Courseiva

CRISC Risk Response and Reporting Practice Question

Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)

⚠ Common exam trap

Many candidates confuse operational detail (like vendor lists or control descriptions) with strategic reporting content, failing to recognize that senior management needs aggregated, decision-focused information rather than granular technical data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk trend analysis over time

Option A (Risk trend analysis over time) is essential because senior management needs to see whether the organization's risk posture is improving, worsening, or stable across reporting periods, which supports strategic decisions rather than a single point-in-time snapshot. Option B (Risk heat map showing current risk levels) is correct because a heat map visually prioritizes risks by likelihood and impact, enabling executives to quickly grasp the current risk landscape and focus attention on the highest-exposure areas. Option D (List of top risks and their mitigation status) is correct because it tells leadership which risks matter most and whether remediation efforts are on track, directly supporting accountability and resource allocation. Option C is not essential because listing every third-party vendor with contract details is a procurement or vendor-management artifact, not a concise risk-reporting element for senior management. Option E is not essential because detailed control deficiency descriptions are operational-level detail better suited to audit or control-owner reports, whereas senior management needs aggregated, decision-oriented risk information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk trend analysis over time

    Why this is correct

    Trend analysis over time reveals whether risk exposure is rising, falling or stable, letting senior management judge whether current mitigation spending is working. Without this longitudinal view, the report shows only a static snapshot and cannot support the forward-looking direction the board needs for risk appetite decisions.

  • ✓

    Risk heat map showing current risk levels

    Why this is correct

    A heat map plots likelihood against impact, letting senior management instantly rank exposures by severity and compare them against the stated risk appetite. This visual prioritisation satisfies the need for an at-a-glance view of current risk levels across the whole portfolio.

  • ✗

    Names of all third-party vendors with contracts

    Why it's wrong here

    Vendor contract names are procurement detail, not risk exposure; senior management needs aggregated risk by business objective. A vendor inventory belongs in third-party risk registers or due-diligence reporting, where each supplier's criticality and controls are tracked operationally.

  • ✓

    List of top risks and their mitigation status

    Why this is correct

    Listing top risks with their mitigation status tells senior management which exposures matter most and whether agreed treatments are on track. This satisfies the report's decision-support purpose, since executives need to know residual risk and outstanding remediation actions, not exhaustive inventories.

  • ✗

    Detailed control deficiency descriptions

    Why it's wrong here

    Control deficiency descriptions are audit-level detail; senior management reports require risk likelihood, impact and treatment status mapped to objectives. Deficiency-level listings belong in audit findings or remediation trackers reviewed by control owners, not executive risk summaries.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.