Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

When prioritizing risk treatment actions, which of the following should be the primary consideration?

⚠ Common exam trap

CRISC often tests the misconception that ease of implementation or compliance alone should drive risk treatment prioritization, when the primary consideration is risk level combined with cost-benefit analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk level and cost-benefit analysis

Risk treatment prioritization should be driven by the level of risk (likelihood and impact) combined with a cost-benefit analysis of the treatment options. This ensures that resources are allocated to the most significant risks where the treatment provides the greatest reduction in risk relative to its cost, aligning with business objectives and risk appetite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ease of implementation

    Why it's wrong here

    Ease of implementation optimises effort rather than exposure reduction, so low-impact quick wins could outrank severe risks. It is tempting because effort informs sequencing, and it would be correct for scheduling approved treatments — not for deciding which risks get treated first.

  • ✗

    Compliance requirements only

    Why it's wrong here

    Compliance requirements cover only regulated obligations, leaving material risks outside scope unranked. It is tempting because mandates carry deadlines and penalties, and it would be correct when prioritising regulatory remediation — not as the primary basis for enterprise-wide risk treatment.

  • ✓

    Risk level and cost-benefit analysis

    Why this is correct

    Risk level and cost-benefit analysis directly satisfy the prioritisation constraint by ranking treatments against both exposure magnitude and the economics of mitigation. Residual risk reduction per unit of spend determines sequencing, ensuring limited resources target the highest-impact exposures first rather than addressing every identified risk equally.

  • ✗

    Risk owner preference

    Why it's wrong here

    Risk owner preference is subjective and can conflict with enterprise risk appetite, so it cannot drive prioritisation. It is tempting because owners understand their domain and fund treatment, and their input is correct for validating treatment plans — not for setting the primary ranking criterion.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.