Courseiva

CRISC · topic practice

Risk Response and Reporting practice questions

Domain 3 of CRISC (16%) covers selecting and implementing risk responses, then reporting risk to stakeholders. Questions are scenario-based: you choose controls, interpret KRIs and metrics, align IT risk with enterprise risk management, and judge what leadership reporting should contain. Expect control classification, metric interpretation, and program-integration judgment calls rather than tool configuration.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Risk Response and Reporting

What the exam tests

What to know about Risk Response and Reporting

You must be able to pick the right risk response for a scenario, classify the control by function, read a KRI trend and act on it, and report risk in business terms aligned to risk appetite. The single most important thing: match the response and reporting to the organization's risk appetite and tolerance.

Classifying controls as preventive, detective, corrective, or compensating when a scenario describes a new safeguard

Interpreting a Key Risk Indicator trend, such as rising average patch lag time, and selecting the appropriate response

Explaining how integrating IT risk management with enterprise risk management improves decision making and risk visibility

Identifying critical elements of a security awareness program that build a sustained risk-aware culture

Watch out for

Common Risk Response and Reporting exam traps

  • ▸Treating a rising KRI as a reporting formality instead of a trigger for reassessing and adjusting the risk response.
  • ▸Labeling controls by technology rather than by function, so preventive controls get misclassified as detective or corrective.
  • ▸Reporting raw technical metrics to executives instead of translating risk into business impact and comparing it to risk appetite.

Practice set

Risk Response and Reporting questions

20 questions · select your answer, then reveal the explanation

An IT risk manager is preparing a quarterly risk report for the CISO. Which type of reporting structure does this represent?

A vendor is classified as 'critical' based on its access to sensitive data and the criticality of its service. According to best practices, what minimum security requirement should be mandated for this vendor?

Which risk reporting frequency is most appropriate for tactical risk reporting to the CISO/CIO?

An organization is designing a vendor risk management program. Which TWO of the following are essential components of ongoing vendor monitoring? (Select TWO)

Which THREE of the following are common elements of a periodic control effectiveness testing program? (Select THREE)

Which of the following is a detective control?

Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?

An organization is implementing a new control to address a high-risk vulnerability. Which TWO factors are MOST important to consider during the control implementation planning phase?

A third-party vendor has been tiered as 'high risk' due to access to sensitive customer data. The vendor's SOC 2 Type II report has a qualified opinion on security controls. The vendor risk appetite requires unqualified SOC 2 Type II for critical vendors. What is the MOST appropriate risk response?

Which of the following is a detective control?

A risk practitioner is developing a tactical risk report for the CISO. Which TWO of the following elements should be included in the report? (Select TWO)

Which TWO of the following are examples of continuous monitoring techniques for IT controls? (Select TWO)

A third-party vendor has been assessed as high risk due to its access to sensitive data. Which TWO ongoing monitoring activities are most appropriate for this vendor? (Select two.)

During a cost-benefit analysis for a proposed control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce the ALE to $100,000. The control implementation cost is $150,000, and the annual operating cost is $30,000. What is the net annual benefit of the control?

An organization is implementing a new access control system. Which of the following is the most important activity to ensure the control is effectively integrated into operations?

A Key Risk Indicator (KRI) for a critical system is the number of unpatched vulnerabilities older than 30 days. The threshold is set at 5. This KRI is best described as:

During a quarterly control effectiveness test, internal audit discovers that a key automated control failed 15% of the time due to a software bug. The risk owner decides to accept the risk because the cost to fix the bug is high. What should the risk manager do next?

An organization is developing a vendor risk management program. Which THREE activities should be included in the initial onboarding assessment for a high-risk vendor?

A risk practitioner is designing a quarterly IT risk report for the CISO. Which of the following elements is MOST critical for tactical decision-making?

Which of the following is the BEST Key Control Indicator (KCI) for measuring the effectiveness of a firewall?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Risk Response and Reporting sessions

Start a Risk Response and Reporting only practice session

Every question in these sessions is drawn from the Risk Response and Reporting domain — nothing else.

Related practice questions

Related CRISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CRISC exam test about Risk Response and Reporting?
You must be able to pick the right risk response for a scenario, classify the control by function, read a KRI trend and act on it, and report risk in business terms aligned to risk appetite. The single most important thing: match the response and reporting to the organization's risk appetite and tolerance.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Risk Response and Reporting questions in a focused session?
Yes — the session launcher on this page draws every question from the Risk Response and Reporting domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CRISC topics?
Use the topic links above to move to related areas, or go back to the CRISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CRISC exam covers. They are not copied from any real exam or dump site.