Courseiva
mediumMultiple Select

Components of an IT Risk Assessment Report — ISACA Guidelines

Which THREE of the following are key components of a risk assessment report?

⚠ Common exam trap

Watch out — candidates often confuse supporting artifacts (like network diagrams or contracts) with mandatory report components, but the CRISC exam specifically tests that the risk assessment report must include the risk register, risk analysis, and risk response recommendations as its key deliverables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk register with identified risks

A risk assessment report must document the identified risks in a structured format, so option A (Risk register with identified risks) is correct because the risk register is the core artifact that catalogs each risk, its owner, and its status. Option C (Recommended risk response actions) is correct because the report must translate findings into actionable treatment options such as mitigate, transfer, avoid, or accept, guiding decision-makers on next steps. Option E (Risk analysis (likelihood and impact)) is correct because quantifying or qualifying each risk by its probability and potential impact is the analytical heart of the assessment, typically expressed as a risk score (e.g., likelihood × impact). Options B (Copies of vendor contracts) and D (Network topology diagram) are supporting evidence or technical artifacts that may inform the assessment but are not key components of the risk assessment report itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk register with identified risks

    Why this is correct

    The risk register catalogues each identified risk with its owner, likelihood, impact and response, forming the evidentiary core that the rest of the report analyses. Without it, findings cannot be traced or tracked, so it satisfies the stem's key-component requirement.

  • ✗

    Copies of vendor contracts

    Why it's wrong here

    Vendor contracts are procurement and legal artefacts; they evidence third-party obligations rather than the assessed likelihood, impact and treatment of identified risks. They are tempting because third-party risk features in assessments, but contracts belong in a vendor risk or compliance review, not the report's core risk findings.

  • ✓

    Recommended risk response actions

    Why this is correct

    A risk assessment report must translate findings into action, so it documents recommended risk response actions — mitigate, transfer, avoid, or accept — mapped to the identified risks. This gives decision-makers a practical basis for treating exposures rather than merely describing them.

  • ✗

    Network topology diagram

    Why it's wrong here

    A network topology diagram is an asset-inventory artefact describing infrastructure, not an assessment of risk likelihood, impact or treatment options. It is tempting because asset context supports scoping, but the report's components are findings, risk ratings, and recommended responses, not the underlying architecture documentation.

  • ✓

    Risk analysis (likelihood and impact)

    Why this is correct

    Risk analysis quantifies each identified risk by assessing likelihood and impact, forming the core evaluative content of the report. Without this analysis, stakeholders cannot prioritise risks or judge whether proposed responses are proportionate to the exposure.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.