easyMultiple Select
CRISC Practice Question: Which TWO of the following are key elements that…
Which TWO of the following are key elements that should be included in an IT risk assessment report?
⚠ Common exam trap
Many candidates confuse supporting documentation (like vendor contracts or network diagrams) with the core required elements of a risk assessment report, which must focus on risk identification, ratings, and treatment recommendations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A list of identified risks and their ratings
Option A is correct because a risk assessment report must document the identified risks along with their assigned ratings (e.g., likelihood and impact scores, or qualitative labels such as high/medium/low), which form the core output of the assessment and enable prioritization. Option B is correct because the report should include recommendations for risk treatment — such as mitigation, transfer, acceptance, or avoidance — so that decision-makers can act on the findings; this is a standard component of risk assessment reporting per frameworks like ISO/IEC 27005 and NIST SP 800-30. Option C is not a key element, since vendor contracts are supporting evidence that may be referenced but are not part of the risk assessment report itself. Option D is not required, as network topology diagrams are technical artifacts that may inform the assessment but do not constitute a core reporting element. Option E is not relevant, because detailed IT financial budgets fall under financial or budgetary reporting, not IT risk assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A list of identified risks and their ratings
Why this is correct
Identified risks with their ratings form the core register that lets management compare exposures and prioritise responses. Without this ranked inventory, the report cannot satisfy its purpose of communicating which risks threaten objectives and where attention should be directed.
- ✓
Recommendations for risk treatment
Why this is correct
Recommendations for risk treatment translate assessment findings into actionable options — mitigate, transfer, accept or avoid — aligned to risk appetite. This satisfies the report's requirement to guide decision-makers beyond mere identification, enabling informed selection of cost-effective controls.
- ✗
Copies of vendor contracts
Why it's wrong here
Vendor contracts are procurement artefacts, not risk assessment content; the report documents identified risks, likelihood, impact, and treatment options. They are tempting because third-party contracts underpin vendor risk, and would be relevant evidence when assessing supplier-related exposure rather than the assessment report itself.
- ✗
Network topology diagrams
Why it's wrong here
Network topology diagrams describe infrastructure layout, not risk analysis; the report states identified risks, their likelihood, impact, and recommended responses. Diagrams are tempting because they support technical understanding, and would be relevant in an architecture review or vulnerability assessment rather than the risk assessment report itself.
- ✗
Detailed financial budgets of the IT department
Why it's wrong here
IT financial budgets record planned expenditure, not risk findings; the report presents risk scenarios, inherent and residual ratings, and mitigation status. Budgets are tempting because risk treatment requires funding, and would be relevant when costing proposed controls rather than documenting the assessment outcome.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.