In the context of IT risk reporting to the board, which THREE elements should be included to effectively communicate risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Top risks and status

A risk heat map, top risks and status, and risk trend analysis help the board understand the current and evolving risk landscape.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Detailed technical logs

    Why it's wrong here

    Too granular for board-level reporting.

  • Top risks and status

    Why this is correct

    Highlights key concerns and progress.

  • Risk heat map

    Why this is correct

    Provides a visual summary of risk posture.

  • Employee performance reviews

    Why it's wrong here

    Not relevant to risk reporting.

  • Risk trend analysis

    Why this is correct

    Shows how risks are changing over time.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.