Courseiva
IT Risk Assessment →mediumMultiple Select

CRISC IT Risk Assessment Practice Question

A retail company is conducting a risk assessment for its point-of-sale (POS) system. The risk team has identified several factors that could affect the likelihood of a data breach. Which TWO factors are considered threat event frequency components that increase the likelihood of a breach? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse vulnerability factors, such as outdated software or encryption strength, with threat event frequency, which is about how often attacks are attempted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The number of attempted intrusions per month

Threat event frequency is the rate at which threat actors attempt to exploit a vulnerability. The number of attempted intrusions per month directly measures this rate. The presence of organized crime groups targeting retail payment systems indicates a higher frequency of attacks because these groups are actively seeking to compromise POS systems. The other factors relate to vulnerability, detection, or impact, not the frequency of threat events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The strength of the encryption used for payment card data

    Why it's wrong here

    The strength of encryption is a control that reduces the impact of a breach if data is stolen, and it may also reduce the likelihood of successful exploitation if it prevents access to plaintext data. However, it does not affect how often threat actors attempt to breach the system. It is a vulnerability mitigation factor, not a threat event frequency component.

  • ✓

    The number of attempted intrusions per month

    Why this is correct

    The number of attempted intrusions per month is a direct measure of threat event frequency. A higher number of attempts increases the likelihood that one will succeed, assuming the vulnerability exists. This is a key input in quantitative risk analysis models like FAIR, where threat event frequency is estimated from historical data or industry trends. It directly affects the probability of a breach.

  • ✗

    The percentage of POS terminals running outdated software

    Why it's wrong here

    The percentage of POS terminals running outdated software is a measure of vulnerability, not threat event frequency. It indicates how susceptible the system is to exploitation, but it does not reflect how often threat actors attempt to exploit it. Vulnerability and threat event frequency are separate factors in risk analysis; this factor affects the probability of success given an attempt, not the frequency of attempts.

  • ✗

    The average time to detect a breach

    Why it's wrong here

    The average time to detect a breach is a measure of response capability and affects the impact or duration of a breach, not the likelihood of the initial event. It is a detective control metric. While important for overall risk, it does not increase the frequency of threat events. Likelihood is about the occurrence of the threat event, not how quickly it is discovered.

  • ✓

    The presence of organized crime groups targeting retail payment systems

    Why this is correct

    The presence of organized crime groups targeting retail payment systems increases the threat event frequency because these groups are actively attempting to compromise POS systems. Their motivation and capability lead to more frequent attack attempts. This is a threat community characteristic that directly raises the likelihood of a breach. It is a key factor in estimating threat event frequency.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.