mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: The exhibit shows a log entry from a GRC system
Exhibit
Refer to the exhibit. ``` GRC System Log - Risk Score Update Timestamp: 2024-09-15 14:30:22 Update type: Batch Risk ID: R-1042 Previous inherent risk score: 12 (High) Current inherent risk score: 9 (Medium) Control effectiveness status: Not updated Risk owner: JSmith Comment: Change due to mitigation project completion. ```
The exhibit shows a log entry from a GRC system. Which of the following is the MOST significant concern regarding this risk score update?
⚠ Common exam trap
ISACA often tests the candidate's ability to identify data integrity issues in risk calculations rather than focusing on procedural or documentation details, so the trap here is that candidates may choose the comment detail option (C) because it seems like a common audit finding, but the core issue is the mathematical inconsistency in the risk score update.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The control effectiveness status was not updated alongside the risk score
The risk score update without a corresponding update to the control effectiveness status creates a data integrity issue in the GRC system. Since the residual risk score is calculated as inherent risk multiplied by (1 - control effectiveness), changing the score without adjusting the effectiveness metric means the system's risk calculation is now inconsistent and unreliable for monitoring and reporting purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The control effectiveness status was not updated alongside the risk score
Why this is correct
Without updating control effectiveness, residual risk cannot be accurately assessed.
- ✗
The inherent risk score decreased without any change in the business environment
Why it's wrong here
Inherent risk can decrease due to mitigation projects.
- ✗
The comment does not provide sufficient detail on the mitigation project
Why it's wrong here
While more detail is helpful, the core issue is the missing control status.
- ✗
The risk owner was not notified of the change
Why it's wrong here
The log shows the risk owner in the comment, but notification status is unknown.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.