Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A retail bank's risk practitioner is building a risk scenario for its online banking platform. He needs to estimate how frequently an attacker could realistically succeed in exploiting the platform's unpatched web tier. Which of the following provides the MOST quantitative basis for this estimate?

⚠ Common exam trap

The trap here is treating a severity metric such as CVSS as if it were a frequency metric for the risk scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Historical loss-event data from the bank's own incident and fraud systems for comparable attack types

Frequency estimation in a risk scenario should be grounded in data that reflects how often the event actually occurs in the organization's own environment. Internal loss-event and incident data capture real attack attempts that succeeded despite existing controls. CVSS scores, industry vulnerability publication rates, and remediation timeliness describe severity or process performance rather than the expected rate of successful exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Historical loss-event data from the bank's own incident and fraud systems for comparable attack types

    Why this is correct

    Historical internal loss-event data reflects how often comparable attacks actually succeeded against this bank's environment, including its existing controls and threat exposure. This makes it the most defensible quantitative input for frequency estimation in the risk scenario, since it is grounded in observed events rather than theoretical severity or generic external statistics.

  • ✗

    The Common Vulnerability Scoring System (CVSS) base score of each unpatched vulnerability on the web tier

    Why it's wrong here

    CVSS base scores describe intrinsic severity of a vulnerability, not the frequency with which an attacker will succeed against this bank's platform. The base score ignores the bank's existing controls, threat activity levels, and the attractiveness of its specific environment, so it cannot quantify how often a successful exploit is realistically expected to occur.

  • ✗

    The mean time to remediate critical vulnerabilities reported by the bank's vulnerability management team

    Why it's wrong here

    Mean time to remediate is a measure of remediation efficiency, not attack success frequency. A long remediation window raises exposure, but by itself it does not tell the risk practitioner how often an attacker would actually succeed, so it cannot serve as the primary quantitative basis for the frequency estimate in the scenario.

  • ✗

    The annualized rate of new vulnerabilities published in the National Vulnerability Database (NVD) for web servers

    Why it's wrong here

    NVD publication rates measure how many vulnerabilities are disclosed industry-wide, not how often an attacker will successfully exploit this bank's web tier. The figure is not conditioned on the bank's controls, exposure, or attacker interest, so it cannot be used as a frequency of successful exploitation for this specific scenario.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.