CRISC Risk Response and Reporting Practice Question
Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)
⚠ Common exam trap
Many candidates confuse operational detail (like vendor lists or control descriptions) with strategic reporting content, failing to recognize that senior management needs aggregated, decision-focused information rather than granular technical data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk trend analysis over time
Option A (Risk trend analysis over time) is essential because senior management needs to see whether the organization's risk posture is improving, worsening, or stable across reporting periods, which supports strategic decisions rather than a single point-in-time snapshot. Option B (Risk heat map showing current risk levels) is correct because a heat map visually prioritizes risks by likelihood and impact, enabling executives to quickly grasp the current risk landscape and focus attention on the highest-exposure areas. Option D (List of top risks and their mitigation status) is correct because it tells leadership which risks matter most and whether remediation efforts are on track, directly supporting accountability and resource allocation. Option C is not essential because listing every third-party vendor with contract details is a procurement or vendor-management artifact, not a concise risk-reporting element for senior management. Option E is not essential because detailed control deficiency descriptions are operational-level detail better suited to audit or control-owner reports, whereas senior management needs aggregated, decision-oriented risk information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk trend analysis over time
Why this is correct
Trend analysis over time reveals whether risk exposure is rising, falling or stable, letting senior management judge whether current mitigation spending is working. Without this longitudinal view, the report shows only a static snapshot and cannot support the forward-looking direction the board needs for risk appetite decisions.
- ✓
Risk heat map showing current risk levels
Why this is correct
A heat map plots likelihood against impact, letting senior management instantly rank exposures by severity and compare them against the stated risk appetite. This visual prioritisation satisfies the need for an at-a-glance view of current risk levels across the whole portfolio.
- ✗
Names of all third-party vendors with contracts
Why it's wrong here
Vendor contract names are procurement detail, not risk exposure; senior management needs aggregated risk by business objective. A vendor inventory belongs in third-party risk registers or due-diligence reporting, where each supplier's criticality and controls are tracked operationally.
- ✓
List of top risks and their mitigation status
Why this is correct
Listing top risks with their mitigation status tells senior management which exposures matter most and whether agreed treatments are on track. This satisfies the report's decision-support purpose, since executives need to know residual risk and outstanding remediation actions, not exhaustive inventories.
- ✗
Detailed control deficiency descriptions
Why it's wrong here
Control deficiency descriptions are audit-level detail; senior management reports require risk likelihood, impact and treatment status mapped to objectives. Deficiency-level listings belong in audit findings or remediation trackers reviewed by control owners, not executive risk summaries.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.