Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

When prioritizing risk treatment actions, which factor is most important to consider alongside the risk level?

⚠ Common exam trap

The trap here is that candidates often prioritize regulatory compliance or implementation speed over economic justification, but CRISC emphasizes that risk treatment must be cost-effective to ensure sustainable risk management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cost-benefit analysis of controls

Risk treatment prioritization must balance the cost of controls against the expected reduction in risk. A cost-benefit analysis ensures that the selected controls provide a net positive value, preventing over-investment in low-impact risks or under-investment in high-impact ones. This aligns with the ISACA Risk IT Framework, which emphasizes that risk treatment decisions should be economically justified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cost-benefit analysis of controls

    Why this is correct

    Risk level alone cannot justify treatment; the cost of the control must be weighed against the loss it prevents, so cost-benefit analysis determines whether mitigation is worthwhile. This satisfies the stem's requirement for the factor considered alongside risk level when prioritising actions.

  • ✗

    Number of stakeholders involved

    Why it's wrong here

    Not as critical.

  • ✗

    Regulatory requirements only

    Why it's wrong here

    Regulatory requirements are one input to risk criteria, not the sole companion to risk level; CRISC expects business impact and appetite to shape prioritisation. It tempts because compliance obligations can mandate treatment regardless of assessed level, making regulation decisive in heavily regulated environments where non-compliance carries penalties.

  • ✗

    Time required to implement controls

    Why it's wrong here

    Implementation time is a scheduling input, not the factor paired with risk level when ranking treatment actions; CRISC expects business impact and likelihood alignment. It tempts because effort estimates genuinely inform delivery planning once treatment is approved, and quick wins can be sequenced early within an agreed risk response programme.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.