Courseiva

CRISC Risk Response and Reporting Practice Question

Which risk reporting level is typically provided to the board of directors and focuses on strategic risk posture?

⚠ Common exam trap

Candidates often confuse 'strategic' with 'operational' or 'tactical' because they think the board needs detailed technical data, when in fact the board requires aggregated, high-level information focused on long-term strategy and risk appetite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Strategic risk reporting

Strategic risk reporting is the correct level for the board of directors because it focuses on high-level, long-term risks that could affect the organization's strategic objectives and overall business posture. Unlike tactical or operational reports, strategic reports aggregate risk data into a format that supports governance, risk appetite decisions, and capital allocation at the executive level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Tactical risk reporting

    Why it's wrong here

    Tactical risk reporting covers business-unit or project-level risks and operational mitigation activity, so it lacks the enterprise-wide strategic focus the board requires. It is tempting because tactical reports do reach senior management, and it would be correct when the audience is middle management needing departmental risk detail.

  • ✗

    Compliance risk reporting

    Why it's wrong here

    Compliance risk reporting addresses adherence to laws, regulations and standards, not strategic risk posture, so it cannot serve the board's strategic oversight need. It is tempting because boards do receive compliance summaries, and it would be correct when the requirement is regulatory exposure or audit findings rather than enterprise-wide strategic risk.

  • ✓

    Strategic risk reporting

    Why this is correct

    Strategic risk reporting addresses enterprise-wide, long-horizon risk posture and aggregated exposure, which is the language and scope a board requires for governance oversight. Operational and tactical reporting deal with day-to-day or function-level detail, not the strategic posture the stem specifies.

  • ✗

    Operational risk reporting

    Why it's wrong here

    Operational risk reporting covers day-to-day process, control and incident detail for management, not strategic posture. It tempts because boards receive summary reporting, but strategic risk posture is delivered through strategic risk reporting, which aggregates enterprise-level exposure.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.