CRISC IT Risk Assessment Practice Question
A company is assessing the impact of a potential ransomware attack. Which TWO impact categories are considered operational impacts?
⚠ Common exam trap
CRISC often tests the overlap between impact categories, tempting candidates to classify financial consequences like fines or share price as operational because they stem from an operational event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System downtime
Operational impacts are those that directly affect the day-to-day functioning of the business, so B (System downtime) is correct because a ransomware attack encrypting servers or endpoints halts services and prevents normal operations until systems are restored. D (Productivity loss) is also correct because employees cannot perform their tasks while systems, files, and applications are unavailable, directly reducing operational output. A (Share price impact) is a financial/market impact rather than an operational one, and C (Regulatory fines) is a legal/compliance impact. E (Customer trust loss) is a reputational impact, so it does not belong in the operational category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share price impact
Why it's wrong here
Share price is a financial/market impact, not an operational one; operational impacts cover service disruption, process downtime and lost productivity. It tempts because ransomware visibly moves markets, so share price feels immediate, but that consequence flows through investor valuation rather than the organisation's day-to-day delivery capability.
- ✓
System downtime
Why this is correct
System downtime directly satisfies the operational impact criterion, as it halts service delivery and disrupts business processes. Unlike financial or reputational categories, operational impacts concern the availability and functioning of systems and people. Ransomware encrypting production servers causes exactly this disruption, making downtime a core operational consequence.
- ✗
Regulatory fines
Why it's wrong here
Regulatory fines are a compliance/legal impact, not operational; operational impacts concern disrupted services, processes and productivity. It tempts because ransomware breaches often trigger fines, but that cost arises from failing statutory obligations, not from the operational outage itself.
- ✓
Productivity loss
Why this is correct
Ransomware encrypting endpoints and file shares halts day-to-day work, so productivity loss is a genuine operational impact. It satisfies the stem's operational category because it disrupts business processes and service delivery, rather than causing financial, legal, or reputational consequences.
- ✗
Customer trust loss
Why it's wrong here
Customer trust loss is a reputational impact, not operational; operational impacts cover service disruption, downtime and lost productivity. It tempts because ransomware erodes confidence, but reputational damage is a separate impact category assessed alongside, not within, operational consequences.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.