Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

A quantitative risk analysis using FAIR requires estimating which THREE primary factors?

⚠ Common exam trap

CRISC often tests whether candidates can distinguish FAIR's primary estimation factors (threat event frequency, vulnerability, loss magnitude) from contextual elements like risk appetite and control cost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability

In FAIR (Factor Analysis of Information Risk), the primary factors estimated for quantitative risk analysis are threat event frequency (D), vulnerability (B), and loss magnitude (C). Threat event frequency (D) captures how often a threat agent is expected to act against an asset, which drives the likelihood side of the risk equation. Vulnerability (B) is the probability that a threat event becomes a loss event, given the resistance strength of the asset's controls, and it modifies threat event frequency into loss event frequency. Loss magnitude (C) represents the probable financial impact per loss event, combining primary and secondary loss forms, and it is multiplied by loss event frequency to produce annualized loss exposure. Risk appetite (A) is a governance-level tolerance statement rather than a FAIR-estimated factor, and control cost (E) is an input to cost-benefit analysis of mitigations, not one of the three primary FAIR estimation factors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk appetite

    Why it's wrong here

    FAIR quantifies frequency and magnitude of loss; risk appetite is a governance threshold used to judge whether calculated risk is tolerable. It is tempting because appetite guides risk decisions, but it is a tolerance statement, not an estimable input to the FAIR calculation.

  • ✓

    Vulnerability

    Why this is correct

    FAIR estimates loss event frequency from threat event frequency and vulnerability, combined with loss magnitude, to quantify risk in monetary terms. Vulnerability is one of the three primary factors, representing the probability a threat event becomes a loss.

  • ✓

    Loss magnitude

    Why this is correct

    Loss magnitude quantifies the financial impact should a threat event occur, forming FAIR's primary impact factor alongside loss event frequency. It satisfies the stem's requirement for a primary estimation factor by capturing probable loss in monetary terms, enabling risk to be expressed as annualised loss exposure rather than qualitative severity ratings.

  • ✓

    Threat event frequency

    Why this is correct

    FAIR estimates threat event frequency, the probable rate at which threat agents act against the asset, as a primary factor feeding loss event frequency. This satisfies the stem's requirement for a primary FAIR estimation factor.

  • ✗

    Control cost

    Why it's wrong here

    FAIR estimates loss event frequency and loss magnitude, decomposed into threat event frequency, vulnerability, primary loss and secondary risk factors. Control cost is a cost-benefit input compared against risk reduction, not a factor in the risk calculation itself.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.