nerdexam
IsacaIsaca

CRISC · Question #200

CRISC Question #200: Real Exam Question with Answer & Explanation

The correct answer is C: Business objectives and strategies. An organization's risk appetite is most significantly influenced by its business objectives and strategies, as these define the level of risk it is willing to accept to achieve its goals.

Submitted by wei.xz· Apr 18, 2026Governance

Question

Which of the following has the GREATEST influence on an organization's risk appetite?

Options

  • AThreats and vulnerabilities
  • BInternal and external risk factors
  • CBusiness objectives and strategies
  • DManagement culture and behavior

Explanation

An organization's risk appetite is most significantly influenced by its business objectives and strategies, as these define the level of risk it is willing to accept to achieve its goals.

Common mistakes.

  • A. Threats and vulnerabilities are components of the risk itself and influence risk assessment, but they do not define the organization's fundamental willingness to take on risk.
  • B. Internal and external risk factors contribute to the overall risk landscape, but the organization's appetite for navigating this landscape is determined by its strategic aims.
  • D. Management culture and behavior significantly influence how risk appetite is implemented and perceived, but the fundamental driver for establishing the appetite itself stems from the strategic goals.

Concept tested. Risk appetite definition

Topics

#Risk Appetite#Business Objectives#Strategic Alignment#Risk Governance

Community Discussion

No community discussion yet for this question.

Full CRISC PracticeBrowse All CRISC Questions