Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

A global manufacturer is performing an IT risk assessment for its industrial control systems (ICS). The risk team is evaluating threat sources and wants to identify factors that INCREASE the likelihood of a threat event occurring. Which TWO of the following factors increase the likelihood of a threat event? (Choose two.)

⚠ Common exam trap

The trap here is selecting strong security controls as likelihood drivers, when controls such as segmentation, response planning, and backups reduce likelihood or impact rather than increase it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A well-funded, motivated threat actor targeting the manufacturer's sector.

Likelihood of a threat event rises when exposure and adversary pressure increase. Numerous unpatched, internet-facing ICS components create exploitable pathways, and a well-funded, motivated actor targeting the sector raises both attempt frequency and success probability. Response planning, segmentation, and backup capability are controls that reduce impact or exposure, not factors that increase the chance of an event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A well-funded, motivated threat actor targeting the manufacturer's sector.

    Why this is correct

    Threat capability and motivation are core likelihood drivers. A well-resourced actor with sector-specific intent is more likely to attempt and succeed at exploiting ICS weaknesses. This raises both the frequency of attempts and the probability of success, making it a legitimate factor that increases the likelihood of a threat event in the assessment.

  • ✗

    A mature backup and recovery capability with regularly tested restores.

    Why it's wrong here

    Backup and recovery capability primarily reduces impact by enabling restoration after an event. It does not increase the probability that an event occurs. Treating it as a likelihood driver confuses resilience with probability and would distort the assessment, since the team is specifically asked to identify factors that raise the chance of a threat event.

  • ✓

    A high number of unpatched, internet-facing ICS components.

    Why this is correct

    Unpatched, internet-facing components expand the attack surface and provide known exploitable entry points, directly raising the probability that a threat actor succeeds. In an ICS environment, where patching is often constrained by uptime requirements, this exposure is especially consequential. More exploitable pathways mean a higher frequency of attempted and successful events, so this factor increases likelihood.

  • ✗

    A documented and tested incident response plan for OT environments.

    Why it's wrong here

    A tested incident response plan reduces the impact and duration of a realized event but does not make an event more likely to occur. It is a preparedness control. Including it as a likelihood driver confuses response capability with probability, and would mislead the team into thinking strong response planning somehow increases the chance of an ICS threat event.

  • ✗

    Segmentation that isolates the ICS network from the corporate network.

    Why it's wrong here

    Network segmentation is a preventive control that reduces exposure by limiting lateral movement and reachable pathways. It lowers, rather than raises, the likelihood of a successful ICS threat event. Selecting it as a likelihood-increasing factor inverts the control's purpose and would weaken the accuracy of the risk assessment for the industrial environment.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.