exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 754 discussion

Actual exam question from Isaca's CRISC
Question #: 754
Topic #: 1
[All CRISC Questions]

Prudent business practice requires that risk appetite not exceed:

  • A. risk capacity.
  • B. inherent risk.
  • C. risk tolerance.
  • D. residual risk.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fvanderschmudt
Highly Voted 3 years, 9 months ago
Because exceeding the capacity, means that the organization will go under. Appetite and tolerance are different. Tolerance is appetite + a little extra. From the book: Risk tolerance is defined as the acceptable level of variation that management is willing to allow for any particular risk as the enterprise pursues its objectives. The interpretation of the ISACA definition is that while management has an official acceptance level of one value, they may accept a slight deviation from that level. An example of tolerance is a situation where the speed limit on a highway is 65 miles/hour, but a police officer may allow a person to travel up to 70 miles/hour before issuing a ticket.
upvoted 11 times
MartyMar
1 year, 4 months ago
I agree if I am being Prudent then I don't want the appetite to be exceeded because it would be be closing in on my Tolerance
upvoted 1 times
...
...
Staanlee
Most Recent 10 months, 4 weeks ago
Selected Answer: A
A. risk capacity. Prudent business practice dictates that risk appetite should not exceed an organization's risk capacity. Risk capacity is the maximum amount of risk that an organization can absorb without jeopardizing its ability to achieve its objectives. It represents the financial, operational, and strategic limits within which an organization can operate while still managing risk effectively. Risk appetite should be set below this threshold to ensure that the organization can handle the risks it takes on without exceeding its capacity to manage them.
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: A
Agree it is A. The review manual talks about appetite not exceeding capacity. I can see that appetite should not exceed tolerance, however tolerance is on a case by case basis whereas appetite and capacity are on organizational / overall basis. Also, if appetite exceeds tolerance you just stop having tolerance, it is only appetite at that point. Appetite could theoretically cancel tolerance, but could never cancel capacity.
upvoted 2 times
...
helg420
1 year, 3 months ago
Selected Answer: A
I gotta go with A. Risk capacity: the amount and type of risk an organisation is able to support in pursuit of its business objectives. Risk appetite: the amount and type of risk an organisation is willing to accept in pursuit of its business objectives. Risk tolerance: organization's or stakeholders’ readiness to bear the risk after risk “treatment” in order to achieve its objectives
upvoted 2 times
...
Koulyo
1 year, 4 months ago
Selected Answer: A
As per the below
upvoted 2 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: C
PRUDENT business practice requires that risk appetite not exceed risk tolerance. exceeding capacity has nothing to do with prudence, if not with unconsciousness
upvoted 1 times
...
Raj1510
2 years, 6 months ago
Risk Capacity > Risk Tolerance > Risk Appetite (risk acceptance) . If organization crossed risk capacity its existence will be in danger. so option A is right
upvoted 1 times
...
Josh93
3 years, 3 months ago
Risk Capacity then Risk Appetite then Risk Tolerance....... That's the hierarchy
upvoted 1 times
...
Calvinc
3 years, 11 months ago
Why the answer is not "C"?
upvoted 1 times
Calvinc
3 years, 11 months ago
i think I know....it is because of the keyword "exceed"!
upvoted 1 times
Rooks
3 years, 10 months ago
I thought the answer would be C - Threahold
upvoted 1 times
Rooks
3 years, 10 months ago
Sorry meant to say Tolerance.
upvoted 1 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...