CRISC IT Risk Identification Practice Question
A multinational bank is assessing the risk of a distributed denial-of-service (DDoS) attack on its online banking platform. The risk practitioner has identified that the platform is hosted in a single data center with no redundancy. Which of the following BEST describes the relationship between the threat, vulnerability, and risk in this scenario?
⚠ Common exam trap
The trap here is mixing up the definitions of threat, vulnerability, and risk, often by treating the attack as the vulnerability or the weakness as the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The DDoS attack is the threat, the single data center is the vulnerability, and the risk is the potential service outage.
In risk terminology, a threat is something that can exploit a vulnerability, a vulnerability is a weakness, and risk is the potential for loss when a threat exploits a vulnerability. Here, the DDoS attack is the threat, the single data center is the vulnerability, and the potential service outage is the risk. Correctly distinguishing these elements is fundamental to IT risk identification and ensures appropriate treatment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The DDoS attack is the threat, the single data center is the vulnerability, and the risk is the potential service outage.
Why this is correct
A threat is any potential cause of harm; here, the DDoS attack is the threat. A vulnerability is a weakness that can be exploited; the lack of redundancy in a single data center is the vulnerability. Risk is the combination of the probability of an event and its impact; the potential service outage is the risk. This mapping is correct and aligns with ISACA definitions.
- ✗
The DDoS attack is the risk, the single data center is the threat, and the potential service outage is the vulnerability.
Why it's wrong here
This confuses all three terms. A DDoS attack is an event, not a risk; risk is the potential for loss. The single data center is a weakness, not a threat. The service outage is an impact, not a vulnerability. Such misclassification would lead to ineffective risk treatment, as the practitioner might try to mitigate the wrong element.
- ✗
The DDoS attack is the vulnerability, the single data center is the threat, and the risk is the potential service outage.
Why it's wrong here
This reverses the roles: a DDoS attack is a threat event, not a vulnerability. The single data center is a vulnerability (a weakness), not a threat. The risk is indeed the potential service outage, but the threat and vulnerability are mislabeled. Correctly identifying each component is essential for accurate risk analysis and treatment.
- ✗
The DDoS attack is the threat, the single data center is the risk, and the potential service outage is the vulnerability.
Why it's wrong here
While the DDoS attack is correctly identified as the threat, the single data center is a vulnerability, not the risk. The risk is the potential service outage. Calling the data center the risk would imply that the facility itself is the potential loss, which is inaccurate. This mislabeling could cause the practitioner to overlook the need for redundancy as a treatment.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.