Courseiva
IT Risk Assessment →mediumMultiple Select

CRISC IT Risk Assessment Practice Question

A healthcare organization is assessing risks to its electronic health record (EHR) system. The risk team is evaluating the likelihood of a threat event. Which TWO factors are MOST relevant when estimating the likelihood of a threat exploiting a vulnerability? (Choose two.)

⚠ Common exam trap

The trap here is selecting impact-related factors such as regulatory fines or control costs when asked about likelihood, as these influence the severity of consequences rather than the probability of occurrence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The skill level and motivation of the threat actor

Likelihood estimation in risk assessment focuses on factors that influence the probability of a threat exploiting a vulnerability. The skill and motivation of the threat actor and the ease of discovery and exploitability of the vulnerability are direct determinants of that probability. Regulatory fines, user count, and control costs are related to impact or treatment, not likelihood.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The number of users with access to the EHR system

    Why it's wrong here

    While the number of users can affect the attack surface and potential for insider threats, it is not a direct measure of likelihood of exploitation. It is more of an exposure indicator that could influence vulnerability, but it does not inherently indicate the probability of a threat event. Likelihood estimation focuses on threat capability and vulnerability characteristics.

  • ✓

    The skill level and motivation of the threat actor

    Why this is correct

    The skill level and motivation of a threat actor directly influence the probability that a vulnerability will be exploited. A highly skilled and motivated attacker is more likely to identify and successfully exploit weaknesses. This factor is a core component of threat likelihood estimation in risk assessments, as it reflects the capability and intent of potential adversaries.

  • ✓

    The ease of discovery and exploitability of the vulnerability

    Why this is correct

    The ease of discovery and exploitability of a vulnerability determines how accessible the weakness is to an attacker. If a vulnerability is publicly known and easy to exploit, the likelihood of exploitation increases. This factor is critical in estimating threat event frequency, as it directly affects the effort required by an attacker to succeed.

  • ✗

    The regulatory fines associated with a data breach

    Why it's wrong here

    Regulatory fines are a consequence or impact factor, not a likelihood factor. They influence the potential loss magnitude if a breach occurs, but they do not affect the probability that a threat will exploit a vulnerability. Including fines in likelihood estimation would conflate impact with probability, leading to inaccurate risk assessment.

  • ✗

    The cost of implementing additional security controls

    Why it's wrong here

    The cost of controls is a factor in risk treatment decisions, not in estimating the likelihood of a threat event. It relates to the economic feasibility of mitigation, not the probability that a vulnerability will be exploited. Including cost in likelihood assessment would confuse risk analysis with risk response planning.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.