CRISC IT Risk Identification Practice Question
A financial services firm is conducting a risk assessment for a new mobile banking application. The risk practitioner needs to evaluate the likelihood of a threat exploiting a vulnerability. Which of the following factors is MOST relevant when assessing the likelihood of a threat event?
⚠ Common exam trap
The trap here is selecting asset value or regulatory penalties as likelihood factors, when they actually measure impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The technical skill and motivation of threat actors targeting the mobile banking application.
When assessing likelihood, the risk practitioner focuses on factors that influence the probability of a threat event, such as threat capability, motivation, and the attractiveness of the target. In this scenario, the technical skill and motivation of threat actors targeting the mobile banking application directly affect how likely an attack is. Asset value, control effectiveness, and regulatory penalties are more related to impact or residual risk, not the inherent likelihood of the threat event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The regulatory penalties that could result from a data breach involving the mobile application.
Why it's wrong here
Regulatory penalties are a component of impact, not likelihood. They describe the potential consequences if a threat event occurs, not the probability of it occurring. While penalties can influence risk appetite and treatment decisions, they do not determine how likely a threat is to exploit a vulnerability. This option again confuses impact with likelihood, which is a common error in risk analysis.
- ✗
The monetary value of the assets that could be impacted by the threat event.
Why it's wrong here
The monetary value of assets is a factor in assessing impact, not likelihood. Likelihood is about the probability that a threat event will occur, which depends on threat capability, motivation, and the presence of vulnerabilities. While asset value may influence attacker targeting, it is not the primary factor for likelihood. This option confuses impact with likelihood, a common mistake in risk assessment.
- ✓
The technical skill and motivation of threat actors targeting the mobile banking application.
Why this is correct
Likelihood of a threat event is heavily influenced by the threat actor's capability and motivation. A highly skilled and motivated attacker is more likely to attempt and succeed in exploiting a vulnerability. In the mobile banking context, financially motivated cybercriminals with advanced skills pose a higher likelihood of attack. This factor directly addresses the probability of the threat event occurring, making it the most relevant for likelihood assessment.
- ✗
The effectiveness of the controls currently in place to prevent or detect the threat event.
Why it's wrong here
Control effectiveness affects residual risk after controls are considered, but when assessing the likelihood of a threat event, we often consider inherent likelihood before controls. However, in some frameworks, control effectiveness can influence likelihood if assessing residual likelihood. Still, the most direct factor for likelihood is the threat's capability and intent relative to the vulnerability. This option is more relevant to determining residual risk or control risk, not the raw likelihood of the threat event.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.