nerdexam
Isaca

CRISC · Question #311

An organization has just started accepting credit card payments from customers via the corporate website. Which of the following is MOST likely to increase as a result of this new initiative?

The correct answer is C. Inherent risk. Accepting credit card payments introduces new vulnerabilities and sensitive data handling requirements, directly increasing the organization's inherent risk before any security measures are applied.

Submitted by fatema_kw· Apr 18, 2026IT Risk Assessment

Question

An organization has just started accepting credit card payments from customers via the corporate website. Which of the following is MOST likely to increase as a result of this new initiative?

Options

  • ARisk tolerance
  • BRisk appetite
  • CInherent risk
  • DResidual risk

How the community answered

(25 responses)
  • A
    8% (2)
  • C
    80% (20)
  • D
    12% (3)

Why each option

Accepting credit card payments introduces new vulnerabilities and sensitive data handling requirements, directly increasing the organization's inherent risk before any security measures are applied.

ARisk tolerance

Risk tolerance is the acceptable deviation around risk appetite and is a measure of an organization's willingness to take on risk, not a direct consequence of a new operational initiative.

BRisk appetite

Risk appetite is the total amount and type of risk an organization is willing to pursue or retain to achieve its objectives, which is a strategic decision and not automatically increased by a new operational initiative.

CInherent riskCorrect

Inherent risk is the level of risk present before any controls or mitigations are in place; accepting credit card payments directly introduces new types of threats and vulnerabilities, such as data breaches and fraud, associated with handling financial data, thereby increasing the baseline risk.

DResidual risk

Residual risk is the risk remaining after controls have been implemented; an increase in inherent risk may lead to an increase in residual risk if controls are insufficient, but inherent risk is the initial and most direct increase.

Concept tested: Inherent vs. Residual Risk

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/reference/nfa-security#risk-definitions

Topics

#Inherent Risk#Risk Identification#Payment Processing Risk#New Initiative Risk

Community Discussion

No community discussion yet for this question.

Full CRISC Practice