CRISC IT Risk Identification Practice Question
A hospital's risk practitioner is building a risk register entry for the loss of a critical electronic health record (EHR) system. The practitioner wants to express the risk in a way that combines the probability of the event with the magnitude of its business impact so that leadership can compare it against other enterprise risks. Which of the following BEST represents this expression?
⚠ Common exam trap
The trap here is assuming that any quantified or numeric value, such as annualized loss expectancy or a count of indicator breaches, automatically satisfies the requirement to combine likelihood with impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk score derived from a likelihood and impact matrix
Risk must be expressed so that dissimilar risks can be compared and prioritized. Combining likelihood with impact in a matrix yields a risk score that reflects both dimensions, works for financial and nonfinancial consequences, and aligns with how IT risk registers are typically populated. Monetary measures such as annualized loss expectancy address only expected financial loss, while control self-assessment results and indicator breach counts are inputs to assessment rather than the risk expression itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk score derived from a likelihood and impact matrix
Why this is correct
A likelihood-and-impact matrix produces a risk score that combines how probable the event is with how severe its effect would be, which is exactly what the practitioner needs for comparison against other enterprise risks. It accommodates both financial and nonfinancial impacts such as patient safety and regulatory exposure. This is the standard qualitative or semi-quantitative expression used in an IT risk register.
- ✗
Key risk indicator (KRI) threshold breach count
Why it's wrong here
KRIs are metrics that provide early warning that risk exposure is changing, and a threshold breach count is an indicator signal rather than a risk expression. Counting breaches tells the practitioner that something may be drifting, but it does not combine probability with business impact for comparison across the register. KRIs feed the assessment; they do not replace the likelihood-and-impact expression.
- ✗
Annualized loss expectancy (ALE)
Why it's wrong here
ALE is a monetary figure derived from single loss expectancy multiplied by annualized rate of occurrence, so it quantifies expected financial loss rather than a combined probability-and-impact rating. The scenario asks for a comparative expression of likelihood and impact, not a dollar expectation. ALE is also difficult to derive reliably for patient-safety and regulatory impacts, making it a poor fit for this EHR risk register entry.
- ✗
Control self-assessment (CSA) result
Why it's wrong here
A CSA captures management's opinion about the design and operating effectiveness of controls, not the combined probability and impact of a risk event. It informs the assessment of likelihood by revealing control weaknesses, but it does not itself express the risk in a form leadership can rank against other risks. Using a CSA result as the risk expression would omit the impact dimension entirely.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.