Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

Which of the following best describes residual risk?

⚠ Common exam trap

Many candidates confuse inherent risk (risk with no controls) with residual risk (risk after controls), leading candidates to incorrectly select Option C, especially when the question emphasizes 'risk assessment' without explicitly mentioning control evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk after assessing control effectiveness

Residual risk is the risk that remains after management has implemented risk responses and assessed the effectiveness of existing controls. It is calculated by considering the inherent risk (risk without controls) and the risk reduction provided by controls, factoring in control gaps or weaknesses. Option D correctly captures this definition by emphasizing the assessment of control effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk that is transferred to a third party

    Why it's wrong here

    Transferred risk is risk shifted to a third party, typically via insurance or contractual indemnity, and it still remains the organisation's responsibility if the transfer fails. It is tempting because transfer is a recognised risk response, but residual risk denotes exposure remaining after all responses, including transfer, are applied.

  • ✗

    Risk that is avoided by eliminating the activity

    Why it's wrong here

    Avoidance eliminates the activity generating the risk entirely, so no residual exposure from that activity persists. It is tempting because avoidance is a valid risk response, but residual risk describes what remains after controls or treatments, not the outcome of removing the underlying process altogether.

  • ✗

    Risk without any controls in place

    Why it's wrong here

    Residual risk is what remains after existing controls are applied, not the exposure with none in place; that untreated exposure is inherent risk. The confusion arises because inherent risk is the starting baseline before mitigation, and it is the figure used when assessing raw impact prior to any control design.

  • ✓

    Risk after assessing control effectiveness

    Why this is correct

    Residual risk is the exposure that remains after controls have been implemented and their effectiveness assessed. It reflects what is left once mitigation is accounted for, distinguishing it from inherent risk, which exists before any controls are applied.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.