CRISC IT Risk Assessment Practice Question
When performing a risk assessment, which TWO of the following are components of inherent risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Impact of the risk event
Inherent risk considers likelihood and impact without controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Residual risk level
Why it's wrong here
Residual risk is the exposure remaining after controls are applied, so it cannot be a component of inherent risk, which is assessed before mitigation. It is tempting because residual risk is a genuine risk-register output, and it would be the right focus when reporting whether existing controls bring exposure within the organisation's risk appetite.
- ✓
Impact of the risk event
Why this is correct
Inherent risk is assessed before controls, and impact measures the potential magnitude of loss or harm should the risk event occur. It forms one of the two components, alongside likelihood, that together express inherent risk exposure in the absence of mitigation.
- ✗
Control effectiveness
Why it's wrong here
Control effectiveness measures how well existing mitigations reduce risk, which determines residual rather than inherent risk. It is tempting because both appear in risk registers, but control effectiveness would be the correct answer when the question asks how residual risk is calculated after controls are applied.
- ✓
Likelihood of a threat event
Why this is correct
Likelihood estimates the probability that a given threat event will actually occur, assessed before considering existing controls. Combined with impact, it constitutes inherent risk, which is evaluated prior to any risk response or control adjustment.
- ✗
Cost-benefit analysis of controls
Why it's wrong here
Cost-benefit analysis of controls evaluates whether proposed mitigations are worth their expense, which belongs to risk response and control selection after inherent risk is assessed. It is tempting because it informs risk decisions, and it would be correct when justifying or prioritising which controls to implement.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.