nerdexam
Isaca

CISA · Question #467

When reviewing results of a risk assessment process, the IS auditor should focus efforts on risk items and scenarios with the highest level of:

The correct answer is C. residual risk. Residual risk is the remaining risk after controls have been implemented. When reviewing a risk assessment, an IS auditor should focus on areas with the highest residual risk because these represent the greatest potential for unmitigated threats to the organization’s objectives.

Submitted by priya_blr· Apr 18, 2026Information System Auditing Process

Question

When reviewing results of a risk assessment process, the IS auditor should focus efforts on risk items and scenarios with the highest level of:

Options

  • Asampling risk.
  • Binherent risk.
  • Cresidual risk.
  • Daudit risk.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    88% (28)
  • D
    6% (2)

Explanation

Residual risk is the remaining risk after controls have been implemented. When reviewing a risk assessment, an IS auditor should focus on areas with the highest residual risk because these represent the greatest potential for unmitigated threats to the organization’s objectives.

Topics

#Risk assessment#Residual risk#IS auditor role#Audit planning

Community Discussion

No community discussion yet for this question.

Full CISA Practice