CRISC IT Risk Assessment Practice Question
A risk analyst is building a scenario for a ransomware event affecting a hospital's electronic health record environment. The analyst wants to capture loss magnitude dimensions that are frequently overlooked when only direct recovery costs are counted. Which TWO loss factors should be included to make the magnitude estimate more complete? (Choose two.)
⚠ Common exam trap
The trap here is treating the ransom demand as the headline loss while omitting regulatory and interruption consequences that usually cost far more.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory penalties and notification obligations triggered by the breach of patient records.
Complete loss magnitude estimates for a ransomware scenario must extend past recovery costs to include consequential and secondary effects. Regulatory penalties and notification duties tied to compromised patient records, along with business interruption from unavailable clinical systems, are two such dimensions. Planned expenses such as license fees and prior training spend are not incident-driven losses and would distort the estimate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Regulatory penalties and notification obligations triggered by the breach of patient records.
Why this is correct
Ransomware affecting health records typically triggers statutory notification and penalty exposure under health privacy regulations, and these costs can dwarf the ransom itself. Including them makes the magnitude estimate reflect legal and compliance consequences rather than only restoration effort. This directly addresses the scenario's concern about undercounting loss dimensions beyond direct recovery.
- ✗
The market price of the cryptocurrency demanded by the attacker at the time of the incident.
Why it's wrong here
The demanded ransom amount is one input to recovery cost, not a separate overlooked magnitude dimension, and exchange-rate movement adds noise rather than insight. The scenario asks for loss factors that broaden the estimate beyond direct recovery, and the ransom figure is already part of that direct cost category. Its inclusion would not improve the completeness of the estimate.
- ✗
The salary of the security awareness trainer who delivered last year's phishing education sessions.
Why it's wrong here
Prior awareness training spend is a control investment already made, not a consequence of the ransomware event. Counting it as loss magnitude would double-count prevention costs and distort the scenario's loss distribution. The scenario targets consequences that materialize if the event occurs, which this historical expense does not represent.
- ✓
Business interruption losses from unavailable clinical systems during containment and recovery.
Why this is correct
When the electronic health record environment is unavailable, clinicians cannot document or retrieve records, so the organization absorbs lost productivity, diverted care, and delayed revenue. These interruption losses are a distinct magnitude dimension from recovery costs and are routinely omitted in narrow estimates. Including them aligns the scenario with a complete loss picture.
- ✗
The annual license renewal cost the hospital already pays for its endpoint protection platform.
Why it's wrong here
A recurring license fee is a planned operating expense, not a loss arising from the ransomware scenario. Including it would inflate the estimate with sunk costs that exist regardless of whether the event occurs. The scenario seeks incremental loss dimensions attributable to the incident, and a pre-existing subscription does not qualify.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.