CRISC IT Risk Assessment Practice Question
A risk analyst is preparing a risk register for a new customer relationship management (CRM) system hosted in a public cloud. For each identified risk, the analyst assigns a likelihood rating (1–5) and an impact rating (1–5) based on team consensus, and then multiplies the two scores to produce a risk score. Which risk assessment approach is the analyst using?
⚠ Common exam trap
The trap here is assuming that any method producing numbers is automatically quantitative, when ordinal consensus ratings multiplied together remain semi-quantitative.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Semi-quantitative risk analysis
Multiplying ordinal likelihood and impact ratings generates a relative risk score, which is characteristic of semi-quantitative analysis. The ratings originate from expert consensus rather than measured frequencies or financial values, so the result is not a true quantitative loss estimate, and it is more structured than a purely qualitative high/medium/low label.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Semi-quantitative risk analysis
Why this is correct
This is correct because semi-quantitative analysis uses numeric rating scales for likelihood and impact but the values are derived from qualitative judgments rather than measured frequencies or monetary losses. Multiplying ordinal ratings produces a relative risk score that supports ranking and prioritization, which matches the analyst's use of consensus-based 1–5 ratings for the CRM system.
- ✗
Quantitative risk analysis
Why it's wrong here
Quantitative analysis requires measurable inputs such as annualized rate of occurrence, asset value, and exposure factor to calculate monetary loss expectancy. Here the analyst uses ordinal 1–5 consensus ratings rather than empirical frequency data or financial values, so the outputs are relative scores and not defensible monetary estimates for the CRM system.
- ✗
Monte Carlo simulation
Why it's wrong here
Monte Carlo simulation runs repeated random sampling across probability distributions to model ranges of outcomes and their likelihoods. It is a quantitative technique requiring defined distributions and computational modeling. The analyst here only performed simple multiplication of consensus ratings, so no simulation or probabilistic distribution modeling was involved.
- ✗
Qualitative risk analysis
Why it's wrong here
Qualitative analysis expresses likelihood and impact in descriptive terms such as high, medium, or low, without converting them to numeric values. Because the analyst assigns numeric ratings and multiplies them into a composite score, the method has moved beyond purely qualitative description even though the underlying judgments remain subjective.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.