CRISC IT Risk Assessment Practice Question
A quantitative risk analysis using FAIR requires estimating which THREE primary factors?
⚠ Common exam trap
CRISC often tests whether candidates can distinguish FAIR's primary estimation factors (threat event frequency, vulnerability, loss magnitude) from contextual elements like risk appetite and control cost.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerability
In FAIR (Factor Analysis of Information Risk), the primary factors estimated for quantitative risk analysis are threat event frequency (D), vulnerability (B), and loss magnitude (C). Threat event frequency (D) captures how often a threat agent is expected to act against an asset, which drives the likelihood side of the risk equation. Vulnerability (B) is the probability that a threat event becomes a loss event, given the resistance strength of the asset's controls, and it modifies threat event frequency into loss event frequency. Loss magnitude (C) represents the probable financial impact per loss event, combining primary and secondary loss forms, and it is multiplied by loss event frequency to produce annualized loss exposure. Risk appetite (A) is a governance-level tolerance statement rather than a FAIR-estimated factor, and control cost (E) is an input to cost-benefit analysis of mitigations, not one of the three primary FAIR estimation factors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk appetite
Why it's wrong here
FAIR quantifies frequency and magnitude of loss; risk appetite is a governance threshold used to judge whether calculated risk is tolerable. It is tempting because appetite guides risk decisions, but it is a tolerance statement, not an estimable input to the FAIR calculation.
- ✓
Vulnerability
Why this is correct
FAIR estimates loss event frequency from threat event frequency and vulnerability, combined with loss magnitude, to quantify risk in monetary terms. Vulnerability is one of the three primary factors, representing the probability a threat event becomes a loss.
- ✓
Loss magnitude
Why this is correct
Loss magnitude quantifies the financial impact should a threat event occur, forming FAIR's primary impact factor alongside loss event frequency. It satisfies the stem's requirement for a primary estimation factor by capturing probable loss in monetary terms, enabling risk to be expressed as annualised loss exposure rather than qualitative severity ratings.
- ✓
Threat event frequency
Why this is correct
FAIR estimates threat event frequency, the probable rate at which threat agents act against the asset, as a primary factor feeding loss event frequency. This satisfies the stem's requirement for a primary FAIR estimation factor.
- ✗
Control cost
Why it's wrong here
FAIR estimates loss event frequency and loss magnitude, decomposed into threat event frequency, vulnerability, primary loss and secondary risk factors. Control cost is a cost-benefit input compared against risk reduction, not a factor in the risk calculation itself.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.