mediumMultiple Select
CRISC Practice Question: Which TWO are characteristics of inherent risk?
Which TWO are characteristics of inherent risk?
⚠ Common exam trap
Many candidates confuse inherent risk with residual risk, mistakenly thinking that inherent risk includes the effect of existing controls, which is a common misconception tested in CRISC questions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk level before controls
Option C is correct because inherent risk is defined as the level of risk that exists before any controls are applied, representing the raw exposure of an asset or process to a threat. Option E is correct because inherent risk is assessed under the assumption that no controls exist, which establishes a baseline against which control effectiveness can later be measured. Together, these two characteristics distinguish inherent risk from residual risk, which is the risk remaining after controls are implemented. Option A is incorrect because basing risk on the effectiveness of current controls describes residual risk, not inherent risk. Option B is incorrect because determining the control gap is a derived analysis activity that compares inherent and residual risk, not a defining characteristic of inherent risk itself. Option D is incorrect because the risk level after controls is the definition of residual risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Based on the effectiveness of current controls
Why it's wrong here
Basing a rating on current control effectiveness produces residual risk, since inherent risk deliberately excludes controls. It is tempting because control effectiveness feeds risk analysis generally, but inherent risk is measured with controls disregarded, making this a residual-risk characteristic.
- ✗
Used to determine control gap
Why it's wrong here
Inherent risk is assessed before controls are applied, so it cannot be used to determine a control gap; that comparison emerges from residual risk against inherent risk. It is tempting because gap analysis does compare the two, but the gap itself is not a characteristic of inherent risk.
- ✓
Risk level before controls
Why this is correct
Inherent risk is the exposure that exists before any controls, mitigations or countermeasures are applied. It establishes the baseline against which residual risk is compared, so the risk level prior to controls is a defining characteristic rather than a by-product of control effectiveness.
- ✗
Risk level after controls
Why it's wrong here
Risk level after controls describes residual risk, not inherent risk. Inherent risk is the exposure that exists before any controls are considered, so this option states the opposite end of the assessment. It is tempting because both are risk levels, but the timing of control consideration is the axis.
- ✓
Based on the assumption that no controls exist
Why this is correct
Inherent risk is assessed on the assumption that no controls, safeguards or mitigating measures are in place, isolating the raw exposure inherent to the activity or asset. This control-free premise distinguishes it from residual risk, which reflects the effect of implemented controls.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.