Courseiva
IT Risk Assessment →easyMultiple Select

CRISC IT Risk Assessment Practice Question

When performing a risk assessment, which TWO of the following are components of inherent risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Impact of the risk event

Inherent risk considers likelihood and impact without controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Residual risk level

    Why it's wrong here

    Residual risk is the exposure remaining after controls are applied, so it cannot be a component of inherent risk, which is assessed before mitigation. It is tempting because residual risk is a genuine risk-register output, and it would be the right focus when reporting whether existing controls bring exposure within the organisation's risk appetite.

  • ✓

    Impact of the risk event

    Why this is correct

    Inherent risk is assessed before controls, and impact measures the potential magnitude of loss or harm should the risk event occur. It forms one of the two components, alongside likelihood, that together express inherent risk exposure in the absence of mitigation.

  • ✗

    Control effectiveness

    Why it's wrong here

    Control effectiveness measures how well existing mitigations reduce risk, which determines residual rather than inherent risk. It is tempting because both appear in risk registers, but control effectiveness would be the correct answer when the question asks how residual risk is calculated after controls are applied.

  • ✓

    Likelihood of a threat event

    Why this is correct

    Likelihood estimates the probability that a given threat event will actually occur, assessed before considering existing controls. Combined with impact, it constitutes inherent risk, which is evaluated prior to any risk response or control adjustment.

  • ✗

    Cost-benefit analysis of controls

    Why it's wrong here

    Cost-benefit analysis of controls evaluates whether proposed mitigations are worth their expense, which belongs to risk response and control selection after inherent risk is assessed. It is tempting because it informs risk decisions, and it would be correct when justifying or prioritising which controls to implement.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.