CRISC IT Risk Assessment Practice Question
A company is assessing the risk of a ransomware attack. The security team estimates the threat event frequency as 2 attacks per year, vulnerability as 0.3 (30% chance of success), primary loss as $500,000, and secondary loss as $200,000. What is the annualized loss expectancy (ALE) using the FAIR framework?
⚠ Common exam trap
The trap here is that candidates often forget to multiply by the vulnerability factor (0.3) or omit secondary loss, leading to answers like $700,000 or $1,400,000, which ignore the probabilistic nature of successful attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$420,000
The FAIR framework calculates ALE as Threat Event Frequency × Vulnerability × (Primary Loss + Secondary Loss). Here, 2 × 0.3 × ($500,000 + $200,000) = 2 × 0.3 × $700,000 = $420,000. This correctly accounts for the probability of a successful attack and the total loss per incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
$420,000
Why this is correct
Multiplying threat event frequency (2) by vulnerability (0.3) gives a loss event frequency of 0.6 per year. Combining primary and secondary loss yields $700,000 per event. ALE is therefore 0.6 × $700,000 = $420,000, satisfying the FAIR requirement to annualise both loss magnitudes.
- ✗
$700,000
Why it's wrong here
$700,000 adds primary and secondary loss, giving single-event loss magnitude, not annualised loss expectancy. Summing both loss components is tempting because it captures total impact per incident, but ALE requires multiplying by the annualised rate of successful events (2 × 0.3), yielding $420,000.
- ✗
$210,000
Why it's wrong here
$210,000 applies the 0.3 vulnerability factor to only one loss component rather than the combined $700,000 magnitude. Partially applying vulnerability is tempting because primary loss dominates, but FAIR multiplies loss event frequency (2 × 0.3 = 0.6) by total loss magnitude ($700,000), yielding $420,000.
- ✗
$1,400,000
Why it's wrong here
$1,400,000 multiplies threat event frequency by total loss without applying the 0.3 vulnerability factor, overstating expected loss. Ignoring vulnerability is tempting when treating every attack as successful, but FAIR requires loss event frequency (2 × 0.3 = 0.6) multiplied by loss magnitude ($700,000), giving $420,000.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.