CRISC IT Risk Assessment Practice Question
A risk analyst is assessing a newly discovered vulnerability in an internet-facing server. The analyst collects several data points: the vulnerability has a CVSS base score of 9.8, there are known exploits in the wild, and the server is critical for processing customer transactions. However, the organization's intrusion detection system has a signature that blocks the specific exploit, and the server is patched monthly. The analyst must determine the risk level. Which of the following should the analyst use to BEST assess the risk?
⚠ Common exam trap
The trap here is assuming that a high CVSS base score directly equates to high organizational risk without considering compensating controls and threat context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A qualitative risk assessment using a likelihood-impact matrix that incorporates the effectiveness of existing controls and threat intelligence.
The analyst must assess risk by combining vulnerability severity, threat activity, existing controls, and asset criticality. A qualitative matrix that incorporates control effectiveness and threat intelligence provides a business-contextualized risk rating, which is essential for prioritization. CVSS base scores or subscores are inputs but not sufficient alone, and financial impact alone misses likelihood and control factors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A qualitative risk assessment using a likelihood-impact matrix that incorporates the effectiveness of existing controls and threat intelligence.
Why this is correct
This approach integrates the vulnerability severity with the organization's control environment (IDS, patching) and real-world threat data (exploits in the wild) to produce a contextual risk rating. It aligns with CRISC's emphasis on business-relevant risk assessment. The analyst can then prioritize remediation based on actual risk exposure rather than raw severity.
- ✗
The CVSS base score alone, because it provides a standardized severity rating.
Why it's wrong here
The CVSS base score reflects intrinsic vulnerability characteristics but does not account for the organization's specific environment, existing controls, or threat context. Relying solely on it would overstate risk because the IDS signature and patching reduce the likelihood of successful exploitation. In this scenario, the analyst needs a contextualized view, not just the base score.
- ✗
The exploitability subscore of CVSS, because it measures the difficulty of exploiting the vulnerability.
Why it's wrong here
The exploitability subscore is a component of the CVSS base score and still does not consider the organization's compensating controls or the asset's business criticality. It provides a partial view of exploitability but ignores the IDS and patching that reduce risk. Thus, it is insufficient for a comprehensive risk assessment in this context.
- ✗
The asset's replacement cost, because risk is a function of financial impact.
Why it's wrong here
While financial impact is a factor, risk also depends on likelihood and existing controls. Replacement cost alone ignores the probability of exploitation and the effectiveness of the IDS and patching. This approach would not capture the full risk picture and could lead to misprioritization. CRISC emphasizes a balanced view of likelihood and impact.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.