CRISC IT Risk Assessment Practice Question
A healthcare organization is assessing risks to its electronic health record (EHR) system. The risk team is evaluating the likelihood of a threat event. Which TWO factors are MOST relevant when estimating the likelihood of a threat exploiting a vulnerability? (Choose two.)
⚠ Common exam trap
The trap here is selecting impact-related factors such as regulatory fines or control costs when asked about likelihood, as these influence the severity of consequences rather than the probability of occurrence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The skill level and motivation of the threat actor
Likelihood estimation in risk assessment focuses on factors that influence the probability of a threat exploiting a vulnerability. The skill and motivation of the threat actor and the ease of discovery and exploitability of the vulnerability are direct determinants of that probability. Regulatory fines, user count, and control costs are related to impact or treatment, not likelihood.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of users with access to the EHR system
Why it's wrong here
While the number of users can affect the attack surface and potential for insider threats, it is not a direct measure of likelihood of exploitation. It is more of an exposure indicator that could influence vulnerability, but it does not inherently indicate the probability of a threat event. Likelihood estimation focuses on threat capability and vulnerability characteristics.
- ✓
The skill level and motivation of the threat actor
Why this is correct
The skill level and motivation of a threat actor directly influence the probability that a vulnerability will be exploited. A highly skilled and motivated attacker is more likely to identify and successfully exploit weaknesses. This factor is a core component of threat likelihood estimation in risk assessments, as it reflects the capability and intent of potential adversaries.
- ✓
The ease of discovery and exploitability of the vulnerability
Why this is correct
The ease of discovery and exploitability of a vulnerability determines how accessible the weakness is to an attacker. If a vulnerability is publicly known and easy to exploit, the likelihood of exploitation increases. This factor is critical in estimating threat event frequency, as it directly affects the effort required by an attacker to succeed.
- ✗
The regulatory fines associated with a data breach
Why it's wrong here
Regulatory fines are a consequence or impact factor, not a likelihood factor. They influence the potential loss magnitude if a breach occurs, but they do not affect the probability that a threat will exploit a vulnerability. Including fines in likelihood estimation would conflate impact with probability, leading to inaccurate risk assessment.
- ✗
The cost of implementing additional security controls
Why it's wrong here
The cost of controls is a factor in risk treatment decisions, not in estimating the likelihood of a threat event. It relates to the economic feasibility of mitigation, not the probability that a vulnerability will be exploited. Including cost in likelihood assessment would confuse risk analysis with risk response planning.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.