CRISC IT Risk Assessment Practice Question
Which of the following best describes residual risk?
⚠ Common exam trap
Many candidates confuse inherent risk (risk with no controls) with residual risk (risk after controls), leading candidates to incorrectly select Option C, especially when the question emphasizes 'risk assessment' without explicitly mentioning control evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk after assessing control effectiveness
Residual risk is the risk that remains after management has implemented risk responses and assessed the effectiveness of existing controls. It is calculated by considering the inherent risk (risk without controls) and the risk reduction provided by controls, factoring in control gaps or weaknesses. Option D correctly captures this definition by emphasizing the assessment of control effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk that is transferred to a third party
Why it's wrong here
Transferred risk is risk shifted to a third party, typically via insurance or contractual indemnity, and it still remains the organisation's responsibility if the transfer fails. It is tempting because transfer is a recognised risk response, but residual risk denotes exposure remaining after all responses, including transfer, are applied.
- ✗
Risk that is avoided by eliminating the activity
Why it's wrong here
Avoidance eliminates the activity generating the risk entirely, so no residual exposure from that activity persists. It is tempting because avoidance is a valid risk response, but residual risk describes what remains after controls or treatments, not the outcome of removing the underlying process altogether.
- ✗
Risk without any controls in place
Why it's wrong here
Residual risk is what remains after existing controls are applied, not the exposure with none in place; that untreated exposure is inherent risk. The confusion arises because inherent risk is the starting baseline before mitigation, and it is the figure used when assessing raw impact prior to any control design.
- ✓
Risk after assessing control effectiveness
Why this is correct
Residual risk is the exposure that remains after controls have been implemented and their effectiveness assessed. It reflects what is left once mitigation is accounted for, distinguishing it from inherent risk, which exists before any controls are applied.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.