nerdexam
Isaca

CRISC · Question #299

Which of the following is the PRIMARY objective of aggregating the impact of IT risk scenarios and reflecting the results in the enterprise risk register?

The correct answer is B. To ensure IT risk impact can be compared to the IT risk appetite. The primary objective of aggregating IT risk scenarios in the enterprise risk register is to enable comparison of the overall IT risk impact to the defined IT risk appetite.

Submitted by takeshi77· Apr 18, 2026Risk Response and Reporting

Question

Which of the following is the PRIMARY objective of aggregating the impact of IT risk scenarios and reflecting the results in the enterprise risk register?

Options

  • ATo ensure IT risk appetite is communicated across the organization
  • BTo ensure IT risk impact can be compared to the IT risk appetite
  • CTo ensure IT risk ownership is assigned at the appropriate organizational level
  • DTo ensure IT risk scenarios are consistently assessed within the organization

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    92% (46)
  • C
    4% (2)
  • D
    2% (1)

Why each option

The primary objective of aggregating IT risk scenarios in the enterprise risk register is to enable comparison of the overall IT risk impact to the defined IT risk appetite.

ATo ensure IT risk appetite is communicated across the organization

While risk appetite communication is important, aggregation itself primarily serves for comparison, not direct communication.

BTo ensure IT risk impact can be compared to the IT risk appetiteCorrect

Aggregating IT risk scenarios provides a holistic view of the cumulative impact of IT-related risks, allowing management to compare this total exposure against the organization's established IT risk appetite. This comparison is critical for determining if the overall level of IT risk is acceptable or if further mitigation strategies are required to bring it within tolerance levels.

CTo ensure IT risk ownership is assigned at the appropriate organizational level

Risk ownership is assigned at the individual scenario level, and while important, it's not the primary objective of aggregating impacts.

DTo ensure IT risk scenarios are consistently assessed within the organization

Consistent assessment is a prerequisite for meaningful aggregation, not the primary objective of aggregation itself.

Concept tested: Enterprise Risk Register Aggregation

Source: https://learn.microsoft.com/en-us/compliance/regulatory/regulatory-compliance-dashboard-risk-assessment

Topics

#Risk aggregation#Enterprise risk register#Risk appetite#Risk impact comparison

Community Discussion

No community discussion yet for this question.

Full CRISC Practice