Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A hospital's risk practitioner is building a risk register entry for the loss of a critical electronic health record (EHR) system. The practitioner wants to express the risk in a way that combines the probability of the event with the magnitude of its business impact so that leadership can compare it against other enterprise risks. Which of the following BEST represents this expression?

⚠ Common exam trap

The trap here is assuming that any quantified or numeric value, such as annualized loss expectancy or a count of indicator breaches, automatically satisfies the requirement to combine likelihood with impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk score derived from a likelihood and impact matrix

Risk must be expressed so that dissimilar risks can be compared and prioritized. Combining likelihood with impact in a matrix yields a risk score that reflects both dimensions, works for financial and nonfinancial consequences, and aligns with how IT risk registers are typically populated. Monetary measures such as annualized loss expectancy address only expected financial loss, while control self-assessment results and indicator breach counts are inputs to assessment rather than the risk expression itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk score derived from a likelihood and impact matrix

    Why this is correct

    A likelihood-and-impact matrix produces a risk score that combines how probable the event is with how severe its effect would be, which is exactly what the practitioner needs for comparison against other enterprise risks. It accommodates both financial and nonfinancial impacts such as patient safety and regulatory exposure. This is the standard qualitative or semi-quantitative expression used in an IT risk register.

  • ✗

    Key risk indicator (KRI) threshold breach count

    Why it's wrong here

    KRIs are metrics that provide early warning that risk exposure is changing, and a threshold breach count is an indicator signal rather than a risk expression. Counting breaches tells the practitioner that something may be drifting, but it does not combine probability with business impact for comparison across the register. KRIs feed the assessment; they do not replace the likelihood-and-impact expression.

  • ✗

    Annualized loss expectancy (ALE)

    Why it's wrong here

    ALE is a monetary figure derived from single loss expectancy multiplied by annualized rate of occurrence, so it quantifies expected financial loss rather than a combined probability-and-impact rating. The scenario asks for a comparative expression of likelihood and impact, not a dollar expectation. ALE is also difficult to derive reliably for patient-safety and regulatory impacts, making it a poor fit for this EHR risk register entry.

  • ✗

    Control self-assessment (CSA) result

    Why it's wrong here

    A CSA captures management's opinion about the design and operating effectiveness of controls, not the combined probability and impact of a risk event. It informs the assessment of likelihood by revealing control weaknesses, but it does not itself express the risk in a form leadership can rank against other risks. Using a CSA result as the risk expression would omit the impact dimension entirely.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.