CRISC IT Risk Assessment Practice Question
A risk analyst is building a risk register for a newly deployed customer relationship management (CRM) system that stores personally identifiable information (PII). The analyst needs to document the risk that an attacker could exfiltrate the PII database. Which of the following BEST represents the threat component of this risk statement?
⚠ Common exam trap
Test-takers frequently confuse a vulnerability, such as unencrypted PII, with the threat actor who could exploit it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An external attacker with data exfiltration capability.
A well-formed risk statement links a threat source to a vulnerability and an impact. The attacker with exfiltration capability is the threat source, while the unencrypted PII fields are the vulnerability and the dollar figure is the impact. Identifying the threat source correctly lets the risk analyst select appropriate controls, such as monitoring for exfiltration behavior, and enables meaningful comparison across other risks in the register.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CRM database contains unencrypted PII fields.
Why it's wrong here
Unencrypted PII fields describe a weakness in the system, which is a vulnerability rather than a threat. A vulnerability is a condition internal to the asset that a threat can exploit; it does not itself represent the actor or event capable of causing harm. In a structured risk statement, the threat is the external or internal agent with the potential to cause the loss, not the missing control.
- ✓
An external attacker with data exfiltration capability.
Why this is correct
The threat component identifies the actor or event that can exploit a vulnerability to cause harm. An external attacker with exfiltration capability is precisely that actor, and pairing it with the unencrypted PII vulnerability produces a complete risk statement. This is the element a risk analyst must document to describe who or what could cause the loss event.
- ✗
The financial impact of a PII breach is estimated at $2 million.
Why it's wrong here
The $2 million figure is an impact estimate, which is the consequence component of a risk statement. Impact quantifies the loss if the threat successfully exploits the vulnerability. It answers 'how bad' rather than 'who or what causes it,' so it belongs in the impact field of the risk register, not the threat field the analyst is documenting here.
- ✗
The likelihood of a PII breach is rated as high.
Why it's wrong here
Likelihood expresses the probability that a threat event will occur, not the threat itself. It is a derived assessment built from threat capability, vulnerability exposure, and control effectiveness. Recording 'high likelihood' in the threat field would conflate the probability dimension with the actor dimension, weakening the traceability of the risk statement and any subsequent analysis.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.