TechNuggets Academy

Risk Response and Reporting

Free Certified in Risk and Information Systems Control practice — 6 questions on Risk Response and Reporting, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: Risk Response and Reporting
A bank's core trading application has a single point of failure. The Annualized Loss Expectancy (ALE) associated with an outage is $400,000. A fully redundant architecture would cost $1.5 million annually to implement and maintain. Which risk response is MOST appropriate given this analysis?
When the cost of full mitigation significantly exceeds the ALE, CRISC guidance directs the practitioner toward risk acceptance supported by documented cost-benefit justification and compensating controls (e.g., enhanced monitoring, rapid failover procedures) that reduce impact/detection time at a fraction of the cost, rather than pursuing disproportionately expensive mitigation.
Question 2 of 6 · Domain 3: Risk Response and Reporting
A critical SaaS provider hosting regulated customer data refuses to grant contractual right-to-audit clauses but provides an unqualified SOC 2 Type II report covering the relevant control period. What should the risk practitioner recommend?
CRISC recognizes independent third-party attestation reports (SOC 2 Type II) as an acceptable alternative form of assurance when direct audit rights cannot be obtained, provided the organization supplements it with compensating measures such as ongoing monitoring, breach-notification clauses, and re-attestation cycles to manage residual supply-chain risk.
Question 3 of 6 · Domain 3: Risk Response and Reporting
Which statement BEST describes the distinction between a risk owner and a control owner within a risk management program?
CRISC clearly separates accountability: the risk owner holds overall accountability for the risk staying within the organization's risk appetite/tolerance, while the control owner is responsible for the operational effectiveness of the specific control(s) selected as part of the response. A risk can have one owner but be mitigated by multiple controls, each with its own control owner.
Question 4 of 6 · Domain 3: Risk Response and Reporting
A KRI tied to unauthorized privileged access attempts breaches its defined threshold at the end of three consecutive monitoring periods, but each time the metric drops back below threshold before the next reporting cycle closes, so no escalation has occurred. Which monitoring approach should the risk practitioner recommend?
Effective KRI monitoring requires trend analysis, not just point-in-time compliance at reporting dates. A recurring pattern of threshold breaches followed by reversion suggests an underlying control weakness or risk factor that is not being addressed, warranting escalation and root-cause investigation even though the metric appears compliant at each snapshot.
Question 5 of 6 · Domain 3: Risk Response and Reporting
Which control testing procedure provides the STRONGEST evidence that a control operated effectively throughout an entire review period, rather than merely being designed correctly at a single point in time?
Reperformance using a representative sample drawn across the full review period provides direct, objective evidence of operating effectiveness over time, addressing whether the control consistently functioned as designed, which is the standard required to assess operating (versus design) effectiveness.
Question 6 of 6 · Domain 3: Risk Response and Reporting
A risk practitioner maintains a heat map of 50 identified enterprise risks. The board has requested a quarterly risk report. Which reporting approach is MOST appropriate for board-level communication?
Board-level reporting should be concise and decision-oriented, focusing on risks that exceed appetite/tolerance, showing trend direction, relevant KRI status, and explicit linkage to strategic objectives so the board can make informed governance decisions without being burdened by operational-level detail.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →