Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

Which of the following best describes the purpose of tactical risk reporting?

⚠ Common exam trap

Candidates often confuse the audience and time horizon of reporting levels—candidates often mistake tactical reporting for operational metrics (Option C) because both involve technical details, but tactical reporting is decision-focused for management, not daily task execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To enable the CISO to make informed decisions about risk mitigation priorities

Tactical risk reporting is designed to provide mid-level management, such as the CISO, with actionable insights to prioritize risk mitigation activities. It focuses on operational risk decisions, not strategic oversight or daily metrics, enabling informed choices about resource allocation and remediation timelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To satisfy regulatory compliance requirements

    Why it's wrong here

    Tactical risk reporting exists to inform operational decisions and track mitigation progress against current risk exposure, not to evidence compliance. Regulatory reporting is a separate, periodic obligation driven by external mandates; satisfying it would be the correct aim only when the stem concerns demonstrating adherence to a specific regulation or standard.

  • ✗

    To inform the board of directors about strategic risk exposure

    Why it's wrong here

    Informing the board of strategic risk exposure is strategic risk reporting, not tactical, which targets senior management below board level. It is tempting because both report risk upward, but the distinguishing axis is audience and time horizon, not the mere act of reporting.

  • ✗

    To provide daily operational metrics to system administrators

    Why it's wrong here

    Daily operational metrics for administrators describe operational or technical reporting, not tactical risk reporting, which addresses risk at business-unit or project level. It is tempting because tactical reporting is frequent, but its audience is management overseeing risk treatment, not system administrators.

  • ✓

    To enable the CISO to make informed decisions about risk mitigation priorities

    Why this is correct

    Tactical reporting translates risk data into prioritised mitigation actions for senior security leadership, supporting near-term resource allocation decisions. Strategic reporting addresses long-term risk appetite, while operational reporting handles day-to-day execution, so tactical reporting uniquely equips the CISO to sequence mitigation priorities.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.